Posted on Leave a comment

The hidden problem inside AI teams isn’t skills — it’s the human environment

A few weeks ago, an SME CEO shared his frustration with me over coffee.

His company had invested heavily in AI tools over the past year. Licences were purchased. Teams attended workshops. Managers were instructed to integrate AI into workflows. Like many businesses today, the organisation moved quickly because it feared falling behind.

Yet despite the investment, adoption remained uneven.

Some teams were using AI aggressively while others barely touched it. Junior employees were often highly fluent with the tools but lacked the business judgment to evaluate outputs critically. Senior staff possessed deep domain expertise but were slower, more cautious, and at times resistant to AI-assisted workflows.

At one point, the CEO leaned back and said something I have heard increasingly often lately.

“The problem is my people. The tools are only as good as the people using them.”

At first glance, this sounds entirely reasonable. Most organisations still approach AI implementation as a capability problem. The assumption is straightforward: train employees, improve prompting skills, close the competency gap, and adoption will follow.

But as he continued speaking, something more interesting began surfacing beneath the frustration.

What he was describing was not merely a people problem. It was a human environment problem.

Because before people make decisions, before teams collaborate, before judgment becomes visible, something else quietly shapes the conditions under which those decisions form.

The environment.

And AI is redesigning that environment far more profoundly than most organisations realise.

Recent research into AI-augmented teams suggests that AI is no longer functioning merely as a passive software tool. Increasingly, it behaves more like an active participant inside the decision environment itself, summarising discussions, synthesising opinions, generating recommendations, shaping meeting outputs, and influencing what becomes visible to the group.

That distinction matters enormously.

Because most organisations still operate with an outdated assumption: humans think, AI assists. But what happens when the environment itself begins participating in thought formation?

Also Read: AI agents could help Southeast Asian firms untangle cross-border payment costs

As the CEO continued describing the tension inside his company, a pattern emerged. Junior staff often moved faster with AI because they were more comfortable experimenting. They generated outputs rapidly, contributed confidently in meetings, and adapted quickly to AI-driven workflows.

Senior employees behaved differently.

They questioned outputs more carefully. They noticed contextual gaps. They distrusted overconfident synthesis. They understood where nuance could disappear. Years of experience had trained them to recognise ambiguity, political complexity, and hidden operational realities that AI-generated summaries could flatten.

Ironically, the very people with the strongest judgment were often the slowest adopters.

This dynamic aligns closely with what researchers are beginning to call the “Expertise Paradox.” Studies increasingly suggest that while AI significantly boosts novice performance, experts often engage more cautiously because they are more sensitive to inaccuracies, overgeneralisation, and the erosion of tacit expertise.

Most organisations interpret this as resistance. But that may be a dangerous misreading. Because what looks like resistance may actually be discernment.

At the same time, a growing movement around “vibe teaming” is accelerating inside AI-enabled workplaces. The idea is deceptively simple: humans and AI collaborate in fluid, fast-moving loops where AI captures conversations, synthesises insights, drafts outputs, and accelerates execution. Researchers at the Brookings Institution recently demonstrated how teams could produce sophisticated strategic briefs in under 90 minutes using these approaches.

On the surface, this appears highly efficient. And in many cases, it is. But it also introduces a deeper organisational tension.

The systems that make collaboration faster may also reshape the conditions under which judgment, disagreement, expertise, and strategic clarity emerge.

As AI continuously summarises discussions and smooths complexity into coherent outputs, organisations can begin drifting toward what might be called consensus acceleration: the compression of disagreement through AI-mediated coherence.

Minority viewpoints become easier to flatten. Nuanced expertise risks being compressed into “clean” strategic summaries. Teams may begin mistaking rapid synthesis for deep understanding.

This is where many AI implementation conversations become too shallow.

The real issue is not whether employees possess enough AI skills. The deeper issue is whether organisations understand the human systems surrounding those skills.

Because every organisation operates inside invisible conditions, conditions that shape confidence, authority, participation, visibility, legitimacy, and interpretation. AI amplifies all of these dynamics. Sometimes positively. Sometimes dangerously.

