Shadow AI outpaces Singapore governance controls
Employee adoption is exposing data and operational risks as firms struggle to track AI use and enforce internal policies.
Singapore companies are struggling to govern artificial intelligence as employee adoption moves faster than internal controls, exposing businesses to data leakage, unreliable outputs and weak oversight.
Modern applications now combine internal code with open-source packages, cloud services, AI-generated code, models and third-party tools. Sunny Rao, senior vice-president for Asia-Pacific at JFrog, said each component risks another route into business systems.
“The complexity crisis that you asked about comes from this gap between software speed and governance speed,” Rao said.
JFrog research found that 60% of Singapore DevSecOps stakeholders regard governance and policy enforcement as their largest time burden, whilst 41% said reviewing AI-generated code drains resources.
Reliance on external providers is adding to the pressure. Christine Low, head of observability for Asia-Pacific, Japan and China at Splunk, said 63% of technology leaders attributed downtime to third-party issues.
Shadow AI presents a more immediate concern because companies may not know which tools employees are using or whether sensitive information is being uploaded. Eighteen per cent of Singapore organisations have policies against unauthorised AI tools but no mechanism to detect violations, according to Rao.
“An AI policy does not equal AI control,” he said, warning that outright bans could push usage further underground.
Low said employees may expose source code, customer information or commercial data through unapproved tools. AI-generated errors can also spread across workflows before reaching customers or critical systems.
“Shadow AI is no longer a future issue. It’s actually a current reality,” she said.
Companies should link asset visibility with policy enforcement across software, AI models and third-party services. Although 95% track application ownership, 54% need at least a week to produce compliance evidence for one application.
Low added that monitoring must extend across infrastructure, applications, security and AI workloads to detect failures faster and reduce disruption.
Commentary
The future of cross-border commerce isn’t faster shipping – it’s better discovery
Delaying AI investment could become construction's most expensive decision
Can Johor-Singapore SEZ build ASEAN’s shared AI manufacturing ecosystem?
Machine-speed AI mistakes are Singapore’s next governance test
Banks need to rethink identity governance for AI agents
As Singapore broadens retail investing, who moves before the news?
Can controlled sandboxes prepare Singapore organisations for production AI?
What the latest sanctions regimes mean for Singapore businesses
Singapore’s tourism economy depends on security infrastructure most never see
Where does value creation really happen?