
Artificial intelligence is moving quickly from experimentation to everyday business use. Employees are using AI assistants to write content, analyse information, automate tasks and solve technical problems. Developers are experimenting with AI agents and AI skills, while teams are connecting third-party tools and plugins to existing workflows.
For businesses, this creates a new question that goes beyond whether employees should use AI.
Do You Have a Grip on What Your Employees Are Doing With AI?
ESET's latest research suggests this question deserves closer attention. In H1 2026, ESET analysed nearly 900,000 AI skills from popular repositories, identifying 25,000 suspicious skills and more than 3,000 malicious instances. Some malicious skills incorporated hacking tools such as Mimikatz and Impacket, while others were capable of creating persistence mechanisms. ESET also identified seemingly legitimate but ineffective security skills that could create a false sense of protection.
These findings highlight an important development in AI cybersecurity: the emerging AI ecosystem itself is becoming part of the enterprise attack surface.
AI Adoption Is Creating A New Enterprise Attack Surface
The conversation around AI risks in business has often centred on familiar concerns: sensitive information being entered into public AI tools, inaccurate AI-generated content or employees using unauthorised applications. Those concerns remain important. But the security picture is becoming more complicated.
Today's Enterprise AI environment can include:
- AI assistants and chatbots
- AI-powered applications
- Third-party plugins and integrations
- AI skills that extend an agent's capabilities
- Autonomous or semi-autonomous AI agents
- Developer tools and coding assistants
- Custom AI workflows
- AI services connected to business data and applications
Each additional tool or capability can introduce new permissions, dependencies and potential points of compromise.
This is why organisations need to start thinking about the AI attack surface for businesses in broader terms. It isn't simply about which AI platform employees are using. It is also about what those platforms can access, what they are allowed to do and what additional capabilities employees are installing or connecting to them.
The Employee Isn't The Threat. The Lack Of Visibility Can Be.
Employees are adopting AI tools because they can make everyday tasks faster and more efficient. Preventing AI use altogether is unlikely to be practical or desirable.
The greater concern is unmanaged adoption. An employee might introduce an AI tool, a developer could install an AI skill, or a team might connect an AI service to a business application without security teams having visibility into the associated risks.
To understand how employees using AI affect cybersecurity, rather than asking, "Are our employees using AI?" It should be "What AI are they using, what can it access, and what can it do?"
AI Skills: Small Components, Potentially Significant Consequences
ESET's H1 2026 research provides an important example of why this matters.
Between March and May 2026, ESET analysed approximately 900,000 AI skills from popular repositories. Of these, 25,000 were considered suspicious, and more than 3,000 were identified as malicious.
AI skills can extend the functionality of an AI agent, allowing it to perform additional tasks. That can be useful, but it also means that an apparently small addition to an AI workflow could introduce capabilities that security teams haven't assessed.
ESET researchers found malicious skills using tools such as Mimikatz and Impacket, as well as suspicious self-modifying skills capable of creating persistence mechanisms.
The implication for businesses is significant. AI security risks for businesses aren't necessarily contained within the AI model itself. The surrounding ecosystem matters too.
What Happens When AI Can Access Business Information?
Consider an employee using an AI assistant as part of their daily workflow.
The assistant might have access to:
- Internal documents
- Source code
- Customer information
- Business emails
- Cloud storage
- Collaboration platforms
- Business applications
- Credentials or tokens
- Other connected services
The more capable an AI system becomes, the more useful these integrations can be. But from a data security perspective, every connection needs to be considered carefully.
If an AI tool is compromised, misconfigured or given excessive permissions, the consequences could extend well beyond the original application.
This is one reason the AI attack surface in the enterprise needs to be considered alongside existing endpoint, cloud and application security.
The Problem With "Shadow AI"
Most organisations are familiar with the concept of shadow IT, which is employees adopting applications without formal approval from IT. AI is creating a similar challenge.
Employees can sign up for new services, install browser extensions, experiment with AI assistants or connect third-party applications without necessarily considering the security implications.
This can create what might be called shadow AI. AI adoption that happens outside formal organisational oversight.
The risks of AI tools in the workplace can increase when security teams don't know:
- Which AI applications are being used
- Which employees have access to them
- What information is being submitted
- Which third-party services are connected
- What permissions have been granted
- Which AI skills or agents have been installed
- Whether those components have been assessed for security
- How access is revoked when an employee changes role or leaves
Without this visibility, AI governance becomes difficult to enforce.
AI Agents Make The Question Even More Important
Traditional software generally performs tasks according to predefined instructions. AI agents can operate differently. Depending on how they are designed, they may interpret objectives, interact with applications, retrieve information and perform actions with a greater degree of autonomy.
This creates both opportunities and new AI safety considerations. An organisation may know which AI platform it has approved, but that doesn't necessarily mean it knows every capability being added to that environment.
For example, an approved AI agent could potentially be extended through third-party skills. If one of those skills is malicious, or simply has excessive permissions, the trusted AI environment can become a route into other systems.
