-

Ungoverned AI Agents and Sophisticated Deepfakes Pose Critical Threats for South African Organisations, New KnowBe4 Research Warns

Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

CAPE TOWN, South Africa--(BUSINESS WIRE)--KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of its new research report, "From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI." The findings expose a dangerous reality for modern South African organisations: autonomous AI tools are expanding the corporate attack surface faster than security teams can implement guardrails.

With agentic AI now widely embedded in day-to-day work, 38% of South African cybersecurity leaders report that AI agents are already taking autonomous actions within organisational workflows. However, a lack of governance is leaving organisations exposed; the report shows that a staggering 64% of organisations report their use of AI is unapproved or ungoverned. This unmanaged "Shadow AI" effectively operates as an invisible layer of shadow employees handling sensitive organisational data without oversight.

Key Findings from the Report:

  • 86% of South African employees say that deepfake voice and video content is now so realistic it is impossible to know what to trust and 63% openly admit they could be tricked by a deepfake scam at work.
  • Just over 6 in 10 cybersecurity leaders in South Africa (62%) report that mistakes during everyday work have had the greatest impact on their organisation’s cybersecurity in the past 12 months. Compounding this, 59% of employees acknowledge that time pressures and workplace distractions actively drive them to make critical security mistakes, even when they know the safe protocol.
  • 34% of South Africa’s cybersecurity leaders identify AI-enabled attacks as a key driver of future human-related cybersecurity risks.
  • 35% of employees reported that they commonly source their own agentic AI tools where options are unavailable or restrictive, leaving organisations vulnerable to cyberattacks. Concurrently, 48% of cybersecurity leaders report that the use of unsanctioned software and AI apps has actively impacted their security posture over the past 12 months.
  • Despite 64% of organisations claiming minor security improvements, only 14% have achieved the 'gold standard' maturity level - a fully integrated approach capable of managing human-and-agent-related cyber risk simultaneously. Furthermore, less than half (46%) of security leaders feel "very well prepared" to handle unexpected or emerging AI-driven threats over the next year.

The report shows that organisations making progress are those who prioritise cybersecurity as a culture over a mere function, seamlessly incorporating secure behaviours into daily work. These organisations are creating environments where employees feel safe reporting mistakes, with 95% of employees agreeing.

"Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’s changing more quickly than security leaders can keep up," said Anna Collard, SVP content strategy and CISO advisor at KnowBe4 Africa. "Attackers are moving at machine speed, using attacks such as deepfakes to target employees and prompt injections to hijack AI agents. Leaving more than half (64%) of your corporate AI usage ungoverned is a massive open invitation to threat actors."

The "From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI" report concludes that achieving "Wins" requires organisations to design systems that guide behaviour, build supportive cultures, and shift from tracking failures to reinforcing positive actions, and extending a security-first mindset across both AI agents and humans.

Download the South African data insights here and the Global report here.

Methodology

This research is based on a global survey conducted by Vanson Bourne, polling 4,000 professionals: 800 security decision makers and 3,200 employees, across the Americas, EMEA, and APJ regions, representing organizations with 250 or more employees.

In South Africa, the survey polled 250 professionals: 50 security decision makers and 200 employees.

About KnowBe4

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

More info at www.knowbe4.com. Follow KnowBe4 on LinkedIn and X.

Contacts

Media contact:
Ellie Williams
PR Manager, EMEA
pr@knowbe4.com

KnowBe4


Release Versions

Contacts

Media contact:
Ellie Williams
PR Manager, EMEA
pr@knowbe4.com

More News From KnowBe4

KnowBe4 Research Finds Global Phishing Susceptibility Drops 79% After One Year of Security Awareness Training

TAMPA BAY, Fla.--(BUSINESS WIRE)--KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today released its 2026 Phishing by Industry Benchmarking Report, revealing that organizations can reduce phishing susceptibility by 79% after one year of consistent security awareness training (SAT), despite a threat landscape increasingly powered by artificial intelligence. The report analyzed 42 million phishing simulations across 14.8 million users at 64,000 organi...

KnowBe4 Announces Workforce Security Summit to Address AI-Native Threats and Securing Digital Workforces

TAMPA BAY, Fla.--(BUSINESS WIRE)--KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced its upcoming Workforce Security Summit. The global virtual event is designed to help organizations modernize their security strategies for an era where the corporate workforce is no longer purely human, but comprised of both human employees and AI agents. As attackers rapidly weaponize deepfakes, voice cloning, and AI-powered phishing, traditional defen...

Over Half of British Employees Are Currently Using ‘Unapproved’ AI Tools at Work, KnowBe4 Research Finds

LEEDS, England--(BUSINESS WIRE)--KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, has today revealed the UK-specific findings of its latest research report: From Agentic Risk to Human Wins. The research found that UK organisations are increasingly concerned about employees using unapproved software and AI tools, with 58% of decision makers citing it as their top human-related cyber risk. The concern is well founded: 55% of employees admit to using un...
Back to Newsroom