Organizations across Asia are adopting artificial intelligence-powered development tools at an unprecedented rate to stay competitive. However, while this rapid integration delivers significant productivity gains, it also introduces security vulnerabilities that traditional application security measures struggle to address. The speed at which AI generates code outpaces security teams’ ability to remediate weaknesses.

The new speed of innovation in Asia

Asian enterprises have embraced AI and autonomous agents as core components of their software development workflows. Companies racing to maintain market position view these technologies as essential investments rather than experimental tools. The productivity improvements have transformed development cycles that previously took weeks into processes completed in days.

This enthusiasm carries a hidden cost. AI models trained on vast code repositories frequently output insecure code that mirrors the vulnerabilities present in their training data. When developers rely on AI-generated snippets without a thorough security review, they inadvertently introduce exploitable weaknesses into production systems.

Autonomous AI agents add to this complexity by holding extensive permissions across development environments, creating an emerging cybersecurity challenge that transcends traditional code quality concerns.

Why machine speed complicates application security

Security teams can identify vulnerabilities in AI-generated code with relative ease using existing scanning technologies. The bottleneck emerges when attempting to fix these issues at the same pace AI creates them.

Sohail Iqbal, Chief Information Security Officer at Veracode, frames the challenge clearly in an interview. “The capability of identifying vulnerability is not an issue. But the issue is that if you’re writing code at machine speed, are you able to remediate it also at machine speed? That’s the challenge the world is facing right now,” he says.

Traditional security workflows were built around human development velocity. Engineers wrote code at a predictable pace, and security reviews could reasonably keep up with the volume of changes. AI fundamentally undermines this assumption by generating thousands of lines in minutes, each requiring the same level of security scrutiny that a human-written module would demand.

The hidden costs of AI security incidents

Financial losses from inadequate application security continue climbing across the region. Regional data breach data from 26 organizations across six Southeast Asian nations show that average breach costs have increased by 12 percent, with the financial and industrial sectors incurring losses of up to $6 million per incident. Organizations accelerating AI adoption without corresponding security investments face even steeper consequences.

Fastly’s latest Global Security Report reveals a stark reality for companies building their competitive advantage on AI-driven development. The research found that “AI-first companies take 6.8 months to recover from security incidents, compared to 3.9 months for other businesses. These incidents cost AI-first organizations 135 percent more than their counterparts, and 44 percent report that AI was directly exploited in their most recent incident.”

The extended recovery periods partly stem from the complex task of tracing vulnerabilities through AI-generated code paths, where traditional forensic techniques often prove inadequate.

The nonhuman identity problem

Many cybersecurity frameworks center on protecting human user accounts through password policies and multifactor authentication. AI agents operate entirely outside these paradigms. These autonomous systems make decisions, access sensitive repositories, and modify production code with minimal human oversight.

A survey of 1,234 organizations across Asia found that machine identities now outnumber human identities by as much as 82-to-one globally, yet resilience strategies remain heavily human-centric. Human identities feature in the cyber resilience strategies of 73 percent of organizations, yet only 34 percent address nonhuman identities in their planning.

The gap creates an expanding attack surface. Each AI agent offers a potential entry point for adversaries who understand that machine identities often receive excessive permissions to function. When an agent requires access to multiple systems to complete its tasks, security teams frequently grant broad privileges rather than implementing granular controls.

Agentic code and supply chain vulnerabilities

Agentic coding tools interact with the entire software supply chain through code repositories, package managers, and Model Context Protocol (MCP) servers. Without proper oversight, agents can pull in compromised dependencies, commit secrets directly to version control, integrate code from untrusted sources, and expose internal systems to external attackers.

Open Worldwide Application Security Project’s secure coding guidelines specifically warn about this direct supply chain risk, noting that compromised MCP servers and agents operating with full developer permissions create pathways for sophisticated attacks that bypass traditional security controls.

Securing these workflows requires platforms designed for the agentic era. Legit is one security provider that offers an agentic AppSec platform to secure AI code, agents, and workflows.

“AI accelerates software development, but without mature governance, that speed creates risk. The teams that succeed don’t fight AI adoption. They evolve how they govern it,” notes the company in a blog on maturity models.

The best AppSec vulnerability management tools for AI-first development must monitor both the code agents produce and the behaviors they exhibit while producing it. Maturity in AI security means progressing from basic detection to comprehensive governance frameworks that treat AI agents as first-class security concerns, requiring their own controls, auditing mechanisms, and risk assessment methodologies.

Rethinking AI governance and security maturity

According to the World Economic Forum’s 2025 Global Cybersecurity Outlook, “While 66 percent of organizations expect AI to have the most significant impact on cybersecurity in the year to come, only 37 percent report having processes in place to assess the security of AI tools before deployment.”

Asian enterprises must shift from reactive patching to proactive governance models that anticipate risks before deployment. This evolution becomes particularly pressing as organizations face sophisticated cyber threats and strict national data protection laws that impose significant penalties for breaches.

Traditional application security testing approaches, designed for human developers, lack the contextual awareness needed to evaluate AI-generated code effectively. Securing AI workflows demands visibility into what agents are doing across the development life cycle.

Organizations need systems in which automated discovery reduces manual asset tracking while providing security teams with real-time insights into code provenance, dependency chains, and access patterns.

The path forward for secure Asian AI development

The enthusiasm driving AI adoption across Asia reflects genuine competitive necessity. Organizations that rushed to deploy AI development tools now face a critical choice about whether their security posture can support the speed they have unleashed. Asian enterprises must determine whether governance structures have matured enough to contain the risks that arrive at machine speed.


Zac Amos is the Features Editor at ReHack, where he covers business tech, HR, and cybersecurity. He is also a regular contributor at AllBusiness, TalentCulture, and VentureBeat. For more of his work, follow him on X (Twitter) or LinkedIn.

Editor’s note: This contributed article has been lightly edited for clarity and house style. The substance of the author’s contribution has been preserved.

Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archive.

Featured image: Godfrey Nyangechi on Unsplash

How to spot phishing when AI removes the old warning signs