Live50m agoSingapore Factory Output Rises 7.2% in June as AI Demand Drives Electronics Boom
← Back to stories

Shadow AI Outpaces Governance Controls in Singapore as Employee Adoption Surges Past Corporate Policies

Source: Singapore Business Review

Singapore companies are finding themselves in an uncomfortable position: their employees are adopting AI tools faster than anyone can govern them. New research from JFrog and Splunk paints a picture of an enterprise landscape where the gap between AI usage and AI oversight is widening, with 60 per cent of...

Shadow AI Outpaces Governance Controls in Singapore as Employee Adoption Surges Past Corporate Policies
SGAI Daily

Singapore companies are finding themselves in an uncomfortable position: their employees are adopting AI tools faster than anyone can govern them. New research from JFrog and Splunk paints a picture of an enterprise landscape where the gap between AI usage and AI oversight is widening, with 60 per cent of Singapore's DevSecOps stakeholders now naming governance and policy enforcement as their single largest time burden.

The numbers are striking. JFrog's survey found that 41 per cent of Singapore technology teams say reviewing AI-generated code is draining resources they don't have, while 63 per cent of technology leaders blame third-party services for critical system downtime. Perhaps most tellingly, 18 per cent of Singapore organisations have formal policies banning unauthorised AI tools but have no mechanism to detect when employees violate them — a scenario that JFrog's Asia-Pacific senior vice-president Sunny Rao describes as a policy without teeth.

"An AI policy does not equal AI control," Rao told Singapore Business Review, warning that outright bans on AI tools may simply push usage further underground. The concern is not hypothetical: employees may be uploading source code, customer information, or commercially sensitive data into unapproved AI tools without their employer's knowledge. Splunk's head of observability for Asia-Pacific, Christina Low, noted that AI-generated errors can also cascade through workflows before reaching customers or critical systems, making detection even harder when the original mistake was made through a shadow tool.

The governance gap reflects a broader complexity crisis in enterprise technology. Modern applications stitch together internal code with open-source packages, cloud services, AI models, and third-party APIs — each representing a potential route for data leakage or operational failure. While 95 per cent of organisations track application ownership, more than half need at least a week to produce compliance evidence for a single application. Against that backdrop, policing unauthorised AI use becomes nearly impossible without automated discovery and enforcement tools that most companies have not yet deployed.

Why it matters for Singapore: Shadow AI is not just a compliance headache — it has direct implications for Singapore's push to become a trusted AI hub. If regulators at IMDA and PDPC are tightening rules around AI data use while employees are freely feeding corporate data into unapproved tools, the gap between policy intent and on-the-ground reality widens. Companies that solve this detection-and-enforcement problem first will have a significant trust advantage, both with customers and with regulators who are increasingly expecting demonstrable AI governance.

Your daily AI edge in Singapore: in <5 minutes.

We do the reading so you don't have to. Get the essential TL;DR on local AI moves delivered to your inbox every morning.