Welcome.AIWelcome.AI
    Skip to content
    AI Agents

    Enterprise AI Risk: Concentration Among Power Users and Security Vulnerabilities

    Akamai's latest report uncovers a staggering concentration of AI risk among just 5% of users, who are transforming AI from a simple tool into a core business collaborator, while traditional security measures fall short.

    cybersecurity-insiders.comAugust 30, 20263 min read

    Key Facts

    • Top 5% of users drive 47.11% of AI conversations, highlighting concentration risk in enterprise AI.
    • AI power users average 18 prompts, indicating a shift from tool to essential collaborator in workflows.
    • 16.31% of AI extensions have CVE vulnerabilities, exposing firms to significant security risks.
    • 14.4% of AI interactions via personal emails risk sensitive data leaks, complicating compliance efforts.
    • Enforcing SSO could mitigate 47.11% of shadow AI risks, aligning security with user productivity needs.

    Summary

    Akamai's recent Enterprise AI Usage Risk Report 2026 reveals a critical shift in the landscape of enterprise AI usage, highlighting a concentration of risk among a small group of power users. This report underscores that nearly half of enterprise AI interactions occur through personal accounts, leaving security teams blind to significant vulnerabilities. The findings indicate that the top 5% of users engage with AI tools at a staggering rate—12 times more than the bottom half—transforming AI from a simple productivity tool into an integral part of business operations. This concentration of usage raises alarms about data security and privacy, suggesting that traditional blanket policies are inadequate to address the nuanced risks posed by shadow AI.

    The report details that 47.11% of enterprise AI conversations occur through personal identities, which bypass corporate oversight. This lack of visibility is compounded by the fact that the top users average 18 prompts per session, compared to just five for the majority. Such engagement levels indicate that these users are not merely utilizing AI for quick tasks but are increasingly integrating it into their workflows as a collaborative partner. This trend signals a need for organizations to rethink their approach to AI governance, as the very employees driving productivity are also the ones inadvertently expanding the enterprise's exposure to risk.

    Akamai's data further reveals that 16.31% of AI browser and IDE extensions contain known vulnerabilities, a figure significantly higher than the 10.80% vulnerability rate for browser extensions overall. Additionally, 14.4% of conversations are initiated through corporate emails linked to personal freemium subscriptions, which can inadvertently expose sensitive information to public AI models. This duality of risk—where the most productive users are also the most vulnerable—highlights a critical gap in identity security that organizations must address.

    The implications of these findings extend beyond immediate security concerns. Organizations must recognize that the concentration of AI usage among a small group of employees creates a unique risk profile that traditional security measures may not adequately mitigate. By focusing on the intensity of AI usage rather than simply the number of users, companies can better identify potential vulnerabilities. This approach necessitates a shift in strategy, emphasizing the need for enhanced visibility into AI interactions and the implementation of robust governance frameworks.

    To effectively manage these risks, organizations should prioritize the identification of high-intensity AI users and implement Single Sign-On (SSO) solutions to ensure that all AI interactions occur within corporate identity systems. By doing so, companies can significantly reduce the percentage of conversations occurring through personal accounts. Furthermore, treating AI agents and extensions as privileged identities will help enforce stricter controls and reduce the likelihood of data breaches stemming from unvetted tools.

    As organizations navigate this evolving landscape, the focus should shift toward understanding the dynamics of AI usage intensity. The same 5% of users who drive productivity gains also represent the most significant risk exposure. By proactively addressing these vulnerabilities, companies can not only safeguard their data but also leverage AI more effectively. The future of enterprise AI governance will depend on a nuanced understanding of user behavior and the implementation of tailored security measures that align with the realities of how AI is being used in the workplace.

    Entities Mentioned

    Companies

    Akamai

    Products

    Gemini Enterprise
    Microsoft Copilot
    ChatGPT
    Claude

    Technologies

    Single Sign-On (SSO)
    AI agents
    browser extensions
    IDE extensions

    People

    Or Eshed

    Key Concepts

    shadow AI
    enterprise AI risk
    identity security
    AI power users
    data security
    data privacy
    BYOAI
    CVE vulnerabilities

    Definitions

    shadow AI
    Shadow AI refers to the use of AI tools and applications that operate outside of an organization's established security and governance frameworks.
    CVE vulnerability
    A Common Vulnerabilities and Exposures (CVE) vulnerability is a publicly disclosed cybersecurity flaw that can be exploited by attackers.
    BYOAI
    Bring Your Own AI (BYOAI) is a trend where employees use personal AI tools and applications in the workplace without IT oversight.
    Single Sign-On (SSO)
    Single Sign-On (SSO) is an authentication process that allows a user to access multiple applications with one set of login credentials.
    AI intensity
    AI intensity measures the frequency and volume of interactions an employee has with AI tools, indicating their level of engagement and potential risk.

    Use Cases

    • Monitoring AI usage intensity among employees
    • Implementing Single Sign-On to secure AI access
    • Auditing corporate emails for freemium account ties
    • Screening browser and IDE extensions for vulnerabilities
    • Governance of AI agents as privileged identities

    Frequently Asked Questions

    What is the main risk associated with shadow AI?

    The main risk associated with shadow AI is that it operates outside of established security controls, leading to potential data security and privacy issues. This can expose sensitive information and create vulnerabilities within the organization.

    How can organizations mitigate the risks of shadow AI?

    Organizations can mitigate the risks of shadow AI by implementing Single Sign-On (SSO) to control access, auditing corporate emails for personal account ties, and monitoring AI usage intensity among employees. This helps ensure that AI tools are used within secure frameworks.

    What role do AI power users play in enterprise risk?

    AI power users, who engage with AI tools at significantly higher rates, contribute to enterprise risk by expanding shadow AI and potentially exposing sensitive data. Their high usage intensity makes them a focal point for monitoring and governance efforts.

    Why is identity important in managing AI risks?

    Identity is crucial in managing AI risks because the identity of the user accessing AI tools determines the level of exposure and risk. Ensuring that users operate under corporate identities helps maintain visibility and control over AI interactions.

    What are some common vulnerabilities found in AI tools?

    Common vulnerabilities in AI tools include those related to browser and IDE extensions, where a significant percentage carry known CVE vulnerabilities. These vulnerabilities can lead to unauthorized access and data breaches if not properly managed.

    Welcome.AI Plus

    Don't just keep up with AI — understand it.

    One click turns any story into a plain-language explanation tailored to your role — then go deeper with a Learn primer. Plus a personalized feed and briefings in your voice.

    • Explain any article
    • Learn the concepts
    • Catch Me Up briefings