Executive Summary
Akamai's 2026 Enterprise AI Usage Risk Report reveals that the top 5% of enterprise AI power users interact with AI models at 12 times the rate of typical employees, creating disproportionate security risks through shadow AI adoption. These super-adopters are embedding unvetted AI tools into critical business operations, with 47% of enterprise AI conversations occurring through personal identities rather than corporate-managed accounts. The research highlights emerging attack vectors including vibe hacking, cursor jacking, and comet jacking that specifically target AI-enabled workflows and bypass traditional security controls. Organizations face significant data leakage risks as employees use corporate email addresses for personal AI subscriptions, with 14.4% of conversations occurring via freemium accounts that may use sensitive data for model training. The expanding landscape of AI browser extensions poses additional vulnerabilities, with 16.31% containing known CVE exploits compared to 10.8% of standard extensions.
This research underscores the urgent need for enterprises to shift from preventing AI adoption to governing AI integration, as traditional security frameworks struggle to address the unique risks posed by autonomous AI agents operating within corporate environments.
Why This Matters Now
The rapid proliferation of shadow AI tools in enterprises is creating unmanaged attack surfaces that bypass existing security controls, requiring immediate visibility and governance strategies as AI becomes embedded in critical business operations.
Attack Path Analysis
Attackers exploit shadow AI usage by targeting high-volume AI power users through prompt injection and malicious browser extensions. They escalate privileges by compromising personal AI accounts with corporate access, then move laterally through unmanaged AI tools and agents. Command and control is established through weaponized AI extensions and autonomous agents, enabling exfiltration of sensitive data through personal AI subscriptions and unmonitored channels. The impact includes data exposure, compromised AI models, and operational disruption through corrupted AI workflows.
Kill Chain Progression
Initial Compromise
Description
Attackers target AI power users through malicious browser extensions with CVE vulnerabilities, prompt injection attacks via CometJacking, or compromised personal AI accounts accessed through corporate credentials
MITRE ATT&CK® Techniques
Trusted Relationship
Valid Accounts: Cloud Accounts
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Hijack Execution Flow: Services Registry Permissions Weakness
Drive-by Compromise
Process Injection: Process Hollowing
Command and Scripting Interpreter: JavaScript
Data from Cloud Storage Object
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System Components with Non-Console Administrative Access
Control ID: 2.2.7
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Third-party risk management
Control ID: Article 8
CISA ZTMM 2.0 – Applications are authorized before connection
Control ID: Application Security - AS.M-3
NIS2 Directive – Risk analysis and information system security policies
Control ID: Article 21(2)(a)
GDPR – Processor obligations
Control ID: Article 28
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI power users embed unvetted tools in development workflows, creating shadow AI risks through IDE extensions with CVE vulnerabilities and prompt injection attacks.
Financial Services
High-risk shadow AI adoption by power users threatens sensitive financial data through unmanaged personal AI subscriptions and egress security policy violations.
Health Care / Life Sciences
HIPAA compliance violations through shadow AI usage, with power users potentially exposing patient data via personal AI accounts and unencrypted traffic.
Information Technology/IT
IT sectors face multiplied attack surfaces from AI extensions with known CVEs, requiring zero trust segmentation and enhanced threat detection capabilities.
Sources
- The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Riskhttps://thehackernews.com/2026/08/the-outsized-shadow-why-5-of-ai-users.htmlVerified
- State of the Internet: Enterprise AI Usage Risk Report 2026https://www.akamai.com/site/en/documents/state-of-the-internet/2026/enterprise-ai-risk-report.pdfVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- NIST National Vulnerability Databasehttps://nvd.nist.gov/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would constrain shadow AI attack progression by segmenting AI workload access and enforcing identity-aware routing between personal and corporate AI services. The fabric's east-west enforcement and egress controls would likely reduce lateral movement scope and limit data exfiltration through unmanaged AI channels.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely constrain the ability to leverage compromised personal AI accounts for corporate system access, reducing the attack surface for credential-based exploitation.
Control: Zero Trust Segmentation
Mitigation: Workload isolation policies would likely limit privilege escalation scope by restricting access paths between AI services and corporate environments, reducing the blast radius of compromised AI accounts.
Control: East-West Traffic Security
Mitigation: Traffic inspection and micro-segmentation would likely constrain lateral movement between AI workloads and corporate applications, reducing reachability across unmanaged AI tool ecosystems.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility across cloud environments would likely detect anomalous AI agent behavior and constrain command channel establishment through unauthorized service configurations.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic controls would likely constrain data exfiltration through personal AI channels by enforcing policy-based restrictions on sensitive data flows to external AI services.
Residual impact would likely be limited to isolated AI workloads with reduced scope of data exposure due to segmentation boundaries and controlled egress paths.
Impact at a Glance
Affected Business Functions
- Information Technology Security
- Data Loss Prevention
- Enterprise AI Governance
- Browser Extension Management
Estimated downtime: N/A
Estimated loss: N/A
The report indicates significant risk of data leakage through shadow AI usage, with 47.11% of enterprise AI conversations occurring through personal identities rather than corporate-managed accounts. Employees using corporate email addresses for personal AI subscriptions (14.4% of conversations) may expose sensitive business data to public model training. AI extensions with high permissions (75% request critical permissions) create pathways to sensitive corporate data, session tokens, and proprietary source code.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Native Security Fabric (CNSF) to provide real-time visibility and inline enforcement for shadow AI usage across all enterprise environments
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration through personal AI subscriptions and unmanaged AI tools
- • Establish Zero Trust Segmentation with identity-based policies to prevent lateral movement between corporate and personal AI services
- • Enable Multicloud Visibility & Control to detect anomalous AI interactions and monitor AI agent behaviors across hybrid environments
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal AI usage patterns and alert on suspicious AI extension activities or prompt injection attempts



