Boards are underestimating the AI agent risk

0
100

Heino Gevers | Vice President | Global Customer Success | Mimecast | mail me |


Artificial Intelligence (AI) is rapidly moving from experimentation to execution within South African organisations. Organisations increasingly embed AI agents across business functions, including finance, customer service, IT and operations. However, a significant governance concern is emerging.

While 81% of Fortune 500 companies already run active AI agents, only 14% have secured full security approval for those deployments. For boards and executive teams, this trend highlights the AI agent risk. Many organisations lack visibility into where, how and by whom these agents operate.

Ask chief information security officers for a definitive inventory of AI agents in their environments. Many cannot provide one with confidence. This challenge mirrors historical IT asset management issues. However, the consequences are far greater. AI agents do not function as passive tools. Instead, they increasingly operate autonomously. They access systems, process sensitive information and execute actions at scale and speed.

Meanwhile, many organisations still struggle with basic phishing attacks and business email compromise. This reality further amplifies the AI agent risk.

The rise of shadow AI

In South Africa, a persistent shortage of cybersecurity skills compounds the problem. Consequently, a growing “shadow AI” gap has emerged. Agents increasingly operate outside formal governance structures.

Most organisations have a limited understanding of the systems these agents access. They also struggle to identify the data they process. As a result, boards must ask more than whether an organisation has an AI strategy. Instead, they must determine whether the organisation controls how AI operates in practice.

The scale of future deployment makes this issue urgent. According to IDC, enterprises will deploy more than one billion AI agents by 2029. This figure represents a fortyfold increase from current levels. Collectively, these agents will execute an estimated 217 billion actions each day. These actions will include reading emails, summarising financial data and initiating workflows across critical systems.

In such an environment, even minor oversight gaps can create substantial exposure. This reality reinforces the AI agent risk facing organisations worldwide.

Regulation will not differentiate

The regulatory dimension also demands attention. South Africa’s Protection of Personal Information Act (POPIA) imposes clear obligations on organisations to safeguard personal information.

Importantly, POPIA applies regardless of how organisations process information. It does not distinguish between human error and machine-driven exposure. From the perspective of the Information Regulator, harm remains harm. Yet many organisations cannot identify which AI agents access personal information. Consequently, they cannot accurately measure or manage compliance risk.

Without this visibility, organisations increase their exposure to regulatory scrutiny and potential penalties.

A shifting threat landscape

At the same time, the threat landscape continues to evolve. Traditionally, organisations viewed email as a human vulnerability. Today, attackers increasingly target AI agents through email channels.

Cybercriminals now use email as a delivery mechanism for prompt injections and malicious instructions. These attacks aim to manipulate systems that automatically read and act on messages.

The inbox itself has not changed. However, the target has changed significantly. Employees are no longer the only parties vulnerable to deception. Systems acting on their behalf can also become targets.

This shift exposes weaknesses in traditional security approaches. Existing email security and data loss prevention tools were designed around human behaviour and decision-making. They were not designed for environments where AI agents can trigger actions instantly and at scale. As a result, organisations may rely on controls that no longer suit current realities.

Human risk still drives outcomes

Importantly, AI does not create entirely new risks. Instead, it amplifies existing vulnerabilities. Limited visibility, inconsistent governance and human behavioural risks already exist. AI simply accelerates these challenges.

In most organisations, a small group of users generates a disproportionate share of security incidents. In some cases, as few as 8% of users drive 80% of the risk. The same pattern will likely emerge with AI. Higher-risk users may deploy or influence higher-risk agents. Consequently, organisations must recognise that the AI agent risk often originates with human decision-making and governance gaps.

For boards, the message is clear. They must integrate AI governance into enterprise risk management. They should not treat it as a niche technical issue.

This approach requires visibility into who deploys AI agents. It also requires visibility into what access those agents possess and whether their behaviour aligns with organisational policy. Furthermore, organisations need real-time oversight. They must manage risk as it occurs rather than attempt to contain it afterwards.

From tools to workforce

Ultimately, organisations must treat AI agents as extensions of their workforce. This requires the same standards of accountability, monitoring and control that apply to employees.

Without these controls, organisations risk creating a parallel layer of ungoverned activity inside their operations. For South African boards, the margin for error continues to shrink. AI adoption accelerates rapidly. Regulatory expectations remain firm. Threat actors also continue to adapt.

In this environment, organisations cannot afford uncertainty. Not knowing where the AI agent risk resides is no longer merely a technical gap. It represents a governance failure. Regulators are unlikely to overlook such failures.


 



LEAVE A REPLY

Please enter your comment!
Please enter your name here