This means the future leadership challenge may no longer be simply, “How do we get our people to use AI?”

The more important question may become: “What kind of decision environment are we creating around human judgment itself?”

Because the future bottleneck may not be AI capability. It may be organisational interpretive capacity. The ability of teams to distinguish signal from noise, preserve nuance under pressure, challenge false coherence, and maintain cognitive quality while operating at speed.

That changes the leadership conversation entirely.

Also Read: Securing Agentic AI for Singapore enterprises: A reference architecture

The companies that succeed in the next phase of AI transformation will likely not be the ones with the most tools. They will be the ones that consciously design environments where expertise is protected rather than flattened, where disagreement survives long enough to improve thinking, where AI accelerates exploration without replacing discernment, and where senior employees become stabilisers of strategic clarity rather than perceived obstacles to innovation.

Research increasingly supports this direction. Emerging work in human-AI complementarity suggests that the highest-performing organisations are not those replacing human judgment, but those deliberately designing collaborative structures where humans and AI contribute different cognitive strengths.

In practical terms, this means organisations must stop treating AI implementation purely as a technology rollout. It is a human environment redesign challenge.

Leaders may need to rethink meeting structures, decision-making rhythms, mentoring systems, review processes, and how authority itself operates inside AI-enabled teams.

Some teams may require deliberate environmental friction where strategic decisions cannot be finalised immediately. Others may require structured dissent loops where minority viewpoints are protected instead of compressed by rapid synthesis. Experienced employees may need to operate not merely as contributors, but as stewards of cognitive quality inside accelerated systems.

Because the future advantage of organisations may not belong solely to those who move fastest. It may belong to those who can preserve discernment while operating under acceleration.

The most important transformation happening inside AI-enabled companies is not technological. It is environmental.

And the real competitive edge may no longer come from AI alone. It may come from the ability to consciously design the human environments operating upstream of decisions themselves.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The hidden problem inside AI teams isn’t skills — it’s the human environment appeared first on e27.

Posted on Leave a comment

The new ransomware playbook: Why ASEAN banks are losing the disclosure war

Late last year, a regional bank in Southeast Asia received an unusual email. Not from the attackers, but from their regulator. The supervisor had received an anonymous tip claiming the bank had suffered a major data breach two weeks earlier, with sample customer records attached as proof. The breach had happened. The bank had not yet finished its internal investigation, let alone disclosed it.

The attackers had taken the disclosure decision out of the institution’s hands.

That scenario, repeated quietly across the region in the past eighteen months, is the part of the ransomware story most ASEAN bank defences are not built for. The playbook the attackers are running today is not the playbook the banks have been training against, and the consequences are starting to show up in regulatory fines, customer notification disasters, and senior executive resignations that were preventable.

What the old playbook looked like

For most of the past decade, ransomware against banks worked in a predictable shape. Attackers gained access through phishing or unpatched vulnerabilities. They moved through the network. They encrypted critical systems. They demanded payment in cryptocurrency in exchange for a decryption key. The institution restored from backups when it could, paid quietly when it could not, and disclosed when it had to.

The defensive playbook was built around this model: offline backups, phishing training, network segmentation, ransom-payment policy, cyber-incident responder relationships. Most major banks across ASEAN have invested heavily here over the last five years. The investments were sound. They are not sufficient anymore.

Also Read: Singapore’s cybersecurity paradox: Leading in digital, lagging in defense

What changed in 2024-2025

Three shifts have happened, and they compound.

Data first, encryption second. Modern ransomware operators no longer begin with encryption. They begin with months of quiet exfiltration. By the time encryption runs, the attackers already hold a complete copy of the institution’s most sensitive data, customer records, internal communications, board materials, sometimes regulatory correspondence. Restoring from backup solves the operational disruption. It does nothing about the data the attackers still have.

Triple extortion. The single threat of decryption has become three threats in parallel. Pay or the data is released publicly. Pay or we sustain a denial-of-service against your customer-facing systems. Pay or we contact your most important enterprise clients directly. Each vector runs independently. Each has a different remediation cost. Banks built to negotiate against one threat are now negotiating against three.

