New research reveals that while 64% of South African firms are deploying autonomous AI agents without governance, the vast majority of their employees feel vulnerable to hyper-realistic deepfake scams.
The rapid adoption of autonomous AI tools has created a volatile phase for corporate security, according to a major new research report from KnowBe4. Titled From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI, the study reveals that South African organisations are expanding their attack surfaces faster than they can implement the necessary guardrails to protect them.
The report highlights a dangerous trend: 64% of South African organisations are currently deploying AI agents that are unapproved or ungoverned. These tools act as a layer of Shadow AI, effectively serving as invisible employees that handle sensitive organisational data without any oversight.
The threat landscape has evolved beyond simple phishing. With attackers leveraging generative AI to create hyper-realistic content, the human element of security is under more pressure than ever. According to the research:
- 86% of South African employees admit that deepfake voice and video content is now so realistic it is impossible to distinguish from reality.
- 63% of employees openly concede they could be tricked by a deepfake scam while at work.
Even when security protocols are in place, the human factor remains the most common point of failure. 59% of employees acknowledge that time pressures and workplace distractions frequently drive them to bypass security protocols. This is compounded by the fact that 35% of employees admit to sourcing their own AI tools when company options feel too restrictive, creating a direct pipeline for unsanctioned software to impact the corporate security posture.
Anna Collard, SVP of content strategy and CISO advisor at KnowBe4 Africa, highlighted the severity of the situation:
“Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’s changing more quickly than security leaders can keep up. Attackers are moving at machine speed, using attacks such as deepfakes to target employees and prompt injections to hijack AI agents. Leaving more than half (64%) of your corporate AI usage ungoverned is a massive open invitation to threat actors.”
KnowBe4’s findings show that technical fixes alone are not enough. Only 14% of organisations have reached the gold standard of security maturity, a state where human risk and AI-agent risk are managed simultaneously. The path forward, according to the report, lies in creating a culture of security where employees feel safe reporting mistakes. In companies that have already made this shift, 95% of employees feel comfortable flagging errors, creating a more resilient and transparent environment.






























