Safetica Research
H1 2026 Data Protection Trends Report
The way people work is changing.
Data protection has to change with it.
Safetica's latest research examines how data risk changed during the first half of 2026 across everyday work platforms, AI tools, communication channels, file types, and user behavior.
Explore the trends shaping data protection and insider risk, based on hundreds of thousands of blocked activities, data policy violations, unusual data-handling events, and risky application interactions across Safetica customer environments worldwide.
What the research found
Core platforms are the top risk surface
43.7%+
Google and Microsoft sites accounted for 43.7% of all blocked activity in Q2 2026, nearly triple their combined 14.2% share in Q3 2025. Data risk is increasingly concentrated inside the productivity platforms employees already use every day.
Everyday tools still carry most of the risk
72%
Email, web, and instant messaging accounted for 72%+ of data policy violation paths in Q2. Presentations and text files made up more than 57% of the file types involved. Most exposure continues to start in ordinary work.
The spotlight on AI tool risk continues
40.7%
AI tools became the #1 risky app category in Q2, accounting for 40.7% of flags. ChatGPT and Copilot together drove 82.3% of blocked AI activity, while AI tools' overall share of blocked activity continued to rise.
Insider risk migrated to the network
21.6%
Network-triggered Dynamic DLP activity more than quadrupled from Q1 to Q2, from 5.1% to 21.6%. Unusual Activity flags tied to the network increased sharply, showing how risky behavior can shift as work patterns and controls change.
See how data risk changed across H1 2026
The full report examines how data protection and insider risk patterns shifted between Q1 and Q2 2026, with longer-term comparisons where the data supports them.
Inside the report:
-
How blocked activity shifted toward Microsoft and Google platforms
-
Why AI tools became the #1 risky application category
-
Which AI assistants account for the majority of blocked AI activity
-
Where data policy violations occur across email, web, and instant messaging
-
How file, network, and user-behavior risk changed between Q1 and Q2
-
How Dynamic DLP patterns differ by industry
About the research
In the first half of 2026, Safetica Researchers analyzed hundreds of thousands of blocked activities, data policy violations, unusual data-handling events, and risky application interactions logged across Safetica customers worldwide.
The report compares Q1 and Q2 2026 and, where the data supports it, extends the analysis back to Q3 2025 to show how data protection and insider risk patterns are changing over time.