Akamai report warns that employees’ personal AI accounts and unmanaged tools are fragmenting sensitive corporate data across millions of prompts, creating a major blind spot for governance, compliance and security teams.

Nearly half of all conversations employees have with artificial intelligence (AI) tools at work are taking place through personal accounts instead of company-managed ones, creating a growing security and compliance risk for businesses, according to Akamai’s Enterprise AI Usage Risk Report 2026.
The report found that 47.11% of enterprise AI conversations happen through personal identities, while only 52.89% take place through corporate-managed accounts. According to the report, this creates a major governance gap because organisations lose visibility over where business data is being shared, how long it is stored and whether it could be used to train public AI models.
According to the report, nearly 20% of employees now use AI every week, while more than 30% use it every month, highlighting how quickly AI has become embedded in workplace operations.
The report warns that AI has become a part of everyday work, with employees using it to write code, analyse documents, summarise meetings, generate content and automate repetitive tasks. While this has boosted productivity, it has also introduced entirely new security risks that traditional cybersecurity tools were never designed to address.
“AI continuously consumes, generates, stores, and acts upon enterprise data,” the report said, adding that organisations are still struggling to understand where their data goes, who has access to it and how AI systems could be abused.
According to the report, the biggest AI security concern is no longer employees using AI tools, but the information they share with them.
Unlike traditional data leaks that happen through emails or file transfers, AI allows employees to share information through prompts, screenshots, copied text, source code, conversations and generated responses. While each interaction may appear harmless on its own, together they can expose sensitive business information.
“The biggest AI security risk is no longer employees who access AI, it is employees who share sensitive business data with AI,” the report said.
The report also found that 14.4% of enterprise AI conversations made using corporate email addresses were linked to personal AI subscriptions instead of enterprise licences. According to Akamai, this means employees may believe they are working in a corporate environment even though the information they share could be processed under consumer AI services that fall outside enterprise security controls.
The report identifies a new category of workers it calls “AI power users”, employees who rely heavily on AI throughout their daily work.
While nearly 20% of employees use AI every week and more than 30% use it every month, a relatively small group accounts for a disproportionate share of AI activity. The average employee participates in 36 AI conversations, but the top 5% of users generate at least 144 conversations. These employees are also more likely to upload files, share business information and use AI to make operational decisions.
Rather than asking whether employees use AI, organisations should identify “who depends on it, how deeply frontier models are embedded in daily workflows, and where the highest concentration of risk may lie,” the report said.
The report also flags AI browser extensions and autonomous AI agents as emerging security concerns.
According to Akamai, nearly 75% of AI browser extensions request high or critical permissions, giving them broad access to browser data and user sessions. More than 16% of AI extensions have known software vulnerabilities, while almost 42% request scripting access—far higher than ordinary browser extensions.
The report highlights new attack techniques such as “CursorJacking”, in which a malicious browser extension can steal AI credentials and API keys, and “CometJacking”, where attackers manipulate AI-powered browsers through prompt injection instead of directly targeting users.
As enterprises increasingly deploy AI agents capable of taking actions on behalf of employees, the report says security strategies will also have to evolve.
“AI security is no longer about controlling access to a handful of applications. Organisations must govern AI interactions, data flows, identities, extensions, and autonomous agents across an increasingly fragmented AI ecosystem,” the report said.
“AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels,” said Or Eshed, Vice President, Enterprise Security Product and Engineering of Akamai. “Traditional data loss prevention tools were built for an era of file transfers and emails. Today, sensitive corporate data is being systematically fragmented across millions of fluid prompts, unmanaged personal accounts, and autonomous AI agents. Security leaders must pivot from trying to block AI to continuously governing how it operates at the interaction level.”