STOCK TITAN

Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive “Shadow AI” Visibility Gaps

(Neutral)
(Neutral)
Tags
AI

Akamai (NASDAQ: AKAM) released its 2026 State of the Internet security report, the Enterprise AI Usage Risk Report 2026, highlighting how decentralized “shadow AI,” highly active AI power users, and rogue browser extensions are expanding enterprise cyber risk by bypassing traditional perimeter defenses.

The report introduces three AI-native attack vectors—Vibe hacking, CursorJacking, and CometJacking—and notes that almost 75% of AI extensions request high or critical permissions, while 16.3% contain known vulnerabilities. Akamai outlines a five-point CISO roadmap focused on AI power users, eliminating shadow AI, inspecting the interaction layer, vetting extensions, and securing autonomous AI agents.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

News Explained

The report adds a scale point: nearly half of enterprise AI use bypasses corporate security, quantifying the shadow-AI visibility gap. As a research release, it changes Akamai’s disclosed risk assessment, not existing holders’ ownership, liquidity, or contractual position.

News Market Reaction – AKAM

-0.88% 1.6x vol
52 alerts
-0.88% Session close to close
+17.2% Peak Tracked
-7.6% Trough Tracked
$19.96B Market Cap
1.6x Rel. Volume

In the Aug 5 session, AKAM declined 0.88%, reflecting a mild negative market reaction. Argus tracked a peak move of +17.2% during that session. Argus tracked a trough of -7.6% from its starting point during tracking. Our momentum scanner triggered 52 alerts that day, indicating high trading interest and price volatility. Trading volume was above average at 1.6x the daily average, suggesting increased trading activity.

Data tracked by StockTitan Argus on the day of publication.

Market Context

Recent insider filings recorded 5,643 shares sold and no shares bought. That ownership context adds ...
Analysis

Recent insider filings recorded 5,643 shares sold and no shares bought. That ownership context adds a risk lens to the report’s security findings; future disclosures can be watched for measurable commercial or financial terms.

Key Figures

AI threat methodologies: 3 methodologies High-risk employees: 5% Core mitigation strategies: 5 strategies +3 more
6 metrics
AI threat methodologies 3 methodologies Discovered by researchers in 2026
High-risk employees 5% Employees driving the majority of interactive AI prompts
Core mitigation strategies 5 strategies 2026 CISO roadmap to secure AI
High or critical extension permissions Almost 75% AI extensions
Extensions with known CVEs 16.3% AI extensions
SOTI report history 12th year Akamai SOTI reports

Previous AI Reports

5 past events · Latest: Jul 15 (Positive)
Same Type Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Jul 15 AI security research Positive -4.8% Commerce-focused SOTI report detailed AI bot attacks, API incidents, and agentic fraud risks.
Jun 15 AI security framework Positive +0.5% Akamai introduced a unified framework for securing AI-driven interactions and commerce.
Jun 02 AI infrastructure collaboration Positive +4.1% NVIDIA collaboration embedded Akamai segmentation into AI-factory infrastructure.
May 19 AI product launch Positive -6.3% AI Brand Presence launched to optimize content for AI search and agentic traffic.
Apr 28 AI security survey Positive -0.5% Survey reported rising API incidents, AI targeting, and gaps in sensitive-data visibility.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

AI-tagged announcements produced mixed reactions, with three of five diverging from positive news sentiment and an average move of -1.4%.

Key Terms

shadow ai, single sign-on (SSO), indirect prompt injection, cves, +1 more
5 terms
shadow ai technical
"The dominance of “shadow AI”: Security teams are suffering from a severe visibility gap"
Shadow AI describes employees using artificial intelligence tools or services without formal approval, oversight, or integration into official systems — for example, personal subscriptions, free web apps, or browser add-ons. For investors this matters because these hidden tools can expose sensitive data, create compliance or legal problems, produce unreliable results, and lead to unexpected costs or reputational damage, much like an unapproved gadget in a factory that creates safety and billing surprises.
single sign-on (SSO) technical
"Force single sign-on (SSO) federation across all platforms"
Single sign-on (SSO) is a login system that lets a user access multiple online services with one set of credentials, like using a single key to open several doors. For investors, SSO matters because it can lower a company’s support costs, improve employee productivity and customer convenience, but it also concentrates access risk—a single compromise can affect many systems and therefore has potential operational and reputational impact.
indirect prompt injection technical
"attackers use indirect prompt injection to manipulate the user’s local AI agent"
An indirect prompt injection is a covert way to trick an AI system by hiding instructions in sources the AI reads—like documents, web pages, or data feeds—rather than in the direct user query. For investors, it matters because automated tools that summarize filings, score sentiment, or generate trading signals can be misled into producing false or biased outputs, creating risks for bad investment decisions, compliance failures, or market-moving misinformation.
cves technical
"16.3% contain known CVEs"
CVEs (Common Vulnerabilities and Exposures) are unique ID numbers assigned to publicly known security flaws in software or hardware, like a catalog entry that describes a specific weak spot. For investors, CVEs matter because they signal potential risks to a company’s systems and customer data—similar to a product recall number that warns of problems requiring fixes, which can lead to costs, downtime, regulatory scrutiny, or reputational damage.
least-privilege technical
"Establish strict, least-privilege boundaries"
A security principle that gives users, programs, and systems the minimum levels of access—or permissions—they need to do their jobs and nothing more. Like giving someone a key that opens only the room they need, least-privilege limits damage from mistakes, bugs, or hacked accounts, so it affects operational risk, compliance exposure, and potential costs tied to data breaches or system failures.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Key takeaways

  • The rise of the “AI power user”: Although AI has expanded across every business function, risk is heavily concentrated. A highly active group of power users are driving the vast majority of enterprise AI exposure.
  • The dominance of “shadow AI”: Security teams are suffering from a severe visibility gap, focusing heavily on a few approved platforms while a massive “long tail” of unmanaged apps runs silently beneath the surface.
  • The emergence of AI-native attack vectors: The new report details three novel threat methodologies discovered by researchers in 2026 that bypass traditional perimeter defenses entirely.

