top of page

Akamai’s Shadow AI Warning Exposes a Corporate Control Gap

Akamai has raised a stark warning: nearly half of enterprise users access AI tools, while much of that activity can escape established corporate controls.

The finding surfaced through a clipped Google News headline linking to an Akamai release distributed by GlobeNewswire. That listing omitted the object after “bypasses,” leaving the central claim incomplete. Akamai’s wider research, however, identifies the missing conflict clearly: productive AI use increasingly happens outside managed identities, approved accounts, and visible security channels.

This is not simply another survey showing that workers like ChatGPT. It describes a collision between employee demand and the control model enterprises built for conventional software. OpenAI, Google, Anthropic, Microsoft, and hundreds of smaller providers have made advanced tools available through an ordinary browser.

The security question has therefore moved. Companies no longer need only to decide which AI systems they approve. They must determine whether sensitive information reaches any model through personal accounts, pasted text, uploads, extensions, or embedded features.

The reversal is uncomfortable. Enterprises have spent years centralizing identity, access, and software procurement. AI adoption is now decentralizing all three from inside the browser.

The Headline Points to a Browser-Sized Blind Spot

Akamai’s warning concerns the path employees use to reach AI, not simply the number of people experimenting with it.

The available evidence comes partly from LayerX, the browser-security company Akamai acquired. LayerX collects telemetry about activity inside web applications, including logins, uploads, pasted text, and movement between corporate and personal accounts.

Its published research found that 45% of enterprise users accessed generative AI from corporate endpoints. ChatGPT represented 92% of observed AI usage in that dataset.

Those figures do not mean 45% of every employee worldwide uses ChatGPT. They describe activity among the organizations and endpoints covered by the vendor’s telemetry. That distinction matters when interpreting any security-company report.

The same research found a more consequential pattern. Forty percent of files uploaded to AI tools contained sensitive corporate information. Twenty-two percent of pasted text also contained sensitive material.

Those percentages measure inspected transfers, not confirmed breaches. A sensitive upload can be authorized, properly protected, and necessary for legitimate work. It can also move through a personal account that the employer cannot audit.

LayerX reported that 32% of data transfers between corporate and personal accounts occurred through AI platforms. Its broader AI usage findings place the browser at the center of that exposure.

That helps explain the truncated “bypasses” language in the Google News listing. The relevant controls include corporate identity, single sign-on, approved-account rules, data-loss policies, and normal software review.

Single sign-on, commonly called SSO, lets an employer manage access through one corporate identity. Personal AI accounts avoid that identity layer even when employees use them on company devices.

Traditional software governance assumes that IT can discover an application, approve it, provision access, and later remove that access. Consumer AI tools compress adoption into a visit, login, and prompt.

No installation request is necessary. A worker can open a chatbot, authenticate with a personal email address, and paste a customer document within minutes.

Embedded AI complicates discovery further. Generative features now appear inside productivity suites, design tools, meeting platforms, customer systems, and browser extensions. Employees may not regard every feature as a separate AI service.

Akamai defines shadow AI as AI use without the knowledge, approval, or oversight of IT, security, or compliance teams. That includes more than unauthorized chatbots.

A developer might submit proprietary code to a personal coding assistant. A marketer might upload a customer list to generate campaign segments. A manager might connect an agent to cloud documents without reviewing its permissions.

Each action can look like ordinary browser traffic. The risky element is the context, including the user’s identity, the information transferred, and the provider’s contractual handling of that information.

A firewall can see a connection to an allowed domain. It does not automatically know whether the employee used a managed enterprise account or a private account.

This is the central change behind the report. Enterprise AI has become common enough that governing access by application name alone no longer provides adequate visibility.

Why Enterprise AI Controls Are Losing the Adoption Race

Employees bypass approved paths when consumer AI offers faster access, broader features, or fewer procedural obstacles.

Shadow AI often begins with a practical task rather than malicious intent. A worker needs to summarize a meeting, revise a proposal, inspect code, or compare several documents.

The approved assistant may lack the preferred model, accept fewer file types, or remain unavailable to that department. Procurement and security reviews can also move more slowly than the work.

A personal chatbot offers immediate access. The employee sees a productivity tool, while the security team sees an unreviewed data processor.

That incentive gap explains why bans produce limited results. Blocking one service can redirect users toward another provider, a mobile device, a personal browser profile, or an embedded feature.

An effective policy must address the reason employees chose the unofficial route. Otherwise, enforcement treats the visible symptom while preserving the demand.

