Enterprise adoption of AI tools has moved beyond experimentation into daily operations, but security measures have not kept up, according to Akamai’s latest research. The company’s State of the Internet report for 2026 identifies a growing gap between how organizations use AI and the ability of existing defenses to manage the risks. Rather than isolated trials, AI assistants now routinely draft code, analyze data, and perform tasks with minimal oversight, creating new pathways for data exposure and unauthorized access.
The shift has redefined the security challenge. Traditional controls focused on file transfers, downloads, or perimeter breaches are ill-equipped to monitor prompts, browser sessions, or cloud-based AI interactions. Security teams now face visibility gaps before they encounter malware or data leaks, as enterprise data increasingly flows through channels outside established governance frameworks.
Decentralized AI expands the attack surface
Akamai’s report argues that the problem stems less from AI models themselves than from the ecosystems built around them. Developers install browser extensions, employees connect personal AI accounts to corporate workflows, and autonomous agents access email, documents, and collaboration platforms. Each integration improves convenience but also introduces potential entry points for attackers.
The report highlights three emerging attack techniques observed in 2026:
- Vibe hacking: Manipulates local instruction files in development environments to influence coding assistants, causing them to generate insecure code or perform unintended actions without triggering security alerts.
- CursorJacking: Exploits browser extensions with broad permissions to capture API keys, source code, and conversation histories from AI coding tools. Extensions often bypass enterprise approval processes, receiving less scrutiny than traditional software despite their access to sensitive data.
- CometJacking: Uses indirect prompt injection via malicious instructions embedded in public websites to influence browser-based AI agents, potentially granting access to local files, emails, or session credentials.
These methods reflect a broader trend: attackers are targeting trusted automated systems rather than infrastructure directly. The report notes that nearly three-quarters of AI-related browser extensions request high or critical permissions, and over 16% contain publicly known vulnerabilities, making them attractive targets.
Governance and monitoring gaps
Akamai’s findings suggest that AI-related risks are not evenly distributed. A small subset of employees often accounts for the majority of enterprise AI interactions, meaning targeted monitoring of high-frequency users could yield greater security benefits than uniform controls. However, many organizations struggle to track unsanctioned AI services, which often enter workflows outside approved procurement channels.
For professionals: Security teams should expand single sign-on coverage to reduce shadow AI, monitor prompts and document uploads alongside traditional data loss prevention channels, and treat browser extensions as privileged software rather than trusted utilities. Least-privilege access and behavioral monitoring become critical as autonomous agents gain broader permissions.
The report also emphasizes the need for cloud providers and SaaS vendors to integrate AI governance, identity federation, and workload monitoring into their platforms. As AI systems become more autonomous, security controls must shift from protecting networks to governing interactions between users, applications, and data—a perimeter that is increasingly difficult to define.
Companies mentioned
Automated pipeline · SaaS
Synthesized from 1 industry feed on 6 Aug 2026. Passed independent editor verification (score 92/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No recent or in-pipeline article covers Akamai's findings on enterprise AI use evading security controls.
- Writing the article — Draft created article_id=399 slug=akamai-enterprise-ai-adoption-outpaces-security-controls
-
Editor review — Approved
- Score: 92/100
- Factual grounding: The draft states 'The report highlights three emerging attack techniques observed in 2026' but the source only says 'emerging during 2026' without confirming they were first observed in 2026. The specific calendar year for observation is unsupported.
- Style compliance: The standfirst ('Shadow AI and browser extensions create new attack vectors, report finds') is slightly editorialized. A more neutral phrasing would be 'Akamai report highlights security gaps as enterprise AI adoption outpaces controls.'
- No copied phrasing: The phrase 'autonomous agents gain access to email, documents, and collaboration platforms' closely mirrors the source's 'Autonomous agents gain access to email, documents, repositories, and collaboration platforms.' While the idea is paraphrased, the structure and key terms are nearly identical.
- Audience relevance and notability: The draft includes a 'For professionals' callout, but the source does not explicitly frame these recommendations as actionable for hosting/domains/DNS/email professionals. The relevance to this audience is implied (e.g., SSO, DLP) but could be more explicitly tied to their operational concerns.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Rejected library image #55: The candidate's alt text ('microsoft office 365 security warning browser') and URL slug ('a-glass-of-beer-wIBDrEv73xY') are unrelated to the article's topic of AI adoption, security risks, or enterprise vulnerabilities. The description does not match the required focus on AI tools, security controls, or attack vectors.
- Assigning hero image — Reused library image unsplash_id=mT7lXZPjk7U q=browser extension security risks picker=The candidate (index 12) depicts a red padlock on a black computer keyboard, which directly illustrates cybersecurity th
- Linking related stories — Linked 5 relations from 341 candidates
- Linking related stories — Linked 5 relations from 342 candidates
- Publishing — Published akamai-enterprise-ai-adoption-outpaces-security-controls
- Mastodon — Posted https://mstdn.social/@hostingpaper/117047065411160644




Discussion · coming soon
Be the first to join the thread when community discussion launches.