Skip to main content

Article

Three key insights on generative AI risks for South African organisations

Across industries, South African businesses are rapidly integrating generative AI to improve efficiency, enhance client outcomes, and develop new products and services.

Across industries, South African businesses are rapidly integrating generative AI to improve efficiency, enhance client outcomes, and develop new products and services. While AI-powered solutions offer significant benefits, they also introduce new risks. To fully harness AI’s potential, organisations need to recognise these risks and put the right measures in place to manager them effectively. There are three common myths to consider when navigating the complex landscape of generative AI risk.

selected option

Generative AI risks are the CISO’s problem alone

A common misconception is that generative AI risks should be managed exclusively by the chief information security officer’s (CISO) team. While robust cybersecurity capabilities are essential, they  are not sufficient to address the full range of risks associated with generative AI. Organisations need a broader, enterprise-wide approach to managing emerging AI related risks, including:

Technical controls:  Cybersecurity measures that may require updates or replacements to effectively mitigate generative AI risks.

Process controls: Governance frameworks, policies and procedures should provide clear oversight, with active involvement from the board and senior leadership in AI adoption and risk management.

People controls: Employees need appropriate education and training to use generative AI responsibly and recognise AI-enabled social engineering threats. In some cases, targeted upskilling and reskilling will also be required.

All three control types must be coordinated and iterated to build resilience. Even the most effective technical controls cannot prevent an employee from inadvertently inputting sensitive data sources into public AI models. Effective governance therefore requires centralised, multi-stakeholder leadership spanning human resources, legal/compliance, business units, risk management  as well as the CISO’s office.

Generative AI is an emerging technology, so cyber and technological risks are the only concerns

Although generative AI is still an emerging technology, its risk extends well beyond traditional cyber and technology issues. Organisations should also consider a broader range of business, legal and operational risks, including:

  • Physical injury or property damage from AI-generated product safety advice.
  • Financial loss or reputational damage from inaccurate or misleading AI-generated content.
  • Intellectual property infringements arising from the use of copyrighted or patented data to train AI models without permission.
  • Bias and discrimination allegations in personalised client experiences or employment practices.
  • Business distruptions caused by AI system failures or cyberattacks.
  • Data privacy breaches linked to AI driven personalised recommendations.
  • Wire transfer fraud enabled by hyper-realistic and convincing AI-generated deepfakes.

These risks span multiple commercial insurance lines, including cyber, technology errors and omissions (E&O), media liability, directors and officers (D&O), employment practices liability, intellectual property, general liability, and product liability.

To determine whether current risk management and insurance progremmes provide adequate protection, organisations should:

  • Inventorying all generative AI models and enterprise use cases.
  • Developing realistic risk scenarios reflecting potential failures and business impacts.
  • Mapping existing controls to these scenarios and planning for resilience.
  • Quantifying potential impacts on insurance programmes to adjust coverage limits or retentions as needed.
  • Aligning key risks with strategic insurance solutions across relevant lines.

Given generative AI’s broad applicability, risk mitigation and transfer strategies must be dynamic and iterative as the technology evolves.

Generative AI requires new, standalone insurance policies

A common assumption is that emerging technologies require new insurance products. While this was true for cyber insurance with the rise of e-commerce, generative AI has not yet introduced an entirely new category of insurable risk. Rather, it increases the frequency, scale and complexity of risks that organisations already manage.

For example:

  • Data privacy and security concerns are heightened by generative AI’s reliance on vast training datasets.
  • The misuse of technology to spread false or harmful content is intensified by AI’s ability to generate misinformation at scale.
  • Intellectual property risks are complicated by questions about training AI on protected data.
  • Technological errors, including AI hallucinations, extend traditional technology failures.

Although some insures have introduced AI-specific endorsements or targeted products, many organisation have incorporated machine learning into their operations without requiring the dedicated AI insurance.

Mitigating AI risk: Insurance considerations

The insurance industry continues to play an important role in helping South African organisations transfer risk and build resilience, adapting policies to address material security gaps to enable them to maintain their competitive edge. It is important to avoid exclusions that remove core coverage solely because generative AI is involved. Existing exclusions such as those for cyber, privacy regulations, professional services, intentional fraud, or government actions continue to apply and should be carefully reviewed before adding new language.

Coverage for generative AI risks should depend on the specific facts of each vulnerability, including the nature of potential damages and parties involved. And while generative AI risks may eventually warrant separate treatment, for now, they generally fit within existing insurance frameworks, with risk amplification managed through appropriate underwriting and pricing.

How Marsh can help

Generative AI represents a groundbreaking technological leap, offering significant opportunities while also introducing complex risks within South Africa's dynamic risk management and insurance landscape. As advancements continue spanning agentic AI, humanoid AI, quantum computing, and human-brain interfaces new and evolving AI-related risks will challenge an organisation’s ability to stay vigilant and informed.

For business leaders, the priority is to move beyond the hype and develop a practical understanding of how technologies may affect their operations, governance, risk profile and insurance arrangements. Oraganisation that proactively identify and manage these exposures will be better positioned to realise the benefits of AI while strengthening resilience against emerging.  At Marsh, we understand the risks posed by generative AI to your organisation. We are deeply committed to helping your business navigate these challenges with tailored risk assessment and management solutions.

To learn more about how Marsh can help your company manage generative AI risks, please get in touch with your Marsh risk advisor.

Note: This is the second article in a two-part series on cyber risk in South Africa. The first instalment examined cyber‑physical risk and property damage.