The Enterprise AI Question Nobody Wants to Answer First: "Who Is Actually Accessing What?"

When enterprise leaders in Bangkok sat down behind closed doors to talk about governing Enterprise AI without slowing innovation, the conversation didn't start with policy. It started with a harder question: can you tell who is accessing what, through which version of which model, right now, inside your own organisation?

For most of the room, the honest answer was no.

The access question nobody had fully answered

Employees are already using public AI tools without IT's visibility, and that is where the discussion opened. The technical detail one participant raised is the uncomfortable part: distinguishing a public, unprotected AI interaction from a governed one, initiated by the same user, is genuinely hard. It requires inspecting request headers, tracing traffic through proxy chains, and applying guardrails based on what is actually being accessed rather than assuming a single policy covers every path.

That complexity compounds. Enterprises are not securing one model. They are securing multiple models, multiple versions of each, and a mix of enterprise-grade and open-source deployments, each carrying a different risk profile and requiring different guardrails. Without a way to see which user is touching which version of which model, a governance policy is a statement of intent. And that's often the more forgiving problem. Most controls only reach company-issued devices on the corporate network. An employee can just pull out a personal phone and photograph a screen, and every guardrail built into the corporate stack becomes irrelevant. 

It's a pattern AIBP has tracked closely: recent closed-door workshops across the region found that nearly 79% of PII leaks into public AI tools come from employees, not external attackers, which is exactly the kind of blind spot this room was trying to close.

Two doors, one failure

That same blind spot is what turns a data leakage problem into a private application problem, because they're really the same failure showing up at different doors. Sensitive data pasted into a public AI tool and an unauthorised user reaching a private AI application both come down to the same missing control: verifying who's requesting access and what they're entitled to before letting the request through.

Santanu Dutt, Vice President and Head of Technology for Asia-Pacific and Japan at Zscaler, added that enterprises often underestimate how many small-looking data flows are also attack surfaces. The examples he offered were deliberately unglamorous. An Australian retail chain facing rising physical security incidents equipped staff with always-on shoulder-worn recording devices, streaming footage over Wi-Fi as evidence for police. An Indian ticketing platform validates every scanned ticket against the cloud the moment it is checked at a venue gate. Neither looks like an AI system. Both are live data pipelines that, left unmanaged, create exactly the exposure enterprises describe when they talk about leakage into public AI.

Zscaler's own path, from securing internet access, to securing private application access, to securing cloud AI environments and the devices generating the data, follows the same logic. The access control discipline applied to a factory sensor or a ticket scanner is the discipline an AI system needs. Zero Trust is not a separate initiative for AI. It is the existing one, extended.

The same blind spots, now weaponised

That logic also determines whether an organisation is ready for what is coming at it. Attackers are already using AI to scale phishing and supply chain attacks, and the question put to the room was blunt: are Thai organisations using AI to defend, or only being targeted by it? Every blind spot discussed earlier, unseen shadow AI usage, ungoverned data flows, unsecured private applications, is a foothold an AI-powered attacker exploits faster than a human one. Visibility and access control are not only governance hygiene. They are the defences that blunt automated attacks.

One layer, not four frameworks

The idea that kept resurfacing was that enterprises do not need a different governance framework for every model, version and deployment type. They need one consistent layer that sees who is accessing what, everywhere, and applies the right guardrail at the point of access.

The room was clear-eyed about what that costs. A layer that sits between users and the tools they want is a layer someone has to run, and someone has to answer when a business unit needs a model it does not yet cover. That is the real content of governing without slowing innovation: not whether to build the layer, but who owns the exceptions once it exists.

As one participant put it, the industry has spent years taking baby steps toward that layer individually. What is different now is that enterprises are describing it as shared work, and treating governance as a value driver rather than a blocker.

Two things make that layer harder to finalise right now. Thailand's own AI Act is still taking shape, and until enterprises have clarity on what it will actually require, any access layer they build is aimed at a moving target rather than a fixed rulebook. At the same time, the population that layer has to govern is changing. It is no longer just employees requesting access. It is AI agents acting on their behalf, initiating requests, chaining tasks together, and doing so at a volume no manual review process can keep pace with. A governance layer built only for human users will not survive contact with agentic AI at scale. It has to authenticate and constrain agents with the same rigour it applies to people, before that shift moves from pilot to production.

For Thai enterprises moving from AI pilots into production over the coming year, the question is not whether the framework exists on paper. It is whether anyone can see what the framework is meant to be governing.



This article draws on discussion from AIBP's closed-door executive roundtable in Bangkok, "Securing the AI Frontier: Governing Enterprise AI Without Slowing Innovation," co-hosted with Zscaler. The conversation continues at the 55th AIBP Conference & Exhibition Thailand, 2 and 3 September 2026 in Bangkok, endorsed by Thailand's Ministry of Digital Economy and Society. Registration is open.

Next
Next

Enterprise Innovation in Indonesia 2026: Building the Foundation for the Next Phase of Digital Transformation