By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechgoonduTechgoonduTechgoondu
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Search
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Reading: Nearly half of enterprise AI use bypasses corporate security: Akamai report
Share
Font ResizerAa
TechgoonduTechgoondu
Font ResizerAa
  • Audio-visual
  • Enterprise
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
  • PC
  • Telecom
Search
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Follow US
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Techgoondu > Blog > Cybersecurity > Nearly half of enterprise AI use bypasses corporate security: Akamai report
CybersecurityEnterprise

Nearly half of enterprise AI use bypasses corporate security: Akamai report

Ai Lei Tao
Last updated: August 12, 2026 at 9:21 AM
Ai Lei Tao
Published: August 12, 2026
5 Min Read

Companies are facing new AI-related cybersecurity risks as employees are using many AI tools, as well as rogue browser extensions and vulnerable autonomous agents that have exposed organisations to new types of cyberattacks, according to an Akamai report.

While AI use has grown across business functions, it revealed, much of the risk is concentrated among a small group of highly active “AI power users” who account for a large share of enterprise AI exposure.

Nearly half or 47.11 per cent of all enterprise AI conversations occur via personal identities, instead of corporate-managed accounts (52.89 per cent).

This “shadow AI” is activity that has not been approved, monitored or audited by IT, security, or compliance teams, according to Akamai, which provides content delivery and security services to businesses.

PHOTO: Immo Wegmann on Unsplash

Its report also found that corporate AI adoption has shifted sharply since early 2025, moving from cautious experimentation to becoming a structural part of business operations. However, Akamai warned that this integration has outpaced traditional security controls.

“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,” said Or Eshed, the vice-president for enterprise security product and engineering at Akamai.

He added that traditional data loss prevention (DLP) tools were built for an earlier era of file transfers and e-mails, while sensitive corporate information is now being broken up across prompts, personal accounts and autonomous AI agents.

“Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level,” he advised. 

New AI-native threats

The report highlighted three emerging AI-native attack methods discovered by researchers in 2026, which Akamai said can bypass traditional perimeter defences.

The first, described as vibe hacking, involves attackers covertly changing local markdown instruction files in a developer’s environment. These modifications can trick AI coding assistants into generating insecure code or carrying out unauthorised actions while appearing to follow the developer’s normal workflow.

The second, called CursorJacking, involves rogue browser extensions using broad permissions to silently collect API keys, proprietary codebases and conversation history from the browser environment. Akamai said this technique targets users of popular AI coding assistants, including Cursor.

The third, CometJacking, uses indirect prompt injection. Attackers embed malicious instructions on a public webpage, which can then manipulate a user’s local AI agent.

According to Akamai, a compromised agent may be able to exfiltrate local files, e-mails and session credentials without the user’s knowledge. The report said this threat targets agentic browsers such as Perplexity’s Comet AI.

Strategies to secure AI

For organisations to gain the benefits of AI without exposing critical data, the report suggests five mitigation strategies for chief information security officers (CISOs).

Businesses should first focus on high-risk AI power users, directing monitoring, telemetry and tailored coaching toward the small group of employees driving the majority of interactive AI prompts, according to Akamai.

It also called on companies to reduce shadow AI by enforcing single sign-on (SSO) federation across platforms and continuously discovering the long tail of niche AI software-as-a-service tools being used within the organisation.

Security teams, it said, should move beyond static DLP and inspect the AI interaction layer in real time, including prompts, copy-and-paste buffers and document uploads.

Organisations are also urged to treat browser and integrated development environment extensions as highly privileged software. According to Akamai, almost 75 per cent of AI extensions request high or critical permissions, while 16.3 per cent contain known vulnerabilities.

Finally, the company said businesses need to secure autonomous AI agents by setting strict least-privilege boundaries and introducing behavioural monitoring for agents that act on behalf of employees.

GenAI can go beyond productivity boosts to transform economies: Nvidia CEO
Gartner: Singapore government to spend US$3.2 billion on IT this year
As TikTok faces a possible ban in the US, should users elsewhere be worried?
First Microsoft Southeast Asia research lab in Singapore marks significant expansion
Scammers are so successful they even accidentally scam themselves now

Sign up for the TG newsletter

Never miss anything again. Get the latest news and analysis in your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Whatsapp Whatsapp LinkedIn Copy Link Print
Avatar photo
ByAi Lei Tao
Ai Lei is a writer who has covered the technology scene for more than 20 years. She was previously the editor of Asia Computer Weekly (ACW), the only regional IT weekly in Asia. She has also written for TechTarget's ComputerWeekly, and was editor of CMPnetAsia and Associate Editor at Computerworld Singapore.
Previous Article Assassin’s Creed Black Flag Resynced review: Pirate thrills with a Singapore sling
Leave a Comment

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

FacebookLike
XFollow

Latest News

Assassin’s Creed Black Flag Resynced review: Pirate thrills with a Singapore sling
Gaming
August 9, 2026
Samsung Galaxy Z Fold 8 review: New shape works wonders for a foldable phone
Cellphones Mobile
August 8, 2026
Singapore firms expect agentic AI ROI to double but gaps remain: SAP study
Enterprise Software
August 7, 2026
AI is fixing problems but skilled workers still have an edge: Teamviewer CEO
Enterprise Software
August 7, 2026

Techgoondu.com is published by Goondu Media Pte Ltd, a company registered and based in Singapore.

.

Started in June 2008 by technology journalists and ex-journalists in Singapore who share a common love for all things geeky and digital, the site now includes segments on personal computing, enterprise IT and Internet culture.


banner							
banner
Everyday DIY
PC needs fixing? Get your hands on with the latest tech tips
READ ON

banner							
banner
Leaders Q&A
What tomorrow looks like to those at the leading edge today
FIND OUT

banner							
banner
Advertise with us
Discover unique access and impact with TG custom content
SHOW ME

 

 

POWERED BY READYSPACE
The Techgoondu website is powered by and managed by Readyspace Web Hosting.

TechgoonduTechgoondu
© 2026 Goondu Media Pte Ltd. All Rights Reserved | Privacy | Terms of Use | Advertise | About Us | Contact
Follow Us!
Hear the signal from the noise. Essential tech analysis from our Reality Check newsletter.

Zero spam. Unsubscribe at any time.

Loading Comments...

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Lost your password?