Posted on Leave a comment

Say it out loud: AI is forcing companies to explain themselves

Tell someone, “I’m going to make pancakes,” and see how they interpret it in their head.

In New York, they’ll picture a fluffy stack with maple syrup. In Amsterdam, a thin, buttery pannenkoek the size of the plate. In Singapore, perhaps min jiang kueh, dense with crushed peanuts. In Sydney, ricotta hotcakes at weekend brunch.

Same sentence. Four completely different plates of food. The words didn’t carry the meaning — the listener’s context did. 

Business communication has quietly relied on this trick for decades. We say something general, and the audience fills in the rest. It worked because the audience was human.

It is about to stop working because, as Cloudflare’s CEO reported in June, bot traffic surpassed human traffic on the internet for the first time.

Humans fill gaps, AI doesn’t

Here is what happens when a human visits a company website. They see a cybersecurity client here, a crisis project there, a media training page somewhere else. And they conclude, without being told: these people could handle our data breach.

Nobody wrote that sentence anywhere on the site. The visitor inferred it.

Humans connect dots, fill gaps and give the benefit of the doubt. Most corporate websites are built on the assumption that we will.

AI does not do this.

When someone asks ChatGPT, Gemini or DeepSeek what a company does — and, increasingly, that is the first thing a prospective customer, investor or journalist does — the model can only work with what was actually said. If you never wrote, “We handle data-breach communications,” then, as far as the machine is concerned, you don’t.

AI cannot smell competence. It cannot read between the lines. There is no benefit of the doubt. Unsaid means invisible.

Also Read: Why AI literacy may become the new financial literacy

We tested this on ourselves

I run a PR consultancy in Singapore. For years, we described ourselves the way most agencies do: “B2B technology PR.” Accurate and, today, almost meaningless. It relies entirely on the reader to work out what that means for them.

When we rebuilt our website to make the business more legible to AI systems this year, we had to undertake an intense exercise: saying exactly what we do, out loud, in words a machine cannot misread.

In doing so, we discovered we had been describing ourselves incorrectly. We don’t just do B2B technology PR; what we actually do, over and over, is help international technology companies enter Southeast Asian markets. Market-entry PR had been the agency’s pattern for the past decade — and we had never once said it plainly.

Our work hasn’t changed. How we describe it has. Once we clearly articulated our proposition on the website, within weeks, AI tools began describing us accurately and recommending us for the work we actually do. Machine readers need us to be as clear as possible.

Conducting that exercise is harder than it sounds. Try writing down what your company does without using the words “solutions,” “holistic,” “end-to-end” or “innovative.” Most executive teams cannot do it on the first attempt.

Ambiguous communication is rarely intentional. It is a byproduct of how humans communicate: both sides meet halfway, each filling in what the other has left out. Machines miss what’s implied.

Analysts have noticed

This year, Gartner made a prediction that startled the communications industry: that by 2027, mass adoption of AI tools as a replacement for traditional search will double PR and earned media budgets.

The rationale is this: as ChatGPT traffic grew 608 per cent year on year, evidence accumulated that AI answer engines overwhelmingly favour credible, non-paid sources, and Gartner argues that making a company legible to these systems is a communications skill, not a technical one.

Yet the industry’s own data confirms the scramble: Muck Rack’s State of PR 2026 survey found 73 per cent of PR professionals now call generative engine optimisation important to their strategy — while 29 per cent admit nobody at their organisation owns it.

In all honesty, that headline figure has been challenged as more marketing than research, and the sceptics, like me, have a point. Whether budgets double is anyone’s guess.

But the underlying shift is not in dispute: ambiguity has become a tax. AI systems cannot recommend what they cannot parse.

Also Read: Southeast Asia in the 2026-2030 world order: Trade, chips, AI, and capital

In Southeast Asia, this problem multiplies

Here is where it gets interesting for this region, because the pancake problem does not only apply to breakfast.

In my experience, “fintech” often signals something different in Jakarta — consumer, mass-market, inclusion-driven and reputationally loaded — than it does in Singapore, where it is more likely to mean infrastructure and institutions.

“Compliance” carries a different weight in Manila than in Sydney. “Enterprise” describes a different kind of buyer in Bangkok than in Kuala Lumpur. Southeast Asia is not homogeneous: there are widely varied vocabularies and sets of assumptions.

