THALES BLOG

Retail Cybersecurity in the Age of Agentic AI: Are Retailers and E-commerce Providers Ready?

August 11, 2026

Marcelo DeLima Marcelo Delima | Senior Manager, Global Solutions Marketing More About This Author >

Retail security teams have always had to protect data without getting in the way of customers. Every extra security check adds a bit of friction to a purchase, be it at a store, online checkout, or mobile app. And the work only starts at the checkout. Omnichannel operations span stores, websites, apps, cloud platforms, payment systems, SaaS applications, and third-party services, with sensitive data flowing throughout all these systems. What happens when you add AI to this already complex situation?

The 2026 Thales Retail and E-commerce Data Threat Report, based on responses from 426 security and IT executives at brick-and-mortar, pure-play e-commerce, and omnichannel organizations across 20 countries, finds that almost three-quarters (72%) of retail organizations cite rapid change in the AI ecosystem as a top source of risk. Some 32% now have a dedicated AI security budget, up from 19% a year ago.

Retailers face AI-assisted attacks, deepfakes, prompt injection, and growing pressure on the cloud infrastructure that supports AI applications and data. AI agents also change internal risk. As agents gain access to corporate data and act across connected systems, they can find and use information at a speed and scale that people cannot match.

The report describes AI as a new insider threat for this reason. An agent can expose sensitive information without behaving maliciously. It may simply have too much access, encounter poorly classified data, or take an action its operators did not anticipate.

Yet retail security investments struggle to keep pace with these risks.

Key Takeaways From the 2026 Retail and E-commerce Data Threat Report:

  • 72% of retail and e-commerce organizations cite rapid change in the AI ecosystem as a top source of risk.
  • Only 37% know where all of their data is stored, and only 41% can classify all of it.
  • Cloud storage, cloud applications, and cloud management infrastructure are the top three attack targets for the third year running.
  • 76% run five or more data protection tools, yet only 39% are highly confident they understand what those tools do.
  • Retail encrypts just 53% of its sensitive cloud data, and ranks data security at 28% of spending priorities against 35% across all industries.

Add your heRetail Data Visibility Is Improving, But Two-Thirds Still Cannot Locate Their Dataadline here

Data visibility has improved. While only 37% of retail organizations say they have complete knowledge of where their data is stored, this is up from 32% last year. Retail also sits slightly ahead of the 34% recorded across all industries in the 2026 Thales Data Threat Report Global Edition.

Being three percentage points above the global figure is a hollow comfort when nearly two-thirds of retailers still don’t know where their data lives, and less than half (41%) say they can classify all their data, compared with 39% across all industries.

Agentic applications increase the velocity of data movement and the volume of data in use. An agent may retrieve information from multiple sources, pass it between tools, or act on it without the manual handoffs that once limited how quickly data moved through an organization.

Retailers have to manage customer identities, payment information, purchase histories, loyalty data, employee records, and commercially sensitive information. If security teams cannot locate and classify that data with any certainty, they cannot consistently protect it according to its value or sensitivity. AI systems exacerbate the problem by making previously obscure information easier to discover and use.

Cloud Remains the Top Target in Retail Cyber Attacks

Cloud-based resources are, for the third straight year, at the heart of the attack landscape. The top three targets cited by retail respondents are cloud-based storage, cloud-delivered applications, and cloud management infrastructure.

Retail organizations use an average of 2.3 cloud providers and 88 SaaS applications. Surprisingly, traditional retailers have an average 106 SaaS applications, compared with only 60 among e-commerce only firms, a probable sign of how operations are more complex for omnichannel organizations.

71% of retail organizations report an increase in credential theft and compromise, including the misappropriation of secrets, making it the most frequently cited rising attack vector against cloud management infrastructure. Third-party vulnerabilities, including external code and APIs, follow at 66%.

Valid credentials can give attackers a route past controls designed to keep unauthorized users out. The concern grows as retailers deploy AI agents that need identities, permissions, credentials, and access to multiple systems to complete tasks.

Human error or misconfiguration remains the leading cause of retail data breaches at 27%, ahead of exploitation of known vulnerabilities at 22%. Security teams are also carrying a heavy operational burden.

Tool Sprawl: More Data Security Tools Don’t Produce More Control

Retail organizations use an average of seven data protection and monitoring tools. More than three-quarters (76%) run five or more. Yet only 39% of retail respondents express high confidence in their understanding and knowledge of existing data security tools.

Security teams have to manage multiple systems, understand how their capabilities overlap, correlate results, and identify gaps between their tools. Each extra layer adds up to more configuration work and more room for errors.

The survey reveals that retailers are reluctant to reduce the number of tools despite these complexities. 62% see gaps in functionality or capability between alternative tools, while 57% describe compatibility issues, preventing consolidation and perpetuating a serious problem.

Sensitive Cloud Data in Retail Remains Exposed: Only 53% Is Encrypted

The encryption figures show how much sensitive data remains exposed.

The average share of cloud data categorized as sensitive rose from 54% in 2025 to 56% in 2026. Yet retail organizations encrypt an average of only 53% of their sensitive cloud data, up a little from 50% last year. Encryption coverage, therefore, remains close to a coin flip, even as the share of cloud data classified as sensitive grows.

AI applications are gaining access to larger data stores, while agents are gaining greater autonomy in handling information. Strong identity controls remain essential, but credential compromise can still bypass them. Data protection must therefore hold when an attacker obtains valid credentials or when an authorized AI system reaches information it should not expose.

Retailers recognize parts of the problem. Cloud security for IaaS and PaaS ranks highly in their spending priorities, as does identity and access management. AI security budgets are rising quickly, too.

Retail Data Security Spending Does Not Match the Risk

However, despite the clear risks retailers face, they give data security less spending priority than organizations overall. Retail organizations prioritize data security spending at 28%, below the 35% survey-wide figure. That may be a sign of previous investment and focus on data security by retail organizations, but it could lead to serious future vulnerabilities as innovation makes older data security technologies and tools obsolete.

As agents gain broader access to corporate systems and information, that mismatch will become harder to ignore.

What Retail and E-commerce Security Leaders Should Do Next:

  • Find and classify the data first. Discovery and classification across stores, e-commerce platforms, SaaS, and cloud is the prerequisite for every other control, and the only way to decide what an AI agent should never reach. Data security posture management makes that inventory continuous rather than a point-in-time audit.
  • Treat every agent as an identity. Give agents scoped, time-bound credentials and monitor what they access, in the same way you would govern a privileged employee.
  • Encrypt sensitive cloud data and control the keys. At 53% coverage, roughly half of retail's sensitive cloud data is still readable to anyone holding valid credentials.
  • Consolidate before you add. Seven tools, five or more key management systems, and 39% confidence is a tooling problem, not a coverage problem.
  • Close the credential gap. Credential theft is the fastest-rising cloud attack vector in retail. Secrets management and strong identity controls are what stop a valid login from becoming a breach.

Retail Cybersecurity and Agentic AI: FAQs

Why is AI considered a new insider threat in retail?

Because AI agents act with legitimate access. An agent granted broad permissions can retrieve, combine, and act on customer, payment, and employee data at machine speed with no malicious intent, exposing sensitive information simply because it was over-permissioned or the data was poorly classified.

What are the biggest data security risks facing retailers in 2026?

The 2026 Thales Retail and E-commerce Data Threat Report points to four: rapid change in the AI ecosystem (72%), credential theft and misappropriated secrets (71%), third-party vulnerabilities including external code and APIs (66%), and human error or misconfiguration, which causes 27% of retail data breaches.

How much of retailers' sensitive cloud data is encrypted?

Retail organizations encrypt an average of 53% of their sensitive cloud data, up from 50% in 2025, even as the share of cloud data classified as sensitive rose from 54% to 56%. Roughly half of retail's most sensitive cloud data remains unprotected.

How many cloud providers and SaaS applications does the average retailer use?

Retail organizations use an average of 2.3 cloud providers and 88 SaaS applications. Traditional retailers average 106 SaaS applications against 60 for e-commerce-only businesses, a measure of how much more complex omnichannel operations are to secure.

Do retailers spend enough on data security?

Not relative to their risk. Retail organizations rank data security at 28% of security spending priorities against 35% across all industries surveyed, while adopting AI agents that widen access to the very data those controls protect.

 

Download the 2026 Thales Retail and E-commerce Data Threat Report for the full findings, including the segment and country breakdowns behind these figures.