Shadow AI at SMBtech

Half Of ANZ Organisations Run AI Agents Without Governance As Deepfake Threats Escalate, Research Finds

Surprisingly Useful AI Article Enhancements

Half of all organisations in Australia and New Zealand are deploying AI agents with little to no formal governance, while 85 per cent of employees say deepfake content has become too realistic to trust, according to new research from cybersecurity firm KnowBe4.

The findings come from the company’s “From Agentic Risk to Human Wins” report, based on a global survey conducted by Vanson Bourne that polled 4,000 professionals across the Americas, EMEA and APJ regions. Of those, 75 security decision-makers and 200 employees were based in Australia and New Zealand.

The report paints a picture of a hybrid threat environment in which both AI agents and human employees are being targeted, often at machine speed.

Shadow AI Operating Without Oversight

According to the research, 64 per cent of surveyed organisations in ANZ deploy autonomous AI agents capable of taking actions on their own within workflows. That figure exceeds the global average of 58 per cent.

However, 50 per cent of organisations report that their AI usage is entirely unapproved or lacks formal corporate governance. KnowBe4 describes this unmanaged layer as “Shadow AI” – tools that effectively operate as invisible employees handling sensitive organisational data without oversight.

The problem is being compounded by workers sourcing their own tools. Fifty-nine per cent of employees reported that they commonly find their own agentic AI tools where options provided by their organisation are unavailable or restrictive. The same proportion of cybersecurity decision-makers (59 per cent) reported that unsanctioned software and AI applications have directly affected their security posture over the past 12 months.

Fifty-seven per cent of Australian workers also acknowledged that they intentionally use workarounds to bypass organisational security controls for productivity purposes.

Deepfakes Outpacing Human Detection

The research highlights a gap between employee confidence and leadership perception when it comes to AI-generated deception.

Eighty-five per cent of ANZ employees stated that deepfake voice and video content is now so realistic that it is harder to know what to trust. Sixty-eight per cent openly acknowledged that they could be successfully deceived by a deepfake scam masquerading as an internal stakeholder or executive at work.

Yet leadership confidence remains high. Ninety-three per cent of ANZ leaders expressed confidence that employees can identify impersonation messages via internal tools, and 88 per cent were confident employees can identify deepfake voice and video content.

The report warns that the threat landscape has shifted from human speed to machine speed, and that ANZ organisations are unprepared for automated, multi-stage attacks targeting employees concurrently across email, SMS and collaboration apps.

Human Error Under Pressure

Beyond AI-driven threats, the research points to the persistent role of human behaviour in security incidents.

Ninety-nine per cent of leaders in ANZ reported that human-related behaviours have affected their organisation’s cybersecurity in the past 12 months. Fifty-six per cent of employees acknowledged that time pressures, cognitive overload and workplace distractions drive them to cut corners and make security errors, even when they know the correct protocol.

There is also a disconnect around reporting culture. While 93 per cent of organisations claim employees feel safe to report mistakes or suspicious activity without fear of blame, one in four employees (24 per cent) admitted they sometimes choose not to report a security mistake due to embarrassment.

Attacks Moving At Machine Speed

Nearly half of cybersecurity leaders in ANZ (49 per cent) identified AI-enabled attacks as a key driver of future human-related cybersecurity risks.

Dr Kawin Boonyapredee, CISO Advisor at KnowBe4 APJ, described the challenge facing security teams.

“Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’s changing more quickly than security leaders can keep up,” Dr Boonyapredee explained.

“Attackers are moving at machine speed, using attacks such as deepfakes to target employees and prompt injections to hijack AI agents. Leaving half of your corporate AI usage ungoverned is a massive open invitation to threat actors.”

Securing A Hybrid Workforce

The report concludes that organisations need to rethink their approach to security culture in light of the hybrid workforce of humans and AI agents now operating within enterprises.

KnowBe4 argues that achieving what it calls “Wins” requires organisations to design systems that guide behaviour, build supportive cultures and shift from tracking failures to reinforcing positive actions. That security-first mindset needs to extend across both AI agents and human employees.

The research was conducted across organisations with 250 or more employees. The global sample comprised 800 security decision-makers and 3,200 employees.

More information is available at www.knowbe4.com.

Last Updated on June 29, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.