STOCK TITAN

Akamai Report: Securing Agentic AI Requires Shift to Behavioral Governance

Akamai’s latest State of the Internet report warns CISOs that agentic AI demands new behavioral governance and edge-focused security controls.

(Moderate)
(Neutral)
Tags
AI

Akamai (AKAM) released a new State of the Internet Security report outlining how agentic AI is reshaping enterprise cyber risk.

The report for CISOs argues that security must shift from human identity management to behavioral governance over autonomous nonhuman agents. Findings include that more than 40% of enterprise users have AI-powered browser extensions, 25% of which alter permissions within 12 months, and over 6% of enterprise chatbot conversations contain sensitive data, with 47% occurring via unmonitored personal accounts. The report highlights a visibility gap around Model Context Protocol exposure, increased exploit discovery by AI models, and the “synthetic customer,” and recommends adaptive edge governance, tighter browser controls, GEO-focused brand protection, and matching AI autonomy to verifiability.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

Market Context

Pre-headline, AKAM was up 12.33% at $117.41; because that market data preceded publication, it does ...
Analysis

Pre-headline, AKAM was up 12.33% at $117.41; because that market data preceded publication, it does not measure investor reaction to the report’s findings on nonhuman identity and AI-related security exposure.

Key Figures

AI browser extension adoption: More than 40% Permission changes: 25% Sensitive chatbot conversations: More than 6% +3 more
AI browser extension adoption
More than 40%
Enterprise users
Permission changes
25%
AI-powered browser extensions within 12 months
Sensitive chatbot conversations
More than 6%
Enterprise AI chatbot conversations
Unmonitored personal accounts
47%
Enterprise AI chatbot interactions
Known CVE exposure
60% more likely
AI-powered browser extensions versus standard extensions
Rogue AI agent threat horizon
2030
Expected top cyberthreat horizon cited in the report

Previous AI Reports

4 past events · Latest: Sep 10
Same Type 4 events
  1. Sep 10

    AI governance collaboration

    24h Move
    -3.3%

    Expanded API defense integration with MuleSoft’s agent governance framework

  2. Aug 05

    AI security report

    24h Move
    -0.9%

    State of the Internet report detailed shadow AI and browser extension risks

  3. Jul 15

    AI security report

    24h Move
    -4.8%

    State of the Internet report examined AI bots and agentic commerce attacks

  4. Jun 15

    Agentic security framework

    24h Move
    +0.5%

    Framework connected identity, observability, trust, and edge security for AI interactions

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Key Terms

model context protocol, personally identifiable information, cves, generative engine optimization
4 terms
model context protocol technical
"The Model Context Protocol (MCP) visibility gap"
A model context protocol is a set of rules or guidelines that determine how a financial model interprets and applies information within a specific situation. It helps ensure consistent and accurate analysis by clarifying what data or assumptions are relevant in a given scenario. For investors, it provides clarity on how predictions or assessments are made, increasing confidence in decision-making.
personally identifiable information regulatory
"primarily personally identifiable information"
Personally identifiable information (PII) is any data that can directly or indirectly identify a single person — for example: full name, home address, national ID numbers, phone or email, financial account details, or unique biometric data. Investors care because mishandling or loss of PII can trigger regulatory fines, costly cleanup and lost customer trust; think of a data breach like losing the keys to many customers’ homes, which can hurt a company’s finances and stock value.
cves technical
"60% more likely to possess known CVEs"
CVEs (Common Vulnerabilities and Exposures) are unique ID numbers assigned to publicly known security flaws in software or hardware, like a catalog entry that describes a specific weak spot. For investors, CVEs matter because they signal potential risks to a company’s systems and customer data—similar to a product recall number that warns of problems requiring fixes, which can lead to costs, downtime, regulatory scrutiny, or reputational damage.
generative engine optimization technical
"include generative engine optimization (GEO) metrics"
Generative engine optimization is the process of improving a computer system that creates content—like text, images or code—so it produces more accurate, faster, and less costly results. For investors, it matters because better optimization can boost a product’s quality and speed to market, lower computing costs, and create a competitive edge similar to tuning a car engine to get more miles per gallon and smoother performance.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Key takeaways

  • Nonhuman identities: Enterprise risk is shifting from human identity management to governing autonomous nonhuman entities.
  • Browser as the unprotected workspace: More than 40% of enterprise users have installed AI-powered browser extensions, with 25% of these extensions altering permissions within 12 months.
  • Chatbot interaction: More than 6% of chatbot conversations contain sensitive information.

CAMBRIDGE, Mass., Sept. 22, 2026 (GLOBE NEWSWIRE) --

As organizations deploy agentic AI to execute tasks across APIs and systems, enterprises face a fundamental shift in risk. Akamai (NASDAQ: AKAM) today released its latest State of the Internet (SOTI) Security report focused on emerging AI challenges. Targeted to a CISO audience, Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape explains that securing modern business has evolved from solely identity and access management for people into a challenge of behavioral governance over nonhuman entities.

