KONews Logo

Protecting the AI Risk from within

Author
Admin
••Last updated: October 3, 2026 at 8:25 AM
Protecting the AI Risk from within
Share:

AI adoption is outpacing internal security governance, leaving Kenyan organisations exposed to both old and unpatched vulnerabilities alongside a new, AI-driven attack surface. Every AI agent, tool and assistant adopted by the business creates another doorway for potential access and Gartner now names agentic oversight as the single most important cybersecurity trend of 2026. 

The visible edge of this risk is already well known with investment scams built on deepfake videos, phishing and impersonation. The Nomani investment scam, for example, has grown by around 62% year-on-year globally, with more than 64,000 malicious URLs blocked in 2025 alone. 

Autonomous AI agents are perhaps one of the most significant threats as, unlike a chatbot, they fetch data, follow links, download components and complete tasks across connected systems. And they do so at remarkable speeds with standing permissions. If they are manipulated, misconfigured or left to run without supervision, they can become a new and distinct attack surface. ESET’s own research has already uncovered AI-enabled threats, that include PromptLock and PromptSpy, while detecting thousands of malicious agentic skills circulating in the wild. An agent that can reach across the AI supply chain can carry anything on its back. 

Companies need a dedicated AI security layer that is built for autonomous agents, scanning AI-related files and components, and inspecting external URLs given to agents. This layer should be capable of following the full download chain so a staged or multi-stage attack is caught before it completes. The intent is to use a solution that lets AI continue safely with agents that work without opening new doors to vulnerabilities. It makes all the difference between productivity gained versus risk imported alongside it. 

AI behavioural monitoring is also key as this tool watches what the agents do and tracks their behaviour continuously, flagging anything suspicious as an incident for investigation. If an agent is caught acting outside its intended limits it can prevent extraordinary levels of damage – think about an agent given authority inside a bank that starts to make decisions it was never meant to make. 

In Kenya, an agent acting outside its guardrails is also not just a technical failure; it is a compliance and accountability problem. Under the Data Protection Act, any company that suffers a personal data breach must notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, with a tighter window for critical infrastructure operators according to Section 65 of the Computer Misuse and Cybercrimes Act. The penalties are high both financially and reputationally. 

It is time to stop treating AI as something new that security has never seen and instead invest in defensive and preventative technologies that understand the risks and the speed at which they move through the business. ESET has developed a platform to match Kenya’s growing appetite for AI, so companies can devour innovation without losing ground, but do so within a secure environment that doesn’t leave trust behind. They have accumulated knowledge across machine learning and cybersecurity which means that the business benefits from capabilities held under one umbrella of AI technologies, and from security it can trust to assess and protect all its systems.