Regulatory weaponisation. This is the shift most ASEAN supervisors are not yet talking about openly. Attackers have started using the institution’s own disclosure obligations as leverage. They contact the supervisor before the bank does. They release sample data publicly to force a notification clock. They threaten to alert the press, the regulator, and major enterprise customers simultaneously, knowing that the regulatory fine for delayed disclosure may exceed the ransom. The disclosure decision has effectively been transferred from the institution’s risk committee to the attacker’s keyboard.

Why ASEAN banks are more exposed

Three regional factors sharpen the exposure here.

Outsourced perimeter. Most ASEAN financial institutions have moved meaningful portions of their operational stack into third-party platforms over the past decade. The attackers have noticed. The entry point into a major bank now often runs through a smaller vendor with weaker security, and the dwell time inside the network is long enough that the attack is well-staged before the bank knows it has been compromised.

Disclosure rule asymmetry. Indonesia’s disclosure framework is lighter and more recently codified than Singapore’s. The Philippines and Vietnam are still building theirs. Attackers selecting targets can choose jurisdictions where regulatory pressure is high enough to weaponise but defensive cyber budgets are not at Singaporean levels.

Supervisor capacity. Banking supervisors and central banks across ASEAN have built cyber risk capability steadily but unevenly. Few of them have a standing capability to receive and triage attacker-initiated disclosures, which is exactly the channel the new playbook depends on.

What is starting to work

A few institutions are responding ahead of the curve.

Pre-staged disclosure plans. The banks handling this best now have legal, communications, regulatory, and executive escalation pre-staged for a scenario where disclosure is forced by an external actor rather than chosen internally. The plan does not eliminate the damage. It reduces the cost of the first seventy-two hours.

Adversary-aware tabletop exercises. The most useful incident response exercises I have seen in the past year simulate not just the technical attack but the multi-front pressure campaign that comes with it. The institutions running these exercises with their boards and regulators are surfacing gaps that purely technical drills do not.

Vendor risk visibility. The institutions tracking which vendors hold their data, with what controls, and under what notification obligations are catching threats earlier than those still treating vendor risk as a procurement question.

Also Read: The demand for SMB cybersecurity is inevitable, the supply was never built correctly

What needs to happen

Three moves would meaningfully shorten the gap.

Update incident response playbooks for forced disclosure. The assumption that the institution controls the timing of its own breach disclosure is no longer reliable. Plans should assume the attacker may move first, and rehearse for that scenario.

Harden the supervisory channel. Regulators should publicise a standardised process for attacker-initiated disclosures, and require banks to reciprocate with internal escalation triggers. The current ambiguity benefits the attackers.

Treat vendor security as systemic. The cyber resilience of a major bank is now functionally a property of the weakest critical vendor it depends on. Vendor risk and cyber risk are no longer separate problems.

The macro stakes

The ransomware threat against ASEAN financial institutions has moved out of the IT department and into the regulatory, legal, and reputational layers that sit above it. The defensive playbook still sits, in most institutions, with the technical teams. The next significant ransomware event in this region is unlikely to be lost in the data centre. It will be lost in the seventy-two hours after the attacker emails the supervisor.

The banks that win those seventy-two hours will be the ones whose CROs, CISOs, general counsels, and communications heads have already run the scenario together. The banks that lose them will be the ones still treating ransomware as an IT problem.

The playbook has changed. The defence needs to change with it.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The new ransomware playbook: Why ASEAN banks are losing the disclosure war appeared first on e27.

Posted on Leave a comment

No fans, no fridges, just paint: ZERC’s founder on cracking SEA’s cooling crisis

ZERC founder Lee Heon  (blue shirt) with his team mates

In much of Southeast Asia, heat has stopped being a seasonal inconvenience and become an infrastructure problem. Parked cars can hit cabin temperatures of 70 to 90 degrees Celsius within minutes, air-conditioning strains power grids at peak demand, and concrete-heavy cities from Bangkok to Jakarta trap heat well into the night.

ZERC, a deeptech startup spun out of Korea University in November 2022, believes part of the solution could be as simple as a coat of paint. Founded by materials science professor Lee Heon, the company has developed a water-based radiative cooling paint that reflects 96 per cent of sunlight and radiates over 93 per cent of absorbed heat back into space, lowering surface temperatures without consuming any electricity.

