Retail · 4 October 2026
Retail AI agents outpace governance, Netskope research finds
Retailers are rapidly deploying autonomous AI agents, but oversight of what these tools do with customer and payment data is lagging well behind adoption, new Netskope research shows.
What happened
Retail companies are rapidly adopting AI agents across their operations, but oversight of these tools is lagging well behind deployment, according to new research from Netskope covered by CIO Dive and Retail Dive. The findings point to a widening gap between how fast agentic AI is spreading inside retail organisations and how well security and governance teams can track what those agents are actually doing with sensitive data.
While retailers have made progress curbing unsanctioned "shadow AI" use by individual employees, the research indicates that autonomous AI agents — tools that can take multi-step actions on their own, often connecting to multiple systems and data sources — are proliferating in ways that are much harder to monitor. This leaves regulated data, including customer and payment information, exposed to risks that traditional oversight models were not built to catch.
Why it matters
Agentic AI represents a step-change from conventional AI tools: rather than simply answering a prompt, these agents can log into systems, move data between platforms and execute tasks with limited human checkpoints. That autonomy is precisely what makes them useful for retailers chasing efficiency in areas like customer service, inventory and personalisation — but it also means a single misconfigured or poorly governed agent can touch far more sensitive data, far faster, than a human employee ever could.
For technology and risk leaders, the story underscores that governance frameworks built for "shadow IT" or shadow AI by individuals don't automatically extend to fleets of interconnected agents acting on an organisation's behalf. As retailers scale agentic deployments to serve customers faster, the operating model for oversight — visibility, access controls and accountability — needs to scale just as quickly, or the gap between capability and control will keep widening.
The Renascence take
The retail sector's enthusiasm for agentic AI is understandable — these tools promise faster service and leaner operations. But the research is a reminder that autonomy without visibility is a governance debt that compounds quietly until it surfaces as a breach.
Most organisations are still thinking about AI governance as a policy problem — write the rules, train the staff, move on. Agentic AI breaks that model, because the "user" making decisions with regulated data is now a piece of software acting on a human's behalf, often several layers removed from anyone who would notice if it went wrong. The fix isn't more policy documents; it's treating every agent like a new employee with system access — onboarded, permissioned, logged and reviewed on a cadence, not left to run quietly in the background because it's "just automation." Retailers that get this right will treat agent oversight as a core part of the customer experience function, not a side task for IT security.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in Retail
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
