Africa’s AI Revolution Has Entered a New Cybersecurity Battle Why Agentic AI Changes the Rules

Share

Artificial intelligence has spent the past few years being sold as a productivity revolution. Now cybersecurity experts are increasingly warning that the same technology could transform the threat landscape. The concern is not simply that criminals will use AI to write better phishing emails or generate malicious code.

The bigger change comes from agentic AI systems designed to plan, make decisions and carry out tasks with a degree of autonomy. African organisations rushing to adopt AI, its important to note that shift creates a new security problem.

Traditional cybersecurity models were largely designed around human users.Whereby a person logs into a system, a person makes a decision and a person carries out an action. Agentic AI complicates that model because software can potentially perform multiple actions at machine speed once given a goal.A recent analysis from Microsoft’s Africa cybersecurity leadership argued that the defining challenge of the AI era is increasingly autonomy, rather than intelligence alone.

The warning arrives as Kenya and other African countries explore agentic AI for government services, finance, business and other sectors. The opportunity is enormous. So is the security challenge.

Why agentic AI is different from ordinary AI

The chatbot era is giving way to autonomous systems Generative AI became mainstream because people could interact with systems through natural language. Some of the interactions include:  Ask a question, receive an answer, ask for a summary, receive a summary, ask for code and receive code.

Agentic systems are designed to go further. They can potentially break a larger objective into smaller tasks and interact with external systems to accomplish them. That difference matters enormously for cybersecurity.

A conventional AI model might explain how a security vulnerability works. An agent could potentially be instructed to investigate systems, analyse information and perform a sequence of actions. The number of steps creates additional opportunities for errors, misuse or manipulation.

AI agents need access to systems. This is the fundamental security dilemma since an AI agent is only useful if it can do something. To schedule an appointment, it needs access to a calendar., to process a payment, it needs access to a financial system, to manage a supply chain, it needs access to logistics data, to support government services, it may need authorised access to multiple databases. Every permission creates a potential risk. The more systems an agent can access, the more powerful it becomes. But greater access also increases the consequences if the system is compromised or behaves unexpectedly.

Africa is entering the agentic AI era at a critical moment

Kenya is already preparing for autonomous government systems The government is developing a unified platform intended to connect public institutions through secure APIs as it prepares for greater use of AI agents in service delivery.

The idea is to move beyond isolated digital services and allow systems to communicate securely. That could eventually make government services more efficient. But it also means cybersecurity becomes a foundational issue. If an AI agent can access several government systems, those systems must be able to establish exactly what the agent is allowed to do. Kenyan officials have already highlighted requirements including authorisation, audit trails, data-access controls, error handling and escalation to human officers. Those controls will be essential.

African banks face a similar challenge

Financial institutions are another obvious target. Banks and fintech companies are increasingly using AI for fraud detection, customer service, risk assessment and operational automation. The benefits can be substantial. But financial systems also contain sensitive information and control valuable assets.

An AI system with excessive permissions could create serious problems if its credentials were stolen or its instructions manipulated. This is why the growth of fintech across Africa needs to happen alongside stronger AI security. The continent has built some of the world’s most innovative mobile-money ecosystems. It now needs to ensure that the next generation of AI-powered financial services does not create vulnerabilities that undermine that progress.

The global threat picture is changing

AI is already being used in sophisticated cyber operations The risks are not purely hypothetical. Anthropic’s September 2026 threat-intelligence report described multiple cases where AI was used to accelerate cyber operations. The company reported an operation involving autonomous workflows for vulnerability research and exploit development, alongside other AI-enabled espionage and surveillance activities.

The report also described a separate Kenyan influence operation in which AI was used to generate large volumes of political content designed to appear organic. Anthropic said it identified and disrupted the operation, while noting that it found no evidence of government involvement. The examples demonstrate that AI misuse is not something Africa can treat as a distant problem. It is already appearing in African digital environments.

AI can lower the barrier to sophisticated attacks. Historically, some cyber operations required highly specialised expertise. AI can potentially reduce the amount of technical knowledge required for certain tasks. That does not mean AI automatically turns inexperienced criminals into elite hackers. But it can accelerate research, automate repetitive work and help operators process large amounts of information.

This changes the economics of cybercrime. A small group may potentially be able to attempt more attacks with fewer people. For African organisations that already struggle with cybersecurity resources, that creates additional pressure.

What African organisations need to do differently

Security must be built into AI systems. One of the most important lessons from the agentic AI shift is that cybersecurity cannot be added after deployment. Organisations need to think about security when designing AI systems.That means defining permissions carefully. An AI agent should have access only to the systems and information necessary to perform its assigned task. It should not automatically receive broad administrative privileges.

Human oversight still matters. Autonomy should not mean unrestricted freedom. High-risk actions may require human approval. A financial transfer, deletion of important information or modification of a government record could require a person to confirm the action. That creates a balance, AI handles repetitive or time-consuming tasks. Humans remain responsible for decisions with serious consequences. Kenyan officials have emphasised the importance of human judgement as AI agents become more capable.

Organisations need better monitoring. AI agents should also leave clear audit trails. If a system performs an action, organisations should be able to determine what happened, which information the agent accessed and why it made the decision. Without that information, investigating mistakes becomes extremely difficult. Monitoring becomes even more important when agents interact with multiple systems.

Africa’s cybersecurity workforce will need to evolve

The agentic AI era will create demand for a different type of cybersecurity professional. Security teams will need to understand traditional networks and cloud systems while also understanding AI models, data flows, permissions and autonomous behaviour. Kenya’s growing focus on AI skills could therefore have a cybersecurity dimension.

The country needs people who can build AI systems and people who can attack, test and secure them.That creates opportunities for universities, technology companies and cybersecurity training providers. The same applies across Africa. As more governments and businesses deploy AI, the continent will need a larger pool of specialists capable of managing the risks.

The biggest mistake would be treating AI security as an IT problem alone

Agentic AI will affect more than IT departments. Boards will need to understand it. Government policymakers will need to regulate it. Bank executives will need to consider it. Healthcare organisations will need to manage it. Universities will need to teach it. Consumers will need to understand what it means when software makes decisions on their behalf.

That makes AI cybersecurity a business and governance issue rather than simply a technical one. Africa is entering this transition while many organisations are still building basic cybersecurity capacity.

The challenge is to avoid repeating an old pattern in which technology is deployed quickly and security is considered later. Agentic AI makes that approach particularly risky because autonomous systems can potentially move faster and across more systems than traditional software.

The technology itself is not inherently dangerous. Its risk depends heavily on how it is designed, deployed, monitored and governed. For Africa, that means the AI revolution and cybersecurity revolution must develop together. Kenya’s current experiments with agentic AI provide an early example of what is coming.

The country wants smarter digital services. Businesses want greater automation. Financial institutions want more efficient operations. Those goals are understandable. But the systems being built today will also determine how resilient African digital economies are tomorrow. Follow Ascendant Africa for more reporting on artificial intelligence, cybersecurity, Kenya technology, African fintech and the digital risks emerging as autonomous AI systems become more widespread.

Read more

Local News