Retail Cybersecurity in the Age of Agentic AI: Are Retailers and E-commerce Providers Ready?

Retail Cybersecurity in the Age of Agentic AI: Are Retailers and E-commerce Providers Ready?
lee.potok@thal…
Wed, 08/12/2026 – 07:40

The 2026 Thales Retail and E-commerce Data Threat Report reveals how rapid AI adoption, cloud complexity, and data visibility gaps are reshaping cybersecurity risks for retailers. With 72% citing rapid changes in the AI ecosystem as a top risk, organizations must strengthen data discovery, access controls, and protection as AI agents gain greater access to sensitive information.

Data Security
Cloud Security
Identity & Access Management
Insider Threat

Marcelo Delima | Senior Manager, Global Solutions Marketing
More About This Author >

Retail security teams have always had to protect data without getting in the way of customers. Every extra security check adds a bit of friction to a purchase, be it at a store, online checkout, or mobile app. And the work only starts at the checkout. Omnichannel operations span stores, websites, apps, cloud platforms, payment systems, SaaS applications, and third-party services, with sensitive data flowing throughout all these systems. What happens when you add AI to this already complex situation?

The 2026 Thales Retail and E-commerce Data Threat Report, based on responses from 426 security and IT executives at brick-and-mortar, pure-play e-commerce, and omnichannel organizations across 20 countries, finds that almost three-quarters (72%) of retail organizations cite rapid change in the AI ecosystem as a top source of risk. Some 32% now have a dedicated AI security budget, up from 19% a year ago.

Retailers face AI-assisted attacks, deepfakes, prompt injection, and growing pressure on the cloud infrastructure that supports AI applications and data. AI agents also change internal risk. As agents gain access to corporate data and act across connected systems, they can find and use information at a speed and scale that people cannot match.

The report describes AI as a new insider threat for this reason. An agent can expose sensitive information without behaving maliciously. It may simply have too much access, encounter poorly classified data, or take an action its operators did not anticipate.

Yet retail security investments struggle to keep pace with these risks.

Key Takeaways From the 2026 Retail and E-commerce Data Threat Report:

  • 72% of retail and e-commerce organizations cite rapid change in the AI ecosystem as a top source of risk.
  • Only 37% know where all of their data is stored, and only 41% can classify all of it.
  • Cloud storage, cloud applications, and cloud management infrastructure are the top three attack targets for the third year running.
  • 76% run five or more data protection tools, yet only 39% are highly confident they understand what those tools do.
  • Retail encrypts just 53% of its sensitive cloud data, and ranks data security at 28% of spending priorities against 35% across all industries.

Add your heRetail Data Visibility Is Improving, But Two-Thirds Still Cannot Locate Their Dataadline here

Data visibility has improved. While only 37% of retail organizations say they have complete knowledge of where their data is stored, this is up from 32% last year. Retail also sits slightly ahead of the 34% recorded across all industries in the 2026 Thales Data Threat Report Global Edition.

Being three percentage points above the global figure is a hollow comfort when nearly two-thirds of retailers still don’t know where their data lives, and less than half (41%) say they can classify all their data, compared with 39% across all industries.

Agentic applications increase the velocity of data movement and the volume of data in use. An agent may retrieve information from multiple sources, pass it between tools, or act on it without the manual handoffs that once limited how quickly data moved through an organization.

Retailers have to manage customer identities, payment information, purchase histories, loyalty data, employee records, and commercially sensitive information. If security teams cannot locate and classify that data with any certainty, they cannot consistently protect it according to its value or sensitivity. AI systems exacerbate the problem by making previously obscure information easier to discover and use.

Cloud Remains the Top Target in Retail Cyber Attacks

Cloud-based resources are, for the third straight year, at the heart of the attack landscape. The top three targets cited by retail respondents are cloud-based storage, cloud-delivered applications, and cloud management infrastructure.

Retail organizations use an average of 2.3 cloud providers and 88 SaaS applications. Surprisingly, traditional retailers have an average 106

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from Thales CPL Blog Feed

Read the original article: