Fri, 9 Oct 2026

PodChats for FutureCISO: Accountability without control – a CISO’s sovereignty dilemma

Asia's 2027 security landscape is defined by a reckoning with "governance over hype". Gartner projects regional security spending will hit US$39.5 billion in 2026, while noting only 7% of APeJ enterprises feel highly prepared in GRC skills.

The analyst further forecasts that 40% of enterprises will demote AI agents by 2027 as governance gaps surface only in production; CISOs face a dual mandate: deploy agents at machine speed while proving verifiable, auditable control to fragmented regulators.

But even as Asia-Pacific security spending climbs, the real challenge isn't budgetary. Enterprises are deploying AI agents far faster than they can govern them.

For CISOs in Asia, this is a moment of dilemma. They must deploy AI agents at machine speed while simultaneously providing fragmented regulators with verifiable, auditable proof of control. In reality, most cannot even answer how many AI agents are running within their organisations, or what data those agents can access.

Invisible agents, ungovernable privileges

Marshall Erwin, chief information security officer at Fastly, offers a blunt assessment of Asia's current state of play. When asked whether enterprises possess a comprehensive real-time inventory of all AI agent identities and their permitted data access, his answer is unequivocal: "The short answer is that, and the simple answer is no."

Erwin notes that the situation is evolving rapidly, but "enterprises overall are lacking the visibility that they need today into the sort of agents that are running in their production and in their enterprises. Many companies today are still in the process of playing catch up."

This is not an isolated technical problem. It points to a deeper structural deficiency: AI agents are becoming highly privileged "non-human actors" within enterprises, and most organisations don't even know they exist.

Erwin's concerns centre primarily on agents as potential vectors for compromise.

Marshall Erwin

"I am more focused on making sure that we have good visibility into those agents because I am worried about them being a potential vector for compromise. Less worried at the moment about those agents sort of going rogue on their own." Marshall Erwin

This concern is well founded. Agents derive their power precisely from their ability to access substantial amounts of data, surface it to internal users, and often take automatic actions without humans in the loop. This tension between capability and risk is the core contradiction CISOs must confront.

Clients are asking, regulators are watching

Contrary to widespread expectations, Erwin suggests that enterprises in Asia are not yet feeling immense pressure from the regulatory environment. "Organisations are not yet feeling a huge burden from that regulatory environment. I expect we will soon."

What is genuinely pressuring enterprises is their customers. Erwin reveals that Fastly's largest clients are already asking: "How are you controlling AI? What AI solutions are touching my data? What security solutions do you have in place? And how can you guarantee me that this is an increasing risk for my data when I give it to you?"

Related:  Indonesian government launches INA Digital to integrate existing mobile apps

The answers to these questions will be reflected in contracts and may trigger audit requirements that let major customers verify AI security controls. This is "client-driven governance," and it may move faster and be less predictable than regulation itself.

Meanwhile, the regulatory environment is itself evolving rapidly. Data localisation requirements across Asia-Pacific are becoming more complex and fragmented. Erwin concedes that tracking all localisation requirements and jurisdictional obligations is "extremely hard," but proposes three core questions that, if answered well, typically satisfy localisation requirements: "Where the data resides, where is it routed... And the third question is like, where is it controlled? Who can touch that data, and from what locations?"

Gartner's forecast corroborates the risk of fragmented governance from another angle. Its analyst, Shiva Varma, notes that enterprises often treat AI agent governance as a binary choice between "fully locked down or fully trusted," which is precisely where failure originates.

"Agents operate at different levels of autonomy across different trust boundaries. When the same controls are applied indiscriminately, organisations encounter two common failure modes: over-restriction of simple agents and under-restriction of more autonomous ones." Marshall Erwin

Zero trust is necessary, but not sufficient

People have discussed zero trust architecture for more than a decade. When asked whether it is sufficiently mature to act as a control plane for AI, Erwin's response is measured: "Zero trust is necessary but not sufficient in the context of AI and the control plane."

He explains: "The basic idea is that you can't just trust your outer perimeter and it is going to work and then have your inner parts of your network that are high trust. You need to think about layers of defence and not have any single high-trust point of failure that doesn't have security controls in place."

The difficulty, however, is that agents will be highly privileged. Erwin observes that when an agent on your infrastructure is compromised, "the basic challenge, though, and why we're going to need to adapt our approach is, agents, are going to be highly privileged."

This assessment aligns with analysis published by the Cloud Security Alliance in 2026. The analysis notes that Five Eyes guidance on agentic AI "requires extending these programmes to a new class of autonomous, non-human actors that operate at speeds and scales traditional security monitoring and governance processes were not designed for."

Sovereignty is more than where data sits

Digital sovereignty is more complex than data localisation. Erwin frames it as a shift from "where does your data reside" to "who actually can touch that data, who can export that data, who can manipulate that data." He adds: "That, from a security risk perspective, is as important as thinking about where it actually sits."

For any company operating across jurisdictions in this space, the challenge is substantial: satisfying sovereignty requirements in a way that gives regulators confidence they have the operational control they need locally.

Related:  PodChats for FutureCISO: How to recession-proof cybersecurity strategies

A further Gartner forecast adds urgency: by 2027, 35% of nations will be locked into region-specific AI platforms. This suggests the AI ecosystem is fragmenting faster, and Asian enterprises are on the front lines.

The CISO's 2027 action list

Faced with these challenges, Erwin offers two core recommendations for CISOs approaching 2027.

First, "you need to get a solution in place that manages the privileges for agents that allows you to understand where they're running, to understand what access they have, and to shut them down quickly if you find that they're doing something malicious."

Second, "think about the risk of AI-driven attacks at speed and try to find solutions that allow your own internal teams to move much more quickly to respond to those." Erwin discloses that Fastly is considering how to "power our SOC to detect and automatically respond much more quickly at AI speed to AI attacks, and how can we remediate vulnerabilities at AI speed that AI finds?"

A Deloitte survey from early 2026 reveals the scale of the problem: among 3,235 senior leaders across 24 countries, only 21% of companies report having mature governance models for autonomous agents. Data privacy and security rank as the most cited AI risk at 73%, followed by legal, intellectual property and regulatory compliance at 50%.

Awareness is clear; mechanisms are lacking. As Erwin suggests, what enterprises need is the capability to answer three fundamental questions: where agents are, what they can do, and how to stop them quickly when they misbehave.

For CISOs in Asia, the defining challenge of 2027 isn't technology itself, but keeping governance pace with AI. The widening gap between machine-speed deployment and human-speed governance is the real risk.

Click the PodChats player to hear Erwin explain what accountability without control means and how to navigate this sovereignty dilemma.

  1. Do enterprises in Asia have a comprehensive, real-time inventory of all AI agent identities and their permitted data access?
  2. From a CISO perspective, have current threat models been updated to treat agents as active actors, not just tools?
  3. How are enterprises demonstrating to regulators across multiple jurisdictions that their AI guardrails and data flows are governed with verifiable, auditable evidence, moving beyond policy to operational proof?
  4. Have enterprises mapped every sector-specific data localisation requirement (beyond the general PDP laws) that applies to business in Asia? (global context)
  5. Are current public and private cloud architectures designed for the necessary data residency and portability?
  6. In your view, is zero-trust architecture sufficiently mature to act as the control plane for AI, effectively preventing a compromised agent or partner from causing a cascading regional incident by eliminating lateral movement?
  7. How are enterprises operationalising digital sovereignty to ensure that reliance on global cloud providers does not compromise technical and operational control, especially in the event of a geopolitical or regulatory shift?

Related Stories

MORE STORIES