VYPR
trendPublished Sep 22, 2026· 1 source

AI Fuels 300% Surge in Bot Traffic and API Attacks, Akamai Report Finds

Akamai's latest State of the Internet report reveals AI is significantly escalating cyber threats, driving a 300% increase in bot traffic and making APIs a primary attack surface.

Artificial intelligence is a key driver behind a dramatic 300% surge in bot traffic observed over the past year, alongside a host of other escalating enterprise threats, according to Akamai's latest State of the Internet report. The security vendor's findings, based on extensive threat intelligence from its global infrastructure, paint a stark picture of AI's growing influence in the cybercrime landscape.

The report highlights that this surge in bot traffic predominantly impacted the commerce sector. Beyond sheer volume, Akamai warns that AI is fundamentally reshaping the threat landscape by elevating Application Programming Interfaces (APIs) as the dominant attack surface for modern enterprises. The data shows a significant 113% increase in daily API attacks between 2024 and 2025, with a concerning 87% of surveyed organizations experiencing an API-related security incident in 2025, a notable rise from 76% in 2022.

AI's reach extends to AI browser extensions, posing a direct risk to enterprise users. The report found that two-fifths (40%) of enterprise users have installed these tools, but a quarter have modified their permissions within a year, substantially increasing their risk profile. Compounding these concerns, 6% of chatbot conversations were found to contain sensitive corporate information. This is particularly alarming given that nearly half (47%) of AI conversations on enterprise devices occur via personal accounts, circumventing IT oversight and tracking capabilities.

Akamai also points to AI's role in accelerating vulnerability research and exploit development, as well as Machine Control Protocol (MCP)-related threats, as significant risks. Despite these growing dangers, MCP exposure ranks low on current CISO security priorities, even as leaders anticipate rogue AI agents to become a top cyber-threat by 2030. MCP's ability to grant AI 'hands' for autonomous actions also introduces risks by blurring the lines between data and code, potentially enabling malicious actors to hijack LLM logic through prompt injection or cross-server attacks.

The proliferation of AI agents within organizations means attackers are no longer solely reliant on traditional network breaches. By exploiting indirect prompt injections, manipulating model context, or compromising unmonitored browser extensions, adversaries can now manipulate an agent's logic to execute unauthorized and high-impact actions. This shift necessitates a re-evaluation of defensive strategies, moving beyond perimeter-based security to address the autonomous capabilities of AI systems.

To combat these AI-driven risks, Akamai advises CISOs to concentrate on several key areas. These include implementing adaptive edge governance with edge-native runtime protections, API filters, and isolation mechanisms to neutralize threats before they can be exploited. Enhanced visibility and behavioral controls within the browser are crucial to reduce data exposure, and restricting the autonomy of AI agents based on the verifiability and reversibility of their actions is paramount, ensuring human oversight for high-risk operations.

The report underscores a critical inflection point where AI is not just a tool for defenders but a powerful enabler for attackers. The increasing sophistication and scale of AI-driven threats, from bot traffic and API exploitation to the manipulation of AI agents themselves, demand proactive and adaptive security measures. Organizations must prioritize understanding and mitigating these new attack vectors to safeguard their digital assets and operations in an AI-augmented threat landscape.

Synthesized by Vypr AI
AI Fuels 300% Surge in Bot Traffic and API Attacks, Akamai Report Finds · VYPR