News

Akamai SOTI Report 2026: Securing Agentic AI

News | 28.09.2026

Enterprises deploying agentic AI across APIs and business systems face a fundamental shift in risk. Autonomous nonhuman entities now execute tasks at machine speed, and traditional identity and access management is no longer enough. Security leaders must move toward behavioral governance to control what AI agents do, when they act, and how their actions can be verified.

What was announced

Akamai (NASDAQ: AKAM) released its latest State of the Internet (SOTI) Security report titled Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape. The report is targeted at a CISO audience and explains that securing modern business has evolved from identity and access management for people into a challenge of behavioral governance over nonhuman entities.

The report highlights two critical challenges: the difficulty of setting guardrails for autonomous agents, and the speed at which AI models discover vulnerabilities, often outpacing human patch cycles.

Key findings from the SOTI report

  • MCP visibility gap: Model Context Protocol exposure ranks last among current CISO priorities, even as leaders expect rogue AI agents to become a top cyberthreat by 2030.
  • Chatbot data leaks: More than 6% of enterprise AI chatbot conversations contain sensitive corporate data, with 47% of interactions occurring via unmonitored personal accounts.
  • Exploit acceleration: AI models can rapidly discover and chain system weaknesses, making reactive patching insufficient.
  • Unprotected browser workspace: Over 40% of enterprise users have installed AI-powered browser extensions; 25% alter permissions within 12 months and are 60% more likely to carry known CVEs.
  • Synthetic customers: AI agents replace traditional web traffic, requiring generative engine optimization (GEO) metrics: citations, accuracy, sentiment and bot management.

AI presents an everything, everywhere, all at once moment for the security ecosystem. Security programs need to adapt to this rapidly evolving reality

Boaz Gelbord, Chief Security Officer at Akamai

Why this matters

For CIOs, CISOs, IT directors and procurement leaders, the agentic web is not a distant concept. It reshapes operational risk in three simultaneous ways: internal AI usage across employees, integration of AI into customer-facing products and cloud workloads, and AI-driven attacks targeting the enterprise. Boards, customers and regulators are already treating this as a central topic.

As autonomous AI moves from answering queries to executing multistep business strategies, security leadership must evolve alongside it

Steve Winterfeld, Advisory CISO of Akamai

Technical details

  • Adaptive edge governance: Deploy edge native runtime protections, API filters and isolation mechanisms to neutralize vulnerabilities immediately while back-end patching takes place.
  • Browser edge lockdown: Establish visibility and behavioral controls inside the browser to secure workforce adoption of unmanaged AI extensions and web-hosted models.
  • Brand authority in a zero-click economy: Implement GEO strategies and machine-readable data layers at the network edge to prevent AI crawlers from misrepresenting corporate brand data.
  • Autonomy matched to verifiability: Grant operational autonomy to AI agents based on how easily actions can be verified and how reversible a failure is, maintaining human-in-the-loop controls for high-stakes actions.

Softprom and Akamai

Softprom is the official distributor of Akamai. Enterprise customers can access licensing, technical consulting and implementation support for Akamai's edge security, API protection and agentic AI defense portfolio through Softprom's certified team.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.