Safetica H1 2026 Data Protection Trends

The way people work is changing.
Data protection has to change with it.

Safetica analyzed hundreds of thousands of blocked activities, data policy violations, unusual data-handling events, and risky application interactions across customer environments worldwide in H1 2026.

The findings show risk concentrating in everyday work, with AI becoming a much more significant part of the data protection challenge.

 

Research period: Q1-Q2 2026
Source: Aggregated Safetica research data across industries · Blocked activity, AI tool risk, policy violations, insider risk signals, and Dynamic DLP triggers

1-2026-data-protection-report-page-1

Core platforms are the top risk surface
43.7%+

Google and Microsoft sites accounted for 43.7% of all blocked activity in Q2 2026, nearly triple their combined 14.2% share in Q3 2025. Data risk is increasingly concentrated inside the productivity platforms employees already use every day.

Everyday tools still carry most of the risk
72%

Email, web, and instant messaging accounted for 72%+ of data policy violation paths in Q2. Presentations and text files made up more than 57% of the file types involved. Most exposure continues to start in ordinary work.

The spotlight on AI tool risk continues
40.7%

AI tools became the #1 risky app category in Q2, accounting for 40.7% of flags. ChatGPT and Copilot together drove 82.3% of blocked AI activity, while AI tools' overall share of blocked activity continued to rise.

Insider risk migrated to the network
21.6%

Network-triggered Dynamic DLP activity more than quadrupled from Q1 to Q2, from 5.1% to 21.6%. Unusual Activity flags tied to the network increased sharply, showing how risky behavior can shift as work patterns and controls change.

Get the full H1 2026 Data Protection Trends Report

Explore the complete findings, quarter-over-quarter trends, industry comparisons, and analysis of how data risk is changing across everyday work, AI tools, collaboration channels, file types, and user behavior.


Inside the full report

  • How Google and Microsoft platforms became the leading blocked-activity surface
  • Why AI tools became the #1 risky application category
  • Which AI assistants account for the majority of blocked AI activity
  • Where data policy violations are occurring across email, web, and messaging
  • How file, network, and user-behavior risk changed between Q1 and Q2
  • How Dynamic DLP patterns differ by industry

 

About the research

In the first half of 2026, Safetica Researchers analyzed hundreds of thousands of blocked activities, data policy violations, unusual data-handling events, and risky application interactions logged across Safetica customers worldwide. The report compares Q1 and Q2 2026 and, where the data supports it, extends the analysis back to Q3 2025 to show how data protection and insider risk patterns are changing over time.