It is not one market for machines either. Different countries are now building their own AI tools, trained on different information and operating under different rules. The AI a buyer consults in Indonesia will not describe your business in the same way as the one a buyer consults in Australia.

Regional companies have always known that trust must be earned market by market. Now clarity must be, too.

Machines don’t take hints

For decades, vague language was permissible because humans are generous readers. Now, the first impression of your company is increasingly formed by a machine — and the machine only knows what you say about your company out loud.

So say it.

Plainly, specifically and in the words each market actually uses.

Ask the AI tools what they think you do. If the answer is wrong, the fault may not lie entirely with the machine. You may simply not have articulated the business clearly enough.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Say it out loud: AI is forcing companies to explain themselves appeared first on e27.

Posted on Leave a comment

Why Dropbox refuses to pick a side in the ChatGPT-Claude-Gemini fight

Kenny Takeuchi, VP (APJ Sales) at Dropbox

Ask most people what Dropbox does, and they’ll tell you it’s where they store files. Ask Kenny Takeuchi, the company’s newly appointed VP of APJ Sales, and he’ll tell you that’s precisely the problem the tech firm is trying to move past.

As ChatGPT, Claude and Gemini become the starting point for how knowledge workers actually get things done, Dropbox has made a calculated decision: rather than building its own AI model to compete with the giants, it’s positioning itself as the connective tissue between them.

Also Read: Do you know what ChatGPT is saying behind your back?

On July 14, the company announced expanded integrations across all three major AI platforms –Dropbox x ChatGPT, Dropbox x Claude, and Dropbox x Gemini Spark. The move reflects a broader strategic bet on becoming what Takeuchi calls the “trusted context layer” for AI-enabled work.

It’s a phrase that sounds like corporate jargon until you unpack what it actually solves.

The problem nobody’s talking about

Here’s the uncomfortable truth about generative AI in the enterprise: the output is often brilliant, but it’s also disposable. A sales team drafts a renewal proposal in ChatGPT, a marketer brainstorms campaign copy in Claude, a developer scaffolds code in Gemini, and then what? The file lives in a chat thread. Nobody else on the team can find it. There’s no version control, no permissions structure, no link back to the original contract or pricing sheet that informed it in the first place.

“AI is only as useful as the information it can work from,” Takeuchi says. “If the underlying content is fragmented, outdated or disconnected from everyday workflows, even the most capable AI models will struggle to produce reliable results.”

This is where Dropbox’s pitch gets interesting. Instead of asking organisations to abandon the tools they’ve already invested in, such as the AI platforms, shared drives, and legacy systems, Dropbox is threading itself through the gaps.

For instance, a sales rep in Singapore working on a renewal proposal in ChatGPT doesn’t need to hunt down the latest contract manually. They can pull it directly into the conversation from Dropbox, and once the AI-assisted work is done, push it back into Dropbox so it becomes part of the team’s shared record, not something trapped forever in a chat window.

“That’s an important distinction,” Takeuchi explains. “Our goal isn’t simply to help AI generate content. It’s to help teams turn AI activity into work that can be saved, shared, reviewed and reused.”

Betting on an open ecosystem, not a single bet

What’s notable about Dropbox’s approach is what it isn’t doing. It isn’t racing to build a proprietary foundation model. It isn’t asking customers to pick a side in the ChatGPT-versus-Claude-versus-Gemini contest playing out across the industry. Instead, it’s wagering that enterprises will never actually consolidate around one AI tool at all.

“The reality is that enterprises aren’t standardising on a single AI tool,” Takeuchi says. “Different teams use different tools for different kinds of work, and that’s likely to remain true for the foreseeable future.”

Also Read: Beyond the cloud: Entering the Web3 horizon for greater security

That thinking shapes how the three integrations are designed, and they’re deliberately not identical. The ChatGPT integration leans into organising files, generating shareable links and executing multi-step workflows. The Claude integration, spanning Claude, Claude Cowork and Claude Code, is built for more technical, developer-adjacent tasks. Gemini Spark’s integration focuses on accessing and sharing files within Google’s newer agentic workflows.

“Some help people find and preview content, others support technical workflows, and others help turn AI-generated output into something that can be saved, shared and built on by a team,” Takeuchi notes. “The value isn’t that every integration does the same thing; it’s that together they support the different ways people work with AI across an organisation.”

