Posted on Leave a comment

From KYC to KYA: how AI agents are reshaping payment risk

The next phase of digital payments may not be defined by faster checkouts or cheaper transfers, but by a more uncomfortable question: who or what is being trusted to move money?

As businesses begin experimenting with AI agents that can search for suppliers, compare prices, negotiate terms, initiate payments, and reconcile invoices, the old assumptions around financial control start to fray. A human no longer clicks every button. A finance team may not manually approve every step. In some cases, software will act on behalf of a company, within rules set in advance.

Also Read: The next AI payments boom may happen in the back office

That shift sits at the centre of “Beyond Automation: Defining Agentic Global Payments”, a report by Sunrate and Mastercard. Its central argument is straightforward: automation alone is not enough. If AI agents are to handle commercial decisions involving millions of US dollars, companies need more than speed. They need accountability.

The report calls this missing infrastructure the “Trust Layer”, a framework that allows businesses to verify an agent’s identity, understand its authority, and trace what it has done. In other words, the future of payments will not just depend on whether AI can act intelligently. It will depend on whether organisations can prove that these actions were authorised, limited, and auditable.

From Know Your Customer to Know Your Agent

For the past decade, much of fintech has been shaped by Know Your Customer (KYC) rules. Banks, payment companies, and fintech startups have built systems to verify that users are who they say they are, screen them for risk, and monitor suspicious activity.

Agentic commerce introduces a new layer of complexity. If an AI agent places an order, books travel, pays a supplier, or moves funds across borders, the payment ecosystem needs to know more than the identity of the company behind it. It must also understand the identity and authority of the agent itself.

This is where “Know Your Agent”, or KYA, comes in.

KYA is not simply a branding exercise. It points to a practical set of controls: verifying an AI agent, defining what it is allowed to do, recording the intent behind a transaction, and ensuring that actions remain within commercial and policy boundaries. An agent authorised to buy office supplies, for example, should not be able to approve a large foreign exchange transfer. A procurement agent with a US$10,000 spending limit should not be able to split payments to bypass that limit.

Also Read: From chatbots to payment agents: AI’s next role in SEA commerce

For Southeast Asia, where many companies already operate across fragmented markets, currencies, payment methods, and compliance regimes, this matters. A regional startup may have suppliers in Vietnam, customers in Indonesia, finance operations in Singapore, and banking relationships across several jurisdictions. Adding autonomous agents into that mix without governance could create a risk environment that is difficult to monitor.

The three pillars of the Trust Layer

The report breaks the Trust Layer into three broad pillars.

The first is credential protection. In today’s payment systems, tokenisation is already used to replace sensitive card or account details with secure digital tokens. In an agentic payments environment, this becomes even more important. AI agents should not be passing around raw card numbers, bank credentials, or account information. If those agents are compromised, the damage could be significant.

The second pillar is intent capture. This means securely transmitting the user’s budget, preferences, constraints, and instructions along with the transaction. In human terms, it is the difference between saying “buy the cheapest ticket” and “buy a refundable economy ticket under US$700, departing after 7pm, with no overnight layover”. For businesses, intent capture allows systems to determine whether an agent acted in line with approved instructions.

The third pillar is KYA and governance. This is the architecture that verifies the agent’s identity and sets strict permission boundaries. It includes authentication, policy enforcement, audit trails, and the ability to revoke or modify permissions when needed.

These controls may sound technical, but their commercial importance is simple. Businesses cannot delegate financial decisions to agents if they cannot later explain what happened, why it happened, and whether it was allowed.

Why many AI projects do not make it past pilots

The urgency is not theoretical. According to Gartner, at least 50 per cent of AI projects were abandoned last year after the proof-of-concept stage. The reasons included poor data readiness, high costs, and a lack of risk control.

That last point is particularly relevant for payments. In many companies, AI pilots are still treated as productivity experiments. Teams test whether a model can draft emails, summarise documents, or automate customer support. Payments are different. A bad recommendation may waste time. A bad transaction may move real money, breach regulations, or damage a company’s relationship with banks and suppliers.

Also Read: The scarcity mindset is killing creativity, not AI

For Southeast Asian startups, this creates both a warning and an opening. The warning is that building a clever agent is not enough. A product that can automate procurement or treasury workflows may impress in a demo, but enterprise customers will ask harder questions before deploying it in live payment flows.

Who approved this transaction? What data did the agent use? Can the company prove that the payment matched its internal policy? Can a bank or payment service provider trace the chain of authorisation? What happens if the agent is tricked by fraudulent instructions?

The opportunity lies in answering those questions better than competitors. The strongest companies in this space may not be the ones with the most sophisticated AI interface, but those that combine automation with controls that banks, CFOs, auditors, and regulators can trust.

Why the ecosystem matters

A Trust Layer cannot be built by a single startup in isolation. Agentic payments will require coordination across banks, card networks, payment service providers, enterprise software platforms, and regulators.

This is where established networks such as Mastercard are likely to play a significant role. Card networks already sit across large parts of the payment ecosystem and have experience with tokenisation, identity standards, fraud management, and dispute processes. Extending governed, traceable tokenisation into autonomous payment flows is a logical next step.

Payment service providers and cross-border platforms also matter, particularly in Southeast Asia. The region’s businesses often deal with multi-currency payments, varied settlement timelines, and uneven levels of banking infrastructure. If AI agents are to operate across borders, they will need infrastructure that can translate business intent into compliant payment execution across different markets.

Regulators will also have to catch up. Many existing rules assume a human actor at key decision points. Agentic systems challenge that assumption. Over time, authorities may need clearer standards on agent identity, liability, consent, auditability, and operational resilience.

Trust as a competitive advantage

The rise of AI agents in payments is often framed as a story about efficiency. There is truth in that. Agents could reduce manual work, speed up reconciliation, and help businesses optimise costs across suppliers and currencies.

But efficiency will not be the deciding factor if companies fear losing control.

Also Read: The next AI payments boom may happen in the back office

The more important race is to build systems where autonomy does not mean opacity. Businesses will need to know not only that an agent completed a task, but that it did so within defined limits. Banks will need confidence that transactions are legitimate. Payment networks will need ways to trace credentials and intent. Regulators will need evidence that responsibility has not disappeared into a black box.

For Southeast Asia’s startup ecosystem, the message is clear. The next wave of payments innovation will not be won by speed alone. It will be won by companies that can make AI agents accountable.

The future belongs not just to agents that are smart enough to act, but to systems that are safe enough to trust.

The post From KYC to KYA: how AI agents are reshaping payment risk appeared first on e27.

Posted on Leave a comment

You can’t force a tailwind, you can force your readiness for one

Ten years into building, the annual planning cycle stops being useful. A year is too short a unit to learn anything from. It’s long enough to feel like progress and short enough to hide the fact that the money isn’t made evenly across time. It shows up in bursts, during the stretches when conditions favour you, and it gets defended during the stretches when they don’t.

Most operators know this and rarely say it plainly, because it sounds like admitting the good years were luck. They weren’t luck. They were timing, and timing is a decision made years before the moment it pays off.

