Half of South Africans Bypass AI Rules at Work, Unpublished Oliver Wyman Survey Shows
An unpublished Oliver Wyman survey shows that 50 percent of 903 surveyed South Africans have bypassed their organization's AI restrictions in the past year, and that managers bypass the rules more often than their own teams. The findings were presented at a cybersecurity meeting in Johannesburg in early October, months before the full report is published.
Most companies build their cybersecurity barriers against external attacks: firewalls, login controls, monitoring of network traffic. But according to fresh, unpublished survey figures from Oliver Wyman, a growing share of the risk now comes from within — from employees using AI tools the company has not approved, and in the worst case from managers who have access to the organization's most sensitive information.
The findings come from the Oliver Wyman Forum Global Consumer Survey 2026 South Africa, based on 903 respondents. The report has not yet been published; it is scheduled for release in November 2026. The figures were presented by Oliver Wyman partner Prejlin Naidoo at a cybersecurity meeting arranged by Marsh in Johannesburg on 6 October 2026, making this a preview of data that will soon be freely available — presented at a moment when many companies are rolling out generative AI tools internally.
The number that makes the news
The central finding is simple: 50 percent of respondents said they had bypassed their organization's AI restrictions in the past year. Naidoo stressed at the same time that the figure is probably underreported — self-reporting of rule violations naturally comes in low.
"This creates an entirely new kind of threat perimeter," Naidoo said, according to the account of the presentation (TechCabal).
The concept he is pointing to is often called "shadow AI": employees using chatbots and other generative tools outside IT's control, in the same way "shadow IT" has long described unauthorized software. The difference is that AI tools often gain access to text, documents and context that the user pastes in or uploads — data that can leave the organization's control without any traditional security check catching it.
The managers are worst
Perhaps the most troubling finding is the distribution of the violations. "When we dig into the data, managers are actually much more likely to do this than their own teams," Naidoo said.
This reverses a common assumption that security risk comes primarily from junior employees who don't know the rules. Managers typically have access to sensitive business information — strategy documents, personnel data, financial figures — and therefore represent greater potential damage if information ends up in the wrong hands via an unapproved tool.
Why bans alone don't work
A natural reaction from organizations is to ban AI tools or lock them down. But the survey suggests this does not remove the problem. In the communications, media and technology sector — where employees in principle have the best access to enterprise AI tools at work — 31 percent still used unapproved tools. In other industries, the figure was 34 percent.
The three-percentage-point difference suggests that access to legitimate alternatives changes behavior very little. Employees use the tools they prefer, regardless of what the employer offers.
The training gap
Another supplementary figure points to why this is hard to control with policy alone. A Kaspersky survey from 2025 — reported via TechCabal's coverage, not from the original study — found that 72.5 percent of surveyed South African professionals use AI tools in their work, but that only 30 percent had received training in cybersecurity risks related to AI.
The gap between widespread use and sparse training means many employees likely lack the knowledge needed to assess what is safe to paste into a chatbot or upload to a cloud service.
The attitudes around it
Naidoo also highlighted several attitude figures from the material, not as causal explanations but as context:
- 35 percent of respondents had seen AI-generated work presented as human-made, raising questions about the origin and reliability of information flowing into organizations' systems.
- Consumer trust in AI has quadrupled, from 11 percent in 2023 to 44 percent.
- 41 percent said they would be comfortable letting an AI agent place an order on their behalf.
Taken together, the figures point in the same direction: AI use has become a normalized part of working life for many, without security routines keeping pace.
Responsibility broader than the IT department
At the same meeting, Spiros Fatouros, chief executive of Marsh Africa, argued that cybersecurity work must extend beyond the IT department. "The main message is that cyber resilience can no longer be viewed solely as an internal IT matter," he said, citing supply-chain attacks as an attack path against South African insurers.
The point connects the shadow AI finding to a larger pattern: security risk increasingly arrives through third parties, tools and relationships — not just through the organization's own perimeter.
Caveats and what remains
It is worth being clear about what this material can and cannot show. The underlying Oliver Wyman report has not yet been published; methodology, question wording and margins of error will not be available until the November release. All figures in this story come from TechCabal's account of Naidoo's presentation, and the Kaspersky figure is a secondary source in that chain. The survey applies to South Africa specifically, and the results cannot readily be generalized to other markets.
Nor is there any incident data in the evidence base documenting that these bypasses have led to concrete security breaches — the claim, for now, is that a new type of exposure exists, not that harm has already occurred.
The concrete thing to watch is the November release, which will hopefully lay out the methodology and make it possible to test whether the manager pattern, the sector comparison and the attitude figures hold up under closer scrutiny.

