Shadow AI outpaces Singapore governance controls
Employee adoption is exposing data and operational risks as firms struggle to track AI use and enforce internal policies.
Singapore companies are struggling to govern artificial intelligence as employee adoption moves faster than internal controls, exposing businesses to data leakage, unreliable outputs and weak oversight.
Modern applications now combine internal code with open-source packages, cloud services, AI-generated code, models and third-party tools. Sunny Rao, senior vice-president for Asia-Pacific at JFrog, said each component risks another route into business systems.
“The complexity crisis that you asked about comes from this gap between software speed and governance speed,” Rao said.
JFrog research found that 60% of Singapore DevSecOps stakeholders regard governance and policy enforcement as their largest time burden, whilst 41% said reviewing AI-generated code drains resources.
Reliance on external providers is adding to the pressure. Christina Low, head of observability for Asia-Pacific, Japan and China at Splunk, said 63% of technology leaders attributed downtime to third-party issues.
Shadow AI presents a more immediate concern because companies may not know which tools employees are using or whether sensitive information is being uploaded. Eighteen per cent of Singapore organisations have policies against unauthorised AI tools but no mechanism to detect violations, according to Rao.
“An AI policy does not equal AI control,” he said, warning that outright bans could push usage further underground.
Low said employees may expose source code, customer information or commercial data through unapproved tools. AI-generated errors can also spread across workflows before reaching customers or critical systems.
“Shadow AI is no longer a future issue. It’s actually a current reality,” she said.
Companies should link asset visibility with policy enforcement across software, AI models and third-party services. Although 95% track application ownership, 54% need at least a week to produce compliance evidence for one application.
Low added that monitoring must extend across infrastructure, applications, security and AI workloads to detect failures faster and reduce disruption.
Commentary
Where does value creation really happen?
Managing the cost of diverging standards: Why Singapore matters
Singapore’s AI ambition has an intelligence problem
Singapore is deploying AI at speed – and security risks are catching up
Precious metal boom is a stress test for Singapore’s gold ambitions
Singapore’s global dispute fault lines
‘Tokenmaxxing’ – The wrong AI race to run in Singapore
To outsmart modern fraud, we must first know the enemy