Security News

AI Fuels Sharp Rise in Bot Attacks and API Threats, New Report Warns

Infosecurity Magazine · 22 Sept 2026
Key Takeaway Small businesses should set clear policies on AI tool use, restrict personal accounts for work-related AI chats, and monitor browser extensions and API activity for unusual behaviour.

A new report from security vendor Akamai has found that AI is significantly reshaping the threat landscape for businesses. Bot traffic surged 300% over the past year, mostly affecting online retail and commerce businesses, while daily attacks on APIs (the software connections that let systems and apps talk to each other) rose 113% between 2024 and 2025. Akamai's report, based on global threat intelligence, found that 87% of organisations experienced an API-related security incident in 2025, up from 76% in 2022.

The report also flagged risks from AI browser extensions and chatbots. Around 40% of enterprise users have installed AI browser tools, and a quarter changed the permissions on these tools within a year, increasing exposure to misuse. Separately, 6% of chatbot conversations were found to contain sensitive company information, a particular concern given that almost half of AI conversations on work devices happen through personal accounts that IT teams cannot monitor.

Akamai also warned about risks tied to AI agents and a technology called MCP, which allows AI systems to take autonomous actions. While security leaders expect rogue AI agents to become a major threat by 2030, MCP-related risks currently rank low on most security priority lists. Akamai noted attackers can potentially manipulate AI agents through prompt manipulation or unmonitored browser extensions, allowing unauthorised actions without a traditional network breach.

AI security API security bot attacks browser extensions enterprise risk
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.