cybersecurity operations center analysts monitoring security screens

Akamai Technologies (NASDAQ: AKAM) is urging security leaders to move beyond conventional human identity controls as autonomous AI agents begin taking actions across enterprise systems and APIs. Its latest State of the Internet Security report identifies visibility into nonhuman entities, browser-based AI tools and chatbot data handling as operational security gaps that can grow as agentic AI is deployed.

The report, titled Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape, frames the issue as behavioral governance. Traditional identity and access management can establish who a person is and what they may access. Agentic systems add another layer: enterprises also need to understand what a nonhuman agent is doing, which systems it can reach and whether its actions can be verified or reversed.

That distinction has practical implications for IT automation. AI agents can carry out multistep tasks across connected systems, which can streamline work but also expand the effect of an incorrect instruction, an excessive permission or a compromised integration. Akamai recommends matching the autonomy granted to an agent with the ease of verifying its actions and the reversibility of a failure, while keeping people in the loop for high-stakes work.

One finding concerns the Model Context Protocol, which enables AI agents to interact with multiple software systems. Akamai said MCP exposure ranks last among current CISO security priorities, despite the protocol’s ability to enable autonomous actions across systems. The company characterized that as a visibility gap rather than evidence of a specific incident. For security teams, the core question is whether inventory, authorization and monitoring processes account for the new connections agents can make.

The report also examines enterprise chatbot use. Akamai said more than 6% of enterprise AI chatbot conversations contain sensitive corporate information, primarily personally identifiable information, and 47% of those interactions occur through unmonitored personal accounts. The figures are drawn from the company’s security infrastructure and describe its observed traffic; Akamai did not provide the underlying sample size or a full methodology.

Browser extensions present another governance challenge, according to the report. Akamai said more than 40% of enterprise users have installed AI-powered browser extensions, with a quarter of those extensions changing permissions within a year. It also said such extensions are 60% more likely than standard extensions to have known CVEs. The company recommends improving visibility and behavioral controls at the browser layer to manage use of unmanaged AI tools and web-hosted models.

Akamai’s recommendations extend to network and application controls. It calls for edge-native runtime protections, API filters and isolation mechanisms that can reduce exposure while back-end patching is underway. Those measures are not substitutes for software remediation, but they can give operations teams an interim control when AI-assisted vulnerability discovery moves faster than established patch cycles.

The report is research rather than a product launch, and its recommendations will not map identically to every environment. Still, its focus on nonhuman identity and operational verification reflects an automation issue security teams now face: autonomous systems need guardrails that address actions as well as access. Organizations expanding AI agents into production workflows will need to define permissions, logging, escalation points and rollback procedures before treating those agents as routine operators.

For CISOs and IT operations leaders, the immediate takeaway is to extend existing security governance to the protocols, browser tools, service accounts and APIs that agentic systems use. As AI moves from responding to queries toward executing work, visibility into that activity becomes a core control rather than an optional layer of oversight.

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest News