PREVIOUS ARTICLENEXT ARTICLE
FEATURE ARTICLES
By 11 September 2026 | Categories: feature articles

0

By Ramprakash Ramamoorthy, director of AI research at ManageEngine

There’s no denying that employees are increasingly relying on AI tools to support their workloads and tasks. AI saves time and, in many cases, improves clarity and speed when used correctly. However, when sensitive company information is shared with AI in the process, businesses must question how the information is stored and processed, and whether the technology can be trusted with it.

According to PwC’s Africa workforce hopes and fears survey, 64% of African workers reported using AI at work, compared with 54% globally. South African executives are particularly optimistic, with 91% saying AI has already improved both the quality and productivity of their work. As employees increasingly incorporate AI into everyday tasks, South African organisations need to consider whether their own visibility and governance are keeping pace with the way these tools are actually used.

Considering that employees use these tools to perform ordinary work, like drafting documents, summarising meetings, and analysing reports, it is important to recognise that employee behaviour that results in data loss is not necessarily malicious. The security gap can emerge when an employee simply does not realise that asking an AI tool for help may also involve sharing company data.

Organisations also need to understand what information is being shared with AI tools to mitigate the risks of shadow AI. Governing the use of AI, however, is not as easy as controlling access to particular applications. These questions also have implications under South Africa's Protection of Personal Information Act (POPIA). Personal information remains subject to data-protection requirements regardless of whether it is being processed through an established enterprise system or entered into an AI platform. South Africa's emerging national AI policy similarly emphasises POPIA-aligned data governance as AI adoption expands.

Make the safe route the usual route

Employers cannot simply ban or prevent employees from using AI without providing useful alternatives, as this risks pushing AI use further out of their control. Instead, organisations need to make approved AI use clear, practical, and accessible enough to support the way people actually work. A ManageEngine study conducted in the United States and Canada might have the answers that South African organisations are seeking. It found that 63% of IT leaders believe integrating approved AI tools into standard workflows could help reduce shadow AI, while 66% of employees said better education to understand the risks would make them more likely to follow official AI-use policies.

Policies and education, however, need to be supported by technical safeguards. Organisations need visibility into the AI applications being accessed across their IT environments, including unsanctioned services, as well as the prompts, uploads, and other interactions taking place within these applications. From there, security teams can apply controls according to risk, which might mean allowing access to an approved AI platform while restricting sensitive file uploads or prompt submissions, preventing the use of personal accounts, or blocking a high-risk service altogether.

Data loss prevention controls can provide another safeguard by identifying sensitive information and preventing it from being transferred to unauthorised applications. Understanding how AI is being used can also show organisations where employees are turning to unsanctioned tools because existing technology is not meeting a genuine need. This insight can inform which AI capabilities businesses choose to approve and integrate into their workflows, making the secure option useful enough that employees have less reason to look elsewhere.

Shadow AI challenges facing organisations today largely concern what employees choose to share. However, as AI becomes more deeply integrated into workplace systems, the question will extend beyond employee behaviour to what these systems themselves are permitted to access. Organisations that establish clear governance, provide useful and approved AI tools, and put the right technical safeguards in place will be better positioned to close this security gap without standing in the way of responsible AI adoption.

USER COMMENTS

Read
Magazine Online
TechSmart.co.za is South Africa's leading magazine for tech product reviews, tech news, videos, tech specs and gadgets.
Start reading now >
Download latest issue

Have Your Say


What new tech or developments are you most anticipating this year?
New smartphone announcements (46 votes)
Technological breakthroughs (29 votes)
Launch of new consoles, or notebooks (14 votes)
Innovative Artificial Intelligence solutions (29 votes)
Biotechnology or medical advancements (25 votes)
Better business applications (160 votes)