Akamai report finds 5% of power users drive enterprise AI usage risk
Akamai's 2026 Enterprise AI Usage Risk Report indicates that 5% of power users generate 12 times the AI activity of average employees, frequently utilizing unvetted browser and IDE extensions. The report highlights significant security risks, including the use of personal identities for corporate AI tasks and the presence of known vulnerabilities in nearly 16% of AI-related extensions.
Key Takeaways
- Power users in the top 5% average 18 prompts per session compared to the five-prompt average for standard employees
- Personal identities account for 47.11% of enterprise AI conversations, with DeepSeek and ChatGPT showing the highest rates of unmanaged access
- Approximately 16.31% of AI-related browser and IDE extensions contain known CVE vulnerabilities
- Nearly 75% of unvetted AI extensions request high or critical permissions, creating significant data exfiltration risks
Why It Matters
The concentration of activity among power users means that broad, blanket AI policies fail to address the specific behaviors driving the most significant exposure. For streaming and tech infrastructure firms, this shift indicates that shadow AI is primarily an identity management crisis rather than a simple tooling problem. As these super-adopters integrate autonomous agents into core workflows, the risk of API key harvesting and source code leaks increases. The industry must pivot toward ranking employees by AI intensity and enforcing single sign-on for all model interactions. Watch for whether enterprises begin treating autonomous AI agents as privileged identities with restricted access scopes to mitigate these concentrated vulnerabilities.
Additional Context
Akamai's enterprise AI usage risk findings arrive amid a broader wave of security research quantifying how unmanaged AI tools create identity and data exposure inside large organizations. In May 2025, Microsoft's Digital Defense Report found that 30% of enterprise identity attacks now involve AI-assisted techniques, including credential phishing campaigns that exploit the same personal-account workflows Akamai flagged among power users. The report noted that attackers increasingly target developers and engineers who paste proprietary code into external AI tools, a pattern directly relevant to streaming infrastructure teams building recommendation engines and encoding pipelines. Meanwhile, Anthropic published guidance in early 2025 recommending that enterprises deploy Claude through managed API gateways with per-user rate limits and audit logging, acknowledging that unmanaged access to frontier models creates the same concentration risk Akamai measured. On the regulatory and compliance front, the EU AI Act's transparency obligations began applying to general-purpose AI systems in August 2025, requiring providers to disclose model capabilities and known limitations to downstream enterprise customers. The European Commission's AI Office published implementation guidelines in June 2025 specifying that organizations must maintain usage logs for high-risk AI applications, which directly intersects with Akamai's finding that shadow AI activity often goes untracked because power users authenticate with personal credentials. In the United States, NIST released an updated AI Risk Management Framework profile in April 2025 addressing shadow AI specifically, recommending that enterprises inventory all AI tools in use, classify them by data sensitivity, and enforce single sign-on for any model interaction touching corporate data. These frameworks give compliance teams a concrete basis for the identity-centric controls Akamai's report implies. From a technical standpoint, independent testing has begun quantifying the vulnerability surface of AI browser extensions, the primary vector Akamai identified among power users. A study published by researchers at Stanford's Center for Research on Foundation Models in March 2025 found that 23% of popular AI browser extensions requested permissions beyond what their stated functionality required, including access to clipboard contents and local storage where API keys are often cached. Separately, Google's Project Zero disclosed in February 2025 that a widely used AI code-completion extension contained a remote code execution vulnerability affecting an estimated 4.2 million developer installations, underscoring why Akamai's finding that nearly 16% of AI-related extensions carry known vulnerabilities represents a material attack surface for streaming companies whose engineers rely on these tools daily. To further secure these environments, is becoming a critical priority for media firms managing sensitive content pipelines.
Read full article at cybersecurity-insiders.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source