Akamai warns that the rapid acceleration of AI is surpassing existing security measures, with more than half of companies vulnerable to emerging cyber threats through shadow AI, malicious browser extensions, and sophisticated attack techniques targeting APIs and AI-driven workflows.
Akamai Technologies says the speed of AI adoption is now outpacing the security controls designed to contain it, leaving more than half of companies exposed to new forms of cyber risk. In a report released on Monday, the cybersecurity and cloud group warned that unapproved “shadow AI”, highly capable power users and hidden browser extensions are creating fresh attack paths into organisations’ most sensitive systems and data.
The company’s researchers identified three techniques this year that they say reflect how attackers are adapting to AI-driven workplaces. Vibe hacking targets the files that coding tools use as instructions, with the aim of steering AI systems towards unsafe or attacker-controlled outputs. CursorJacking relies on malicious browser extensions to steal material such as API keys, source code and chat logs from tools like Cursor. CometJacking uses booby-trapped web pages to issue hidden commands to AI agents and extract files, emails and login details from agentic browsers such as Perplexity’s Comet AI.
Or Eshed, Akamai’s vice president for enterprise security product and engineering, said AI has become far more than a productivity aid, describing it as a collaborative partner with direct access to a company’s “crown jewels”. He argued that many data loss prevention systems were built for a world dominated by file transfers and email, not one in which sensitive information is fragmented across prompts, personal accounts and autonomous agents. Akamai says security teams should move away from attempts to block AI outright and instead manage how it behaves at the interaction layer.
The warning comes as Akamai’s wider research points to AI becoming a major force multiplier for attackers, with APIs emerging as a primary target surface. The company said its 2026 Apps, APIs and DDoS State of the Internet report found a 104% rise in Layer 7 DDoS attacks over two years and said 87% of organisations surveyed experienced an API-related security incident in 2025. Akamai has also said commerce has become the main target for AI bot attacks and agentic fraud, while its work with NVIDIA on AI factories and its new agentic security framework suggest the company is pushing to embed controls closer to the infrastructure and decision-making layer.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





