Wednesday, September 23, 2026

Organisations across APJ struggle to govern growing AI risk

The results show AI awareness and usage are accelerating, but accountability, monitoring and identity infrastructure are struggling to keep pace

Okta, the leading independent identity partner, released findings from its Okta AI Security Poll, revealing that while Singaporean organisations are moving fast on AI adoption, many remain unclear on who owns the associated risks and how those risks should be governed.

The live poll, conducted in November at Okta’s Oktane on the Road event in Singapore, surveyed technology and security leaders and highlights a growing gap between AI deployment and the maturity of governance and identity controls required to manage it effectively.

The results show AI awareness and usage are accelerating, but accountability, monitoring and identity infrastructure are struggling to keep pace.

Key findings:

  • Unclear ownership of AI risk: 53% said AI security risk sits with the CISO or security function, yet a concerning 25% reported no single person or function currently owns AI risk in their organisation.
  • Limited visibility into AI behaviour: Only 31% expressed confidence in their ability to detect if an AI agent operates outside its intended scope, while 33% do not currently monitor AI agent activity at all.
  • Growing blind spots: Data leakage via integrations was identified as the top security gap (36%), followed closely by Shadow AI, unapproved or unmonitored tools (33%).
  • Identity systems lagging: Just 8% said their identity systems are fully equipped to secure non-human identities such as AI agents, bots and service accounts, with 58% describing their capabilities as only partially equipped.
  • Boards aware, but not fully engaged: While 50% said their boards are aware of AI-related risks, only 31% reported full board engagement in oversight.

“Organisations in Singapore are adopting AI at speed, which signals growing maturity in how the technology is being used. We are seeing a shift from early experimentation to responsible, strategic adoption. The next step is ensuring governance and security evolve at the same pace,” said Stephanie Barnett, Vice President, Asia Pacific & Japan, Okta

“As AI becomes more embedded across workflows, organisations need to treat AI agents like any other and apply the same discipline to securing AI agents as they do to human users. When identity is strong, trust follows, and that’s what enables innovation to scale safely and sustainably.”

APJ perspectives

Organisations across Asia Pacific & Japan are accelerating their use of AI, and the latest findings from our Oktane on the Road AI Security Polls show just how quickly the landscape is shifting.

Across Australia, Singapore and Japan, one message is consistent: AI adoption is rising fast, but governance, accountability and identity controls need to evolve at the same pace.

Here’s what stood out across the region:

Ownership of AI risk is still fragmented

  • 41% of Australian organisations say no single owner manages AI security risk.
  • 25% in Singapore report the same gap.
  • Japan mirrors this trend, with 29% saying accountability remains unclear.
    This is becoming a board-level issue, and clarity will be essential in 2026.

Visibility into AI agent behaviour is low

  • Only 18% in Australia and 31% in Singapore feel confident they could detect an AI agent acting outside its intended scope.
  • In Japan, just 8% are confident.
    As AI agents become digital workers, this gap represents real operational risk.

Shadow AI is now the region’s biggest blind spot

  • 35% in Australia and 33% in Singapore cite Shadow AI as their top concern.
  • Japan highlights data leakage (36%) as its primary risk, followed closely by unapproved agents.

Identity systems aren’t yet ready for non-human identities (NHIs)

Across all three countries, fewer than 10% say their IAM systems are fully equipped to secure AI agents, bots and service accounts. Most describe their systems as only partially ready. This is the next frontier of identity security.

Boards are waking up, but not uniformly

  • 70% of Australian boards are aware of AI-related risk, but only 28% are fully engaged.
  • In Singapore, 50% awareness but only 31% engagement.
  • Japan shows 43% full engagement, driven by tightening regulatory expectations.

Across APJ, AI momentum is strong, but so is the recognition that trust, governance and identity have to advance together.

As AI becomes embedded in workflows, organisations will need to secure not just people, but every system, every integration, and every AI agent acting on their behalf.

The poll findings point to a critical need for clearer accountability, stronger governance frameworks and modern identity systems that can secure both human and non-human identities as AI becomes embedded across enterprise operations.

Powered byspot_img

Table of contents [hide]

Read more

News

Powered byspot_img