
Artificial intelligence (AI) is rapidly transforming economies and societies across Southeast Asia. Governments are increasingly integrating AI into public services, while businesses are deploying AI tools to improve productivity, customer engagement, and decision-making. Research suggests that 43% of employees across Asia Pacific are using Gen AI for work purposes. As AI systems become more embedded in critical sectors such as finance, healthcare, education, and public administration, questions surrounding governance have moved from theoretical discussions to urgent policy priorities.
However, the pace of AI adoption has outstripped the development of governance capabilities in many organisations. Across the region, policymakers, businesses, and civil society are grappling with risks relating to privacy protection, algorithmic bias, data security, and transparency among others. The increasing use of generative and agentic AI systems has introduced new challenges that put into question the need for more adaptive principles and approaches to guide action when AI systems cause harm.
Against this backdrop, Keith Detros, Programme Manager at the Tech for Good Institute (TFGI), participated in the panel discussion “When AI Goes Wrong and How to Get it Right: Privacy Risks, Ethical Harm, and Accountable AI Governance” during the National Privacy Awareness Week 2026 conference organised by the National Privacy Commission. The panel brought together experts from government, industry, and civil society, to identify the risks that come with greater integration of AI in organisational processes, and best practices stakeholders can deploy for a more proactive response.
Moderator and Panellists
- Sandra Liu, Fellow, Center for Information Policy Leadership
- Royce Wee, Public Policy Director,META APAC
- Bo Kim, Head of Legal, Global Privacy Regulatory & Policy,Tiktok
- Sara Venturina, Chief Data Officer, GCash
- Keith Detros, Programme Manager, Tech for Good Institute
Key Takeaways
1. Shadow AI is a tangible risk to organisations
One of the most underestimated risks in AI deployment is not necessarily a major data breach or malicious AI system, but the proliferation of “Shadow AI” or the use of AI tools by employees outside formal organisational oversight. As AI tools become increasingly accessible, employees are adopting them to improve productivity, often without the knowledge of management, compliance teams, or data protection officers. This creates invisible data flows that organisations cannot effectively monitor. Research increasingly suggests that Shadow AI is becoming widespread. Microsoft’s 2024 Work Trend Index found that 78% of AI users bring their own AI tools to work, while 60% of leaders reported lacking a clear AI implementation strategy.
For the Philippines, the challenge is amplified by rapid AI adoption and relatively low public awareness of privacy rights. There is a growing gap between technological adoption and privacy literacy. Organisations may possess robust privacy and cybersecurity policies on paper, but accountability becomes impossible when decision-makers lack visibility into where AI systems are being used, what data they are processing, and how outputs are influencing decisions. Effective AI governance therefore begins with basic organisational visibility: mapping AI use cases, identifying data flows, and understanding where AI systems are operating before more sophisticated governance mechanisms can be applied.
2. Responsible AI governance requires updating existing governance systems
Existing frameworks across Southeast Asia (SEA) jurisdictions exist that can be used to govern emerging technologies. These include cybersecurity frameworks, data protection policies, consumer protection regulations, and vendor management protocols among others . The challenge is not the absence of governance structures, but whether these structures have been updated to reflect how AI systems operate.
Cybersecurity policies, for instance, can be updated to establish clear guidelines on the use of AI tools in the workplace, including protocols for employees who use personal AI accounts and safeguards to prevent the inadvertent disclosure of sensitive information. Similarly, data governance and privacy frameworks can be enhanced to account for AI systems that ingest, analyse, and repurpose data in complex ways, ensuring that organisations maintain visibility over how information is being processed and used. Ethics policies can also be expanded to address the growing role of automated and AI-assisted decision-making, particularly in contexts that affect individuals’ access to employment, financial services, customer support, or public services. By adapting existing governance mechanisms to reflect how AI systems operate, policymakers can address many emerging risks without waiting for entirely new AI-specific regulations or frameworks.
3. Accountability requires auditability, testing, and preparedness before failures occur
Accountability cannot be achieved after an AI incident occurs. It must be built into systems from the outset through robust auditability and testing mechanisms. Organisations should be able to reconstruct how an AI-assisted decision was made and whether safeguards were triggered during operation. AI accountability can be compared to aviation safety investigations, where flight data recorders enable investigators to reconstruct events after an incident. AI systems require comparable mechanisms through audit logs, data lineage records, monitoring systems, and documented decision trails. Without such records, determining responsibility becomes difficult, particularly in complex AI value chains involving developers, deployers, vendors, and end users.
Red teaming and adversarial testing before deployment are also crucial mechanisms. By systematically probing AI systems for vulnerabilities, organisations can identify weaknesses before they affect real users. Increasingly, governments and regulators are incorporating these approaches into AI governance frameworks. The Singapore Infocomm Media Development Authority’s recent work on legal responsibility for AI agents similarly highlights the need for documentation, testing, and traceability to support accountability across increasingly autonomous AI systems. Lastly, organisations deploying AI in high-impact contexts should also maintain continuity plans and human fallback mechanisms. As AI becomes embedded in core functions, there is a risk that human expertise and institutional processes deteriorate over time. The ability to pause or disable an AI system is therefore insufficient on its own; organisations must also ensure they can continue operating safely and effectively when AI systems fail.
