Home Frontier Tech AI & ML AI agents: Innovate with caution

AI agents: Innovate with caution

- Advertisement -

Governments and enterprises across the region are investing heavily in AI to drive efficiency, productivity, and competitiveness. Singapore’s National AI Strategy 2.0, Malaysia’s National AI Office, and both Indonesia and the Philippines’ AI roadmaps have all launched within the last couple of years, and illustrate the region’s appetite to unleash AI innovation.

The rise of AI agents, specifically, is likely to bring transformative change in the coming years. Research published earlier this year in Netskope’s “Cloud and Threat Report: Shadow AI and Agentic AI 2025” reported that 5.5% of organisations worldwide already have users running AI agents on their infrastructure. But innovation carries risks that organisations need to factor in. As AI usage, projects, and deployments accelerate and grow in sophistication, so do the risks of potential sensitive data exposure if tools and agents are not appropriately secured.

Generative AI security: A relevant use case 

Employees are usually the catalyst for technological change within organisations. They often experiment with new technologies and tools, forcing IT and security teams to adjust.

- Advertisement -

Generative AI is a good illustration of this. When ChatGPT was released, everyone wanted to play with it and understand its potential, but many were doing so at work, often on personal accounts and in the context of work projects. This led to early instances of data leaks, including developers uploading proprietary source code into ChatGPT for error checking. Back then, the majority of generative AI usage was “shadow AI,” meaning that most security teams had no visibility into it, and thus no ability to apply security controls.

Fast forward to today, and organisations have now deployed company-approved generative AI applications en masse with layers of data-security guardrails, such as data loss prevention or real-time user coaching, to prevent the leak of sensitive data. In its recently published report dedicated to Asia, Netskope Threat Labs found that just over one in three (35%) organisations in the continent detected usage of personal generative AI accounts among their workforce in September of this year, a dramatic drop from 79% less than a year ago. This drop coincided with a sharp increase in the deployment of “corporate generative AI” applications, from 17% to 55% over the same period, indicating that Asian organisations are adopting generative AI and reducing many of the initial risks.

But now history is threatening to repeat itself, potentially bringing newly heightened security risks as employees start to experiment with platforms to design and deploy custom AI agents and models within their organisation.

Agentic AI security: Another problem entirely

Custom agentic AI deployments are quickly creating a new shadow AI problem, and this one is more complex, as the security risks related to these platforms, models, and agents are more varied and potentially more difficult to address than those created by generative AI.

When building AI agents, individuals are likely to use open-source components, which often come from open-source platforms and carry supply-chain risks. Hugging Face is one of the largest hubs for individuals to share open-source AI models and tools, and ReversingLabs reported earlier this year that it had discovered a malicious machine-learning model hosted on the platform. Open-source resources are valuable, but they present a risk of compromising the AI supply chain if those experimenting with AI cannot detect whether they are using infected components or tools.

Another issue lies in the tools used to design and deploy AI models, which sometimes have little to no embedded security. Ollama is one of the most popular LLM interfaces, but it doesn’t offer default authentication or protection capabilities, and requires the addition of security layers before it can be used securely.

Finally, in-house AI presents a major risk for sensitive data if security teams are not involved in configuration, especially concerning permission levels. AI models and agents require data to train and perform their tasks, but unless restricted to only the data they need, the models could access information that should not be used. This can become a larger issue as AI agents running on local infrastructure often rely on external AI models. For example, Netskope Threat Labs’ report found that more than half of organisations in Asia (57%) are connecting to api.openai.com, suggesting that they run AI agents relying on OpenAI’s model.

It is easy to see how unsupervised usage and deployments of sophisticated AI could have larger implications for data security, and organisations need to start anticipating this.

Nipping shadow AI in the bud

Ensuring organisations can safely enjoy the benefits of AI platforms and agents requires closing the gap between adoption and the application of security controls as quickly as possible. The key is to eliminate shadow AI by ensuring security teams have visibility over all AI-related projects within the organisation from the outset, and to build relevant security guardrails where appropriate. Visibility must not depend on human reporting, as this is something that data-security platforms can and should detect.

Guardrails should include a blend of smart security capabilities such as adaptive access control, data loss prevention, or zero-trust network access. They should also include tools that provide visibility into the range of unsanctioned AI applications that will continue to emerge, including tools that can automatically toggle user permissions based on whether they are using a sanctioned or unsanctioned instance of an AI application.

It took some time to witness significant progress among Asian organisations in addressing generative AI security. This first phase of AI adoption will hopefully serve as a guide for organisations, delivering best practices for this new wave of AI.

- Advertisement -