The Browser Is the New Security Layer
Akamai announced its intent to acquire LayerX Security for approximately $205 million, pairing the world’s most distributed edge platform and fastest ZTNA with LayerX’s browser and AI security. Or Eshed, Co-Founder and CEO of LayerX Security, joins Alan Shimel on Techstrong TV to unpack what the deal means for enterprise workforce security and how the combined platform will let global organizations adopt AI without trading off productivity or availability. Or also walks through the latest LayerX AI usage report. Twenty percent of enterprise users are heavy AI users, 5 percent are full-blown AI employees running multiple LLMs across business workflows, and ChatGPT still tops Copilot inside the corporate browser. He explains the three degrees of AI usage — direct, embedded, and workflow-native — why CASB and SaaS-security paradigms break down on opinionated AI users, and why the browser has become the most critical and overlooked security layer in modern work.
Transcript
Hi, everyone. Welcome back here to Techstrong TV. I'm happy to introduce you to my next guest.
His name is Or Eshed, co-founder and CEO at LayerX Security. LayerX has a lot of news going on. We're going to get to it.
But first, let's talk welcome, Or. Or, welcome back to Techstrong TV. It's good to have you on.
How's everything? Everything is good, and thank you for having me. It's always fun to be back.
Absolutely. Or, for people who are not familiar with you and LayerX, let's start with you. Tell us how you came to co-found LayerX.
What was your passion? Right. So, I grew up in incident response and security operations, and probably it's the worst kind of entrepreneur.
I wasn't thinking about the money. I tried to build a tool that I would want to use. Uh-huh.
So I know it sounds romantic. In our case, it actually worked. So I grew up in network security, incident response, security operations, and I was always, I would say, borderline furious that every time I would investigate what happened with an employee, today you don't say employee, it's workforce, because you have also agents, not only users.
But when a workforce is doing something by mistake or by intent, and they get online, and online is AI applications, SaaS applications, different sites, it's gone. You don't know what happened. It's impossible to run a proper investigation.
And I had this wild idea sort of saying that if the world is becoming file-less, connected, AI driven, and everything happens outside in all kinds of applications, this is a necessary visibility layer. So this is really why we started LayerX. We just felt there was a missing platform, a true platform, native platform, to understand what the workforce is doing in a way which is not dependent on network security tools.
So anything you click on, type, and interact, the way you interact across AI, web, and SaaS. Love it. I love it.
Now, recently, LayerX had some M&A news. I'll let you tell us. So Akamai announced its intent to acquire LayerX.
I think it's an amazing synergy story. Akamai has the largest managed network in the world and the fastest ZTNA in the world. If you combine a strong interaction security platform such as LayerX, which includes browser security and AI security, and top it on top of the best network security infrastructure in the world, and the best ZTNA, you can get a premium in quality platform for heavy duty network security.
So this is something pretty much any global organization, any large bank would want in order to make sure that the workforce is connected and interacts with internal resources, external resources, and AI in a more secure manner without any trade-offs on availability. So think about a big law firm. A big law firm, partners, it's available, it's public knowledge.
Partners in big law firms are making, earning to the firm, millions of dollars a year. Those are people that every minute of their day counts. Just imagine what happens then when the internet is too slow, or they cannot get to their Harvey, which is the most popular AI for legal.
So we want to make sure that adding the security into the stack is not degrading productivity. Think about the buyer standpoint. Today, most projects, and every CISO would say, it's about enablement for AI.
Below this terminology, enablement for AI, we want to make sure that we allow proper usage of AI without changing the way the network runs. And LayerX on top of Akamai is the best solution in the world for that, and I believe this is a game changer. I don't disagree with you.
I don't disagree. First of all, congratulations. Thank you very much.
I've done, I don't know, four venture-backed startups, done some acqui-- They've been acquired, and then one of the companies that acquired my company, I went on to do their corp dev, biz dev, is back in the dot com. We did 30 acquisitions in 36 months, like one a month. It was crazy.
So I have a lot of experience. But you know what? Building a company that someone's willing to pay good money for is an amazing thing.
I don't know if you could even announce this, even if you knew, but when is this expected to close? So according to Akamai's PR, this is expected to close within Q3. Our capabilities and roadmap are aligned.
Our customers are very excited about this movement because we bring Akamai capabilities, but Akamai is actually bringing us capabilities as well. So the synergy- Sure ... is bi-directional.
So we believe it will happen sooner than later. And I'll say it's not only about the commercial side of it. Akamai allows us the opportunity to move mountains and make a change in the cybersecurity world.
Very rarely, there is an opportunity to really make tectonic shifts in cybersecurity, and I think the time has never been as ripe for true disruption. And together with Akamai, we'll be able to take over the network security world. Yeah.
