Moving from AI experimentation to operational execution is no longer a distant objective. It is a current priority for enterprises across Asia Pacific.

Organizations have moved past asking whether they should adopt AI. Their attention has shifted to how they can deploy it, govern it, and maintain accountability as AI agents become a permanent and increasingly autonomous part of the workforce.

This shift changes enterprise architecture. Modern organizations rarely rely on a single AI platform, model, or cloud provider. Instead, they operate across multiple environments, with specialized teams selecting the tools that best suit specific functions.

Pursuing a single standardized AI tool may therefore be impractical. The more pressing requirement is consistent governance across a diverse technology ecosystem.

The new workforce and non-human identities at scale

As agentic AI becomes more deeply embedded in core operations, legacy perimeter and identity security models face growing strain. Organizations can no longer rely on fragmented tools designed primarily for human logins to secure an increasingly autonomous, non-human workforce.

Industry research has found that machine identities can outnumber human identities by as much as 45 to one. Okta also found that fewer than 10 percent of organizations across Australia, Japan, and Singapore believe their identity and access management systems are fully equipped to secure AI agents, bots, and service accounts.

Organizations are expanding their autonomous workforce faster than their ability to govern it.

When an AI agent receives access to corporate calendars, sensitive email conversations, and critical business databases, it can become a target for credential theft, prompt injection, and lateral movement.

An agent may hold credentials, invoke application programming interfaces, or initiate automated transactions. Identity consequently becomes the enterprise control plane for determining what that agent is permitted to access and do.

Identity as the regulatory and operational control plane

Executive teams and boards are beginning to recognize that non-human identities require the same visibility, lifecycle management, and access controls that organizations have spent years developing for human users.

An organization that cannot determine where its agents are, which systems they can access, and what actions they are authorized to perform has a significant governance gap.

Regulatory frameworks across Asia Pacific already require organizations to establish controls for technology and information security risks. Singapore’s Monetary Authority of Singapore Technology Risk Management requirements cover areas such as critical systems, resilience, recovery, and incident reporting. Australia’s APRA CPS 234 also places ultimate responsibility for information security on the boards of regulated entities.

To address these requirements without slowing technical development, enterprises should move beyond static, point-in-time authentication toward continuous, context-aware authorization.

An identity-first approach requires three core capabilities:

  • Identity for every actor: Organizations must issue, manage, and secure identities for every non-human agent. Each request and action should be tied to a specific, governable entity.
  • Verifiable, granular consent: Organizations need mechanisms that manage the full consent lifecycle, including explicit approval for high-risk actions and a simple way to revoke access.
  • An immutable, context-rich audit trail: Audit logs should show who authorized an agent, what action it performed, which resources it accessed, and when the activity occurred. This provides the evidence needed for internal reviews and regulatory scrutiny.

Building the secure agentic enterprise

The pace of AI development is unlikely to slow. Organizations that can demonstrate control over their agents will be better positioned to adopt new capabilities while managing the associated risks.

A neutral and independent identity foundation can give businesses the flexibility to adopt emerging AI tools securely. Adding isolated AI security controls to legacy infrastructure may create further complexity and technical debt.

Enterprises should instead consider an identity fabric that works across cloud environments, applications, and AI platforms.

Treating AI agents as first-class identities allows organizations to enforce least-privilege access, monitor their activity, and deactivate compromised or misbehaving agents immediately.

With these controls in place, AI can become a significant source of business value rather than an unmanaged expansion of the attack surface.

The future of enterprise technology will increasingly involve agentic systems. The pace of innovation should be matched by the ability to establish trust and accountability.

By making identity the control plane, organizations can ensure that as AI becomes more capable, their operations remain secure, governed, and resilient.


Dan Mountstephen is Senior Vice President and General Manager for Asia Pacific and Japan at Okta. Based in Singapore, he leads the company’s regional strategy, go-to-market operations, and partner-led growth.

He brings more than 20 years of experience in technology and cybersecurity, including senior positions in enterprise software and identity security.

TNGlobal INSIDER publishes contributions relevant to entrepreneurship and innovation. You may submit your own original or published contributions subject to editorial discretion.

Featured image: Steve A Johnson on Unsplash

Jaewha Choi of Bunjang on AI authentication and trust in cross-border recommerce [Q&A]