Akamai says nearly half of enterprise AI use bypasses corporate security
Unapproved AI tools and risky browser extensions leave corporate networks exposed, according to new research detailing unmanaged workplace software risks.
Nearly half of enterprise artificial intelligence activity takes place outside corporate security controls, according to a recent Akamai study examining unapproved applications, browser extensions and autonomous agents. The Enterprise AI Usage Risk Report 2026 revealed that exposure is heavily concentrated among a small subset of staff. Specifically, the most active 5% of users generate the majority of interactive AI prompts, making this specific cohort the main priority for oversight and tailored security guidance.
Table Of Content
This exposure comes as workplace adoption shifted rapidly from cautious experimentation in early 2025 to widespread integration across various business functions. However, existing security controls struggle to monitor how employees enter sensitive company data into external AI services or grant automated tools direct access to corporate systems.
Shadow AI limits corporate oversight
While security teams frequently focus their protection efforts on a small selection of approved AI platforms, employees routinely turn to personal accounts, niche tools and unmanaged software services. This trend creates an extensive long tail of shadow AI operating entirely outside normal corporate visibility. Within this unmonitored environment, sensitive information can be entered into prompts, pasted into web applications or uploaded as documents without encountering controls built for standard email and file transfers.
Or Eshed, Vice President of Enterprise Security Product and Engineering at Akamai, pointed out that traditional data loss prevention mechanisms were originally designed for files and emails. Because AI services distribute enterprise data across prompts, personal accounts and autonomous agents, security teams must now evaluate individual user interactions rather than depending primarily on access blocks.
To address these vulnerabilities, the report recommends enforcing single sign-on across all AI platforms while continuously discovering unapproved applications. It further highlights the need for real-time inspection of prompts, pasted text and document uploads to provide security teams with complete visibility into how information moves through AI ecosystems.
Browser extensions add another route to company data
The report reveals that almost 75% of AI extensions request high or critical permissions, and 16.3% contain known software vulnerabilities. Because tools with such broad permissions can access API keys, proprietary source code and conversation histories, Akamai advises organisations to classify browser and software development extensions as privileged applications subject to rigorous review and approval workflows.
Akamai researchers identified three distinct attack techniques emerging in 2026 that exploit these environment vulnerabilities. The first technique, known as vibe hacking, involves covertly modifying local markdown instruction files inside a developer’s workspace. These silent alterations can cause coding assistants to produce insecure output or perform unauthorised actions while appearing to maintain the developer’s normal workflow.
A second vector, termed CursorJacking, employs malicious browser extensions with extensive permissions to harvest API keys, internal code and conversation logs, targeting coding assistants like Cursor through the web browser. Meanwhile, CometJacking relies on indirect prompt injection, where malicious instructions hidden on public web pages manipulate local AI agents into accessing sensitive files, emails or session credentials, an exploit linked in the report to agentic tools like Perplexity’s Comet AI.
Because all three attack methods operate through software already running in a browser, development setup or local AI agent, standard perimeter defences are often inadequate. Security controls that focus primarily on network boundaries may fail to detect the covert instructions or data access taking place.
Monitoring should follow the most active users
To address these risks effectively, Akamai recommends directing oversight, guidance and tailored training towards employees exhibiting the highest levels of AI usage. Focusing resources on the specific power users responsible for most interactive prompts addresses the vast majority of enterprise exposure highlighted in the study. Beyond user monitoring, organisations must restrict autonomous agents to the minimum access necessary and continuously track their actions when operating on behalf of staff.
Enforcing these strict access limits ensures that fewer internal files, corporate accounts and systems are exposed if an agent is manipulated or compromised. These measures provide a critical defence layer against emerging agentic threats.
The report forms part of Akamai’s State of the Internet security series, now in its 12th year. Its conclusions are drawn from threat activity observed across the vendor’s cybersecurity infrastructure, which processes a substantial proportion of global web traffic.







