By Ben Wilmot-Sitwell ,
Cyber Growth Leader, South Africa
22/07/2026
Across industries, South African businesses are rapidly integrating generative AI to improve efficiency, enhance client outcomes, and develop new products and services. While AI-powered solutions offer significant benefits, they also introduce new risks. To fully harness AI’s potential, organisations need to recognise these risks and put the right measures in place to manager them effectively. There are three common myths to consider when navigating the complex landscape of generative AI risk.
A common misconception is that generative AI risks should be managed exclusively by the chief information security officer’s (CISO) team. While robust cybersecurity capabilities are essential, they are not sufficient to address the full range of risks associated with generative AI. Organisations need a broader, enterprise-wide approach to managing emerging AI related risks, including:
Technical controls: Cybersecurity measures that may require updates or replacements to effectively mitigate generative AI risks.
Process controls: Governance frameworks, policies and procedures should provide clear oversight, with active involvement from the board and senior leadership in AI adoption and risk management.
People controls: Employees need appropriate education and training to use generative AI responsibly and recognise AI-enabled social engineering threats. In some cases, targeted upskilling and reskilling will also be required.
All three control types must be coordinated and iterated to build resilience. Even the most effective technical controls cannot prevent an employee from inadvertently inputting sensitive data sources into public AI models. Effective governance therefore requires centralised, multi-stakeholder leadership spanning human resources, legal/compliance, business units, risk management as well as the CISO’s office.
Although generative AI is still an emerging technology, its risk extends well beyond traditional cyber and technology issues. Organisations should also consider a broader range of business, legal and operational risks, including:
These risks span multiple commercial insurance lines, including cyber, technology errors and omissions (E&O), media liability, directors and officers (D&O), employment practices liability, intellectual property, general liability, and product liability.
To determine whether current risk management and insurance progremmes provide adequate protection, organisations should:
Given generative AI’s broad applicability, risk mitigation and transfer strategies must be dynamic and iterative as the technology evolves.
A common assumption is that emerging technologies require new insurance products. While this was true for cyber insurance with the rise of e-commerce, generative AI has not yet introduced an entirely new category of insurable risk. Rather, it increases the frequency, scale and complexity of risks that organisations already manage.
For example:
Although some insures have introduced AI-specific endorsements or targeted products, many organisation have incorporated machine learning into their operations without requiring the dedicated AI insurance.
The insurance industry continues to play an important role in helping South African organisations transfer risk and build resilience, adapting policies to address material security gaps to enable them to maintain their competitive edge. It is important to avoid exclusions that remove core coverage solely because generative AI is involved. Existing exclusions such as those for cyber, privacy regulations, professional services, intentional fraud, or government actions continue to apply and should be carefully reviewed before adding new language.
Coverage for generative AI risks should depend on the specific facts of each vulnerability, including the nature of potential damages and parties involved. And while generative AI risks may eventually warrant separate treatment, for now, they generally fit within existing insurance frameworks, with risk amplification managed through appropriate underwriting and pricing.
Generative AI represents a groundbreaking technological leap, offering significant opportunities while also introducing complex risks within South Africa's dynamic risk management and insurance landscape. As advancements continue spanning agentic AI, humanoid AI, quantum computing, and human-brain interfaces new and evolving AI-related risks will challenge an organisation’s ability to stay vigilant and informed.
For business leaders, the priority is to move beyond the hype and develop a practical understanding of how technologies may affect their operations, governance, risk profile and insurance arrangements. Oraganisation that proactively identify and manage these exposures will be better positioned to realise the benefits of AI while strengthening resilience against emerging. At Marsh, we understand the risks posed by generative AI to your organisation. We are deeply committed to helping your business navigate these challenges with tailored risk assessment and management solutions.
Note: This is the second article in a two-part series on cyber risk in South Africa. The first instalment examined cyber‑physical risk and property damage.