The AI is inside - Securing the business in the age of autonomous AI
By Industry Contributor 2 October 2026 | Categories: feature articles
By Allan Juma, Lead Cybersecurity Engineer at ESET
South Africa, according to the Microsoft Global AI Diffusion monitor, is leading the continent in generative AI adoption with 23.1% of the working-age population actively using AI in their daily activities. Companies have introduced AI into daily operations rapidly, implementing tools across customer service, credit decision-making, marketing and the back-office. However, where AI brings immense value to the organisation, it also introduces risk. AI has widened the attack surface within the business while handling real decisions that can have serious consequences.
The data behind the risk is concerning. ESET found that from March to May 2026, the number of unique AI skills scanned rose from 60,000 to almost 900,000, with more than 25,000 found to be suspicious and over 3,000 malicious. Another study discovered that across 13 frontier models, every model was hijacked at least once in more than 250,000 attack attempts. The risk introduced by AI has not yet been fully fathomed across the board, and the consequences are easy to underestimate.
Imagine a model inside an insurance company that decides to change the parameters of all customer’s insurance? It could and would create an immediate financial and regulatory crisis caused by a system doing as it was instructed to do by a malicious or rogue AI agent.
While this isn’t something that can happen every day, it is concerning that AI has the authority to make decisions with real weight as it moves from people to systems and accountability isn’t moving with it. That gap between what AI is now trusted to do versus oversight around what it does and who introduced it to the business is a security question the South African business must answer this year.
It is not a South Africa-specific problem either. Globally, companies are wrestling with the AI conundrum. Companies have been pressured to take up AI at speed without deeper insight into how it functions, what access it has, and how to manage it correctly. Ensuring the security of AI isn’t asking companies to step back and stop using the technology; it’s asking for more discipline around it, and more controls around its usage.
This control tends to slip in two places. The first is with the autonomous agent that is capable of acting on its own, fetching data, following links and downloading components across connected systems at machine speeds and with standing permissions. When left unmanaged, these agents could carry harmful code across the AI supply chain without anyone noticing. The second area is the misuse of publicly available tools within the enterprise ecosystem.
Employees reach for solutions like Claude and ChatGPT to quickly resolve a problem or support their work, uploading confidential company data at the same time. When employees operate outside of the walled garden of a secured company AI system, they run the risk of sharing data with the wrong people or introducing malicious code back into the business.
The challenge facing the AI-powered business is how to put controls around both places without losing the value that AI introduces. For example, AI agent security deals with the risk of autonomous AI agents by scanning AI-related files and components, inspecting external URLS handed to the agent, and following the full download chain. They are capable of catching an attack before it’s completed. The technology is also capable of AI behavioural monitoring that watches agents as they work and flags anything suspicious. The goal is to ensure the business retains authority over systems that would otherwise operate out of sight.
These controls are critical to companies in South Africa right now. POPIA and the Information Regulator have teeth, and any company suffering a compromise has to report this as soon as possible. An autonomous system that exposes personal data doesn’t change the reality – the machine that did it belongs to the business, and the responsibility lands on the business. Oversight of AI has become both an engineering and governance issue.
AI does carry risk, but this doesn’t mean that adoption should stall, but rather that the risk is managed effectively. Like flying, there is a chance that things can go wrong, and the sensible answer is not to refuse to fly but to choose the airline with the best record. That’s the posture ESET takes, ensuring that AI is monitored and managed pre-emptively and under human oversight so it becomes both the surface that has to be defended and the means of defending it.
Most Read Articles

Have Your Say
What new tech or developments are you most anticipating this year?

