Organisations hold back on scaling agentic AI due to trust issues

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Agentic AI adoption across Asia-Pacific is widespread but governance infrastructure is lagging badly, according to Sumsub’s Asia-Pacific State of Digital Trust report, which surveyed 720 business decision-makers across nine markets. Only 50% of organisations can reconstruct an AI decision pathway, and just 38% maintain tamper-proof audit trails, even as 95% claim confidence in explaining AI decisions. A separate Boomi/Forrester study of 409 IT decision-makers found that 86% have deployed AI agents but only 34% trust what those agents actually do. Singapore’s own numbers are worse than the regional average on evidence production.

What this means for your business

The confidence-capability gap here is the story. Ninety-five percent of respondents say they can explain an AI decision; fewer than half can actually reconstruct the decision pathway that would let them prove it. That gap isn’t a training problem or a culture problem. It’s an instrumentation problem, and it sits squarely in the CISO’s jurisdiction. If your organisation is in the majority that has deployed agents but hasn’t built tamper-proof audit trails (the kind that can survive a regulator’s request or a legal discovery process), you’re not cautious, you’re exposed while believing you’re covered.

The traceability score of 61% being the weakest of the three governance dimensions is worth sitting with. Autonomy and responsibility scores hover around 70%, which suggests organisations have made deliberate choices about where agents act and who nominally owns outcomes. What they haven’t built is the technical layer that would let them verify those ownership claims after the fact. An audit trail that can be tampered with isn’t an audit trail, it’s a liability dressed as a control. Financial services leads the verticals at 63.3% traceability, with only 41% holding tamper-proof records, which means the sector with the most regulatory scrutiny is still betting that a post-incident reconstruction will hold up.

The Boomi finding that organisations with genuine agentic readiness show 55% confidence versus 22% for those in “agentic chaos” suggests the gap compounds quickly. Organisations that skip instrumentation now aren’t just behind on a compliance checklist; they’re building agents on top of a foundation that makes every future deployment harder to defend. The falsification condition for optimism here is straightforward: if your organisation can produce a tamper-proof, end-to-end audit trail for every autonomous action an agent takes in a regulated workflow today, this story isn’t about you. If you can’t, the question your next vendor renewal should force is whether the platform you’re buying agents from can actually generate that evidence, or whether it’s treating governance as a roadmap item.

Concept deep-dive: Tamper-proof audit trail

A tamper-proof audit trail is a cryptographically secured, append-only log of every action an AI agent takes, including inputs, decisions, and outputs, structured so that no one can alter or delete entries after the fact. Think of it as a flight data recorder for AI decisions. It exists because regulators and courts need proof that a system behaved as claimed, not just an organisation’s word. Without it, accountability for an AI-driven outcome is a policy on paper rather than a fact you can demonstrate.

Based on reporting from Organisations hold back on scaling agentic AI due to trust issues, originally published 2026-08-04 23:00:00.

TAGGED:
Share This Article