Fri, 18 Sep 2026

Prioritise on the best governance, not the best model

Halfway through 2026, the reality for CISOs across Asia Pacific is that the deployment of AI agents has raced well ahead of the ability to govern them. Salesforce’s Agentic Enterprise Index shows that the average number of active AI agents in enterprises jumped from five a year ago to thirteen, nearly a threefold increase, while the time taken to create a new agent fell from four days to 1.9 days.

Gartner’s forecast is more aggressive still: by the end of 2026, 40% of enterprise applications will embed task-specific AI agents, up from less than 5% in 2025.

Deployment is not the problem. The problem is that most organisations do not know what they have deployed.

IBM’s 2026 Cost of a Data Breachresearch reveals an uncomfortable figure: security incidents involving “shadow AI” doubled year on year to 43%, while roughly two-thirds of organisations still lack governance processes capable of detecting it.

Standard Chartered’s Lavy Stokhamer, global head of Cybersecurity and AntiCrime Tech, reduces this to a more fundamental point. As AI agents become part of the workforce, he argues, “banks need the same level of visibility and accountability that they apply to people, applications and privileged accounts”.

A real-time inventory provides “a clear view of what each agent is allowed to do, what data it can access and who is accountable for its actions”.

His formulation is blunt: “You cannot govern, secure or manage risk at scale if you do not know which digital actors exist and what authority they have.”

This is where the triple challenge of trust, resilience and economics begins.

First: trust rests on visibility, not assurances

The “organisational chart for a digital workforce” that Stokhamer describes is not a metaphor. As AI agents begin to take on decisions and actions across business processes, a real-time, comprehensive inventory of agent identities and their permitted data access become an absolute precondition for governance. “In many ways, it is becoming the organisational chart for a digital workforce,” he says.

The data is colder than intuition suggests. CyberArk estimates that, in enterprise environments, non-human identities — service accounts, API keys, machine certificates, automation tokens — already outnumber human identities by a factor of 45.

More critically, governance coverage runs in precisely the opposite direction: most organisations have detailed governance processes for human identities, and almost no visibility into non-human ones.

When AI agents are added to this already lopsided equation, the problem escalates from a visibility gap to an accountability vacuum. Research cited by Security Boulevard finds that credential-based attacks account for more than 80% of all breaches, with a highly consistent pattern — a leaked API key or service-account credential, over-privileged, providing lateral movement that stolen human credentials typically cannot.

Stokhamer’s formulation points in the same direction. The shift, he says, “is from viewing AI as technology to viewing AI as an operational participant”. Threat models are evolving to consider “not only attacks against AI, but also the decisions, actions and influence AI agents may have across business processes”.

The focus is increasingly on “autonomy, authority and business impact”. As agents become more capable, organisations must understand “not only how an attack could occur, but also how far a compromised or poorly governed agent could influence operations, customers or critical services”.

In Asia Pacific, this anxiety has a particular context. Splunk’s 2026 CISO report found that 82.9% of CISOs in Australia and New Zealand are worried about personal liability for cyber incidents, while 88.6% cite “hallucination-driven false negatives or false positives” as a primary concern in adopting agentic AI. The absence of trust begins with the absence of visibility.

Second: resilience is not “restoring service”, it is “restoring trust”

Stokhamer is equally direct on the regulatory dimension. “Regulatory expectations are moving beyond governance frameworks and policies towards demonstrable outcomes,” he says. Banks are investing in “continuous assurance models that provide visibility into AI activity, control effectiveness and data flows across the lifecycle”. The objective is to show that controls “are not only designed appropriately but are operating effectively every day”.

His analogy is telling: “Much like financial reporting evolved from periodic attestations to continuous oversight, AI governance is moving towards evidence-based assurance supported by independent testing, monitoring and auditability.”

Related:  Prisma AIRS to secure AI Innovations amidst cybersecurity skills gap

That judgement maps directly onto the core finding of the Financial Stability Board’s June 2026 framework on agentic AI governance. The FSB report acknowledges a reality that had previously been avoided: as agent use scales, real-time human monitoring of individual decisions becomes impractical.

An agent pursuing a goal may take hundreds of intermediate steps, any one of which could go wrong. In some cases, monitoring those steps itself requires another AI agent to assist.

On this basis, the FSB proposes six supervisory models, pointing towards “human on the commanding seat” for agentic AI — that is, high-level oversight of the autonomy boundaries and guardrails for human agents, rather than item-by-item approval. Its deeper recommendation is that, as agent numbers grow, “AI in the loop” monitoring will become necessary, with AI systems alerting humans when performance metrics are breached or agent behaviour deviates from parameters.

Stokhamer’s practical path aligns closely with this framework. The “assume breach” philosophy he describes is not a slogan but a discipline — “built like elite sports training, on repetition, precision and instinct under pressure”. Standard Chartered measures MTTD and MTTR in minutes rather than hours, running continuous purple-team simulations and automated red-blue exercises.

Lavy Stokhamer

But the real leap in resilience sits at the architectural layer. Stokhamer identifies a sequencing problem that many organisations overlook. “Leading banks are increasingly recognising that the ability to scale AI is directly linked to the strength of their core foundations,” he says.

“Before organisations can deploy thousands of AI agents, they need trusted data, resilient infrastructure, strong identity controls and operational resilience.” Lavy Stokhamer

This means cloud architectures must be designed around “resilience, portability and sovereignty from the outset”. Data residency remains important, “but the broader objective is ensuring that critical services remain secure, recoverable and under operational control during cyber incidents, provider disruptions or regulatory interventions”.

