Five ways AI is creating everyday risks for African businesses
In our fast-evolving cyber risk landscape, it’s easy to be captivated by headline stories of cutting-edge exploits, wild new attack vectors, and AI shaping malware that once seemed impossible. But while these futuristic threats grab attention, the real challenge lies in understanding the everyday risks businesses face and the practical steps to mitigate them. Attackers

Five ways AI is creating everyday risks for African businesses
In our fast-evolving cyber risk landscape, it’s easy to be captivated by headline stories of cutting-edge exploits, wild new attack vectors, and AI shaping malware that once seemed impossible. But while these futuristic threats grab attention, the real challenge lies in understanding the everyday risks businesses face and the practical steps to mitigate them.
Attackers are clearly becoming increasingly inventive. The surge of AI-driven techniques reshapes the global threat landscape, and Africa faces the same growing threat. Sophisticated fraud schemes continue to rise, driven by generative AI, deepfakes, and internal vulnerabilities. This shift calls for businesses to rethink their strategies and stay ahead in this advancing game.
The best place to start is to focus on real-world risks. During Trend Micro’s recent World Tour in Johannesburg, the tour unpacked the tangible risks posed by AI advancements and shared actionable insights on how businesses can effectively counter these emerging challenges.
A new wave of AI-powered phishing emerges
Phishing has evolved from poorly worded emails riddled with typos to messages that appear polished, professional, and even flawlessly translated into multiple languages. A more recent development shows how attackers now leverage AI to scour social media posts not just the content of posts, but the rich ecosystem of interactions around them. A treasure trove of personalised insights can be mined from comments and connections.
Bad actors now use AI’s ability to craft hyper-personalised messages with astonishing precision. Readily available tools even platforms like ChatGPT enable phishing emails that feel tailored and authentic. This shift doesn’t require advanced coding expertise. Instead, it places powerful capabilities in the hands of malicious actors.
This change raises the stakes for businesses. Social engineering pressure through phishing channels continues to intensify. As a result, businesses must adopt a more vigilant and proactive approach to cybersecurity.
Deepfakes are becoming mainstream
Synthetic media has entered the conversation and is rewriting the rules of social engineering. Deepfakes, once considered a novelty, now represent a mainstream threat. In Africa, deepfake incidents increased sevenfold from Q2 to Q4 of 2024 due to advanced AI tools.
With just a few seconds of audio, voice cloning tools can convincingly mimic an executive’s voice, allowing fraudsters to issue urgent fund transfer requests that sound entirely real. It doesn’t stop there. Real-time face swaps on video platforms like WhatsApp turn even a casual “let’s jump on a quick call” into a potential trap. The line between real and fake continues to blur, and attackers exploit that ambiguity with alarming precision. Recent headline-grabbing incidents like last year’s Quantum AI investment scam, which cost consumers billions underscore how high the stakes have become.
AI is exposing deeper gaps in data governance
One of the rising challenges businesses face is the risk of data leakage, especially with tools like AI assistants entering the picture. Imagine an employee whether inadvertently or with malicious intent asking for sensitive information such as salary details, acquisition plans, or financial results. Without the correct access restrictions, the AI could provide restricted data that was never meant for broader access.
This situation reflects how AI often inherits flawed permissions folders scattered across an organisation with access settings that are too broad. For example, a folder might be set to “accessible to everyone” when only specific employees should have clearance. AI tools will surface information that should remain locked down. This issue doesn’t stem solely from AI, it points to deeper gaps in data governance and permissions management within organisations.
Open source is an avenue for malicious code
Another emerging concern around AI involves the potential spread of malicious code. Developers building AI applications frequently rely on open-source repositories or widely used models like Meta’s LLaMA. If these repositories contain buggy or malicious code, vulnerabilities can slip into applications unnoticed. Even trusted tools can become conduits for risk when developers fail to vet them carefully.
Hallucinations can prove catastrophic
Hallucinations where AI models generate false or misleading information pose another critical challenge. These issues tend to occur with hastily developed or poorly vetted models. For instance, OpenAI’s Whisper model, used for speech recognition and transcription, created additional words when doctors paused during dictation.
In a medical context, such inaccuracies are more than just inconvenient they are potentially catastrophic. This highlights the urgent need for robust quality assurance processes tailored specifically to AI systems.
What’s the path forward?
It starts with visibility broad, deep, and continuous. Understanding where and how AI operates across the organisation is no longer optional; it’s foundational. Businesses must monitor AI interactions closely. If prompts or responses raise red flags, that insight becomes a critical opportunity to intervene, guide, and improve. At the same time, application security processes must evolve to reflect the new AI-driven threat landscape. Organisations training models must prioritise the integrity of their data. Govern it. Protect it. Own it.
The good news is that defensive AI continues to outpace offensive capabilities, thanks to growing investments in talent, tools, and innovation. Even as attackers advance in areas like vulnerability discovery, defenders use the same techniques to stay one step ahead. And with the rise of agentic AI, more power is shifting into the hands of those who protect. The future of cybersecurity isn’t just about reacting faster it’s about anticipating smarter. And that future is already taking shape.



