Singapore AI governance faces enforcement gap as 84% bypass approval processes: report

by

Ansherina Baes

-

2 minutes ago

Singapore – Nearly all Singaporean IT leaders surveyed by Delinea said an AI tool or agent had accessed sensitive data beyond its intended scope in the past year, highlighting a gap between AI governance policies and their enforcement.

According to Delinea’s report, 98.8% of Singaporean IT leaders reported such an incident, the second-highest rate among the markets surveyed. Only 14% said they can detect a scope violation as it happens, compared with 19% globally.

The research is based on two global surveys involving 2,254 IT and security leaders and 2,250 non-IT employees at organisations with at least 500 employees that use AI. The surveys covered the UK, US, Germany, Australia, Singapore, UAE, France and India.

The findings also indicate that widespread adoption of AI policies has not necessarily translated into consistent compliance. In Singapore, 99.6% of organisations surveyed have a formal policy governing the data AI tools and agents can access, while 84% of employees said they had bypassed the required approval process for using AI at some point.

Of those employees, 51% said they bypass the process always or regularly.

“Singaporean organisations have done the hard part already; nearly every one of them has a formal AI policy,” said Cynthia Lee, VP of APAC at Delinea. 

“What’s missing is enforcing it in the moment. Without that, security teams won’t have full visibility and control over what their agents are actually doing,” Lee continued.

Policy adoption outpaces enforcement

Delinea’s research found that fewer than half of Singaporean organisations check AI access against policy in real time, despite the widespread presence of formal governance policies.

The report also found that 76% of Singaporean employees have felt pressured to use AI with sensitive or confidential data despite being unsure whether they were permitted to do so. The figure was the third-highest among the markets surveyed.

Accountability was another area where the research identified a gap. While 98.8% of Singaporean organisations require named-individual approval for at least some sensitive AI use, only 38% of Singaporean IT leaders said they can always trace a sensitive AI access event back to a named human authoriser.

AI enforcement gaps extend across IT environments

The report examined enforcement across six major technology environments and found that 47% of organisations globally lack enforcement at the moment of action in at least two environments.

CI/CD pipelines, Kubernetes and on-premises file systems were among the environments with the weakest enforcement, while cloud data stores and SaaS applications recorded stronger levels of enforcement but still contained gaps.

Delinea said the issue is particularly relevant as organisations increasingly use coding agents and other AI systems to perform tasks across their technology environments.

In Singapore, 72% of organisations surveyed said it takes a full day or longer to detect when an AI agent has moved outside its authorised scope. This was the highest proportion among the markets included in the research.

Runtime authorisation

The report argues that organisations need to move beyond authorising AI access only at login and instead enforce permissions at the point when an action is taken.

Delinea said its approach uses continuous, runtime authorisation with least-privilege controls and session visibility across AI, human and machine identities.

The company said this can provide security teams with a record of who authorised an access request, what an AI agent did and the reason the action was permitted.

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

Singapore AI governance faces enforcement gap as 84% bypass approval processes: report
GoTyme pairs AWS DevOps agent with human approval for AI incident response
Antom partners with Google Gemini to expand AI service access across Asia
Apple Pay now available in India with Axis Bank credit card support
MongoDB launches Atlas Agent Engine for production AI agents
Ellipse 3

RELATED ARTICLES

bain report
watchguard report
Report Hidden channel let AI Chatbot accounts secretly exchange tasks
Ellipse 3

FEATURED ARTICLES

'Retail & E-Commerce Innovation Summit' returns for its 2nd edition in the Philippines — initial speaker lineup revealed
‘Retail & E-Commerce Excellence Awards Asia Pacific
EW2025_(UT)Launch Article_Feature Image_11zon

Subscribe to UpTech Media Newsletter

JOIN OUR NEWSLETTER

Subscribe to our newsletter to get the latest APAC marketing news.