This is why AI agents should be treated as part of the broader enterprise security architecture rather than as isolated productivity tools.
Why Traditional Security Controls Aren't Enough On Their Own
Businesses already have extensive cybersecurity controls designed to protect endpoints, networks, identities, applications and data.
Those controls remain essential, but the rapid development of AI introduces new questions that traditional security policies may not fully address.
For example:
Who approved the AI tool?
An application may be legitimate, but its use within a particular business environment may still require assessment.
What permissions does it have?
An AI tool with access to a calendar is very different from one connected to customer databases or source-code repositories.
What third-party capabilities does it use?
An AI agent's functionality may depend on skills, plugins or external services that introduce additional risk.
What happens when those components change?
AI ecosystems can evolve rapidly. A previously assessed tool may later gain new functionality, integrations or dependencies.
This makes continuous visibility increasingly important for enterprise security.
How Businesses Can Secure AI Tools
There is no single solution to the challenges created by AI adoption. Organisations need a combination of governance, visibility, employee education and technical controls.
1. Know what AI is being used
You can't secure what you can't see.
Organisations should establish visibility into approved and unapproved AI applications, services, agents and integrations.
This doesn't necessarily mean blocking every unapproved tool. It means understanding the environment well enough to make informed decisions.
2. Assess permissions and access
An important part of AI cybersecurity risks for enterprises is determining what an AI system can access.
Apply least-privilege principles wherever possible. AI tools and agents should have only the permissions they genuinely need to perform their intended functions.
3. Establish clear AI governance
Employees need clear guidance on acceptable AI use.
Policies should address areas such as:
- Which AI tools are approved
- What information can be entered into AI services
- How third-party AI applications should be assessed
- Who can create or deploy AI agents
- How AI integrations are approved
- How access and permissions are managed
Good AI governance should enable responsible adoption rather than simply prohibit it.
4. Assess AI skills and third-party components
ESET's research demonstrates why organisations need to look beyond the headline AI application.
Third-party AI skills can extend functionality, but they can also introduce malicious or suspicious capabilities.
Businesses should consider where these components come from, what permissions they require and whether they have been assessed before being introduced into enterprise environments.
5. Educate employees
Technology alone cannot solve the problem. Employees need to understand why connecting an AI tool to company systems or installing an unfamiliar AI skill can create security implications.
Training should focus on practical decision-making rather than treating AI as something employees should fear.
The goal is to help employees ask better questions, such as:
- Do I need this tool?
- What information will it access?
- Who developed it?
- What permissions am I granting?
- Has my organisation approved its use?
6. Monitor for emerging threats
The AI ecosystem is changing too quickly for a one-time assessment to be enough.
Organisations should continuously monitor developments in AI threats, malicious AI components and emerging attack techniques.
ESET's H1 2026 Threat Report illustrates why. Alongside malicious AI skills, ESET observed the emergence of PromptSpy, which it describes as the first Android malware observed actively using generative AI at runtime. The report also documented the continued evolution of ClickFix techniques, including attacks designed to exploit trust in generative AI.
These developments demonstrate a broader trend. Attackers are not waiting for organisations to become comfortable with AI before adapting their tactics.
How AI Is Changing The Cybersecurity Landscape
The rise of AI doesn't mean businesses need to stop employees from experimenting with new technology. Organisations do need to rethink how they approach risk.
The traditional question was often: "Is this application safe?"
With AI, organisations increasingly need to ask: "What capabilities does this application introduce, what can it access, and what other components does it depend on?"
That is a much broader security challenge.
The AI attack surface for businesses can extend from an employee's browser to an AI assistant, from an AI agent to a third-party skill, and from that skill to sensitive enterprise systems.
Understanding those connections is becoming an important part of modern AI cybersecurity.
A More Informed Approach To AI Adoption
Artificial intelligence can deliver genuine value to businesses. Employees can work more efficiently, developers can accelerate software development, and organisations can create entirely new services.
The answer isn't to treat every employee experimenting with AI as a security problem. Instead, businesses need sufficient visibility and control to support responsible adoption.
That means understanding the employee use of AI security risks without losing sight of the benefits AI can deliver. It means putting appropriate governance around AI tools, understanding permissions and connections, assessing third-party skills and agents, and ensuring employees know how to use AI safely.
Most importantly, it means recognising that the AI ecosystem itself is evolving into an important part of the cybersecurity landscape.
The AI Attack Surface Is Evolving Rapidly.
ESET's H1 2026 research shows just how quickly the AI ecosystem is developing. Its analysis provides a clear reminder that organisations need visibility into the technologies entering their environments.
For South African businesses embracing Enterprise AI, the question isn't whether employees will use artificial intelligence. In many cases, they already are.
The more important question is whether the organisation can see, understand and manage what that use introduces.
Keep up to date. Read the ESET H1 2026 Threat Report to explore the latest developments shaping the threat landscape