AI Fuels 300% Surge in Bot Traffic and API Attacks
Share
Artificial intelligence is driving a 300% increase in bot traffic and a massive rise in API-targeted attacks, according to new research from Akamai. The security vendor’s State of the Internet report highlights how AI is accelerating various enterprise threats, most notably by making APIs a dominant attack surface.
Rising API and Bot Vulnerabilities
The report recorded a 113% increase in daily API (Application Programming Interface) attacks between 2024 and 2025. This trend coincides with a growing number of organisations falling victim to such exploits; 87% of surveyed companies experienced an API-related security incident in 2025, compared to 76% in 2022.
The surge in bot traffic, which has primarily impacted the commerce sector, is also being propelled by AI capabilities. This increase in automated, intelligent traffic poses a significant challenge to maintaining service availability and protecting against fraudulent activities.
Data Exposure and Unmonitored AI Use
Beyond direct attacks, the proliferation of generative AI tools has introduced new channels for data leakage. Akamai found that 6% of chatbot conversations contain sensitive corporate information. The risk is compounded by the fact that nearly half (47%) of AI interactions on enterprise devices are carried out using personal identities and accounts, preventing IT teams from tracking or monitoring the data being shared.
AI-powered browser extensions also present a growing risk to the enterprise. While 40% of enterprise users have installed these tools, a quarter of them altered their permissions within a 12-month period, a move that Akamai warns significantly increases an organisation’s risk profile.
The Risks of Autonomous AI Agents
As organisations move toward more autonomous systems, the security landscape is shifting to address Model Context Protocol (MCP) related threats. MCP gives AI the ability to execute autonomous actions, but it also creates vulnerabilities by blurring the distinction between data and code. This could allow malicious third-party servers to hijack large language model (LLM) logic through prompt injection or cross-server attacks.
Security leaders are also bracing for the rise of rogue AI agents. Adversaries can potentially manipulate an agent’s logic through indirect prompt injections or by compromising unmonitored browser extensions to execute unauthorised, high-impact actions.
To mitigate these evolving threats, Akamai suggests that Chief Information Security Officers (CISOs) focus on adaptive edge governance, including edge-native runtime protections and API filters. Additionally, organisations should implement visibility and behavioural controls within the browser and restrict the autonomy of AI agents by ensuring humans remain in the loop for high-risk actions.




Leave a Reply