PREVIOUS ARTICLENEXT ARTICLE
FEATURE ARTICLES
By 14 August 2026 | Categories: feature articles

0

An employee under pressure at a logistics firm finds a productivity boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary. It saves a couple of hours of reading. They may also see their email client now integrates their favourite AI tool, so they do so and save even more time.

When the organisation subsequently deploys an autonomous AI agent integrated into its internal environment, the agent studies the employee's workflow to identify efficiencies and increasingly acts on their behalf. That assistant doesn't just learn from a security policy. It learns from actual behaviour.

Because AI agents are often treated like infallible magic bullets, we need to change the way we look at the AI colleagues we are getting, states Anna Collard, SVP of content strategy and CISO advisor at KnowBe4 Africa. “In a quite real way, we're essentially working with digital toddlers that watch and learn from us, including our laxer habits.”

The anthropomorphism trap

Humans are increasingly falling into the anthropomorphism trap, in which they project human characteristics onto AI agents. It's a natural instinct, but one that can create a dangerous illusion of competence. "The personification is where people can get into deeper trouble," Collard warns.

"We interact with these agents as if they are eager junior employees, assuming they possess common sense and a basic ethical compass."

But an AI agent has no conscience, no stake in the outcome, and no fear of disciplinary action. "A human can be reasoned with, can grasp why a rule exists, and can exercise judgement in a novel situation," Collard explains. "An agent – however fluent it sounds – is pattern-matching against its training and context.

“That fluent, human-sounding language is a programmed output, not an indicator of understanding – and treating it as a trusted colleague is a severe vulnerability,” Collard cautions.

Yet the similarities are real, too. "Both learn from examples, from feedback, and from the behaviour modelled around them, and both can be manipulated through language," she explains. 

Both develop habits that drift from intended behaviour and need recalibrating or even correcting. Both can be overconfident, and both can be nudged. The behavioural-science toolkit, baselining, reinforcement, simulation, and monitoring for drift, transfers between the two, which is why structured behavioural data is such a powerful lens for managing both.

Agentic drift and the digital toddler

The industry term for an AI system gradually deviating from its original alignment is "agentic drift". It occurs because agents accumulate behavioural patterns from new data, user interactions and environmental feedback over time. If the dominant feedback it receives from an employee is a pattern of bypassing security guardrails to speed up a process, the agent's parameters could very well drift to accommodate that behaviour.

"We are in many ways introducing digital toddlers into the corporate network," Collard explains. "They watch everything, they mimic what they see, and they lack the maturity to independently distinguish between a sanctioned process and a dangerous shortcut."

"This drift compounds the risk of prompt injection – a technique where attackers disguise malicious instructions as legitimate input, because a moving behavioural baseline makes it harder to tell an attacker's injected instruction from the agent's own evolving habits."  

Why you can't monitor one without the other

Risk, Collard argues, now flows in both directions. "Agents act with real privileges, at speed and scale, sometimes even with less oversight than a junior employee would get, yet a drifting agent can cause damage no single human generally could." 

And the two risk profiles are coupled: an inadvertently and well-intentioned but careless human shapes a careless agent, and, to a certain extent, vice versa. "An over-trusted agent makes humans complacent, lowering their guard until they stop checking its output at all. That's automation bias, and it's a measurable human risk."

You need behavioural baselines for both humans and agents, and must watch for drift. "The real risk is in the interaction between them," Collard notes. Detecting drift requires knowing what normal behaviour looks like over time.

"The challenge is implementing this kind of oversight without it becoming costly," Collard explains. "The answer isn't to scrutinise everything with equal intensity.” This is layered behavioural monitoring: where lightweight signals continuously track whether humans and agents are behaving as expected, while more in-depth analysis only kicks in when something looks like an anomaly, a drift, or a sign of intent gone wrong." 

Strong behavioural baselines, she argues, are what make this multi-layered approach possible, turning governance from a costly checkpoint into a continuous risk signal.

The urgency is real

By the end of 2026, Gartner projects that 40% of enterprise applications will include task-specific AI agents. Yet adoption is dramatically outpacing governance. KnowBe4's recent report, "From Agentic Risk to Human Wins," found that 38% of South African cybersecurity leaders report that AI agents are already taking autonomous actions within organisational workflows. However, a lack of governance is leaving organisations exposed; the report shows that a staggering 64% of organisations report their use of AI is unapproved or ungoverned. The result is a widening issue: unmonitored agents executing autonomous transactions that can lead to data leakage, runaway operational costs, or both.

The solution is not to block AI, though, but to recognise that human and agent risks are inextricably linked. An organisation cannot secure its AI without first securing the habits of the employees training it. The new paradigm of security awareness and greater cyber resilience is about ensuring that the digital assistants watching over employees’ shoulders are learning the right lessons.

USER COMMENTS

Read
Magazine Online
TechSmart.co.za is South Africa's leading magazine for tech product reviews, tech news, videos, tech specs and gadgets.
Start reading now >
Download latest issue

Have Your Say


What new tech or developments are you most anticipating this year?
New smartphone announcements (46 votes)
Technological breakthroughs (29 votes)
Launch of new consoles, or notebooks (14 votes)
Innovative Artificial Intelligence solutions (29 votes)
Biotechnology or medical advancements (25 votes)
Better business applications (160 votes)