The report highlights two critical challenges: the difficulty of setting guardrails for autonomous agents, and the speed at which AI models discover vulnerabilities — often outpacing human patch cycles.

Key findings from the SOTI report

  • The Model Context Protocol (MCP) visibility gap: Despite the fact that MCP (the protocol that allows AI agents to interact with multiple software systems) enables AI models to execute autonomous multisystem actions, MCP exposure ranks last among current CISO security priorities. This reveals a critical visibility gap, even as security leaders expect rogue AI agents to become a top cyberthreat by 2030.
  • Chatbot data leaks: More than 6% of enterprise AI chatbot conversations contain sensitive corporate data — primarily personally identifiable information — with 47% of interactions occurring via unmonitored personal accounts.
  • Exploit acceleration: Frontier AI initiatives demonstrate that models can rapidly discover and chain system weaknesses, rendering reactive patching insufficient and mandating real-time edge mitigation.
  • Browser as the unprotected workspace: More than 40% of enterprise users have installed AI-powered browser extensions, with 25% of these extensions altering permissions within 12 months. These tools are 60% more likely to possess known CVEs than standard extensions.
  • Rise of the synthetic customer: As AI agents replace traditional web traffic to drive brand discovery, CISOs must expand protection beyond malware to include generative engine optimization (GEO) metrics: citations, accuracy, sentiment, and bot management.

“AI presents an ‘everything, everywhere, all at once’ moment for the security ecosystem as a whole,” said Boaz Gelbord, Chief Security Officer at Akamai. “You have this triple threat: First, internal usage of AI across the organization, whether that’s AI generated code or leveraging AI productivity tools. Second, you have the integration of AI directly into customer-facing products and cloud workloads, which reshapes your operational risk profile. Third, you have AI-driven attacks targeting the enterprise. Security programs need to adapt to this rapidly evolving reality, and there’s a lot of pressure in the system due to the unprecedented speed of these changes. This is going to be a central topic for boards, customers, and regulators in the foreseeable future.”

“The rise of the agentic web marks a fundamental shift in how business value and operational logic are created,” said Steve Winterfeld, Advisory CISO of Akamai. “As autonomous AI moves from answering queries to executing multistep business strategies, security leadership must evolve alongside it.”

Strategic recommendations for security leaders

To navigate the agentic era, Akamai outlines four core pillars for CISOs in the report:

  1. Shift to adaptive edge governance: Deploy edge native runtime protections, API filters, and isolation mechanisms to neutralize vulnerabilities immediately while back-end patching takes place.
  2. Lock down the browser edge: Establish visibility and behavioral controls inside the browser to secure workforce adoption of unmanaged AI extensions and web-hosted models.
  3. Protect brand authority in a zero-click economy: Implement GEO strategies and machine-readable data layers at the network edge to prevent AI crawlers and synthetic shoppers from hallucinating or misrepresenting corporate brand data.
  4. Match autonomy to verifiability: Grant operational autonomy to AI agents based on how easily their actions can be verified and how reversible a potential failure is, maintaining human-in-the-loop controls for high-stakes actions.

Now in their 12th year, Akamai’s SOTI reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai’s cybersecurity infrastructure, which handles a significant portion of global web traffic.

About Akamai
Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow Akamai Technologies on X and LinkedIn.

Contacts
Akamai Media Relations
akamaipr@akamai.com

Akamai Investor Relations
invrel@akamai.com


FAQ

AI-generated questions and answers. How Rhea-AI works. Not financial advice.

Who is the primary audience for Akamai’s new State of the Internet Security report?

The report, titled “Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape”, is targeted to a CISO audience, focusing on how security leadership should adapt to autonomous AI agents, new browser risks, and changing threat dynamics.

What is the Model Context Protocol (MCP) and why does the report call it a visibility gap?

The Model Context Protocol (MCP) is described as the protocol that allows AI agents to interact with multiple software systems and execute autonomous multisystem actions. The report notes that MCP exposure ranks last among current CISO security priorities, indicating a visibility gap even as security leaders expect rogue AI agents to become a top cyberthreat by 2030.

What strategic pillars does Akamai recommend for CISOs in the agentic AI era?

Akamai outlines four pillars: shift to adaptive edge governance with edge runtime protections and API filters; lock down the browser edge with visibility and behavioral controls for AI extensions and web-hosted models; protect brand authority in a zero-click economy using GEO strategies and machine-readable data at the network edge; and match autonomy to verifiability by granting AI agents operational freedom based on how easily actions can be checked and reversed, keeping human-in-the-loop for high-stakes tasks.

On what data are Akamai’s SOTI insights about AI and security based?

The State of the Internet reports draw insights from attacks observed across Akamai’s cybersecurity infrastructure, which the company states handles a significant portion of global web traffic. This 2026 report continues that 12-year series, focusing the collected data on emerging AI-related security trends.

Keep reading