The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
13:30 · August 24, 2026 · Hacker News AI Section

Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power
Summary
Akamai’s analysis of enterprise telemetry shows that the top 5 percent of AI users generate twelve times the model interactions of the bottom half of the workforce, concentrating risk in a small cohort whose longer sessions—averaging eighteen prompts versus five for typical employees—embed AI models deeper into operational workflows. These power users expand the attack surface through shadow AI, including unapproved niche tools and autonomous agents that operate outside corporate identity and logging controls.
Nearly half of all recorded enterprise conversations occur under personal accounts, while another 14.4 percent route through corporate email addresses tied to freemium subscriptions. In both cases, prompts containing sensitive data may be retained for model training without enterprise oversight, creating visibility gaps that standard frontier-LLM policies do not address. The same pattern appears with browser and IDE extensions: 17.7 percent of employees at midsize firms and 9.53 percent at larger organizations install at least one AI extension, three-quarters of which request high or critical permissions and 16.31 percent of which carry known vulnerabilities.
The resulting exposure is not limited to data leakage. Personal subscriptions and extension pathways also supply infrastructure for future automated attacks that bypass conventional network and endpoint controls. Akamai therefore recommends shifting from broad LLM governance to targeted identification of high-dependency users, mapping where AI is embedded in business processes, and enforcing consistent identity and retention policies across both sanctioned and unsanctioned tools.
Why it matters
Directly addresses AI security risks and privacy concerns relevant to EU enterprises under GDPR and upcoming AI Act. Provides actionable insights for Dutch security teams to identify power users and manage shadow AI. Aligns with Netherlands focus on ethical, transparent AI deployment.












