"AI helped drive a 300% increase in bot traffic last year," Akamai reports, a stark numeric opening to a dossier that links rising automated threats with the spread of generative tools across enterprise environments.
Bot traffic surge: commerce in the crosshairs
Akamai's State of the Internet report, published on September 22, draws on the vendor's global security and network telemetry to show that bot traffic rose 300% in the previous year. The surge "primarily impacted the commerce vertical," the report says, underscoring how retailer-facing systems and transaction pipelines have been a principal target as automated tools scale attack volume and velocity.
That volume is not benign: bots both probe for weak endpoints and execute high-frequency, low-cost actions that can harvest credentials, distort analytics, scrape inventory, and enable fraud at scale. Akamai ties the escalation in part to AI-enabled tooling that lowers the technical barrier for hostile automation.
APIs as the dominant attack surface
Akamai warns that AI is "elevating APIs as the dominant attack surface for modern enterprises." The data bear that out: the report recorded a 113% increase in daily API attacks between 2024 and 2025. Surveyed organizations reported increased exposure — 87% experienced an API-related security incident in 2025, up from 76% in 2022.
APIs concentrate business logic, data flows, and integrations; as attackers automate discovery and exploitation with AI-assisted tooling, the frequency and impact of API-focused campaigns have climbed. Those figures suggest API hygiene, filtering, and runtime protection are becoming critical front-line controls for enterprise defenders.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleBrowsers, extensions, and sensitive AI conversations
Akamai flags browser-based AI tooling as another emergent risk. Two-fifths (40%) of enterprise users have installed AI browser extensions, and a quarter of users have changed extension permissions within a 12‑month window — behavior Akamai says "significantly increases their risk profile."
The report also finds that 6% of chatbot conversations contain sensitive corporate information. That risk is amplified because nearly half — 47% — of AI conversations on enterprise devices are conducted via personal identities and accounts, leaving IT teams unable to track or control those exchanges. Together, these practices create a pipeline by which sensitive data can leave monitored environments or be exposed through compromised extensions.
Agentic AI, MCP exposure, and faster exploit development
Akamai documents an AI-driven acceleration not only in vulnerability research and exploit development but also in threats related to model‑connected platforms (MCPs). The report cautions that "MCP gives AI the 'hands' to execute autonomous actions, but it also creates significant security risks by blurring the line between data and code, which may allow malicious third‑party servers to hijack large language model (LLM) logic through prompt injection or cross‑server attacks."
That architecture — agents that can act on behalf of users, connected to third‑party services — changes the attack calculus. Akamai says attackers no longer need to rely solely on network breaches; they can exploit indirect prompt injections, manipulate model context, or compromise unmonitored browser extensions to "manipulate an agent’s logic to execute unauthorized, high‑impact actions."
Protecting the agentic enterprise — and what it means for security teams, policymakers, and procurement
Akamai recommends several mitigation paths for the "agentic enterprise." Key controls listed in the report include:
- Adaptive edge governance: edge‑native runtime protections, API filters, and isolation mechanisms to neutralize threats before exploits land.
- Visibility and behavioral controls inside the browser: to reduce data exposure from extensions and unmanaged accounts.
- Restricting agent autonomy: limit actions based on how easily outcomes can be verified and how reversible failures would be, keeping humans in the loop for high‑risk operations.
What this means in practice:
- Technologists and security teams should prioritize API filtering, edge‑level runtime defenses, and browser behavioral controls to intercept automated attacks before they escalate.
- Policymakers and regulators will need to reckon with the blurred boundary between data and executable model logic that Akamai says enables cross‑server attacks and third‑party hijacking of LLM decision flows.
- Affected enterprises and procurement leaders must reassess vendor integrations, extension policies, and the degree of autonomy granted to internal agents — particularly where a misstep could trigger irreversible actions.
One tension the report leaves framed but unresolved: MCP exposure ranks last among current CISO security priorities even as security leaders expect rogue AI agents to become a top cyber‑threat by 2030, Akamai notes. That gap — between where risk is expected to concentrate and where today’s priorities lie — will determine whether mitigation measures keep pace with the rapid evolution of AI‑enabled threats.
Read the full Akamai report: https://www.infosecurity-magazine.com/news/ai-drives-surge-in-bot-and-api/




