The biggest AI risk may already be inside your company

Half of South Africans surveyed have bypassed their employers’ restrictions on artificial intelligence (AI) tools in the past year, exposing companies to a new security risk that traditional cyber controls may struggle to contain.

Prejlin Naidoo, partner at Oliver Wyman, a global strategy and risk consultancy, shared the findings at a cybersecurity roundtable hosted by Marsh, an international risk and insurance adviser, in Johannesburg on Tuesday. 

They point to a growing problem for companies racing to adopt generative AI. The corporate security perimeter now extends beyond networks and devices to employees and the AI tools they use. 

Naidoo said the Oliver Wyman Forum Global Consumer Survey 2026 South Africa report is based on responses from 903 South Africans. The report, due to be released in November, found that 50% of those surveyed had bypassed enterprise AI restrictions over the past year. Naidoo said the figure was likely to be underreported. 

Naidoo said the figure was likely to be underreported. “This creates an entirely new kind of threat perimeter,” Naidoo said.

Companies have traditionally approached cybersecurity by securing their networks, devices and approved applications. But employees can now bypass those controls by copying company information into public AI tools such as large language models (LLMs).

Sensitive information can therefore leave a company’s controlled environment without a conventional cyberattack. The risk may also not be concentrated among junior employees. “When we dig into the data, managers are actually much more likely to be guilty of this than their teams,” Naidoo said.

Managers often have access to more sensitive commercial, financial and customer information, potentially making unauthorised AI use a bigger data-security problem than companies assume, said Naidoo.

The problem also persists even where employees have access to enterprise AI tools. Other research points to a similar gap between AI adoption and workplace preparedness. A 2025 Kaspersky study found that 72.5% of professionals surveyed in South Africa use AI tools for work, but only 30% had received training on the cybersecurity risks associated with AI.

Naidoo said communications, media and technology companies have some of the best access to enterprise AI tools in South Africa. Yet 31% of employees in the sector still use unapproved AI tools, compared with 34% across other industries.

He warned that simply giving employees approved AI products or blocking unauthorised ones may not be enough to control how businesses use AI.

The issue is also moving beyond data security to the reliability of AI-produced work. Naidoo said 35% of people surveyed had seen AI-generated work passed off as human work, raising questions about the provenance and reliability of information entering corporate systems.

“Those are two really important areas that I think we need to watch,” Naidoo said, referring to employees sharing sensitive company data with AI tools and the integrity of AI-generated work.

Consumer adoption creates another layer of risk as people become more comfortable letting AI make decisions for them. Naidoo stated that consumer trust in AI has increased fourfold in Oliver Wyman’s research, from 11% in 2023 to 44% now.

At the same time, 41% of people surveyed said they would be comfortable allowing an AI agent to place an order on their behalf. That growing trust creates new opportunities for businesses. It also expands ways AI can interact with company systems, customer information and transactions.

The discussion at the Marsh cybersecurity roundtable also highlighted why AI-related risks cannot be separated from broader cyber resilience. Marsh Africa and South Africa chief executive officer (CEO) Spiros Fatouros said recent cyber incidents involving South African insurance companies showed how attackers can gain access through suppliers and partners rather than directly attacking a targeted company’s systems.

“The key message is that cyber resilience can no longer be viewed solely as an internal IT issue,” Fatouros said.

He argued that companies need to consider the security of suppliers, partners, cloud providers and other organisations connected to their operations. The same principle applies to employees and the AI tools they use.

Keletjo Chiloane, a career and workforce consulting executive at Marsh, said companies also need to redesign the division of work between humans and machines rather than simply inserting AI into existing processes.

“AI is not just a technology implementation. It changes how work gets done, which means organisations need to rethink roles, responsibilities and the skills people need to work alongside these systems,” she said.

True scale demands moving beyond surface-level integrations to robust execution. We’ve filtered the noise out of Moonshot 2026, optimising the conference strictly for high-calibre connections between startup founders, global financial operators, enterprise leaders and individuals rewiring Africa’s technical frameworks. Get 20% off Early Bird tickets for a limited time.

Click Here For The Original Source

——————————————————–

..........

.

.