- Sep 17, 2026
- 12 min read
Willing to Own It, Unable to Prove It: Research on AI Governance in APAC
See how organizations govern AI today: Benchmark data on autonomy and accountability, including practical frameworks and best practices to close the gaps.

In recent years, organizations have persistently asked one question about artificial intelligence: what can it do for us? Lately, harder questions have replaced it: what is AI doing on our behalf, and can we prove it?
That shift is the reason AI governance has moved from a compliance afterthought to a board-level priority. AI has stopped being a tool that drafts a memo or flags an anomaly. It now opens tickets, moves money, approves transactions, and carries multi-step tasks through to completion with limited human involvement.
Accountability is clear when a person makes a decision – we can trace it back to them. But what happens when an autonomous system makes thousands of decisions a day? Organizations must be able to explain what AI did, why it did it, and who is accountable for the outcome.
To measure how ready organizations are to answer those questions, Sumsub commissioned an independent research study of 720 senior professionals across nine Asia-Pacific markets – Sumsub APAC State of Digital Trust: AI Governance Benchmark.
The results look reassuring. Across the region, AI governance appears to be keeping pace with how fast AI is being deployed. But the composite score hides the pattern that matters. Organizations are willing to own what their AI does; far fewer can prove what it did.
What is AI governance, and why does trust matter now?
AI governance is the system of policies, roles, controls, and processes that lets an organization direct and account for how its AI is built, deployed, and used. It answers who decides what a model is allowed to do, who owns the outcome when it acts, and how anyone can reconstruct a decision after the fact.
Enterprise AI governance applies that discipline across every model and team, from a single onboarding decision to an entire agentic workflow running in production.
In 2026, AI has moved past the role of an assistant and into the role of an actor. Systems that once supported staff with recommendations now make decisions inside live environments, often without a human in the loop for each step. Sumsub APAC State of Digital Trust: AI Governance Benchmark found that 72% of APAC organizations already run an AI system that either handles decisions and actions with human approval or acts independently with exception-based oversight. Once AI acts on an organization's behalf, a responsibility it has accepted but can’t reconstruct becomes a liability it can’t quantify. That liability surfaces the moment a regulator, shareholder, or customer asks what happened.
The trust challenges driving AI governance adoption in APAC
Informal control is breaking down: AI systems are acting further on their own, being stretched past what was approved, and already producing outcomes nobody intended. Meanwhile, regulators are arriving on a fixed timeline. Four pressures show up repeatedly in the data.
The first is scope creep. More than nine in ten respondents (92%) admit they stretched an AI system past its original purpose in the past year, and 30% did so significantly. The AI running today is rarely the AI that was reviewed and signed off.
The second is failure that has already happened. Roughly six in ten organizations (63%) have watched an autonomous action produce an unintended or problematic outcome, and 31% have seen it more than once. The risk is no longer hypothetical.
The third is the evidence gap. 95% of respondents are confident they can explain an AI decision, but only 50% can reconstruct the decision pathway, and just 38% hold a tamper-proof audit trail. Confidence is running well ahead of provability.
The fourth is regulation. Every APAC market is either extending existing privacy and consumer law to cover AI or standing up new mandates. Firms are building formal governance now because the frameworks they will be judged against are arriving on a fixed timeline.
Across APAC, autonomous AI has moved past isolated pilots. Nearly three-quarters of organizations use AI across multiple functions, and the frontier is delegation rather than adoption: AI runs workflows, makes calls, and carries tasks through several steps without a person approving each one.
How the Research was run
The study was conducted independently by Blackbox Research, commissioned by Sumsub in partnership with the Singapore FinTech Association (SFA), between April and June 2026. A quantitative survey reached 720 senior professionals in technology, product, risk, compliance, and operations roles across nine Asia-Pacific markets and four sectors. Three-quarters of respondents (76%) sat in senior leadership, and the sample split roughly six to four between enterprises and smaller companies.
The report scores each organization from 0 to 100 across three pillars:
- Autonomy measures how far AI systems already act on their own inside the organization.
- Responsibility measures how clearly the organization owns and answers for what its AI systems do.
