When Singapore backed its AI ambitions with a $37 billion R&D investment and launched its landmark Agentic AI Governance Framework, it sent a clear message to Asia: the era of experimenting with chatbots is over. Autonomous AI agents are racing from pilot to implementation. Deloitte reports that 72 percent of Singapore businesses plan to deploy them within two years, up from just 15 percent today.
While agentic AI delivers undeniable operational savings, a single misstep can cost millions. Government agencies have already recognized that the next phase of AI adoption depends on trusted and resilient digital infrastructure. The same principles must now extend to enterprise security. To continue innovating safely, businesses must reframe their strategy. If we cannot prevent every breach, we must be able to detect and contain it.
Contain attacks before they spread
In the past, cybersecurity was about finding permanent fixes: analyze a vulnerability, issue a patch and eliminate the threat for good. Then came zero-days, cutting response windows to hours. Today, frontier AI brings us into the zero-minute era, where humans are running out of time to react.
Many organizations are used to restricting human employees from walking through high-security corridors. AI agents should be treated with the same discipline. As they gain greater autonomy and access across enterprise environments, organizations need strict identity and access policies, alongside clear audit trails that maintain visibility and control.
If an AI system gets hacked, the primary goal is to keep the damage contained. By dividing their network into several isolated compartments, organizations can delay a breach from spreading. This does not require a complete overhaul. It does require consistent enforcement of clear guardrails.
Detect the low-noise signals
Frontier AI threats are not just faster. They also do not always trigger the security alarms we trust to keep us safe. In a recent test, an experimental AI agent reportedly escaped its isolated testing environment and accessed live systems on the Hugging Face platform. Incidents like this demonstrate how autonomous systems can behave in unexpected ways and find pathways their developers did not anticipate. If attackers can exploit that autonomy, the consequences could escalate quickly.
When AI agents are hijacked, they may simply continue communicating as designed. An unfamiliar login request at 3 a.m., followed by strange file transfers, may appear unrelated individually. Together, they could reveal the beginning of an attack. By the time malicious intent becomes obvious, company data may already have been exfiltrated and could be misused for high-leverage extortion, social engineering or competitive sabotage.
Detecting these low-noise signals requires more than traditional alerts. Organizations need to bring signals from across the business into a unified view, understand how systems normally behave and identify when even trusted identities or agents deviate from those patterns. Operational threat intelligence adds another layer of context, helping security teams connect subtle activity with known attacker tactics and behaviors.
Close the threat detection-to-response gap
To stay safe in the zero-minute era, organizations must shrink the window between detection and response as much as possible. No single security control can achieve this in isolation. Instead, we must adopt an intelligence-led cyber resilience framework. Looking for hidden threats, known as threat hunting, is a fundamental part of this. But you cannot hunt what you do not know.
Effective threat hunting relies on a massive, global dataset of real-world threat intelligence. Latest trends show that attackers are now poisoning trusted software building blocks and actively exploiting open-source software to spread. They are also hiding inside legitimate public services to slip past traditional filters. When automated agents unknowingly run this corrupted code, breaches can occur instantly without raising obvious red flags.
As organizations give AI agents greater autonomy and access to sensitive environments, this reinforces the importance of sovereign AI: keeping AI operations contained within trusted environments, with control over how sensitive data is accessed and where it can go.
Monitoring and cross-verifying global intelligence from various sources helps organizations connect these subtle clues. This allows security teams to spot anomalies and isolate compromised systems preemptively, keeping the rest of the business running smoothly.
Secure APAC’s next frontier
Organizations in Singapore and APAC do not need to reinvent the wheel to upgrade their defenses against frontier AI threats. Many of the foundations already exist. The priority now is extending them to AI: strengthening identity controls, connecting visibility across the security environment, operationalizing threat intelligence and building security operations capable of responding at machine speed.
In the zero-minute era, security cannot be a feature added later. Organizations need to combine intelligence-led security and real-time visibility with AI that is secure and sovereign by design. This can help them deploy agentic AI while maintaining stronger control over the risks that come with greater autonomy.

Neville Vincent is Senior Vice President and General Manager, APCJ, at Trellix.
Editor’s note: This contributed article has been lightly edited for clarity and TNGlobal house style. The views and arguments expressed remain those of the author.
Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archive.
Featured image: Robynne O on Unsplash

