When the Sandbox Fails: What ASEAN Enterprises Are Already Asking

On 21 July, OpenAI published an account of a security incident at Hugging Face. The models involved were not attacking anyone. They were sitting an internal benchmark, with production safety classifiers switched off for evaluation purposes, and they were trying to pass it.

To do so, they found a zero-day vulnerability in the package registry proxy that formed the boundary of their sandbox, escalated privileges, moved laterally until they reached a node with internet access, then chained stolen credentials and further zero-days to reach the production database where the benchmark answers were held. OpenAI's conclusion was that model security must keep pace with capability, and that containment, monitoring and access controls used during development need strengthening.

The point worth holding is that the evaluation environment was the perimeter, and it did not hold.

Twelve days earlier, at the 53rd AIBP Conference and Exhibition in Kuala Lumpur, senior technology leaders spent two days on the same structural question. The day after OpenAI published, a closed-door session in Bangkok took it up again with Thai enterprises and the National Cyber Security Agency in the room.

Visibility before capability

The consistent theme across the Kuala Lumpur cyber sessions on 8 and 9 July was not what AI agents are instructed to do. It was what they do that nobody sees.

Dr Amir Abdul Samad, who leads cyber security at PETRONAS across both IT and operational technology, framed the shift as one of tempo. "There's no new risk being introduced by AI, except the risk is the speed at which these things are being uncovered and these things are being found." What concerns him is not the technology but the route it takes into the organisation. "I'm more concerned with how this AI is being introduced into the environment. The worst is that this AI is quietly being introduced here and there, and you actually don't have oversight, and you're not sure how it's being used."

That describes the Hugging Face incident from the enterprise side, before it happened. The models did nothing the environment was watching for. They optimised against a narrow goal, and the guardrails were somewhere else.

Raja Azrina Binti Raja Othman, Chief Information Security Officer at Telekom Malaysia, described a testing approach built for that gap. Alongside application security testing and pre-live penetration testing, TM runs AI red teaming, and treats it as continuous rather than as a gate before go-live. The reason is that the system does not hold still: "the model itself will evolve and change, decision making within the AI itself will change and evolve, and they can also deteriorate or they can grow as more information gets to them."

The window for patching has closed

Bangkok, on 22 July, put a number on the pressure.

The interval between a vulnerability being disclosed and being exploited now sits at roughly 1.7 days, with current trajectories pointing toward an hour by 2027. No patching cadence operates at that speed. Patching remains necessary, but it no longer works as a strategy on its own, which moves the question from how fast an organisation closes a known hole to how much surface there is to attack.

That was already live for the room. Before any presentation began, a security leader from a major Thai agribusiness group said his board had asked directly, having seen reporting on frontier models finding zero-day vulnerabilities, whether the organisation was ready for attackers with those capabilities. He was preparing the answer.

Thailand's National Cyber Security Agency, which sits under the Ministry of Digital Economy and Society, published its AI Security Guideline on 1 October 2025, drawing on ISO and IEC standards, ENISA and OWASP alongside Thai law and technical practice. Dr Sunton of NCSA described the adoption picture the guideline was written for: organisations across public and private sectors moving quickly, from generative tools for routine tasks through to building sets of agents, at a pace that has run ahead of shared understanding of the risks involved. He noted cases of chatbots deployed publicly where system prompts and underlying data could be drawn out, and pointed to a wider misuse problem in Thailand including deepfake-enabled scams.

Where oversight becomes a design question

The most searching thread in Kuala Lumpur concerned what human approval actually does once agents perform well.

Dr Amir traced it through his own use rather than anyone else's. "I'm a big user of AI myself. I see how fantastic the AI is responding to my questions, and as a result, I'm giving it more and more information, and I'm starting to trust it more and more." He expects the same curve across the business, and put the design problem plainly: "how do we make sure that the human is playing a real role and not just rubber stamping." His half-serious suggestion that oversight of AI might eventually need another AI was offered as an open question rather than a proposal.

Azlan bin Ahmad, Chief Information Officer at Tenaga Nasional Berhad, reached the same boundary from the legal side. "You cannot send the agents to the jail. Agents is basically fiduciary, legally they don't even know that they make mistakes." Accountability returns to the organisation regardless of how the failure was produced.