- Traceability measures whether the organization can reconstruct, explain, and audit what its AI models did.
Organizations then fall into three maturity bands: Leading (above 75), Advanced (50 to 75), and Developing (below 50).
Autonomy is outrunning traceability
The composite score of 67.1 hides an uneven profile. Autonomy and Responsibility both sit close to 70, while AI Traceability is at 61.0. The pattern is consistent across markets and sectors.

AI governance score in APAC
Around half of organizations let AI handle decisions with humans required for key steps, and one in five run genuine autonomous agents, with humans involved only for exceptions.
From accountability gap to trust gap: The problem is proof
The Research calls this pattern the Accountability Asymmetry: the gap between how fully organizations take responsibility for their AI decisions and how well they can prove what those decisions were. The intent to take responsibility is there, but the evidence often isn’t. Being able to explain a decision when asked is not the same as being able to prove how it happened.

Where AI is taking on autonomous agent roles
Many APAC organizations are accelerating their use of AI but still lack the controls needed to see where their systems are going. As Mick Amelishko puts it:
AI governance across APAC: The regulatory landscape
APAC has no single AI rulebook, but its national frameworks rest on shared international reference points. The OECD AI Principles, adopted in 2019 and updated in 2024, are the most widely cited, setting out five commitments:
- inclusive growth and well-being
- respect for human rights and democratic values, including fairness and privacy
- transparency and explainability
- robustness, security, and safety
- accountability
Alongside them, the NIST AI Risk Management Framework and ISO/IEC 42001 give organizations operational scaffolding, and the EU AI Act's risk-tiered regulatory approach has become the reference point several APAC markets draw on.
Markets diverge in how they translate those shared principles into enforceable rules, and the range is wide. Four of the benchmark's nine markets map out the span, from innovation-first regimes to regulation gated at the point of market entry.
India takes an innovation-first stance backed by strict data law. Its AI Governance Guidelines, issued by the Ministry of Electronics and IT (MeitY), are built on seven "sutras," guiding principles meant to keep oversight proportionate to risk rather than pre-emptively heavy. The harder boundary comes from the Digital Personal Data Protection Act, which sets the rules for anything a model does with personal data.
China regulates hard, and gates it at market entry. Rather than reviewing systems after they cause harm, the Cyberspace Administration of China runs algorithm registries and security reviews before a system goes live. In June 2026, the country went further than any other market with its AI Agent Interconnection standard, which assigns every agent a unified identity. It is the Know Your Agent principle written directly into national policy.
Hong Kong governs through the laws it already has, led by privacy. The Personal Data (Privacy) Ordinance provides the statutory backbone. On top of it, the Privacy Commissioner for Personal Data (PCPD) has published a Model Framework for procuring and deploying AI, and a Generative AI Technical and Application Guideline extends that guidance to generative systems specifically.
Australia keeps its approach technology-neutral, updating existing statute rather than writing a dedicated AI act. Automated decision-making amendments to the Privacy Act take effect on December 10, 2026, requiring organizations to be transparent about significant decisions made by automated systems, while the Australian AI Safety Institute anchors the country's technical and safety work.
Suggested read: Comprehensive Guide to AI Laws and Regulations Worldwide
Expert perspective: Building trust in AI, with Holly Fang, President of the Singapore FinTech Association
THE SUMSUBER: Singapore is often held up as APAC's reference point for trustworthy AI in finance: MAS's FEAT principles, Veritas, and the Model AI Governance Framework. From where you sit at the Singapore FinTech Association (SFA), what has actually moved the needle on trust, versus what's still aspirational?
HOLLY FANG: I think what has really moved the needle in Singapore is the shift from setting principles to working through how they are applied in practice. Frameworks such as FEAT and Veritas created an important foundation, but increasingly the conversation is about what responsible deployment actually looks like as AI becomes embedded in financial services.
Across the industry, we have seen rapid adoption of AI across fraud detection, compliance, customer service, underwriting, treasury, and operations, and increasingly in agentic workflows. But many of the founders and builders we speak with would also say that technology is moving faster than governance. The harder and still more aspirational part is achieving the same level of maturity in governance across all of those different use cases, particularly as the level of autonomy increases.