You can’t cause a cycle, but you can force your position in it

Andrew Carnegie’s steel business went through two price collapses, in the 1870s and again in the 1890s. Competitors did the obvious thing both times: cut production, lay off crews, wait for demand to return. Carnegie ran his mills at a loss instead, because construction costs were cheap and rivals were selling assets at fire-sale prices to survive. His instruction to a subordinate was “small profits and large sales” while everyone else retrenched. He wasn’t predicting the recovery. He was buying it in advance, at a discount, while the rest of the industry was too scared to spend.

Toyota’s position going into 1973 is the cleaner example of catching a shift rather than buying one. American demand ran on large-displacement engines, and Japanese compacts held a rounding error of US market share. The 1973 oil embargo changed the math on fuel cost overnight, and Japanese import share in the US moved from roughly 9 percent in 1976 to 21 percent by 1980. Toyota didn’t cause the oil shock. It had spent the prior decade building a fuel-efficient car for a market that didn’t want one yet, so when the market changed, the product was already on the lot.

Also Read: 15 Thai AI companies betting on products, not hype

Neither company controlled the macro event. Both controlled whether they were structurally ready the moment it hit, in cash, in capacity, in product that already existed rather than product still waiting to be built. That’s the actual answer to whether a tailwind can be forced: the conditions can’t be forced, but the position relative to them can.

Built to survive the gap between tailwinds

Corning is the case for doing this more than once. It’s a 170-year-old glass manufacturer that ran on Pyrex and CorningWare through most of the twentieth century, invented low-loss optical fibre in 1970 decades before the internet needed it, rode the fiber boom of the late 1990s, absorbed the 2001 fibre bust without gutting its glass science team, sold off Pyrex in 1998 to focus entirely on advanced glass, and turned a shelved forty-year-old formula into Gorilla Glass in 2007 after a call from Steve Jobs. Corning didn’t get one cycle right. It built a company that could survive the years between cycles, so it was still standing when the next one arrived.

Samsung’s memory chip business runs the same logic on a shorter clock. In 2008, when the financial crisis hit and every other DRAM maker cut capital spending to preserve cash, Samsung increased it, and repeated the move in the 2012 and 2019 downturns. Competitors treated the downturns as something to survive. Samsung treated them as the one window where capacity was cheap and competitors were retreating, which is a structurally different decision, and it’s a large part of why Samsung still leads the category.

Also Read: Your product is not your startup

None of these four were guessing about macro timing. Each decided, years ahead of the shift, what kind of company it wanted to be caught being when conditions turned, then built the balance sheet, product, or manufacturing base to match before the turn happened.

Conclusion

The planning horizon matters more than the plan itself. A company that budgets in single years will always be reacting to the season it’s already in. A company that plans in multi-year cycles can spend the quiet years on the unglamorous work: building capacity, buying distressed assets, shipping a product nobody’s asking for yet, so it isn’t scrambling to catch up when conditions turn favourable.

The harder question isn’t whether the next favorable window is coming. It always is. It’s whether the quiet years get spent building something ready to catch it, or just something that survived long enough to still be there when it shows up.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post You can’t force a tailwind, you can force your readiness for one appeared first on e27.

Posted on Leave a comment

The Kospi enters a bull market while crypto consolidates: Where did the risk appetite go

Global equity exchanges expanded following an inflation report. The S&P 500 index gained 0.26 per cent to reach 7,748.50 while the Nasdaq Composite added 0.54 per cent to close at 26,588.49. Technology and artificial intelligence companies like CoreWeave and Super Micro Computer powered this equity rally.

Asian bourses mirrored this optimism as the MSCI Asia Pacific index rose 0.8 per cent. Major chipmakers, including Samsung Electronics and SK Hynix, led the regional charge. South Korea saw strength as the Kospi Index jumped 3.7 per cent, entering a technical bull market on renewed momentum in artificial intelligence. Headline Consumer Price Index data showed a 0.1 per cent monthly gain and a 3.4 per cent yearly advance.

Core inflation metrics advanced 0.2 per cent monthly and 2.5 per cent yearly. This tame July inflation report eased fears regarding an imminent Federal Reserve interest rate hike. Money markets currently price in less than a 50 per cent chance of a September rate hike. Brent crude dipped below US$83 to snap a six-day rally. I view this divergence as a signal that institutional allocators favour tangible cash flows over speculative ledgers.

The broader digital asset space failed to participate in this traditional financial optimism. The total cryptocurrency valuation declined 0.55 per cent to US$2.17T over a 24-hour period. This modest drop highlights a distinct lack of positive catalysts and residual selling pressure within a low-liquidity environment.

Digital tokens exhibit remarkably weak correlations with traditional safe havens and equity benchmarks. The space shows only a nine per cent correlation with the S&P 500 and a mere five per cent correlation with Gold. Trading volume fell 8.23 per cent on a weekly basis, reflecting widespread participant apathy.

The Fear and Greed Index currently sits at 37, illustrating this lack of conviction. Institutional developments also failed to ignite buyer enthusiasm. Goldman Sachs recently acquired a Bitcoin income exchange-traded fund business via NEOS. Participants ignored this news. I believe the decentralised sector suffers from an attention deficit and requires a unique internal narrative to attract fresh capital.

Also Read: Crypto’s new threat is not a hack, but a knock at the door

Specific sectors and isolated security incidents dragged down sentiment. The Liquid Staking Derivatives sector fell 0.02 per cent and severely underperformed the broader digital asset space. A major security breach on the Harmony network created immense panic among retail participants. Harmony token prices crashed over 30 per cent after an attacker minted four billion unauthorised tokens. This massive unauthorised supply influx forced immediate liquidations across the network.

While this specific event does not pose a systemic risk, such incidents severely dampen morale. These breaches highlight the ongoing security vulnerabilities inherent in decentralised infrastructure. Macroeconomic factors also threaten to disrupt liquidity conditions.

The Bank of Japan might implement a potential rate hike in September to influence global liquidity flows. These isolated security breaches are stark reminders of the fragile infrastructure underlying these speculative networks and a primary reason for traditional allocators’ continued scepticism.

Participants must watch key technical thresholds to determine the trajectory of the total valuation. The yearly low of US$2.15T currently acts as the most crucial support zone. A decisive break below this floor could trigger a test of the 78.6 per cent Fibonacci retracement near US$2.09T. Negative exchange-traded fund flows would likely accelerate a drop into the US$2.09T-US$2.12T range.

Conversely, reclaiming the US$2.19T mark, representing the seven-day simple moving average, could signal a short-term bounce. Buyers need to see a sustained rise in spot volume above US$120B to confirm renewed interest and validate any upward price movement.

Current price action stays inside a tight range while automated algorithms fiercely defend these mathematical boundaries against aggressive intraday selling. This technical setup is a classic consolidation phase where the space simply waits for a major external catalyst to define the next directional move and establish a clear trend.

Also Read: Bitcoin’s 73% correlation with gold forces investors to rethink crypto

Bitcoin mirrored the broader stagnation despite its strong correlation with traditional equity benchmarks. The premier cryptocurrency declined 0.66 per cent, trading at US$63,383.12. Bitcoin currently maintains a strong 69 per cent correlation with the Dow Jones exchange-traded fund, indicating a shared macro-driven movement.

