Enterprise AI Risk Concentrates in a Sliver of Power Users, Report Finds

A new visibility study says the bulk of corporate AI exposure traces back to a thin slice of heavy users — most of it invisible to security teams.

ThreatVectr Newsdesk· 3 min read
Enterprise AI Risk Concentrates in a Sliver of Power Users, Report Finds
Share

Most enterprise AI risk does not look the way CISOs were told it would. It is not a broad fog of casual ChatGPT queries from across the workforce. It is a concentrated plume, coming from a small population of heavy users on a handful of platforms.

That is the headline finding of LayerX Security's State of AI Usage Report 2026, which examined how AI tools are actually consumed inside organizations and where sensitive data ends up.

LayerX is a browser security vendor that monitors AI and SaaS usage at the session layer, which gives it a vantage point on what employees paste into chatbots — not just which tools IT has formally sanctioned.

The report's core argument: enterprise AI risk is not evenly distributed. A small cohort of power users drives a disproportionate share of prompts, file uploads, and account activity. The long tail barely registers by comparison.

That matters for how exposure gets measured. Headcount-based AI governance assumes the average user. The data suggests security teams should be modeling the top decile instead.

The other concentration is platform-level. A short list of consumer-grade generative AI services accounts for most of the activity, often accessed through personal accounts rather than enterprise tenants. That distinction collapses most of the data-loss controls organizations think they have in place. Logging, retention policies, and admin visibility all behave differently on a free account.

Shadow AI, in other words, is not a vague cultural problem. It is a measurable one with named platforms and identifiable users behind it.

The study also flags identity hygiene around AI tools. A meaningful share of corporate AI accounts are created with personal email addresses, and many are not protected by single sign-on or multi-factor authentication. When credentials for those accounts surface in infostealer logs — a thriving market on Russian-language Telegram channels and underground forums — attackers inherit whatever prompt history and uploaded files sit behind them.

For incident responders, that is a fresh class of exposure. Prompt histories can include source code, customer records, contract language, and internal financial figures. None of it is covered by traditional DLP if the channel is a browser tab pointed at a consumer LLM.

LayerX frames the takeaway around visibility. You cannot govern what you cannot see, and most enterprise tooling still treats AI usage as a binary — allowed or blocked at the network edge — rather than a behavior to be monitored at the user and session level.

The report stops short of naming specific breach incidents tied to AI prompt leakage, and public disclosures in that category remain rare. That gap is itself part of the visibility problem the research describes. Few organizations have the telemetry to know whether a leak has occurred.

The full report is available from LayerX.

© 2026 Threat Vectr