Look, I'm a longtime fan of Akamai. My friend Andy Ellis was the CSO there for about 20 years. Andy's moved on since then.
And then we were talking off camera about down here. They got a big office down here, the old Prolexic team that they bought for DDoS control. Their office is right here in Fort Lauderdale, and so I stay in touch with my Akamai friends.
It's a great company. It's amazing, and they have locations worldwide and a global operation. It's seeing the power for an organization that is able to take technology and propagate it to every continent in the world.
I'm not sure, probably they cover Antarctica. I didn't check yet, but everywhere there is business. No.
Everywhere there is business, they are there, and they are powering the internet and securing businesses online. Love it. So again, congratulations.
We'll keep forward with that. And for those of you who are not used to dealing in fiscal quarters and so forth, Q3 is next quarter, so sometime maybe from July to September. Or if you don't mind, though, I want to pivot a little bit.
You guys recently came out with your 2026 AI usage report, and I would imagine it has a lot of interesting findings. Why don't you give us the key findings? Yeah.
So, I'd say that our AI usage security report is supposed to take the hype, which is confusing, and I think most managers are confused about AI, and take it to the bottom ground and try to put some context into it. So everyone is using AI, but not everyone is using AI at the same level. I'd say that 20% of users inside of the organization are using AI in a heavy-duty manner.
So the 80%, they just interact with it asking, give me a recipe for a whiskey sour, something basic. But 20% are actually using it for business context, one of five. And within those one of five, 5%, 25% of the 20%, 5% of users do pretty much everything with AI, and their interactions are across multiple LLMs, and they use them for business context.
So one of 20 employees is really an AI employee, and a fifth of your employees are heavy users of AI. And that goes into the risk. For example, the usage of multiple AI platforms.
So even though most organizations out there are Microsoft shop, and Copilot is definitely a strong number two, ChatGPT is still number one. Users use ChatGPT with both their personal email and corporate email. We see a lot of power users using multiple AI platforms for different use cases.
Let's take this into the security side and not the business side. Historically, I think that AI security took a lot of paradigms from SaaS security and CASB. One of the paradigms of SaaS security is, let's pick our ticketing system.
Let's pick our ticketing system by the enterprise account and use the management, so using an API control. However, in AI, it's really hard to convince users to use the AI that we want. We, as IT and the business.
Because they have their own preference, and they are vocal, and they're opinionated, and one user prefers Claude, and one user prefers ChatGPT, and that has a big effect. Eventually, it means that an organization has to license multiple tools in order to gain security. The cost of those AI platforms is immense.
So we're getting to a new workforce cost to manage all those different platforms. And in reality, a lot of our usage is done without and out of our control. So it's hard to see what users are doing.
If I'll translate it to non-technical language, what we have is an uncontrolled chaos. So we don't really control what they do, and we cannot see everything they do out there. That's one thing that we see.
We see some sort of a diversification in AI usage, but still there is some sort of a long tail when Copilot and ChatGPT are the most prominent, and all the others are coming in afterwards. Even at the enterprise level, you're not seeing Claude above them? It's a fantastic question.
Within our research, we've checked user interactions within the LLM space and not coding agents. So this report is only on- Got it ... written interface.
So probably- Yeah ... if we look at automation and coding agents and independent agents on the device, probably Claude will be- Yeah ... on the top two.
That makes sense. I got you. Yeah, but still Claude- And also you- Yeah, sorry.
Yeah. Just one thing- No, no ... that Claude is still 12% of all LLM interface usage.
That's one of nine, pretty much. It's still quite a lot. Absolutely.
And the thing to remember, and people out there don't realize this, Microsoft has such a long tail, whether you're talking about the developer community or consumer community, and when they build in a Copilot by default into GitHub, into Office, into Microsoft, that alone gives them that kind of market penetration, right? They're that big. Where with something like an OpenAI or a Claude, you've got to consciously go download a separate application use.
By the way, same thing with Google and Gemini, right? If you look at what's being used the most, how many Google searches is Google using Gemini in? It's probably billions a day, if not billions an hour.
Yeah. So, that skews these numbers sometimes when you start looking at that. You're bringing up a good, valid point that we have first-degree usage, second-degree usage, third-degree usage.
So the first degree is me versus the LLM. The second degree is an AI that's embedded strongly into a device or an application, so that would be a coding agent, some sort of a copilot. And then we have AI that's already embedded within the workflows.
When we use Google Search, we use Gemini. So you can look at it this or that way. I think the reason why we focus on the LLM interface is that this is typically where employees do their work activity, so it's not that common, although possible, for a user to upload a business document into Google Search and ask it to make some modifications.
