The AI agent trap: How Singapore firms can avoid tech’s costliest pattern

The deployment of AI agents should be a risk management decision at the executive level

Summarise
    • The technology industry has “perfected” a costly playbook over 30 years.
    • The technology industry has “perfected” a costly playbook over 30 years. PHOTO: REUTERS
    Published Thu, Feb 26, 2026 · 08:46 AM

    AT DAVOS in January, Singapore unveiled new governance rules for autonomous artificial intelligence (AI) agents – systems capable of independent reasoning, decision-making and executing multistep tasks with limited human oversight.

    The Model AI Governance Framework for Agentic AI explicitly addresses what regulators call “unauthorised and erroneous actions” when AI agents access sensitive information such as customer databases and financial records.

    The timing was not coincidental. Across Asia-Pacific, enterprise deployment of coordinated multi-agent AI systems has surged 327 per cent in just four months, according to new research from Databricks covering more than 20,000 customers worldwide.

    In Singapore’s highly regulated business environment, these autonomous systems now execute trades, process compliance filings, and access confidential data – at computational speed, with minimal human checkpoints.

    What makes this moment critical is the pattern it is repeating.

    History repeating, but faster

    The technology industry has “perfected” a costly playbook over 30 years.

    Network security in the 1990s and 2000s relied on software firewalls. Attackers compromised them. Companies added more software monitoring tools. Breaches continued for roughly 15 years until hardware-based security became standard.

    Cloud security in the 2010s repeated the pattern. Software controls failed to prevent breaches. Companies added policy frameworks and monitoring systems. Roughly eight years later, hardware-based isolation finally provided the protection that should have existed from day one.

    Years of breaches, compliance violations, and expensive retrofitting.

    Today, the same pattern is unfolding in months instead of years, now with autonomous systems that have direct access to production data.

    Anthropicʼs November 2024 decision to open-source Model Context Protocols made it dramatically easier to connect AI agents directly to enterprise systems. By mid-2025, major technology firms including Amazon Web Services and Google formed an emergency consortium to address architectural weaknesses.

    It took eight months from widespread deployment to industry crisis response. Singapore’s regulatory response at Davos signals that governments recognise the urgency.

    Why AI agents are a boardroom issue

    Business leaders watching competitors deploy AI agents face a dilemma: move fast and accept security risk, or move cautiously and fall behind.

    The business case for AI agents is compelling. A PwC survey found that 66 per cent of companies adopting AI agents report measurable productivity gains.

    But AI agents represent a fundamental change in operational control. Traditional systems require explicit human authorisation for sensitive operations. AI agents eliminate those checkpoints, interpreting instructions and executing operations across interconnected systems without approval at each step.

    The efficiency comes from removing human friction. The risk comes from removing human oversight.

    When security vulnerabilities affect AI agents with production access, compromised systems execute unauthorised operations: data exfiltration, fraudulent transactions, regulatory violations. The business impact shifts from reputational embarrassment to material financial and legal exposure.

    Most companies deploying AI agents treat this as an IT implementation project. It should be a risk management decision at the executive level.

    The security investment dilemma

    Companies deploying AI agents face three security approaches.

    The first focuses on prevention: input filtering and instruction validation systems from Nvidia, Anthropic and OpenAI. The limitation is fundamental: these are pattern-matching systems similar to spam filters, effective against known attacks but vulnerable to novel techniques.

    The second emphasises containment: permission frameworks and behaviour monitoring protocols. However, AI agents need broad permissions to deliver efficiency gains. Tightly scoped permissions eliminate business value, while behaviour monitoring detects breaches after they occur.

    Missing from most procurement discussions is the third layer: detection systems that operate at the infrastructure level, monitoring where data physically resides rather than where applications run. This represents hardware-level oversight that functions even when software controls are compromised.

    The pattern from previous technology cycles suggests this third layer will eventually become mandatory. The question is then: will business leaders invest proactively or wait for the first major breach to force the decision?

    What this means for Singapore companies

    For companies operating in Singapore’s highly regulated environment, the stakes are particularly acute.

    Regulatory exposure is immediate. The Personal Data Protection Act carries penalties up to S$1 million or 10 per cent of annual turnover for data protection failures.

    Financial institutions face additional scrutiny under Monetary Authority of Singapore technology risk management guidelines. If an AI agent mishandles customer data or executes unauthorised transactions, companies face statutory penalties regardless of whether the breach was “autonomous”.

    Operational risk compounds quickly. AI agents operate rapidly across interconnected systems. By the time anomaly detection flags suspicious behaviour, autonomous operations may have been executed across multiple systems.

    Competitive positioning will separate quickly. Early adopters who prioritise AI agent security from the start will scale autonomous operations confidently. Those that deploy first and address security later will face a choice: continue with known vulnerabilities or roll back deployments while competitors advance.

    Singapore’s position as a regional technology hub creates opportunity. Jurisdictions that demonstrate mature security frameworks will attract investment.

    The agenda for boards

    The first challenge to address is visibility. Many agents are deployed at business unit level without enterprise security oversight. IT security teams often lack visibility into which agents have production system access or what operations they are authorised to execute.

    Visibility alone is insufficient. When an agent begins exfiltrating customer records at computational speed, organisations need clear authority structures for shutting down business-critical agents without disrupting operations.

    AI agents are autonomous systems with privileged access to customer data, financial systems, and operational infrastructure. This is strategic risk that belongs in board-level discussions alongside cybersecurity and regulatory compliance.

    The window for proactive investment is closing. Agents are already in production. The security architecture is still being built. What took 10 to 15 years in previous technology cycles is happening in months.

    The technology industry has already documented this lesson in breach reports and retrofit costs. We have the opportunity to read it before repeating the same mistakes.

    The writer is chief executive officer and co-founder of X-PHY