
Artificial Intelligence is rapidly changing the way organisations operate. From automating routine processes and analysing large volumes of information to supporting decision making and improving customer experiences, AI is becoming an increasingly important component of modern business strategy. For many organisations, the question is no longer whether AI should be adopted, but how it can be adopted responsibly and securely. As businesses embrace these technologies, however, an important consideration is often overlooked: what happens to organisational data when employees begin using AI tools?
Consider a simple scenario. An employee receives a confidential document containing financial information, customer details, internal strategies or other sensitive business information. They need to summarise the document quickly and decide to upload it to an AI platform. Within seconds, the task is completed.
From a productivity perspective, this may appear harmless. From a security, privacy and governance perspective, however, it raises important questions about how that information is being processed, where it is being transferred, who may have access to it and whether its use is consistent with the organisation’s policies and regulatory obligations.
The AI Opportunity Comes With a Data Risk
AI presents enormous opportunities for organisations, but its rapid adoption also introduces a new dimension of technology risk. The challenge is not necessarily the technology itself, but how it is introduced, governed and used within the organisation.
Employees can now access powerful AI tools with very little technical expertise. This accessibility creates opportunities for greater productivity, but it can also make it easier for sensitive information to leave the organisation without appropriate controls. Confidential reports, customer information, intellectual property, financial records and strategic documents may be entered into AI platforms without employees fully understanding the implications.
This creates an important shift in the way organisations should think about cybersecurity. Protecting the business is no longer only about securing networks, applications and devices. It is also about understanding how people interact with emerging technologies and how those interactions affect organisational data.
AI Governance Is Becoming a Business Priority
As AI becomes embedded in everyday operations, organisations need clear governance frameworks that define how these technologies should be used. Employees need to understand which AI tools are approved, what information can be shared, what information must remain protected and what procedures should be followed when AI is used to process business information.
This is not simply an IT responsibility. AI governance sits at the intersection of cybersecurity, data protection, risk management, compliance, technology and business strategy.
The National Institute of Standards and Technology (NIST) recognises this need through its Artificial Intelligence Risk Management Framework and its Generative AI Profile, which provide organisations with structured approaches to identifying, assessing and managing AI related risks throughout the technology lifecycle.
The importance of this is becoming increasingly clear. IBM’s 2025 Cost of a Data Breach research found that 63% of organisations lacked AI governance policies to manage AI or prevent the proliferation of shadow AI, while 97% of organisations reporting an AI related security incident lacked proper AI access controls.
The Human Element Cannot Be Ignore
Technology may provide the tools, but people determine how those tools are ultimately used.
The accessibility of AI means employees can transfer information into an AI platform almost instantaneously. Often, the intention is not malicious. An employee may simply be trying to work faster, analyse information or improve the quality of a document. However, without clear policies and awareness, a well intentioned action can create an unintended security or privacy risk.
This is why responsible AI adoption requires more than policies. Organisations need to create an environment where employees understand both the opportunities and responsibilities that come with using AI.
The World Economic Forum’s Global Cybersecurity Outlook 2026 highlights this growing challenge, noting that AI is reshaping cybersecurity by strengthening defensive capabilities while also enabling new and more sophisticated risks. The report also identifies AI related vulnerabilities as a rapidly growing cyber risk.
Moving From AI Adoption to Responsible AI Adoption
The organisations that benefit most from AI will not necessarily be those that deploy the greatest number of AI tools. They will be those that establish the right foundations for using AI securely, responsibly and strategically.
This means understanding what data is being processed, where it is going, who has access to it and what controls are in place to protect it. It also means assessing third party AI providers, establishing appropriate access controls, developing clear policies and continuously reviewing the organisation’s evolving technology risk landscape.
AI adoption should therefore not be viewed simply as a technology project. It should be approached as a business transformation initiative that requires appropriate governance, risk management and accountability.
Partner With Baker Tilly
At Baker Tilly Central Africa, we understand that technology creates value when it is supported by the right combination of strategy, governance, security and risk management.
Our multidisciplinary approach enables us to help organisations navigate the complexities of digital transformation, including cybersecurity, data protection, technology risk and the governance of emerging technologies. We work with organisations to identify vulnerabilities, strengthen controls and develop practical approaches that support innovation without losing sight of security and compliance.
Our role is not to discourage organisations from embracing AI. Rather, it is to help them understand the risks, establish appropriate controls and create an environment in which AI can be adopted with greater confidence.
For organisations exploring AI adoption, the question should therefore extend beyond “What can AI do for our business?”
It should also be:
“How can we use AI while protecting the information, people and trust that our business depends on?”
AI is here to stay. The organisations that succeed will not simply be those that adopt AI, but those that know how to integrate it responsibly into their operations.
The future of AI in business is not only about intelligence. It is about trust.
At Baker Tilly Central Africa, we are ready to help organisations navigate that future securely, responsibly and strategically.
References
Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1). National Institute of Standards and Technology.
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST.
IBM. (2025). Cost of a Data Breach Report 2025. IBM Security and Ponemon Institute.
World Economic Forum. (2026). Global Cybersecurity Outlook 2026. World Economic Forum, in collaboration with Accenture.
By Tanyaradzwa Sithole
Head of Systems Business Development