Shadow AI Crisis Exposed as Nearly 50% of Enterprise AI Bypasses Security, Warns Akamai Report

2 Sources

Share

Akamai's Enterprise AI Usage Risk Report 2026 reveals a Shadow AI crisis where nearly 50% of enterprise AI bypasses security controls. The report exposes three novel AI-native attack vectors—Vibe hacking, CursorJacking, and CometJacking—that exploit rogue browser extensions and autonomous agents, putting corporate data at unprecedented risk.

Shadow AI Emerges as Critical Enterprise Security Threat

Akamai released its State of the Internet security report, the Enterprise AI Usage Risk Report 2026, exposing a Shadow AI crisis where nearly 50% of enterprise AI usage bypasses traditional security controls

1

. The Akamai Report tracks how decentralized Shadow AI, highly active AI power users, and silent rogue browser extensions are exposing critical corporate assets to entirely new classes of cyber risk. What began in early 2025 as cautious experimentation has solidified into a structural mandate, but this rapid integration has outpaced traditional security guardrails

2

.

"AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels," said Or Eshed, Vice President, Enterprise Security Product and Engineering of Akamai. "Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented across millions of fluid prompts, unmanaged personal accounts, and autonomous agents. Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level"

1

.

Three Novel AI-Native Attack Vectors Bypass Traditional Defenses

The report details three emerging cybersecurity threats discovered by researchers in 2026 that exploit enterprise AI usage through AI-native attack vectors, completely bypassing traditional perimeter defenses. Vibe hacking represents a subtle but dangerous technique where attackers covertly manipulate local markdown instruction files within a developer's environment. This modification tricks frontier AI coding assistants into generating insecure outputs or executing unauthorized actions while mimicking a developer's normal workflow

1

.

CursorJacking poses a high-impact threat targeting popular AI coding assistants like Cursor. Rogue browser extensions exploit broad permissions to silently harvest API keys, proprietary code, and conversational history directly from the browser environment

2

. Almost 75% of AI extensions demand high or critical permissions, and 16.3% contain known CVEs, making them particularly dangerous vectors for data exfiltration

1

.

CometJacking leverages indirect prompt injection by embedding malicious instructions on public web pages to manipulate the user's local AI agent. The compromised agent can then exfiltrate local files, emails, and session credentials without the user's knowledge. This threat specifically targets agentic browsers like Perplexity's Comet AI

1

.

Five-Point CISO Roadmap to Secure AI

To capture the economic benefits of AI Security without exposing critical data, the Akamai Report outlines five core mitigation strategies for modern CISOs. First, organizations must target AI power users by directing telemetry, monitoring, and tailored coaching toward the 5% of high-risk employees who are driving the majority of interactive AI prompts

1

.

Second, enterprises need to eliminate Shadow AI by forcing single sign-on federation across all platforms and continuously discovering the long tail of niche AI software as a service tools. Third, security teams must inspect the interaction layer by transitioning from static DLP to real-time, contextual analysis of prompts, copy/paste buffers, and document uploads

1

.

Source: CXOToday

Source: CXOToday

Fourth, organizations should vet browser and IDE extensions by treating them as highly privileged software, given that 75% of AI extensions demand high or critical permissions. Finally, companies must secure AI through strict, least-privilege boundaries and behavioral monitoring for autonomous agents that act on behalf of employees

1

. Now in their 12th year, Akamai's State of the Internet reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai's cybersecurity infrastructure, which handles a significant portion of global web traffic.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved