Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive “Shadow AI” Visibility Gaps
New Report Reveals the Rise of Shadow AI, High-Risk Power Users, and Emerging AI-Native Attack Vectors Threatening Enterprise Security.

Akamai (NASDAQ: AKAM) released a new State of the Internet (SOTI) security report today that details how rogue browser extensions and vulnerable autonomous agents are actively expanding the enterprise threat surface. The Enterprise AI Usage Risk Report 2026 reveals how decentralised shadow AI, highly active AI power users, and silent browser extensions are exposing critical corporate assets to entirely new classes of cyber risk.
The report tracks a profound shift in corporate AI adoption. What began in early 2025 as cautious experimentation has solidified into a structural mandate. However, this rapid integration has outpaced traditional security guardrails.
“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,” said Or Eshed, Vice President, Enterprise Security Product and Engineering, Akamai. “Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented across millions of fluid prompts, unmanaged personal accounts, and autonomous AI agents. Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level.”
Emerging AI-Native Attack Vectors
The report details three novel threat methodologies discovered by researchers in 2026 that bypass traditional perimeter defences entirely.
- Vibe Hacking: Attackers covertly manipulate local markdown instruction files within a developer’s environment. This subtle modification tricks frontier coding assistants into generating insecure outputs or executing unauthorised actions, mimicking a developer’s normal workflow.
- CursorJacking: Rogue browser extensions exploit broad permissions to silently harvest API keys, proprietary codebases, and conversational history directly from the browser environment. This is a high-impact exploit targeting popular AI coding assistants (such as Cursor).
- CometJacking: By embedding malicious instructions on a public web page, attackers use indirect prompt injection to manipulate the user’s local AI agent. The compromised agent can then exfiltrate local files, emails, and session credentials without the user’s knowledge. This threat targets agentic browsers such as Perplexity’s Comet AI.
The 2026 CISO Roadmap to Secure AI
To capture the economic benefits of AI without exposing critical data, Akamai’s report outlines five core mitigation strategies for modern CISOs.
- Target AI Power Users: Target telemetry, monitoring, and tailored coaching towards the 5% of high-risk employees who are driving the majority of interactive AI prompts.
- Eliminate Shadow AI: Force single sign-on (SSO) federation across all platforms and continuously discover the long tail of niche AI software-as-a-service (SaaS) tools.
- Inspect the Interaction Layer: Transition from static DLP to real-time, contextual analysis of prompts, copy-and-paste buffers, and document uploads.
- Vet Browser and IDE Extensions: Treat extensions as highly privileged software. Almost 75% of AI extensions demand high or critical permissions, and 16.3% contain known CVEs.
- Secure AI Agents: Establish strict least-privilege boundaries and behavioural monitoring for autonomous AI agents that act on behalf of employees.
Now in its 12th year, Akamai’s SOTI report continues to offer critical insights into cybersecurity trends and web performance, drawn from attacks observed across Akamai’s cybersecurity infrastructure, which handles a significant portion of global web traffic.



