Agentic AI is reshaping enterprise security in APAC, making identity, privilege and access controls critical as AI agents gain the ability to act autonomously across business systems.
AI adoption across APAC is entering a new phase. For the past two years, much of the enterprise conversation has focused on chatbots, copilots and productivity tools. The main risks were familiar: inaccurate outputs, data leakage, prompt injection and employees entering sensitive information into public AI tools.
Agentic AI changes that equation. Unlike traditional AI tools that generate answers, AI agents can plan tasks, call tools, access data, interact with APIs, trigger workflows, write code and make decisions with varying degrees of autonomy. In practical terms, they are moving from assistance to action. Once an AI agent can act on behalf of a user or business function, it starts to behave less like ordinary software and more like a non-human privileged user.

Jack Wang, Senior Director – ASEAN & East Asia, Tenable
The security question has changed
Many organisations still approach AI security as primarily a model problem. They ask whether the AI tool is accurate, whether it might leak data, or whether it can be manipulated through prompts. These are important questions, but they are incomplete once the AI system is connected to enterprise tools and workflows.
The more important issue is authority. Can the agent access customer data, query internal systems, connect to cloud environments or code repositories, or trigger actions without human review? If so, the organisation is no longer just managing an AI tool. It is delegating access and decision-making power to a machine. A chatbot that gives a wrong answer may create confusion. An AI agent that takes the wrong action can create business impact.
This is why AI agents should be viewed as part of the broader identity problem. Organisations already struggle to manage non-human identities such as service accounts, bots, API keys and automation scripts. These identities often have persistent access, multiply quickly and retain permissions long after their original purpose has changed.
AI agents add a more complex layer because they may rely on service accounts, plugins, APIs, cloud permissions, third-party packages and enterprise integrations. They may also operate across several systems to complete a task, often without constant human oversight. If their access is too broad, poorly monitored or difficult to revoke, they can become a powerful source of exposure. A compromised or misconfigured agent may give attackers a new route into sensitive data, internal systems or business workflows.
Tenable’s 2026 Cloud and AI Security Risk Report highlights this emerging challenge. It found that 18% of organisations have overprivileged AI identities expanding their cloud attack surface, while 86% use third-party code packages with critical vulnerabilities.
The point is clear: AI risk is increasingly connected to cloud, identity, code, permissions and business process risk.
Why this matters now
Agentic AI is moving from experimentation into real enterprise use cases. Across APAC, organisations are exploring agents for customer service, software development, IT operations, finance, HR, cybersecurity and internal productivity. The business case has already been made; faster processes, less manual work and greater efficiency.
The challenge is that adoption can move faster than control. Many companies are still focused on AI policies, acceptable-use guidelines and governance frameworks. These are useful, but they do not answer the operational question security teams need to resolve: what authority has this agent been given inside our environment?
Regulators are starting to recognise the issue. Singapore’s Cyber Security Agency recently released guidance on securing agentic AI systems, noting that these systems introduce additional risks because they can plan and take actions through access to tools and data. That is an important signal for the region as AI agents become more autonomous and more deeply connected to enterprise systems.
The concern is practical. An overprivileged AI agent could access more data than required. A compromised plugin could become a route into enterprise systems. A prompt injection attack could become more damaging if the agent can retrieve sensitive data or trigger workflows. A poorly scoped service account could allow an agent to act outside its intended role.
From AI policy to AI control
The answer is not to slow AI adoption. Businesses will continue to deploy AI agents because the productivity gains are too significant to ignore. What has to change is what AI security means in practice. It is no longer only a question of whether the model behaves as expected, but of what the agent is permitted to do once it is inside the business, and that is a question of privileged access and enterprise exposure, managed with the same discipline organisations already apply to both.
Security teams need to know which AI agents exist, who owns them, what systems they can access, what actions they can perform and which identities or permissions they rely on. They also need clear controls around least privilege, access reviews, monitoring, permission scoping and rapid revocation.
This requires a shift from policy-led AI governance to control-led AI governance. A policy may state what employees should or should not do with AI, but controls determine what AI can actually do inside the business. That distinction will become more important as agents are embedded into critical workflows.
Before scaling agentic AI, organisations should be able to answer a simple set of questions: what can the agent access, what can it change, what actions can it trigger, who owns it, how is its access reviewed, how quickly can that access be revoked, and what happens if it is misused or compromised?
Agentic AI can bring real benefits to APAC organisations. But those benefits will only be sustainable if businesses understand and control the authority they are giving to machines. If an AI agent can act on behalf of the business, it needs to be secured like a privileged insider, not treated like ordinary software.