The asset briefly rallied past US$64,000 following the release of the cooling July Consumer Price Index data. Buyers quickly faded these gains as participants had already completely priced in this benign inflation report and adjusted their portfolios accordingly. The total digital asset valuation dipped 0.59 per cent, reflecting a broader wait-and-see sentiment among speculators who anticipate further volatility.

The upcoming September Federal Open Market Committee meeting decision will serve as the next macro trigger to guide institutional positioning. I view Bitcoin primarily as a high-beta proxy for traditional technology rather than an effective inflation hedge or a distinct alternative asset class.

Technical indicators and derivatives data confirm this profound lack of bullish conviction for the leading cryptocurrency. Bitcoin currently trades below its 50-day moving average of US$63,624 and its 200-day moving average of US$64,173. This configuration strongly indicates bearish medium-term momentum across the daily timeframe. The Relative Strength Index currently reads 43, indicating neutral to weak momentum without reaching oversold territory.

Derivatives exchanges remain calm and completely devoid of aggressive speculative positioning from large institutional players. Bitcoin liquidations totalled a mere US$19.85M over the past 24 hours, a 55.64 per cent drop from the prior day, highlighting the lack of forced selling.

Open interest rose only modestly, illustrating the extreme apathy among leverage speculators who refuse to take large directional bets. This low-leverage environment significantly reduces the immediate risk of a violent short squeeze. I argue that this subdued derivatives activity strips the space of the volatility required to attract active day traders.

Also Read: The Fed held rates, but the real story is what that means for crypto and risk assets

Crucial support and resistance boundaries define Bitcoin trading. The US$63,000 level currently acts as major support and aligns closely with the median realised price. A breakdown below this critical floor risks triggering massive liquidations near US$61,000. Such a breach would likely open a direct path toward the US$58,000-US$60,000 range.

Bulls must achieve a decisive daily close above the US$65,000 resistance threshold to invalidate the current bearish structure and invite fresh buying pressure. Reclaiming this specific resistance would open a clear path toward a US$67,000 target and signal a definitive shift in momentum across the entire sector.

Speculators must monitor spot exchange-traded fund flow data to spot early signs of returning institutional demand and validate any upward price movement. Capital clearly prefers the predictable earnings growth of traditional technology giants over the unpredictable fluctuations of decentralised tokens.

I firmly believe the space will remain within this neutral range until a macroeconomic surprise forces allocators to reevaluate their exposure and deploy fresh capital.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The Kospi enters a bull market while crypto consolidates: Where did the risk appetite go appeared first on e27.

Posted on Leave a comment

K2 Therapeutics raises US$50M to build global biotech pipeline from Singapore

K2 Therapeutics CEO Ying Huang

Singapore’s biotech sector has long had the ingredients of a serious life sciences hub: strong universities, public research funding, hospital networks, and a government keen to pull high-value industries into the city-state. What it has had less of is a steady stream of venture-backed drug developers built to compete internationally from day one.

K2 Therapeutics is trying to fit that gap.

The Singapore-based biotechnology company has raised US$50 million in seed financing from MPM BioImpact, the US investment firm that founded the company in 2024. The round has already helped K2 expand its pipeline to eight therapeutic programmes across multiple modalities, including antibody-drug conjugates and T-cell engagers, with assets ranging from pre-clinical candidates to clinical-stage programmes.

Also Read: The 27 SEA biotech firms betting on cells, fermentation, and code

That is a wide starting point for a newly formed biotech company. In drug development, “pre-clinical” typically means a therapy is still being tested in the lab or in animal studies, while “clinical” means it has entered human trials. The jump between those stages is where many young biotechs struggle, as costs rise sharply and scientific promise meets regulatory, safety and manufacturing realities.

K2’s model is to identify drug candidates internationally and advance them through in-house development. In practice, that means the company is not beginning solely as a discovery lab. It is looking globally for promising assets, then using capital and development expertise to move them through the difficult middle stretch of biotech: from candidate selection to human proof-of-concept, and potentially towards commercial partnerships or approvals.

A platform built around global asset sourcing

K2 Therapeutics said it expects to grow its portfolio further through asset acquisition, capital deployment and development. The approach reflects a broader shift in biotech financing, where investors increasingly back teams that can source overlooked or underdeveloped science globally, rather than relying on a single internal platform.

This matters in Southeast Asia because the region’s biotech ecosystem is still young compared with those in the US, Europe, China, South Korea and Japan. Singapore has strong research capabilities and hosts major pharmaceutical manufacturing and regional headquarters operations, but building venture-scale therapeutic companies remains difficult. Drug development takes years, requires specialised talent, and depends on access to sophisticated clinical, regulatory and manufacturing infrastructure.

A US$50 million seed round gives K2 unusually deep early backing by regional standards. Seed rounds in software can be used to build a product and test the market. In biotech, that money is often spent on experiments, toxicology studies, manufacturing preparation, regulatory filings and early clinical work before any revenue is in sight. The scale of K2’s financing signals that MPM BioImpact is not treating the company as a small exploratory bet, but as a vehicle to assemble and advance a serious therapeutic pipeline.

MPM BioImpact manages more than US$3.5 billion in assets and has a long history of forming and financing biotechnology companies. Its decision to found K2 in Singapore is also notable at a time when global life sciences investors are looking beyond the traditional Boston-San Francisco axis for scientific talent, clinical access and new deal flow.

A CEO with commercial experience

Alongside the financing, K2 has appointed Ying Huang as CEO. Huang was previously chief executive and a board member of Legend Biotech, where he oversaw the development and commercialisation of cell therapies and the company’s expansion to more than 3,000 employees. Before Legend, he was head of biotechnology equity research at Bank of America Merrill Lynch.

That mix of operating and capital markets experience is important for a company like K2. Biotech CEOs are not only expected to understand the science; they must also raise large amounts of capital, prioritise programmes, manage clinical risk, negotiate with pharmaceutical partners, and explain complex data to investors and regulators.

Also Read: Singapore’s Biobot Surgical raises US$15.6M to take prostate-care robot global

“By combining global asset sourcing with experienced development leadership,” K2 can rapidly advance differentiated therapeutic candidates with the potential to address significant unmet medical needs, Huang said.

The quote is measured, but it captures the thesis. K2 is betting that the bottleneck in biotech is not only invention. It is also execution: knowing which assets deserve capital, which should be stopped early, and how to move the strongest candidates through a highly regulated system.

Why ADCs and T-cell engagers are attracting attention

Among K2’s notable programmes are antibody-drug conjugates, or ADCs, and T-cell engagers. Both areas have drawn intense investor and pharmaceutical interest globally.

ADCs are often described as targeted cancer therapies. They combine an antibody, which seeks out specific markers on diseased cells, with a toxic payload designed to kill those cells more precisely than traditional chemotherapy. The field has seen several major acquisitions and licensing deals in recent years as drugmakers race to build oncology pipelines.

T-cell engagers work differently. They are designed to bring immune cells, particularly T cells, into close contact with cancer cells so the immune system can attack them. The idea is powerful, though developing safe and effective T-cell engager therapies can be scientifically and clinically challenging.

K2 has not disclosed the specific diseases targeted by its eight programmes, nor the terms of any asset acquisitions or licensing arrangements. That leaves key questions unanswered: how differentiated the candidates are, how much clinical data already exists, and how K2 will decide which assets deserve priority.

