Skip to main content
5% of Your Workforce Uses AI 12x More Than Everyone ElseResearch
3 min readFor CISOs

5% of Your Workforce Uses AI 12x More Than Everyone Else

Understanding the AI Usage Disparity

Akamai's State of the Internet: Enterprise AI Usage Risk Report 2026 highlights a critical issue: the top 5% of AI users in your organization engage with AI models 12 times more than the bottom 50%. This isn't about widespread AI adoption like ChatGPT. It's about a select few integrating unvetted AI tools into essential workflows while your security team focuses on the wrong threats.

The governance gap is significant. Nearly half of enterprise AI interactions (47.11%) occur through personal identities instead of corporate-managed accounts. These power users bypass IT approval, connecting AI extensions, custom GPTs, and third-party agents to production systems via personal Google accounts.

Key Findings

AI extensions are riskier than standard browser extensions. The report shows 16.31% of AI extensions have known CVE vulnerabilities, compared to 10.80% for browser extensions overall. Your security scans likely catch the latter but miss the former.

Shadow AI bypasses your security perimeter. With 47.11% of AI interactions outside corporate-managed accounts, you can't enforce data loss prevention, monitor sensitive data exposure, or revoke access when employees leave. Your CASB sees traffic to openai.com but can't differentiate between benign and risky activities.

Power users create ongoing risk channels. These aren't isolated incidents. The 12x usage rate means top users have integrated AI into daily tasks, building custom agents and automating processes with tools you don't control. Blocking these integrations could disrupt critical business functions.

Volume obscures the real threat. Tracking total AI usage isn't enough. The bottom 50% using AI for simple tasks pose minimal risk. The top 5% connecting unvetted AI tools to critical systems pose significant exposure.

Implications for Your Team

Your current AI governance likely assumes uniform risk. You've probably implemented an acceptable use policy and some monitoring, thinking it's sufficient. But policies don't stop power users who find workarounds.

The 47.11% personal identity usage highlights your visibility gap. Your MDM controls devices, and your SSO manages applications. Yet, when your VP of Sales uses a personal account to connect AI tools to Salesforce, you won't know until a breach occurs.

The CVE vulnerability gap in AI extensions is crucial because these tools often request broad permissions. A compromised extension can exfiltrate any data visible in your web applications. Developers using AI coding assistants risk exposing your entire repository to vulnerabilities.

Or Eshed, Vice President Enterprise Security Product & Engineering at Akamai, puts it well: power users aren't malicious. They're solving real problems with effective tools. Your role is to create safe channels before they resort to unsafe ones.

Action Steps

Identify your power users within 30 days. Analyze authentication logs for AI services like OpenAI, Anthropic, Google AI, and Microsoft Copilot. Cross-reference with CASB or proxy logs to find the top 5% by request volume.

Audit AI extension permissions. If using Chrome or Edge in enterprise mode, inventory installed extensions. Filter for AI-related tools and check against CVE databases. Remove those with critical vulnerabilities and document data access for others.

Establish a shadow AI disclosure program. Survey power users about the AI tools they use, problems they're solving, and data shared. Collaborate to gain better insights and help them find approved alternatives.

Implement identity-aware AI controls. Configure SSO to support AI services, requiring corporate authentication for any AI tool accessing business data. This creates a compliant path that's easier than workarounds.

Segment AI risk by data classification. Don't treat all AI usage equally. Prioritize controls around high-sensitivity workflows by mapping power users to the data they access.

Monitor for API key exposure. Power users connect AI tools via API keys. Scan repositories, wikis, and shared drives for exposed credentials. Set up alerts for new API key creation in high-risk services.

Test incident response for AI scenarios. Conduct tabletop exercises to simulate a power user's personal account compromise. Ensure you can revoke access to AI agents connected to your production environment.

CVE databases

Topics:Research

You Might Also Like