Governance is lagging behind AI deployment across organizations in APAC. What happens when thousands of AI agents get out of control?
According to a BCG report, close to three-quarters of organizations across the region are already working with autonomous agents, yet only about a third of the people around those systems genuinely understand how they behave.
Saviynt’s research found that 71% of security leaders say AI tools now have access to core business systems, yet only 16% believe they govern that access effectively.
That gap underscores the entire problem of emerging insider risk, according to Tim Wedande, Field Chief Technology Officer, Asia Pacific and Japan, Saviynt. We find out more in this interview…

Tim Wedande, Field Chief Technology Officer, Asia Pacific and Japan, Saviynt
AI agents can act, transact, and access systems autonomously. When software starts behaving more like an employee, how does that change the nature of insider risk?
Wedande: For decades, insider risk meant watching people, and the whole discipline was built on that assumption. You hired carefully, you trained your staff, and you reviewed who could access what on a regular schedule, all on the understanding that the threat had a face and a desk. That assumption has come undone because there is now a new kind of worker on the network – one that logs in, makes decisions, and acts without a person anywhere in the loop.
What changes is the way reach and speed compound. An agent takes on the permissions of whoever built it, often including access that the person never realised they held, so the over-provisioning that used to sit harmlessly dormant becomes live exposure the moment an agent inherits it. Where a human insider works one system at a time, an agent can read customer records, rewrite configurations, and move across connected systems faster than anyone can trace the path back to an owner.
It does not even take a bad actor. Attackers are already hijacking well-behaved agents through prompt injection and turning them hostile from within. And underneath all of it sits the question of volume, because machine identities now outnumber human ones by roughly 82 to 1 in the average enterprise. Identity is simply multiplying faster than anyone can govern it.
The industry is focused on model safety, be it guardrails, prompts, and outputs. Are we securing what AI says, while ignoring what it can do?
Wedande: The industry has invested heavily in controlling what a model says, which is important work, but it only addresses half the risk surface. The more critical question is not just whether an AI behaves safely in conversation, but what systems it can reach, what data it can access, and what actions it can execute.
The numbers make the gap impossible to ignore. Organizations have invested heavily in the conversation layer while leaving the action layer comparatively open, and an agent draws no distinction between what it can access and what it should.
The newer agent-to-agent protocols raise the stakes further, because once machines start talking directly to other machines, the moment of human judgement that used to sit in between simply disappears, and those connections carry real authority to act. Model safety and identity security are complementary, not interchangeable. Identity is the layer that eventually determines who or what is acting, with what permission, and for how long.
If AI agents are effectively “non-human identities” with credentials and privileges, who is accountable for their actions and how should access be controlled or revoked in practice?
Wedande: Accountability is the first question any organization needs to resolve, because no piece of software can be held responsible in any meaningful sense. An AI agent cannot carry liability, so accountability must sit with the individuals and business functions that deploy and govern it.
In practice, this requires treating agents as formal extensions of the workforce. Each agent should have a clearly defined business owner and a technical sponsor, both of whom are accountable for its actions end-to-end, including any downstream agents it triggers and any external systems it interacts with. Today, however, this accountability model remains underdeveloped, with governance frameworks lagging behind the pace of deployment.
On access control, traditional patterns built around long-lived service accounts are insufficient. Persistent, high-privilege credentials that remain active by default do not scale safely in environments where agents operate autonomously across systems.
The emerging approach is toward short-lived, tightly scoped identities that are issued only when required, continuously evaluated during use, and automatically revoked when tasks are completed or risk thresholds are breached. Standing privileges should no longer be assumed.
As AI investment surges across APAC, is governance structurally lagging behind deployment? Where are organizations most exposed today?
Wedande: Yes, and the gap is widening because organizations are scaling access faster than they are scaling control. The core issue is that most enterprises are still governing AI as a software rollout problem rather than an identity problem.
AI agents, copilots, and automation layers are being deployed quickly into core business workflows, but the identity model underneath them – who and what is acting, what they are allowed to do, and how that access is monitored – has not evolved at the same pace.
The biggest exposure today sits in three areas:
- Over-privileged AI and machine identities
AI agents are often built on service accounts or inherited user permissions that are far broader than required. This creates excessive standing access into core systems like CRM, and cloud environments, significantly increasing blast radius if compromised or misused. - Lack of visibility and ownership over machine identities
Most enterprises do not have a complete, continuously updated inventory of AI agents, APIs, and service accounts nor clear ownership for each. Without this, access cannot be effectively governed, reviewed, or risk-assessed at scale. - Absence of lifecycle and least-privilege controls for AI access
Traditional IAM controls such as just-in-time access are not consistently applied to AI-driven identities. As a result, permissions granted during rapid AI deployment often persist long after the original use case, creating accumulated and unmanaged risk.
If this layer is not addressed now, what is the most likely failure scenario and what should boards and regulators be paying attention to next?
Wedande: The first is a high-impact cyber event, where an AI agent with excessive privileges is manipulated or misconfigured and causes rapid, irreversible damage – such as data deletion, unauthorised transactions, or disruption of core systems. This creates immediate operational downtime, regulatory scrutiny, and direct financial loss.
The second is a slower, harder-to-detect erosion of business performance. AI agents execute continuous, “valid-looking” actions that individually pass controls but collectively may result in compliance breaches and governance issues.
In both cases, the business impact spans three dimensions: revenue (from disrupted operations), reputation (loss of trust following incidents or audit failures), and cyber risk (expanded attack surface through over-privileged non-human identities).
