Akamai’s Enterprise AI Usage Risk Report finds that 5% of power users generate most enterprise AI conversations. Nearly half run through unmanaged personal accounts outside corporate oversight. Browser extensions request dangerous permissions (75% high or critical) and 16% carry known CVEs. Specific threats like CursorJacking are already documented in the wild.
This looks like shadow IT, which it is. But the risk concentration is actually strategic. Five percent of a workforce is a tractable focus area for security teams. Personal account usage is addressable through conventional controls: conditional access policies that gate logins to corporate networks, extension blocklists in browsers, and endpoint detection. The real problem is visibility. Most organizations have no line of sight into where AI conversations actually happen.
The solution isn’t new tooling; it’s deploying existing security controls where the risk actually lives. Security teams already have the tools. They just need to deploy them where the conversations are.
Sources: Akamai Enterprise AI Usage Risk Report
Coverage: The Hacker News
Related on this blog: [QT] Amazon’s AI Spending Problem • Amazon Ran a Project 860% Over Budget and Took Five Months to Notice • AI Browsers Keep Getting Hijacked, and Nobody Claims a Fix