Akamai’s core conclusion is that autonomous AI agents require behavioral governance, not identity checks alone: agents can access data, call APIs, and take actions at machine speed. The practical response is to inventory agents and connected tools, enforce least privilege, monitor data and runtime behavior, and rese...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How does Akamai’s “Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape” report describe the security risks created by autonomo. Article summary: Akamai’s central warning is that autonomous AI agents turn AI from a passive information tool into a nonhuman actor that can retrieve data, invoke APIs, alter workflows, and execute transactions at machine speed. Consequ. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
Akamai’s Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape frames agentic AI as a shift from software that answers questions to nonhuman entities that can retrieve information, invoke tools, call APIs, and carry out multistep actions. Its central security argument is that authentication and static access controls are no longer enough: enterprises need to govern what these identities do, in context and in real time. 1
17
An autonomous agent can combine a model’s reasoning with access to enterprise systems. That combination creates risk at the point where the agent can act: moving data, using a browser, connecting to an API, or initiating a workflow.
Akamai describes this as a problem of nonhuman identity. The enterprise must be able to identify not only the employee or service behind an action, but also the agent, the tools it can use, the data it can reach, and whether its behavior is appropriate for the task. 1
2
Akamai reports that more than 6% of enterprise-device AI chatbot conversations contain sensitive information. That makes prompts, uploads, and chat histories part of the organization’s data-security perimeter rather than merely a productivity-tool concern. 1
The exposure is amplified when employees use personal or otherwise unmonitored AI accounts. Those interactions can sit outside normal enterprise visibility and policy controls, leaving organizations with less ability to determine what corporate data was shared and where it went. Akamai identifies shadow AI as part of the expanding enterprise AI threat surface. 12
The browser is a particularly difficult control point because it is where employees work, authenticate, view sensitive information, and increasingly use AI assistants. Akamai says more than 40% of enterprise users have installed AI-powered browser extensions; 25% of those extensions changed permissions during the prior 12 months. 1
2
The concern is not that every extension is malicious. It is that permissions, data access, and extension behavior can change in a workspace that may not receive the same scrutiny as managed enterprise applications.
The Model Context Protocol (MCP) enables agents to use tools and APIs. Akamai characterizes it as giving agentic AI its practical “hands,” while also blurring the boundary between data and code. A malicious or compromised MCP server may influence model behavior through prompt injection or cross-server attacks. 2
This creates a visibility and authorization challenge: teams need to know which MCP services an agent can reach, what credentials and permissions are available, and what actions the agent actually performs at runtime.
Akamai links the rise of agents to a broader challenge in bot and API security. Automated systems can imitate customer behavior and increase the volume of interactions that defenders must assess for intent and abuse. In commerce, Akamai recorded a 19% year-over-year increase in AI bot traffic in 2025, driven largely by retail activity. 20
That does not mean every AI bot is malicious. Useful crawlers, search bots, fetchers, and agents exist alongside abusive automation. The security task is therefore to distinguish permitted, expected activity from behavior that is anomalous or harmful. 18
27
The report’s wider warning extends to web-facing services. Akamai-observed research cited in the supplied material found verified AI crawlers, including ChatGPT, making high-frequency POST requests rather than only retrieving pages with GET requests. POST requests can submit information or trigger actions such as login, cart, and checkout flows. 19
In that 30-day analysis, ecommerce accounted for 44.8% of AI-bot POST transactions, while travel reached 30% in one month. The implication is not that a POST request is inherently malicious; it is that AI-originated traffic may increasingly reach the workflows where fraud controls, authorization checks, and transaction monitoring matter most. 19
Akamai’s recommended direction is to move from conventional identity management toward behavioral governance of human and nonhuman actors. Its approach can be translated into four operational priorities. 1
17
Authenticate users, services, and agents—but also evaluate what they are trying to do. Controls should account for an agent’s requested action, target system, tool use, data access, and unusual behavior across workflows and APIs. 1
17
Organizations need visibility into deployed agents, service accounts, browser extensions, MCP servers, connected APIs, and their permissions. Unknown connections and excessive privileges are difficult to secure because teams cannot reliably assess their impact. 2
Limit every agent and connected tool to the data, systems, and actions required for its defined task. Pair that with monitoring of chatbot use, browser-based AI tools, and sensitive-data movement so that policies reflect the context and destination of data—not simply whether an account successfully logged in. 1
2
Machine-speed automation calls for runtime defenses that can assess behavior as it occurs. Low-risk, reversible tasks may be suitable for greater autonomy; high-impact, sensitive, or anomalous actions should face stronger controls or require human approval. This aligns with Akamai’s emphasis on governing nonhuman behavior and API activity in real time. 17
Akamai’s report does not treat AI agents as just another category of user or bot. It treats them as operational actors that can bridge data, tools, and transactions. The security priority is therefore to gain visibility into those connections, constrain permissions, monitor behavior continuously, and make autonomy proportional to risk. 1
2
17
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Akamai’s core conclusion is that autonomous AI agents require behavioral governance, not identity checks alone: agents can access data, call APIs, and take actions at machine speed.
Akamai’s core conclusion is that autonomous AI agents require behavioral governance, not identity checks alone: agents can access data, call APIs, and take actions at machine speed. The practical response is to inventory agents and connected tools, enforce least privilege, monitor data and runtime behavior, and reserve human approval for consequential or anomalous actions.