IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Singapore firms face AI access gaps, Delinea finds

Singapore firms face AI access gaps, Delinea finds

Wed, 30th Sep 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Delinea has published research showing that almost all surveyed organisations in Singapore experienced AI tools or agents accessing sensitive data beyond their intended scope. The findings point to a gap between formal AI rules and day-to-day enforcement.

The report found that 98.8% of IT and security leaders in Singapore said such an incident had occurred in the past year, the second-highest rate among the markets covered.

The research was based on two global surveys of 2,254 IT and security leaders and 2,250 non-IT employees at organisations with 500 or more staff that use AI. Respondents came from Singapore, the UK, the US, Germany, Australia, the UAE, France and India.

While formal governance is now widespread, the study suggests many businesses struggle to apply those rules when employees and AI systems interact with sensitive information. In Singapore, 99.6% of organisations surveyed said they had a formal policy governing what data AI tools and agents can access.

Yet only 46.8% said they check that access against policy in real time, leaving a gap of more than 50 percentage points between having a policy and enforcing it at the point of use.

Detection delays

The survey also indicated that companies are often slow to spot when an AI tool or agent exceeds its intended remit. Only 14% of respondents in Singapore said they can detect a scope violation as it happens, below the global average of 19%.

Once a violation occurs, detection can take time. The findings show that 72% of organisations in Singapore take a full day or longer to identify a breach of scope, the highest level recorded across the countries surveyed.

The data also raised questions about accountability inside organisations. Although 98.8% of respondents in Singapore said named-individual approval is required for at least some sensitive AI use, only 38% said they can always trace a sensitive AI access event back to a named human authoriser.

That suggests many companies have approval structures on paper but weaker audit trails in practice. For regulated sectors and companies handling confidential customer or internal data, the inability to tie access decisions to a specific person may complicate internal oversight and incident response.

Employee behaviour

Delinea's study found that workers often bypass formal controls. Among employees in Singapore surveyed, 84% said they had bypassed the required approval process for using AI at work at some point, while 51% said they did so always or regularly.

Pressure from managers, deadlines or workplace expectations may be part of that pattern. The report found that 76% of employees in Singapore said they had felt pressured to use AI on sensitive or confidential data even when they were unsure it was permitted.

The findings suggest governance issues are not confined to technical controls. They also reflect the way AI use is becoming embedded in everyday work, sometimes ahead of the internal processes designed to manage risk.

Across six major environments globally, 47% of organisations lacked enforcement at the moment of action in at least two of them. The weakest areas were CI/CD pipelines, Kubernetes and on-premises file systems, while cloud data stores and SaaS applications also showed gaps.

These results suggest companies may have inconsistent controls depending on where AI systems operate. That can create blind spots when developers or employees use AI agents across multiple systems.

Cynthia Lee, VP of APAC at Delinea, said the issue was not the absence of formal rules. "Singaporean organisations have done the hard part already; nearly every one of them has a formal AI policy," Lee said.

She said implementation remained the main challenge. "What's missing is enforcing it in the moment. Without that, security teams won't have full visibility and control over what their agents are actually doing," Lee said.

The report arrives as governments and companies face closer scrutiny over how AI systems handle access to data, particularly in sensitive or regulated settings. The Singapore findings point to a broad operational problem: policy adoption has spread quickly, but enforcement, monitoring and traceability have not kept pace.

The gap was most visible in environments where developers hand more work to coding agents, and the report found that even where controls exist, they are often not applied continuously at the moment an action is taken.

Among the study's most striking figures is the contrast between the near-universal adoption of AI policies and how often employees still work around them: 84% of employees in Singapore said they had bypassed the required approval process to use AI at work.