Much of America’s 2026 AI debate has been about who gets to write the rules. On a Singapore stage, WIZ.AI’s Robin Li was already working through a different question: governed how, once an agent is actually let loose on a customer, a payment, or a business system — and a widening body of 2026 data suggests most enterprises cannot yet answer it.
Washington spent much of 2026 fighting over jurisdiction: whether AI should answer to one federal standard or to the patchwork of state laws that had already reached 29 states by July, with President Trump pushing a “ONE RULE” executive order to preempt them [1][2]. That fight has been almost entirely about who holds the pen. Robin Li, Senior AI Strategy & Partnerships Director at WIZ.AI, was working a narrower and more practical version of the same question in front of a Singapore audience at Tech in Asia Conference 2026: not which authority governs AI, but what a workable governance standard for a single AI agent actually looks like once it is deployed — and a widening body of 2026 data suggests most enterprises still cannot answer that for their own agents.
The panel, and the point it was making
More than 2,000 people filled the Sands Expo and Convention Centre on September 15–16 for the 15th edition of Tech in Asia Conference, organized around the theme “Lead the Enterprise AI Era” [3]. The sessions leaned into deployment mechanics — infrastructure, workflow integration, talent, return on investment — rather than model capability, reflecting what conference materials described as a region that “continues to outpace the global average in AI adoption” even as most businesses struggle to move past experimentation [3].
That struggle framed the panel “Eleven markets, one strategy: Real challenges of building AI for Southeast Asia,” where Li appeared alongside Irzan Raditya of Kata.ai and Shauna Bull of Sierra, moderated by Sue Stephens of Bluente [4]. The panel’s framing was pointed: the model may be global, but the production last mile is always local [4]. Li’s slides posed a question that inverts how most enterprises evaluate agentic AI: not whether a model is intelligent enough, but whether the workflow around it is governable enough [4].
The governance gap has a body count now
Through most of 2026, that question stopped being theoretical. A joint Cloud Security Alliance and Token Security study published in April found that 65% of organizations had experienced at least one cybersecurity incident caused by an AI agent in the prior year — 61% involving exposure of sensitive data, 43% causing operational disruption, and 35% resulting in direct financial loss [5]. The study’s more uncomfortable finding was about cause rather than symptom: the dominant failure mode was not agents malfunctioning, but agents functioning exactly as built, inside permissions that were simply too broad. Sixty-three percent of organizations told researchers they cannot enforce purpose limitations on what an agent is allowed to touch, and 60% said they cannot terminate a misbehaving agent once it is running [5].
A separate VentureBeat Pulse research wave from July reached a similar place from a different angle. Among enterprises that had already invested in securing AI agent identities — the standard first move in most agent security programs — 80% still could not contain a compromised agent, and only 18% could isolate their highest-risk agents even with per-agent credentials in place [6]. The researchers’ own framing of the gap is direct: giving an agent scoped credentials does not bound the blast radius when those credentials are misused; sandboxing does [6]. Fifty-three percent of respondents in that wave had already had an agentic security incident or near-miss. Gartner’s own projection sits on top of this pattern rather than apart from it: by 2027, 40% of enterprises will demote or decommission autonomous AI agents, and the trigger will typically be a governance gap discovered only after a production incident, not a model limitation discovered in testing [7]. Gartner’s Shiva Varma traces the failure to a false binary — agents treated as either locked down or fully trusted — when what enterprises actually need is governance that scales with how much autonomy an agent has actually been given [7].
Singapore’s own regulator had already reached the same conclusion, in the same city, eight months before Li took the stage. In January, the Infocomm Media Development Authority released an updated Model AI Governance Framework specifically for agentic AI, announced by Minister Josephine Teo at the World Economic Forum in Davos [8]. Its four requirements read like a checklist version of what would appear on WIZ.AI’s slides later that year: risk assessment that limits an agent’s autonomy, tool access, and data availability to what a given use case actually needs; human checkpoints for significant decisions; technical controls and access restrictions tested across the agent’s full lifecycle; and transparency that lets end users understand what they are dealing with [8]. IMDA frames the underlying problem in almost identical terms to the security researchers — agents introduce risks distinct from ordinary software, including unauthorized action and automation bias, that existing AI governance frameworks were not built to catch [8]. Unlike Washington’s fight over which government gets to hold the pen, Singapore’s framework does not attempt to settle governance with a single uniform rule; it scales requirements to how much autonomy a given agent actually holds — the same principle Gartner arrived at independently from enterprise failure data [7].
