Closing the AI Governance Gap
Notes from a conversation with senior executives on enterprise AI adoption and control

There is a quiet gap. Personal AI tools are showing up on corporate expense reports. Corporate AI tools are being used for personal side projects. The AI adoption is real. The governance isn't. 💡
Last week I spoke to hundreds of the most senior executives in Singapore - in collaboration with the Claude Singapore Community and Anthropic - about the question I hear in every enterprise AI conversation across APAC:
How do you close the gap between how AI is actually used and how it's governed?
The answer isn't 'ban the tools.' It's to offer something better - with security, privacy, compliance, and governance built in from day one.
'Stored here' and 'processed here' are different promises
Your data at rest is like money in a vault - it sits where you put it. An inference request is a card swipe - and the swipe may clear through a different geography.
You need to understand the storage, processing, access, and downstream flows. Then you have a residency answer. Otherwise, you only have a residency assumption.
This distinction matters deeply in regulated industries and across ASEAN, where data sovereignty isn't just a compliance checkbox - it's a trust requirement. 🎯
You don't have to pick one operating model only
You need to know which one fits which use case.
There are multiple operating models for enterprise AI - each has different governance boundaries, different data processing relationships, and different commercial structures.
Many organisations run more than one simultaneously. For example: governed seats for productivity, controlled infrastructure for regulated workloads, and developer-first surfaces for speed.
The organisations that are moving fastest aren't the ones that picked a single path. They're the ones that mapped their use cases to the right operating model - and built the governance layer to match.
Governance is not a checklist
The organisations pulling ahead are designing systems where non-compliance is structurally impossible.
Enforceable policy over paper policy. Denied-by-default over approved-by-memo.
The question isn't whether you have a compliance statement - it's whether your infrastructure can actually enforce it. 🔹
This is where human-first AI shows up in practice. Good governance doesn't slow people down. It gives them the confidence to move faster, because the guardrails are built into the system itself.
The energy in the room
This session was a collaboration with the Claude Singapore Community's Freddy Lim, Anthropic team members Daragh McGough and Eric C, as well as my AWS colleagues Mark Tay, Jake Khoo, and Karen Teo.
I'm grateful for the incredible energy in the room. The questions from the audience were sharper than most board decks I've read.
If your organisation is navigating the tension between AI adoption and governance - including data sovereignty - I'd love to hear how you're solving it. Drop a comment or reach out directly. 🙏
The gap between adoption and governance won't close itself. But together, we can design systems that make the right thing the easy thing.
#AlwaysDay1 #EnterpriseAI #AIGovernance #DataSovereignty #ResponsibleAI #AIStrategy #GenAI
Gallery


The views and opinions expressed in this post are my own and do not necessarily reflect those of my employer or any organisation I am affiliated with.