Security teams governing AI by blanket policy are aiming at the wrong target. New usage telemetry from Akamai, the content-delivery and cloud-security firm, shows enterprise AI risk concentrates in the top 5% of power users. They run AI at 12 times the rate of the bottom half of staff, and they increasingly hand work to AI agents operating outside enterprise guardrails. Its Enterprise AI Usage Risk Report 2026 reframes shadow AI as a concentration problem, where a small population carries most of the exposure.
- Nearly half of enterprise AI conversations, 47.11%, run through personal identities rather than corporate-managed accounts, leaving security and compliance teams with no view of them.
- The average employee conversation lasts about five prompts; the top 5% routinely run 18 or more, the mark of AI shifting from quick-draft tool to embedded collaborator.
- 16.31% of AI browser and IDE extensions carry a known CVE vulnerability, against 10.80% of browser extensions overall, and nearly 75% of them request high or critical permissions.
- 14.4% of conversations reach AI through corporate email tied to personal freemium subscriptions, so sensitive prompts can feed public model training even under a corporate login.
The 5% who run AI 12 times harder than everyone else
A small group of AI super-adopters is quietly wiring unvetted tools into core business operations, while security teams keep watch on the four frontier models everyone already knows. Akamai’s telemetry puts numbers to that group. The top 5% touch AI models 12 times as often as the bottom 50%, and their conversations stretch to 18 prompts or more against an average of about five. “AI is no longer just a productivity booster; it is a virtual colleague with keycard access to the company vault,” says Or Eshed, Vice President of Enterprise Security Product and Engineering at Akamai.
The same population drives the exposure. These AI power users expand shadow AI, upload more sensitive data into prompts, and stand up autonomous agents that run inside the enterprise but outside its established controls. That is a data security and data privacy problem dressed as productivity, and it echoes a wider pattern in AI incidents that ran without access controls.
Why personal logins turn shadow AI into an identity gap
Whose identity reaches the model matters more than which model it is. Platforms built with governance controls hold the line: Gemini Enterprise keeps 98.15% of interactions inside corporate identity systems, and Microsoft Copilot for M365 holds 90.55%. Consumer-grade access leaks the other way. DeepSeek, the Chinese AI assistant, runs 99.8% on personal logins, while ChatGPT (61.36%), Claude (61.09%), and Microsoft Copilot Standard (63.92%) are all dominated by personal identities.
The sharper reading is that the most productive AI users and the riskiest ones are the same people. Akamai leans on the broad visibility gap, but its own telemetry says something narrower: risk tracks usage intensity, so the employees a CISO would least want to slow down are exactly where the exposure pools. That makes shadow AI an identity security problem before it is a tooling one, because the fix is visibility into who is using the tools and how hard.
The long tail widens the same way. Employees increasingly bring their own AI tools, or BYOAI, through browser and IDE extensions that IT never reviewed. Akamai already documents these being weaponized: CometJacking uses a poisoned web page to trick an AI agent into exfiltrating local files, and rogue extensions harvest API keys and source code. Blanket AI governance aimed at the four big models never touches this layer.
Profile AI intensity before adversaries map it first
The sequence follows the risk: find the concentration first, close the identity gap that hides it, then contain the agents and extensions operating at the edge.
Rank employees by AI intensity, not headcount – The 5% running 18-prompt conversations at 12 times average volume are where telemetry and coaching should land first. That is where sensitive data and unvetted tooling actually sit.
Force AI onto corporate identity with Single Sign-On (SSO) – Enforcing SSO and blocking unmanaged personal logins closes the 47.11% of conversations running through personal identities. Auditing corporate emails tied to freemium accounts catches the rest.
Govern AI agents and extensions as privileged identities – Treat every autonomous agent as a credentialed identity with least-privilege scope. Screen browser and IDE extensions for the CVE vulnerability rate and the high permissions that a program-level approach to AI governance is built to catch.
None of that requires slowing the super-adopters down. The AI security job now is to watch where AI intensity concentrates, because the same 5% that makes AI pay off is the shadow AI surface an attacker will find first.
Join our LinkedIn group Information Security Community!
