

Singapore companies are moving quickly from experimenting with artificial intelligence to letting it perform multi-step tasks with limited human intervention. But a new study by Sumsub and the Singapore Fintech Association suggests many businesses still cannot answer a basic question: what exactly did the AI decide, and can they prove it?
According to the Sumsub APAC State of Digital Trust: AI Governance Benchmark report, 94 per cent of Singapore businesses are using or piloting multi-step AI systems, often described as agentic AI. Unlike simple chatbots or copilots, agentic AI can plan, take actions across systems, trigger workflows, and make decisions with varying degrees of autonomy.
Also Read: Razer and NUS launch Singapore AI lab to rethink how games respond to players
That shift matters because AI is no longer just helping employees draft emails, summarise documents, or analyse data. In some organisations, it is moving into operational workflows, compliance checks, fraud monitoring, risk screening, customer service, and other areas where mistakes can carry financial, legal, or reputational consequences.
Yet only 29 per cent of organisations can produce an audit trail for AI-driven decisions, according to the study. Sumsub calls this gap “Accountability Asymmetry”: companies may own the consequences of AI decisions, but many cannot reconstruct or explain how those decisions were made.
“Everyone is focused on how quickly AI is advancing, but the bigger question is whether governance is keeping pace,” said Holly Fang, President of the Singapore Fintech Association. “As AI moves beyond copilots into autonomous agents handling increasingly critical workflows, the focus now should be on building the traceability, accountability and governance needed to deploy AI at scale.”
A cautious market, not a slow one
The findings complicate the usual narrative that Southeast Asian businesses are racing into AI with little restraint. Singapore, in particular, appears to be moving deliberately.
Only 16 per cent of Singapore businesses significantly increased the scope or autonomy of their AI systems over the past year, the most measured deployment rate among the APAC markets surveyed. The report frames this not as hesitation, but as caution in a market where regulators, banks, fintechs, and enterprise buyers are asking harder questions about risk.
Singapore scored 65.6 on the report’s overall AI governance benchmark, slightly below the APAC average of 67.1. At first glance, that might suggest the country is lagging. But the report argues the opposite: Singapore’s more mature regulatory environment has given companies a clearer yardstick, making them more conservative in judging their own readiness.
Earlier in 2026, Singapore launched governance guidance for AI agent use through its Model AI Governance Framework for Agentic AI. This means local firms are being pushed beyond broad policy statements and towards more technical questions: Who authorised an AI agent? What systems did it access? Which data did it use? What action did it take? Who is accountable if something goes wrong?
In other words, Singapore businesses may be less willing to claim readiness unless they can back it up.
“Prudence, rather than a lack of strategic intent, defines how the enterprises are scaling AI agents,” said Penny Chai, Vice President for APAC at Sumsub. “When financial liabilities are on the line, immature traceability systems create an unacceptable operational risk.”
Governance is becoming an infrastructure problem
The study evaluates businesses across three dimensions: autonomy, responsibility, and traceability. Autonomy measures how far AI systems are already acting independently. Responsibility looks at whether ownership of outcomes is clearly assigned. Traceability examines whether decisions can be reconstructed and explained.
Singapore performs relatively well on responsibility. Seventy per cent of businesses maintain explicit guidelines assigning direct responsibility for AI outcomes, split between a specific person at 40 per cent and a team at 30 per cent. That matches the APAC average.
Also Read: What AI safety researchers actually worry about
The weakness lies in evidence. Having a policy that names an accountable person is not the same as having system logs, identity verification, access records, model activity histories, and decision pathways that can stand up to scrutiny from regulators, customers, or internal risk teams.
This is where agentic AI creates a new problem. Traditional enterprise software usually follows predictable rules. Human users click buttons, systems record actions, and responsibility can often be traced through access controls and approvals. Agentic systems are more fluid. They can chain tasks together, call external tools, act on outputs from other models, and operate across platforms. Without proper monitoring, the decision path can become blurred.
For Singapore’s financial services and fintech sectors, this is not an abstract concern. AI is already being applied to fraud detection, anti-money laundering checks, customer due diligence, credit workflows, and risk monitoring. The report found that Singapore businesses see the greatest real-world impact from AI in data-related tasks at 29 per cent, operations and workflow processing at 21 per cent, and security applications such as fraud detection, AML, and risk monitoring at 15 per cent.
These are precisely the areas where an unexplained decision can become costly.
Southeast Asia’s uneven AI governance map
Across APAC, the study shows how regulation shapes business behaviour. Thailand leads the benchmark at 70.3, followed by the Philippines at 69.6, with the report linking their performance to early alignment with strict digital laws and business requirements.
India scored 68.5, China 68.0, Hong Kong and Australia both 66.7, Indonesia 66.0, and Malaysia 62.4. Malaysia’s lower score reflects a market preparing for an incoming AI Governance Bill, rather than one operating under fully settled rules.
For Southeast Asia, the broader lesson is that AI governance will not be solved by adoption alone. The region has a large base of digital-first consumers, fast-growing fintech and e-commerce sectors, and governments keen to use AI to improve productivity. But it also has fragmented regulatory regimes, uneven enterprise infrastructure, and varying levels of technical capacity across markets.
Highly regulated industries appear to be ahead. Financial services topped the sector index at 69.6, supported by rigid compliance standards and 68 per cent audit trail adoption. IT and software services followed at 68.8, although the report warns that rapid deployment could outpace governance.
By contrast, e-commerce scored 65.4, while mobility and delivery platforms came last at 64.4. These sectors often prioritise speed, conversion, routing efficiency, and customer experience. But as AI systems begin making operational decisions at scale, weak oversight could create blind spots in pricing, fraud handling, worker allocation, refunds, or dispute resolution.
From AI policy to proof
Singapore businesses are aware of the technical hurdles. The report identifies their top engineering priorities as managing model complexity at 66 per cent, integrating AI systems smoothly across platforms at 50 per cent, and tracking actions taken by third-party or external AI tools at 49 per cent.
That last point is especially important. Many companies do not build every AI tool in-house. They rely on external models, software vendors, cloud platforms, and specialised agents. If those systems act inside a company’s workflow, businesses still need a way to link each action back to an authorised AI agent and a responsible human overseer.
Also Read: Why Southeast Asia cannot build sovereign AI on borrowed choices
The appetite for such infrastructure appears strong. Ninety-eight per cent of Singapore businesses said they are ready to adopt a third-party verification solution that ties autonomous AI actions back to a verified identity network.
For regulators and enterprises, the next phase of AI governance will likely be less about writing principles and more about proving compliance in real time. Singapore’s approach, including initiatives such as MAS’ Safeguards for Agentic Finance at Runtime, points to a future where AI systems need operational guardrails, not just ethics statements.
The report’s message is clear: agentic AI is already entering the enterprise. The harder task now is making sure every automated decision leaves a trail.
The post Singapore firms embrace agentic AI, but audit trails remain thin appeared first on e27.