Where Asia’s tech ecosystem comes together.
- 00Days
- 00Hrs
- 00Mins
- 00Secs
Every organisation now claims to practise responsible AI. Far fewer can prove it. As enterprises across the region push AI deeper into regulated workflows — finance, telco, healthcare, critical infrastructure — the gap between a governance document sitting in a shared drive and a system that is actually accountable, auditable, and secure is where the real risk lives. At ATxEnterprise 2026, five sessions on AI governance and enterprise cybersecurity converged on the same conclusion: responsible AI in 2027 will be judged not by the policies an organisation writes, but by the evidence it can produce. Responsible AI, on this reading, is less a value statement and more an operating discipline — one built on AI accountability, auditable controls, and cyber resilience working together.
Why AI governance keeps stalling at the policy stage
The starting problem, raised repeatedly across the sessions, is structural. In "From Governance to Ground Truth," MSD's Jason Tamara Widjaja and Dr. Aravind Sesagiri Raamkumar described AI governance built around three pillars — legal and regulatory requirements, internal compliance policy, and technical implementation — with a fourth pillar, upskilling employees as AI stewards, added to make governance a shared organisational capability rather than a compliance department's job alone. They pointed to the emergence of ISO/IEC 42001, the first certifiable international standard for AI management systems, as a practical baseline. Published in December 2023, ISO 42001 addresses the need for a structured approach to managing AI's complexities, ethics, and risks, and aligns with global regulatory efforts such as the EU AI Act. For organisations trying to translate abstract responsible AI principles into something a regulator or a board can actually inspect, that alignment matters — it turns "we have an AI policy" into a management system that can be audited against a recognised external standard. That shift, from principle to audited system, is the entire distance between responsible AI as intent and responsible AI as practice.
The panel in "Responsible AI in Practice: Governance, Accountability, and Trust in a Fragmented Global Landscape" pushed this further into the question of AI accountability itself: who is responsible when an AI system makes a decision. Speakers from SMU's Centre for Digital Law, Access Partnership, the AI Asia Pacific Institute and the ASEAN Secretariat agreed that legacy infrastructure and unclear ownership — not a lack of principles — are what stall AI governance in practice. Their recurring recommendation was blunt: name a specific individual accountable for each AI system's ethical and safe use, because AI accountability that isn't assigned to a person doesn't function as accountability at all. Without that ownership layer, even a well-written AI governance policy has no mechanism for enforcing AI accountability when something goes wrong.
This is also where AI governance in Asia has its own texture. The ASEAN Guide on AI Governance and Ethics, referenced directly in that session, sets out seven guiding principles for the region — transparency and explainability, fairness and equity, security and safety, robustness and reliability, human-centricity, privacy and data governance, and accountability and integrity. Crucially, the guide does not override any individual member state's own laws, and instead aims to encourage interoperability of AI frameworks across ASEAN jurisdictions. For enterprises operating across Singapore, Indonesia, the Philippines and beyond, that voluntary, non-binding design is both an opportunity and a gap: it gives organisations room to build AI governance that fits local regulatory maturity, but it also means AI compliance can't rely on a single regional rulebook. Organisations have to build their own bridge from principle to proof — the same challenge every session in this article circled back to.
From policy to proof: what evidence-based AI governance actually looks like
The clearest operational answer came from Globe's five-pillar compliance model, presented in "From Policy to Proof: Connecting Controls and Evidence in Modern Telco Environments." Thomas Smart, VP of Globe's Compliance Centre for Enablement, described a model that starts by interpreting regulatory obligations, filters and contextualises them collaboratively across policy and engineering teams, maps them to specific technical environments, and finally implements controls — preventive, detective, or corrective — designed to be auditable and automated wherever possible. The result: compliance evidence traceable in a single line from a high-level policy down to a specific technical control, instead of policy teams and engineers working from disconnected documents.
This structure is what separates AI governance as paperwork from AI governance as infrastructure, and it's the clearest working example of AI accountability actually functioning end to end rather than living in a policy document. Anchoring compliance to a single source of truth lets an organisation automate evidence collection, cut manual audits, and generate assessment reports on demand — the operational proof that underpins genuine digital trust with regulators, customers, and partners alike. It also solves a problem several sessions raised independently: automation tools alone don't fix AI governance. DevSecOps pipelines and compliance dashboards improve efficiency, but if they aren't built on a policy-to-control lineage, they just produce faster versions of the same disconnected, manual-validation problem. Responsible AI, in other words, needs an operating model change, not just better tooling bolted onto an old one — and that operating model change is itself an AI accountability mechanism, because it makes every control traceable to a named owner and a specific obligation.