One recommendation in the FSB framework is striking in its specificity: for agents executing financial transactions, particularly those involving customer funds, higher thresholds should apply — human approval or dual authorisation above a set value, restricted access to payment systems, and an audit trail for every agent transaction. This is not excessive caution. When an agent can act at machine speed, damage also occurs at machine speed.

Third: the economics of AI — from tracking cost to proving value

Stokhamer’s third observation may be the most underrated. “Deploying AI is easy; operating it efficiently at enterprise scale is much harder,” he says. “The equivalent of FinOps for AI — understanding cost, consumption, value and optimisation — may ultimately become as important as the technology itself.”

Source: State of FinOps 2026 Report, FinOps Foundation

The 2026 data provides dense footnotes to that statement. The FinOps Foundation’s State of FinOps 2026 reports that “AI cost management is the number one skill teams need to build”, with 98% of respondents saying they are managing AI spend — up from just 31% two years earlier.

But the distance between “managing spend” and “understanding value” is widening. Forrester’s observations from FinOps X 2026 reveal a structural tension: as AI vendors shift from seat-based pricing to consumption-based (token-driven) models, enterprise buyers struggle to connect fine-grained usage metrics to meaningful business outcomes, with the result that the “AI value gap” continues to widen — cost is visible, but impact is not.

Gartner’s forecast offers a timeline for this tension: by the end of 2027, more than 40% of agentic AI projects will be shelved, owing to rising prices, unclear business value and insufficient risk controls.

FinOps research shows that 73% of organisations experienced AI budget overruns in 2026, driven by “instrumentation lag” — teams adopting new model APIs or agent frameworks faster than finance can establish cost-attribution strategies — and the “multiplier effect” of agentic workflows, where a single user request can trigger a chain of model calls, tool calls and retries, each generating an independent billing event.

The direction Stokhamer proposes under “FinOps for AI” is essentially this: the economics of AI must evolve from cost control into value optimisation. Forrester reaches the same conclusion: “Organisations that tie token consumption to revenue growth, productivity gains and customer outcomes will move from cost control to genuine AI value optimisation.”

Related:  Deepfake: real and present danger to financial institutions

Digital sovereignty as a resilience strategy

Stokhamer also reframes digital sovereignty in a way that will resonate with Asian CISOs operating across multiple jurisdictions. “Digital sovereignty is increasingly being viewed as a resilience strategy rather than a compliance requirement,” he says.

The objective “is not to reduce the use of global technology providers, but to ensure the bank retains control over critical data, security operations and recovery capabilities under a range of geopolitical, regulatory and cyber scenarios”. Lavy Stokhamer

Organisations that achieve this balance, he argues, “will be able to innovate with confidence, knowing they can continue operating securely and maintain control even during periods of significant disruption”.

For banks in Singapore, Hong Kong, India and Australia navigating divergent data-localisation regimes, this reframing matters: sovereignty is not an obstacle to innovation but the precondition for it.

Zero trust as the guardrail, governance as the authority

On zero trust, Stokhamer is careful to avoid overclaiming. “Zero trust is becoming an essential foundation for the AI era because it replaces implicit trust with continuous verification and least-privilege access,” he says. However, “AI introduces new considerations around delegated authority, autonomy and decision-making”.

His distinction is precise: “Zero trust provides the guardrails, but governance determines how much authority an agent should have within those guardrails.”

The future control plane will combine both disciplines, “ensuring agents operate within clearly defined business, risk and ethical boundaries while limiting the potential impact of failures or compromise”.

For CISOs building target-state architectures for 2027, this is the sentence to take to the board: zero trust is necessary but not sufficient; governance is what sets the limits.

Recalibrating priorities for Asia’s CISOs

For CISOs in Asia Pacific, the overlap of these three challenges produces a concrete action agenda.

First, bring non-human identity governance into the core architecture, not the appendix of a security assessment. Security Boulevard predicts that, by 2027, “non-human identity governance” will appear explicitly in SOC 2 Type 2 audit procedures.

For Asian financial institutions operating across multiple jurisdictions, this means building agent identity inventories, permission constraints, automated rotation and revocation propagation at the same level as for human identities. The “organisational chart for a digital workforce” that Stokhamer describes needs to exist before the auditors arrive, not after.

Second, turn “human on the commanding seat” from a principle into an auditable operating model. The FSB framework offers a starting point: distinguishing which actions agents may execute independently, which require human approval, and which must suspend the agent. 360factors’ observations on agentic AI deployment in banks in 2026 show a convergent pattern emerging in compliance and financial crime — “agent handles the first pass, human approves, system records every step”. This pattern has direct applicability in fraud detection and compliance monitoring across Asian banks.

Third, establish agent-level cost attribution as a governance tool, not a finance tool. As Forrester observes the “AI value gap” widening, the CISO’s distinctive position is this: they understand risk, controls and technical architecture simultaneously.

Bringing the mapping of token consumption to business outcomes into the security governance framework means the CISO can supply the judgement on “whether this agent is worth keeping” before the project is shelved. That is more valuable than post-hoc audit.

Stokhamer’s conclusion in 2027 is sober. “By 2027, the leading organisations will not necessarily be those with the most AI agents,” he says. “They will be those that can deploy and govern them safely, recover from disruption quickly, and demonstrate clear business value from every AI dollar spent.”

He goes further, identifying the three foundational challenges that will separate winners from the rest: “First, they will strengthen the core through high-quality data, resilient infrastructure and robust security. Second, they will establish governance that allows AI to scale safely. Third, they will master the economics of AI.”

For Asia’s CISOs, this means the role itself is evolving once again. The CISO’s mission is shifting from “defender” to “architect of enterprise trust”. Under that definition, the governance of AI agents is not a burden on the security function but the central arena in which the CISO proves strategic value.

Related Stories

MORE STORIES