Also Read: Korean startup ZERC develops paint that cools roofs, vehicles, and helmets

Unlike many competitors that rely on toxic, solvent-based formulations, ZERC’s paint uses polymers, water, and ceramic pigments, eliminating volatile organic compound emissions at the source. The company is targeting rooftops, vehicles, ships, industrial equipment, and even safety helmets, positioning paint as a cheaper, more versatile alternative to radiative cooling panels and films.

We spoke to Lee about ZERC’s Southeast Asia (SEA) strategy, the true economics of the technology, and the obstacles standing between the startup and its first large-scale commercial deployment in the region.

Edited excerpts:

SEA looks like your toughest and most promising market. What’s the actual go-to-market plan? Direct sales, licensing, or partnerships?

We’re keeping all three options open. Our initial strategy is to export the finished product into Southeast Asia, establish its performance and credibility there, and then expand with local partners. Ultimately, we envision local production through licensing agreements with regional paint manufacturers.

SkyCool uses panels, SpaceCool uses film, RadiaCool focuses on EVs. You’ve bet everything on paint. Where might that bet lose?

Paint is the most versatile, commercially applicable format of radiative cooling technology. It has a relatively low manufacturing cost, can be applied easily over very large areas, and works on curved or irregular surfaces where panels and films are more limited. Installation costs are also significantly lower than film.

For these reasons, I believe cooling paint has the potential to dominate the radiative cooling materials market. Its main weakness is that manufacturing cost is still higher than conventional paint, though that additional cost is typically recovered within one to two years through energy savings.

Water-based formulations are often criticised for weaker adhesion and shorter lifespans than solvent-based ones. How did you solve that trade-off?

Water-based paint is more environmentally friendly, but its coating durability is generally inferior to oil- or solvent-based paint. So I expect solvent-based cooling paints to gain market adoption first.

Also Read: 5 Seoul startups made their Southeast Asia debut at Echelon Singapore 2026 under the SBA pavilion

In the longer term, however, as water-based formulations improve and environmental regulations tighten, I expect water-based radiative cooling paints to become increasingly important.

You claim that the cooling effect can last for more than five years. Has this claim been validated through multi-year field testing in tropical conditions, or is it extrapolated from lab ageing tests?

It’s currently an estimate based on standard accelerated ageing tests. In harsher environments, actual lifespan could be shorter. Put another way: we expect performance comparable to conventional solvent-based exterior paints. If a conventional paint can maintain its coating for five years under a tropical monsoon climate with strong UV exposure, we expect our cooling paint to last just as long, or longer.

Walk us through the actual numbers — cost per square metre versus electricity savings for a mid-sized warehouse roof in Manila or Jakarta.

The paint costs around US$10 per square metre. Incoming sunlight carries over 1,000W/m² of energy; conventional paint reflects only 30 to 80 per cent of it, while ours reflects over 95 per cent. That means our coating absorbs roughly 500-600 watts less solar energy per square metre than conventional paint.

Assuming only half of that reduced heat load translates into lower cooling demand, and that a cooling system runs eight hours a day for 300 days a year, that works out to around 600 kWh of reduced heat load annually. With a cooling system coefficient of performance (COP) of 3, that equates to roughly 200 kWh saved per square metre each year. At about US$0.12 per kWh, that’s approximately US$24 in annual savings per square metre, meaning the paint’s additional cost can potentially be recovered within the first year.

Safety helmets are a strikingly different category from rooftops and ships. Genuine commercial priority, or proof-of-concept?

It’s essentially a proof of concept, though it could bring real benefits to outdoor workers enduring hot conditions. It demonstrates that the technology works not only on large structures, but also on small, irregularly shaped objects directly exposed to sunlight, solving the discomfort of sweat trapped inside a helmet.

Turning smelting slag into a cooling pigment is compelling, but industrial byproducts vary batch to batch. How do you guarantee consistent optical performance?