What WIZ.AI put on the same stage
WIZ.AI’s own framework arrives at a nearly identical structure from the deployment side rather than the regulatory or research side. Before any agent can act, Li’s material poses four questions: is the outcome’s success clear and measurable, are the data, tools, and permissions bounded, what happens if the agent is wrong, and can the system confirm the task was actually completed [4]. Those four questions gate a staged progression — observe, recommend, act with approval, autonomous within a proven boundary — that maps closely onto Gartner’s recommended classification of agents into Observe, Advise, Act with Approval, and Act Autonomously tiers [7], and onto IMDA’s emphasis on bounding autonomy and tool access before an agent is trusted with more [8]. Conversational autonomy, as Li put it, is not execution authority [4].
The panel’s second argument was about production rather than policy. A model can score well in evaluation and still fail on a live customer call, because the call path runs through more than the model: carrier conditions, audio codecs and packet loss, speech recognition across accent and code-switching, the model’s own reasoning, the business systems the agent has to act inside, and the handoff to a human when something falls outside the agent’s authority [4]. WIZ.AI’s material treats each of those six links as something to validate independently, market by market, rather than assuming a model that performs well in one geography will perform the same way in the next — a version, at the level of a single phone call, of the same purpose-binding and containment problems the CSA and VentureBeat data describe at the level of an enterprise’s entire agent fleet.
That insistence traces back to how the company built its Southeast Asia footprint in the first place. Founded in Singapore in 2019 by Jennifer Zhang and Jianfeng Lu, WIZ.AI’s founding principle was to put R&D, product, and delivery teams into each market before sales teams arrived — the inverse of the more common playbook of centralizing a product and selling it outward [9]. The company has since built proprietary models for dialects including Singlish, Bahasa Indonesia, and Tagalog, and says it cut data annotation time from four months to three weeks through crowdsourcing, work that Zhang has described in granular terms — down to how a name is pronounced differently market to market, citing Thailand as a specific case [9]. WIZ.AI now operates across Southeast Asia, East Asia, the Middle East, Latin America, and the US, and closed a Series B round led by SMBC Asia Rising Fund with participation from Beacon Venture Capital and SMIC SG Holdings to extend that same local-first approach into new markets [10]. Founder and CEO Jianfeng Lu framed the raise as validation of that strategy directly: “This funding endorses our ‘local-first’ strategy… we are excited to deepen market penetration and expand into new frontiers like Latin America” [10].
The gap Li has been describing for a year
None of this was a new argument for Li. In a September 2025 conversation on the On Call with Insignia podcast, he had already pointed to the same failure pattern from the buyer’s side of the table, citing an MIT finding that 95% of organizations were getting zero return from their AI efforts [11]. His explanation was structural rather than technical: “the builders are successful because their AI products are always focusing on narrow use cases,” he said, while “the buyers, the big companies, the enterprises, are always asking for more complex solutions” that have to sit inside existing workflows and change how employees actually work [11]. A narrow pilot can clear a demo; it is the integration into a real workflow, with real handoffs and real failure modes, where most of that 95% gets stuck — the same last-mile problem the Tech in Asia panel put a name to a year later. Li also pointed to how unevenly the underlying comfort with AI adoption is distributed even within the region, contrasting China’s top-down push with Southeast Asia’s more wait-and-see posture, and framing his own two decades in enterprise tech as reason to keep watching how each market actually behaves rather than assuming one playbook travels intact [11].
The organizational shift underneath the framework
The panel’s closing argument moved past the technical checklist to something closer to an operating model. Building a “truly AI-native company,” in Li’s framing, means treating hiring, organizational structure, and decision rights as things to be redesigned around AI working alongside people, rather than a layer bolted onto an unchanged organization [4]. Certis’s Ng Tian Beng, speaking elsewhere at the same conference about deploying AI across a 25,000-person workforce, and GoTo Group’s Hans Patuwo, discussing AI’s role in ecosystem growth, were working through versions of the same problem from opposite ends of enterprise scale [3] — evidence that the governance-before-autonomy argument is not confined to one vendor’s panel.
