Home Technology Security The risk reality of AI agents in the enterprise

The risk reality of AI agents in the enterprise

AI agents are already inside the enterprise. They are autonomous, non-deterministic, and multiplying. Unlike conventional software that follows defined logic, an AI agent reasons its way to an outcome, which means its behaviour cannot be fully predicted at deployment.

Across Asia-Pacific, IDC forecasts AI and generative AI investments will reach US$175 billion by 2028, with agentic systems increasingly central to that spend. The governance structures needed to contain that risk are not keeping pace.

The identity problem nobody priced in

AI agents operate through machine identities – service accounts, API tokens, and credentials that grant access to systems and data. Gartner identifies machine identity access management (IAM) as one of the least mature areas within most IAM programs, despite being among the fastest-growing in scale and risk exposure.

According to SailPoint’s whitepaper “Who’s Watching The Machines? An Effective Strategy for Managing Machine Identities,” machine identities now outnumber human users, yet a vast majority of organisations still define only human identities as privileged users.

The most common failure mode is over-permissioning. AI agents are frequently granted broader access than their task requires, partly because the people building them optimise for capability, not constraint, and partly because purpose-built tooling for non-human identity governance is still maturing.

According to Omdia’s report, “The Risky Reality of AI Agents in the Enterprise,” 77% of organisations rely on existing IAM platforms for machine identity visibility, but only 2% have deployed a dedicated non-human identity security tool. The gap between exposure and coverage is significant.

The consequences are already materialising. According to the SailPoint report, “AI agents: The new attack surface,” 80% of organisations report their AI agents have performed unintended actions, including accessing or sharing sensitive data. These are not edge-case failures. They are structural gaps in how AI identities are managed.

A region raising the stakes

For enterprises operating in APAC, the regulatory environment is adding urgency.

Singapore launched the world’s first Model AI Governance Framework for Agentic AI, providing structured guidance on bounding agent autonomy and maintaining meaningful human oversight throughout the agent lifecycle. Vietnam’s AI Law took effect in March 2026. Indonesia’s Personal Data Protection Law imposes requirements on the handling and cross-border transfer of personal data.

The direction across the region is unmistakable: governance of AI systems is becoming a legal requirement, not a best practice.

For financial institutions, healthcare providers, and enterprises connected to government supply chains, an ungoverned AI agent is not just a security risk. It is a compliance liability.

Confidence without foundation

What makes the current moment acutely risky is the combination of high confidence and low maturity. While technology leaders report confidence in their ability to manage AI agent risk, organisations lack clear accountability during deployment regarding what those agents access and the decisions they influence. That gap, between perceived and actual governance capability, is precisely where incidents become breaches.

The confidence is understandable. Most current deployments are relatively contained, embedded in enterprise platforms like Salesforce or ServiceNow, operating within broadly understood parameters. The risk profile changes sharply as agentic systems become more autonomous, as multi-agent architectures scale, and as those agents interact with systems outside the organisation’s direct control.

Govern first, scale after

The organisations that will navigate this well are those that have built governance into the foundation rather than layered it on after deployment. That means treating every AI agent as a distinct identity, with defined ownership, scoped access entitlements, and a clear lifecycle. It means applying the same rigour to agent access reviews that mature organisations apply to privileged human accounts. And it means continuous visibility, not point-in-time audits.

The industry is moving towards capabilities designed to discover, govern, and continuously monitor AI agent identities at scale across a range of deployment environments, from packaged SaaS agents to custom-built autonomous systems. The core principle is identity-first governance: no agent operates without a known owner, defined permissions, and the ability to be audited or revoked.

For APAC enterprises, the argument for getting this right early is not purely defensive. As governments across the region tighten AI governance expectations and procurement increasingly screens for governance maturity, organisations that can demonstrate clear accountability for their AI systems will hold a structural advantage.

The productivity case for AI agents is real. So is the risk. What determines which side dominates is not the sophistication of the agent. It is the quality of the governance built around it.

- Advertisement -