The competitive field

K2 Therapeutics will be entering a crowded global race. In Asia, companies such as China’s Akeso, Kelun-Biotech, DualityBio and RemeGen have drawn attention for antibody-based oncology drugs and ADC pipelines. Singapore has also produced antibody and oncology-focused biotechs such as Hummingbird Bioscience, while larger global players including Genmab, BioNTech, AstraZeneca, Gilead and Daiichi Sankyo are investing heavily in next-generation cancer therapies.

The competition is not only for patients or market share. It is also for assets, clinical trial sites, scientific talent, manufacturing capacity and partnership attention from big pharma. For a Singapore-based biotech, that means regional credibility alone will not be enough. K2 will need to show that its pipeline can stand up to global scientific scrutiny.

Still, Singapore offers some advantages. Its regulatory environment is considered predictable, its biomedical research base is deep for a country of its size, and its position in Southeast Asia gives companies a regional operating base close to diverse patient populations. For founders and investors, the challenge is turning those strengths into globally competitive drug development companies rather than regional outposts for multinational pharma.

K2’s US$50 million seed financing is therefore more than another funding announcement. It is a test of whether Singapore can host the next generation of biotech companies that are not merely doing research, but assembling, developing and potentially commercialising therapies for global markets.

Also Read: From lab to factory floor: ChemT nets US$4M to make cell therapies easier to manufacture

For now, K2 Therapeutics has capital, a sizeable early pipeline and a CEO who has taken advanced therapies from development into commercial scale. The harder part begins next: proving that the assets it has gathered can survive the long, expensive and unforgiving path from promising science to medicines that patients can actually use.

The post K2 Therapeutics raises US$50M to build global biotech pipeline from Singapore appeared first on e27.

Posted on Leave a comment

Strategic chokepoints: Designing leverage without owning everything

One of the laziest ambitions in strategy is the desire to own the whole stack.

It sounds bold in leadership meetings. It sounds defensible in investor conversations. It sounds like control. If we own more of the value chain, more of the customer relationship, more of the workflow, more of the economics, then surely we are building a stronger position.

Often, we are doing the opposite.

In many markets, trying to own everything is not a sign of strength. It is a sign that the firm has not yet understood where leverage actually lives. Ownership expands surface area. It increases execution burden. It drags the company into activities where it may have no real advantage. It creates cost, complexity, and management sprawl. Worst of all, it can distract leaders from the far more important question. Which part of this system truly matters enough that others will keep orienting around us, even if we do not own the rest.

That is where strategic chokepoints come in.

The strongest positions often sit between assets, not on top of them

A surprising amount of strategic thinking still assumes power sits with the party that owns the most assets. More infrastructure, more products, more distribution, more channels, more touchpoints. The image is imperial. The larger footprint must mean the stronger position.

Real markets are often organised differently.

Some of the most durable positions sit not with the actor that owns everything, but with the actor that sits at the point where different things have to come together. The place where supply meets verification. The place where data becomes decision. The place where activity becomes auditable. The place where users become billable. The place where risk becomes governable. The place where systems that do not naturally speak to one another must suddenly agree.

A chokepoint is where uncertainty has to be resolved

The clearest way to identify a real chokepoint is to stop asking where activity happens and start asking where uncertainty must be settled before activity can continue.

That is the deeper strategic move.

In many markets, the most valuable position is not at the point of creation or consumption. It is at the point of resolution. The place where someone has to decide whether identity is real, whether payment can be trusted, whether compliance is sufficient, whether a model output is acceptable, whether a supplier is approved, whether risk is within tolerance, whether a transaction can be recorded as final, whether a failure can be recovered without chaos.

Also Read: Why Southeast Asian startups should stop treating Europe as one market

Those moments are strategically rich because they are not optional. The surrounding market can innovate, fragment, diversify, and compete aggressively, but when it reaches a point where uncertainty must be converted into confidence, somebody has to perform that function.

Whoever performs it well can become disproportionately powerful.

Leverage is usually designed at the point where others need certainty

The original strategic instinct behind many great businesses is not, how do we own more. It is, how do we become the answer at the moment others need certainty faster than they can create it themselves.

That is a much more intelligent design question.

A strategic chokepoint can emerge around trust. It can emerge around technical compatibility. It can emerge around data custody. It can emerge around regulatory interpretation. It can emerge around reconciliation, recovery, settlement, or proof. What matters is not the category name. What matters is whether others start depending on that point to turn ambiguity into action.

This is why the best chokepoints often feel smaller than the markets they influence. They are concentrated. They do not need to carry the whole weight of the system. They only need to sit at the moment where the system cannot proceed safely, credibly, or efficiently without them.

Once that happens, leverage follows almost naturally.

The weak version of this idea is bottlenecking, the strong version is coordination

Not every chokepoint is strategically healthy. Some are little more than bottlenecks. They create friction without adding enough legitimate value. They slow the system down, tax it, or trap participants through inconvenience rather than through necessity. Those positions may produce short term leverage, but they also invite resentment, workaround behaviour, regulation, or eventual displacement.

The stronger version of a chokepoint is different. It improves coordination.

A legitimate chokepoint does not merely obstruct passage. It makes passage safer, faster, more intelligible, more governable, or more trusted. It reduces transaction cost. It lowers institutional anxiety. It gives multiple participants a shared basis on which to act. It helps the market function at a level of scale or complexity that would otherwise be difficult to sustain.

That is why the best strategic chokepoints are not experienced as pure extraction. They are experienced as useful compression. They narrow the system at the exact place where narrowing is valuable.

This is also why they last. Participants may not enjoy dependence, but they will tolerate it when the alternative is disorder.

Designing a chokepoint means designing a habit in the market

A useful way to think about strategic leverage is that the company is not simply building a product or service. It is trying to build a habit in the market.

Not a consumer habit in the narrow behavioural sense, but a systemic habit. A repeated pattern in which others begin to assume that before they proceed, they should pass through this layer. Before a model is trusted, it must be reviewed here. Before a vendor is activated, it must be cleared here. Before value is counted, it must be recorded here. Before a workflow scales, it must connect here.

That habit is what turns a useful position into a durable one.

Also Read: The myth of the neutral stack: Why SEA startups can no longer sit on the fence

The deeper point is that leverage compounds when the market starts organising itself around your existence without having to be forced. Once institutions begin embedding you into policy, process, reporting, integration design, or internal governance, the relationship is no longer just commercial. It becomes operational and cognitive. You are no longer merely chosen. You are expected.

That is the point at which designing a chokepoint starts to look less like product expansion and more like market architecture.

The danger is becoming so powerful that you weaken your own legitimacy

The more important a chokepoint becomes, the greater the temptation to overuse it. Companies start increasing take rates, privileging their own offers unfairly, reducing transparency, or changing rules in ways that maximise extraction at the expense of trust. That is usually the beginning of strategic decay, even if the financial effects take time to show.

A chokepoint remains durable only while participants believe the power attached to it is being exercised in a way that preserves the health of the broader system. Once that belief breaks, market actors start building alternatives, regulators become more interested, and internal defenders inside customer organisations become less willing to protect the relationship.