Washington’s debate has largely been fought over jurisdiction: whether one federal standard should override a patchwork of 29 state regimes covering companion chatbots, data centers, and consumer protection [1][2]. What the incident data, Singapore’s regulator, and WIZ.AI’s own deployment checklist converge on is a different axis entirely — not which government writes the rule, but whether the rule scales to what a given agent is actually authorized to do. An organization that cannot specify, in advance, what an agent is allowed to touch, how a failure gets caught, and who is on the other end of the handoff when it does, will not be rescued by winning the argument over federal versus state jurisdiction. The bottleneck enterprises are hitting in Southeast Asia’s eleven markets, and in the broader agentic AI market the CSA and VentureBeat data describe, was never really about whose rulebook applies. It is about whether there is a rulebook, scaled to risk, that anyone is actually enforcing.
References
- “Where State AI Legislation Stands Half Way Into 2026,” Tech Policy Press, 2026. https://www.techpolicy.press/where-state-ai-legislation-stands-half-way-into-2026/
- “State AI Law Moratorium Omitted From 2026 Defense Bill, But Trump Is Preparing ‘ONE RULE’ Executive Order,” StateScoop, 2026. https://statescoop.com/state-ai-law-moratorium-omitted-2026-defense-bill-trump-eo/
- “Tech in Asia Conference Returns to Singapore for 15th Edition as Enterprise AI Takes Centre Stage,” PR Newswire, September 2026. https://www.prnewswire.com/apac/news-releases/tech-in-asia-conference-returns-to-singapore-for-15th-edition-as-enterprise-ai-takes-centre-stage-302878625.html
- WIZ.AI, LinkedIn post recapping the panel “Eleven markets, one strategy: Real challenges of building AI for Southeast Asia,” Tech in Asia Conference 2026. https://www.linkedin.com/posts/wiz-ai_tech-in-asia-conference-activity-7507731067655606272-nbEP
- “More Than Half of Organizations Experience AI Agent Scope Violations,” Cloud Security Alliance, April 2026; “AI Agent Security Incidents Hit 65% of Firms in 2026,” Kiteworks. https://cloudsecurityalliance.org/press-releases/2026/04/16/more-than-half-of-organizations-experience-ai-agent-scope-violations-cloud-security-alliance-study-finds
- “Four of Five Enterprises That Secured AI Agent Identities Still Can’t Contain One That Goes Rogue,” VentureBeat, 2026. https://venturebeat.com/security/four-of-five-enterprises-that-secured-ai-agent-identities-still-cant-contain-one-that-goes-rogue
- “Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure,” Gartner, May 26, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
- “Singapore Launches New Model AI Governance Framework for Agentic AI,” Infocomm Media Development Authority, January 22, 2026. https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai
- “Seven Years of AI Innovation from Talkbots to AGI: How WIZ.AI Built a Global AI Transformation Platform for Enterprise from Singapore,” Insignia Business Review, February 19, 2026. https://review.insignia.vc/2026/02/19/wiz-ai/
- “Voice Agent Pioneer WIZ.AI Raises Tens of Millions in Series B to Scale Enterprise AGI Solution Globally,” PR Newswire, 2026. https://www.prnewswire.com/apac/news-releases/voice-agent-pioneer-wizai-raises-tens-of-millions-in-series-b-to-scale-enterprise-agi-solution-globally-302604934.html
- “Driving Conversational AI Adoption from China to Singapore Then the World with WIZ.AI Senior Director of AI Strategy and Partnerships Robin Li,” On Call with Insignia Ventures podcast, as recapped in Insignia Business Review, September 25, 2025. https://review.insignia.vc/2025/09/25/wiz-ai-robin-li/
Paulo Joquiño is a writer and content producer for tech companies, and co-author of the book Navigating ASEANnovation. He is currently Editor of Insignia Business Review, the official publication of Insignia Ventures Partners, and senior content strategist for the venture capital firm, where he started right after graduation. As a university student, he took up multiple work opportunities in content and marketing for startups in Asia. These included interning as an associate at G3 Partners, a Seoul-based marketing agency for tech startups, running tech community engagements at coworking space and business community, ASPACE Philippines, and interning at workspace marketplace FlySpaces. He graduated with a BS Management Engineering at Ateneo de Manila University in 2019.