Security & Risk

AI and Workplace Security: The Real Danger Isn't What You Think

10 MIN READ · STAURUS TRAINING · 12 JULY 2026 An office worker viewed from behind at a desk in a dimly lit room, facing a laptop screen showing a blurred video conference call, evening atmosphere

Ask most executives what worries them about AI and security, and they describe something cinematic — a rogue system, a hacked algorithm, a machine making decisions nobody sanctioned. The actual danger already costing organisations money looks nothing like that. It looks like an employee trying to finish a task before lunch, and a finance officer joining a video call with people who look exactly like their colleagues. Neither requires imagining the future. Both are already measured, and both have already happened in Nigeria.

Danger one: your own staff, not maliciously, leaking your data

Verizon's 2026 Data Breach Investigations Report, drawn from a dataset of over 22,000 breaches globally, found that 45% of employees are now regular AI users on corporate devices — up from 15% in the 2025 edition. That is a tripling in twelve months, a faster adoption curve than almost any workplace technology on record. Of those users, roughly two-thirds were accessing AI tools through personal accounts their IT departments never approved.

What they're putting into those tools is the real problem. Verizon's analysis of data-loss-prevention violations found source code was the single largest category of sensitive material entered into unauthorised AI tools, followed by images, structured data, and documents. In a smaller but still material share of cases, employees uploaded proprietary research and technical documentation. None of this requires bad intent. IBM's 2025 breach research found that 63% of organisations have no AI governance policy at all, and — more tellingly — 97% of organisations that suffered an AI-related security incident had no access controls around the AI tools involved. This is not a story about clever attackers. It's a story about an open door nobody thought to close.

An HR officer pasting termination details into a chatbot to polish the wording isn't being reckless. They have no idea they just sent employee data outside the organisation's walls.

The World Economic Forum's Global Cybersecurity Outlook 2026 put this at the top of the boardroom agenda directly: 87% of surveyed cyber leaders named AI-related vulnerabilities the fastest-growing risk category, and data-loss-prevention failure from generative AI was the single largest CEO-level concern, ahead of ransomware.

TWO ATTACK SURFACES, MOVING IN OPPOSITE DIRECTIONS SHADOW AI — DATA LEAVES Staff pastes data Public AI Tool Outside your control 45% OF STAFF · 67% ON PERSONAL ACCOUNTS DEEPFAKE FRAUD — INSTRUCTIONS ARRIVE Fraudster with AI-generated video impersonates Staff Unauthorised transfer $25.6M LOST · ONE DOCUMENTED CALL

Left: information leaves the organisation through an employee trying to be productive. Right: false instructions arrive from outside, dressed as a trusted colleague. Neither is caught by traditional phishing filters or MFA.

Danger two: a video call with someone who doesn't exist

In January 2024, a finance employee at the Hong Kong office of Arup — the engineering firm behind the Sydney Opera House — received an email from what appeared to be the company's UK-based CFO, requesting a confidential transaction. He suspected phishing and asked for a video call to confirm. The call went ahead: several familiar colleagues, including the CFO, discussed the transaction and corroborated the request. Every one of them was an AI-generated deepfake, built from publicly available video and audio of real Arup executives. The employee made fifteen transfers totalling roughly $25.6 million before discovering the deception by contacting headquarters directly.

What makes this case worth studying isn't the technology — it's where the organisation's existing defences failed. Arup's controls were built for phishing emails and compromised credentials: multi-factor authentication, endpoint detection, email filtering. None of those defend against a real-time video call that looks and sounds correct. The actual gap was procedural: no requirement for out-of-band confirmation of a high-value transfer, through a separate, pre-agreed channel, regardless of how convincing the request appeared.

This is not a distant, foreign risk. A Nigerian cartel used a deepfake to impersonate a senior government official on a video call in 2024, convincing an international NGO to release funds for a fraudulent development project — reported by the Bloomsbury Intelligence and Security Institute as part of a wider pattern of AI-enabled fraud targeting Nigerian organisations, which face an estimated 4,388 cyberattacks per week industry-wide since the start of 2025.

What this looks like in Nigeria specifically

Nigeria's fraud data tells a genuinely mixed story, and the nuance matters more than a single alarming headline. NIBSS reported total digital payment fraud value of ₦25.85 billion in 2025, actually down from ₦52.26 billion in 2024 — a real improvement in the aggregate figure. Set against that, a separate measure specific to instant transfers found NIP-related fraud losses jumped 603% to ₦3.29 billion in the first quarter of 2025 alone, according to industry reporting. Both figures are real; they measure different things, and reading either one alone would mislead. The honest picture is that overall fraud losses have fallen even as identity-based and AI-assisted fraud typologies are rising sharply within that total.

DevelopmentWhat it shows
CBN's March 2026 AML frameworkIntroduces active liveness detection standards (randomised gestures, prompted speech) to replace passive facial checks that deepfakes can spoof; 18–24 month implementation window for full compliance
87.5% of Nigerian fintechsNow report active AI deployment specifically for fraud detection — meaning both sides of the fraud arms race are already using AI
SEC Nigeria warnings, Sept 2025–Feb 2026Public deepfake videos falsely showing real Nigerian figures, including a business executive and an international trade official, endorsing fraudulent investment platforms
Corporate treasury accountsFlagged by Nigerian banking commentary as a prime target for AI-assisted account takeover, given the scale of funds typically held

Why traditional security training doesn't cover this

Most workplace security training was built for a world of suspicious emails and obviously wrong web addresses. Shadow AI and deepfake fraud both route around that training entirely. Shadow AI doesn't require deceiving anyone — the employee is a willing participant who simply doesn't understand where their data goes once it leaves the prompt box. Deepfake fraud doesn't require a technical vulnerability — it exploits the single verification method almost every organisation has relied on for decades: recognising a colleague's face and voice.

Staurus Training's Governing AI: Risk, Procurement & Data workshop covers exactly this — building the internal policy, verification procedures, and staff awareness that neither generic phishing training nor a blanket AI ban actually provides.

See the Programme