As digital transformation accelerates across Southeast Asia, enterprise tech leaders face a critical turning point: the rapid shift from passive AI tools to autonomous agents executing complex, end-to-end workflows across multi-market regulatory environments. While these agents offer unprecedented operational scale, this explosion of non-human workforce accounts is outstripping traditional cybersecurity frameworks. Industry research highlights a severe governance deficit across the region: while 82% of organisations already deploy AI agents and 98% plan to expand their use over the coming year, only 44% have established security policies to govern them, a gap that has already led 80% of enterprises to experience unintended agent actions and credential exposure.
Transitioning to address this widening security perimeter, cybersecurity leader SailPoint is pushing the enterprise landscape toward an identity-centric governance architecture that treats autonomous agents not as application features, but as a new class of enterprise identity. Aligning with regional policy shifts, such as Singapore’s IMDA Model AI Governance Framework for Agentic AI and guidance highlighted at the National Day Rally, the company is doubling down on Zero Standing Privilege and dynamic least-privilege access models. By replacing static quarterly reviews with continuous discovery and real-time lifecycle management, SailPoint is enabling organisations to replace unmanaged risk with governed autonomy.
Jasie Fon from Ping Identity explains why structural friction is now a critical board mandate for agentic AI in Southeast Asia
At the core of this strategy is the realisation that identity governance is not a bottleneck to innovation, but the foundational infrastructure required to scale agentic AI safely across complex enterprise ecosystems. By embedding explicit human ownership, context-aware permissions, and continuous behavioural auditing into the tech stack, enterprises can contain risk while maximising operational autonomy. We sit down with Eric Kong, GVP, ASEAN, SailPoint, to discuss managing the expansion of non-human identities, enforcing dynamic least-privilege controls, and why an identity-centric framework is essential for the future of safe AI adoption in Southeast Asia.
Where do the biggest enterprise opportunities lie for autonomous AI agents to drive productivity, scale operations, and create new value?
The biggest opportunity is not simply using AI agents to automate isolated tasks, but enabling them to complete meaningful, end-to-end work across enterprise processes, from customer service and procurement to IT operations and finance. The real value emerges when agents can coordinate activity across approved systems, act on routine decisions within clear parameters, and escalate exceptions that require human judgement.
For businesses in Southeast Asia, this can be particularly valuable. Organisations often operate across multiple markets, systems and regulatory environments, creating significant manual coordination. Well-designed agents can help teams scale work more consistently, reduce operational friction and allow employees to focus on higher-value decisions, customer engagement and innovation.
However, agents that can access data, make decisions and take action are not simply productivity tools; they are a new class of enterprise identity. The goal should not be maximum autonomy, but governed autonomy. Every agent needs a clearly defined business purpose, a named human owner, formal lifecycle governance, tightly scoped access, clear limits on what it can do, and an auditable record of its activity. That gives organisations the confidence to give agents enough authority to be genuinely useful while ensuring they operate within their intended remit.
This becomes increasingly important as adoption accelerates. SailPoint research found that 82% of organisations are already using AI agents today, and 98% plan to increase their use over the next year. Yet only 44% have policies in place to secure them. Singapore’s National Day Rally reinforced the need to balance the productivity gains from AI agents with appropriate safeguards and human accountability as these systems become more capable.
For CIOs, the priority should be to build governance into the agent strategy from the start. The organisations that do this will be better positioned to scale AI confidently, rather than having to slow down later to address risks that could have been managed from the outset.
How can organisations give AI agents the system access they need without compromising control or creating unnecessary business risk?
The starting point is to stop thinking about access as something that is granted once and left in place. Organisations need to govern agent access throughout its lifecycle.
First, define the agent’s purpose and boundaries before deployment. Be explicit about what the agent is authorised to do, what data and systems it needs to access, which actions it can take autonomously, and which require human approval. This establishes a clear boundary around the agent’s authority before it becomes embedded in business processes.
Second, assign clear ownership and accountability. Every agent should have a named human owner who is responsible for its access, behaviour and lifecycle. That accountability should not disappear when the agent is integrated into a workflow or when the original developer or business user moves on. Organisations should be able to answer a simple question at any point: who is responsible for this agent and the access it holds?
Third, enforce dynamic least-privilege access and make human intervention enforceable. An agent should have only the permissions required for its specific role, rather than broad standing access across systems. Where an action carries higher risk or falls outside the agent’s defined remit, the workflow should require human approval rather than simply relying on a policy that says a person should be involved. The controls need to be built into the system itself.
Finally, continuously review and adjust access as the agent changes. Agents can be updated, connected to new systems, given new responsibilities or behave differently as workflows evolve. Static permissions and periodic reviews can quickly become outdated. Our research found that 80% of organisations have already experienced unintended actions from AI agents, from pulling unapproved files to inadvertently exposing credentials. Organisations need ongoing visibility into what agents exist, what they can access and what they are actually doing, with the ability to adjust or revoke access when the risk or business need changes.
This gives organisations a practical framework for balancing autonomy with control: define the boundaries, assign accountability, limit access, enforce human oversight and continuously reassess. The goal is not to prevent agents from accessing enterprise systems. It is to make that access deliberate, traceable and proportionate to the work the agent is authorised to perform.
What are the key principles of an identity-centric framework for governing autonomous AI agents?
An identity-centric framework begins by recognising that an autonomous AI agent is not simply a feature within an application. It is a non-human identity that can access enterprise systems, use data, trigger workflows and take action. The framework therefore needs to govern the agent throughout its lifecycle: it should be discoverable, have a defined purpose and accountable owner, and be subject to controls over the data, systems and actions it can access.
