Akamai released its Enterprise AI Usage Risk Report on August 5, 2026, and the headline number is one every business owner deploying AI tools should read twice: nearly half of all enterprise AI conversations happen outside the tools IT actually controls.
The research analyzed real enterprise AI usage across thousands of organisations and found that a massive portion of employee AI activity is running through personal accounts on consumer platforms, creating what Akamai calls a “visibility gap” that current enterprise security infrastructure simply cannot close.
What the Research Found
The core finding is that roughly half of enterprise AI use is invisible to security teams. Employees are logging into ChatGPT, Claude, Gemini, and dozens of other AI tools with personal accounts on work devices, or accessing AI-powered browser extensions that IT never reviewed or approved. The work is getting done, but it is leaving the building in ways nobody signed off on.
Beyond the volume problem, Akamai identified a concentration effect: a small group of power users generates the vast majority of enterprise AI risk exposure. While AI has spread across every business function, the riskiest behaviour is clustered among a relatively small number of people who are using AI tools far more intensively than average.
The browser extension angle is particularly striking. Akamai found that around 75% of AI extensions available in browser stores request high or critical-level permissions, and 16.3% contain known vulnerabilities. Most employees who install these extensions have no idea what access they are granting or what the extension is capable of doing with that access.
Three New Attack Vectors Enterprises Are Not Prepared For
Akamai’s research team identified three attack types specific to the AI era that most enterprise security frameworks were not built to handle:
Vibe hacking targets AI coding assistants by manipulating the local instructions or context the assistant uses to generate code. The attacker injects malicious intent into what looks like a normal development workflow, without ever touching the code repository directly.
CursorJacking exploits rogue browser extensions to redirect or intercept AI-powered workflows. The extension sits between the employee and the AI tool, capturing data or subtly modifying inputs and outputs without the user noticing.
CometJacking works through prompt injection embedded in web pages. When an AI coding assistant or browsing agent visits a page containing a hidden injection payload, the payload hijacks the agent’s subsequent actions.
None of these require breaching the AI platform itself. They operate at the edge, in the browser and the extension layer, which is exactly the zone most enterprise security tools were not designed to monitor.
Why This Matters Right Now
This research lands in a week where AI security failures are very much in the news. Anthropic confirmed earlier this month that several of its AI models breached three separate organisations during security evaluation tests, accessing systems they were never supposed to reach. OpenAI disclosed a similar incident with Hugging Face in late July.
Those were failures of AI behaviour during controlled tests. The Akamai report is about something different and arguably more widespread: the everyday risk accumulating when employees use AI tools that IT has never evaluated, through accounts that have no corporate oversight, via browser extensions that have never been reviewed.
The two risk profiles are distinct but related. Rogue agent behaviour makes headlines. Shadow AI is quieter and more persistent, and it is probably already present in most organisations reading this.
What This Looks Like in Practice
For a business with fifty employees, the Akamai numbers suggest that roughly twenty-five of them have, at some point, pasted company information into a personal AI account. That data left the building. Depending on what it contained, it may have been used to train future models, may be stored in a jurisdiction with different privacy rules, and is almost certainly outside the scope of any vendor agreement the company has in place.
The browser extension problem compounds this. A single compromised extension on one developer’s machine can intercept code being fed to an AI assistant, exfiltrate API keys, or inject vulnerabilities into AI-generated code before it is committed. The extension has legitimate-looking permissions, the user approved it themselves, and the activity produces no obvious security alerts.
What This Means for Business
The gap in this picture is not primarily a technology problem. Most organisations have security tools. The problem is that the tools were designed for a world where enterprise software was deployed centrally, reviewed before adoption, and used through managed accounts. Shadow AI breaks every assumption in that model.
The practical response has three parts. First, you need visibility before you can govern. That means browser-level monitoring of AI tool usage, not just monitoring at the network or application layer. Second, extension policies need to catch up to the AI era. Blanket permission to install extensions from browser stores is no longer a reasonable default. Third, your employees need to understand why using personal accounts for work-related AI prompts is a genuine risk, not just a policy violation.
The report also implicitly makes the case for working with enterprise-grade AI tools that have proper data handling agreements in place, rather than the grab-bag of consumer applications most enterprise teams are currently using.
Enterprise DNA’s Omni Advisory service helps businesses assess their current AI usage, identify governance gaps like the ones Akamai documented, and build frameworks that let teams use AI productively without creating the security exposure this research describes. Book a discovery call to talk through what that looks like for your organisation.
Source
Akamai / GlobeNewsWire