"The top 5% of enterprise power users interact with AI models at 12 times the rate of the bottom 50%," according to new research by Akamai — a statistic that reframes AI risk as a concentrated, not diffuse, problem.
AI super-adopters and usage patterns
Akamai’s State of the Internet: Enterprise AI Usage Risk Report 2026 finds that a handful of employees — the top 5% of power users — are not merely heavier users, they are embedding AI into work. The typical employee conversation with an AI model lasts about five prompts; the top 5% routinely engage in conversations of 18 prompts or more. Akamai frames those users as "AI super-adopters" whose persistent, deep interactions turn models into "embedded collaborators in essential business operations."
Or Eshed, Vice President Enterprise Security Product & Engineering at Akamai, warns that these small groups “are casting outsized shadows across enterprise threat surfaces.” That shadow grows as super-adopters hardcode unvetted tools into workflows and rely on autonomous agents outside established controls.
Corporate identity versus personal access: where data slips away
Visibility gaps are stark. Akamai reports that 47.11% of enterprise AI conversations occur through personal identities, not corporate-managed accounts. Some platforms keep interactions inside corporate identity systems: Gemini Enterprise (98.15%) and Microsoft Copilot M365 (90.55%) show strong enterprise-bound usage. By contrast, DeepSeek (99.8%), Microsoft Copilot Standard (63.92%), ChatGPT (61.36%), and Claude (61.09%) are dominated by personal identity logins.
Even more troubling, 14.4% of enterprise AI conversations occur via corporate email addresses linked to personal "freemium" AI subscriptions. Eshed notes that when employees use corporate email to register personal accounts, the sensitive data they inject into prompts "may be used for public model training." That practice blurs the lines between managed and unmanaged data flows.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildLong-tail blind spots: extensions, niche tools, and BYOAI
Security teams concentrating on major models such as ChatGPT, Claude, Copilot, and Gemini risk missing a widening long tail of niche AI tools, AI-enabled SaaS, and personal subscriptions. Akamai says employees increasingly "bring their own AI tools — or BYOAI" to work, creating additional visibility gaps around storage, retention, and processing of business data.
Browser and IDE extensions are a rapidly expanding blind spot. At midsize enterprises, 17.7% of employees use at least one AI extension, versus 9.53% at larger organizations. Nearly 75% of those extensions request high or critical permissions, and 16.31% of AI extensions contain known CVE vulnerabilities — higher than the 10.80% rate for browser extensions overall. Akamai cautions these add-ons can create "broad, unmanaged pathways directly into active user sessions and sensitive corporate data."
New attack vectors named: Vibe Hacking, CursorJacking, CometJacking
The report identifies emergent techniques that exploit the AI surface rather than traditional endpoints. Vibe Hacking involves modifying local instruction files (for example, AI_CONFIG.md) to manipulate coding assistants into producing vulnerable or unauthorized code. CursorJacking weaponizes rogue extensions to harvest API keys, session tokens, and proprietary source code from local stores. CometJacking uses indirect prompt injection in malicious web pages to trick AI agents into exfiltrating local user files, shifting the target from the human endpoint to the AI collaborator.
Akamai frames these methods as ways attackers can bypass legacy controls by targeting the AI layer itself, turning automated collaborators into conduits for data theft.
CISO checklist: concrete controls Akamai recommends
- Establish continuous visibility: discover all AI applications, browser/IDE extensions, and agents across the network; inspect prompts, uploads, and responses in real time.
- Eliminate Shadow AI: enforce corporate Single Sign-On (SSO), block unmanaged personal logins, and audit corporate emails tied to "freemium" subscriptions.
- Deploy contextual AI DLP: implement prompt-level inspection to detect unstructured leakage — such as code snippets or internal text — that legacy pattern-matching tools miss.
- Audit extensions and permissions: maintain a rigorous inventory of browser and IDE extensions, enforce strict permission boundaries, and screen add-ons for known CVEs.
- Govern AI agents as identities: treat autonomous AI agents and browsers as privileged digital identities with least-privilege access, strict scope limits, and real-time monitoring.
What this means for technologists, procurement leaders, and end users
Technologists and security teams must shift from policing "if" AI is used to mapping where it operates, which teams depend on it most, and whether those instances are inside enterprise guardrails. Akamai urges discovery and real-time inspection to find concentrated risk before attackers do.
Procurement leaders will need to account for dozens of niche tools and browser/IDE extensions that evade central procurement, and to screen add-ons for known CVEs and excessive permissions before approving use.
End users — especially power users — should assume that heavy, unsanctioned use of freemium accounts or extensions can expose proprietary data and, inadvertently, train public models. Eshed’s blunt framing captures the consequence: “AI is no longer just a productivity booster; it is a virtual colleague with keycard access to the company vault.”
Concentration, not ubiquity, is now the defining feature of enterprise AI risk. The Akamai data make that plain: a small share of users, using a broad palette of unmanaged tools and extensions, can create outsized attack surfaces. For CISOs and security teams, the imperative is not to ban every tool but to know where AI lives in their environment and to apply the same identity, least-privilege, and visibility controls they use to protect other privileged access — and to do it before adversaries map that same terrain.




