VMTech
Discuss a project

Akamai report identifies concentrated security risks from AI power users

Akamai report identifies concentrated security risks from AI power users

Akamai’s State of the Internet: Enterprise AI Usage Risk Report 2026 finds that the top 5% of enterprise AI power users interact with AI models at 12 times the rate of the bottom half of employees. These users routinely hold conversations of 18 prompts or more, compared with about five prompts for the average employee, indicating that AI is becoming embedded in essential business activity.

The report argues that this small group can create a disproportionate security exposure. Security teams may focus on governing prominent frontier models used for routine drafting, while power users connect a growing collection of niche tools, personal subscriptions, browser extensions and autonomous agents to business workflows outside established controls.

Personal identities widen the visibility gap

Akamai found that 47.11% of enterprise AI conversations occur through personal identities rather than corporate-managed accounts. The distinction matters because platforms with governance controls can enforce corporate identity boundaries, while personal-access accounts leave IT, security and compliance teams with less visibility into how information is processed, retained and stored.

Usage patterns differ sharply by product. Gemini Enterprise keeps 98.15% of interactions inside corporate identity systems, while Microsoft Copilot M365 records 90.55%. By contrast, DeepSeek is 99.8% dominated by personal identity logins; the figures are 63.92% for Microsoft Copilot Standard, 61.36% for ChatGPT and 61.09% for Claude.

Corporate email does not necessarily mean corporate governance. Akamai says 14.4% of enterprise AI conversations took place through corporate email addresses connected to personal “freemium” AI subscriptions rather than enterprise-managed licences. The report warns that sensitive material entered in prompts may then be used for public model training.

Extensions and agents expand the attack surface

The long tail of AI-enabled tools is another blind spot. Employees increasingly bring their own AI tools through personal accounts, creating uncertainty over where business data is retained and processed. Browser and integrated development environment extensions can also gain direct access to active sessions and sensitive corporate data.

At midsize enterprises, 17.7% of employees use at least one AI extension, compared with 9.53% at larger organisations. Nearly 75% of these extensions request high or critical permissions. Akamai found known CVE vulnerabilities in 16.31% of AI extensions, above the 10.80% recorded across browser extensions overall.

The report highlights several attack techniques: “Vibe Hacking,” in which attackers alter local instruction files such as AI_CONFIG.md to influence coding assistants; “CursorJacking,” where rogue extensions seek API keys, session tokens and source code; and “CometJacking,” which uses indirect prompt injection in malicious web pages to induce agents to exfiltrate local files.

Controls should follow concentrated dependency

Akamai recommends continuous discovery of AI applications, extensions and agents, with inspection of prompts, uploads and responses. It also calls for corporate single sign-on, blocking unmanaged personal logins, auditing corporate email addresses attached to freemium accounts, and contextual AI data-loss prevention for unstructured material such as source code and internal text.

For extensions, the checklist calls for a rigorous inventory, strict permission boundaries and screening for known CVEs. Autonomous AI agents and browsers should be treated as privileged digital identities, with least-privilege access, narrow scope limits and real-time monitoring. The practical implication is that businesses should identify the teams whose workflows depend most heavily on AI, then apply governance where use and exposure are concentrated rather than assuming a uniform risk across the workforce.

#shadowai#aisecurity#dataprotection#enterprisesecurity
Open analytics
On the site 0 views
min read 4 24.08.2026
Instagram

Akamai report identifies concentrated security risks from AI power users

Open the post on Instagram ↗