Akamai Report: Securing Agentic AI Requires Shift to Behavioral Governance
Akamai’s latest State of the Internet report warns CISOs that agentic AI demands new behavioral governance and edge-focused security controls.
Rhea-AI Summary
Akamai (AKAM) released a new State of the Internet Security report outlining how agentic AI is reshaping enterprise cyber risk.
The report for CISOs argues that security must shift from human identity management to behavioral governance over autonomous nonhuman agents. Findings include that more than 40% of enterprise users have AI-powered browser extensions, 25% of which alter permissions within 12 months, and over 6% of enterprise chatbot conversations contain sensitive data, with 47% occurring via unmonitored personal accounts. The report highlights a visibility gap around Model Context Protocol exposure, increased exploit discovery by AI models, and the “synthetic customer,” and recommends adaptive edge governance, tighter browser controls, GEO-focused brand protection, and matching AI autonomy to verifiability.
Positive
- None.
Negative
- None.
Key Figures
- AI browser extension adoption
- More than 40%
- Enterprise users
- Permission changes
- 25%
- AI-powered browser extensions within 12 months
- Sensitive chatbot conversations
- More than 6%
- Enterprise AI chatbot conversations
- Unmonitored personal accounts
- 47%
- Enterprise AI chatbot interactions
- Known CVE exposure
- 60% more likely
- AI-powered browser extensions versus standard extensions
- Rogue AI agent threat horizon
- 2030
- Expected top cyberthreat horizon cited in the report
Previous AI Reports
-
Expanded API defense integration with MuleSoft’s agent governance framework
-
State of the Internet report detailed shadow AI and browser extension risks
-
State of the Internet report examined AI bots and agentic commerce attacks
-
Framework connected identity, observability, trust, and edge security for AI interactions
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Key Terms
model context protocol technical
personally identifiable information regulatory
cves technical
generative engine optimization technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
Key takeaways
- Nonhuman identities: Enterprise risk is shifting from human identity management to governing autonomous nonhuman entities.
- Browser as the unprotected workspace: More than
40% of enterprise users have installed AI-powered browser extensions, with25% of these extensions altering permissions within 12 months. - Chatbot interaction: More than
6% of chatbot conversations contain sensitive information.
CAMBRIDGE, Mass., Sept. 22, 2026 (GLOBE NEWSWIRE) --
As organizations deploy agentic AI to execute tasks across APIs and systems, enterprises face a fundamental shift in risk. Akamai (NASDAQ: AKAM) today released its latest State of the Internet (SOTI) Security report focused on emerging AI challenges. Targeted to a CISO audience, Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape explains that securing modern business has evolved from solely identity and access management for people into a challenge of behavioral governance over nonhuman entities.
The report highlights two critical challenges: the difficulty of setting guardrails for autonomous agents, and the speed at which AI models discover vulnerabilities — often outpacing human patch cycles.
Key findings from the SOTI report
- The Model Context Protocol (MCP) visibility gap: Despite the fact that MCP (the protocol that allows AI agents to interact with multiple software systems) enables AI models to execute autonomous multisystem actions, MCP exposure ranks last among current CISO security priorities. This reveals a critical visibility gap, even as security leaders expect rogue AI agents to become a top cyberthreat by 2030.
- Chatbot data leaks: More than
6% of enterprise AI chatbot conversations contain sensitive corporate data — primarily personally identifiable information — with47% of interactions occurring via unmonitored personal accounts. - Exploit acceleration: Frontier AI initiatives demonstrate that models can rapidly discover and chain system weaknesses, rendering reactive patching insufficient and mandating real-time edge mitigation.
- Browser as the unprotected workspace: More than
40% of enterprise users have installed AI-powered browser extensions, with25% of these extensions altering permissions within 12 months. These tools are60% more likely to possess known CVEs than standard extensions. - Rise of the synthetic customer: As AI agents replace traditional web traffic to drive brand discovery, CISOs must expand protection beyond malware to include generative engine optimization (GEO) metrics: citations, accuracy, sentiment, and bot management.
“AI presents an ‘everything, everywhere, all at once’ moment for the security ecosystem as a whole,” said Boaz Gelbord, Chief Security Officer at Akamai. “You have this triple threat: First, internal usage of AI across the organization, whether that’s AI generated code or leveraging AI productivity tools. Second, you have the integration of AI directly into customer-facing products and cloud workloads, which reshapes your operational risk profile. Third, you have AI-driven attacks targeting the enterprise. Security programs need to adapt to this rapidly evolving reality, and there’s a lot of pressure in the system due to the unprecedented speed of these changes. This is going to be a central topic for boards, customers, and regulators in the foreseeable future.”
“The rise of the agentic web marks a fundamental shift in how business value and operational logic are created,” said Steve Winterfeld, Advisory CISO of Akamai. “As autonomous AI moves from answering queries to executing multistep business strategies, security leadership must evolve alongside it.”
Strategic recommendations for security leaders
To navigate the agentic era, Akamai outlines four core pillars for CISOs in the report:
- Shift to adaptive edge governance: Deploy edge native runtime protections, API filters, and isolation mechanisms to neutralize vulnerabilities immediately while back-end patching takes place.
- Lock down the browser edge: Establish visibility and behavioral controls inside the browser to secure workforce adoption of unmanaged AI extensions and web-hosted models.
- Protect brand authority in a zero-click economy: Implement GEO strategies and machine-readable data layers at the network edge to prevent AI crawlers and synthetic shoppers from hallucinating or misrepresenting corporate brand data.
- Match autonomy to verifiability: Grant operational autonomy to AI agents based on how easily their actions can be verified and how reversible a potential failure is, maintaining human-in-the-loop controls for high-stakes actions.
Now in their 12th year, Akamai’s SOTI reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai’s cybersecurity infrastructure, which handles a significant portion of global web traffic.
About Akamai
Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow Akamai Technologies on X and LinkedIn.
Contacts
Akamai Media Relations
akamaipr@akamai.com
Akamai Investor Relations
invrel@akamai.com
FAQ
AI-generated questions and answers. How Rhea-AI works. Not financial advice.
Who is the primary audience for Akamai’s new State of the Internet Security report?
The report, titled “Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape”, is targeted to a CISO audience, focusing on how security leadership should adapt to autonomous AI agents, new browser risks, and changing threat dynamics.
What is the Model Context Protocol (MCP) and why does the report call it a visibility gap?
The Model Context Protocol (MCP) is described as the protocol that allows AI agents to interact with multiple software systems and execute autonomous multisystem actions. The report notes that MCP exposure ranks last among current CISO security priorities, indicating a visibility gap even as security leaders expect rogue AI agents to become a top cyberthreat by 2030.
What strategic pillars does Akamai recommend for CISOs in the agentic AI era?
Akamai outlines four pillars: shift to adaptive edge governance with edge runtime protections and API filters; lock down the browser edge with visibility and behavioral controls for AI extensions and web-hosted models; protect brand authority in a zero-click economy using GEO strategies and machine-readable data at the network edge; and match autonomy to verifiability by granting AI agents operational freedom based on how easily actions can be checked and reversed, keeping human-in-the-loop for high-stakes tasks.
On what data are Akamai’s SOTI insights about AI and security based?
The State of the Internet reports draw insights from attacks observed across Akamai’s cybersecurity infrastructure, which the company states handles a significant portion of global web traffic. This 2026 report continues that 12-year series, focusing the collected data on emerging AI-related security trends.