Akamai API Security Survey: AI-related API incidents top the list, costing Japanese companies approximately 246 million JPY per incident
Akamai's APAC survey reveals API security incidents are increasingly driven by AI, with Japanese companies facing an average incident cost of 246 million JPY.
📋 Article Processing Timeline
- 📰 Published: May 25, 2026 at 20:00
- 🔍 Collected: May 25, 2026 at 11:31
- 🤖 AI Analyzed: May 28, 2026 at 11:32 (72h 0m after Collected)
Akamai has revealed new survey findings on how API security is impacted by the rise of AI adoption in the Asia-Pacific region. The Akamai API Security Impact Survey (APAC edition) found that 81% of APAC respondents experienced security incidents related to APIs in the past 12 months. Financial losses are also notable, with the average estimated cost per incident surging beyond 1 million USD (approximately 155 million JPY), significantly higher than the 580,000 USD reported in last year's survey. As AI changes the methods and scale of attacks, expanding blind spots are becoming increasingly clear.
The survey covered 640 cybersecurity decision-makers in China, India, Japan, and Singapore. 43% of respondents identified API attacks related to AI technologies—including applications, agents, and Large Language Models (LLMs)—as the most common type of incident. The findings also point to a lack of continuous visibility: only 22% of respondents claimed to have full insight into their APIs and an understanding of which APIs return sensitive information.
These results indicate an widening gap between the ambition for digitalization and security readiness. As companies rapidly deploy AI-enabled services, monitoring, managing, and protecting APIs has become more difficult, increasing risks such as service disruption, data leaks, and higher operating costs.
Reuben Koh, Director of Security Technology & Strategy for Akamai Technologies in the Asia-Pacific and Japan region, stated: "While organizations in APAC are rapidly expanding their AI utilization, the security foundations supporting this growth often lack the necessary robustness. Because APIs and AI work in tandem, enterprises must treat API security as a core element when building genuinely trustworthy AI systems."
Key highlights from the APAC survey:
- AI-related API attacks are the most common in APAC: 43% of respondents reported experiencing attacks on APIs related to AI technologies, apps, agents, or LLMs in the past year.
- India and Singapore reported the highest frequency of incidents: 93% of companies in India and 90% in Singapore experienced API security incidents in the past year.
- Japan recorded the highest average cost per incident: The average cost of API security incidents reached 1.59 million USD (approximately 246 million JPY) in Japan, compared to 1.33 million USD in Singapore.
- Security maturity remains uneven: While 72% of respondents stated they increased focus on API security compared to the previous year, only 19% reported having security testing fully integrated across the entire API software development lifecycle and CI/CD pipeline.
Across the four markets surveyed, companies are generally increasing focus on API security, clarifying ownership, and strengthening testing. However, as AI transitions from experimentation to scaling, the reality is that the benefits gained have not yet been translated into consistent protection.
The survey covered 640 cybersecurity decision-makers in China, India, Japan, and Singapore. 43% of respondents identified API attacks related to AI technologies—including applications, agents, and Large Language Models (LLMs)—as the most common type of incident. The findings also point to a lack of continuous visibility: only 22% of respondents claimed to have full insight into their APIs and an understanding of which APIs return sensitive information.
These results indicate an widening gap between the ambition for digitalization and security readiness. As companies rapidly deploy AI-enabled services, monitoring, managing, and protecting APIs has become more difficult, increasing risks such as service disruption, data leaks, and higher operating costs.
Reuben Koh, Director of Security Technology & Strategy for Akamai Technologies in the Asia-Pacific and Japan region, stated: "While organizations in APAC are rapidly expanding their AI utilization, the security foundations supporting this growth often lack the necessary robustness. Because APIs and AI work in tandem, enterprises must treat API security as a core element when building genuinely trustworthy AI systems."
Key highlights from the APAC survey:
- AI-related API attacks are the most common in APAC: 43% of respondents reported experiencing attacks on APIs related to AI technologies, apps, agents, or LLMs in the past year.
- India and Singapore reported the highest frequency of incidents: 93% of companies in India and 90% in Singapore experienced API security incidents in the past year.
- Japan recorded the highest average cost per incident: The average cost of API security incidents reached 1.59 million USD (approximately 246 million JPY) in Japan, compared to 1.33 million USD in Singapore.
- Security maturity remains uneven: While 72% of respondents stated they increased focus on API security compared to the previous year, only 19% reported having security testing fully integrated across the entire API software development lifecycle and CI/CD pipeline.
Across the four markets surveyed, companies are generally increasing focus on API security, clarifying ownership, and strengthening testing. However, as AI transitions from experimentation to scaling, the reality is that the benefits gained have not yet been translated into consistent protection.
FAQ
AkamaiのAPIセキュリティ調査によると、APAC地域で最も一般的なインシデントは何ですか?
回答者の43%が、AI技術(アプリ、エージェント、大規模言語モデルなど)に関連するAPI攻撃を最も一般的なインシデントとして挙げています。
調査対象となった国の中で、日本企業におけるAPIセキュリティインシデント1件あたりの平均被害額はどれくらいですか?
日本におけるAPIセキュリティインシデントの平均被害額は159万米ドル(約2億4,600万円)に達し、調査対象国の中で過去最高を記録しました。
企業がAIを急速に導入する中で、セキュリティ上の課題は何ですか?
APIの監視、管理、保護が困難になり、サービスの中断、データの漏えい、運用コストの増加といったリスクが高まっています。また、APIの機微情報への可視性が低いことも課題です。
APIセキュリティへの注力度は昨年度と比べてどう変化しましたか?
回答者の72%がAPIセキュリティへの注力度が前年より増したと答えていますが、ソフトウェア開発ライフサイクルにセキュリティテストが完全に組み込まれている企業はわずか19%です。
APIセキュリティインシデントの頻発は何を示唆していますか?
システムの複雑さに対して、既存のセキュリティ対策が追いついていない現状と、デジタル化への意欲とセキュリティ備えの間のギャップが拡大していることを示しています。