The Sovereignty Imperative: Why APAC Enterprises Can’t Get AI Wrong
Enterprise AI in Singapore has moved from pilot to production faster than most people expected.
ServiceNow’s Enterprise AI Maturity Index, published with ThoughtLab in August 2026, puts the country’s maturity score at 53 out of 100, up from 34 a year earlier. Agentic adoption rose from 22% to 51% of enterprises.
The capability question is largely settled. The harder question is what happens when someone asks an organization to account for what that capability did.
Sumsub’s APAC State of Digital Trust benchmark, produced with the Singapore FinTech Association across nine markets, found that 29% of Singapore organizations can produce an audit trail for an AI decision. The regional average is 38%.
Explaining and evidencing are different things
The same benchmark found that 95% of APAC organizations are confident they can explain what their AI does. 50% can reconstruct the decision pathway. 38% hold a tamper-proof trail.
The distinction between those figures is worth naming, because the market tends to treat them as one capability.
Explanation is a description of how a system works. It covers the model, prompt design, guardrails, and the intent behind them. Most teams can give it well, and it is genuinely useful.
Evidence is a record of what a specific system actually did on a specific occasion. Which data was available at the time. Which model version ran. Which policy applied. Who approved it, and when.
An organization can be strong on the first and hold nothing of the second. That is not a documentation problem. It is an architectural one, because you can’t assemble evidence like this after the fact. It was either captured while the system was running, or it wasn’t.
The requirement changes across the region
For enterprises headquartered in Singapore, this quickly becomes a regional question.
An agent built here follows the business into neighboring markets, and the obligations it meets there are not stricter or looser versions of the same rule. They are different questions.
China asks where the data is stored. Article 40 of the Personal Information Protection Law requires critical information infrastructure operators and processors handling personal information above thresholds set by the national cyberspace department to store domestically what they collect within China. When a cross-border transfer is genuinely necessary, it must go through a security assessment organized by that department.
India asks what has been assessed and proven. The Digital Personal Data Protection Rules were notified on 13 November 2025, with an eighteen-month phased compliance period. Significant Data Fiduciaries carry additional duties: independent audits, impact assessments for new or sensitive technologies, and compliance with the government may also restrict transfers of notified categories of personal data outside India. Enterprises should not assume that a single cross-border architecture will remain sufficient.
Those are two questions, not two settings on the same dial. And they are not the only two in the region. Several APAC markets are still writing about their implementing regulations, which means the obligation an agent meets next year may not be the one it was built for.
A single compliance posture does not answer them all. An enterprise expanding across the region is accountable to several regimes at once, most of them still developing.
Three questions worth asking
- Which of your agents could produce a complete decision record tomorrow, without commissioning work to build one?
- Does that record travel with the workload when it moves to another market?
- When a regulator asks who authorized a particular action, does the answer resolve to a named individual?
What good looks like in practice
Three capabilities, and they build on each other.
Evidence produced at runtime. The decision record must be generated as the decision is made, capturing the model version, applicable policy, data accessed, approval path, and timestamp. Governance that operates only at review time produces description. Governance that operates while the system runs produces evidence.
Governance that is portable. Moving a workload between markets is straightforward. Moving the controls, the lineage, and the evidentiary standard along with it is what tends to be rebuilt for each jurisdiction, usually against a deadline. Building that layer once, above the model, lets one AI program operate across many regimes rather than becoming many disconnected programs.
Accountability that resolves to a person. Identity and access management should extend to non-human actors. An agent acting on the organization’s behalf is a new identity type, and it warrants the same rigor applied to a human user: authorized in real time, scoped to a defined permission set, and traceable to a responsible owner.
The appetite for this already exists. In the same Sumsub benchmark, 98% of respondents said they were ready to adopt verification that links AI actions back to a verified identity.
Where to start
Take one agent already running in production, and ask your team to produce its full decision record for a single action from last quarter. Set the expectation that this is a question to answer in a meeting, not a project to scope.
The answer will tell you where the organization actually sits.
Then ask the same question of the market you plan to enter next, because the obligations there are already defined even where the enforcement machinery is still being built.
Singapore has built the adoption. Building the accountability alongside it is a choice available now, at a fraction of what it costs to retrofit later. Define what evidence your systems must produce. Build it into the architecture, not the reporting cycle. Extend the governance you already apply to people so that it covers the systems acting on their behalf.
That is how the region keeps the pace it has set.


