CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Shadow AI Power Users: The 5% Creating Outsized Enterprise Security Risk

August 24, 2026

New research from Akamai reveals that a small fraction of enterprise employees—the top 5% of AI power users—are creating a disproportionate security risk by expanding shadow AI usage, increasing data leakage opportunities, and introducing autonomous AI agents that operate outside established guardrails.

According to Akamai’s State of the Internet: Enterprise AI Usage Risk Report 2026, these power users interact with AI models at 12 times the rate of the bottom 50% of the workforce. While the average employee conversation lasts about five prompts, power users routinely engage in conversations of 18 prompts or more, indicating that AI has become an embedded collaborator in critical business operations.

The report highlights a stark contrast between enterprise-managed and personal AI accounts. Nearly half (47.11%) of all enterprise AI conversations occur through personal identities rather than corporate-managed accounts. Gemini Enterprise (98.15%) and Microsoft Copilot M365 (90.55%) keep most interactions inside corporate identity systems, while DeepSeek (99.8%), Microsoft Copilot Standard (63.92%), ChatGPT (61.36%), and Claude (61.09%) are overwhelmingly dominated by personal logins. Additionally, 14.4% of enterprise AI conversations occurred via corporate email addresses linked to personal freemium subscriptions, potentially exposing sensitive data to public model training.

Browser and IDE extensions represent another growing blind spot. Akamai found that 17.7% of employees at midsize enterprises use at least one AI extension, compared with 9.53% at larger organizations. Nearly 75% of these extensions request high or critical permissions, and 16.31% contain known CVE vulnerabilities—significantly higher than the 10.80% for browser extensions overall.

The report also identifies new attack vectors, including Vibe Hacking (manipulating local instruction files to alter AI coding assistants), CursorJacking (rogue extensions harvesting API keys and source code), and CometJacking (indirect prompt injection to exfiltrate local files). Akamai’s CISO checklist recommends establishing continuous visibility, eliminating shadow AI, deploying contextual AI DLP, auditing extensions and permissions, and governing AI agents as privileged identities.

CVEs: CVE-2026-58231

Companies: Akamai

Products: Gemini Enterprise, Microsoft Copilot M365, DeepSeek, Microsoft Copilot Standard, ChatGPT, Claude