Back to News
Market Impact: 0.22

Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive “Shadow AI” Visibility Gaps

Cybersecurity & Data PrivacyArtificial IntelligenceRegulation & LegislationMarket Technicals & Flows
Akamai Research: Nearly Half of Enterprise AI Use Bypasses Corporate Security, Creating Massive “Shadow AI” Visibility Gaps

Akamai’s 2026 State of the Internet security report warns that enterprise AI risk is concentrating in a small group of “AI power users” and expanding via “shadow AI,” including rogue browser extensions and vulnerable autonomous agents. It highlights three new AI-native attack vectors (vibe hacking, CursorJacking, and CometJacking) that can bypass perimeter defenses, while noting ~75% of AI extensions require high/critical permissions and 16.3% contain known CVEs. Akamai outlines a CISO roadmap—targeting power users, eliminating shadow AI via SSO/continuous discovery, inspecting the interaction layer, vetting extensions, and securing AI agents—implying elevated near-term cybersecurity urgency for enterprises.

Analysis

This is more a demand-creation note for cyber budgets than a near-term earnings driver. The biggest beneficiaries are vendors sitting at the identity/browser/endpoint intersection, because the pain point is no longer perimeter breach prevention but governance of user interaction, extensions, and agent permissions. That argues for continued budget rotation toward PANW, ZS, CRWD, and OKTA; AKAM participates only if it can convert this narrative into measurable attach or cross-sell in enterprise security, not just brand lift.

Second-order, the report implies a broader procurement shift from single-tool visibility to continuous telemetry across unmanaged apps and local environments. That helps platforms with high-switching-cost integration layers and hurts point solutions that only solve one slice of the stack. It also creates a headwind for “approved SaaS only” assumptions: as shadow AI expands, security teams will likely fund discovery/SSO controls first, then agent monitoring, which could delay spend on newer AI-native products by 1-2 quarters.

The market risk is overpaying for the headline while underestimating budget friction. If AI incidents do not spike in the next 1-3 months, this could remain a slide-deck catalyst rather than a revenue catalyst; the thesis breaks if AKAM does not show pipeline or billings improvement in the next earnings cycle. Contrarian view: consensus may be too optimistic that every AI-security headline creates incremental TAM; a meaningful portion is just reclassification of existing security spend, which favors incumbents with clear category ownership more than report publishers.

More News