More companies across Asia implement AI policies than ever before. Boards have approved acceptable-use guidelines, legal teams have drafted principles on privacy and transparency, and responsible AI now appears routinely in annual reports.
However, my conversations with business leaders around the region consistently reinforce a gap between policy and action in AI implementation. Closing this gap by turning intent into responsible everyday practice is emerging as a real governance challenge for enterprises in Asia.
Why the gap keeps widening
AI capability is advancing faster than any governance process can keep pace with. By the time a policy has been written, reviewed and circulated, the tools it was meant to cover have already changed.
Employees, meanwhile, are pasting text into whatever assistant sits on their phone or browser because it helps them finish work faster. This is the quiet reality of shadow AI: staff use these tools even when company policy forbids it, and nothing in practice stops them.
Most policies are also written as documents rather than built as controls. Stating that staff “must not share confidential information with AI tools” is not the same as making it difficult to do so. Without technical guardrails, training and clear ownership, a policy is an aspiration, not a safeguard.
The data bears this out. McKinsey’s 2025 global survey found that while 88 per cent of organisations now use AI regularly in at least one function, nearly two-thirds have yet to scale it across the enterprise. Adoption is racing ahead of the systems, processes and accountability needed to govern it, and that is precisely where the policy-to-practice gap opens.
What is actually at risk with sensitive documents
The consequences become concrete the moment sensitive documents enter ungoverned tools. Contracts, financial statements, customer records, invoices and internal reports are among a company’s most valuable, and most regulated, assets.
When they are fed into a consumer-grade tool with no data controls, an organisation loses visibility over where that information goes, how it is stored, and whether it could resurface elsewhere.
The risks are not hypothetical. Confidential data can be exposed or retained in ways the business never sanctioned, causing intellectual property to leak. Generative AI also introduced new real-world threats such as prompt injection, where malicious instructions are hidden inside content to manipulate a model into revealing information.
Since AI behaviour can be opaque, these incidents are difficult to detect and harder still to contain.
The deeper cost is trust. For any company that handles sensitive information, a single incident can undo years of credibility with customers and regulators. Convenience is never worth compromising security, because once trust is lost, the foundation of the business is shaken.
Governing across markets at very different stages
For organisations operating across Asia, there is an added layer of difficulty: the region’s markets sit at very different regulatory stages. Singapore has moved to the front. In January 2026, its Infocomm Media Development Authority launched the Model AI Governance Framework for Agentic AI, the first framework of its kind anywhere, addressing AI systems that can plan, reason and take autonomous action on a user’s behalf.
It sets expectations around bounding risk, keeping humans meaningfully accountable, and building technical controls into the AI lifecycle.
Most of the region is earlier on that journey. Many markets still rely on general data-protection law, with AI-specific guidance emerging slowly, if at all. Managing governance across this patchwork is genuinely hard: what is expected in one market may be unaddressed in the next.
Set your internal standard to the highest level required in any market where you operate. Then adjust for local rules, languages and business customs. The ASEAN Guide on AI Governance and Ethics gives a shared, practical baseline that leaders across Southeast Asia can use straight away, even before national rules arrive.
Following the stricter standard from the start keeps operations safer and prepares the business for regulation that is already on the way.
Practical steps for SMEs with limited resources
None of this requires the resources of a large enterprise. Small and medium-sized businesses, which make up the overwhelming majority of companies in this region, can build effective AI governance with a few disciplined steps.
Start by knowing your data. You cannot protect what you have not classified, so identify which documents are genuinely sensitive, such as contracts, financials, and personal data, and set clear rules for those first.
But classification only tells you what is at risk; protection comes from the tools people use every day. The decisive move is to actively adopt secure, enterprise-grade tools with proper data protections, and make them the easy, obvious option, so staff has no reason to reach for ungoverned alternatives.
Keep the rules simple. A short, plain-language acceptable-use policy that every employee actually understands will do more than a lengthy document no one reads. Pair it with light-touch training so people know not just what is prohibited, but why.
Insist on human oversight where it matters. AI can draft, summarise and extract data well, but a person should review any output that carries real business or legal weight. In my own organisation, for instance, no new AI tool is adopted before a small team assesses it for security, ethical and legal considerations, a practice that costs little but prevents a great deal.
Finally, use what is already available. Governments and international bodies now publish free frameworks and testing toolkits, Singapore’s AI Verify among them, that give smaller companies a credible starting point without heavy investment.
The lesson from every market I work in is the same. The policy-to-practice gap does not close by writing more policies. It closes through habits, enablement and ownership, by making the safe choice the easy choice, and by treating governance not as a document to be filed, but as a discipline to be practised every day. That is how AI becomes something an organisation can trust and build on, for the long term.