This is why the strongest chokepoints are governed, not merely exploited.

They carry a burden of stewardship. The company at the centre has to act in ways that keep the market willing to route through it. That means predictability, fairness, quality control, and enough restraint that dependence does not start to feel intolerable.

In other words, the position has to remain useful enough to stay legitimate.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Strategic chokepoints: Designing leverage without owning everything appeared first on e27.

Posted on Leave a comment

The new ransomware playbook: Why ASEAN banks are losing the disclosure war

Late last year, a regional bank in Southeast Asia received an unusual email. Not from the attackers, but from their regulator. The supervisor had received an anonymous tip claiming the bank had suffered a major data breach two weeks earlier, with sample customer records attached as proof. The breach had happened. The bank had not yet finished its internal investigation, let alone disclosed it.

The attackers had taken the disclosure decision out of the institution’s hands.

That scenario, repeated quietly across the region in the past eighteen months, is the part of the ransomware story most ASEAN bank defences are not built for. The playbook the attackers are running today is not the playbook the banks have been training against, and the consequences are starting to show up in regulatory fines, customer notification disasters, and senior executive resignations that were preventable.

What the old playbook looked like

For most of the past decade, ransomware against banks worked in a predictable shape. Attackers gained access through phishing or unpatched vulnerabilities. They moved through the network. They encrypted critical systems. They demanded payment in cryptocurrency in exchange for a decryption key. The institution restored from backups when it could, paid quietly when it could not, and disclosed when it had to.

The defensive playbook was built around this model: offline backups, phishing training, network segmentation, ransom-payment policy, cyber-incident responder relationships. Most major banks across ASEAN have invested heavily here over the last five years. The investments were sound. They are not sufficient anymore.

Also Read: Singapore’s cybersecurity paradox: Leading in digital, lagging in defense

What changed in 2024-2025

Three shifts have happened, and they compound.

Data first, encryption second. Modern ransomware operators no longer begin with encryption. They begin with months of quiet exfiltration. By the time encryption runs, the attackers already hold a complete copy of the institution’s most sensitive data, customer records, internal communications, board materials, sometimes regulatory correspondence. Restoring from backup solves the operational disruption. It does nothing about the data the attackers still have.

Triple extortion. The single threat of decryption has become three threats in parallel. Pay or the data is released publicly. Pay or we sustain a denial-of-service against your customer-facing systems. Pay or we contact your most important enterprise clients directly. Each vector runs independently. Each has a different remediation cost. Banks built to negotiate against one threat are now negotiating against three.

Regulatory weaponisation. This is the shift most ASEAN supervisors are not yet talking about openly. Attackers have started using the institution’s own disclosure obligations as leverage. They contact the supervisor before the bank does. They release sample data publicly to force a notification clock. They threaten to alert the press, the regulator, and major enterprise customers simultaneously, knowing that the regulatory fine for delayed disclosure may exceed the ransom. The disclosure decision has effectively been transferred from the institution’s risk committee to the attacker’s keyboard.

Why ASEAN banks are more exposed

Three regional factors sharpen the exposure here.

Outsourced perimeter. Most ASEAN financial institutions have moved meaningful portions of their operational stack into third-party platforms over the past decade. The attackers have noticed. The entry point into a major bank now often runs through a smaller vendor with weaker security, and the dwell time inside the network is long enough that the attack is well-staged before the bank knows it has been compromised.

Disclosure rule asymmetry. Indonesia’s disclosure framework is lighter and more recently codified than Singapore’s. The Philippines and Vietnam are still building theirs. Attackers selecting targets can choose jurisdictions where regulatory pressure is high enough to weaponise but defensive cyber budgets are not at Singaporean levels.

Supervisor capacity. Banking supervisors and central banks across ASEAN have built cyber risk capability steadily but unevenly. Few of them have a standing capability to receive and triage attacker-initiated disclosures, which is exactly the channel the new playbook depends on.

What is starting to work

A few institutions are responding ahead of the curve.

Pre-staged disclosure plans. The banks handling this best now have legal, communications, regulatory, and executive escalation pre-staged for a scenario where disclosure is forced by an external actor rather than chosen internally. The plan does not eliminate the damage. It reduces the cost of the first seventy-two hours.

Adversary-aware tabletop exercises. The most useful incident response exercises I have seen in the past year simulate not just the technical attack but the multi-front pressure campaign that comes with it. The institutions running these exercises with their boards and regulators are surfacing gaps that purely technical drills do not.

Vendor risk visibility. The institutions tracking which vendors hold their data, with what controls, and under what notification obligations are catching threats earlier than those still treating vendor risk as a procurement question.

Also Read: The demand for SMB cybersecurity is inevitable, the supply was never built correctly

What needs to happen

Three moves would meaningfully shorten the gap.

Update incident response playbooks for forced disclosure. The assumption that the institution controls the timing of its own breach disclosure is no longer reliable. Plans should assume the attacker may move first, and rehearse for that scenario.

Harden the supervisory channel. Regulators should publicise a standardised process for attacker-initiated disclosures, and require banks to reciprocate with internal escalation triggers. The current ambiguity benefits the attackers.

Treat vendor security as systemic. The cyber resilience of a major bank is now functionally a property of the weakest critical vendor it depends on. Vendor risk and cyber risk are no longer separate problems.

The macro stakes

The ransomware threat against ASEAN financial institutions has moved out of the IT department and into the regulatory, legal, and reputational layers that sit above it. The defensive playbook still sits, in most institutions, with the technical teams. The next significant ransomware event in this region is unlikely to be lost in the data centre. It will be lost in the seventy-two hours after the attacker emails the supervisor.

The banks that win those seventy-two hours will be the ones whose CROs, CISOs, general counsels, and communications heads have already run the scenario together. The banks that lose them will be the ones still treating ransomware as an IT problem.

The playbook has changed. The defence needs to change with it.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The new ransomware playbook: Why ASEAN banks are losing the disclosure war appeared first on e27.

Posted on Leave a comment

The hidden problem inside AI teams isn’t skills — it’s the human environment

A few weeks ago, an SME CEO shared his frustration with me over coffee.

His company had invested heavily in AI tools over the past year. Licences were purchased. Teams attended workshops. Managers were instructed to integrate AI into workflows. Like many businesses today, the organisation moved quickly because it feared falling behind.

Yet despite the investment, adoption remained uneven.

Some teams were using AI aggressively while others barely touched it. Junior employees were often highly fluent with the tools but lacked the business judgment to evaluate outputs critically. Senior staff possessed deep domain expertise but were slower, more cautious, and at times resistant to AI-assisted workflows.

At one point, the CEO leaned back and said something I have heard increasingly often lately.

“The problem is my people. The tools are only as good as the people using them.”

At first glance, this sounds entirely reasonable. Most organisations still approach AI implementation as a capability problem. The assumption is straightforward: train employees, improve prompting skills, close the competency gap, and adoption will follow.

But as he continued speaking, something more interesting began surfacing beneath the frustration.

What he was describing was not merely a people problem. It was a human environment problem.

Because before people make decisions, before teams collaborate, before judgment becomes visible, something else quietly shapes the conditions under which those decisions form.

The environment.

And AI is redesigning that environment far more profoundly than most organisations realise.

