The rapid adoption of autonomous AI tools is introducing new cybersecurity challenges for enterprises, according to a new KnowBe4 report that examines how organizations are managing both human and AI-driven risks. The research finds that while agentic AI is becoming part of everyday business operations in South Africa, governance has not kept pace, leaving many organizations vulnerable to unauthorized AI use, deepfake attacks, and human error.
As enterprises accelerate the adoption of generative and agentic artificial intelligence, cybersecurity leaders are facing a new challenge: securing not only employees but also autonomous AI systems capable of making decisions and taking actions within business workflows.
That is the central finding of KnowBe4’s latest research report, From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI, which explores how organizations are adapting security strategies as AI becomes embedded across the workplace.
The South African findings paint a picture of rapid AI adoption accompanied by limited governance. According to the study, 38% of South African cybersecurity leaders say AI agents are already performing autonomous actions within organizational workflows. At the same time, 64% report that AI usage across their organizations remains either unapproved or lacks formal governance.
The report describes this phenomenon as “Shadow AI”—employees independently adopting AI applications outside approved IT environments, creating blind spots for security teams and increasing exposure to sensitive corporate data.
Deepfakes and AI-driven attacks reshape enterprise risk
The growing sophistication of AI-generated content is adding another layer of complexity to enterprise security.
According to the survey, 86% of South African employees believe AI-generated voice and video deepfakes have become so convincing that distinguishing authentic communications from fabricated ones is increasingly difficult. Meanwhile, 63% acknowledge they could potentially be deceived by a deepfake attack in the workplace.
These concerns come as cybercriminals increasingly leverage generative AI to automate phishing campaigns, create realistic impersonation attacks, and exploit both employees and AI-powered business systems.
Anna Collard, Senior Vice President of Content Strategy and CISO Advisor at KnowBe4 Africa, said organizations are now defending environments where both humans and AI agents operate simultaneously.
She warned that attackers are increasingly combining deepfake technologies with techniques such as prompt injection attacks that manipulate AI systems into exposing sensitive information or performing unintended actions.
Human behavior remains a major security vulnerability
Despite growing attention on AI-powered threats, the research indicates that human behavior continues to represent one of the largest cybersecurity risks.
Approximately 62% of South African cybersecurity leaders identified mistakes made during routine work as the most significant contributor to cybersecurity incidents over the past year.
Employees themselves recognize the challenge. Nearly 59% reported that workplace pressure, heavy workloads, and distractions increase the likelihood of making security-related mistakes, even when they understand established security procedures.
The findings reinforce an emerging view across the cybersecurity industry that technological controls alone cannot eliminate organizational risk without corresponding investments in employee awareness and security culture.
Shadow AI complicates governance
Unauthorized adoption of AI tools is becoming another growing concern.
The report found that 35% of employees regularly source their own AI applications when approved alternatives are unavailable or too restrictive.
For enterprise security teams, that creates new governance challenges. Nearly 48% of cybersecurity leaders said unsanctioned software and AI applications had negatively affected their organization’s security posture during the past 12 months.
As organizations adopt multiple AI platforms, maintaining visibility into how sensitive information is shared across applications is becoming increasingly difficult.
Major technology providers including Microsoft, Google, OpenAI, Salesforce, and Amazon Web Services have expanded enterprise AI governance capabilities in response to growing demand for identity management, data protection, and policy enforcement across AI ecosystems.
Security culture emerges as a competitive advantage
While many organizations report incremental improvements in cybersecurity, relatively few have achieved mature governance models.
According to the study, 64% of organizations reported minor security improvements, yet only 14% reached what the report describes as a fully integrated security maturity level capable of managing both human and AI-related cyber risks simultaneously.
Confidence levels also remain modest. Less than half (46%) of security leaders said they feel very well prepared to respond to emerging AI-driven cyber threats over the next year.
The report suggests organizations making the greatest progress share a common characteristic: they treat cybersecurity as an organizational culture rather than solely an IT function.
Among those organizations, 95% of employees reported feeling comfortable reporting mistakes without fear of blame, creating opportunities for faster incident detection and continuous improvement.
This reflects a broader shift toward behavioral cybersecurity strategies that emphasize positive reinforcement, secure-by-design workflows, and collaboration between technology, leadership, and employees.
What the findings mean for enterprise security
The research highlights a growing challenge facing organizations worldwide as AI adoption accelerates faster than governance frameworks.
According to Gartner, AI governance is becoming an essential component of enterprise risk management as organizations expand the use of autonomous systems. IBM’s Cost of a Data Breach Report has similarly found that organizations with mature security governance and employee awareness programs generally experience lower breach costs and faster incident response.
As businesses continue integrating AI assistants and autonomous agents into everyday operations, cybersecurity strategies are increasingly shifting beyond traditional endpoint protection toward governance models that secure people, AI systems, and the data connecting them.
For enterprise leaders, the findings suggest that successful AI adoption will depend not only on deploying advanced technologies but also on establishing clear governance policies, improving workforce awareness, and embedding security into everyday decision-making.
Market Landscape
Enterprise cybersecurity is entering a new phase as organizations deploy generative AI, agentic AI, and autonomous digital assistants across business functions. Security vendors including Microsoft, Google Cloud, Cisco, CrowdStrike, Palo Alto Networks, and KnowBe4 are expanding AI governance, identity management, phishing protection, and security awareness capabilities to address emerging risks associated with AI-powered workflows and human-AI collaboration.
Top Insights
- KnowBe4’s research found that 64% of South African organizations operate with unapproved or ungoverned AI usage, increasing exposure to Shadow AI and data security risks.
- Deepfake threats continue to grow, with 86% of surveyed employees saying AI-generated voice and video content has become difficult to distinguish from authentic communications.
- Human error remains the leading cybersecurity concern, with routine workplace mistakes identified by 62% of security leaders as the biggest contributor to cyber incidents.
- Nearly half of cybersecurity leaders reported that unauthorized AI applications have negatively affected their organization’s security posture during the past year.
- Organizations with stronger cybersecurity cultures—where employees are encouraged to report mistakes—demonstrate higher levels of AI security maturity and preparedness.
Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights
Business Wire, a Berkshire Hathaway company, is the global leader in press release distribution and regulatory disclosure. Public relations, investor relations, public policy and marketing professionals rely on Business Wire for secure and accurate distribution of market-moving news and multimedia. Founded in 1961, Business Wire is a trusted source for news organizations, journalists, investment professionals and regulatory authorities, delivering news directly into editorial systems and leading online news sources via its multi-patented NX network. Business Wire’s global newsrooms are available to meet the needs of communications professionals and news media worldwide.