Each agent needs an identity and an accountable owner. It should not operate as an anonymous application or service account. Second, access needs to be governed throughout the agent’s lifecycle, from creation and permissioning through changes, reviews and eventual decommissioning. Third, privilege should be dynamic. An agent should receive the minimum access required for the task rather than broad permissions indefinitely. And fourth, organisations need continuous visibility into what an agent is doing, what systems it can reach and whether its behaviour remains appropriate.
Singapore is leading to make the policy direction clearer for the wider region. IMDA’s Model AI Governance Framework for Agentic AI recognises that conventional approaches may struggle when agents act on behalf of multiple users, delegate tasks to other agents or require permissions that change according to the task. Its guidance points towards a more adaptive model: assess and bound risks upfront, maintain meaningful human accountability, and put technical controls and processes in place throughout the agent lifecycle.
The next step for enterprises is to translate those principles into identity infrastructure. No agent should operate without known ownership, appropriately scoped access and visibility into its activity, with the ability to audit, constrain or revoke that access as circumstances change. That is what turns AI governance from a policy statement into something an organisation can actually enforce.
How can security teams enforce least privilege access controls for AI agents that execute dynamic, unpredictable workflows?
Least privilege means giving an identity, whether a person, application or AI agent, only the minimum access needed to complete a specific task, and nothing more. This principle remains the right security principle for AI agents because it reduces unnecessary exposure: if an agent is compromised, behaves unexpectedly or is given an inaccurate instruction, it should not have broad, persistent access to sensitive data or critical systems.
This approach is increasingly important because AI agents create a different risk profile from conventional machine identities. In fact, 72% of organisations in our research believe AI agents pose a greater risk than traditional machine identities, reflecting how much more dynamic and autonomous these identities can be.
With a human user, you may be able to anticipate the applications and data they need. An agent can move through a workflow dynamically and make decisions based on changing inputs, so giving it a broad set of standing permissions simply because it might need them creates unnecessary exposure.
Instead, access should be contextual and time-bound. Organisations can evaluate the task being performed, the resources being requested and the associated risk, then provide the minimum privilege required at that particular moment. Once the task is complete, that access should expire or be reassessed.
This is where Zero Standing Privilege becomes important. Rather than giving an agent permanent access to systems or data, it receives access only when it is needed, for as long as it is needed, and under defined conditions. The goal is not to make agents less capable, but to make their capabilities conditional on context. If an agent behaves unexpectedly or is compromised, limiting its access in this way helps contain the potential blast radius.
Why is Identity and Access Governance (IAG) becoming increasingly vital as non-human AI identities proliferate?
Identity and Access Governance is becoming more important because AI agents are expanding the enterprise identity perimeter at a scale that traditional, human-centred access models were not designed to manage.
The challenge is no longer simply knowing who has access to what. It is understanding what has access, why it needs that access, who is accountable for it, and whether that access remains appropriate as an agent’s role changes. An agent can access data, call APIs, interact with enterprise applications and trigger workflows across multiple systems, sometimes acting on behalf of different users or functions. This creates a much more complex chain of identity and accountability than traditional human access models were designed to handle.
As AI agents become embedded across enterprise workflows, strong identity governance becomes the layer that connects access with accountability, helping organisations scale agentic AI without allowing non-human identities to become an unmanaged source of risk.
Why is continuous oversight necessary to scale AI safely compared to traditional, periodic security reviews?
Periodic reviews were designed for environments where change happened relatively slowly. AI agents change that equation. They can be created quickly, connected to new systems, given new capabilities and interact with other agents at a pace that traditional review cycles were never designed to accommodate.
A quarterly review may tell you what an agent was supposed to have access to three months ago. It does not necessarily tell you what it is doing today, how its role has changed, or whether its access is still appropriate. As enterprises deploy agents across more business functions, that gap becomes increasingly difficult to manage through periodic reviews alone.
That is why organisations need to move towards an adaptive identity security approach with just-in-time access, continuous discovery and risk assessment. The objective is not to manually review every action in real time. It is to maintain a clear view of how agents are operating and where risk is changing, so teams can focus their attention on the identities, permissions and behaviours that require intervention. This allows enterprises to scale AI with greater confidence, rather than having to slow adoption every time the operating environment changes.
How can continuous monitoring detect and contain anomalous AI behaviour before it leads to a major security breach?
Monitoring must provide context, not just generate alerts. Security teams need to know which agent is acting, who owns it, what it is expected to do and which systems it can access.
This enables organisations to identify meaningful deviations, such as an agent accessing a sensitive system for the first time, attempting to escalate privileges or acting outside its role.
The visibility gap is significant: only 52% of organisations in our research can fully track and audit AI-agent activity. Without that visibility, it is difficult to distinguish legitimate autonomous behaviour from a security issue.
Detection must also connect to response. When behaviour changes, organisations should be able to reduce or revoke permissions, isolate the agent or trigger a wider security response. Identity provides the context to detect anomalies and take proportionate action.
What is your top advice for Southeast Asian tech leaders looking to balance rapid AI adoption with strong identity governance?
My advice is not to treat governance as a brake on AI adoption. It is infrastructure for scaling AI safely.
The pace of adoption is already clear: 82% of organisations are using AI agents, and 98% expect to expand their use. At the same time, governments and regulators across Southeast Asia are beginning to establish clearer expectations around accountability and risk.
For technology leaders, the practical priority is to build the identity foundation before agents become deeply embedded across the business. Know what agents exist, establish clear ownership, understand what they can access, apply least privilege and put lifecycle controls in place. From there, move towards continuous monitoring and adaptive access as the environment scales.
AI will move faster than traditional governance processes, so the time to put these foundations in place is now. The organisations that get ahead will be those that build identity and accountability into their AI strategy from the start, giving agents room to operate while maintaining the visibility and control needed to scale with confidence over the long term.