Cybersecurity as the proving ground for AI accountability
If AI governance is the framework, enterprise cybersecurity is where it gets tested under real pressure — and the picture across the region is sobering. In "Cybersecurity in a Hyperconnected World: Why Everything Is Now a Target," CISOs from Agoda, Huawei International, PLTPRO Data Centre and (ISC)² described a threat surface expanding across IoT, OT, cloud and now AI systems themselves, where attackers routinely exploit governance blind spots rather than technical vulnerabilities alone. That matches what the wider data shows: the Asia-Pacific region faces the largest cybersecurity workforce gap of any region globally, with well over a million additional security professionals needed to close it. That shortage is precisely why enterprise cybersecurity in Singapore and across the region increasingly depends on structured frameworks rather than headcount alone — segmentation, zero-trust architecture, and compensating controls for legacy systems that can't be patched fast enough to keep up with new threats. Frameworks, not headcount, are what make cyber resilience achievable at the pace the workforce gap demands.
The panel also flagged something specific to this AI moment: shadow IT and ungoverned AI tool usage are now a live cybersecurity risk, not a hypothetical one. Their recommended fixes — consolidating access through gateways, deploying monitoring agents, enforcing usage policies through platform-level hooks — are really AI governance controls wearing a cybersecurity hat, and they build cyber resilience into AI deployment from day one rather than bolting it on after an incident. Quantum computing was flagged as the next horizon risk, particularly for finance, with post-quantum cryptography and shortened certificate lifetimes cited as early moves organisations are already making to future-proof their security posture.
"From Prevention to Resilience: Cybersecurity as a Business Imperative" reframed the whole conversation around cyber resilience rather than prevention alone. CISOs from RMA Group, Agoda, HELM AG and DTN Advisory drew a sharp distinction: prevention is controls — firewalls, policies, patching — while cyber resilience is the organisation's capacity to keep operating through an incident nobody fully anticipated. That distinction matters regionally too — a joint 2025 report on cyber resilience in the Indo-Pacific found that while countries in the region have made progress defending against and responding to cyberattacks, meaningful disparities remain in long-term protection strategies, underlining that cyber resilience is still an uneven, actively developing capability rather than a solved problem, even among well-resourced markets. The panel's own prescription echoed that finding: cyber resilience has to be treated as a business-wide goal, tested through tabletop exercises that pull in legal, marketing and operations teams alongside IT, not just a cybersecurity department's KPI. Boards, they argued, need financial justification for resilience investment the same way they'd expect a return-on-investment case for anything else — which puts cyber resilience squarely on the same accountability track as AI governance: it only counts if leadership can see and act on the evidence.
Building the accountability loop, end to end
Put these five sessions together and a single operating model for responsible AI in 2027 emerges. AI governance sets the principles. AI accountability assigns them to specific, named owners. Evidence-based controls — the Globe model — turn those principles into something auditable in real time. Enterprise cybersecurity, tested for cyber resilience rather than just prevention, protects the systems those controls depend on. And AI compliance, whether measured against ISO 42001 or the ASEAN Guide, becomes the shared language that lets regulators, boards and customers trust the whole loop — proof that AI accountability was designed in, not added after the fact.
None of this happens by accident, and none of it happens by policy alone. Responsible AI happens through structured investment in AI governance, AI accountability, cyber resilience and digital trust as a single connected discipline — which is exactly the throughline ATxEnterprise's 2026 sessions on governance and cybersecurity were built around, and exactly what ATxEnterprise 2027 will dig into further.
If this resonated, the full picture from ATxEnterprise 2026 is worth exploring further. Download the ATxEnterprise 2026 Post-Show Report for the complete data behind these sessions, read more session summaries from the show's AI governance and cybersecurity tracks, and pre-register for ATxEnterprise 2027 to be in the room for where this conversation goes next.
This article draws on official AI-generated session summaries from ATxEnterprise 2026, Asia Tech x Singapore's enterprise tech conference held at Singapore EXPO.
