The AI velocity trap

The AI velocity trap

Singapore’s AI lead is real. The onus going forward is to secure the AI infrastructure and ensure good governance.

By on

Singapore has stopped experimenting with artificial intelligence. It is now running on it. Across the city-state, AI has moved from novelty to infrastructure at a pace few economies can match.

Research from Notion puts 21 percent of Singaporean organisations at advanced AI maturity, the point where AI operates as embedded workflow, autonomous teammate, or core operating machinery. The global benchmark sits at 12 percent. In corporate AI, it appears as if Singapore is running a different race.

That tempo is set from the top. Nearly 90 percent of local decision-makers say government policy directly shapes their AI strategy, evidence of how tightly national ambition and enterprise automation have fused. The business case writes itself: almost half of workers say AI now saves them more than an hour a day. In a productivity-obsessed economy, that becomes a competitive weapon.

The trouble is that speed has become the entire strategy. Companies are wiring powerful systems into their operations faster than the security controls around those systems can be built. The result is a widening gap between adoption and assurance. Ninety-seven percent of Singaporean enterprises have deployed or piloted AI, and ESET found that four out of five organisations have experienced at least one AI-related security threat in the past year.

Visibility is the weak point. Only about one out of two organisations monitor access to AI tools and their outputs, leaving security teams guessing at what data is going in, who can see what comes out, and where it might resurface. The fallout is already tangible: 40 percent of organisations report employee misuse of generative tools that leaked sensitive data onto public platforms.

Attackers have clocked it too. AI-generated phishing and impersonation have hit 46 percent of local companies, climbing to 62 percent in financial services. The same systems that help staff draft, summarise, and automate are helping criminals scale deception, with better grammar, sharper context, more convincing timing.

When AI becomes the access layer

The deeper threat lives in the stack itself. Tenable's global research found that about one out of five organisations have overprivileged AI identities: cloud AI services inheriting or assuming roles with far more access than they need. What this does is that AI starts functioning as an access layer.

That access lands inside cloud environments already riddled with familiar weaknesses. Sixty-five percent of organisations are still carrying forgotten credentials that have never been rotated. Eighty-six percent host third-party code packages with critical vulnerabilities. Eighty-two percent run cloud workloads so exposed that analysts call them sitting ducks. Layer AI on top and the blast radius changes shape: a misconfigured permission becomes a route in for a system that reads broadly, acts fast, and follows instructions at machine speed.

This is what many organisations still underestimate. AI risk isn't confined to hallucinations or careless prompting. It's a question of identity, access, context, and control. Gartner expects that by 2029, more than half of successful attacks on autonomous AI agents will exploit access-control weaknesses and prompt injection. The security market is already pricing that in, with AI security spending projected to approach US$4.8 billion by 2027.

The governance gap

Singapore's enterprises understand the upside. Whether they understand the operating burden is another matter. Seventy-nine percent of local organisations remain in the lower AI maturity bands, where use is still confined to personal productivity and ad hoc task support. The leap from assistants to autonomous teams takes more than training sessions and tool licences; it demands a governance model that defines what AI can reach, what it can disclose, and what it can do without a human signing off.

For the advanced adopters, the question is no longer about whether employees can use AI well. It's whether the organisation can prove what AI touched, why it touched it, and whether it should have had access to begin with.

Singapore's AI lead is real, and it's exposed. Enterprises can't keep treating vulnerability management as an alert-volume exercise while autonomous systems magnify the cost of a single weak control. The next test is whether they can secure AI as infrastructure: tighter access governance, context-based exposure management, and monitoring that tracks both prompts and permissions. Velocity got Singapore to the front of the pack. The harder question is what that speed is dragging along behind it.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
© iTnews Asia
Tags:

Most Read Articles