Governance without reinventing the wheel

For enterprises, particularly in security-conscious markets across Asia Pacific, the obvious anxiety is data governance. Who sees what, and who decides?

Takeuchi is careful to draw a clean line here: Dropbox governs the content itself, while the AI platforms manage how their own connectors are deployed inside an organisation. Crucially, users only ever see what they already had permission to access in the first place.

“That means organisations can introduce AI using the governance models they already trust, rather than creating entirely new ones,” he says.

This layered structure also gives Dropbox room to accommodate wildly different risk appetites across the region, a genuine consideration given how differently AI adoption is unfolding across APJ.

Japan’s caution, Southeast Asia’s speed

Having spent two decades building his career in Japan with stints at Adobe, Salesforce Japan, Databricks Japan and DocuSign Japan, Takeuchi is unusually well-placed to speak to the region’s contradictions.

“It’s inaccurate to think about APJ as a single market,” he says bluntly. “While the appetite and curiosity for AI is remarkably consistent across the region, the pace of adoption and the reasons behind it can be very different.”

Japan, he explains, has the technical capability to move fast but often chooses deliberate, governance-first rollouts. Markets like Singapore and India, by contrast, are frequently more focused on scaling initiatives and proving business value quickly. “Neither approach is better than the other,” he adds. “They’re simply different starting points.”

That nuance extends to how Dropbox packages its pitch: some customers deploy AI broadly across the workforce from day one, others start with a narrow, tightly controlled set of connectors. “Our approach supports both,” Takeuchi says. “Ultimately, our goal is to give organisations flexibility. They should be able to adopt AI at a pace that reflects their own business priorities and risk tolerance, not ours.”

A familiar playbook, applied differently

Takeuchi’s time at DocuSign offers a useful parallel for where he sees Dropbox heading. E-signature was the entry point, but customers soon started asking about the entire agreement lifecycle: what happens before and after a document gets signed.

Also Read: Gemini’s SEA growth puts local-language AI at the centre of the assistant race

He sees the same pattern repeating. “For years, storing files was the primary job. Today that’s almost expected,” he says. “The harder challenge is helping organisations keep knowledge connected as work spreads across documents, conversations and an increasing number of AI tools.”

Dropbox says it’s seeing the strongest early traction in construction, technology and professional services, the industries that generate and shuffle enormous volumes of documentation daily and where the cost of fragmented knowledge is acutely felt.

What success actually looks like

For a newly appointed regional sales leader, the obvious yardstick is revenue growth, and Takeuchi doesn’t pretend otherwise. But he’s framing the next 12 to 18 months around something less easily quantified.

“The measure I’ll be paying closest attention to is whether customers feel work has become less fragmented,” he says. “If people can work seamlessly without worrying about where information lives, whether they have the latest version or how to share it with colleagues, then we’ve created meaningful value.”

Whether that ambition translates into a durable market position, or simply a well-argued footnote in the broader AI platform wars, will depend on whether enterprises actually want a “context layer” at all, or whether they’ll eventually demand the AI giants solve this problem themselves. For now, Dropbox is betting that the fragmentation is the real opportunity, not a temporary inconvenience.

The post Why Dropbox refuses to pick a side in the ChatGPT-Claude-Gemini fight appeared first on e27.

Posted on Leave a comment

Bukalapak stays EBITDA-positive as gaming powers first-half revenue growth

Bukalapak’s latest results show a company still trying to prove that its post-marketplace reinvention can work.

The Indonesian listed technology firm reported revenue of US$88.6 million in the second quarter of 2026, while first-half revenue rose 29 per cent year on year to about US$221.6 million. More importantly for investors who have grown wary of loss-making consumer internet companies, Bukalapak remained adjusted EBITDA-positive for the second consecutive quarter.

Adjusted EBITDA stood at roughly US$332,000 in Q2. For the first six months of the year, the company posted positive adjusted EBITDA of about US$554,000, compared with a loss of around US$1.9 million in the same period last year. The swing, worth about US$2.4 million, is modest in absolute terms but symbolically important for a company that has spent the past few years moving away from growth-at-all-costs towards tighter cost control and higher-quality revenue.

Also Read: Bukalapak to shift focus from physical goods to virtual products in strategic overhaul

“Maintaining a positive adjusted EBITDA throughout the first semester of 2026 reflects the sustained progress of the transformation we are undertaking,” said Victor Putra Lesmana, Director of Bukalapak. “Amid ongoing economic uncertainty, we remain focused on operational discipline, improving revenue quality, and developing sustainable business across all segments.”