The slag-based paint, developed with South Korean steel manufacturer POSCO, is primarily a demonstration of sustainability and circularity potential rather than the core of our commercial strategy. In fact, without slag, we can produce a higher-performance radiative cooling paint. It shows how industrial waste can be upcycled into a functional material, rather than defining our product roadmap.

Which country are you targeting first for regulatory approval, and what’s been the biggest bureaucratic surprise?

We haven’t yet obtained certification in Southeast Asia –only in Korea so far. We expect regional requirements to be broadly similar, so we don’t anticipate certification being a major obstacle once we begin expanding in earnest.

EV battery-range preservation requires OEM-level integration, not just aftermarket application. Are you in talks with any EV or fleet manufacturers in the region?

Our initial EV application isn’t passenger cars; we’re testing the paint on electric bus roofs, running joint experiments with a global automobile manufacturer, with very promising results so far. We haven’t yet discussed this application with Southeast Asian EV or fleet companies, but we’d be very interested in joint testing with regional partners.

Also Read: Korea’s startup ecosystem is training founders, not just funding them

What’s the single biggest obstacle to ZERC’s first large-scale commercial deployment in Southeast Asia?

To launch large-scale projects there, our first priorities are securing sufficient funding and expanding our team. We’ll also need reliable local distribution and business partners. Manufacturing, however, isn’t likely to be the bottleneck; our facility in Ulsan, Korea, can already produce up to around five tonnes a day, and scaling further by using existing paint manufacturing facilities in Korea or Southeast Asia should be relatively straightforward. Our biggest immediate challenge is securing the funding, people, and local partners needed to accelerate commercialisation in the region.

The post No fans, no fridges, just paint: ZERC’s founder on cracking SEA’s cooling crisis appeared first on e27.

Posted on Leave a comment

The system behind the smile: How to make volunteer efforts sustainable

When a resident faces a difficult problem, a community volunteer is often the first person willing to listen.

The issue may involve housing, employment, financial hardship, healthcare, family concerns or a neighbourhood dispute. What begins as a simple conversation can quickly become a complicated process involving documents, appeals and coordination with government agencies, social-service organisations or non-profit groups.

Volunteers step forward because they care. Yet goodwill alone cannot carry an unlimited workload.

Community needs will continue to grow, and not every problem can be resolved quickly. If programmes depend mainly on personal dedication and informal knowledge, even committed volunteers may become overwhelmed.

The real question is not how to persuade volunteers to put in more effort. It is how to ensure that every hour they contribute creates meaningful and sustainable impact.

Goodwill is not an operating system

Many volunteer initiatives are built on an admirable belief: when people care enough, they will find a way to help. That works until problems become more complex.

A volunteer may need to identify the responsible organisation, gather documents, prepare an appeal, explain the resident’s circumstances and follow up several times.

Without a clear workflow, experienced volunteers often carry the heaviest burden because they know the procedures and contacts. New volunteers may hesitate because they fear giving incorrect advice. Residents may repeat the same story to different people, while volunteers may duplicate one another’s work.

This is not a lack of commitment. It is a system-design problem.

Employees cannot perform consistently without clear processes, appropriate tools and defined responsibilities. Volunteer organisations are no different.

Define the volunteer’s role

Volunteers are most effective when they understand both their responsibilities and their limits.

They can listen, clarify the main concern, gather essential information, explain available support, make referrals and help residents communicate with the relevant organisation. However, they should not be expected to replace social workers, lawyers, healthcare professionals, counsellors or government officers.

Also Read: Why building a people-first work culture in HR tech matters more than ever in Southeast Asia

Clear boundaries protect both the volunteer and the resident.

A volunteer should never feel pressured to promise an outcome that depends on eligibility rules or an agency’s decision. Matters involving immediate danger, family violence, serious mental-health concerns or severe financial distress should be escalated promptly to qualified professionals.

A three-level system can help: routine enquiries are handled by trained volunteers, complex cases are referred to experienced coordinators, and urgent or specialised matters are transferred to professional support.

Make the work visible

One of the most effective improvements is a shared case-management process.

A secure system should record the resident’s concern, documents received, organisations contacted, actions taken, responses obtained, the next step and the person responsible for follow-up.