Recent research into AI-augmented teams suggests that AI is no longer functioning merely as a passive software tool. Increasingly, it behaves more like an active participant inside the decision environment itself, summarising discussions, synthesising opinions, generating recommendations, shaping meeting outputs, and influencing what becomes visible to the group.

That distinction matters enormously.

Because most organisations still operate with an outdated assumption: humans think, AI assists. But what happens when the environment itself begins participating in thought formation?

Also Read: AI agents could help Southeast Asian firms untangle cross-border payment costs

As the CEO continued describing the tension inside his company, a pattern emerged. Junior staff often moved faster with AI because they were more comfortable experimenting. They generated outputs rapidly, contributed confidently in meetings, and adapted quickly to AI-driven workflows.

Senior employees behaved differently.

They questioned outputs more carefully. They noticed contextual gaps. They distrusted overconfident synthesis. They understood where nuance could disappear. Years of experience had trained them to recognise ambiguity, political complexity, and hidden operational realities that AI-generated summaries could flatten.

Ironically, the very people with the strongest judgment were often the slowest adopters.

This dynamic aligns closely with what researchers are beginning to call the “Expertise Paradox.” Studies increasingly suggest that while AI significantly boosts novice performance, experts often engage more cautiously because they are more sensitive to inaccuracies, overgeneralisation, and the erosion of tacit expertise.

Most organisations interpret this as resistance. But that may be a dangerous misreading. Because what looks like resistance may actually be discernment.

At the same time, a growing movement around “vibe teaming” is accelerating inside AI-enabled workplaces. The idea is deceptively simple: humans and AI collaborate in fluid, fast-moving loops where AI captures conversations, synthesises insights, drafts outputs, and accelerates execution. Researchers at the Brookings Institution recently demonstrated how teams could produce sophisticated strategic briefs in under 90 minutes using these approaches.

On the surface, this appears highly efficient. And in many cases, it is. But it also introduces a deeper organisational tension.

The systems that make collaboration faster may also reshape the conditions under which judgment, disagreement, expertise, and strategic clarity emerge.

As AI continuously summarises discussions and smooths complexity into coherent outputs, organisations can begin drifting toward what might be called consensus acceleration: the compression of disagreement through AI-mediated coherence.

Minority viewpoints become easier to flatten. Nuanced expertise risks being compressed into “clean” strategic summaries. Teams may begin mistaking rapid synthesis for deep understanding.

This is where many AI implementation conversations become too shallow.

The real issue is not whether employees possess enough AI skills. The deeper issue is whether organisations understand the human systems surrounding those skills.

Because every organisation operates inside invisible conditions, conditions that shape confidence, authority, participation, visibility, legitimacy, and interpretation. AI amplifies all of these dynamics. Sometimes positively. Sometimes dangerously.

This means the future leadership challenge may no longer be simply, “How do we get our people to use AI?”

The more important question may become: “What kind of decision environment are we creating around human judgment itself?”

Because the future bottleneck may not be AI capability. It may be organisational interpretive capacity. The ability of teams to distinguish signal from noise, preserve nuance under pressure, challenge false coherence, and maintain cognitive quality while operating at speed.

That changes the leadership conversation entirely.

Also Read: Securing Agentic AI for Singapore enterprises: A reference architecture

The companies that succeed in the next phase of AI transformation will likely not be the ones with the most tools. They will be the ones that consciously design environments where expertise is protected rather than flattened, where disagreement survives long enough to improve thinking, where AI accelerates exploration without replacing discernment, and where senior employees become stabilisers of strategic clarity rather than perceived obstacles to innovation.

Research increasingly supports this direction. Emerging work in human-AI complementarity suggests that the highest-performing organisations are not those replacing human judgment, but those deliberately designing collaborative structures where humans and AI contribute different cognitive strengths.

In practical terms, this means organisations must stop treating AI implementation purely as a technology rollout. It is a human environment redesign challenge.

Leaders may need to rethink meeting structures, decision-making rhythms, mentoring systems, review processes, and how authority itself operates inside AI-enabled teams.

Some teams may require deliberate environmental friction where strategic decisions cannot be finalised immediately. Others may require structured dissent loops where minority viewpoints are protected instead of compressed by rapid synthesis. Experienced employees may need to operate not merely as contributors, but as stewards of cognitive quality inside accelerated systems.

Because the future advantage of organisations may not belong solely to those who move fastest. It may belong to those who can preserve discernment while operating under acceleration.

The most important transformation happening inside AI-enabled companies is not technological. It is environmental.

And the real competitive edge may no longer come from AI alone. It may come from the ability to consciously design the human environments operating upstream of decisions themselves.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The hidden problem inside AI teams isn’t skills — it’s the human environment appeared first on e27.

Posted on Leave a comment

No fans, no fridges, just paint: ZERC’s founder on cracking SEA’s cooling crisis

ZERC founder Lee Heon  (blue shirt) with his team mates

In much of Southeast Asia, heat has stopped being a seasonal inconvenience and become an infrastructure problem. Parked cars can hit cabin temperatures of 70 to 90 degrees Celsius within minutes, air-conditioning strains power grids at peak demand, and concrete-heavy cities from Bangkok to Jakarta trap heat well into the night.

ZERC, a deeptech startup spun out of Korea University in November 2022, believes part of the solution could be as simple as a coat of paint. Founded by materials science professor Lee Heon, the company has developed a water-based radiative cooling paint that reflects 96 per cent of sunlight and radiates over 93 per cent of absorbed heat back into space, lowering surface temperatures without consuming any electricity.

Also Read: Korean startup ZERC develops paint that cools roofs, vehicles, and helmets

Unlike many competitors that rely on toxic, solvent-based formulations, ZERC’s paint uses polymers, water, and ceramic pigments, eliminating volatile organic compound emissions at the source. The company is targeting rooftops, vehicles, ships, industrial equipment, and even safety helmets, positioning paint as a cheaper, more versatile alternative to radiative cooling panels and films.

We spoke to Lee about ZERC’s Southeast Asia (SEA) strategy, the true economics of the technology, and the obstacles standing between the startup and its first large-scale commercial deployment in the region.

Edited excerpts:

SEA looks like your toughest and most promising market. What’s the actual go-to-market plan? Direct sales, licensing, or partnerships?

We’re keeping all three options open. Our initial strategy is to export the finished product into Southeast Asia, establish its performance and credibility there, and then expand with local partners. Ultimately, we envision local production through licensing agreements with regional paint manufacturers.

SkyCool uses panels, SpaceCool uses film, RadiaCool focuses on EVs. You’ve bet everything on paint. Where might that bet lose?

Paint is the most versatile, commercially applicable format of radiative cooling technology. It has a relatively low manufacturing cost, can be applied easily over very large areas, and works on curved or irregular surfaces where panels and films are more limited. Installation costs are also significantly lower than film.

For these reasons, I believe cooling paint has the potential to dominate the radiative cooling materials market. Its main weakness is that manufacturing cost is still higher than conventional paint, though that additional cost is typically recovered within one to two years through energy savings.

Water-based formulations are often criticised for weaker adhesion and shorter lifespans than solvent-based ones. How did you solve that trade-off?

