Allan Juma, Lead Cybersecurity Engineer at ESET, tells us why stronger governance, behavioural monitoring and security controls are essential to managing AI risk without slowing innovation.

South Africa, according to the Microsoft Global AI Diffusion monitor, is leading the continent in Generative AI adoption with 23.1% of the working-age population actively using AI in their daily activities.
Companies have introduced AI into daily operations rapidly, implementing tools across customer service, credit decision-making, marketing and the back-office. However, where AI brings immense value to the organisation, it also introduces risk. AI has widened the attack surface within the business while handling real decisions that can have serious consequences.
ESET found that from March to May 2026, the number of unique AI skills scanned rose from 60,000 to almost 900,000, with more than 25,000 found to be suspicious and over 3,000 malicious. Another study discovered that across 13 frontier models, every model was hijacked at least once in more than 250,000 attack attempts.
Companies have been pressured to take up AI at speed without deeper insight into how it functions, what access it has and how to manage it correctly. Ensuring the security of AI isn’t asking companies to step back and stop using the technology; it’s asking for more discipline around it and more controls around its usage.
This control tends to slip in two places. The first is with the autonomous agent that is capable of acting on its own, fetching data, following links and downloading components across connected systems at machine speeds and with standing permissions. When left unmanaged, these agents could carry harmful code across the AI supply chain without anyone noticing.
The second area is the misuse of publicly available tools within the enterprise ecosystem. Employees reach for solutions like Claude and ChatGPT to quickly resolve a problem or support their work, uploading confidential company data at the same time. When employees operate outside of the walled garden of a secured company AI system, they run the risk of sharing data with the wrong people or introducing malicious code back into the business.
The challenge facing the AI-powered business is how to put controls around both places without losing the value that AI introduces. For example, AI agent security deals with the risk of autonomous AI agents by scanning AI-related files and components, inspecting external URLs handed to the agent and following the full download chain. They are capable of catching an attack before it’s completed. The technology is also capable of AI behavioural monitoring that watches agents as they work and flags anything suspicious. The goal is to ensure the business retains authority over systems that would otherwise operate out of sight.
An autonomous system that exposes personal data doesn’t change the reality – the machine that did it belongs to the business and the responsibility lands on the business. Oversight of AI has become both an engineering and governance issue.
AI does carry risk, but this doesn’t mean that adoption should stall, but rather that the risk is managed effectively.