Akamai’s own guidance says shadow usage drops when enterprises provide capable approved tools with contractual protections, audit logging, and SSO integration. The secure route must still solve the user’s problem.

The historical comparison is shadow IT, which grew as departments bought cloud applications without central approval. Security teams eventually adopted cloud access brokers, application discovery, and more flexible procurement.

AI raises the stakes because the transaction often contains business data. A conventional unauthorized application might store a new project schedule. A chatbot interaction can immediately transmit source code, legal language, customer records, or an unreleased strategy.

Generative systems also create outputs that workers may reuse without documenting their origin. That introduces questions about accuracy, intellectual property, bias, and accountability alongside data exposure.

The same AI service can present different risk profiles depending on the account. An enterprise contract may provide retention controls, administrative logs, and restrictions on model training.

A personal account may lack those protections. Security teams therefore need to distinguish identities and sessions, not merely recognize the destination domain.

This difference pressures chief information officers and security leaders from opposite directions. CIOs are expected to increase AI adoption, while security leaders must reduce uncontrolled data movement.

Business leaders add another demand: measurable productivity. If the official environment slows employees without improving outcomes, shadow use becomes a predictable response.

That conflict appears beyond Akamai’s customer base. Axios reported that companies commonly had 67 generative AI tools in use, with 90% lacking proper licensing or approval. Its shadow AI reporting described security vendors racing to close the visibility gap.

Again, vendor measurements vary by customer population, collection method, and definition. One company may count domains, while another counts applications, accounts, users, or individual sessions.

The direction is more reliable than any single percentage. Employees have many routes to AI, and enterprise inventories consistently capture only part of that activity.

The pressure does not stop with security teams. Legal departments must determine which providers can process regulated or confidential information.

Privacy teams need to understand where prompts and files travel. Procurement teams must review a growing list of AI features, including functions added to products already under contract.

Managers also need rules for generated output. An approved tool does not make every answer accurate, and an enterprise agreement does not validate every decision made with its output.

The control problem therefore has two layers. Enterprises must govern information entering AI systems and decisions leaving them.

Blocking unsanctioned accounts addresses only the first layer. It does not establish when a generated answer needs review, which sources the system used, or who remains accountable.

That broader governance burden explains why the adoption race feels uneven. A worker can begin using AI immediately, while a complete enterprise control structure requires cooperation across several departments.

The Real Contest Is Managed AI Versus Useful AI

The primary opponent is not Akamai versus another security vendor; it is managed AI versus the tools employees find most useful.

Enterprises sometimes frame security and productivity as opposing goals. That framing encourages blunt controls, including complete blocks, narrow allowlists, and lengthy approval procedures.

Employees then encounter a simple choice. They can wait for an approved workflow or finish the task with a familiar consumer service.

The better contest concerns product quality. A managed assistant must offer enough capability, context, speed, and reliability to become the default choice.

Context is especially important. Knowledge workers need AI to operate on documents, conversations, project history, and specialized internal material.

That access also creates risk. Broad permissions can expose information that a worker did not realize they could retrieve through an AI interface.

A managed knowledge environment should preserve existing access boundaries. It should also show which sources supported an answer and keep retrieval within authorized material.

This is where a personal knowledge base can reduce ad hoc copying between business systems and public chatbots. Local or controlled capture does not eliminate governance duties, but it can narrow unnecessary transfers.

Security controls must operate at the moment of interaction. Network tools remain useful, yet they can miss distinctions hidden inside encrypted browser sessions.

Browser-level controls can identify the active account, inspect an upload, and recognize a paste before information leaves the endpoint. They can then warn, redact, block, or log the action.

Akamai’s Workforce Protector, formerly LayerX, reflects that approach. According to Akamai, it governs user and agent behavior inside applications rather than relying only on perimeter traffic.

The company has a commercial interest in defining the browser as the critical enforcement point. Buyers should examine that claim alongside endpoint, network, identity, and data-security alternatives.

No single layer sees every route. A browser extension cannot govern an unmanaged phone that never touches the corporate environment.

Network controls can identify destinations but may lack detailed session context. Endpoint agents can inspect device activity but may not understand every application’s internal semantics.

Identity controls establish who signed in, yet they do not automatically determine whether each prompt contains restricted information. Data classification can recognize sensitive content but depends on accurate labels and coverage.

The practical architecture combines these signals. It connects identity, device posture, destination, account type, content sensitivity, and the requested action.

