Full Report
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power
Analysis Summary
# Research: The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
## Metadata
- **Authors:** Or Eshed (contributor/spokesperson) et al.
- **Institution:** Akamai Technologies
- **Publication:** Akamai State of the Internet (SOTI) Report
- **Date:** August 24, 2026 (Report Title: *Enterprise AI Usage Risk Report 2026*)
## Abstract
This research identifies a critical concentration of security risk within a small cohort of "AI super-adopters." While enterprise security efforts are currently focused on broad governance of popular Large Language Models (LLMs) like ChatGPT, the report reveals that the top 5% of users interact with AI at 12 times the rate of the average employee. These power users are increasingly integrating unvetted, "long-tail" AI tools and browser extensions into core business operations, creating significant blind spots through personal identity logins and vulnerable third-party integrations.
## Research Objective
The study aims to quantify the disparity in AI usage across the enterprise and identify the specific security risks associated with high-frequency AI adoption, particularly focusing on "Shadow AI" and the erosion of the corporate security perimeter.
## Methodology
### Approach
The research utilized a multi-dimensional approach combining real-world telemetry data, behavioral analysis of prompt patterns, and vulnerability scanning of AI-related software components.
### Dataset/Environment
- Real-world usage and telemetry data from Akamai’s global enterprise customer base.
- Analysis of browser extension permissions and CVE (Common Vulnerabilities and Exposures) databases.
- Comparison between midsize and large enterprise environments.
### Tools & Technologies
- Akamai telemetry and threat analysis platforms.
- Identity management tracking (Corporate vs. Personal accounts).
- Extension vulnerability scanners.
## Key Findings
### Primary Results
1. **The 5% Rule:** The top 5% of AI power users engage with models 12x more frequently than the bottom 50%, representing a high concentration of risk.
2. **Deep Integration:** Power users average 18+ prompts per conversation (compared to the standard 5), suggesting AI is being used for complex, multi-step business logic rather than simple drafting.
3. **The Identity Gap:** 47.11% of enterprise AI conversations occur through personal identities, bypassing corporate governance.
4. **Shadow Extensions:** 17.7% of employees in midsize firms use AI browser extensions, with nearly 75% of these tools requesting "high or critical" permissions.
### Supporting Evidence
- **Platform-specific leakage:** DeepSeek (99.8%) and ChatGPT (61.36%) are dominated by personal accounts, whereas Gemini Enterprise (98.15%) remains largely within corporate boundaries.
- **Vulnerability Data:** 16.31% of AI-related browser extensions contain known CVEs, a rate significantly higher than the 10.80% average for standard extensions.
### Novel Contributions
- The identification of **"BYOAI" (Bring Your Own AI)** as a successor to BYOD, specifically highlighting the risk of niche, task-specific AI tools over "Frontier" LLMs.
- The concept of the **"AI Outsized Shadow,"** where a tiny fraction of the workforce dictates the vast majority of the attack surface.
## Technical Details
The research highlights a critical technical failure in "freemium" models: **14.4% of conversations** occur via corporate email addresses linked to personal subscriptions. Technically, this means that even if a user logs in with a `[email protected]` address, if the license is not enterprise-managed, the data injected into prompts is frequently opted-in for public model training by default, leading to permanent data exposure.
## Practical Implications
### For Security Practitioners
- Shift focus from broad AI bans to targeted monitoring of "power users" who handle the highest volume of sensitive data.
- Inventory browser and IDE extensions, as these operate with high-level permissions and often contain unpatched vulnerabilities.
### For Defenders
- **Actionable Insight:** Prioritize the implementation of Enterprise-grade licenses for ChatGPT/Claude to force data into managed silos.
- **Actionable Insight:** Audit browser extensions specifically for those requesting "read and change all data on all websites" permissions.
### For Researchers
- Investigate the security of autonomous AI agents that operate via API or extensions without human-in-the-loop oversight.
## Limitations
- The report primarily reflects users within the Akamai ecosystem, which may skew toward specific industries.
- The distinction between "benign" high-volume use and "risky" high-volume use requires further qualitative analysis of prompt content.
## Comparison to Prior Work
Unlike earlier 2023-2024 reports that focused on the *breadth* of AI adoption (how many people use it), this 2026 research focuses on the *depth* and *density* of usage, highlighting that the risk is not evenly distributed but concentrated in a "power user" elite.
## Real-world Applications
- **Risk Profiling:** Security Operations Centers (SOCs) can use these metrics to create "AI Risk Profiles" for different departments (e.g., Engineering vs. HR).
- **Vendor Management:** Provides a framework for vetting which AI tools require strict enterprise identity integration vs. those that can be blocked.
## Future Work
- Analysis of how AI-powered attacks are specifically targeting these 5% power users (e.g., via prompt injection or malicious extensions).
- Long-term tracking of data leaks originating from "freemium" corporate accounts.
## References
- Akamai State of the Internet: *Enterprise AI Usage Risk Report 2026*
- Related: *SANS Survey on AI Adoption Governance 2026* (hXXps://thehackernews[.]uk/sans-insights-2026)