Ungoverned AI Agents and Sophisticated Deepfakes Pose Critical Threats for Singaporean Organisations, New KnowBe4 Research Warns
Global study reveals 44% of Singaporean organisations already deploy autonomous AI agents with little to no governance, while 93% of employees admit they are unlikely to be able to spot attacks such as deepfakes

KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of its new research report, “From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI.” The findings expose a dangerous reality for modern Singaporean organisations: autonomous AI tools are expanding the corporate attack surface faster than security teams can implement guardrails.
With agentic AI now widely embedded in day-to-day work, 2 in 5 Singaporean cybersecurity leaders (40%) report that AI agents are already taking actions autonomously within organisational workflows. However, a lack of governance is leaving organisations exposed. The report shows that, despite 99% of Singaporean organisations admitting to using AI in workflows, a staggering 44% report that their use of AI is unapproved or ungoverned. This unmanaged “Shadow AI” effectively operates as an invisible layer of shadow employees handling sensitive organisational data without oversight.
Key Findings From the Report:
• 93% of Singaporean employees say that deepfake voice and video content is now so realistic it is impossible to know what to trust, and 87% openly admit they could be tricked by a deepfake scam at work. This is markedly higher than the global averages of 86% and 64%, respectively.
• Yet, a gap persists, with 88% of leaders remaining confident that employees can identify impersonation messages via internal tools, and 74% confident that employees can identify deepfake voice and video content.
• 100% of leaders in Singapore report that human-related behaviours have impacted their organisations’ cybersecurity in the past 12 months. Compounding this, 67% of employees acknowledge that time pressures and workplace distractions actively drive them to make critical security mistakes, even when they know the safe protocol.
• Nearly one in three employees (32%) reported that they commonly source their own agentic AI tools where options are unavailable or restrictive, leaving organisations vulnerable to cyberattacks. Concurrently, 56% of cybersecurity leaders report that the use of unsanctioned software and AI apps has actively impacted their security posture over the past 12 months.
• Despite 88% of organisations claiming that employees feel safe reporting mistakes or suspicious activity without fear of blame or embarrassment, the data tells a different story: more than a third (37%) of employees admit they sometimes choose not to report a security mistake due to embarrassment.
“Cybersecurity has entered a volatile phase where organisations are trying to secure a hybrid human and AI workforce that’s changing more quickly than security leaders can keep up,” said Dr Kawin Boonyapredee, CISO Advisor at KnowBe4 APJ. “Attackers are moving at machine speed, using attacks such as deepfakes to target employees and prompt injections to hijack AI agents. Leaving nearly half of your corporate AI usage ungoverned is a massive open invitation to threat actors.”
The “From Agentic Risk to Human Wins: Building a Culture of Security in the Era of Agentic AI” report concludes that achieving “Wins” requires organisations to design systems that guide behaviour, build supportive cultures, and shift from tracking failures to reinforcing positive actions, while extending a security-first mindset across both AI agents and humans.



