AI Power Users Pose Disproportionate Risk to Enterprise Security

New Akamai research finds the top 5% of enterprise AI adopters are embedding unvetted tools directly into critical business operations, creating risks that dwarf those of casual AI use.

AI-generated illustration depicting ai security for the story: AI Power Users Pose Disproportionate Risk to Enterprise Security

Summary

  • Akamai research identifies a small cohort of ‘AI super-adopters’ — roughly the top 5% of enterprise users — as the most significant AI-related security risk in organisations.
  • The risk is not casual use of ChatGPT for drafting; it is deep, unsanctioned integration of AI tools into business-critical workflows and systems.
  • These power users are hardcoding unvetted AI into operations without security review, creating persistent and often invisible exposure.
  • Security teams focused on broad AI usage policies may be overlooking the higher-stakes behaviour of a small, technically capable minority.
  • The source material does not detail specific remediation steps beyond identifying the cohort as a priority for security attention.

The wrong threat in focus

Enterprise security programmes have spent considerable energy managing the sprawl of employees turning to generative AI tools for everyday tasks — summarising documents, drafting emails, producing first-cut code. That is a legitimate governance concern, but new research from Akamai suggests it may be consuming attention that belongs elsewhere.

A small cohort, an outsized footprint

Akamai’s research points to the top 5% of enterprise AI users as the source of disproportionate risk. These are not casual adopters experimenting on the margins. They are technically capable individuals who are actively embedding AI tools — many of them unvetted — directly into critical business processes and systems. The scale of their integration means that when something goes wrong, the blast radius extends well beyond a single user or team.

Hardcoded and largely invisible

The specific behaviour that distinguishes this cohort is not frequency of use but depth of integration. According to the research, these super-adopters are hardcoding AI tools into workflows in ways that may not be visible to security or IT teams. Unlike a browser-based SaaS tool that generates observable network traffic, AI baked into operational pipelines or business logic can persist quietly, making discovery and remediation substantially harder.

Why the standard policy response falls short

Most enterprise AI governance frameworks are built around acceptable use policies, browser extension restrictions, and data loss prevention controls aimed at preventing sensitive data from reaching consumer AI platforms. Those controls are calibrated for the average user. They are less effective against someone with the technical skill to integrate an API directly, to build tooling around a model, or to spin up a local or cloud-hosted instance outside the monitored environment. The research implies that the risk profile of this cohort is qualitatively different, not just quantitatively greater.

Confidence without oversight

Part of what makes this group difficult to manage through conventional awareness programmes is that their technical confidence is precisely what drives the behaviour. These individuals are often effective at what they do. They integrate AI because it produces results, and they may not perceive — or may actively discount — the security implications of bypassing review processes. The risk is therefore less about malicious intent and more about the gap between capability and governance.

What the research does not tell us

It is worth being clear about the limits of the available information. The Akamai research, as summarised, identifies the cohort and characterises the risk. It does not, in the source material available, prescribe a detailed remediation playbook or quantify the number of organisations affected. CISOs should treat this as a signal to investigate their own environments rather than a fully mapped threat.

Why it matters

For CISOs, this research reframes where AI governance attention and budget should concentrate. A broad-brush acceptable use policy is unlikely to reach the 5% of users driving the most significant exposure. If AI tools are being hardcoded into critical operations without security review, the organisation may be accumulating third-party AI dependencies it has not assessed for data handling, model reliability, supply chain risk, or regulatory compliance. The difficulty of discovering these integrations after the fact makes early identification of the super-adopter cohort a higher priority than managing the much larger population of casual users.

What to do now

  • Identify your AI super-adopter cohort by reviewing API usage logs, development environments, and internal tooling for unsanctioned AI integrations, rather than relying solely on DLP or browser-level controls.
  • Shift AI governance conversations with high-capability technical staff from policy enforcement toward structured fast-track review pathways, so that integration can happen with oversight rather than around it.
  • Audit critical business workflows and operational pipelines for embedded or hardcoded AI dependencies that may not have been surfaced through standard software asset management processes.

Sources