AI assistants learn bad workplace habits

August 2026 AI & Data Analytics, Security Services & Risk Management


An employee under pressure at a logistics firm finds a productivity-boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary. It saves a couple of hours of reading.

They may also see their email client now integrates their favourite AI tool, so they can save even more time. When the organisation subsequently deploys an autonomous AI agent integrated into its internal environment, the agent studies the employee's workflow to identify efficiencies and increasingly acts on their behalf. That assistant does not just learn from a security policy. It learns from actual behaviour.

Because AI agents are often treated like infallible magic bullets, we need to change the way we view the AI colleagues we are getting, says Anna Collard, SVP of content strategy and CISO advisor at KnowBe4 Africa. “In a quite real way, we are essentially working with digital toddlers that watch and learn from us, including our laxer habits.”

The anthropomorphism trap

Humans are increasingly falling into the anthropomorphism trap, in which they project human characteristics onto AI agents. It is a natural instinct, but one that can create a dangerous illusion of competence.

"The personification is where people can get into deeper trouble," Collard warns. "We interact with these agents as if they are eager junior employees, assuming they possess common sense and a basic ethical compass."

An AI agent has no conscience, no stake in the outcome, and no fear of disciplinary action. "A human can be reasoned with, can grasp why a rule exists, and can exercise judgement in a novel situation," Collard explains. "An agent, however fluent it sounds, is pattern-matching against its training and context.”

“That fluent, human-sounding language is a programmed output, not an indicator of understanding, and treating it as a trusted colleague is a severe vulnerability,” Collard cautions.

Yet the similarities are real, too. "Both learn from examples, from feedback, and from the behaviour modelled around them, and both can be manipulated through language."

Both develop habits that drift from intended behaviour and need recalibrating or even correcting. Both can be overconfident, and both can be nudged. The behavioural-science toolkit- baselining, reinforcement, simulation, and monitoring for drift- transfers between the two, which is why structured behavioural data is such a powerful lens for managing both.

Agentic drift and the digital toddler

The industry term for an AI system gradually deviating from its original alignment is ‘agentic drift’. It occurs because agents accumulate behavioural patterns from new data, user interactions and environmental feedback over time. If the dominant feedback it receives from an employee is a pattern of bypassing security guardrails to speed up a process, the agent's parameters could very well drift to accommodate that behaviour.

"We are in many ways introducing digital toddlers into the corporate network," Collard explains. "They watch everything, they mimic what they see, and they lack the maturity to independently distinguish between a sanctioned process and a dangerous shortcut."

"This drift compounds the risk of prompt injection – a technique where attackers disguise malicious instructions as legitimate input, because a moving behavioural baseline makes it harder to tell an attacker's injected instruction from the agent's own evolving habits."

Why you can't monitor one without the other

“Risk,” Collard argues, “now flows in both directions. Agents act with real privileges, at speed and scale, sometimes even with less oversight than a junior employee would get, yet a drifting agent can cause damage no single human generally could."

The two risk profiles are coupled: an inadvertent and well-intentioned, but careless human shapes a careless agent, and, to a certain extent, vice versa. "An over-trusted agent makes humans complacent, lowering their guard until they stop checking its output at all. That is automation bias, and it is a measurable human risk."

You need behavioural baselines for both humans and agents, and must watch for drift. "The real risk is in the interaction between them," Collard notes. Detecting drift requires knowing what normal behaviour looks like over time.

The challenge is implementing this kind of oversight without it becoming costly. The answer is not to scrutinise everything with equal intensity. This is layered behavioural monitoring: lightweight signals continuously track whether humans and agents are behaving as expected, while more in-depth analysis kicks in only when something appears to be an anomaly, a drift, or a sign of intent gone wrong.

“Strong behavioural baselines,” she argues, “are what make this multi-layered approach possible, turning governance from a costly checkpoint into a continuous risk signal.”

The urgency is real

By the end of 2026, Gartner projects that 40% of enterprise applications will include task-specific AI agents. Yet adoption is dramatically outpacing governance. KnowBe4's recent report, From Agentic Risk to Human Wins, found that 38% of South African cybersecurity leaders report that AI agents are already taking autonomous actions within organisational workflows. A lack of governance is leaving organisations exposed; the report shows that a staggering 64% of organisations report that their use of AI is unapproved or ungoverned. The result is a widening issue: unmonitored agents executing autonomous transactions that can lead to data leakage, runaway operational costs, or both.

The solution is not to block AI, though, but to recognise that human and agent risks are inextricably linked. An organisation cannot secure its AI without first securing the habits of the employees training it. The new paradigm of security awareness and greater cyber resilience is about ensuring that the digital assistants watching over employees’ shoulders are learning the right lessons.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Protect More with SecuVue
Secutel Technologies Surveillance AI & Data Analytics
Whether you are responsible for electronic key management, securing safes and containers, transport operations or high-value equipment, every asset represents an investment that deserves intelligent protection.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
From hype to practical value
Genetec AI & Data Analytics
Artificial intelligence is drawing more attention across the physical security industry. In the 2026 Genetec State of Physical Security report, AI ranked alongside access control and video surveillance as a key priority for the year ahead.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.