The top 5% of enterprise power users interact with AI models at 12 times the rate of the bottom 50% of the workforce, creating a disproportionate security risk that most enterprise teams are missing. Those findings come from Akamai's State of the Internet: Enterprise AI Usage Risk Report 2026, published this week and based on real-world usage telemetry and threat analysis. While security teams focus on policing broad employee access to ChatGPT and Claude, a handful of AI super-adopters are quietly hardcoding unvetted tools into critical business operations, expanding shadow AI and introducing autonomous agents that operate outside established guardrails.
Nearly half of all enterprise AI conversations—47.11%—occur through personal identities rather than corporate-managed accounts, according to the report. Gemini Enterprise keeps 98.15% of interactions inside corporate identity systems, and Microsoft Copilot M365 maintains 90.55% within managed accounts. In contrast, DeepSeek channels 99.8% of usage through personal logins, while Microsoft Copilot Standard (63.92%), ChatGPT (61.36%), and Claude (61.09%) are dominated by personal identity access. The average employee conversation lasts about five prompts, but the top 5% of power users routinely engage in exchanges of 18 prompts or more—evidence that AI models have become embedded collaborators in essential business operations. Among midsize enterprises, 17.7% of employees use at least one AI extension, compared with 9.53% at larger organizations, and nearly 75% of those extensions request high or critical permissions. Crucially, 16.31% of AI extensions contain known CVE vulnerabilities, compared to 10.8% of browser extensions overall.
"Small groups of AI power users are casting outsized shadows across enterprise threat surfaces that are already riddled with dips and blind spots," says Or Eshed, Vice President Enterprise Security Product & Engineering at Akamai. The report warns that one of the most surprising findings was that 14.4% of enterprise AI conversations occurred via corporate email addresses linked to personal "freemium" AI subscriptions rather than enterprise-managed licenses, meaning sensitive data employees inject into prompts may be used for public model training. Eshed notes that "AI is no longer just a productivity booster; it is a virtual colleague with keycard access to the company vault," and security teams need to identify which employees depend most on AI to know where risk is concentrated.
This expanding AI surface is creating new attack vectors that bypass traditional controls, the report explains. Vibe hacking involves attackers subtly modifying local instruction files to covertly manipulate AI coding assistants into generating vulnerable code or executing unauthorized actions. CursorJacking weaponizes rogue extensions to silently harvest API keys, session tokens, and proprietary source code directly from local databases. CometJacking uses indirect prompt injection embedded in malicious web pages to trick AI agents into exfiltrating local user files, shifting the target from the human endpoint to the AI collaborator. Browser and IDE extensions represent a rapidly expanding blind spot because these tools create broad, unmanaged pathways directly into active user sessions and sensitive corporate data, the report warns. Employees increasingly "bring their own AI tools—or BYOAI" to access AI through personal accounts, creating additional visibility gaps around how business data is stored, retained, and processed.
The challenge for CISOs is no longer whether employees are using AI—they are—but to identify where AI is operating, which teams depend on it most, and whether those systems remain inside enterprise guardrails, the report concludes. Akamai recommends that security teams establish continuous visibility across all AI applications and extensions, eliminate shadow AI by enforcing corporate Single Sign-On, deploy contextual AI data loss prevention with prompt-level inspection, audit extensions and permissions while screening for known CVEs, and govern AI agents as privileged digital identities with least-privilege access and real-time monitoring. The report frames the imperative simply: answer those questions before adversaries do. The concentration of AI usage among power users means that traditional perimeter defenses designed for uniform employee behavior will fail to catch the risks that matter most, and the window to secure these emerging pathways is closing as attackers begin to weaponize them.