Water-based paint is more environmentally friendly, but its coating durability is generally inferior to oil- or solvent-based paint. So I expect solvent-based cooling paints to gain market adoption first.

Also Read: 5 Seoul startups made their Southeast Asia debut at Echelon Singapore 2026 under the SBA pavilion

In the longer term, however, as water-based formulations improve and environmental regulations tighten, I expect water-based radiative cooling paints to become increasingly important.

You claim that the cooling effect can last for more than five years. Has this claim been validated through multi-year field testing in tropical conditions, or is it extrapolated from lab ageing tests?

It’s currently an estimate based on standard accelerated ageing tests. In harsher environments, actual lifespan could be shorter. Put another way: we expect performance comparable to conventional solvent-based exterior paints. If a conventional paint can maintain its coating for five years under a tropical monsoon climate with strong UV exposure, we expect our cooling paint to last just as long, or longer.

Walk us through the actual numbers — cost per square metre versus electricity savings for a mid-sized warehouse roof in Manila or Jakarta.

The paint costs around US$10 per square metre. Incoming sunlight carries over 1,000W/m² of energy; conventional paint reflects only 30 to 80 per cent of it, while ours reflects over 95 per cent. That means our coating absorbs roughly 500-600 watts less solar energy per square metre than conventional paint.

Assuming only half of that reduced heat load translates into lower cooling demand, and that a cooling system runs eight hours a day for 300 days a year, that works out to around 600 kWh of reduced heat load annually. With a cooling system coefficient of performance (COP) of 3, that equates to roughly 200 kWh saved per square metre each year. At about US$0.12 per kWh, that’s approximately US$24 in annual savings per square metre, meaning the paint’s additional cost can potentially be recovered within the first year.

Safety helmets are a strikingly different category from rooftops and ships. Genuine commercial priority, or proof-of-concept?

It’s essentially a proof of concept, though it could bring real benefits to outdoor workers enduring hot conditions. It demonstrates that the technology works not only on large structures, but also on small, irregularly shaped objects directly exposed to sunlight, solving the discomfort of sweat trapped inside a helmet.

Turning smelting slag into a cooling pigment is compelling, but industrial byproducts vary batch to batch. How do you guarantee consistent optical performance?

The slag-based paint, developed with South Korean steel manufacturer POSCO, is primarily a demonstration of sustainability and circularity potential rather than the core of our commercial strategy. In fact, without slag, we can produce a higher-performance radiative cooling paint. It shows how industrial waste can be upcycled into a functional material, rather than defining our product roadmap.

Which country are you targeting first for regulatory approval, and what’s been the biggest bureaucratic surprise?

We haven’t yet obtained certification in Southeast Asia –only in Korea so far. We expect regional requirements to be broadly similar, so we don’t anticipate certification being a major obstacle once we begin expanding in earnest.

EV battery-range preservation requires OEM-level integration, not just aftermarket application. Are you in talks with any EV or fleet manufacturers in the region?

Our initial EV application isn’t passenger cars; we’re testing the paint on electric bus roofs, running joint experiments with a global automobile manufacturer, with very promising results so far. We haven’t yet discussed this application with Southeast Asian EV or fleet companies, but we’d be very interested in joint testing with regional partners.

Also Read: Korea’s startup ecosystem is training founders, not just funding them

What’s the single biggest obstacle to ZERC’s first large-scale commercial deployment in Southeast Asia?

To launch large-scale projects there, our first priorities are securing sufficient funding and expanding our team. We’ll also need reliable local distribution and business partners. Manufacturing, however, isn’t likely to be the bottleneck; our facility in Ulsan, Korea, can already produce up to around five tonnes a day, and scaling further by using existing paint manufacturing facilities in Korea or Southeast Asia should be relatively straightforward. Our biggest immediate challenge is securing the funding, people, and local partners needed to accelerate commercialisation in the region.

The post No fans, no fridges, just paint: ZERC’s founder on cracking SEA’s cooling crisis appeared first on e27.

Posted on Leave a comment

Moving past the chatbox: The hidden risks of agentic AI and MCP in enterprise infrastructure

In Singapore, Hong Kong, and across the APAC region, the corporate adoption of Generative AI has completed its initial trial phase. Over the past year, enterprise technology leaders have realised that simple internal chatbots offer limited structural value. The real ROI lies in the next evolutionary phase: fully autonomous AI agents.

We are shifting from static AI “assistance” to dynamic “decision execution.”

However, as organisations rush to deploy autonomous agents that can pull enterprise context and execute live API actions across legacy silos, a critical infrastructure gap has emerged. In the race for velocity, many CISOs are inadvertently leaving the enterprise backdoor wide open.

The protocol shift: Why legacy security is blind to the semantic layer

The rapid rise of the Model Context Protocol (MCP) has changed the architecture of AI implementation. MCP allows large language models to seamlessly connect to secure, local data sources, development tools, and enterprise environments.

But from an infrastructure security perspective, this creates an unmanageable perimeter risk.

Traditional Web Application Firewalls (WAFs) and legacy Data Loss Prevention (DLP) systems operate at the network or packet layer. They are fundamentally blind to the semantic layer of LLM prompts and agentic workflows. They cannot parse what an autonomous agent is “thinking” or planning to execute.

When a localised agent leverages MCP to pull a massive code repository, database query, or customer PII profile to ground its context, it automatically bundles that proprietary data. The moment that bundle is sent to a third-party, public cloud LLM for inference, your data ownership is permanently compromised.

Also Read: From chatbots to payment agents: AI’s next role in SEA commerce

The three structural blindspots of agentic infrastructure

Having spent over two decades building enterprise protection systems, from the early days at Bell Labs and Symantec to engineering data security architectures at Websense and IBM, I see the current LLM landscape repeating the fatal mistakes of the early cloud migration wave.

There are three immediate risks stalling enterprise AI from moving safely into production:

  • The autonomy risk (shadow actions): Once an agent is granted execution rights via MCP to interact with internal databases, it becomes highly vulnerable to Prompt Injection. A malicious external input can hijack the agent’s logic, leading to unauthorised API execution or lateral escalation within your network. Post-incident auditing is simply too late.
  • The privacy paradox: To make an AI agent useful, you must feed it deep organisational data. But traditional security models force a brutal trade-off: you either compromise on AI intelligence by withholding data, or you trade away data privacy by passing raw tokens across your corporate boundary.
  • The FinOps nightmare: Autonomous agents operating in background loops frequently fall into execution deadlocks. A single looping agent misinterpreting a complex database schema can burn thousands of dollars in token expenditure within hours, while completely shattering your compliance audit trails.

Also Read: If AI can’t find your startup, does your startup exist?

Rebuilding the boundary: Inline, client-controlled governance

To unlock the true power of Agentic AI without exposing critical core assets, APAC enterprises must shift from reactive monitoring to proactive, runtime governance.

Security cannot act as the emergency brake on innovation; it must become the accelerator.

The industry requires a fundamental architectural upgrade: a centralised AI Access Gateway that deploys a client-controlled data plane directly at the boundary level.

Before an agentic prompt or an MCP resource payload ever hits an external LLM provider, the data plane must execute real-time, zero-trust token scrubbing. It must de-identify PII, strip sensitive API keys, and mask core proprietary source code locally, inside your domain. Once the model returns its response, the gateway dynamically re-identifies the tokens, allowing the local workflow to execute seamlessly.

