Live16h agoMastercard Makes It Easier for Merchants to Sell With AI Shopping Agents
← Back to stories

Singapore's AI Lead Is Real — But the Security Gap Is Widening

Source: iTnews Asia

Singapore has moved past AI experimentation into full-scale deployment, with 21 percent of organisations at advanced maturity — nearly double the global average. But a new report warns that this speed has outpaced security controls, leaving enterprises exposed to data leaks, AI-driven phishing, and overprivileged cloud identities.

Singapore's AI Lead Is Real — But the Security Gap Is Widening
SGAI Daily

Singapore has stopped experimenting with artificial intelligence. It is now running on it. Research from Notion puts 21 percent of Singaporean organisations at advanced AI maturity — the point where AI operates as embedded workflow, autonomous teammate, or core operating machinery. The global benchmark sits at 12 percent. Nearly 90 percent of local decision-makers say government policy directly shapes their AI strategy, and almost half of workers report AI now saves them more than an hour a day.

But speed has become the entire strategy. Companies are wiring powerful systems into their operations faster than the security controls around those systems can be built. ESET found that four out of five Singaporean organisations have experienced at least one AI-related security threat in the past year. Only about half monitor access to AI tools and their outputs, and 40 percent report employee misuse of generative tools that leaked sensitive data onto public platforms.

The deeper threat lives in the infrastructure stack itself. Tenable's research found that roughly one in five organisations have overprivileged AI identities — cloud AI services inheriting roles with far more access than they need. Layered on top of forgotten credentials, unpatched third-party code, and exposed cloud workloads, AI starts functioning as an access layer that reads broadly, acts fast, and follows instructions at machine speed. AI-generated phishing has hit 46 percent of local companies, climbing to 62 percent in financial services.

Meanwhile, 79 percent of Singaporean organisations remain in the lower AI maturity bands, where use is confined to personal productivity and ad hoc task support. The leap from assistants to autonomous teams demands governance models that define what AI can reach, what it can disclose, and what it can do without a human signing off. Gartner expects that by 2029, more than half of successful attacks on autonomous AI agents will exploit access-control weaknesses and prompt injection.

Why it matters for Singapore: The city-state's AI ambition is real and well-funded, but the security debt is accumulating just as fast. With AI security spending projected to approach US$4.8 billion by 2027, Singapore's enterprises that treat security as an afterthought to deployment speed will find themselves on the wrong side of the next major breach. The governance frameworks are there — what's missing is the discipline to enforce them before the gap becomes irreversible.