Artificial intelligence has quietly become the new attack surface of the modern enterprise. That’s the central warning in Akamai’s newly released Enterprise AI Usage Risk Report 2026, part of its State of the Internet/Security series, built on data from LayerX, the AI-security firm Akamai recently acquired. The report paints a picture of an enterprise landscape in which AI adoption has outpaced governance — and security teams are struggling to see what’s actually happening within their own organisations.
A Small Group of “Power Users” Drives Most of the Risk
While nearly 20% of employees use AI weekly, the report finds that risk isn’t evenly spread. A small slice of “AI power users” — the top 5% — generate at least 144 conversations each, compared to just 12 or fewer for the bottom half of users. These heavy users share more sensitive business context, upload more files, and increasingly let AI drive real decisions, making them the highest-value targets for attackers.
Shadow AI Is Everywhere
Beyond well-known platforms like ChatGPT, Copilot, and Gemini lies a sprawling “long tail” of AI tools operating with zero oversight. Startlingly, nearly half of all enterprise AI conversations (47%) happen through personal accounts rather than corporate-managed ones — and 14.4% of conversations tied to corporate email addresses are actually running on personal “freemium” subscriptions, meaning that data may be feeding public model training without anyone realising it.
Data Doesn’t Leak the Way It Used To
Traditional data-loss prevention tools were built for emails and file transfers. AI breaks that model entirely: sensitive information now moves through prompts, pasted text, screenshots, and iterative conversations — channels legacy security tools were never designed to monitor. The report cites a real-world case in which a U.S. government official inadvertently exposed restricted CISA operational data via a public AI tool, underscoring how easily routine AI use can lead to a serious leak.
Extensions and Agents: The New Frontier of Attack
AI browser extensions are especially risky — nearly 75% request high or critical permissions, and they’re almost three times more likely to request cookie access than average extensions. The report details two proof-of-concept attacks: “CursorJacking,” in which a malicious extension silently steals AI coding assistant credentials, and “CometJacking,” in which a booby-trapped webpage hijacks an AI browser agent via prompt injection.
The Bottom Line
Akamai’s message to CISOs is clear: securing AI isn’t about blocking tools, but about gaining visibility — into power users, shadow apps, data flows, extensions, and autonomous agents alike. As AI agents take on more independent action inside enterprise systems, the report argues they must be governed with the same rigour as any human employee.
