AI Is Expanding the Enterprise Attack Surface
A new Akamai security report highlights the risks of shadow AI, browser extensions and autonomous agents operating beyond corporate controls
Enterprise AI adoption is creating a growing security problem: organizations increasingly do not know which AI tools employees are using, what data they are sharing with them, or what those tools can access.
That is the finding of a new Akamai State of the Internet (SOTI) Security report, Enterprise AI Usage Risk Report 2026, authored by Kimberly Gomez, Akamai’s director of security research. The report analyzes data from LayerX, the secure enterprise browser provider acquired by Akamai, to examine emerging risks around workplace AI.
One of the biggest concerns is shadow AI. According to the research, 47.11% of enterprise AI conversations take place through personal accounts rather than corporate-managed identities. More than 14% involve personal freemium AI subscriptions, potentially exposing business data to models used for public training.
AI use is also highly concentrated among power users. The top 5% generate at least 144 AI conversations, often exceeding 18 prompts, and are more likely to upload files, share business information and delegate tasks to autonomous agents.
The risks extend beyond AI platforms themselves. Nearly 75% of AI browser extensions request high or critical permissions, potentially giving them access to web content, credentials and enterprise applications. LayerX research also identified known vulnerabilities in some extensions.
The report highlights CursorJacking, in which a malicious browser extension can steal API keys used by the Cursor AI coding assistant, potentially allowing attackers to impersonate developers and compromise AI-driven development environments.
Autonomous agents introduce another threat because they can act without continuous human oversight. LayerX researchers demonstrated CometJacking, an indirect prompt injection technique targeting Perplexity’s Comet AI browser, in which malicious instructions embedded in a web page could manipulate the AI agent into accessing data and performing unauthorized actions.
The report argues that traditional security controls are not enough for this fragmented AI environment. Organizations need governance covering identities, data flows, browser and IDE extensions, and autonomous agents.
The challenge for security leaders, therefore, is not simply controlling AI use, but gaining visibility into how employees are actually using it — before those new workflows become new attack paths.