Akamai has released a new State of the Internet report warning that enterprise artificial intelligence adoption is outpacing corporate security controls, creating what the company calls a “shadow AI” visibility gap.
The Enterprise AI Usage Risk Report 2026, published on 5 August 2026, found that risk is concentrated among a small group of “AI power users”, with just 5 per cent of high-risk employees accounting for the majority of interactive AI prompts across enterprises.
Three new AI-native attack vectors
Akamai researchers identified three novel threat methodologies discovered in 2026 that bypass traditional perimeter defences. “Vibe hacking” involves attackers covertly manipulating local markdown instruction files to trick coding assistants into generating insecure outputs. “CursorJacking” uses rogue browser extensions with broad permissions to harvest API keys and codebases from AI coding tools. “CometJacking” embeds malicious instructions on public web pages to hijack agentic browsers such as Perplexity’s Comet AI through indirect prompt injection.
“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels. Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level,” said Or Eshed, Vice President, Enterprise Security Product and Engineering, Akamai.
Extensions and agents flagged as high risk
The report found that almost 75 per cent of AI browser extensions demand high or critical permissions, and 16.3 per cent contain known vulnerabilities. Akamai recommends five mitigation steps for chief information security officers: targeting monitoring at high-risk power users, eliminating shadow AI through single sign-on federation and continuous discovery, inspecting prompts and uploads in real time, vetting browser and IDE extensions as privileged software, and applying least-privilege controls to autonomous AI agents.
- Target telemetry and coaching toward the highest-risk employees
- Force single sign-on across all AI platforms to eliminate shadow tools
- Move from static data loss prevention to real-time prompt inspection
- Treat browser and IDE extensions as highly privileged software
- Apply least-privilege, behaviourally monitored boundaries to AI agents
Now in its 12th year, Akamai’s State of the Internet series draws on data from across the company’s global cybersecurity infrastructure.

