Security1 distinct publisher3 min readPublished
If a fifth of the risk sits with a twentieth of the staff, blanket policing of ChatGPT use is the wrong spend. The identity and extension figures in the same report say why.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
A population that touches AI models twelve times more often than the bottom half of the workforce is, by construction, the easiest population to find [1]. Volume is what telemetry is good at. The awkward part is that the same volume makes them the people you can least afford to simply block, because Akamai's own framing has them wiring models into operations rather than drafting emails, and adding autonomous agents that run inside the business and outside its guardrails [12].
The identity split explains why an approved-vendor list cannot be the control. Microsoft Copilot M365 keeps 90.55% of interactions inside corporate identity systems, and Gemini Enterprise 98.15% [5]. Microsoft Copilot Standard is 63.92% personal logins [6]. Same vendor, same brand, opposite governance outcome, and the variable is the licence tier rather than the model. DeepSeek sits at 99.8% personal identity [6], which is a procurement fact disguised as a usage statistic.
Then there is an addition the report leaves to the reader. Personal identities account for 47.11% of enterprise AI conversations [4]. A further 14.4%, according to Akamai's Or Eshed, run through corporate email addresses attached to personal freemium subscriptions, where injected data may end up in public model training [7]. Those are described as distinct categories, so on the report's own numbers roughly 61.5% of enterprise AI conversation happens outside an enterprise-managed licence [16]. Half of that total will pass an identity check cleanly.
Extensions are where the concentration argument gets concrete. Midsize enterprises report 17.7% of employees running at least one AI extension against 9.53% at larger organisations, about 1.9 times the rate [8][17]. Nearly three-quarters request high or critical permissions [9], and 16.31% carry known CVEs against 10.80% for browser extensions generally, about half again as many [10][15]. Smaller estates, more installs, worse packages.
Two cautions on the load-bearing figure. The 12x is an interaction-rate ratio; the conversation-length gap is smaller, 18-plus prompts against a workforce average of about five, or roughly 3.6 times [3][14]. And every number here comes from one vendor's telemetry, published by Akamai, quoted by an executive who runs Akamai's enterprise security product and engineering [2][18]. The report counts exposure, not incidents.
What survives the caution is the shape. Of everything described, extensions are the only surface with a hard artefact behind them: an installed package, a permission grant, a CVE identifier. The identity leakage is a licensing question. The agents are behaviour. Eshed's own recommendation is to work out which employees depend most on AI in order to know where risk sits [13], and that is a smaller piece of work than governing everyone, which is presumably why the long tail of dozens of niche tools has stayed unmeasured while the frontier vendors got the policy documents [11].
Ranked by verification strength, evidence, and original report placement.
Akamai research found the top 5% of enterprise power users interact with AI models at 12 times the rate of the bottom 50% of the workforce.
The findings were published in Akamai's State of the Internet: Enterprise AI Usage Risk Report 2026, based on real-world usage and telemetry data as well as research and threat analysis.
All figures in the reporting originate from Akamai's own report and are quoted by Or Eshed, Akamai's Vice President Enterprise Security Product & Engineering; the two supplied source blocks are the same article from thehackernews.com.
Akamai data shows the average employee AI conversation lasts about five prompts, while the top 5% of power users routinely engage in conversations of 18 prompts or more.
Nearly half of all enterprise AI conversations, 47.11%, occur through personal identities rather than corporate-managed accounts.
Gemini Enterprise keeps 98.15% and Microsoft Copilot M365 keeps 90.55% of interactions inside corporate identity systems.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise vendor telemetry, no methodology or corroboration
The figures are specific to two decimal places and internally consistent across the cluster, but every one originates from a single vendor report relayed by a single publisher (the cluster's two items are the same article). No sample size, tenant population, measurement window, industry or geographic composition is disclosed, no independent dataset is offered for comparison, and the causal claims about concentrated risk rest on usage intensity rather than incident data.
AI use is pervasive but mostly outside managed identity
The disclosed telemetry shows enterprise AI usage is already broad and deep — conversations averaging five prompts with a heavy cohort running 18-plus, and roughly half of all conversations flowing through personal identities. Governed enterprise SKUs demonstrably retain 90-98% of interactions inside corporate identity, so managed adoption is real where it is deployed, while extension adoption (17.7% midsize, 9.53% large) marks a smaller but growing unmanaged layer. Scored on reported usage breadth, discounted because the figures are one vendor's telemetry of an undisclosed population.
Threat framing runs ahead of the measurements
The usage and identity numbers are concrete, but the language wrapped around them — 'biggest security risk', 'virtual colleague with keycard access to the company vault', shadow AI as 'the infrastructure for the next generation of automated cyberattacks' — asserts severity the data does not measure. The report ranks long-tail tooling above frontier LLM access as a risk without comparative evidence, attributes disproportionate harm to the top 5% without incident data, and the headline 12x intensity gap is softened by the 3.6x conversation-depth gap in the same dataset. Overstatement is moderate rather than extreme because the underlying percentages are specific and the recommended controls are conventional.
Vendor research that maps directly onto vendor product
Akamai authored the data, supplied the sole spokesperson, and closes the piece with a CISO checklist prescribing continuous discovery of AI apps, extensions and agents, real-time prompt/upload inspection, SSO enforcement and freemium-account auditing — the exact capability set an enterprise security vendor sells. The publisher relays the report without an independent counter-source or disclosure of that alignment, and the duplicate posting amplifies a single vendor voice.
Directionally credible, weakly verified
Confidence is moderate-low: the direction of the findings (heavy-user concentration, large personal-identity share, riskier AI extensions) is plausible and consistently reported, but verification is thin — one vendor, one publisher duplicated, no methodology, no third-party replication, and interpretive claims about risk concentration left unevidenced. The quoted percentages should be treated as vendor-reported indicators rather than established base rates.
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
security
Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume1 distinct publisher
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 24, 2026