Akamai acquires LayerX, delivering end-to-end security and real-time AI usage control to any browser. Get details
Background

Shadow AI, Rogue Agents, and Data Leaks: A Special Report on Navigating AI Risk

August 05, 2026 by Kimberly Gomez

Share

Key takeaways

A special Akamai State of the Internet (SOTI) Security report reveals how rapid enterprise AI adoption expands threat surfaces with new risks that legacy tools cannot detect.

Nearly half of workplace AI conversations use personal accounts, creating visibility gaps and exposing data to public model training.

Nearly 75% of AI browser extensions request high or critical permissions, introducing vulnerabilities like API key theft through extension exploits.
Autonomous AI agents and prompt injection attacks like CometJacking let threat actors perform unauthorized actions without human oversight.
Security leaders must implement targeted AI governance over identities, extensions, and data flows to balance productivity with risk mitigation.

Enterprises are all in on AI. Although the use of artificial intelligence (AI) was once viewed with caution, it is now becoming a mandate for most enterprises. The result is a sprawling ecosystem of AI assistants, agents, browsers, and extensions, and autonomous workflows that touch every corner of the enterprise — from code writing and content generation to contract analysis and task automation.

While these AI tools are rapidly becoming essential productivity drivers, they are also quietly expanding organizations’ threat surfaces. As AI use increases, it introduces new categories of risk that traditional security tools were not designed to address. Security leaders are struggling to understand where their data is going, who has access to it, and how to secure these third-party systems.

New insights on AI use and threats

We examine this critical trend of increasing AI use in a special edition State of the Internet (SOTI) Security report: the Enterprise AI Usage Risk Report 2026.

This report is an analysis of data from LayerX, a leader in secure enterprise browser provider and AI use control that Akamai recently acquired. The report dissects where and how AI is being used in the enterprise, how it can be exploited by threat actors, and how CISOs can effectively manage these new risk vectors without losing the productivity benefits of AI.

The top 5 risks from AI use

We provide a practical, fact-based analysis of the top five risks from AI use that enterprises face today:

  1. The expansion of the threat surface via the proliferation of AI in the workplace
  2. Personal AI accounts and unapproved AI apps that drive shadow AI
  3. Data leak risks via AI data exposure
  4.  Browser and IDE extensions that go unnoticed in most organizations
  5.  AI agents that penetrate the enterprise environment and operate outside of existing guardrails

Want more details? The report features targeted security spotlights that expose how attackers exploit these vulnerabilities in the wild.

The expansion of the threat surface via the proliferation of AI in the workplace

Analysis by LayerX identifies the emergence of a small group of “AI power users.” Their data shows that the top 5% of users generate at least 144 conversations, often exceeding 18 prompts, reflecting a trend toward iterative collaboration.

These users are more likely to share business information, upload files, submit sensitive data, integrate AI into daily decision-making, and delegate execution-level work to autonomous AI agents. This underscores that enterprise AI risk is largely driven by a concentrated group of heavy users.

In addition, the rise of vibe hacking — i.e., the use of natural language prompts to trick AI models into bypassing guardrails or to launch automated cyberattacks — contributes even more unseen risk. Understanding how deeply AI models are embedded in workflows is becoming critical.

Personal AI accounts and unapproved AI apps that drive shadow AI

Most organizations focus governance efforts on widely used AI platforms like ChatGPT, Microsoft Copilot, and Google Gemini. But employees are increasingly using AI apps or subscriptions that operate without corporate oversight. This creates a significant visibility gap into how business data is stored, retained, and processed.

According to LayerX data, nearly half of all enterprise AI conversations (47.11%) take place through personal identities rather than via corporate-managed accounts, creating a major governance visibility gap. And more than 14% of enterprise AI conversations involved personal “freemium” AI subscriptions, which exposes data to large language models (LLMs) for public model training.

The example of the Chinese AI company DeepSeek illustrates how explosive user adoption can overcome critical data security controls. This highlights the need for continuous visibility of AI applications that employees adopt independently.

Data leak risks via AI data exposure

AI fundamentally changes the data loss prevention (DLP) equation. Information transfer is no longer confined to well-defined and well-protected channels like email, file transfers, and cloud storage. With AI, sensitive information can be shared through prompts, conversations, snippets of code, copied text, and other unstructured forms.

While individual interactions may appear harmless, they can collectively expose valuable business context that legacy DLP controls were not designed to detect.

For example, this SOTI report spotlights the recent case of a U.S. government official who accidentally released sensitive, restricted operational data from the Cybersecurity and Infrastructure Security Agency (CISA) via a public AI infrastructure.

Browser and IDE extensions that go unnoticed in most organizations

Employees are increasingly accessing AI through browser extensions that operate directly inside the browser. These browser extensions often have extensive access to web content, user activity, credentials, and enterprise applications.

LayerX research revealed that nearly 75% of AI browser extensions request high or critical permissions. This can create a channel for unmanaged AI access to sensitive data — a ripe target for malicious actors. The research also found that many AI extensions have known common vulnerabilities and exposures (CVEs).

Take CursorJacking, for instance — a sneaky security flaw that targets developers who are using the popular Cursor AI coding assistant. All it takes is a rogue browser extension for an attacker to quietly swipe Cursor API keys, impersonate a developer, and compromise the entire AI-driven dev environment.

AI agents that penetrate the enterprise environment and operate outside of existing guardrails

The rapidly growing use of autonomous AI agents, together with AI browsers and agentic user interfaces, has created another new dimension of risk. The deeper these agents integrate into daily operations and sensitive data flows, the more they act as independent team members, making decisions with very little human supervision.

A new technique called CometJacking, which targets Perplexity’s Comet AI browser, illustrates the threat. LayerX researchers showed that by embedding malicious instructions within a web page, an attacker could manipulate the browser's AI agent through an indirect prompt injection attack, giving them free reign to access data and perform unauthorized actions.

How CISOs can meet the challenge of new AI risks

This SOTI Security report clarifies the need for organizations to meet the challenge of this new, fragmented AI ecosystem by introducing strict AI governance over data flows, identities, extensions, and autonomous agents.

To help guide this effort, our report provides:

  • A practical, field-tested mitigation framework
  • An actionable checklist of recommendations for CISOs and security leaders

With the right security frameworks, organizations can tap the full potential of AI, without exposing them to new risks.

Want the full story?

Download the new special edition SOTI: Enterprise AI Usage Risk Report 2026.

About the Author(s)

Akamai Wave Blue

Kimberly Gomez

Kimberly Gomez is the Director of Security Research at Akamai, where she leads research teams to deliver comprehensive analyses and reports that help organizations stay one step ahead of cybercriminals. With more than a decade in cybersecurity and a background spanning print, broadcast, and online journalism, Kimberly is passionate about security storytelling — the kind that can help even your grandparents understand what's happening in the threat landscape.

 

When she's not tracking down the latest cyberthreats, you can find her buried in a book, planning her next adventure, or chasing her son through the theme parks of Orlando.