CAMBRIDGE, Mass., Aug. 05, 2026 (GLOBE NEWSWIRE) --

Akamai (NASDAQ: AKAM) released a new State of the Internet (SOTI) security report today that details how rogue browser extensions and vulnerable autonomous agents are actively expanding the enterprise threat surface. The Enterprise AI Usage Risk Report 2026 reveals how decentralized shadow AI, highly active AI power users, and silent browser extensions are exposing critical corporate assets to entirely new classes of cyber risk.

The report tracks a profound shift in corporate AI adoption. What began in early 2025 as cautious experimentation has solidified into a structural mandate. However, this rapid integration has outpaced traditional security guardrails.

“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,” said Or Eshed, Vice President, Enterprise Security Product and Engineering of Akamai. “Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented across millions of fluid prompts, unmanaged personal accounts, and autonomous AI agents. Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level.”

Emerging AI-native attack vectors

The report details three novel threat methodologies discovered by researchers in 2026 that bypass traditional perimeter defenses entirely.

  1. Vibe hacking: Attackers covertly manipulate local markdown instruction files within a developer’s environment. This subtle modification tricks frontier coding assistants into generating insecure outputs or executing unauthorized actions — mimicking a developer’s normal workflow.
  2. CursorJacking: Rogue browser extensions exploit broad permissions to silently harvest API keys, proprietary codebases, and conversational history directly from the browser environment. This is a high-impact exploit targeting popular AI coding assistants (like Cursor).
  3. CometJacking: By embedding malicious instructions on a public web page, attackers use indirect prompt injection to manipulate the user’s local AI agent. The compromised agent can then exfiltrate local files, emails, and session credentials without the user’s knowledge. This threat targets agentic browsers like Perplexity’s Comet AI.

The 2026 CISO roadmap to secure AI

To capture the economic benefits of AI without exposing critical data, Akamai’s report outlines five core mitigation strategies for modern CISOs.

  1. Target AI power users: Target telemetry, monitoring, and tailored coaching toward the 5% of high-risk employees who are driving the majority of interactive AI prompts.
  2. Eliminate shadow AI: Force single sign-on (SSO) federation across all platforms and continuously discover the long tail of niche AI software as a service (SaaS) tools.
  3. Inspect the interaction layer: Transition from static DLP to real-time, contextual analysis of prompts, copy/paste buffers, and document uploads.
  4. Vet browser and IDE extensions: Treat extensions as highly privileged software. Almost 75% of AI extensions demand high or critical permissions, and 16.3% contain known CVEs.
  5. Secure AI agents: Establish strict, least-privilege boundaries and behavioral monitoring for autonomous AI agents that act on behalf of employees.

Now in their 12th year, Akamai’s SOTI reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai’s cybersecurity infrastructure, which handles a significant portion of global web traffic.

About Akamai

Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow Akamai Technologies on X and LinkedIn.

Contacts
Akamai Media Relations
akamaipr@akamai.com

Akamai Investor Relations
invrel@akamai.com


FAQ

What is Akamai’s 2026 Enterprise AI Usage Risk Report about for AKAM investors?

Akamai’s 2026 Enterprise AI Usage Risk Report analyzes how shadow AI, AI power users, and rogue extensions increase enterprise cyber risk. According to Akamai, these trends expand the threat surface and bypass traditional defenses, driving demand for modern AI-aware security controls and governance approaches.

What does Akamai mean by “shadow AI” in its 2026 report on AKAM?

Shadow AI refers to unmanaged AI tools and apps used outside corporate security oversight. According to Akamai, security teams often focus on a few approved platforms while a long tail of unmonitored AI SaaS and extensions silently handles sensitive data, creating major visibility gaps.

Which new AI-native attack vectors did Akamai identify in 2026 for AKAM security clients?

Akamai identified three 2026 AI-native threats: Vibe hacking, CursorJacking, and CometJacking. According to Akamai, these methods manipulate local instructions, abuse rogue extensions, or inject prompts via web pages to hijack coding assistants and agentic browsers, exfiltrating files, code, and credentials beyond traditional perimeters.

What statistics did Akamai report on risky AI browser and IDE extensions in 2026?

Akamai reported that almost 75% of AI extensions seek high or critical permissions and 16.3% contain known vulnerabilities. According to Akamai, this concentration of privilege and exposure makes extension vetting and governance essential for securing AI-assisted developer and browser environments.

What roadmap does Akamai recommend for CISOs to secure enterprise AI in 2026?

Akamai recommends five actions: focus on AI power users, eliminate shadow AI via SSO, inspect the interaction layer, vet extensions, and secure AI agents. According to Akamai, this roadmap helps capture AI’s economic benefits while limiting data exposure and novel AI-native attack paths.

How are AI power users impacting enterprise risk according to Akamai’s 2026 AKAM report?

AI power users are a small subset of employees generating most interactive AI prompts and risk. According to Akamai, targeting telemetry, monitoring, and tailored coaching at roughly 5% high-risk users can meaningfully reduce exposure from sensitive prompts, unmanaged accounts, and autonomous AI agents.