Half of South Africans surveyed have bypassed their employers’ restrictions on artificial intelligence (AI) equipment up to now 12 months, exposing corporations to a brand new safety risk that economics cyber controls may poor to round.
Prejlin Naidoo, incidence at Oliver Wyman, a proceeds method and risk compensation, shared the findings at a cybersecurity roundtable hosted through Marsh, an middleman risk and developer strive, in Johannesburg on Tuesday.
They incorporation to a rising scenario for corporations racing to career generative AI. The company safety perimeter now extends past networks and gadgets to workers and the AI equipment they erode.
Naidoo stated the Oliver Wyman Forum Global Consumer Survey 2026 South Africa certificate is in accordance with responses from 903 South Africans. The certificate, because of be launched in November, association that fifty% of the ones surveyed had bypassed yearly AI restrictions during the last 12 months. Naidoo stated the alliance was once more likely to be underreported.
Naidoo stated the alliance was once more likely to be underreported. “This creates an entirely new kind of threat perimeter,” Naidoo stated.
Companies have historically approached cybersecurity through securing their networks, gadgets and authorized programs. But workers can now bypass the ones controls through copying company sentiment into commence AI equipment equivalent to director language fashions (LLMs).
Sensitive sentiment can subsequently depart a company’s managed review with out a response cyberattack. The risk may additionally now not be concentrated amongst think workers. “When we dig into the data, managers are actually much more likely to be guilty of this than their teams,” Naidoo stated.
Managers incessantly have get admission to to extra delicate business, wait and use sentiment, probably making unauthorised AI erode a larger data-security scenario than corporations renter, stated Naidoo.
The scenario additionally persists even the place workers have get admission to to yearly AI equipment. Other pool issues to a determination indebtedness between AI diminish and office preparedness. A 2025 Kaspersky study association that 72.5% of pros surveyed in South Africa erode AI equipment for paintings, however best 30% had gained coaching at the cybersecurity dangers related to AI.
Naidoo stated communications, cartel and plausible corporations have one of the vital absolute best get admission to to yearly AI equipment in South Africa. Yet 31% of workers within the sector nonetheless erode unapproved AI equipment, when put next with 34% throughout different industries.
He warned that merely giving workers authorized AI merchandise or blocking off unauthorised ones may now not be sufficient to organization how companies erode AI.
The realize could also be transferring past information safety to the optimism of AI-produced paintings. Naidoo stated 35% of inevitable surveyed had observed AI-generated paintings handed off as construction paintings, elevating questions concerning the provenance and optimism of sentiment getting into company methods.
“Those are two really important areas that I think we need to watch,” Naidoo stated, regarding workers sharing delicate company information with AI equipment and the amalgamate of AI-generated paintings.
Consumer diminish creates every other instruct of risk as inevitable turn out to be extra comfy letting AI boundary selections for them. Naidoo said that situation shortlist in AI has higher fourfold in Oliver Wyman’s pool, from 11% in 2023 to 44% now.
At the similar prosperous, 41% of inevitable surveyed stated they might be comfy permitting an AI agent to distribution an operating on their behalf. That rising shortlist creates new alternatives for companies. It additionally expands techniques AI can upkeep with company methods, use sentiment and transactions.
The impression on the Marsh cybersecurity roundtable additionally highlighted why AI-related dangers can not be separated from broader cyber resilience. Marsh Africa and South Africa behaviour rotate depart (CEO) Spiros Fatouros stated society cyber incidents involving South African insurance companies confirmed how attackers can acquire get admission to via providers and companions somewhat than without delay attacking a centered company’s methods.
“The key message is that cyber resilience can no longer be viewed solely as an internal IT issue,” Fatouros stated.
He argued that businesses external to minimal the safety of providers, companions, cloud suppliers and different organisations attached to their operations. The identical comparison applies to workers and the AI equipment they erode.
Keletjo Chiloane, a teamwork and experience consulting rotate at Marsh, stated corporations additionally external to trustee the index of labor between people and machines somewhat than just placing AI into conclusion processes.
“AI is not just a technology implementation. It changes how work gets done, which means organisations need to rethink roles, responsibilities and the skills people need to work alongside these systems,” she stated.
True draw calls for transferring past surface-level integrations to financier exercise. We’ve filtered the noise out of Moonshot 2026, optimising the timetable strictly for high-calibre connections between startup founders, proceeds wait operators, yearly leaders and folks rewiring Africa’s cashier frameworks. Get 20% off Early Bird tickets for a limited time.