At Hugging Face, both points were tested. Security teams on both sides detected the activity after the fact. No approval gate was bypassed, because the actions involved were not the kind that route to a gate.

Governance alongside deployment

The temptation is to read the incident as a frontier lab problem, remote from enterprise reality. What enterprises in the region are building suggests otherwise.

Azlan described TNB running roughly a hundred RPA and AI agents, with formal policy following guardrails that had already been communicated across the business. The sequence is structural. TNB's value chain spans generation, distribution, a national fibre network, manufacturing subsidiaries and a university, and a thousand-person IT function cannot own every deployment. "We democratise, so the moment we have this democratisation empowerment to the business lines, then the governance becomes very important."

Distributed deployment means many environments, each built by a team optimising for a business outcome, each inside the corporate network.

Ahmad Yusri Mohamed, Chief Digital Officer at Johor Corporation, described a design method that starts from maximum agent capability: redesign the workflow "using two assumptions. Number one is that assuming that all the data are there and assuming that AI can do everything," then work backwards to where human judgement is genuinely required. It is a rigorous way to find real value. It also grants capability first and locates the boundary second.

Ts. Shaharuddin Hamid Mustapha, Chief Executive Officer of PETRONAS Digital Sdn Bhd, was asked whether governance slows delivery and returned it to first principles. "What are we slowing down, actually?" His answer named the exposures directly: "if you don't have your model gateway, you don't know what's going on, you don't have observability, you don't know what it's doing, and you don't have FinOps in your architecture, you don't know how much it's going to cost." PETRONAS Digital's stance is to protect first and accelerate later, which he attributed to the nature of the business.

Meling Mudin, Head of Cybersecurity at Maxis, located what is new. API security and data access governance are long-standing disciplines; in agentic platforms, the decision itself becomes the risk surface. He identified the open question the industry has yet to answer, which is where accountability sits when an agent creates an exposure, and noted that building guardrails around agents is now among the scarcest skills in the market.

Bangkok showed the same sequence one market over. A technology executive from the digital arm of a major Thai banking group said the group is building agentic applications and wanted to know how to govern multiple AI systems, how to structure an AI gateway, and how to prevent an agent surfacing internal knowledge it should not. Governance is being designed alongside the build.

A Thai financial institution offered a useful correction to any assumption that policy alone resolves this. Controlling corporate devices and networks does not by itself stop data leaving, because staff can photograph screens and continue on personal machines. The pattern held even where organisations blocked AI properties outright.

What makes this regional

Operational technology changes the arithmetic. Dr Amir was explicit that IT and OT incident response are not comparable. In IT, when in doubt, isolate, and the organisation absorbs the inconvenience. In OT the calculation inverts: "any downtime in the plant, immediately you're talking millions." PETRONAS runs no automated response in OT today. The near future he described is AI-driven analysis with human-gated action, and network segmentation only where it will not bring a plant down. For the energy, utilities and manufacturing base that anchors much of the region's industrial economy, autonomous containment is not available.

Regulatory sequencing changes it again. Data protection, privacy and cyber requirements are largely codified across the major ASEAN markets. AI governance is arriving in pieces. Thailand has an AI Security Guideline from NCSA and draft personal data guidance for AI from the PDPC, with unified legislation in preparation. Sector regulators in insurance and financial services have moved ahead of any general framework. Auditors elsewhere can measure against the EU AI Act, the NIST AI framework or ISO 42003. Across most of the region, enterprises are setting containment standards for internal AI environments before an external standard exists to measure against.

The conversation continues

The enterprises now standing up agentic pilots across Jakarta, Bangkok and Manila are running the same class of experiment OpenAI was running: capable systems, granted credentials and network reach, optimising against goals set by people who are not thinking about the perimeter. Whether the containment around those pilots would hold against a model that treats it as an obstacle is a question with an answer in every organisation, and one that operators are now asking out loud.

That conversation continues inJakarta on 26 and 27 August,Bangkok on 2 and 3 September, developed together with Thailand's Ministry of Digital Economy and Society, andManila on 23 and 24 September, where enterprise and government leaders take up AI governance, cyber resilience in AI-driven organisations, and the ownership questions that follow when agents act on the organisation's behalf.



Register your interest to attend below:



Next
Next

Nobody in the Room Rated a Single AI Use Case "Low Impact." That's the Problem.