Tackling "Shadow AI" in the ASEAN Context
The use of unauthorized generative AI tools by employees, termed "shadow AI," poses a substantial cybersecurity threat to businesses by exposing sensitive data. For ASEAN, the challenge is not just about policy but about the foundational elements of digital trust and.

The Governance Gap in Corporate AI
The cybersecurity firm Kaspersky has drawn attention to the growing corporate risk of "shadow AI," as reported by the Bangkok Post. This phenomenon involves employees using generative AI tools, often without their employer's approval or knowledge. While seemingly harmless, this practice creates significant vulnerabilities. When employees input sensitive corporate information into public AI models, that data can become part of the model's training set, risking its exposure. This unauthorized data flow complicates corporate governance and expands the potential surface for cyberattacks, creating new entry points for malicious actors.
The issue is not the technology itself, but its ungoverned application. Companies are struggling to create policies that balance the productivity gains from AI with the imperative of data security. The rapid adoption of these tools by individuals often outpaces the ability of corporate IT and security departments to establish safe usage guidelines. This gap between employee behavior and corporate policy highlights a fundamental challenge in managing the modern digital workplace. For businesses in ASEAN, where digital transformation is a priority, the risk is pronounced. As companies encourage digital adoption, they must also build the institutional capacity to govern new technologies effectively. Without clear frameworks, the very tools meant to enhance competitiveness could become sources of corporate weakness.
Sovereignty, Trust, and Infrastructure
The discussion around "shadow AI" connects to a deeper theme outlined in "ASEAN Rising": the development of a secure and sovereign digital economy. The book argues that true digital sovereignty is not just about developing local AI models. The real test is in establishing control over the underlying digital infrastructure. As the book notes, the core issue is "who controls the compute, the data layer and the digital identity rails that sit underneath everyday economic life." The "shadow AI" problem is a practical example of this principle. When employees use external AI platforms, they are ceding a degree of control over corporate data to third parties, often outside their own country's jurisdiction.
This is where the concept of trust becomes central. For employees to avoid using unauthorized tools, they need access to trusted, company-sanctioned alternatives that are just as effective. For businesses to operate securely, they need to rely on digital infrastructure and identity systems that are robust and verifiable. Building this trust is an immense undertaking that involves both technology and policy. It requires investment in secure cloud infrastructure, the development of reliable digital identity systems, and the implementation of data governance standards that are respected across the organization. The talent to manage these systems is also a necessary component. Addressing the "shadow AI" risk is therefore not merely a matter of updating an IT policy; it is part of the larger project of building a trustworthy and resilient digital ecosystem in the region.
What to watch
Observe how ASEAN companies and governments move beyond high-level AI strategies to implement tangible governance frameworks. The focus should be on the development of enterprise-grade AI tools, investment in secure domestic cloud infrastructure, and the establishment of clear data residency and privacy regulations. The success of these efforts will determine whether the region can effectively manage risks like "shadow AI" and build a truly sovereign digital future.


