Security News

AI Systems Are Leaking Sensitive Data to the Wrong Users, ANZ Report Finds

Key Takeaway Australian small businesses using AI tools should review access controls and data governance settings regularly, since AI systems can unintentionally expose sensitive information to the wrong users as usage grows.

A new regional threat report from Netskope Threat Labs shows that AI systems revealing sensitive information to people who shouldn't see it has become the second most common type of AI security incident in Australian and New Zealand organisations. These so-called 'downstream' violations, where AI tools surface data to unauthorised users, made up 666 of every 10,000 AI security alerts among businesses with the governance controls to detect them. The most common issue remains employees feeding sensitive data into AI tools in the first place, accounting for 8,300 of every 10,000 alerts.

Netskope links the rise in downstream risks to the growing use of AI agents and machine-to-machine connections, particularly through the Model Context Protocol, a standard that lets AI models connect to external data sources and tools. Over a two-month period, agent activity involving remote MCP servers rose 89 percent in the region, while MCP-related security events climbed 69 percent. The report also found that prompt injection and jailbreaking attacks, which try to manipulate AI systems into producing harmful or sensitive outputs, occurred at twice the global rate in ANZ organisations.

The report further warns of attackers using 'AI Engine Optimisation' to get public AI tools to cite malicious links as trustworthy sources, with an average of 67 workers per 100,000 clicking such links weekly over the past year, peaking at 175 late in 2025. Fake AI-branded apps, trojanised developer tools and credential-stealing lures were also flagged, with 140 of every 100,000 workers falling for AI-related scams in May alone.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.