By Mohammed Jabie (Regional Sales Manager – SADC)
I keep seeing the same blind spot in organisations across the region. We’ve given AI assistants on our phones access to basically everything: contacts, messages, files, calendars, because that’s what makes them useful. But almost nobody stops to ask whether each individual task actually needs that much reach. We’d never approve a random third-party app requesting that scope without a second look. An AI assistant gets a pass because it feels like a productivity tool, not a permission request.
Adoption is outrunning the security model
This isn’t a one-off case I’ve encountered. It’s happening across the board, and the pace is the problem. GSMA’s Mobile Economy Africa 2026 report puts mobile’s contribution to the continent’s economy at $240 billion in 2025, with AI now moving from pilot to deployment across operators and enterprise services alike. That’s the upside. The downside is that most of this activity is happening on devices that already sit outside the traditional enterprise perimeter, and our security thinking hasn’t caught up. Globally, the picture is just as stark. Zscaler’s ThreatLabz 2026 AI Security Report recorded a 93% year-on-year increase in enterprise data transferred into AI and machine learning tools, with more than 18,000 terabytes moved in a single year. A meaningful share of that traffic now originates from mobile devices, quietly, in the background, well outside whatever policy exists on paper.
Built to catch the wrong threat
Our mobile threat defence tools weren’t built for this. They’re designed to catch malware, jailbroken devices, dodgy networks, malicious apps, not a legitimate, sanctioned AI agent quietly working through sensitive data in the background. Zimperium’s 2025 Global Mobile Threat Report found that AI services embedded within everyday workplace apps grew by roughly 160% in a single year, and that a single provider, OpenAI, was integrated into around 70% of the AI-powered apps its researchers analysed on enterprise devices. That’s not a niche pattern. It’s becoming the default, and it’s happening inside apps that already passed whatever vetting process an organisation has in place. An AI assistant reading a calendar entry, summarising a contract, or drafting a reply using customer data doesn’t trip any of the alarms mobile threat defence was built to catch, because it isn’t malicious. It’s doing precisely what it was installed to do. Cisco’s State of AI Security 2026 puts a number on the resulting gap: 83% of organisations plan to deploy agentic AI, but only 29% feel genuinely prepared to secure it. IBM’s 2025 Cost of a Data Breach Report adds the sharper detail: 97% of organisations that experienced an AI-related breach lacked proper access controls at the time it happened, and 63% had no AI governance policy in place at all.
The answer isn’t a ban
I don’t think the answer is banning these tools. That ship has sailed, and they’re genuinely useful to the people using them. The answer is getting our mobile threat defence tooling to see what the AI agent is actually doing: what data it’s touching, what it’s doing with that data, and whether that activity lines up with what it’s supposed to be doing. That’s a visibility problem before it’s a policy problem, and visibility is something we can build toward without asking anyone to give up the tools that make them faster at their jobs.
At DataGroupIT, this is the conversation we’re increasingly having with partners across the region, in Lusaka, Cape Town, Nairobi, and Lagos alike: mobile security has to evolve from watching for bad actors to watching for bad behaviour, regardless of how legitimate the tool behind it looks.
The question every CISO should be able to answer
Here’s the question I’d put to any CISO on the continent. If an AI assistant on one of your employees’ mobile devices touched sensitive corporate data right now, could you detect that? Could you explain it after the fact? Most organisations I talk to can’t, and that’s the gap I want this piece to put on the table. The tools that got us this far weren’t built for what’s running on our phones today. The ones that get us through the next few years will need to be.
Mohammed Jabbie is Sales Manager for SADC at DataGroupIT (DGIT), a pan-African cybersecurity value-added distributor helping organisations build security architecture across identity, data, cloud, network, and managed security services.