An interesting thinking exercise can be take Gemini LLM interface, Gemini in the browser, and Gemini within Google Docs, and let them do the same task on some sort of a data. Probably they'll bring different results because each of them has a different context. Absolutely.
I've run that experiment. The same thing you're talking about, I wanted to see because look, I'm a freak. I use Microsoft Office.
I've got Google Workspace and everything else. And so I'm constantly comparing these things and seeing what works here and which I'll do one thing in OpenAI, then I'll do the same thing in Claude, and I'll do it in Gemini and see the difference. So I'm building my harness to figure out what I want to use when.
And it is. It's a very different experience in Google Search than it is in, let's say, Google Workspace, right? Same Gemini, different experience.
When you do these kinds of reports, though, Or, there's always something that you didn't have on your bingo card. You know what I mean? Like, wow, I didn't see that coming.
Anything pop in the report that kind of was a surprise to you? Well, not that much of a surprise to me, but probably for the viewers. First of all, that the distribution of sensitive data is not the same as the distribution of actual AI usage.
So the sensitive data is more scattered across applications. So in other words, ChatGPT and Copilot are searching tools and are kind of replacing or fading in as an alternative for Google or Bing. Whereas, the usage of an LLM to process sensitive data is pretty much scattered across applications.
It can be anything from DeepSeek to ChatGPT to others. So we've actually seen that on the conversation count with sensitive data, DeepSeek had more sensitive interactions than ChatGPT. Not by landslide, but it was pretty much scattered across all the different applications.
So that shows that in order to really secure data, you have to control all the different applications. On top of that, there is a stat around personal AI versus corporate AI. Just to explain what it means.
When you buy an enterprise license, there is someone out there. You can go to ChatGPT, pay them your gray dollars, and ask to use ChatGPT Enterprise. Activate the data security controls, and then they won't train on your data.
When it's done on a personal account, we have two problems. One of them, I can still access the data when I left the business. So if I upload data to my personal account, I can fetch it from another device.
It's less secure. Someone can compromise my account. Basically, it's an incident.
It's a breach. It is a breach. The second thing is that AI is training on your data.
So nearly half of AI usage is done on personal accounts. So we have a problem. We have about 12 different main platforms.
Sensitive data exists across all of them, but each of those platforms has a business account and a personal account. So that gets to the case in which we have 12 times 2, that's 24 different instances that exist in your environment. Only half of them are enterprise, probably only three of them are secure.
So it goes to the fact that the question is: What percentage of activity is actually governed by your security program? And it's probably anything between 10% to 50% at best. At least half is not governed at all whatsoever, creating a big problem.
Agreed. Or, these are the kinds of reports I think people are very interested in because this is what we're living in now, right? This is the world we all have to figure out.
Is this report publicly available already? Yep. This report is publicly available.
You can find it on the LayerX site. It's important for us to contribute to the community. " We want you to see what research we have and be able to pick if you want to trust us.
So it's a part of a vendor-customer relationship to share information and to help the industry move the right direction. I was the proudest to see stats that we created starting Gartner research papers. So it means that not only we are aligned with the market, but the market aligns with us.
So you can find all those researchers on the LayerX site, soon enough on the Akamai site as well, and we'll keep distributing those. Last year, LayerX was the only contributor to Verizon's DBIR on AI security. We intend to expand significantly the amount of research we have on AI usage to help you and the community to get a better, proper view of what's really happening out there.
I love it. You guys planning on being at any events or conferences coming up? 100%.
So we'll be at Black Hat. You're welcome to stop by our booth. We will have a station on our booth for research, and we'll bring a lot of our researchers there to speak with viewers and their partners.
We were just recently in Gartner SRM, and I had a nice talk over there about the risks of AI security, and we try to be pretty much everywhere. We'll be at Black Hat. We're doing, actually, from the show floor, I'm doing videos of Black Hat this year.
Maybe if you're there, we'll have our people talk to your people. We'll make something happen. I love it.
All right. Hey, Or. First of all, again, congratulations on the Akamai situation.
I hope it closes quickly, and having done, as I said, a few of these, I hope it closes quickly and painlessly because once the lawyers, before they cross all the T's and dot all the I's, it's like going to an exam. But also thank you for the work you're doing with this usage report and putting it out there for people, because, as you said, there's so many talking voices out here vying for attention. People want to know what's right, what's wrong, what's the truth, what's the real deal, and this is important.
Thanks for coming on Techstrong TV. I hope to see you soon. Thank you very much, Alan.
All right, Or. Or Shched, co-founder, CEO, LayerX Security, here on Techstrong TV. We're going to take a break.
We'll be back in a bit.