The rapid adoption of artificial intelligence in South African workplaces has outpaced security policies, creating new vulnerabilities for organizations. A recent survey indicates that half of employees have circumvented employer-imposed AI limits, exposing companies to unseen threats.
Introduction
Findings from an Oliver Wyman survey, presented at a Marsh cybersecurity roundtable in Johannesburg, show that 50% of 903 South African respondents bypassed enterprise AI restrictions over the past year. The actual figure is likely higher, as the analyst noted the data is probably underreported. This shift expands the corporate security perimeter beyond traditional networks and devices to include the AI tools and the people using them.
What Happened
Employees are bypassing controls by copying company information into public AI tools such as large language models. This allows sensitive data to leave a company's controlled environment without a conventional cyberattack. The study also found that managers are notably more likely than their teams to bypass restrictions, often because they access more sensitive commercial and financial information. Additionally, a 2025 Kaspersky study revealed that while 72.5% of South African professionals use AI for work, only 30% have received training on the associated cybersecurity risks.
Why This Matters
When employees input proprietary data into public AI systems, information can exit the organization without a traditional cyberattack, widening the threat landscape. Consumer trust in AI has surged from 11% in 2023 to 44% now, and 41% of users are comfortable allowing AI agents to make purchases on their behalf, expanding the ways AI can interact with corporate systems. The risk is further amplified by the fact that 35% of those surveyed have seen AI-generated work presented as human output, raising concerns about information reliability.
Key Takeaways
- Half of surveyed South African employees have bypassed workplace AI restrictions, often without IT or management awareness.
- Managers are more likely than junior staff to use unapproved AI tools, increasing data-exposure risk.
- Traditional cybersecurity controls designed for networks and devices are insufficient against AI-mediated data leaks.
- Only about one-third of professionals using AI at work have received cybersecurity training on the technology.
- Growing consumer trust in AI, with 44% trust now versus 11% in 2023, increases organizational exposure.
- Companies must rethink roles, responsibilities, and skills to safely integrate AI rather than simply blocking or approving tools.
Conclusion
The findings underscore that AI security is no longer just an IT issue—it is a business-wide concern. As AI adoption deepens, organizations must move beyond surface-level controls and redesign how humans and machines collaborate, ensuring that security keeps pace with innovation.




Discussion
Join the conversation
Thoughtful reactions, questions, and follow-up ideas help shape the next story.