Enterprise software was built around the assumption that when a person initiated an action, they would be held accountable for it. Employees had identities, roles and permissions. Applications knew which user was making a request and audit logs could connect an action to an individual.
Agentic artificial intelligence (AI) changes that, however, as autonomous agents can interpret an objective, select tools, access enterprise data and execute actions with limited human intervention.
For enterprises across Southeast Asia, this creates a governance challenge that policy alone cannot solve. Technology leaders need to know what an agent is authorised to do, which data and systems it can access, which actions it can execute and when control must return to a person.
Where can Southeast Asia still compete as AI funding concentrates globally?
The region’s AI ambitions make this an infrastructure question
Across the region, governments are developing frameworks intended to support responsible AI while enabling innovation. The ASEAN Guide on AI Governance and Ethics, for example, aims to promote greater alignment between national approaches and highlights issues including accountability, privacy, security and human involvement.
While at a country level, the likes of Singapore’s Infocomm Media Development Authority (IMDA) have introduced a Model AI Governance Framework for Agentic AI, which recommends organisations assess and bound risks upfront, establish meaningful human accountability and implement technical controls throughout the agent lifecycle. An update in May added guidance on multi-agent systems, third-party agents and automation bias.
For infrastructure and data leaders, a policy stating that an agent should only access certain information is of limited value if the underlying architecture gives it unrestricted access to databases, cloud resources or Application Programming Interfaces (APIs).
Delegation is not inheritance
Traditional identity and access management was designed primarily around human users. An employee might have access to customer records, billing systems and administrative tools because those permissions are appropriate to their role.
An agent performing a specific task should not automatically inherit all of them.
A customer service agent retrieving an order history may need to read customer and transaction information. It may have no legitimate reason to modify customer details, issue refunds or access unrelated financial records.
This matters because autonomous systems operate at machine speed. A permission that appears manageable when assigned to one employee can become far more consequential when given to an agent capable of repeating an action across thousands of transactions.
An AI agent therefore needs its own identity and defined security boundary.
Data access is the real governance challenge
Organisations need granular controls over which agents can access particular datasets, under which conditions and for how long.
An HR agent may need employee information without access to payroll records. A customer service agent may need order information without unrestricted access to the wider customer database. A finance agent may need transaction data without being able to modify financial records.
These are hugely important architectural questions, especially for organisations operating in ASEAN, where enterprise data and infrastructure may span multiple countries, cloud providers, data centres and Software-as-a-Service (SaaS) platforms. An agent operating across Singapore, Malaysia, Indonesia or Thailand may encounter different systems and jurisdictions.
Visibility therefore matters alongside permission. Organisations need to know where data resides, how an agent reaches it and whether those boundaries can be consistently enforced.
Multi-agent systems raise the stakes
The challenge becomes harder when agents work together.
A customer service agent might identify a billing problem, call a finance agent to determine whether a credit should be issued and then trigger another agent to update an order.
The employee initiated the process, but several autonomous systems performed the subsequent actions.
An audit trail that records only the employee’s identity leaves important questions unanswered. Which agent acted? What data did it access? Which tools did it use? What authority did it exercise? Which downstream systems did it affect?
Singapore’s updated guidance recognises the risks associated with multi-agent systems and third-party agents, and underscores the need for provenance to be built into the environment rather than reconstructed after an incident.
Design the boundary before deployment
As organisations consider agentic AI guardrails, it may be more beneficial to frame the issue not how much human intervention can be removed but where an agent’s authority should end.
Low-risk and reversible actions can often be automated. More consequential actions may require approval, while certain activities may need to remain outside an agent’s authority altogether.
Before deployment, organisations need to establish a distinct identity for each agent, define what it can access and determine what it can actually do. They also need clear escalation points and sufficient evidence to reconstruct significant actions afterwards.
That means governance must be reflected in identity systems, access controls, APIs, data platforms, application architecture, logging and monitoring. It cannot sit solely in an AI policy document.
Governance needs to travel with the agent
AI agent does not care about silos, and so, its authority must remain in check and visible wherever it operates.
For ASEAN enterprises modernising across jurisdictions, that is becoming an architectural fault line.
That means rethinking governance before the first agent reaches production. Identity, data access, application connectivity, policy enforcement and real-time visibility cannot be separate conversations. They have to work together as part of the architecture. Because once an AI agent becomes embedded in a critical workflow, governing it retrospectively becomes considerably harder.
The article titled “The rise of Agentic AI: Why Southeast Asia needs a data access rethink” was authored by Philip Miller, AI Strategist, Progress Software
About the author
Philip Miller is Director of Product Marketing and AI Strategist at Progress Software, where he helps shape the strategy, positioning and adoption of AI- and data-driven solutions. With more than 20 years of experience in the technology industry, he specialises in enterprise AI, data platforms, AI governance and digital transformation. Philip is a frequent contributor to Progress blogs, webinars and community programs, translating complex AI concepts into practical guidance that helps organisations build trusted, scalable AI initiatives.
At Progress, Philip leads product marketing efforts for Progress Data Platform and helps organisations move from AI experimentation to real-world business outcomes. His work focuses on AI strategy, data platforms, semantic technologies, retrieval-augmented generation (RAG), AI governance and enterprise-scale adoption. He collaborates across product, engineering, sales and partner teams to develop messaging, thought leadership and go-to-market strategies that help customers unlock value from their data while building AI systems that are accurate, trusted and governed.