Furthermore, this orchestration layer must feature circuit breakers to halt deadlocked agents and implement intelligent model routing, automatically offloading long-context, low-risk MCP tasks to highly optimised local open-source models to manage FinOps overhead.

As AI transitions from a novelty to the digital foundation of modern commerce, the question is no longer about which model is the smartest. The real question is: Who controls the data plane that keeps those models safe?

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post Moving past the chatbox: The hidden risks of agentic AI and MCP in enterprise infrastructure appeared first on e27.

Posted on Leave a comment

The system behind the smile: How to make volunteer efforts sustainable

When a resident faces a difficult problem, a community volunteer is often the first person willing to listen.

The issue may involve housing, employment, financial hardship, healthcare, family concerns or a neighbourhood dispute. What begins as a simple conversation can quickly become a complicated process involving documents, appeals and coordination with government agencies, social-service organisations or non-profit groups.

Volunteers step forward because they care. Yet goodwill alone cannot carry an unlimited workload.

Community needs will continue to grow, and not every problem can be resolved quickly. If programmes depend mainly on personal dedication and informal knowledge, even committed volunteers may become overwhelmed.

The real question is not how to persuade volunteers to put in more effort. It is how to ensure that every hour they contribute creates meaningful and sustainable impact.

Goodwill is not an operating system

Many volunteer initiatives are built on an admirable belief: when people care enough, they will find a way to help. That works until problems become more complex.

A volunteer may need to identify the responsible organisation, gather documents, prepare an appeal, explain the resident’s circumstances and follow up several times.

Without a clear workflow, experienced volunteers often carry the heaviest burden because they know the procedures and contacts. New volunteers may hesitate because they fear giving incorrect advice. Residents may repeat the same story to different people, while volunteers may duplicate one another’s work.

This is not a lack of commitment. It is a system-design problem.

Employees cannot perform consistently without clear processes, appropriate tools and defined responsibilities. Volunteer organisations are no different.

Define the volunteer’s role

Volunteers are most effective when they understand both their responsibilities and their limits.

They can listen, clarify the main concern, gather essential information, explain available support, make referrals and help residents communicate with the relevant organisation. However, they should not be expected to replace social workers, lawyers, healthcare professionals, counsellors or government officers.

Also Read: Why building a people-first work culture in HR tech matters more than ever in Southeast Asia

Clear boundaries protect both the volunteer and the resident.

A volunteer should never feel pressured to promise an outcome that depends on eligibility rules or an agency’s decision. Matters involving immediate danger, family violence, serious mental-health concerns or severe financial distress should be escalated promptly to qualified professionals.

A three-level system can help: routine enquiries are handled by trained volunteers, complex cases are referred to experienced coordinators, and urgent or specialised matters are transferred to professional support.

Make the work visible

One of the most effective improvements is a shared case-management process.

A secure system should record the resident’s concern, documents received, organisations contacted, actions taken, responses obtained, the next step and the person responsible for follow-up.

This prevents cases from being lost when a volunteer becomes unavailable. It reduces repeated explanations and allows another team member to continue the work. It also turns individual experience into organisational knowledge.

If applications are delayed because the same document is missing, the organisation can improve its checklist. If cases are repeatedly sent to the wrong department, the referral guide can be updated. If residents often misunderstand a process, volunteers can be given clearer communication materials.

Technology can support this, but the solution need not be expensive. A small group may begin with a secure digital form and controlled-access tracker. A larger organisation may require a case-management platform with reminders, permissions and audit records.

The aim is not to automate compassion. It is to remove administrative friction so volunteers can spend more time helping people.

Train for real situations

Volunteer orientation often focuses on values, expected behaviour and programme objectives. These matter, but volunteers also need practical skills.

They should know how to conduct a structured conversation, identify the central issue, ask for relevant information and distinguish confirmed facts from assumptions.

They should also learn to write concise appeals. A strong appeal explains the resident’s circumstances, assistance already sought, supporting documents available and the specific action requested.

Other essential areas include privacy, conflict management, respectful communication and emotional boundaries.

Scenario-based training is especially useful. Volunteers can practise realistic cases, identify missing information, decide which organisation should be approached and recognise when escalation is necessary.

Experienced volunteers can serve as mentors, but this role should not be assigned automatically. A person may be knowledgeable without knowing how to guide others. Effective mentors explain their reasoning, demonstrate good practices, observe newer volunteers and provide constructive feedback.

Build stronger agency partnerships

Many volunteers become frustrated not because they are unwilling to help, but because they must navigate multiple organisations with unclear responsibilities.

Public agencies, social-service organisations and non-profit groups can support volunteers by providing updated referral guides, designated contact channels and clearer explanations of eligibility requirements.

Where several organisations are involved, someone should coordinate the next step. Repeatedly redirecting a resident may be procedurally correct, but it can create the impression that nobody owns the problem.

Even a basic referral-status system could help. Volunteers may not need access to confidential details, but confirmation that a referral has been received, assigned or completed would reduce repeated calls and emails.

Sometimes the most useful innovation is ensuring that the correct information reaches the correct person at the correct time.

Also Read: Human value in the AI era is not what most people think

Measure contribution fairly

Volunteer effectiveness should not be judged only by the number of cases resolved. Many outcomes depend on regulations, eligibility criteria, funding and decisions beyond a volunteer’s control.

Better measures include response time, referral accuracy, documentation quality, communication, teamwork and whether the resident understands what will happen next.

Organisations should also monitor volunteer wellbeing. Warning signs include a small number of people handling most difficult cases, frequent late-night follow-ups, rising frustration and volunteers gradually withdrawing.

Recognition should be specific. Leaders can acknowledge a volunteer’s patience, accurate record-keeping, sound judgement, teamwork or ability to manage a difficult conversation respectfully.

Residents must be partners too

Community assistance cannot be completely one-sided.

Residents should provide accurate information, prepare necessary documents, attend appointments and allow reasonable time for organisations to respond. Volunteers should explain these expectations early so residents understand that assistance is a partnership, not an unlimited service.

There will also be cases where the requested outcome cannot be achieved. Volunteers should then provide an honest explanation and, where possible, suggest another pathway.

Sustainable volunteerism should not depend on heroes

Communities often celebrate volunteers who go far beyond what is expected. Their dedication deserves appreciation.

However, a strong volunteer programme should not depend on a few individuals repeatedly sacrificing their time, energy and wellbeing.

A sustainable model shares knowledge, documents cases, trains volunteers, defines escalation routes and builds reliable working relationships with agencies. It allows experienced volunteers to take a break without leaving residents unsupported and gives new volunteers confidence to contribute effectively.

The best volunteer is not necessarily the person who handles the most cases alone. It is the person who works responsibly within a trusted system, collaborates with others and helps residents move from uncertainty towards a practical next step.

Volunteerism will always begin with goodwill. But goodwill creates greater impact when it is supported by sound operations, useful technology, practical training and shared responsibility.

Volunteers do not need endless demands for more effort. They need systems that ensure their effort truly matters.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post The system behind the smile: How to make volunteer efforts sustainable appeared first on e27.