So I don’t think Singapore’s advantage is that we have solved AI governance. It is that regulators, financial institutions, fintechs, and technology companies are actively working through these questions together, while real deployment is already happening. That feedback loop between policy and practice is important, because ultimately trust will come not from having more frameworks, but from showing that AI can be deployed responsibly at scale.
THE SUMSUBER: Our Research found that autonomy is outrunning traceability: firms are deploying AI that acts faster than they can prove why it acted. Given your vantage point on fraud and scams in digital payments, where does that traceability gap worry you most?
HOLLY FANG: I think the biggest risk is when AI moves from supporting decisions and recommending actions to executing them. A system that flags fraud is one thing; an agent that can initiate payments, change beneficiaries, or block transactions is another. Payments amplify this risk because speed leaves little room for intervention. So if something goes wrong in real time, there could be severe consequences.
Fraudsters are also using AI to scale impersonation and adapt attacks, meaning machines will increasingly be defending against machines in milliseconds.
Traceability is absolutely critical, and it must capture the full chain of authority. The higher the impact, the higher the standard of accountability required. This is why Singapore’s agentic AI framework continues to emphasize human accountability even as systems become more autonomous.
THE SUMSUBER: Trust has to be earned on all fronts: consumers need to trust AI-driven decisions, but so do regulators and partners. Which of those trust deficits is the hardest for a fintech to close right now?
HOLLY FANG: From my conversations with our members, institutional trust, especially with regulated partners, is often the hardest to earn.
Consumer trust can build through experience, but banks and regulators need to understand risk upfront. And because fintechs operate within interconnected ecosystems of banks, payment networks, and cloud and data providers, one weak link affects all parties.
This is particularly acute for smaller firms and newer entrants that rely heavily on third-party infrastructure and do not yet have long operating histories with conservative financial institutions. For them, the challenge is not just building good AI systems, but proving repeatedly that those systems are safe, controllable, and auditable enough for highly risk-averse partners who tend to default to established providers and proven processes.
The fastest way to build trust is to make AI systems externally legible: build clear governance, clear documentation, and clear evidence of how decisions are made and controlled. In financial services, trust increasingly depends on explainability, transparency, and the ability to demonstrate reliability over time.
THE SUMSUBER: Big banks can throw a governance team at this. A 30-person fintech can't. What should smaller players prioritize to build defensible AI governance without the headcount?
HOLLY FANG: For smaller firms, what matters most is being deliberate about where AI is used and ensuring there is no ambiguity about responsibility or control. In practice, that means having a clear view of every AI system in use, understanding what each one is doing, and being honest about the level of risk it introduces. From there, firms need to be disciplined about how much autonomy they actually allow these systems to have, especially when it comes to anything involving financial transactions or regulated decisions.
Equally important is making sure there is always a way to trace what happened. If an AI system makes a recommendation or takes an action, it should keep a clear record of what data it relied on, which model version it used, and whether a human intervened. And ultimately, someone in the organization has to own the outcome, regardless of whether the decision was assisted or fully automated.
THE SUMSUBER: What's the one shift in AI governance or trust infrastructure across APAC that you think leaders are underestimating?
HOLLY FANG: I think it is how quickly we are moving from governing what AI says to governing what AI is actually allowed to do.
We are already seeing this shift in Singapore. The Model AI Governance Framework for Agentic AI sets out how organizations can bound an agent’s autonomy and maintain meaningful human accountability, and the Safeguards for Agentic Finance at Runtime (SAFR) framework goes a step further in financial services. It’s looking at real-time controls to keep agents operating within predefined mandates and risk boundaries.
This will ultimately create a new layer of trust infrastructure. Today we authenticate people and businesses. Increasingly, we will need to authenticate agents. So, AI governance is becoming less about compliance and more about infrastructure. And in Asia’s real-time, digital-first financial systems, this shift will arrive sooner than many expect.
Governing agentic and autonomous AI
Governing autonomous AI is where the findings land hardest, because agents compress the distance between a decision and an irreversible action. AI agent governance has to hold even when no human is watching a given step. Agentic AI appears first where the stakes are lowest, in operations and customer service, well ahead of fraud, AML, and payments. The caution is rational: missing a sanctioned entity carries fines, license risk, and personal liability for officers involved.
