The AI governance gap is becoming increasingly difficult to ignore.
Gartner warned that applying the same governance approach to every AI agent can itself lead to failure.
"Enterprises are treating AI agent governance as binary, either locked down or fully trusted, and that is the root cause of failure," said Shiva Varma, senior director analyst at Gartner. "Agents operate at different autonomy levels and across different trust boundaries."
Varma added that applying the same controls indiscriminately can lead to two extremes: over-restricting simple agents, slowing delivery and increasing shadow development; and under-restricting more autonomous agents, heightening operational, security and compliance risk.
For CIOs in Asia, the challenge is further complicated by varying levels of AI adoption, privacy requirements, data-localisation rules and regulatory expectations across markets.

Melvin Tan, sales engineering manager, Asia at Varonis, discusses the importance of visibility, governance, and sovereignty to scale AI quickly and safely.
Gaining visibility
"Once we have the visibility, then you have the knowledge to put in policies and processes in place to basically safeguard the usage of AI within your environment itself." Melvin Tan
To scale AI securely, CIOs first need to know which AI tools and embedded AI features are operating across their organisations.
For Tan, this visibility lets leaders assess the safety of tools in their environments and identify potential vulnerabilities.
"Once we have the visibility, then you have the knowledge to put in policies and processes in place to basically safeguard the usage of AI within your environment itself," he said.
The challenge becomes more complex as autonomous AI agents begin acting as independent identities. Organisations therefore also need to extend their data security controls to ensure these machine identities operate with least-privilege access.
For Tan, this starts with understanding which datasets AI agents can access and what permissions they have.
"Next, you need to tie down the permissioning: what accounts the agentic AI or AI uses to gain access to these datasets. And secondly, you need to have visibility on what these AI tools are doing to those datasets," Tan said.
Engineering teams should also understand the purpose of each dataset, what information it contains and whether it includes sensitive data.
"If they are, then you need to have an audit and compliance tool to make sure that the AI does not misuse that information when outputting these results to either a front-end application or to the user's perspective itself," he added.
Remediating data exposure
Visibility, however, is only the first part of the equation. Remediating data exposure is also important.
For Tan, organisations need to understand what types of files are stored in their data environments and whether they contain "things like PCI data, PI information, or anything related to an organisation that is sensitive itself."
This information is critical to properly categorising and cataloguing data so that appropriate remediation rules can be applied.
"If there is any sensitive information that is overexposed outside the organisation, there is a tool that can remediate and remove those shares if necessary, or remove that overly-permissioned sensitive information that is in your data store," Tan shared.
Handling fragmented AI and data localisation laws
Compared with other jurisdictions, ASEAN adds another layer of complexity because of its fragmented AI and data-localisation landscape. For organisations operating across multiple markets, this raises the challenge of preventing sensitive information from crossing sovereign boundaries when interacting with global or regional AI models.
For Tan, organisations should begin by understanding the AI services they subscribe to or use, including where those services are hosted and where their underlying infrastructure is located.
They should also establish what data is being sent to these AI tools, where that data is routed and whether the AI service uses company data for model training.
Visibility into data flows is therefore essential to maintaining compliance, particularly when information is being transferred outside the jurisdictions where it is permitted to reside.
"If there are, then you will probably need to see how you can adjust what kind of data you're sending to those platforms, if it's necessary at all." Tan shared.
Protecting data stores
Data security risks do not end with controlling where information goes. Organisations must also defend their enterprise data stores against malicious prompts, jailbreak attempts and actions originating from compromised AI agents.
Tan believes that penetration testing can help organisations identify whether AI tools are vulnerable to malicious attempts, whether initiated by users or by compromised AI agents themselves.
Once those vulnerabilities are identified, Tan said, organisations should deploy guardrails that can operate in real time.
"And if any output from this LLM is malicious, we should block the responses from this LLM back to the application or back to the users themselves." He added.
Graduated sovereignty
These challenges are particularly relevant as a "graduated sovereignty" model emerges across Asia, where organisations must navigate different rules and requirements depending on the market in which they operate.
"Because of differences between countries today, the AI laws are not that defined and detailed at this point. A lot of the countries follow things like the EU AI Act itself because they are more established AI compliance frameworks that we have globally today," said Tan.
He expects countries to gradually formalise their own AI compliance requirements as the market matures. Until then, he urges organisations to take a cautious approach to the AI services they adopt.
"The idea here is to use trusted AI sources or trusted LLMs." Melvin Tan
"The idea here is to use trusted AI sources or trusted LLMs," he emphasised.
Tan cautioned organisations against using untrusted models where possible. Where their use is necessary, vulnerability testing and penetration testing can identify and block malicious attempts.
Metrics for AI governance
As AI deployment brings more threats, organisations also need concrete metrics to show their governance measures are reducing risk.
For Tan, this starts with visibility into the AI services and tools being used across the organisation and ensuring that they are free from vulnerabilities.
Beyond security testing, Tan encourages organisations to align with global compliance frameworks such as the EU AI Act and ISO/IEC 42001, as well as relevant cybersecurity and AI governance requirements.
He also recommends audit and compliance functionality within AI governance platforms so organisations can generate reports on how their enterprise AI systems operate and interact with data.
These measures, he said, are important to ensure AI and agentic AI systems continue to perform the functions they were designed to perform, rather than deviating from their intended tasks.
Safe over quick
Scaling AI safely across a fragmented landscape such as Asia comes with significant challenges, but it is not impossible.
With the right planning, testing and governance, organisations can build the controls needed to scale AI not just quickly, but safely, laying a stronger foundation for AI-equipped enterprises.










