As small firms start handing routine tasks to AI tools that can act on their own, a new question follows close behind: who is watching what those tools do? Security firm KnowBe4 argues that securing AI agents is now just as important as training the people who work alongside them, and that treating the two as separate problems leaves a dangerous gap.
In a recent post from KnowBe4, CISO Advisor Dr Kawin Boonyapredee sets out how the threat picture is shifting as AI moves from a helpful assistant to what the company calls a “digital workforce”. You can read the original KnowBe4 article for the full detail.
Why this matters to UK SMEs
Most small businesses now use AI in some form, whether that is a chatbot handling enquiries or an assistant drafting emails. The risk is that these tools can be tricked. KnowBe4 points to AI-generated phishing (fake messages designed to steal data), deepfakes (convincing fake audio or video) and “prompt injection”, where an attacker hides malicious instructions inside content an AI reads and then follows.
For a firm without a dedicated IT team, that is a lot to keep on top of. The good news is that the underlying advice is practical and does not require enterprise budgets.
What KnowBe4 recommends
- Train people continuously, not once a year. KnowBe4 says passive, tick-box awareness training no longer cuts it. Regular, realistic practice keeps staff alert to newer scams.
- Give AI agents their own identity controls. Just as you manage staff logins, any AI tool that can access your systems needs limits on what it can reach and do.
- Keep a human in the loop. High-impact decisions, such as payments or data sharing, should still need a person to approve them.
- Build a “resilience culture”, not a blame culture. Staff who fear being told off tend to hide mistakes. An open reporting habit helps you catch problems early.
These ideas echo good practice UK firms should already recognise. If you are getting started, our guides on using ChatGPT and Copilot without breaking UK GDPR and the risks behind the Copilot “AI worm” hidden in Word documents cover similar ground in plain English.
The practical takeaway
You do not need to buy a big security platform to act on this. Start by listing every AI tool your business uses and what each one can access. Then set clear rules: which decisions always need human sign-off, and how staff should report a suspected scam without fear of blame. Working towards Cyber Essentials certification is a sensible next step, and a simple security routine to catch problems early costs little beyond an hour of your time.
AI can save your business real hours. Treating your tools and your team as one connected defence is how you keep those savings safe.





