A recent report from Akamai highlights significant cybersecurity challenges faced by enterprises, particularly noting a staggering 300% increase in bot traffic over the past year, attributed largely to advancements in artificial intelligence (AI). The findings originate from the company’s latest publication, the State of the Internet report, which is grounded in threat intelligence compiled from its extensive global security infrastructure and network operations.
The report, published on September 22, draws attention to a troubling trend within the enterprise sector: as AI technology continues to evolve, it is transforming application programming interfaces (APIs) into the primary attack surface for modern businesses. This assertion is underscored by a shocking 113% rise in daily API attacks recorded between 2024 and 2025. Alarmingly, 87% of organizations surveyed reported experiencing an API-related security incident within 2025, a notable increase from 76% in 2022.
Further complicating the threat landscape are AI browser extensions, which are increasingly adopted by enterprise users. According to the report, 40% of these users have installed such tools; however, a concerning 25% have modified their permissions within a year, thereby significantly heightening their risk profile. This trend poses a unique vulnerability, given the potential for such extensions to access sensitive data and systems.
Digging deeper into the concerning data, Akamai found that an estimated 6% of conversations held by chatbots could contain sensitive corporate information. This statistic is particularly alarming when considering that nearly half (47%) of AI-related exchanges on enterprise devices occur through personal identities and accounts. Such practices prevent IT departments from effectively tracking interactions, leaving organizations exposed to data breaches and unauthorized disclosures.
The report also illuminates the accelerated pace of vulnerability research and exploit development stimulated by AI. Additionally, the emergence of malicious computerized processes (MCPs) presents considerable threats. Notably, MCP exposure ranks at the bottom of current Chief Information Security Officers’ (CISOs) security priorities, despite predictions that rogue AI agents will evolve into a predominant cybersecurity threat by 2030. This discrepancy illustrates a worrisome blind spot in enterprise risk assessment and management.
Akamai elaborated on the security issues surrounding MCP, noting that it provides AI models with the “hands” needed to perform autonomous actions. However, this capability also invites significant security challenges by blurring the distinctions between data and code. Such vulnerabilities could permit adversaries to exploit these models through methods like prompt injection or cross-server attacks, potentially compromising large language models (LLMs).
The rapid proliferation of AI agents within organizations indicates a shift away from traditional network breaches toward more sophisticated attack vectors. Akamai emphasized that attackers are no longer dependent solely on breaching networks. Instead, they exploit avenues such as indirect prompt injections, manipulate model contexts, or leverage unmonitored browser extensions. These tactics enable adversaries to compromise an agent’s logic and execute unauthorized, high-impact actions, underlining the urgent need for robust cybersecurity measures.
In light of these emerging threats, Akamai offers several recommendations for CISOs and IT leaders aimed at mitigating AI-related risks. The report advocates for enhanced adaptive edge governance, which encompasses edge-native runtime protections, API filters, and isolation mechanisms designed to neutralize risks before they can escalate into exploitation.
Furthermore, the need for improved visibility and behavioral controls within browser environments is emphasized. Such measures are essential for minimizing data exposure and ensuring that organizations can maintain better oversight of their digital interactions.
Lastly, the report advises restricting the autonomy of AI agents, proposing that organizations evaluate how easily the agents’ actions can be verified and the reversibility of potential failures. Keeping human oversight in critical, high-risk actions ensures that there is accountability and a safeguard against unauthorized actions executed by AI.
In conclusion, as enterprises navigate an increasingly complex threat landscape amplified by advancements in AI, proactive measures and strategic governance will be essential in safeguarding organizational assets. The rise of AI-driven attacks illuminates an urgent call to arms for cybersecurity leaders, emphasizing the importance of re-evaluating traditional security paradigms in favor of more adaptive and vigilant strategies that can respond effectively to evolving threats.

