Enterprises need transparency and controls from model providers before allowing access to data and workflows
PACING frontier development may give AI model companies more time to improve safety, alignment and interpretability. But none of that, by itself, makes a chief executive more willing to connect an agent to payroll, customer records or production scheduling.
Even as diligent testing and alignment increase confidence in an AI model, enterprises still need to know what they are accepting when they give it access to their data, workflows and decision rights.
In my conversations with large enterprises across Asia, the real constraint has moved further down the stack, from frontier capability to deployability. And it sits inside the companies putting these systems to work.
The constraint is deployability #
In one Asian e-commerce business, embedding AI-enabled workflows into core operations demonstrated that technology can readily automate processes. What took time were the questions about data access, decision control, exception ownership and compliance scrutiny.
The efficiency gains were substantial, but the difficulty lay in the exceptions – when a process deviated from the standard path and a human had to decide next steps. The economics and the controls had to move together.
The hardest AI conversations are about whether the business can redesign the process around these systems without creating more risk than value. Governance is a key part of the adoption decision.
This sharpens as agents move from assisting people to acting autonomously inside business processes. Before giving an agent authority, the enterprise needs controls over identity, data access, permissions, traceability and reversibility.
Non-human identity management, agentic permissions and execution controls become conditions of deployment.
IBM’s 2026 study on the cost of a data breach puts numbers on the consequence.
Incidents involving an organisation’s own AI models or applications rose from 13 per cent of breaches to 21 per cent in a single research cycle. Among organisations suffering an AI-related breach, 92 per cent had inadequate access controls, while only 19 per cent said their governance and security teams worked together.
For a board or chief risk officer, these numbers determine how much authority an AI system can actually be given inside the enterprise.
Pacing raises the verification bar for enterprise buyers #
When model companies say publicly that capability is advancing faster than safeguards, enterprise buyers will rationally raise their standards of proof before granting those systems deeper access.
In the short term, pacing raises the assurance bar rather than lowering it.
Enterprise data and workflows remain the moat in this industry, and access is contingent on trust and auditable assurance. Frontier capability only becomes durable enterprise revenue when an enterprise deploys it.
Governance is therefore moving from a responsible-AI principle to part of the product itself.
Open weights sharpen the problem. I have seen enthusiasm for an open model change the moment the conversation moves from experimentation to a core business process.
Publishing weights creates access, but not verifiability. Once a model can be downloaded, modified and redeployed, the enterprise still has to establish provenance (record of origin, creation and modification), version history and known limitations before trusting it inside a core process.
That shifts a verification burden onto the buyer, which many enterprises are not equipped to carry.
Model providers can reduce that burden by providing such documentation. That may slow release, but it can make deployment easier and adoption faster once the model reaches the market.
Assurance cannot stop at the frontier lab #
Pharmaceutical companies settled a version of this problem long ago. A medicine carries a batch number and evidence of what it contains. Material changes must be documented, and monitoring continues after launch.
The primary obligation sits with the manufacturer. It may not control how a doctor prescribes the medicine, but it remains responsible for what is inside the bottle and on its label.
AI needs a similar division of responsibility. The frontier lab does not have to own enterprise deployment, but it has to make models inspectable enough for others to govern their use.
Disclosure therefore becomes a product feature rather than a compliance artefact.
Training data sources, methodology and architectural decisions can be published in machine-readable form, as a step towards an AI bill of materials comparable to the software bill of materials the industry already accepts.
Enterprises buy from supply chains they can audit. Assurance also has to continue after release. A model evaluated before launch tells a board little about how an agent behaves six months into production.
Monitoring must be continuous, with a clear identity for every agent, a named human owner, narrow access to tools and data, and actions that can be traced and reversed.
Asia should shape the debate in deployment governance #
Singapore’s Infocomm Media Development Authority published its Model AI Governance Framework for Agentic AI in January 2026 and updated it in May. The first of its kind globally, it is a practical blueprint for what organisations need before autonomous AI systems are trusted inside real business operations.
It calls for bounded risk, meaningful human accountability, technical controls, verifiable agent identity, and audit trails. This is a more useful contribution to the enterprise adoption problem, and one the region should press harder.
South-east Asia has more than 680 million people, with more than 60 per cent of payments already digital, according to Google, Temasek and Bain’s e-Conomy 2025 study. In India, Microsoft’s 2026 Work Trend Index found that 32 per cent of AI users are redesigning work around agents, twice the global average. These active markets should have a bigger voice in shaping the rules.
The commercial risk to the AI industry is not simply that models become too powerful too quickly. It is that enterprises refuse to hand over proprietary data, workflows and decision rights to systems they do not trust.
Frontier companies have to earn that access through transparency, security, governance and demonstrable control. Trust will determine how far into the enterprise AI is allowed to reach.
Making AI trustworthy enough to deploy is not a constraint on growth. It is the growth strategy.
The writer is vice president and senior partner at IBM Consulting Asia Pacific. The views expressed here are her own