IT Brief India - Technology news for CIOs & IT decision-makers
India
Akamai warns of blind spots in workplace agentic AI

Akamai warns of blind spots in workplace agentic AI

Tue, 22nd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Akamai has published research on security risks linked to agentic AI in the workplace, pointing to weak visibility over browser-based AI tools and autonomous software agents.

Its latest State of the Internet security report says more than 40% of enterprise users have installed AI-powered browser extensions. It also says 25% of those extensions changed their permissions within 12 months, raising questions for security teams trying to monitor how staff use AI tools.

The report examines how corporate security risks are changing as businesses adopt AI systems that can act across multiple applications and interfaces rather than simply respond to prompts. Akamai argues this shifts the focus from managing human logins and access rights to monitoring the behaviour of non-human identities such as software agents and automated tools.

One of the main concerns is what the report describes as a visibility gap around the Model Context Protocol, or MCP. The protocol allows AI agents to interact with several software systems, yet exposure to MCP ranks lowest among current security priorities for chief information security officers, according to Akamai.

That matters because autonomous agents can carry out multistep tasks across systems with limited direct human involvement. The report says security leaders already expect rogue AI agents to become a leading cyber threat by the end of the decade, even though attention to MCP remains comparatively low.

Data exposure

Akamai's research also highlights how sensitive information is handled in chatbot exchanges. More than 6% of enterprise AI chatbot conversations contain sensitive corporate data, most commonly personally identifiable information, the report says.

Nearly half of those interactions, or 47%, took place through unmonitored personal accounts. That suggests another blind spot for employers trying to apply data protection rules consistently across workplace systems and consumer-grade services used by staff.

The findings extend beyond internal use. AI bot traffic rose by 300% in 2025, with the commerce sector seeing the heaviest impact, as automated systems increasingly interact with online services once dominated by human users.

The report also puts a financial figure on one part of the problem, saying the average annual cost for an enterprise resolving API breaches has reached USD $700,000. That underscores the expense of securing the software connections that modern AI tools often rely on.

Faster exploits

Another theme in the research is the speed at which AI models can identify and connect weaknesses in systems. Akamai says advanced AI initiatives show models can discover exploitable flaws quickly enough to outpace standard human-led patching cycles.

That weakens a security approach based mainly on fixing software after vulnerabilities are found. The report argues that companies need more immediate protections at the network edge and inside user environments if they are to contain threats before back-end fixes are deployed.

AI-powered browser extensions are also 60% more likely than standard extensions to contain known common vulnerabilities and exposures, or CVEs, according to Akamai. That adds to concern over the browser becoming what the report describes as an unprotected workspace, especially as employees adopt AI assistants and productivity tools without central oversight.

Boaz Gelbord, chief security officer at Akamai, said the spread of AI is reshaping security challenges on several fronts at once.

“AI presents an 'everything, everywhere, all at once' moment for the security ecosystem as a whole,” Gelbord said. “You have this triple threat: First, internal usage of AI across the organization, whether that's AI generated code or leveraging AI productivity tools. Second, you have the integration of AI directly into customer-facing products and cloud workloads, which reshapes your operational risk profile. Third, you have AI-driven attacks targeting the enterprise. Security programs need to adapt to this rapidly evolving reality, and there's a lot of pressure in the system due to the unprecedented speed of these changes. This is going to be a central topic for boards, customers, and regulators in the foreseeable future.”

Governance shift

The report frames the wider issue as a governance problem rather than a narrow access-control question. Instead of asking only who is authorised to enter a system, security teams are being pushed to decide which automated actions should be allowed, how those actions can be verified, and how quickly harmful behaviour can be stopped.

Akamai recommends tighter browser-level controls, closer scrutiny of AI agents operating through APIs, and human review for higher-risk actions. It also argues that companies need to weigh autonomy against verifiability, granting more independence only where the effects of an AI action can be checked easily and reversed if necessary.

Steve Winterfeld, advisory CISO at Akamai, said the change reflects a broader shift in how digital activity is organised.

“The rise of the agentic web marks a fundamental shift in how business value and operational logic are created,” Winterfeld said. “As autonomous AI moves from answering queries to executing multistep business strategies, security leadership must evolve alongside it.”