Human-in-the-loop oversight
Autonomous AI systems can operate independently within defined boundaries, but human oversight remains important, especially when decisions carry significant consequences. The level of oversight should reflect the risk of the workflow. For low-risk tasks, exception-based monitoring may be sufficient. For high-stakes actions, such as moving client funds or making an onboarding decision, the system should require human approval before the action is completed.
Know Your Agent: Identity and traceability
The most important emerging concept in AI agent governance is Know Your Agent, the discipline of binding every autonomous agent to a verifiable identity and tracing its actions back to an accountable human.
It extends Know Your Customer to non-human actors, so any action traces to an authorized agent under a responsible human's authority.
Suggested read: From AI Agents to Know Your Agent: Why KYA Is Critical for Secure Autonomous AI
AI governance best practices
A durable AI governance framework rests on several principles, and most organizations take them from the OECD AI Principles and the NIST AI Risk Management Framework. Putting one in place requires input from privacy, legal, compliance, security, engineering, risk, and other relevant teams.
Make AI governance a shared responsibility
One of the most basic AI governance best practices is not leaving it to a single department. Whoever owns the program, whether that's the chief compliance officer, the chief risk officer, or a dedicated AI lead, should bring in stakeholders from across the business from the start, so risks, responsibilities, and controls are defined by the people who'll actually work with them. Controls built this way tend to fit how the business actually works, so teams can adopt AI responsibly without governance turning into a bottleneck.
Promote fairness and bias mitigation
Fairness and bias mitigation help prevent AI systems from producing unjustifiably discriminatory outcomes for particular groups. These risks can originate in unrepresentative training data or insufficient efforts to identify and mitigate bias.
Checking for bias is a multi-level task. Audit the training data, test the model's outputs before launch, and keep monitoring its decisions once it's live to catch any group getting consistently worse outcomes.
Be transparent about AI and explain its decisions
Transparency means telling people when they are interacting with AI. Explainability means being able to communicate why an AI-supported decision was made in terms that a human can understand and challenge.
Traceability should be built into the deployment process, so reviewers can reconstruct important decisions from the relevant inputs, rules, and actions rather than relying solely on an explanation generated by the model.
Keep humans accountable for AI decisions
Every AI-supported outcome should have a clear human owner. Accountability belongs in the design phase, not after go-live: name who is responsible for monitoring, reviewing, escalating, and overriding AI-supported decisions before the system reaches production.
The level of oversight should match the risk and autonomy of the workflow. Low-risk tasks may require exception-based monitoring, while high-stakes actions should include human approval gates, the ability to pause or override the system, and clear escalation procedures.
Protect privacy and security
Privacy and security controls should protect the data AI systems consume, the decisions they support, and the logs they generate. Good practice includes minimizing the personal data a system can access, enforcing role-based permissions, and protecting models and records against unauthorized changes.
Access and actions should be logged as well, so organizations can identify who, or what system, touched sensitive data or influenced a decision.
Match governance controls to risk and autonomy
Controls should reflect the level of risk rather than apply the same requirements to every AI use case. Governance should be built into organizational culture, product development, deployment, and ongoing monitoring, rather than signed off once before launch and forgotten. When designed well, AI governance helps teams understand risks, make informed decisions, and deploy AI with greater confidence, without losing sight of who is responsible for the outcome.
Suggested challenge: Got 50 seconds? Test your memory and see if you can outsmart the Beast!
How Sumsub closes the trust and traceability gap
Sumsub builds trust infrastructure with AI systems that act under human oversight. The approach maps onto the three pillars – autonomy, responsibility, and traceability – so AI governance and compliance become connected.
Unified access controls across models and projects
A major governance risk in practice is fragmentation: models and agents spun up across teams with no central view of who can reach what. That is how shadow AI takes hold, with unsanctioned systems acting outside the governance perimeter. Unified access control brings models, agents, and projects under one policy layer, with role-based access ensuring each person and system reaches only what its role requires.
