More than 1 in 4 organisations banned GenAI

January 2024 Security Services & Risk Management, AI & Data Analytics

Cisco released its 2024 Data Privacy Benchmark Study, an annual review of key privacy issues and their impact on business. Considering International Data Privacy Day, the findings highlight the growing privacy concerns with GenAI, trust challenges facing organisations over their use of AI, and the attractive returns from privacy investment.

Drawing on responses from 2600 privacy and security professionals across 12 geographies, the seventh edition of the Benchmark shows that privacy is much more than a regulatory compliance matter.

Growing privacy concerns with Generative AI

“Organisations see GenAI as a fundamentally different technology with novel challenges to consider,” said Dev Stahlkopf, Cisco's Chief Legal Officer. “More than 90% of respondents believe GenAI requires new techniques to manage data and risk. This is where thoughtful governance comes into play. Preserving customer trust depends on it.”

Among the top concerns, businesses cited the threats to an organisation’s legal and Intellectual Property rights (69%), and the risk of disclosure of information to the public or competitors (68%).

Most organisations are aware of these risks and are putting in place controls to limit exposure; 63% have established limitations on what data can be entered, 61% have limits on which GenAI tools can be used by employees, and 27% said their organisation had banned GenAI applications altogether for the time being. Nonetheless, many individuals have entered information that could be problematic, including employee information (45%) or non-public information about the company (48%).

Slow progress on AI and transparency

Consumers are concerned about AI use involving their data today, and yet 91% of organisations recognise they need to do more to reassure their customers that their data is being used only for intended and legitimate purposes in AI. This is similar to last year’s levels, suggesting that not much progress has been achieved.

Organisations’ priorities to build consumer trust differ from those of individuals. Consumers identified their top priorities as getting clear information on exactly how their data is being used, and not having their data sold for marketing purposes. When asked the same question, businesses identified their top priorities as complying with privacy laws (25%) and avoiding data breaches (23%).

It suggests additional attention on transparency would be helpful — especially with AI applications where it may be difficult to understand how the algorithms make their decisions.

The role of external certifications and laws

Organisations recognise the need to reassure their customers about how their data is being used, and 98% said that external privacy certifications are an important factor in their buying decisions. This is the highest we’ve seen over the years.

“94% of respondents said their customers would not buy from them if they did not adequately protect data,” explains Harvey Jang, Cisco Vice President and Chief Privacy Officer. “They are looking for hard evidence that organisation can be trusted. Privacy has become inextricably tied to customer trust and loyalty. This is even more true in the era of AI, where investing in privacy better positions organisations to leverage AI ethically and responsibly.”

Despite the costs and requirements privacy laws may impose on organisations, 80% of respondents said privacy laws have positively impacted them, and only 6% said the impact has been negative. Strong privacy regulation boosts consumer confidence and trust in the organisations with which they choose to share their data.

Further, many governments and organisations are putting in place data localisation requirements to keep certain data within a country or region. While most businesses (91%) believe that their data would be inherently safer if stored within their country or region, 86% also said that a global provider, operating at scale, can better protect their data compared to a local provider.

Over the past five years, privacy spending has more than doubled, benefits have trended up, and returns have remained strong. This year, 95% indicated that privacy’s benefits exceed its costs, and the average organisation reports getting privacy benefits of 1,6-times their spending. Further, 80% indicated getting significant “Loyalty and Trust” benefits from their privacy investments, and this is even higher (92%) for the most privacy-mature organisations.

In 2023, the largest organisations (10 000+ employees) increased their privacy spending by seven to eight percent since last year. However, smaller organisations saw lower investment. For example, businesses with 50-249 employees decreased their privacy investment by a fourth, on average.

See the key points of the study in this Infographic.


News summary

• The Cisco 2024 Data Privacy Benchmark Study reveals that most organisations are limiting the use of Generative AI (GenAI) over data privacy and security issues. 27% had banned its use, at least temporarily.

• 48% admit entering non-public company information into GenAI tools.

• 91% of businesses recognise they need to do more to reassure customers that their data is used for intended and legitimate purposes in AI.

• 98% said that external privacy certifications are an important factor in their buying decisions, the highest level in years.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
R45 billion private security sector’s growing liability gap
Security Services & Risk Management
Constitutional Court and appellate decisions shine a spotlight on the potentially massive civil liability that security companies could face for operational failures and, in certain circumstances, the conduct of employees – exposure often not covered by public liability insurance.

Read more...
AI fraud is outrunning banking defences
Security Services & Risk Management Financial (Industry)
South Africans are increasingly being targeted by AI-generated fraudsters who sound just like bank employees. However, many local banks are still struggling with legacy tech, slow change processes, and limited data visibility.

Read more...
AI assistants learn bad workplace habits
AI & Data Analytics Security Services & Risk Management
An employee under pressure at a logistics firm finds a productivity-boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
Mining's critical controls are not the problem; execution is
Security Services & Risk Management Mining (Industry)
As Parliament considers amendments intended to strengthen managerial responsibility, employer accountability, enforcement and penalties under the Mine Health and Safety Act, Alvarez & Marsal warns that tougher rules must be matched by stronger execution at the rockface.

Read more...
Shadow AI: The next evolution of Shadow IT
AI & Data Analytics Security Services & Risk Management
Today, as AI gains traction in all aspects of life and business, African organisations face a new challenge, known as ‘Shadow AI’, where employees at all levels make use of AI without considering the potential impact.

Read more...
Free live travel risk map covering multiple countries
News & Events Security Services & Risk Management
Most widely cited travel risk maps are published once a year as static documents, but risk conditions do not follow a publishing calendar. The Sicuro map draws on official travel advisories from the ...

Read more...
Unrest readiness is built between crises, not during them
Technews Publishing Security Services & Risk Management
The 30 June marches passed largely peacefully, and that outcome was no accident. It was the result of preparation, and a level of cooperation between police, private security, communities and business that this country has not always managed.

Read more...
The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.