{"slug": "making-ai-trustworthy-does-not-constrain-growth", "title": "Making AI trustworthy does not constrain growth", "summary": "IBM's 2026 study on the cost of a data breach found that incidents involving an organisation's own AI models or applications rose from 13 per cent of breaches to 21 per cent in a single research cycle, with 92 per cent of affected organisations having inadequate access controls and only 19 per cent reporting that their governance and security teams worked together. The column argues that enterprise AI adoption is now constrained by deployability rather than frontier capability, as companies demand controls over identity, data access, permissions, traceability and reversibility before granting agents authority inside core business processes. Open-weight models further shift a verification burden onto buyers, who must establish provenance, version history and known limitations before trusting a model in a core process.", "body_md": "# Making AI trustworthy does not constrain growth\n\nEnterprises need transparency and controls from model providers before allowing access to data and workflows\n\n[PACING frontier development](https://www.businesstimes.com.sg/international/global/anthropic-ceo-urges-slower-ai-development-altman-musk-rally-behind-call) may give AI model companies more time to improve safety, alignment and interpretability. But none of that, by itself, makes a chief executive more willing to connect an agent to payroll, customer records or production scheduling.\n\nEven as [diligent testing and alignment](https://www.businesstimes.com.sg/opinion-features/pacing-ai-development-possible-how-can-singapore-contribute) increase confidence in an AI model, enterprises still need to know what they are accepting when they give it access to their data, workflows and decision rights.\n\nIn my conversations with large enterprises across Asia, the real constraint has moved further down the stack, from frontier capability to deployability. And it sits inside the companies putting these systems to work.\n\n## The constraint is deployability\n\nIn one Asian e-commerce business, embedding AI-enabled workflows into core operations demonstrated that technology can readily automate processes. What took time were the questions about data access, decision control, exception ownership and compliance scrutiny.\n\nThe efficiency gains were substantial, but the difficulty lay in the exceptions – when a process deviated from the standard path and a human had to decide next steps. The economics and the controls had to move together.\n\nThe hardest AI conversations are about whether the business can redesign the process around these systems without creating more risk than value. Governance is a key part of the adoption decision.\n\nThis sharpens as agents move from assisting people to acting autonomously inside business processes. Before giving an agent authority, the enterprise needs controls over identity, data access, permissions, traceability and reversibility.\n\nNon-human identity management, agentic permissions and execution controls become conditions of deployment.\n\nIBM’s 2026 study on the cost of a data breach puts numbers on the consequence.\n\nIncidents involving an organisation’s own AI models or applications rose from 13 per cent of breaches to 21 per cent in a single research cycle. Among organisations suffering an AI-related breach, 92 per cent had inadequate access controls, while only 19 per cent said their governance and security teams worked together.\n\nFor a board or chief risk officer, these numbers determine how much authority an AI system can actually be given inside the enterprise.\n\n## Pacing raises the verification bar for enterprise buyers\n\nWhen model companies say publicly that capability is advancing faster than safeguards, enterprise buyers will rationally raise their standards of proof before granting those systems deeper access.\n\nIn the short term, pacing raises the assurance bar rather than lowering it.\n\nEnterprise data and workflows remain the moat in this industry, and access is contingent on trust and auditable assurance. Frontier capability only becomes durable enterprise revenue when an enterprise deploys it.\n\nGovernance is therefore moving from a responsible-AI principle to part of the product itself.\n\nOpen weights sharpen the problem. I have seen enthusiasm for an open model change the moment the conversation moves from experimentation to a core business process.\n\nPublishing weights creates access, but not verifiability. Once a model can be downloaded, modified and redeployed, the enterprise still has to establish provenance (record of origin, creation and modification), version history and known limitations before trusting it inside a core process.\n\nThat shifts a verification burden onto the buyer, which many enterprises are not equipped to carry.\n\nModel providers can reduce that burden by providing such documentation. That may slow release, but it can make deployment easier and adoption faster once the model reaches the market.\n\n## Assurance cannot stop at the frontier lab\n\nPharmaceutical companies settled a version of this problem long ago. A medicine carries a batch number and evidence of what it contains. Material changes must be documented, and monitoring continues after launch.\n\nThe primary obligation sits with the manufacturer. It may not control how a doctor prescribes the medicine, but it remains responsible for what is inside the bottle and on its label.\n\nAI needs a similar division of responsibility. The frontier lab does not have to own enterprise deployment, but it has to make models inspectable enough for others to govern their use.\n\nDisclosure therefore becomes a product feature rather than a compliance artefact.\n\nTraining data sources, methodology and architectural decisions can be published in machine-readable form, as a step towards an AI bill of materials comparable to the software bill of materials the industry already accepts.\n\nEnterprises buy from supply chains they can audit. Assurance also has to continue after release. A model evaluated before launch tells a board little about how an agent behaves six months into production.\n\nMonitoring must be continuous, with a [clear identity for every agent](https://www.businesstimes.com.sg/opinion-features/ai-agents-were-going-need-see-some-id), a named human owner, narrow access to tools and data, and actions that can be traced and reversed.\n\n## Asia should shape the debate in deployment governance\n\nSingapore’s Infocomm Media Development Authority published its [Model AI Governance Framework for Agentic AI](https://www.businesstimes.com.sg/singapore/singapore-updates-national-ai-strategy-partners-google-and-openai) in January 2026 and updated it in May. The first of its kind globally, it is a practical blueprint for what organisations need before autonomous AI systems are trusted inside real business operations.\n\nIt calls for bounded risk, meaningful human accountability, technical controls, verifiable agent identity, and audit trails. This is a more useful contribution to the enterprise adoption problem, and one the region should press harder.\n\nSouth-east Asia has more than 680 million people, with more than 60 per cent of payments already digital, according to Google, Temasek and Bain’s e-Conomy 2025 study. In India, Microsoft’s 2026 Work Trend Index found that 32 per cent of AI users are redesigning work around agents, twice the global average. These active markets should have a bigger voice in shaping the rules.\n\nThe commercial risk to the AI industry is not simply that models become too powerful too quickly. It is that enterprises refuse to hand over proprietary data, workflows and decision rights to systems they do not trust.\n\nFrontier companies have to earn that access through transparency, security, governance and demonstrable control. Trust will determine how far into the enterprise AI is allowed to reach.\n\nMaking AI trustworthy enough to deploy is not a constraint on growth. It is the growth strategy.\n\n**The writer is vice president and senior partner at IBM Consulting Asia Pacific. The views expressed here are her own**", "url": "https://wpnews.pro/news/making-ai-trustworthy-does-not-constrain-growth", "canonical_source": "https://www.businesstimes.com.sg/opinion-features/making-ai-trustworthy-does-not-constrain-growth", "published_at": "2026-09-21 05:00:00+00:00", "updated_at": "2026-09-21 05:24:08.414016+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "artificial-intelligence"], "entities": ["IBM", "Anthropic", "Sam Altman", "Elon Musk", "Singapore"], "alternates": {"html": "https://wpnews.pro/news/making-ai-trustworthy-does-not-constrain-growth", "markdown": "https://wpnews.pro/news/making-ai-trustworthy-does-not-constrain-growth.md", "text": "https://wpnews.pro/news/making-ai-trustworthy-does-not-constrain-growth.txt", "jsonld": "https://wpnews.pro/news/making-ai-trustworthy-does-not-constrain-growth.jsonld"}}