Gaming becomes the growth engine

The clearest driver of Bukalapak’s first-half performance was gaming.

The segment generated US$77 million in revenue in the second quarter. For the first half, gaming revenue grew 42 per cent year on year to around US$193.9 million, supported by the company’s international expansion. The business also recorded positive adjusted EBITDA of about US$388,000 in the second quarter.

That matters because gaming has become one of Southeast Asia’s more durable digital consumption categories, even as e-commerce and fintech face margin pressure. The region has a young mobile-first population, high usage of digital wallets, and a large base of players who spend small but frequent amounts on in-game items, vouchers, and credits. For platforms that can manage payment flows and distribution efficiently, gaming can offer better margins than traditional online retail.

Bukalapak’s shift reflects a broader pattern among Southeast Asian tech companies. After years of chasing gross merchandise value and user growth, many are now prioritising verticals where they can monetise more predictably. In Bukalapak’s case, gaming appears to be doing much of the heavy lifting, contributing the majority of first-half revenue and helping support the group’s adjusted EBITDA.

The company did not break down the international markets powering the gaming segment’s expansion, but the direction is clear: Bukalapak is no longer merely an Indonesian e-commerce story. It is increasingly a portfolio of digital businesses, with gaming, investment products, retail, and services for small merchants sitting alongside what remains of its original marketplace identity.

Mitra shrinks, but margins improve

The performance of Mitra Bukalapak, the company’s small-merchant services arm, was more nuanced.

Revenue in the segment fell to US$8.4 million in the second quarter from US$10.4 million a year earlier. For the first half, Mitra revenue declined 27 per cent year on year as Bukalapak became more selective about the products it pushes through the channel.

On the surface, that decline looks troubling. Mitra was once central to Bukalapak’s pitch: a way to digitise Indonesia’s vast network of warungs, kiosks, and neighbourhood merchants. These small retailers remain crucial to the country’s consumer economy, particularly outside major cities where informal trade still plays a large role.

Also Read: Bukalapak responds to TEMU acquisition report following recent share price increase

But Bukalapak is now arguing that smaller, more profitable revenue is preferable to larger but lower-margin sales. The numbers give some support to that claim. Mitra’s contribution margin grew 48 per cent year on year to about US$1.6 million in the second quarter. Its adjusted EBITDA also turned positive at roughly US$443,000, compared with a loss of about US$499,000 in the same period last year.

That suggests the company is cutting back on weaker products and focusing on areas where it can generate healthier returns. For Southeast Asian platforms serving offline merchants, this is a familiar challenge. Acquiring and retaining small shops is expensive, usage can be inconsistent, and many merchants are highly price-sensitive. The winners are likely to be those that provide practical services (payments, inventory, digital goods, financing, or procurement)  without relying too heavily on subsidies.

Investment business gains ground

Bukalapak’s investment segment, through BMoney, also continued to grow from a smaller base.

First-half revenue rose 68 per cent year on year to about US$2.4 million, from US$1.4 million. Contribution margin increased 62 per cent to around US$831,000, supported by assets under management of more than US$332 million.

The investment business is still small compared with gaming, but it sits in a market with long-term potential. Retail investing has become more accessible across Southeast Asia, helped by digital onboarding, low minimum balances, and growing familiarity with mutual funds and other wealth products. In Indonesia, where bank penetration and capital market participation remain relatively low compared with more developed economies, digital investment platforms have room to expand if they can build trust and manage regulatory expectations.

Bukalapak’s challenge will be to show that BMoney can become more than an ancillary service. The investment segment can deepen customer engagement and improve monetisation, but it also operates in a competitive space where users can switch easily between apps.

Retail remains under pressure

Bukalapak’s retail segment showed the effect of a more cautious operating approach.

The business recorded second-quarter revenue of around US$3.3 million. First-half revenue came in at about US$7.7 million, down 14 per cent from roughly US$9 million a year earlier. The company said it is optimising its product pipeline, managing inventory, and selectively expanding its outlet network.

That language points to a more disciplined retail strategy, but also to the limits of physical or inventory-heavy expansion in the current environment. Across Southeast Asia, retail-tech models have had to deal with thin margins, supply chain complexity, and uneven consumer demand. For Bukalapak, retail is unlikely to be judged purely on top-line growth if the company can demonstrate better inventory control and lower operating drag.

