KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, has today revealed the UK-specific findings of its latest research report: From Agentic Risk to Human Wins. The research found that UK organisations are increasingly concerned about employees using unapproved software and AI tools, with 58% of decision makers citing it as their top human-related cyber risk. The concern is well founded: 55% of employees admit to using unapproved tools, while 1 in 10 knowingly entered sensitive information into AI platforms despite understanding the risks.
55% of British employees admit to using unapproved AI tools at work.
58% of decision makers cite unapproved AI tools as top human-related cyber risk.
1 in 10 employees knowingly entered sensitive information into AI platforms.
49% of decision makers say managing safe AI use is a top concern.
85% say improvement is needed to ensure AI tools operate within security policies.
38% of decision makers cite high workloads and fatigue as top cyber risk drivers.
Employees are consistently less confident in their ability to identify cyber threats than cyber decision makers think they are. The deficit is particularly pronounced for deepfake video or audio impersonation, which 81% of decision makers believe employees could identify, compared with only 66% of employees themselves. Both decision makers and employees are most confident in their ability to spot phishing emails (98% of decision makers are confident compared to 95% of employees). The top human-related cyber risk indicators that organisations measure most frequently is phishing reporting rates (44%).
Almost half (49%) of decision makers said that managing the safe use of AI tools and AI agents is one of their top concerns. In fact, 46% of decision makers said they have specific targets for improving the safe use of AI agents in day-to-day workflows over the next 12 months. Almost one in five (19%) of decision makers said that AI tools/AI agents take actions autonomously in multiple workflows with limited human oversight. Of those respondents who said their organisation uses AI tools/agents in workflows today, 85% say 'improvement is needed' to ensure AI tools/agents operate within the organisation's security policies and approved risk limits.
Another of the biggest perceived threats to British organisations in the next 12 months is high workloads and fatigue, with 38% of decision makers noting that high workloads or time pressures are likely to contribute to cyber related mistakes made by employees. Nearly half of employees (47%) acknowledged that time pressure or distraction can lead to security mistakes even when they know the safe action to take. 93% of decision makers said that employees often know the right thing to do when facing cyber threats but may act differently under pressure, suggesting that security failures are less about knowledge gaps and more about behavioural responses under pressure.
When it comes to existing regulations, 84% say that regulatory reporting requirements are the primary driver of how quickly cybersecurity incidents are escalated and reported within their organisation. Additionally, 85% of decision makers say that the Cyber Security and Resilience Bill will play a significant role in how they manage human-related cyber risk. 39% of decision makers say that risks from third-party organisations/suppliers is one of the biggest drivers of human-related cyber risk within their organisation.
Javvad Malik, lead CISO advisor at KnowBe4, stated: "Undeniably, AI tools and agents are reshaping the workplace, but organisations can't afford to overlook the human element of cybersecurity. Our research shows that while UK businesses are embracing AI to drive productivity, many employees are still under pressure, using unapproved tools and regularly facing sophisticated threats such as deepfakes and phishing. Building a strong security culture, especially one that prioritises education, behavioural support and safe AI adoption, will be critical to reducing human-related cyber risk in the years ahead."
About KnowBe4
KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15-years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.