Chris Norton | General Manager | Sub-Saharan Africa | Kaspersky | mail me |
Our recent research conducted in the Middle East, Turkiye and Africa (META) region, titled “Cybersecurity in the workplace: Employee knowledge and behaviour”, reveals key insights about AI use in South Africa.
The study found that 72.5% of professionals surveyed in the country use Artificial Intelligence (AI) tools for their work tasks. However, only 30% have received training on the cybersecurity aspects of neural networks. This training is critical for protecting against AI-related risks such as data leaks and prompt injections.
The findings highlight a growing divide between shadow AI vs managed AI in the corporate environment. Many employees rely on AI tools without formal company oversight, which exposes organisations to cybersecurity vulnerabilities.
Understanding AI use and knowledge levels
A vast majority of South African respondents (97%) said they understand the term “generative artificial intelligence”. For many employees, this knowledge goes beyond theory. AI tools are now part of their daily workflow.
Overall, 72.5% of respondents use AI tools for professional tasks. Most commonly, they use them to write or edit texts (54.5%), draft work e-mails (52.4%), create images or videos through neural networks (33.8%) and perform data analytics (47.9%).

These patterns demonstrate the increasing influence of AI on daily productivity and communication.
The training and policy gap
The survey revealed a serious gap in employee preparedness for AI-related risks. Almost half of the professionals surveyed (46.5%) said they have not received any AI-related training.
Among those who have taken courses, 33.5% focused on learning how to use AI tools effectively and how to create prompts. Only 30% received guidance on the cybersecurity aspects of AI use, which is a major concern in the ongoing debate around shadow AI vs managed AI.
AI tools that automate everyday tasks are becoming widespread in many organisations. Yet, they often fall under the category of “shadow IT”, meaning employees use them without formal corporate guidance.
The research shows that 67% of respondents are permitted to use generative AI tools at work. However, 24% said such tools are not allowed, while 9% were unsure of their organisation’s policy.
Moving from shadow AI to managed AI
To make AI usage more secure and transparent, organisations need to implement company-wide policies. These policies should clearly outline where and how AI tools can be used. For instance, companies can prohibit AI use for certain data types, regulate which AI tools employees may use and only approve tools from a verified list.
Such policies must be formally documented. Employees should then receive training to ensure compliance and cybersecurity awareness. After defining these hygiene measures and restrictions, companies should monitor AI usage, identify popular tools and use this data to refine security practices.
These measures will help organisations transition from shadow AI to managed AI, improving both innovation and safety.
Recommendations for secure AI use
For successful AI implementation, companies should avoid the extremes of a total ban as well as a free-for-all. The most effective strategy is a tiered access model, where AI use aligns with the data sensitivity of each department. With comprehensive training on AI cybersecurity, this approach fosters innovation and efficiency while maintaining security standards.
To secure corporate AI use, we recommend that organisations:
- Train employees on responsible AI usage. Courses on AI security from the Automated Security Awareness Platform can help add specialised training to corporate programmes.
- Provide IT specialists with relevant knowledge on exploitation techniques and practical defence strategies. The “Large Language Models Security” training, part of the Cybersecurity Training portfolio, strengthens both employee expertise and organisational safety.
- Ensure all employees install cybersecurity solutions on every device used to access business data. Kaspersky Next products protect against threats such as phishing and fake AI tools, especially given the rise of scammers embedding infostealers in deceptive AI applications.
- Conduct regular surveys to monitor how often employees use AI and for what tasks. This information helps organisations assess both benefits and risks, allowing them to adjust their company policies.
- Use specialised AI proxies that clean queries by removing sensitive information, such as customer IDs and employ role-based access control to prevent misuse.
- Create a comprehensive AI policy that addresses all relevant risks. Our guidelines for secure AI implementation can assist in this process.


























