From Wild West to Enterprise Control

Retailers have been among the most aggressive adopters of generative AI. According to Netskope, 95 % of retail organizations now use generative AI in some capacity, up from 73 % just a year ago. What’s notable is not just the speed, but the shift in how they use it.

Earlier, staff often experimented with AI tools on their personal accounts, “shadow AI.” But that has declined. Use of personal accounts dropped from 74 % to 36 %, while use of company-approved tools more than doubled from 21 % to 52 %. That signals a maturing posture: retail is trying to wrest control over unpredictable use.

Still, the transition is perilous.

The Hidden Costs: Exposure, Misconfiguration, Leakage

The strength of generative AI, its capacity to digest and respond to data, is also its Achilles’ heel.

One of the clearest risks is data leakage. The report finds that the most frequent type of policy violation in AI apps is exposure of a company’s own source code (47 %), followed by regulated, confidential customer or business data (39 %). That’s not a trivial risk in retail, where proprietary algorithms, pricing models, customer profiles, and supply chain details are gold mines.

Retailers are reacting. Some are outright banning tools judged “too risky.” The most commonly blocked app is ZeroGPT, banned by 47 % of organizations over concerns that it stores user content and routes it to third parties.

But bans are a blunt instrument. The real battleground is in secure integration.

Many retailers now embed generative AI deeper into their operations. Some 63 % are connecting directly to OpenAI’s API, embedding capabilities in backend systems and workflows. That amplifies risk: a misconfiguration, a lax permissions setting, or a compromised credential could open doors to critical systems.

Worse, cloud security hygiene is already a struggle. Attackers are blending in, using trusted names and services to deliver malware. The report notes that Microsoft OneDrive was cited in 11 % of retail malware incidents monthly and GitHub in nearly 9.7 %. Meanwhile, personal apps and social media remain vectors: 76 % of policy violations involving regulated data stem from files uploaded to unapproved personal services.

Vendor Moves: Enterprise-Grade over Ad Hoc

To counter these risks, many retailers are migrating to enterprise-grade AI tools, often offered by big cloud providers. These platforms promise more control: private hosting, stricter governance, and custom tool development.

In the retail sector, OpenAI via Azure and Amazon Bedrock lead in adoption (both used by about 16 % of retailers). But these are not panaceas, misconfigurations or insufficient policy enforcement may still undercut the safeguards.

What Retailers Must Do: Governance, Visibility, Controls

If generative AI is becoming core infrastructure, it needs the same rigor as financial systems or supply chains. The report’s prescription is blunt but essential: gain full visibility on web traffic, block high-risk applications, enforce strict data protection policies, and control what information can be fed into AI models.

Retailers can’t afford to treat AI as a toy. Without governance baked into the deployment, the next AI innovation could turn into the next headline breach.

#AI#ChatBots#Netskope#Retailers#Security#User data

Daniel Reyes is not a person. No notebook, no deadlines, no face behind the name — just a byline this newsroom publishes under. Here is the production line underneath it, because a name beside a portrait reads like a journalist, and this one is not one.

The models. Writing: gpt-5.6-luna and qwen3-max. Out on the live web: gpt-5.6-luna and gpt-5.6-terra. Pictures: gpt-image-1 and gpt-image-1-mini. Swap one in the newsroom and this line swaps with it — it is read off the machines, not typed here.

How a story is made

  • Research. The searching model reads around the story, pointed at primary sources — the filing, the post, the repository — rather than at somebody else's write-up of them.
  • Writing. The writing model drafts it against what was found, at Daniel Reyes's usual length and in Daniel Reyes's usual register.
  • The loop. A reviewer reads the draft and sends it back with notes. Then reads it again. A piece can go round several times before it leaves the building.
  • Enrichment. A quotation has to appear word for word on the page it is taken from. A chart may only use figures that appear in the source it cites. Whatever fails is dropped, and the reason is kept.
  • Fact check. A last pass hunts for claims the article makes and its sources do not.
  • A human stop. Sensitive subjects are held for a person to read before publication, and a person can kill any of it at any point.

If that sounds less like a newsroom and more like a factory: quite. It is called Press Factory.

This article was generated using AI and published automatically without human pre-publication review.

How this article was made

The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.