Home Technology Security Singapore’s innovation faces a new risk: Shadow AI

Singapore’s innovation faces a new risk: Shadow AI

Singapore has rapidly laid the groundwork for trusted AI and innovation by pioneering frameworks such as IMDA’s Model AI Governance Framework and MAS’s Veritas Toolkit. The stage is set for AI-driven adoption across the public and private sectors, and momentum is growing. However, a new challenge is emerging around AI, one that is harder to see but already having a material impact on organisations.

Across industries and businesses, from development teams to operations groups, employees are increasingly taking the initiative to use generative AI tools and external APIs on their own. Often, it is to solve a problem quickly or move a task forward. While well intentioned, this unapproved usage typically sits outside formal IT or security oversight and creates blind spots. This practice is commonly referred to as shadow AI, and it is becoming a significant risk for enterprises.

The hidden cost of shadow AI

Shadow AI isn’t like what we see in the movies, where AI silently goes rogue. It can sound as harmless as a department lead integrating Slack with ChatGPT to help teams collaborate better, or a developer using a publicly available OpenAI API to test his AI model’s responsiveness and performance.

Yes, these well-intentioned moves bring short-term productivity gains. But when AI tools are integrated into workflows without proper guardrails, they open the door to untracked data movement, insecure dependencies, and compliance risks that no one owns.

Sensitive data, whether customer records, financial projections, or proprietary code, may be routed through external systems without visibility or consent. Even the most well-meaning use can violate data handling rules under sector-specific governance, or privacy laws such as the Personal Data Protection Act. For example, developers may introduce plug-ins or scripts that call external AI endpoints directly to hasten development, testing, and production, or unwittingly upload proprietary code to public LLMs for troubleshooting.

These actions introduce unvetted code paths, model outputs, and third-party dependencies. Beyond being a development hygiene issue, approaches like these expose organisations to financial and compliance risks, and create numerous opportunities for supply chain attacks, data leaks, or logic manipulation.

What makes shadow AI especially difficult to manage is fragmentation across security ecosystems. JFrog’s State of Supply Chain 2025 report found that 73% of organisations rely on seven or more security tools, with nearly half using 10 or more, creating inconsistent visibility across teams. Many security, IT, and data teams also operate using different playbooks and responsibilities. When ownership is unclear, accountability slips and traceability breaks down.

Visibility is the new frontier of AI governance

If enterprises want to continue scaling AI safely, visibility must come first. Research cited in the State of Supply Chain 2025 report found that 40% of organisations lack full visibility into the provenance of the software running in production, meaning they often cannot trace which models, datasets, or AI services touch their systems. In addition, 49% have no reliable way to control ML model usage, and 58% have no policy governing how developers use open source AI components.

To enhance visibility and security, organisations must start treating AI usage the same way they treat code: Track what’s used, scan for vulnerabilities, and monitor it in real time.

CTOs and CISOs should be asking these questions:

  1. What models are running across the organisation?
  2. Where is sensitive data flowing?
  3. Are there unapproved AI tools embedded in our day-to-day workflows?

This is where concepts like the AI Bill of Materials (AI-BOM) come in handy. Just as we map software components to ensure secure delivery, organisations must maintain a clear inventory of AI models, APIs, and datasets across the stack. AI-BOMs give leaders a way to prove control, readiness, and compliance, especially as Singapore’s AI regulations mature.

Visibility doesn’t just help with policy. Having that transparency and full understanding of workflows, from development to deployment, helps organisations catch risk before it compounds. It acts as the foundation for trust at scale, something many enterprises must prioritise today as the shadow AI risk grows.

How can we build an AI supply chain secure against shadow AI?

Responsible AI governance to rein in shadow AI doesn’t mean locking everything down. In fact, organisations that move quickly with AI while maintaining security often do so by adopting a “trust but verify” model.

This approach involves giving teams access to approved, secure AI tools, while monitoring unapproved or unmanaged usage at the margins. This includes scanning code for embedded model calls, tracking data flows to and from AI services, and validating model provenance. By integrating scanning, signature validation, and evidence collection across both code and AI artefacts, organisations can reduce reliance on periodic checks and move towards more continuous forms of assurance.

When oversight spans both software and AI components, organisations don’t have to choose between speed and compliance.

Innovation and visibility in execution

Singapore has made progress in AI governance, but the spotlight is increasingly shifting to security in execution. Progress is no longer defined by publishing frameworks alone. It depends on applying controls consistently, starting with visibility across every model, dataset, and AI interaction that touches an organisation.

For CIOs, CISOs, and technology leaders, this means making AI observability a standard part of the governance stack. Organisations that address shadow AI directly will be better positioned to meet regulatory expectations and maintain trust.

Singapore has demonstrated leadership in governance. The next phase is execution. Visibility, rather than ambition alone, will determine how organisations build and deploy AI responsibly.

- Advertisement -