O
DEEPFAKES
Ungoverned AI agents and Deepfakes expose growing security risks in UAE and Saudi Arabia
rganisations across the UAE and
O
Saudi Arabia are embracing agentic
Artificial Intelligence at a rapid pace, but a lack of governance is creating new cyber-risks that security teams are struggling to contain. According to new research from KnowBe4, autonomous AI agents, sophisticated deepfakes and the growing use of unsanctioned AI tools are expanding the enterprise attack surface faster than organisations can implement effective safeguards.
The company’ s latest report, From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI, found that AI agents are already embedded in everyday business operations, with 84 % of cybersecurity leaders in the UAE and Saudi Arabia reporting that autonomous AI systems are actively performing tasks within organisational workflows. However, almost one in four organisations( 24 %) admit their AI usage remains unapproved or largely ungoverned, creating what KnowBe4 describes as a growing layer of“ Shadow AI” operating without adequate oversight.
The findings suggest organisations are facing a dual challenge. While AI is delivering productivity gains, it is simultaneously creating new opportunities for cybercriminals to exploit both employees and autonomous systems.
Deepfake technology has emerged as one of the most pressing concerns. The study found that 88 % of employees believe AIgenerated voice and video content has become so convincing that it is increasingly difficult to distinguish genuine communications from fraudulent ones. More worryingly, 52 % admitted they could be deceived by a deepfake attack in the workplace, highlighting the growing effectiveness of AI-powered social engineering.
Human behaviour continues to play a significant role in organisational cyber risk. More than half( 54 %) of cybersecurity leaders said everyday employee mistakes had the greatest impact on their organisation’ s security over the past year. Employees themselves acknowledged the problem, with 44 % saying time pressures and workplace distractions
Dr Martin Kraemer, CISO Advisor at KnowBe4 often lead them to ignore established security procedures despite understanding the associated risks.
The report also highlights the growing challenge of unsanctioned AI adoption. Around 41 % of employees said they source their own AI tools when approved alternatives are unavailable or considered too restrictive. This trend has tangible security implications, with 52 % of security leaders reporting that the use of unauthorised software and AI applications has negatively affected their organisation’ s security posture during the past 12 months.
AI-driven attacks are also expected to become increasingly common. More than one-third( 36 %) of cybersecurity leaders identified AIenabled threats as one of the most significant drivers of future human-related cyber risk, reflecting growing concern that attackers are leveraging artificial intelligence to automate phishing campaigns, generate convincing deepfakes and manipulate AI systems through techniques such as prompt injection.
Despite these concerns, confidence among security leaders remains high. More than three-quarters( 76 %) believe their organisations are well prepared to respond to emerging AI-driven threats over the next year. However, that confidence is tempered by the recognition that significant work remains. Nearly 84 % acknowledged that improvements are still required to ensure AI tools and autonomous agents operate within approved security policies and organisational risk thresholds.
According to Dr Martin Kraemer, CISO Advisor at KnowBe4, cybersecurity has entered a new phase in which organisations must secure both human employees and AI-powered digital workers.
“ Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’ s changing more quickly than security leaders can keep up,” he said.“ Attackers are moving at machine speed, using attacks such as deepfakes to target employees and prompt injections to hijack AI agents. Leaving almost a quarter of your corporate AI usage ungoverned is a massive open invitation to threat actors.”
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 31