When AI gets hands: Akamai warns security chiefs the rules have changed

Akamai’s latest State of the Internet report, Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape (Volume 12, Issue 5, published September 2026), says companies are entering a new phase of risk. The danger is no longer just who logs in. It is what autonomous software does once it is inside.

Two problems, one era

The report frames the moment around two challenges. The first is the “autonomy guardrail dilemma”: attackers can trick AI agents through hidden instructions, poisoned context, or rogue browser extensions, leading them to take unauthorised, high-impact actions. The second is the “asymmetric velocity gap.” AI can find and chain software flaws in hours, while most companies still patch at human speed.

The numbers behind the shift

Akamai’s network data shows the scale. AI bot traffic rose 300% in 2025. Daily API attacks per organisation grew 113%, from 121 to 258. Some 87% of surveyed organisations reported an API-related incident, and API breaches now cost enterprises an average of US$700,000 per year.

MCP: Power with peril

Akamai’s CTO Charlie Gero describes the Model Context Protocol as giving AI “a hand”. It lets models query databases, run code and orchestrate workflows. But it blurs the line between data and code. A malicious third-party server can hide instructions in tool descriptions, or use a low-trust tool to push an AI into raiding a high-trust one, such as a key vault. His advice is not to avoid MCP but to isolate trust levels, add proxy gateways and require human approval for state-changing actions.

The browser is the new weak spot

Employees are a fast-growing risk. Some 99% run at least one browser extension, and over 40% have installed AI-powered ones. A quarter of those AI extensions changed their permissions within a year, compared with 4.33% of extensions overall. Almost 6% of employee chatbot conversations contained sensitive data, mostly personal information, and 47% of AI conversations on work devices used personal accounts, leaving security teams blind.

Lessons from Project Glasswing

Akamai took part in Anthropic’s Project Glasswing and had early access to the Mythos model. Its takeaway: frontier AI did not make software less secure, but it made discovery dramatically faster. The bottleneck is now deciding which exposures are reachable, exploitable and business-critical. Until patches land, firms need runtime protection, edge controls and segmentation.

Brand risk in a zero-click world

As AI agents replace websites as the front door to customers, CISOs must watch four areas: citations, accuracy, and sentiment and bot management.

Trusting the machine

The report offers a practical test instead of a philosophical one. Can I verify the output? How bad, and how reversible, is a confidently wrong answer? Its guidance: match autonomy to verifiability, not capability; treat confident output as a signal to check; and keep accountability human.

The takeaway

Akamai stresses that firms need not build a separate AI security programme. Instead, they should extend proven basics such as visibility, Zero Trust segmentation, exposure management and identity checks into autonomous workflows, while also separating shadow AI from managed systems. As the report puts it, AI does not replace traditional attacks. It industrialises them.

A note for readers: Akamai sells security products, so its recommendations favour edge-based defences. The data is from its own network and customer analysis.

Author