The most AI-confident organisations are often the most exposed
Singaporean firms face an "AI confidence trap," where high adoption confidence masks poor security. Organizations must shift from policy-based governance to infrastructure-led controls to ensure actual data security and operational visibility.
The gap between what firms believe they can control and what they can prove has become harder to ignore
SINGAPORE’S AI strategy is accelerating the pace at which companies feel able to operationalise artificial intelligence. The country has launched four National AI missions and introduced a National AI Impact Programme designed to support 10,000 small and medium-sized enterprises (SMEs), among various initiatives.
Clear policy direction, growing investment and a maturing ecosystem are giving businesses a clearer path to move AI into regional operations.
That momentum is set to continue, with 72 per cent of businesses in Singapore planning to deploy agentic AI in several operational areas within two years, said Deloitte.
However, only 14 per cent of Singapore leaders said they have mature governance in place for agentic AI.
Singapore’s approach has helped build confidence in AI among business leaders, which has in turn catalysed AI innovation. But that sense of confidence could also risk inhibiting effective AI implementation.
While adoption is healthy, security is lagging behind.
Too many organisations are falling into the “AI confidence trap” – a heightened state of vulnerability when organisations fail to establish real control and visibility over their AI tools and broader IT environments.
Confidence is not security
Many senior leaders believe their organisations are already handling AI safely. A large percentage of firms have acceptable AI use policies, strong employee training programmes and a clear message from leadership on AI use.
In Singapore, that confidence is reinforced by a broader ecosystem focused on AI safety and innovation. Yet, strong national-level AI governance does not automatically translate into operational control inside every organisation.
Worryingly, organisations may have the right policies and right intentions, yet still lack true operational visibility and control.
AvePoint’s 2026 State of AI report, which surveyed 750 enterprise respondents globally, found that 82.7 per cent of organisations say they are very or extremely confident in their ability to prevent unauthorised access to data in AI environments.
Yet, 62 per cent still experienced at least one AI-related unauthorised access incident in the past 12 months.
In fact, greater confidence in AI correlated with greater risk of a breach.
From policy to infrastructure
To escape the AI confidence trap, organisations need to shift from policy-led governance to infrastructure-led governance.
Instead of treating AI governance as a set of documents and training programmes, organisations need a “trust layer” – a web of governance systems to power real AI control that operates continuously in the AI environment.
That trust layer does four things:
- governs what AI can access, enforcing permissions and approvals before systems reach sensitive data;
- provides visibility on what AI is doing, in both sanctioned and unsanctioned usage;
- maintains audit trails that document actions, decisions and changes for compliance and investigation; and
- ensures recovery, so that when something goes wrong, systems can be restored to a known-good state.
Singapore’s Government Technology Agency (GovTech) recently announced a registry of AI agents for 150,000 public officers to use cutting-edge AI in their work without compromising data security. It is part of a suite of tools that provide greater oversight over employees’ AI use.
This is a good example of infrastructure-led governance. Without such a foundation, confidence in AI will continue to be illusory and dangerous. Organisations may believe they are prepared while experiencing breaches at historically high rates.
The real test is enforcement
Boards and chief information security officers should stop asking how confident the organisation feels about AI security – and start asking what the organisation can actually enforce.
How many AI systems can you see? How many are governed by technical controls rather than written policies? How quickly can you detect and remediate an AI-related incident?
If an autonomous system takes an unauthorised action outside business hours, can you detect, contain and recover from it?
These are operational realities already faced by the vast majority of organisations using AI.
Confidence does not automatically equate to readiness. Organisations that recognise the difference between confidence and real control will be the ones that scale AI safely and sustainably.
source: The Business Times https://www.businesstimes.com.sg/opinion-features/most-ai-confident-organisations-are-often-most-exposed