A new study warns that the deployment of cybersecurity threats to organizations in Saudi Arabia and the UAE often stems from the use of autonomous AI agents without proper governance. Specifically, the research from KnowBe4 highlights that 24% of regional organizations deploy these tools with little to no oversight. Meanwhile, 52% of employees admit they cannot reliably detect sophisticated attacks like deepfakes.
According to the report, titled “From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI,” the rapid adoption of these technologies is expanding the corporate attack surface. Notably, 84% of cybersecurity leaders in the region report that AI agents already execute actions within daily workflows. However, the lack of formal governance means that approximately one in four organizations uses unapproved tools. Consequently, this unmanaged software operates as an invisible layer of shadow employees handling sensitive corporate data.
Deepfakes and Human Error Risks
The study reveals that 88% of employees in Saudi Arabia and the UAE find deepfake voice and video content too realistic to verify. Furthermore, 52% of workers acknowledge they could fall victim to a deepfake scam while at work. In addition, 54% of cybersecurity leaders state that everyday employee mistakes had the greatest impact on security over the past year. Many employees (44%) blame workplace distractions and time pressures for driving them to bypass safety protocols.
Managing Autonomous AI Agents in the Workplace
Employees frequently source their own autonomous AI agents when official options are unavailable or too restrictive, according to 41% of respondents. This practice directly impacts security postures, as 52% of security leaders report issues from unsanctioned software. Although 76% of leaders feel prepared for emerging threats, 84% admit they must improve policies to keep AI tools within approved risk limits. Therefore, organizations must establish clearer guidelines to manage these emerging digital assets.
Building a Culture of Security
To address these vulnerabilities, the report suggests that organizations must prioritize security culture and employee training over basic technical functions. Notably, 82% of employees feel safer reporting mistakes in environments that encourage open communication. Dr. Martin Kraemer, CISO Advisor at KnowBe4, stated that attackers are moving at machine speed using deepfakes and prompt injections. He added that leaving corporate AI usage ungoverned serves as an open invitation to threat actors.
“Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’s changing more quickly than security leaders can keep up.”
Dr. Martin Kraemer, CISO Advisor at KnowBe4
Future Outlook and Recommendations
To secure a hybrid workforce of humans and autonomous AI agents, organizations must design systems that actively guide secure behaviors. Specifically, the report recommends shifting from tracking security failures to reinforcing positive employee actions. Furthermore, security teams must extend their defensive frameworks to cover both human employees and automated tools. Ultimately, building a supportive culture remains the most effective defense against sophisticated AI-driven threats.





