零售业 · 2026年10月4日
Retailers curb shadow AI but lose sight of agentic AI risks
Retailers have reined in unsanctioned shadow AI use, but Netskope research shows oversight of approved autonomous AI agents acting on payment and customer data is falling behind their rapid rollout.
What happened
New research from security vendor Netskope finds that retailers are racing to deploy autonomous AI agents across their operations, but oversight of these tools has not kept pace with their rollout. According to coverage in CIO Dive and Retail Dive, retail IT and security teams have made progress curbing unsanctioned "shadow AI" use by employees, yet they are struggling to monitor what officially sanctioned AI agents actually do once they are set loose on internal systems, customer records and payment data.
The distinction matters: shadow AI refers to staff quietly using unapproved chatbots or copilots, a problem many retailers have now brought under some governance. Agentic AI — software that can independently take multi-step actions such as querying databases, processing transactions or interacting with other systems — is a newer and less visible risk. Netskope's findings suggest that as retailers hand these agents broader autonomy to improve efficiency, visibility into their behaviour, data access and decision-making is falling behind.
Why it matters
This is fundamentally a technology and governance story: agentic AI changes what automation is capable of inside a retail environment, moving from passive analytics or chat assistance to tools that can act on sensitive data with limited human checkpoints. That shift raises the stakes for how retailers architect oversight, because an agent that misbehaves, misreads an instruction or is manipulated does not simply give a wrong answer — it can execute an action involving payment or customer information.
For transformation leaders, the lesson is that agentic AI adoption is outpacing the governance frameworks built for earlier generations of AI tools. Policies designed to catch unsanctioned chatbot use are not necessarily built to track what an approved, embedded agent is doing moment to moment across systems. Retailers that scale agents without equivalent investment in monitoring, logging and permissioning are effectively trading one blind spot for another.
The Renascence take
Most coverage of this trend frames it as a cybersecurity compliance issue. The more interesting read is behavioral: organisations tend to govern what they can see, and shadow AI was visible precisely because it was unsanctioned and therefore flagged as risk. Agentic AI, once approved, slips into the category of "trusted infrastructure" — and trusted infrastructure gets audited far less often than suspicious activity.
The real exposure here isn't rogue employees using ChatGPT — it's retailers mistaking "we approved it" for "we can see what it's doing." An agent with standing permissions to touch payment and customer data needs the same scrutiny as a new hire with system access: clear boundaries, logged actions and periodic review, not a one-time sign-off. Any retailer treating agentic AI governance as a security afterthought rather than a core design requirement is building customer trust on a foundation nobody is actually monitoring.
来源
本简报由我们的新闻编辑部撰写,综合了以下媒体的报道。点击链接可查看原始报道。
FAQ