This prevents cases from being lost when a volunteer becomes unavailable. It reduces repeated explanations and allows another team member to continue the work. It also turns individual experience into organisational knowledge.

If applications are delayed because the same document is missing, the organisation can improve its checklist. If cases are repeatedly sent to the wrong department, the referral guide can be updated. If residents often misunderstand a process, volunteers can be given clearer communication materials.

Technology can support this, but the solution need not be expensive. A small group may begin with a secure digital form and controlled-access tracker. A larger organisation may require a case-management platform with reminders, permissions and audit records.

The aim is not to automate compassion. It is to remove administrative friction so volunteers can spend more time helping people.

Train for real situations

Volunteer orientation often focuses on values, expected behaviour and programme objectives. These matter, but volunteers also need practical skills.

They should know how to conduct a structured conversation, identify the central issue, ask for relevant information and distinguish confirmed facts from assumptions.

They should also learn to write concise appeals. A strong appeal explains the resident’s circumstances, assistance already sought, supporting documents available and the specific action requested.

Other essential areas include privacy, conflict management, respectful communication and emotional boundaries.

Scenario-based training is especially useful. Volunteers can practise realistic cases, identify missing information, decide which organisation should be approached and recognise when escalation is necessary.

Experienced volunteers can serve as mentors, but this role should not be assigned automatically. A person may be knowledgeable without knowing how to guide others. Effective mentors explain their reasoning, demonstrate good practices, observe newer volunteers and provide constructive feedback.

Build stronger agency partnerships

Many volunteers become frustrated not because they are unwilling to help, but because they must navigate multiple organisations with unclear responsibilities.

Public agencies, social-service organisations and non-profit groups can support volunteers by providing updated referral guides, designated contact channels and clearer explanations of eligibility requirements.

Where several organisations are involved, someone should coordinate the next step. Repeatedly redirecting a resident may be procedurally correct, but it can create the impression that nobody owns the problem.

Even a basic referral-status system could help. Volunteers may not need access to confidential details, but confirmation that a referral has been received, assigned or completed would reduce repeated calls and emails.

Sometimes the most useful innovation is ensuring that the correct information reaches the correct person at the correct time.

Also Read: Human value in the AI era is not what most people think

Measure contribution fairly

Volunteer effectiveness should not be judged only by the number of cases resolved. Many outcomes depend on regulations, eligibility criteria, funding and decisions beyond a volunteer’s control.

Better measures include response time, referral accuracy, documentation quality, communication, teamwork and whether the resident understands what will happen next.

Organisations should also monitor volunteer wellbeing. Warning signs include a small number of people handling most difficult cases, frequent late-night follow-ups, rising frustration and volunteers gradually withdrawing.

Recognition should be specific. Leaders can acknowledge a volunteer’s patience, accurate record-keeping, sound judgement, teamwork or ability to manage a difficult conversation respectfully.

Residents must be partners too

Community assistance cannot be completely one-sided.

Residents should provide accurate information, prepare necessary documents, attend appointments and allow reasonable time for organisations to respond. Volunteers should explain these expectations early so residents understand that assistance is a partnership, not an unlimited service.

There will also be cases where the requested outcome cannot be achieved. Volunteers should then provide an honest explanation and, where possible, suggest another pathway.

Sustainable volunteerism should not depend on heroes

Communities often celebrate volunteers who go far beyond what is expected. Their dedication deserves appreciation.

However, a strong volunteer programme should not depend on a few individuals repeatedly sacrificing their time, energy and wellbeing.

A sustainable model shares knowledge, documents cases, trains volunteers, defines escalation routes and builds reliable working relationships with agencies. It allows experienced volunteers to take a break without leaving residents unsupported and gives new volunteers confidence to contribute effectively.

The best volunteer is not necessarily the person who handles the most cases alone. It is the person who works responsibly within a trusted system, collaborates with others and helps residents move from uncertainty towards a practical next step.

Volunteerism will always begin with goodwill. But goodwill creates greater impact when it is supported by sound operations, useful technology, practical training and shared responsibility.

