A recent global study involving 3,700 business and IT leaders worldwide, including 200 respondents from Singapore, highlights growing concerns about the pace of artificial intelligence adoption within organisations. The findings reveal that 67% of Singapore-based respondents have experienced pressure to approve or implement AI initiatives despite having reservations about security risks. More notably, nearly one in nine respondents described their concerns as “extreme,” yet felt compelled to move forward in order to meet competitive expectations and satisfy internal demands for innovation.
According to David Ng, Managing Director for Singapore, the Philippines, and Indonesia, the issue is not a lack of awareness regarding AI-related risks. Instead, many organisations lack the governance structures, processes, and resources needed to manage those risks effectively. He noted that when AI deployment is driven primarily by market competition rather than organisational readiness, businesses risk integrating AI into critical operations without sufficient safeguards. The study reinforces the importance of balancing AI-driven business outcomes with strong risk management and governance practices.
These challenges are further amplified by inconsistent governance frameworks and uncertainty over who should be responsible for managing AI-related risks. In many organisations, security teams are forced into a reactive role, responding to executive-led AI initiatives after deployment decisions have already been made. This environment often encourages employees to seek unofficial solutions, resulting in increased use of unsanctioned or “shadow AI” tools that operate outside established security controls.
At the same time, the cyber threat landscape is evolving rapidly. Recent TrendAI™ threat research indicates that cybercriminals are increasingly leveraging AI to automate reconnaissance activities, enhance phishing operations, and simplify sophisticated attack techniques. As a result, attackers can execute campaigns with greater speed, scale, and efficiency than ever before, raising the stakes for organisations that lack adequate AI governance.
AI Adoption Is Moving Faster Than Organisational Readiness
The study suggests that many organisations in Singapore are embracing AI technologies at a pace that exceeds their ability to govern and secure them effectively. While enthusiasm for AI remains high, confidence in managing associated risks remains relatively low. Only 29% of organisations believe they are well prepared to keep up with the speed of AI adoption. Meanwhile, 59% report only moderate confidence, or less, in their understanding of the legal and regulatory frameworks that govern AI use.
Governance maturity remains a significant concern. Just 39% of organisations have implemented comprehensive AI policies, while many others are still in the process of developing guidelines and governance frameworks. Nearly half of respondents, 48%, identified uncertainty surrounding regulations and compliance requirements as a major obstacle to effective AI adoption. This suggests that many businesses are operationalising AI technologies before establishing clear rules, responsibilities, and oversight mechanisms.
Trust in Autonomous AI Systems Remains Limited
While organisations are increasingly exploring advanced forms of AI, including autonomous and agentic systems, confidence in these technologies is still developing. More than half of IT decision makers, 57%, believe agentic AI could significantly strengthen cybersecurity capabilities in the near future. However, optimism is tempered by persistent concerns regarding oversight, accountability, and data security.
The survey highlights several areas of concern. Forty-two percent of IT decision makers worry that attackers could exploit the trusted status of AI systems to gain unauthorised access or manipulate operations. Another 39% are concerned about AI agents accessing sensitive corporate data without adequate controls. Meanwhile, 36% identify autonomous code deployment as a potential security risk, fearing that AI-driven systems could introduce vulnerabilities or make changes without sufficient human review.
Security professionals are also concerned about the growing attack surface created by AI adoption. One-third of respondents believe malicious prompts or prompt injection attacks could compromise AI systems and organisational security. Additionally, 31% point to the expanding opportunities available to cybercriminals as organisations deploy more AI-powered tools across their environments.
Perhaps most concerning is the lack of visibility into how these systems operate. More than a third of respondents, 38%, admit they do not have adequate observability or audit capabilities for autonomous AI systems. Without sufficient monitoring and transparency, organisations may struggle to understand AI decision-making processes, investigate incidents, or intervene when problems occur.
Questions Remain Over Maintaining Control
As AI systems become increasingly autonomous, organisations continue to debate how much control should remain in human hands. Around 40% of respondents support implementing AI “kill switch” mechanisms that would allow organisations to immediately disable AI systems in the event of malfunction, misuse, or unexpected behaviour. However, nearly half of respondents remain undecided on the issue.
This uncertainty reflects a broader challenge facing organisations today. While businesses are rapidly moving toward more autonomous AI deployments, there is still no clear consensus on the governance models, oversight mechanisms, and emergency controls required to manage these technologies safely.
Rachel Jin emphasised that agentic AI introduces an entirely new category of organisational risk. She noted that concerns surrounding sensitive data exposure, loss of oversight, and insufficient governance are already evident. Without stronger visibility, accountability, and control mechanisms, organisations risk deploying AI systems that they do not fully understand or effectively manage. As AI capabilities continue to advance, these risks are likely to become even more significant unless organisations take proactive steps to strengthen governance and security frameworks.