Consider an employee summarizing a public product announcement. A personal chatbot presents limited organizational risk because the input is already public.

Now consider the same employee pasting customer support transcripts. The destination may remain identical, but privacy, retention, and contractual requirements change the decision.

File inspection alone also misses copy-and-paste behavior. LayerX’s measurements indicate that pasted text forms a meaningful exposure channel, even when employees never upload a document.

Agents add another dimension. An agent can retrieve information, call external services, update records, and repeat actions without a separate human gesture each time.

That turns permission design into an operational security issue. A chatbot answers a request, while an agent can cause a change.

Akamai’s 2026 API security study surveyed 1,840 security leaders and practitioners across ten countries. It found that 80% used web application firewalls, while only 35% used dedicated API security tools.

APIs are interfaces that let software systems exchange data and commands. They form the connective layer between agents, models, databases, and business applications.

An unauthorized chatbot session can leak information. An overprivileged agent can also modify a ticket, issue a refund, send a message, or query a restricted system.

Managed AI must therefore compete on more than model quality. It needs useful integrations, narrow permissions, reliable logging, and human approval for consequential actions.

If those safeguards make every task painful, employees will avoid them. If they disappear completely, the organization cannot distinguish convenience from unacceptable exposure.

The winning design makes common low-risk actions easy. It reserves additional friction for sensitive data, unusual destinations, personal accounts, and high-impact commands.

That is a product challenge as much as a policy challenge. Enterprises cannot train their way out of interfaces that consistently reward unsafe shortcuts.

What the Google News Headline Does Not Establish

The underlying risk is credible, but the clipped headline does not independently prove that nearly half of all enterprise AI activity bypasses controls.

The Google News entry truncates the claim immediately after “bypasses.” It does not identify the control, measurement period, sample, geography, or denominator.

Those omissions prevent a precise interpretation. “Nearly half of enterprise AI use” might refer to users, accounts, sessions, endpoints, organizations, uploads, or another measured category.

Publicly indexed Akamai and LayerX materials support several adjacent findings. They do not make every possible reading of that sentence interchangeable.

LayerX reported that 45% of enterprise users accessed AI tools on corporate endpoints. It separately reported sensitive content in 40% of uploaded files and 22% of pasted text.

It also reported extensive use of personal identities in software services. Its 2025 identity research found that 40% of SaaS access used personal credentials and 67% bypassed SSO.

Those statistics describe different populations and behaviors. Combining them into one sweeping statement would create a number the research did not publish.

The first caution, therefore, concerns denominator discipline. Readers should ask what was counted before treating a percentage as a universal adoption rate.

The second caution concerns vendor telemetry. Security providers often analyze activity from customers that already deployed their products.

Those organizations may differ from companies without comparable monitoring. Their industries, sizes, policies, and risk profiles can shape the measured results.

Telemetry still offers value because it observes behavior rather than relying only on memory. However, it does not automatically represent every enterprise or employee.

Surveys carry a different limitation. Respondents can misunderstand definitions, underreport prohibited activity, or represent organizations with unusually mature AI programs.

Independent research should therefore compare several forms of evidence. Useful sources include endpoint telemetry, network logs, identity records, employee surveys, incident reports, and regulatory disclosures.

The third caution concerns the word “bypass.” A personal login can bypass corporate identity management without bypassing every security control.

The endpoint might still run data-loss prevention software. The network might still block certain destinations. The provider may still offer consumer privacy settings.

Conversely, an approved account can create risk even when it passes through SSO. Excessive permissions, weak retention rules, prompt injection, and inaccurate output remain possible.

This distinction prevents a simplistic conclusion. Managed does not mean safe, and unmanaged does not mean a confirmed breach.

Akamai’s commissioned 2025 enterprise AI study illustrates the wider concern. Among 400 director-level global respondents, 63% identified security concerns as a leading AI application challenge.

The same study found that 55% cited technology or platform gaps, while 55% cited compliance and regulatory concerns. Forty-five percent worried about applications failing to function as intended.

Those findings show that governance pressure extends beyond shadow accounts. Organizations are concerned about performance, reliability, compliance, and brand consequences even inside formal deployments.

The fourth caution concerns causation. Shadow AI is often described as employee misconduct, but the available evidence does not support one universal motive.

Some employees intentionally ignore rules. Others encounter unclear policies, missing tools, slow approvals, or AI features embedded in products that IT already approved.

Leaders can also create contradictory incentives. They demand rapid AI adoption while evaluating teams on speed, then impose restrictions that prevent employees from reaching those targets.

