Live1h agoNTUC's first job security chief targets two groups as AI disruption reshapes work
← Back to stories

Nearly Half of Enterprise AI Use Happens Behind IT's Back, Akamai Report Warns

Source: Techgoondu

Singaporean companies have spent the past year racing to put AI into everyday work — and that is exactly why a new warning from Akamai deserves attention. The content-delivery and security firm's Enterprise AI Risk Report found that nearly half of all enterprise AI conversations now happen through personal...

Nearly Half of Enterprise AI Use Happens Behind IT's Back, Akamai Report Warns
SGAI Daily

Singaporean companies have spent the past year racing to put AI into everyday work — and that is exactly why a new warning from Akamai deserves attention. The content-delivery and security firm's Enterprise AI Risk Report found that nearly half of all enterprise AI conversations now happen through personal identities rather than corporate-managed accounts, meaning a large share of the AI use inside organisations is invisible to the IT, security and compliance teams responsible for protecting them.

The numbers paint a picture of adoption outrunning control: 47.11 per cent of enterprise AI conversations occur via personal accounts, and the risk is concentrated among a small group of "AI power users" who drive a disproportionate share of exposure. Akamai's researchers also flagged three new AI-native attack methods discovered this year — vibe hacking, which tampers with local instruction files to steer AI coding assistants into generating insecure code; CursorJacking, where rogue browser extensions silently harvest API keys and conversation history; and CometJacking, which uses indirect prompt injection on public webpages to manipulate agentic browsers such as Perplexity's Comet AI.

The report's broader point is that traditional security tools were built for a different era. Data-loss-prevention systems designed for file transfers and email are ill-equipped for a world where sensitive corporate information is fragmented across prompts, personal accounts and autonomous agents. "AI is no longer just a productivity booster; it is a collaborative colleague with direct access to the corporate crown jewels," said Or Eshed, Akamai's vice-president for enterprise security product and engineering. The extension problem alone is stark: almost 75 per cent of AI browser extensions request high or critical permissions, and 16.3 per cent contain known vulnerabilities.

Akamai's prescriptions are less about blocking AI than governing how it operates: focus monitoring on high-risk power users, enforce single sign-on federation to shrink shadow AI, inspect the AI interaction layer in real time, treat browser and IDE extensions as highly privileged software, and give autonomous agents strict least-privilege boundaries with behavioural monitoring. The direction mirrors where Singapore's own regulatory thinking has been heading, from IMDA's AI governance frameworks to MAS guidance on AI agents in finance — the message being that security must shift from perimeter defence to continuous governance of AI behaviour.

Why it matters for Singapore: Singapore's enterprises are among Asia's most aggressive AI adopters, which puts them on the front line of the shadow-AI problem. With agentic AI moving from pilots into production across banking, logistics and government-adjacent industries here, the line between approved and unapproved AI use becomes a first-order security issue. For local CISOs, the report doubles as a practical checklist — and a reminder that Singapore's AI governance conversation is no longer just about ethics frameworks, but about who inside the organisation can reach the crown jewels.

Your daily AI edge in Singapore: in <5 minutes.

We do the reading so you don't have to. Get the essential TL;DR on local AI moves delivered to your inbox every morning.