Sumsub extends the mitigation measures to non-human actors through Know Your Agent and AI Agent Verification, binding each autonomous system to a verified owner. When a system starts a high-value action, the platform can trigger an on-demand liveness check for an authorized person acting on that owner's behalf, so every automated action traces back to a verified owner.
Built-in safeguards
Governance must apply both to how AI is used within Sumsub’s products and to how AI agents interact with those products.
For Sumsub’s AI-powered systems, human oversight remains central. These systems make recommendations, but the final decision on an applicant’s status is always made by a human – the client’s compliance officers. Recommendations can be overridden at any time. Destructive actions, such as changing data or configuration, are traceable and require human review before they are applied.
For AI agents operating in the dashboard, safeguards should help verify the agent’s identity, authority, and actions. This includes knowing which agent did what, on whose behalf, and whether the action was authorized.
Sumsub's Device Intelligence and bot detection track device, session, and behavioral signals in real time to intercept rogue automated processes, while mule-network prevention exposes coordinated abuse that basic IP blocks miss.
On the traceability side, Summy, Sumsub’s platform-native AI Copilot for compliance and fraud teams, provides visibility into actions through audit logs in the dashboard. This helps teams track activity and maintain transparency across compliance and fraud workflows.
Together, these give teams practical guardrails and human oversight over what their AI may do, and a defensible record of what it did.
AI governance FAQs
-
Why is AI governance important?
AI governance matters because AI has moved from advising humans to acting for them, and delegation without control creates unpriceable risk. Most organizations interviewed have stretched AI past its intended use, and many have had an autonomous action go wrong, yet few hold a tamper-proof trail. Governance turns AI from an unquantifiable liability into a capability you can scale and defend.
-
What are the best AI governance tools?
The best tools are those that produce proof rather than paperwork. A mature stack combines a central system inventory and risk classification, role-based access to prevent shadow AI, continuous monitoring for data drift, tamper-proof audit logging, and identity tools that bind each agent action to an accountable human. Frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 provide a structure for AI governance. Trust infrastructure platforms can help with identity verification, agent traceability, and guardrails. The AI built into these products often includes its own controls, such as human review.
-
What are the best practices for AI governance?
Make governance a shared responsibility across privacy, legal, compliance, security, engineering, and risk rather than one team's job. Check for bias throughout the AI lifecycle, tell people when they're interacting with AI, and be able to explain decisions in terms a person can challenge. Name a human owner for every AI-supported outcome before deployment, and scale oversight to the stakes – light monitoring for routine tasks, approval gates, and override options for high-risk ones. Protect the data these systems use with minimal access, role-based permissions, and logs that show who influenced a decision. Above all, treat governance as part of how you build and run AI, not a one-time compliance exercise.
-
What is an AI governance framework?
An AI governance framework is the structured set of policies, roles, controls, and processes used to direct and account for AI systems across their lifecycle. A working framework ties governance to what the business is trying to achieve. It defines who owns what and sorts each system into a risk tier. Controls are built in from design through retirement, and not bolted on at the end. Monitoring, documentation, and incident response make it possible to reconstruct any decision after the fact. So, every outcome has a named owner, set before deployment, and a trail behind it that can't be quietly edited.
-
How do we overcome common barriers to AI governance?
Establishing clear governance frameworks, assigning responsibilities across teams, and matching controls to the level of risk helps overcome common barriers to AI governance. Start with practical, risk-based policies, involve legal, privacy, security, and engineering teams, and build ongoing monitoring and human oversight into AI systems. This makes AI governance an operational process, not a one-time compliance exercise.
-
What are the biggest AI governance challenges?
The biggest challenge is Accountability Asymmetry: organizations are willing to own their AI's decisions but can’t yet prove what those decisions were. Confidence in explaining a decision runs well ahead of the ability to reconstruct it. Underneath sit scope creep and infrastructure debt, since siloed data and rigid architectures make unified records hard to build, and culture compounds both when governance is treated as friction.
Relevant articles
- Article
- 1 week ago
- 7 min read
Learn how AI agent skills and MCP power compliance automation in AML/KYC, what AI agents are, how they work, and why they matter.

- Article
- 1 week ago
- 11 min read

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


