AI and Workplace Security: The Real Danger Isn't What You Think
Ask most executives what worries them about AI and security, and they describe something cinematic — a rogue system, a hacked algorithm, a machine making decisions nobody sanctioned. The actual danger already costing organisations money looks nothing like that. It looks like an employee trying to finish a task before lunch, and a finance officer joining a video call with people who look exactly like their colleagues. Neither requires imagining the future. Both are already measured, and both have already happened in Nigeria.
Danger one: your own staff, not maliciously, leaking your data
Verizon's 2026 Data Breach Investigations Report, drawn from a dataset of over 22,000 breaches globally, found that 45% of employees are now regular AI users on corporate devices — up from 15% in the 2025 edition. That is a tripling in twelve months, a faster adoption curve than almost any workplace technology on record. Of those users, roughly two-thirds were accessing AI tools through personal accounts their IT departments never approved.
What they're putting into those tools is the real problem. Verizon's analysis of data-loss-prevention violations found source code was the single largest category of sensitive material entered into unauthorised AI tools, followed by images, structured data, and documents. In a smaller but still material share of cases, employees uploaded proprietary research and technical documentation. None of this requires bad intent. IBM's 2025 breach research found that 63% of organisations have no AI governance policy at all, and — more tellingly — 97% of organisations that suffered an AI-related security incident had no access controls around the AI tools involved. This is not a story about clever attackers. It's a story about an open door nobody thought to close.
An HR officer pasting termination details into a chatbot to polish the wording isn't being reckless. They have no idea they just sent employee data outside the organisation's walls.
The World Economic Forum's Global Cybersecurity Outlook 2026 put this at the top of the boardroom agenda directly: 87% of surveyed cyber leaders named AI-related vulnerabilities the fastest-growing risk category, and data-loss-prevention failure from generative AI was the single largest CEO-level concern, ahead of ransomware.
Left: information leaves the organisation through an employee trying to be productive. Right: false instructions arrive from outside, dressed as a trusted colleague. Neither is caught by traditional phishing filters or MFA.
Danger two: a video call with someone who doesn't exist
In January 2024, a finance employee at the Hong Kong office of Arup — the engineering firm behind the Sydney Opera House — received an email from what appeared to be the company's UK-based CFO, requesting a confidential transaction. He suspected phishing and asked for a video call to confirm. The call went ahead: several familiar colleagues, including the CFO, discussed the transaction and corroborated the request. Every one of them was an AI-generated deepfake, built from publicly available video and audio of real Arup executives. The employee made fifteen transfers totalling roughly $25.6 million before discovering the deception by contacting headquarters directly.
What makes this case worth studying isn't the technology — it's where the organisation's existing defences failed. Arup's controls were built for phishing emails and compromised credentials: multi-factor authentication, endpoint detection, email filtering. None of those defend against a real-time video call that looks and sounds correct. The actual gap was procedural: no requirement for out-of-band confirmation of a high-value transfer, through a separate, pre-agreed channel, regardless of how convincing the request appeared.
What this looks like in Nigeria specifically
Nigeria's fraud data tells a genuinely mixed story, and the nuance matters more than a single alarming headline. NIBSS reported total digital payment fraud value of ₦25.85 billion in 2025, actually down from ₦52.26 billion in 2024 — a real improvement in the aggregate figure. Set against that, a separate measure specific to instant transfers found NIP-related fraud losses jumped 603% to ₦3.29 billion in the first quarter of 2025 alone, according to industry reporting. Both figures are real; they measure different things, and reading either one alone would mislead. The honest picture is that overall fraud losses have fallen even as identity-based and AI-assisted fraud typologies are rising sharply within that total.
| Development | What it shows |
|---|---|
| CBN's March 2026 AML framework | Introduces active liveness detection standards (randomised gestures, prompted speech) to replace passive facial checks that deepfakes can spoof; 18–24 month implementation window for full compliance |
| 87.5% of Nigerian fintechs | Now report active AI deployment specifically for fraud detection — meaning both sides of the fraud arms race are already using AI |
| SEC Nigeria warnings, Sept 2025–Feb 2026 | Public deepfake videos falsely showing real Nigerian figures, including a business executive and an international trade official, endorsing fraudulent investment platforms |
| Corporate treasury accounts | Flagged by Nigerian banking commentary as a prime target for AI-assisted account takeover, given the scale of funds typically held |
Why traditional security training doesn't cover this
Most workplace security training was built for a world of suspicious emails and obviously wrong web addresses. Shadow AI and deepfake fraud both route around that training entirely. Shadow AI doesn't require deceiving anyone — the employee is a willing participant who simply doesn't understand where their data goes once it leaves the prompt box. Deepfake fraud doesn't require a technical vulnerability — it exploits the single verification method almost every organisation has relied on for decades: recognising a colleague's face and voice.
- Replace blanket bans with a governed alternative. Multiple industry studies agree prohibition doesn't work — employees route around it. The organisations reducing shadow AI risk provide an approved, secure tool alongside clear rules, not just a policy banning the unapproved ones.
- Require out-of-band verification for high-value transfers, unconditionally. Any instruction to move money or release sensitive data — however it arrives, including by video call — should require confirmation through a separate, pre-agreed channel before execution. This single control would have stopped the Arup transfer.
- Treat deepfake awareness as its own training module. Generic phishing training does not prepare staff for a face they recognise asking them for money. Staff need to know this specific attack pattern exists and what the procedural response is, not just how to spot a suspicious email.
- Write the AI usage policy the data says most organisations still lack. With 63% of organisations globally still without one, and Nigeria's own NDPA 2023 obligations already applying to any AI system touching personal data, this is a governance gap with an existing legal hook to build from, not a hypothetical one.
Staurus Training's Governing AI: Risk, Procurement & Data workshop covers exactly this — building the internal policy, verification procedures, and staff awareness that neither generic phishing training nor a blanket AI ban actually provides.
See the Programme