Volunteers do not need endless demands for more effort. They need systems that ensure their effort truly matters.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The system behind the smile: How to make volunteer efforts sustainable appeared first on e27.

Posted on Leave a comment

Moving past the chatbox: The hidden risks of agentic AI and MCP in enterprise infrastructure

In Singapore, Hong Kong, and across the APAC region, the corporate adoption of Generative AI has completed its initial trial phase. Over the past year, enterprise technology leaders have realised that simple internal chatbots offer limited structural value. The real ROI lies in the next evolutionary phase: fully autonomous AI agents.

We are shifting from static AI “assistance” to dynamic “decision execution.”

However, as organisations rush to deploy autonomous agents that can pull enterprise context and execute live API actions across legacy silos, a critical infrastructure gap has emerged. In the race for velocity, many CISOs are inadvertently leaving the enterprise backdoor wide open.

The protocol shift: Why legacy security is blind to the semantic layer

The rapid rise of the Model Context Protocol (MCP) has changed the architecture of AI implementation. MCP allows large language models to seamlessly connect to secure, local data sources, development tools, and enterprise environments.

But from an infrastructure security perspective, this creates an unmanageable perimeter risk.

Traditional Web Application Firewalls (WAFs) and legacy Data Loss Prevention (DLP) systems operate at the network or packet layer. They are fundamentally blind to the semantic layer of LLM prompts and agentic workflows. They cannot parse what an autonomous agent is “thinking” or planning to execute.

When a localised agent leverages MCP to pull a massive code repository, database query, or customer PII profile to ground its context, it automatically bundles that proprietary data. The moment that bundle is sent to a third-party, public cloud LLM for inference, your data ownership is permanently compromised.

Also Read: From chatbots to payment agents: AI’s next role in SEA commerce

The three structural blindspots of agentic infrastructure

Having spent over two decades building enterprise protection systems, from the early days at Bell Labs and Symantec to engineering data security architectures at Websense and IBM, I see the current LLM landscape repeating the fatal mistakes of the early cloud migration wave.

There are three immediate risks stalling enterprise AI from moving safely into production:

  • The autonomy risk (shadow actions): Once an agent is granted execution rights via MCP to interact with internal databases, it becomes highly vulnerable to Prompt Injection. A malicious external input can hijack the agent’s logic, leading to unauthorised API execution or lateral escalation within your network. Post-incident auditing is simply too late.
  • The privacy paradox: To make an AI agent useful, you must feed it deep organisational data. But traditional security models force a brutal trade-off: you either compromise on AI intelligence by withholding data, or you trade away data privacy by passing raw tokens across your corporate boundary.
  • The FinOps nightmare: Autonomous agents operating in background loops frequently fall into execution deadlocks. A single looping agent misinterpreting a complex database schema can burn thousands of dollars in token expenditure within hours, while completely shattering your compliance audit trails.

Also Read: If AI can’t find your startup, does your startup exist?

Rebuilding the boundary: Inline, client-controlled governance

To unlock the true power of Agentic AI without exposing critical core assets, APAC enterprises must shift from reactive monitoring to proactive, runtime governance.

Security cannot act as the emergency brake on innovation; it must become the accelerator.

The industry requires a fundamental architectural upgrade: a centralised AI Access Gateway that deploys a client-controlled data plane directly at the boundary level.

Before an agentic prompt or an MCP resource payload ever hits an external LLM provider, the data plane must execute real-time, zero-trust token scrubbing. It must de-identify PII, strip sensitive API keys, and mask core proprietary source code locally, inside your domain. Once the model returns its response, the gateway dynamically re-identifies the tokens, allowing the local workflow to execute seamlessly.

Furthermore, this orchestration layer must feature circuit breakers to halt deadlocked agents and implement intelligent model routing, automatically offloading long-context, low-risk MCP tasks to highly optimised local open-source models to manage FinOps overhead.

As AI transitions from a novelty to the digital foundation of modern commerce, the question is no longer about which model is the smartest. The real question is: Who controls the data plane that keeps those models safe?

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Moving past the chatbox: The hidden risks of agentic AI and MCP in enterprise infrastructure appeared first on e27.