Skip to main content

Akamai Report: Securing Agentic AI Requires Shift to Behavioral Governance

Key takeaways

  • Nonhuman identities: Enterprise risk is shifting from human identity management to governing autonomous nonhuman entities.
  • Browser as the unprotected workspace: More than 40% of enterprise users have installed AI-powered browser extensions, with 25% of these extensions altering permissions within 12 months.
  • Chatbot interaction: More than 6% of chatbot conversations contain sensitive information.

CAMBRIDGE, Mass., Sept. 22, 2026 (GLOBE NEWSWIRE)

As organizations deploy agentic AI to execute tasks across APIs and systems, enterprises face a fundamental shift in risk. Akamai (NASDAQ: AKAM) today released its latest State of the Internet (SOTI) Security report focused on emerging AI challenges. Targeted to a CISO audience, Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape explains that securing modern business has evolved from solely identity and access management for people into a challenge of behavioral governance over nonhuman entities.

The report highlights two critical challenges: the difficulty of setting guardrails for autonomous agents, and the speed at which AI models discover vulnerabilities — often outpacing human patch cycles.

Key findings from the SOTI report

  • The Model Context Protocol (MCP) visibility gap: Despite the fact that MCP (the protocol that allows AI agents to interact with multiple software systems) enables AI models to execute autonomous multisystem actions, MCP exposure ranks last among current CISO security priorities. This reveals a critical visibility gap, even as security leaders expect rogue AI agents to become a top cyberthreat by 2030.
  • Chatbot data leaks: More than 6% of enterprise AI chatbot conversations contain sensitive corporate data — primarily personally identifiable information — with 47% of interactions occurring via unmonitored personal accounts.
  • Exploit acceleration: Frontier AI initiatives demonstrate that models can rapidly discover and chain system weaknesses, rendering reactive patching insufficient and mandating real-time edge mitigation.
  • Browser as the unprotected workspace: More than 40% of enterprise users have installed AI-powered browser extensions, with 25% of these extensions altering permissions within 12 months. These tools are 60% more likely to possess known CVEs than standard extensions.
  • Rise of the synthetic customer: As AI agents replace traditional web traffic to drive brand discovery, CISOs must expand protection beyond malware to include generative engine optimization (GEO) metrics: citations, accuracy, sentiment, and bot management.

“AI presents an ‘everything, everywhere, all at once’ moment for the security ecosystem as a whole,” said Boaz Gelbord, Chief Security Officer at Akamai. “You have this triple threat: First, internal usage of AI across the organization, whether that’s AI generated code or leveraging AI productivity tools. Second, you have the integration of AI directly into customer-facing products and cloud workloads, which reshapes your operational risk profile. Third, you have AI-driven attacks targeting the enterprise. Security programs need to adapt to this rapidly evolving reality, and there’s a lot of pressure in the system due to the unprecedented speed of these changes. This is going to be a central topic for boards, customers, and regulators in the foreseeable future.”

“The rise of the agentic web marks a fundamental shift in how business value and operational logic are created,” said Steve Winterfeld, Advisory CISO of Akamai. “As autonomous AI moves from answering queries to executing multistep business strategies, security leadership must evolve alongside it.”

Strategic recommendations for security leaders

To navigate the agentic era, Akamai outlines four core pillars for CISOs in the report:

  1. Shift to adaptive edge governance: Deploy edge native runtime protections, API filters, and isolation mechanisms to neutralize vulnerabilities immediately while back-end patching takes place.
  2. Lock down the browser edge: Establish visibility and behavioral controls inside the browser to secure workforce adoption of unmanaged AI extensions and web-hosted models.
  3. Protect brand authority in a zero-click economy: Implement GEO strategies and machine-readable data layers at the network edge to prevent AI crawlers and synthetic shoppers from hallucinating or misrepresenting corporate brand data.
  4. Match autonomy to verifiability: Grant operational autonomy to AI agents based on how easily their actions can be verified and how reversible a potential failure is, maintaining human-in-the-loop controls for high-stakes actions.

Now in their 12th year, Akamai’s SOTI reports continue to offer critical insights on cybersecurity trends and web performance, drawn from attacks viewed across Akamai’s cybersecurity infrastructure, which handles a significant portion of global web traffic.

About Akamai
Akamai is the cybersecurity and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defense in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform. Global enterprises trust Akamai to provide the industry-leading reliability, scale, and expertise they need to grow their business with confidence. Learn more at akamai.com and akamai.com/blog, or follow Akamai Technologies on X and LinkedIn.

Contacts
Akamai Media Relations
akamaipr@akamai.com

Akamai Investor Relations
invrel@akamai.com

Disclaimer & Cookie Notice

Welcome to GOLDEA services for Professionals

Before you continue, please confirm the following:

Professional advisers only

I am a professional adviser and would like to visit the GOLDEA CAPITAL for Professionals website.

Important Notice for Investors:

The services and products offered by Goldalea Capital Ltd. are intended exclusively for professional market participants as defined by applicable laws and regulations. This typically includes institutional investors, qualified investors, and high-net-worth individuals who have sufficient knowledge, experience, resources, and independence to assess the risks of trading on their own.

No Investment Advice:

The information, analyses, and market data provided are for general information purposes only and do not constitute individual investment advice. They should not be construed as a basis for investment decisions and do not take into account the specific investment objectives, financial situation, or individual needs of any recipient.

High Risks:

Trading in financial instruments is associated with significant risks and may result in the complete loss of the invested capital. Goldalea Capital Ltd. accepts no liability for losses incurred as a result of the use of the information provided or the execution of transactions.

Sole Responsibility:

The decision to invest or not to invest is solely the responsibility of the investor. Investors should obtain comprehensive information about the risks involved before making any investment decision and, if necessary, seek independent advice.

No Guarantees:

Goldalea Capital Ltd. makes no warranties or representations as to the accuracy, completeness, or timeliness of the information provided. Markets are subject to constant change, and past performance is not a reliable indicator of future results.

Regional Restrictions:

The services offered by Goldalea Capital Ltd. may not be available to all persons or in all countries. It is the responsibility of the investor to ensure that they are authorized to use the services offered.

Please note: This disclaimer is for general information purposes only and does not replace individual legal or tax advice.