CIO Influence
CIO Influence News Machine Learning Security

Ungoverned AI Agents and Sophisticated Deepfakes Pose Critical Threats for South African Organisations, New KnowBe4 Research Warns

Ungoverned AI Agents and Sophisticated Deepfakes Pose Critical Threats for South African Organisations, New KnowBe4 Research Warns

KnowBe4 Unveils Brand Refresh to Celebrate 15 Years of Delivering Human Risk Management

Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of its new research report, “From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI.” The findings expose a dangerous reality for modern South African organisations: autonomous AI tools are expanding the corporate attack surface faster than security teams can implement guardrails

Also Read: CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX

With agentic AI now widely embedded in day-to-day work, 38% of South African cybersecurity leaders report that AI agents are already taking autonomous actions within organisational workflows. However, a lack of governance is leaving organisations exposed; the report shows that a staggering 64% of organisations report their use of AI is unapproved or ungoverned. This unmanaged “Shadow AI” effectively operates as an invisible layer of shadow employees handling sensitive organisational data without oversight.

Key Findings from the Report:

  • 86% of South African employees say that deepfake voice and video content is now so realistic it is impossible to know what to trust and 63% openly admit they could be tricked by a deepfake scam at work.
  • Just over 6 in 10 cybersecurity leaders in South Africa (62%) report that mistakes during everyday work have had the greatest impact on their organisation’s cybersecurity in the past 12 months. Compounding this, 59% of employees acknowledge that time pressures and workplace distractions actively drive them to make critical security mistakes, even when they know the safe protocol.
  • 34% of South Africa’s cybersecurity leaders identify AI-enabled attacks as a key driver of future human-related cybersecurity risks.
  • 35% of employees reported that they commonly source their own agentic AI tools where options are unavailable or restrictive, leaving organisations vulnerable to cyberattacks. Concurrently, 48% of cybersecurity leaders report that the use of unsanctioned software and AI apps has actively impacted their security posture over the past 12 months.
  • Despite 64% of organisations claiming minor security improvements, only 14% have achieved the ‘gold standard’ maturity level – a fully integrated approach capable of managing human-and-agent-related cyber risk simultaneously. Furthermore, less than half (46%) of security leaders feel “very well prepared” to handle unexpected or emerging AI-driven threats over the next year.

The report shows that organisations making progress are those who prioritise cybersecurity as a culture over a mere function, seamlessly incorporating secure behaviours into daily work. These organisations are creating environments where employees feel safe reporting mistakes, with 95% of employees agreeing.

“Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’s changing more quickly than security leaders can keep up,” said Anna Collard, SVP content strategy and CISO advisor at KnowBe4 Africa. “Attackers are moving at machine speed, using attacks such as deepfakes to target employees and prompt injections to hijack AI agents. Leaving more than half (64%) of your corporate AI usage ungoverned is a massive open invitation to threat actors.”

The “From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI” report concludes that achieving “Wins” requires organisations to design systems that guide behaviour, build supportive cultures, and shift from tracking failures to reinforcing positive actions, and extending a security-first mindset across both AI agents and humans.

Catch more CIO Insights: What Does “Job-Ready” Really Mean in IT and Cybersecurity?

[To share your insights with us, please write to psen@itechseries.com ]

Related posts

Vultr Cloud AI Added to Liftr Insights Data

PR Newswire

NetObjex Partners with Zortag for Anti-Counterfeiting and Tracking of Assets for the Digital Economy

CIO Influence News Desk

Sun Life Deploys Privacera to Accelerate AWS Migration and Unify Data Access Governance and Compliance

CIO Influence News Desk