A credible analysis must hold both sides together. Users remain responsible for handling sensitive information, while organizations remain responsible for offering workable approved paths.

Regulatory forecasts also require care. Gartner has predicted that 40% of enterprises will experience an AI-related security or compliance incident by 2030 through unauthorized shadow AI use.

As summarized in coverage of the Gartner forecast, that figure concerns projected incidents. It is not a current breach count.

Forecasts can identify exposure, but they do not confirm that a particular organization has lost data. Buyers should resist turning risk estimates into claims about completed attacks.

The incomplete feed item creates one final editorial problem. Google News is an aggregation layer, not the underlying evidence.

The direct release, methodology, and complete report should control the wording. Until the full claim and denominator are visible, “nearly half” deserves attribution rather than presentation as an established universal fact.

That does not make the story unimportant. It makes the verification gap part of the story.

Three Signals Will Show Whether Enterprises Regain Control

The next phase will be measured by account visibility, sensitive-data movement, and the permissions granted to AI agents.

The first signal is the share of AI activity tied to managed corporate identities. Enterprises should track whether employees move from personal accounts to approved services over time.

A falling personal-account share would strengthen the case that useful enterprise tools can reduce shadow AI. A flat or rising share would show that policies and licenses are not changing behavior.

This metric should be segmented by department and task. Developers, marketers, analysts, support teams, and executives use different tools and handle different information.

A company-wide average can hide concentrated exposure. One small group may create most sensitive transfers because its work involves code, customer records, or legal documents.

Identity measurement also needs a clear denominator. Organizations should report users, sessions, transfers, and applications separately.

The second signal is the rate of sensitive data moving into AI services. That includes pasted text, file uploads, form entries, browser extensions, and API requests.

A useful measure distinguishes blocked attempts from completed transfers. It also separates approved enterprise accounts from personal and unknown identities.

If completed sensitive transfers decline while legitimate AI use grows, governance is improving. If only blocked attempts rise, employees may simply be encountering more friction.

Security teams should also examine where users go after a block. A warning that redirects work toward an approved assistant is more useful than one that ends the workflow.

The underlying objective is not to produce a larger count of policy violations. It is to reduce unnecessary exposure while preserving valuable work.

Organizations can support that objective by giving employees controlled ways to search, summarize, and connect their own materials. A local second brain can limit repeated copying across unrelated services.

The third signal is the permission profile assigned to AI agents. Companies need an inventory showing which systems each agent can read, write, and trigger.

Read-only access presents one risk level. Permission to send messages, update financial records, change code, or approve transactions presents another.

Enterprises should watch for default access reductions, shorter authorization periods, action-level logs, and approval gates for consequential commands.

This is where API visibility becomes decisive. An agent often acts through APIs even when a user begins the task in a browser.

Security teams must connect the human identity, agent identity, model request, tool call, and resulting business action. A disconnected log for each component cannot reconstruct the full decision.

The signal will strengthen Akamai’s thesis if enterprises discover large numbers of unknown agents or excessive permissions. It will weaken the thesis if inventories show narrow, monitored, and intentional access.

Product announcements deserve less weight than operating data. Vendors will continue releasing AI gateways, secure browsers, model firewalls, and agent-control systems.

The meaningful question is whether those products change behavior. Reduced unknown-account usage and fewer sensitive transfers would offer stronger evidence than deployment counts.

Executives should also watch employee satisfaction with approved tools. Low usage can indicate strong control, but it can also indicate that employees stopped using valuable AI altogether.

A mature program measures both safety and utility. Relevant outcomes include task completion, adoption, error rates, review time, policy exceptions, and confirmed incidents.

The decision facing enterprises is not whether employees will use AI. That behavior has already spread through browsers, software suites, and development environments.

The decision is whether official systems become useful enough to attract that activity back into visible channels. Security teams cannot govern what they cannot see.

Akamai’s warning should therefore prompt a direct review. Which AI accounts are active, what information reaches them, and which agents can act on company systems?

The clipped Google News claim still needs its complete methodology before readers treat “nearly half” as a universal rate. The surrounding evidence already supports a narrower conclusion.

Enterprise AI adoption has outrun traditional account and application controls. The organizations that close that gap will make the approved path easier, instrument the browser, and restrict agent permissions.

Start with one practical audit this month. Measure managed versus personal AI sessions, identify sensitive transfers, and list every agent with write access. Those three views will reveal whether AI governance exists in operations or only in policy.

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page