Published on the 16/09/2026 | Written by Heather Wright
Agents gain access to business – and data…
Local organisations are moving beyond AI experimentation and into AI automation, with new data suggesting a sharp increase in technology that allows AI systems to connect directly to business applications and enterprise data.
Netskope Threat Labs Australia and New Zealand 2026 report shows usage of the Model Context Protocol, a key technology underpinning agentic AI and enabling AI systems to directly connect with external applications, databases and enterprise tools, is rising rapidly across the region as organisations increasingly wire AI into operational workflows, software development environments and enterprise workflows, rather than using it solely as a standalone productivity tool.
“While MCP traffic is a sign that agentic AI adoption is progressing fast within organisations across A/NZ, each of these connections is a new pathway for company data to move between AI apps and outside systems…”
The findings align with trends identified in Netskope’s global 2026 AI report, which describes a worldwide shift from shadow AI concerns towards governance of autonomous AI agents and connected AI systems. Globally, Netskope says organisations are moving beyond monitoring prompts and are increasingly focused on how AI interacts with enterprise data and executes actions across connected systems.
Across Australia and New Zealand, one of the clearest indicators of that transition is the rapid growth of MCP, an emerging standard which allows AI systems to connect with external tools and data sources.
The report found the number of agents interacting with remote MCP servers increased by 89 percent during the two month reporting period, while MCP-related events rose by 69 percent. Globally MCP has also experienced a surge in use. The A/NZ report says much of this increased activity is linked to coding agents such as Claude Code and Codex, which are increasingly being used to interact with enterprise systems on behalf of users.
Rather than simply generating responses, AI systems connected through MCP can potentially retrieve information from multiple systems, interact with business applications and participate in business workflows. That represents a marked shift from the first wave of generative AI adoption, where employees primarily used AI as a productivity tool for drafting documents, summarising information and generating code.
The report warns that the same tools which unlock productivity, including MCP servers, simultaneously expand attack surfaces.
“While MCP traffic is a sign that agentic AI adoption is progressing fast within organisations across A/NZ, each of these connections is a new pathway for company data to move between AI apps and outside systems, and a vector of potential data leaks if not properly governed.”
The report says downstream data policy violations, where an AI service returns sensitive information to users or agents who are not authorised to access the information are rising as organisations connect AI systems to data stores and business applications. They accounted for 666 out of every 10,000 AI security alerts among organisations with the ability to monitor for such activity. Upstream data policy violations – where employees send sensitive data into AI tools, remained the most prevalent AI-related risk accounting for 8,300 of every 10,000 alerts across Australia and New Zealand.
Anthropic pulls ahead
The growth of connected AI systems comes as AI adoption continues to surge throughout Australian and New Zealand organisations.
According to the report, the proportion of users actively using AI applications increased from 53 percent to 75 percent over the past year. However, direct AI use only tells part of the story, with Netskope finding that 97 percent of employees now use applications with embedded AI capabilities and 93 percent interact with systems that use customer or user data to train models.
“These figures illustrate how deeply AI has become embedded in everyday work, often through features built into familiar business applications rather than standalone tools.”
The report also points to a notable difference between A/NZ and broader global usage patterns: ChatGPT remains the leading AI application across most global regions monitored for the global report. Locally, however, organisations have shifted sharply towards Anthropic’s Claude platform which is now used by 81 percent of organisations in the region. ChatGPT follows on 68 percent, with Microsoft bringing up the rear with 66 percent. Netskope says a similar pattern is emerging in enterprise API usage, where Anthropic’s API leads local adoption, establishing a significant lead over competing providers. It has 82 percent of organisations connecting to it, well ahead of second-placed Assemblyai on just 47 percent and OpenAI on 44 percent.
That divergence may reflect the increasing influence of developers and enterprise users as AI adoption matures. The report notes that the popularity of Claude Code and related development tools is helping drive wider enterprise adoption of Anthropic’s platform.
Shortening shadows
The findings also suggest ANZ organisations are bringing AI under more formal governance. Use of organisation-managed AI applications climbed from 34 percent to 75 percent during the year, while use of personal AI applications declined from 76 percent to 55 percent.
However, the report also highlights an emerging challenge with the proportion of users switching between personal and enterprise AI accounts almost doubling from 11 percent to 21 percent. According to Netskope, that indicates employees continue to experiment with new AI services even as organisations establish approved platforms and governance frameworks. Netskope’s take? It’s time to streamline the review and approval of new AI applications.



























