Report by KnowBe4

From Agentic Risk to Human Win: Building a Culture of Security in the Era of Agentic AI

9 FINDINGSPublished May 20, 2026
View Original Report →

Key Findings

Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.

Shadow AIAI AdoptionInsider RiskAgentic AI

42% of cybersecurity leaders identify AI-enabled attacks as a key driver of future human-related cybersecurity risks.

AI AttacksHuman Error

86% of employees say deepfake content is so realistic that it is harder to know what to trust.

DeepfakesEmployee Awareness

58% of cybersecurity leaders say mistakes during everyday work have had the greatest impact on their organization’s cybersecurity in the past 12 months.

Human ErrorOperational Risk

19% of cybersecurity leaders report their organizations have an integrated and culture-embedded approach in place to manage human-related cybersecurity risk.

Security CultureRisk ManagementHuman Error

58% of cybersecurity leaders report that AI agents are already taking actions within organizational workflows.

AI AgentsWorkplace Automation

52% of organizations report their use of AI is unapproved or ungoverned.

AI GovernanceOrganizational RiskAI Use

64% of employees say it is possible that they could be tricked by AI-enabled attacks.

AI AttacksEmployee RiskHuman Error

89% of employees say they feel safe reporting mistakes in organizations that prioritize cybersecurity as a culture.

Security CultureHuman Error