Discover your interests, together

Real deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Discover your interests, togetherReal deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Half of Enterprise AI Conversations Hide in Personal Accounts—Here’s the Security Risk

Half of Enterprise AI Conversations Hide in Personal Accounts—Here’s the Security Risk
Interest|AI Application Exploration

Shadow AI: The invisible half of enterprise AI use

Shadow AI security refers to employees using AI tools, agents and browser extensions outside corporate oversight, often with personal accounts, creating unmonitored channels where sensitive data, code and decisions move beyond standard authentication, logging and compliance controls and expose organisations to new cyberattack paths and policy violations.

That invisible half is no longer a fringe problem. According to research from Akamai, 47.11 per cent of all enterprise AI conversations occur via personal identities, rather than corporate-managed accounts, which represent 52.89 per cent of usage. In other words, almost half of what staff discuss with AI systems is happening outside the company’s official security perimeter. Security teams cannot meaningfully manage corporate AI risk when they cannot even see where prompts, code and context are going. This is not a tooling gap; it is a governance failure.

For years, cybersecurity assumed systems and users followed defined rules and access models. Artificial intelligence is changing that assumption by introducing fluid, conversational workflows that feel personal—but are, in reality, deeply entangled with corporate data. Ignoring that mismatch between personal identities and corporate accountability is how today’s quiet AI convenience becomes tomorrow’s headline breach in enterprise AI compliance.

Why unmanaged AI use is more dangerous than classic shadow IT

Traditional shadow IT meant an unsanctioned SaaS account; shadow AI means unsanctioned decision-making. Companies are already facing new AI-related cybersecurity risks as employees use many AI tools, rogue browser extensions and vulnerable autonomous agents that expose organisations to fresh attack types. These are not passive apps parked on a server; they are active systems that read, write and act across workflows.

As organisations give agentic systems more autonomy in enterprise workflows, the consequences of failure extend beyond a wrong answer. A single misdirected instruction can disrupt business processes, influence decisions and trigger unintended actions across connected systems. When those agents are tied to personal identities, security teams lose any reliable audit trail. Mistakes blend with misuse, and both fall outside enterprise AI compliance processes.

Greater autonomy also creates new points of vulnerability whenever AI is given access to data, systems and external tools. Akamai’s report shows how this plays out in practice: vibe hacking corrupts local instructions so coding assistants generate insecure code, CursorJacking browser extensions quietly steal API keys and proprietary codebases, and CometJacking prompt injections manipulate local agents to exfiltrate local files and session credentials. These AI-native threats thrive in the shadows where no one is watching.

Half of Enterprise AI Conversations Hide in Personal Accounts—Here’s the Security Risk

Blind spots in monitoring and compliance: when security cannot see, it cannot govern

The core problem with shadow AI is not that people use AI; it is that they do it in ways the organisation cannot approve, monitor or audit. That turns every personal account and unvetted extension into a blind spot, where security monitoring and compliance auditing simply do not reach. Traditional data loss prevention tools were built for file transfers and e‑mail, while sensitive corporate information is now being broken across prompts, personal identities and autonomous agents.

Without clear identity and traceable activity, AI systems can bypass security and compliance controls because of design flaws rather than malicious intent. Like any trusted user or system, AI agents should have a verifiable identity, tightly controlled access to data and systems, and auditable records of the actions they take. Shadow AI throws all three requirements out of the window: no single view of users, no consistent policy enforcement, no reliable logs.

The scale of the blind spot is amplified by AI power users. Akamai notes that much of the risk is concentrated in a small group of highly active staff who drive a large share of AI exposure. When those users rely on personal identities and high-permission extensions—almost 75 per cent of AI extensions request high or critical permissions, and 16.3 per cent contain known vulnerabilities—the organisation’s most AI-dependent workflows operate outside its AI security governance. That is unsustainable.

Why now: AI agents have become colleagues with system access

Corporate AI adoption has shifted from cautious experimentation to a structural part of business operations, but this integration has outpaced traditional security controls. As one Akamai executive put it, “AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels.” Meanwhile, nearly 50 per cent of cybersecurity solutions buyers expect AI to be embedded across the cyber stack within three years. The trajectory is clear: more AI, in more places, with more access.

Security architectures built for predictable applications and human users cannot cope when autonomous agents make decisions, interact with users and act on external tools. Organizations need a unified security architecture that gives consistent visibility and controls across AI and traditional systems, making it easier to identify threats, enforce policies and respond quickly when incidents occur. Without that, every new AI rollout widens the gap between where policy applies and where work actually happens.

Security also cannot stop at deployment. AI systems learn from new data, work in changing contexts and can behave differently over time. Organizations therefore need continuous monitoring to ensure agents stay within defined boundaries and policies remain enforced, including clear ownership, escalation paths and kill switches that can safely contain or stop agents behaving unexpectedly. Technical controls are most effective when backed by effective governance that brings together AI and traditional systems with consistent controls and clear lines of responsibility.

Bring AI back inside the perimeter: authentication and governance first

The uncomfortable truth is that enterprises do not fix shadow AI security with more blocking; they fix it by making managed use easier than unmanaged use. That starts with identity. AI agents and tools must be treated as first‑class actors in identity and access management, each with a verifiable identity, least‑privilege permissions and auditable actions. Enforcing single sign‑on federation across platforms turns personal logins into corporate identities, pulling conversations back into the security perimeter.

Enterprises should define where human intervention is required and who is responsible for decisions models make. High‑risk activities—such as changing customer records, touching financial processes or interacting with production systems—should have stronger guardrails and oversight, while low‑impact tasks can remain largely autonomous. Organizations also need policies that treat context as a security boundary, controlling what AI can see, not only what it can do, to counter manipulation and context poisoning.

In practical terms, security leaders should first focus on high‑risk AI power users, directing monitoring, telemetry and tailored coaching toward the small group driving most interactive prompts. They must also cut down the long tail of unsanctioned tools by continuously discovering niche AI SaaS in use and reducing it through managed alternatives and SSO. If organisations want the benefits of AI without exposing critical data, they need authentication frameworks and AI security governance that treat every AI conversation as enterprise activity—never as a personal side channel.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!