Overall, Bukalapak’s first-half contribution margin reached about US$9.5 million, up 12 per cent year on year. The figure is important because it shows whether revenue is translating into better unit economics after variable costs. In Bukalapak’s case, the contribution margin improvement suggests that the company’s focus on revenue quality is beginning to show in the numbers, even as some segments contract.

Rivals and the road ahead

Bukalapak operates in one of Southeast Asia’s toughest digital markets. In e-commerce, it competes with far larger and more aggressive players such as Sea Group’s Shopee, GoTo’s Tokopedia, TikTok Shop, Lazada, and Indonesia-listed Blibli. In digital merchant services, the firm faces competition from fintech and super-app ecosystems that also want to serve warungs and small retailers. Its gaming and digital goods businesses overlap with regional specialists such as Codashop, as well as payment platforms and app-store channels.

Meanwhile, BMoney sits in a wealthtech market that includes local investment apps and banking-backed platforms.

That competitive backdrop explains why Bukalapak’s transformation is being watched closely. The company can no longer rely on the old narrative of Indonesian e-commerce growth alone. Its future depends on whether it can build a set of focused, profitable businesses around digital transactions, merchant services, gaming, and financial products.

Also Read: SEA’s e-commerce giants hit profitability: What it means for region’s digital future

For now, the first-half results show progress but not yet a finished turnaround. Revenue is growing, adjusted EBITDA is positive, and several segments are showing better margins. At the same time, some businesses are shrinking, and the group’s profitability remains thin.

Bukalapak has bought itself time by improving discipline. The next test is whether it can turn that discipline into a larger and more defensible business.

The post Bukalapak stays EBITDA-positive as gaming powers first-half revenue growth appeared first on e27.

Posted on Leave a comment

Your real customer might be procurement, legal, or the CFO, not the user

One of the most persistent mistakes in product and growth strategy is the assumption that the person using the product is the person who matters most in the buying decision. That belief is comforting because it gives teams a clean story. Build something people love, remove friction, improve the experience, and growth will follow.

In many markets, that story is incomplete.

The user may be the visible actor, but the real decision can sit elsewhere. In enterprise software, financial services, security, regulated operations, healthcare, infrastructure, and increasingly in any category touching data or operational risk, the product is often judged by functions that never use it in the way the end user does. Procurement will test commercial discipline. Legal will test exposure and enforceability. Security will test control. Finance will test cost logic, payback, and budget legitimacy. Risk will test survivability under stress. The user may still matter, but the user is no longer the whole market.

This is where many otherwise strong product teams lose strategic altitude. They continue optimising for adoption while the actual buying system is optimising for assurance, control, and budget protection. They interpret slow progress as a sales problem or a messaging problem, when in reality the product has not yet been made legible to the real customer.

The myth of the user led buying model

Consumer shaped thinking has had an enormous influence on modern product practice. It has improved usability, sharpened empathy, and corrected years of enterprise indifference to the people expected to live with bad systems. That was necessary. But it also created a distortion. Too many teams now behave as though user love is sufficient to unlock commercial success in markets where institutional buying logic still dominates.

It rarely is.

A product can be intuitive, elegant, and strongly demanded by an operating team and still fail to move forward. Not because the value is weak, but because the organisation buying it is asking a different set of questions. Can this vendor be governed properly? Are the contractual terms survivable? Does the pricing model create long-term exposure? Will this product introduce regulatory ambiguity? Are the data rights acceptable? Is the implementation risk worth the return? Does this purchase create new headcount, hidden cost, or architectural dependency? These are not marginal questions asked on the side. They are often the core questions.

Also Read: Your customers are not buying your product, they are buying a better version of themselves

The product is not being evaluated only for usefulness

Most teams understand the need to show product value. Far fewer understand that value is being assessed through different lenses by different internal audiences. The user is asking whether the product helps them do something better, faster, or more effectively. Procurement is asking whether the commercial structure can be managed without regret. Legal is asking whether the downside is bounded. The CFO is asking whether the economics are credible and whether this deserves capital ahead of other demands on the budget.

None of these perspectives is irrational. They are performing their roles exactly as they should. The problem arises when product leaders treat them as obstacles rather than as customers in their own right.

