Press Releases August 5, 2026 06:30 AM

Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive “Shadow AI” Visibility Gaps

Akamai highlights rising 'Shadow AI' risks and emerging AI-native cyberattack vectors in new 2026 Enterprise AI Usage Risk Report

By Maya Rios
Share
Twitter Reddit Facebook LinkedIn
AKAM

Akamai Technologies releases its 2026 State of the Internet Security report revealing significant enterprise cybersecurity risks from decentralized 'shadow AI' usage and novel AI-native attack methods that evade traditional defenses. The report urges CISOs to adopt new mitigation strategies targeting AI power users, managing shadow AI, and securing autonomous AI agents to protect critical corporate data.

Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive “Shadow AI” Visibility Gaps
AKAM
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Nearly half of enterprise AI usage bypasses corporate security, creating large ‘shadow AI’ visibility gaps.
  • Researchers identified three novel AI-native attack methods in 2026 – Vibe hacking, CursorJacking, and CometJacking – that circumvent perimeter defenses.
  • Akamai proposes five core strategies for CISOs to mitigate AI-related risks, including targeting AI power users and enforcing strict security on browser extensions and autonomous AI agents.

Key takeaways

  • The rise of the “AI power user”: Although AI has expanded across every business function, risk is heavily concentrated. A highly active group of power users are driving the vast majority of enterprise AI exposure.
  • The dominance of “shadow AI”: Security teams are suffering from a severe visibility gap, focusing heavily on a few approved platforms while a massive “long tail” of unmanaged apps runs silently beneath the surface.
  • The emergence of AI-native attack vectors: The new report details three novel threat methodologies discovered by researchers in 2026 that bypass traditional perimeter defenses entirely.

CAMBRIDGE, Mass., Aug. 05, 2026 (GLOBE NEWSWIRE) --

“Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented…”
“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,”
“Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented…”
“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,”
“Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented…”

Akamai (NASDAQ: AKAM) released a new State of the Internet (SOTI) security report today that details how rogue browser extensions and vulnerable autonomous agents are actively expanding the enterprise threat surface. The Enterprise AI Usage Risk Report 2026 reveals how decentralized shadow AI, highly active AI power users, and silent browser extensions are exposing critical corporate assets to entirely new classes of cyber risk.

The report tracks a profound shift in corporate AI adoption. What began in early 2025 as cautious experimentation has solidified into a structural mandate. However, this rapid integration has outpaced traditional security guardrails.

“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,” said Or Eshed, Vice President, Enterprise Security Product and Engineering of Akamai. “Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented across millions of fluid prompts, unmanaged personal accounts, and autonomous AI agents. Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level.”

Emerging AI-native attack vectors

The report details three novel threat methodologies discovered by researchers in 2026 that bypass traditional perimeter defenses entirely.

  1. Vibe hacking: Attackers covertly manipulate local markdown instruction files within a developer’s environment. This subtle modification tricks frontier coding assistants into generating insecure outputs or executing unauthorized actions — mimicking a developer’s normal workflow.
  2. CursorJacking: Rogue browser extensions exploit broad permissions to silently harvest API keys, proprietary codebases, and conversational history directly from the browser environment. This is a high-impact exploit targeting popular AI coding assistants (like Cursor).
  3. CometJacking: By embedding malicious instructions on a public web page, attackers use indirect prompt injection to manipulate the user’s local AI agent. The compromised agent can then exfiltrate local files, emails, and session credentials without the user’s knowledge. This threat targets agentic browsers like Perplexity’s Comet AI.

The 2026 CISO roadmap to secure AI

To capture the economic benefits of AI without exposing critical data, Akamai’s report outlines five core mitigation strategies for modern CISOs.

  1. Target AI power users: Target telemetry, monitoring, and tailored coaching toward the 5% of high-risk employees who are driving the majority of interactive AI prompts.
  2. Eliminate shadow AI: Force single sign-on (SSO) federation across all platforms and continuously discover the long tail of niche AI software as a service (SaaS) tools.
  3. Inspect the interaction layer: Transition from static DLP to real-time, contextual analysis of prompts, copy/paste buffers, and document uploads.
  4. Vet browser and IDE extensions: Treat extensions as highly privileged software. Almost 75% of AI extensions demand high or critical permissions, and 16.3% contain known CVEs.
  5. Secure AI agents: Establish strict, least-privilege boundaries and behavioral monitoring for autonomous AI agents that act on behalf of employees.

Now in their 12th year, Akamai’s SOTI reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai’s cybersecurity infrastructure, which handles a significant portion of global web traffic.

About Akamai

Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow Akamai Technologies on X and LinkedIn.

Contacts
Akamai Media Relations
[email protected]

Akamai Investor Relations
[email protected]


Risks

  • Unmanaged 'shadow AI' tools exponentially increase enterprise vulnerability to data breaches and intellectual property theft.
  • Highly privileged AI browser extensions with known vulnerabilities can be exploited to harvest sensitive data.
  • Emerging AI-native cyberattack vectors bypass traditional security tools, increasing risk in sectors reliant on cloud computing and enterprise AI integration.

More from Press Releases

Lithium Argentina Announces $220 Million of New Debt Facilities Closed at Cauchari-Olaroz Aug 5, 2026 Stardust Power Announces Offtake Agreement Aug 5, 2026 Bioventus Reports Second Quarter Financial Results Aug 5, 2026 Medline Reports Second Quarter and First Six Months 2026 Results Aug 5, 2026 BriaCell Receives FDA Clearance to Initiate Bria-PROS+™ Clinical Study in Prostate Cancer Aug 5, 2026