Amidst the rapid integration of artificial intelligence in business operations, a small segment of users poses a significant security risk. According to Akamai’s latest research, only 5% of enterprise users, labeled as AI super-adopters, engage with AI models at rates 12 times higher than the bottom 50% of employees. This group is embedding unvetted AI tools into critical business functions, heightening the risk of data breaches and bypassing established security protocols.
AI Super-Adopters and Their Security Impact
These power users are significantly expanding the use of shadow AI, increasing the likelihood of data leaks and introducing autonomous AI agents that function outside of enterprise security measures. Or Eshed, Vice President of Enterprise Security Product & Engineering at Akamai, emphasizes the disproportionate risk posed by these users, noting that while security teams focus on securing major AI platforms, the smaller tools used by power users present a more considerable threat.
Akamai’s data reveals that these top users engage in much longer AI interactions, with sessions averaging 18 prompts compared to the typical five seen among regular employees. This indicates AI’s growing role as a critical collaborator in business operations, necessitating enhanced scrutiny from security teams.
Managing Enterprise and Personal AI Usage
Almost half of AI conversations in enterprises (47.11%) occur through personal accounts rather than corporate-managed identities. This creates a divide between regulated AI usage and unmonitored, personal AI tools, complicating visibility for IT and compliance teams. Platforms like Gemini Enterprise and Microsoft Copilot M365 maintain most interactions within corporate boundaries, yet others like ChatGPT and Claude are predominantly accessed via personal logins.
The report highlights a concerning trend: 14.4% of AI interactions are via corporate emails tied to personal AI subscriptions. This raises the risk of sensitive data being used for public model training, even when accessed through official corporate channels.
Addressing Shadow AI and Security Blind Spots
Employees are increasingly using personal AI tools and extensions without IT oversight, creating a new layer of security challenges. Akamai found that 17.7% of employees in midsize enterprises utilize AI extensions, with a notable portion requesting high permissions and containing known vulnerabilities.
Eshed warns that this uncontrolled landscape is not just about data privacy but also sets the stage for future cyberattacks. Security teams must adapt by identifying where AI is used, who depends on it, and ensuring these systems operate within secure boundaries.
Strategies for Securing AI Systems
The Akamai report outlines a comprehensive checklist for Chief Information Security Officers (CISOs) to secure enterprise AI applications. Key recommendations include establishing continuous visibility of AI tools, eliminating shadow AI through enforced SSO, and auditing extensions and permissions rigorously. Furthermore, AI agents should be treated as privileged identities with stringent access controls and real-time monitoring to mitigate threats effectively.
As the AI landscape evolves, the need for proactive security measures becomes crucial. Organizations must adapt quickly to safeguard against the emerging risks posed by the increasing integration of AI tools in business operations.