Procurement is often about buying risk shape, not just price

Procurement is routinely misunderstood by product teams. It is seen as the function that arrives late, pushes on price, and creates delay. That is a shallow reading of what is actually happening.

In serious buying environments, procurement is not only about negotiating cost. It is testing whether the vendor behaves with discipline, whether the deal structure is coherent, whether commitments are clear, and whether the organisation is about to enter an arrangement it will later struggle to unwind. Procurement is often less interested in your product narrative than in whether your commercial model creates hidden expansion, ambiguous service scope, unbounded support expectations, or contractual lock-in without reciprocal protection.

A team that has only learned to sell value often struggles here because procurement is examining maturity. Loose packaging, vague service descriptions, inconsistent pricing logic, missing governance terms, and fuzzy implementation commitments all signal future pain. Even a strong product can start to look risky if the commercial architecture around it feels improvised.

Legal is evaluating future failure, not present excitement

Legal does not buy possibilities. Legal models fail. That distinction matters.

When product teams present a new capability, they often describe what the product can do at its best. Legal is usually concerned with what happens when it does not. What if the data flows are disputed? What if a regulatory complaint is raised? What if the service fails during a critical period? What if an automated output creates harm? What if an external dependency breaks? What if customer information is retained too long or used in a way that exceeds consent? What if an internal team relies on a claim that later proves indefensible?

This is not cynicism. It is the institutional function responsible for asking what others are tempted to postpone.

Also Read: The agent as customer: Jensen Huang’s trillion-dollar bet on AI’s next era

The CFO is not buying features; the CFO is buying economic confidence

Perhaps the biggest mismatch in modern product storytelling is with finance. Product teams often believe that if user demand is visible enough, budget logic will follow. In practice, the CFO is often evaluating a completely different object.

The CFO is not buying your roadmap. The CFO is buying confidence in the economic shape of the decision. That includes the direct cost, the total cost, the speed of value, the certainty of value, the downside if adoption underperforms, and the extent to which this spend displaces something else with a clearer return. Even where the numbers appear favourable, finance will still ask whether the value is measurable, durable, and attributable enough to deserve investment.

This is where many good products become strategically weak. They talk in terms of empowerment, efficiency, collaboration, and innovation, while finance needs to understand cost avoidance, revenue protection, compliance reduction, productivity recovery, margin impact, capital discipline, or risk containment. The product story may be true, but it is not yet in a language that capital allocation can trust.

The internal sponsor is often carrying too much of the load

One of the most overlooked signs of strategic weakness is when a product depends too heavily on an internal champion to do all the translation work. The user or business sponsor loves the product, sees the value, and wants the deal to happen. But they are left carrying the burden of explaining security posture, financial rationale, implementation risk, legal safeguards, and commercial structure to functions that were never part of the original product conversation.

That is not a sales inconvenience. It is a design failure in the route to market.

A strong product organisation does not simply create demand in the user base. It equips the buying system. It gives the sponsor material that travels across functions. It anticipates objections that are not really objections but legitimate decision criteria. It understands that internal advocacy has limits, especially in large institutions where each function is being judged on whether it prevented the wrong kind of decision, not on whether it accelerated the exciting one.

If your deal advances only when a heroic sponsor spends political capital carrying you through the organisation, your model is less scalable than it appears.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Your real customer might be procurement, legal, or the CFO, not the user appeared first on e27.

Posted on Leave a comment

Why concentration disclosure is key to ASEAN’s financial stability

On a Friday morning in July 2024, a single software update, pushed by a single vendor, applied automatically across customer environments, took the operational layer of more financial institutions offline simultaneously than any single bank failure in modern history. Airports stopped boarding. Hospitals reverted to paper. Customer service platforms inside Asian banks went dark for hours.

The CrowdStrike outage was resolved within days. The lesson it taught was not.

After fifteen years inside risk functions across Indonesian banking, insurance, and multifinance, I have come to believe the most consequential systemic risk in ASEAN’s financial system is no longer the one our supervisors are best equipped to assess. It is what I think of as the outsourced perimeter, the operational layer that used to live inside an institution and now lives at a vendor, sometimes several layers of vendors deep. The next significant financial disruption in this region is more likely to begin outside an institution than inside one.

The shift that quietly happened

For most of the last century, banks ran themselves on infrastructure they owned. Core banking systems sat in their own data centres. Risk models ran on internal servers. Compliance reporting was assembled by internal teams.

