Agents are Asia-Pacific’s AI security reality check

By Kris Day, Senior VP and GM, Asia Pacific & Japan at SentinelOne

Source: SentinelOne. Kris Day.
Source: SentinelOne. Day.
As Asia-Pacific accelerates its AI ambitions, the biggest AI risk may no longer be what AI can do, but how vulnerable AI itself has become. While we celebrate AI's growing impact across banking, healthcare, government, logistics, and customer service, it's also the right moment to ask a more important question: are we doing enough to secure the AI we're increasingly relying on?

For years, the conversation has centred on using AI to strengthen cybersecurity. Today, AI has become something else entirely: an attack surface in its own right. Across the region, organisations are building what is effectively a new digital workforce made up of AI assistants, autonomous agents, and intelligent applications. 

These systems log into enterprise platforms, move data across environments, call APIs, analyse information, and execute tasks on behalf of human employees. They behave like users, make decisions in real time, and often operate around the clock. Yet many organisations still treat them as invisible infrastructure rather than digital identities that require governance, oversight, and protection. 

That creates a growing security challenge. Anything that can act like a user can also be exploited like one. If an AI agent can access sensitive customer information, approve transactions, or reconfigure business systems, compromising that agent – or the prompts, models, or workflows that guide it – can have consequences comparable to compromising a privileged employee account. 

In Asia-Pacific, where organisations are embracing AI to overcome talent shortages and scale operations, the risks associated with this emerging AI workforce are only becoming more pronounced.

For defenders, it is no longer enough to focus on how AI can improve threat detection, automate investigations, or reduce alert fatigue. We also need to understand who – or increasingly, what – is operating inside our environments. 

- What identities do AI agents use? 

- What permissions were they granted? 

- How are their actions monitored and controlled? 

In an AI-driven world, identity becomes the control plane not just for people, but for non-human actors as well. At SentinelOne, we're seeing this shift play out across Asia-Pacific. Security leaders are asking two questions simultaneously: how can AI help automate and accelerate security operations, and how do we secure the AI systems being deployed across the business? 

They want autonomous detection and response, but they also want confidence that the models, agents, and data pipelines powering those capabilities operate within clear, enforceable guardrails. In short, they want to increase AI's autonomy without sacrificing accountability. 

That balance between autonomy and control will define the next chapter of cybersecurity. The organisations that lead will be those that treat AI agents as first-class participants in their security programmes – authenticated, governed, continuously monitored, and subject to the same level of oversight as any privileged user. 

They will embrace AI to accelerate defence while ensuring every autonomous action remains transparent, auditable, and, when necessary, reversible.

Celebrating AI's potential is easy. Protecting it is the harder, and ultimately more important, challenge. As AI adoption continues to accelerate across Asia-Pacific, securing this new digital workforce – its identities, permissions, and behaviour – will be essential to maintaining trust in the systems our economies increasingly depend on. That is the kind of AI progress truly worth appreciating.

Comments

Popular posts from this blog

NVIDIA brings secure agent workspaces and confidential computing to AI factories

Fortinet enhances FortiRecon to align with CTEM framework

Agnes AI enters global top 10 AI lab rankings