AI Drives Surge in Bot and API Threats
Akamai says AI drove a 300% rise in bot traffic and a 113% increase in daily API attacks.
Akamai’s 22 September State of the Internet report says AI helped drive a 300% increase in bot traffic, mainly against commerce, and a 113% rise in daily API attacks between 2024 and 2025. It says 87% of surveyed organizations had an API security incident in 2025, up from 76% in 2022. Forty percent of enterprise users installed AI browser extensions, 6% of chatbot conversations contained sensitive corporate information, and 47% of AI chats on enterprise devices used personal accounts. Akamai warns that Model Context Protocol and indirect prompt injection can let adversaries manipulate agents into high-impact actions.
- Bot traffic rose 300%, mainly hitting the commerce vertical.
- Daily API attacks increased 113% from 2024 to 2025.
- 87% of surveyed organizations had an API incident in 2025.
- 6% of chatbot chats held sensitive data; 47% used personal accounts.
- Indirect prompt injection via MCP can drive unauthorized agent actions.
Full article430 words · extracted from infosecurity-magazine.com · click to collapse
AI helped drive a 300% increase in bot traffic last year, alongside a range of other enterprise threats, a new report from Akamai has revealed.
The security vendor’s latest State of the Internet report, published on September 22, is based on threat intelligence gathered from across its global security and network infrastructure.
Alongside the surge in bot traffic, which primarily impacted the commerce vertical, Akamai warned that AI is “elevating APIs as the dominant attack surface for modern enterprises.”
It recorded a 113% increase in daily API attacks between 2024 and 2025. Some 87% of surveyed organizations experienced an API-related security incident in 2025; up from 76% in 2022.
Read more on AI threats: AI Is Making Attacks Cheaper, Faster and More Covert, Says ReliaQuest
AI browser extensions are another potential threat to the enterprise. Two-fifths (40%) of enterprise users have installed these tools, but a quarter have altered permissions within 12 months, something Akamai warned “significantly increases their risk profile.”
The report also revealed that 6% of chatbot conversations contain sensitive corporate information. That’s particularly concerning given that almost half (47%) of AI conversations on enterprise devices are carried out via personal identities and accounts, meaning IT teams aren’t able to track them.
Akamai also pointed to an AI-driven acceleration in vulnerability research and exploit development, as well as MCP-related threats, as posing a considerable risk to the enterprise.
MCP exposure ranks last among current CISO security priorities even as security leaders expect rogue AI agents to become a top cyber-threat by 2030, the report warned.
“MCP gives AI the ‘hands’ to execute autonomous actions, but it also creates significant security risks by blurring the line between data and code, which may allow malicious third-party servers to hijack large language model (LLM) logic through prompt injection or cross-server attacks,” it added.
Akamai claimed that the proliferation of AI agents in organizations mean attackers no longer need to rely only on network breaches.
“Instead, by exploiting indirect prompt injections, manipulating model context, or compromising unmonitored browser extensions, adversaries can manipulate an agent’s logic to execute unauthorized, high-impact actions,” it said.
Protecting the Agentic Enterprise
In order to mitigate such AI-related risks, CISO should focus on several critical areas, Akamai claimed. These include:
- Adaptive edge governance including edge-native runtime protections, API filters, and isolation mechanisms to neutralize threats before exploits land
- Visibility and behavioral controls inside the browser to reduce data exposure
- Restricting autonomy for agents based on how easily their actions can be verified and how reversible a failure would be, keeping humans in the loop for high-risk actions