That stopped being true in the last decade. Modernisation, driven by cost, talent scarcity, and regulatory pressure to digitise, moved successive operational layers outside the institution. Core banking platforms migrated to cloud-hosted vendors. Risk and compliance tooling moved to SaaS. Identity verification, fraud detection, customer onboarding, AI capabilities, even some second-line functions now sit inside third-party systems.

Each migration looked sensible in isolation. The aggregate is something the institutions and their supervisors are still catching up to.

What concentration looks like in 2026

Three layers of the ASEAN financial stack now show concentration severe enough to matter.

Cloud infrastructure. The major financial institutions across Indonesia, the Philippines, Vietnam, Thailand, and Malaysia run their critical workloads on a small number of hyperscale cloud providers. If any single provider experiences a regional outage, a meaningful share of the financial sector goes with it.

Identity and verification rails. Customer onboarding and identity checks across ASEAN financial services flow through a handful of regional and global vendors. The failure of one, operational or commercial, would prevent new account openings and customer due diligence refreshes across multiple institutions simultaneously.

Also Read: How do you finance a first nuclear reactor for a data centre? The deal structure is finally coming together

AI and intelligence services. As generative AI moves into credit decisions, fraud detection, and customer service, an increasing share of those workloads is served by a small number of foundation model providers. Most institutions cannot run their AI systems if those upstream providers are down.

Why this is more dangerous than people think

Three risk vectors compound.

Cascading correlation. The vendors financial institutions depend on are often the same vendors other critical sectors depend on. The same cloud provider that hosts an Indonesian bank also hosts the hospital network, the payment switch, and the government identity service. A failure does not just affect financial services. It affects the systems financial services depend on to function.

Limited substitutability. The migration paths off a major cloud provider, a core banking vendor, or an identity rail are measured in years, not weeks. The lock-in is structural. Institutions cannot reroute around a failing vendor in real time the way they can re-paper a syndicated loan or call in a backup credit line.

Asymmetric oversight. Banks are stress-tested. Insurers are stress-tested. Their critical vendors are not, at least not by anyone supervising the financial sector. The vendor sits one regulatory step removed from the supervisor that ultimately bears the consequences of its failure.

What is starting to work

A few institutions are responding ahead of regulation.

Multi-cloud architectures. The largest Indonesian banks now run mission-critical workloads across at least two hyperscale providers, with automated failover. The cost is high. So is the alternative.

Vendor stress testing. Some risk committees have begun running tabletop exercises against vendor failure scenarios — what happens if our identity provider goes down for forty-eight hours? What happens if our core banking vendor announces a price increase we cannot absorb? — and identifying the gaps in their continuity plans before they appear in production.

Concentration disclosure to boards. The institutions that handle this best require their CIOs and CTOs to report quarterly on vendor concentration in the critical operational stack. The number alone is often clarifying.

What regulators should be doing

Three actions would meaningfully reduce systemic exposure.

Define critical third parties. Supervisors in ASEAN should formally designate the vendors whose failure would have systemic consequences, and bring them inside the supervisory perimeter, much as the United Kingdom’s Critical Third Parties regime under the Financial Services and Markets Act 2023 has done for the UK financial system.

Also Read: Finance doesn’t have a math problem, it has an ego problem.

Require concentration disclosure. Institutions should disclose, in regulatory filings, the share of critical operational workload running through each major vendor. The information would surface concentration that is currently invisible.

Stress-test the dependencies. Annual supervisory stress tests already model credit shocks, liquidity shocks, and market shocks. They should now model vendor shocks, the operational impact of a major cloud, identity, or AI provider becoming unavailable for forty-eight to ninety-six hours.

The macro stakes

ASEAN’s financial system has spent the last decade moving its operational infrastructure outside the institutions themselves. That migration was rational. It has also produced a regional financial sector whose stability now depends on a small number of vendors, most headquartered outside the region, and none supervised by the regulators that bear the consequences of their failure.

The next significant financial disruption in ASEAN is unlikely to look like 1997, or 2008, or any of the crises the region’s supervisors have spent decades preparing for. It is more likely to look like a Friday morning when a vendor most customers had never thought about pushed a bad update, and the consequences cascaded across the institutions that depended on it.

The window to build the supervisory infrastructure for that scenario is closing, not opening.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Why concentration disclosure is key to ASEAN’s financial stability appeared first on e27.