Shallow AI adoption is a board problem, not a technology one. The oversight model that answers it is portable.
What should a board actually do about shallow adoption?
Govern the depth of your own company’s AI use, because no board can fix the national statistic. The diagnosis behind that is now in. Six markets and four different kinds of number all land on one finding. Adoption is broad, depth is rare, and the published figures are too unstable to steer by. Roughly 8% of Southeast Asian enterprises have fully scaled AI (McKinsey and Singapore EDB, February 2026). And roughly three-quarters of the businesses that have adopted it at all are still at basic use (AWS and Strand Partners, 2025).
The national statistic was never measuring your company in the first place. What a board can govern is whether its own organisation ends up in the 8% or in the roughly three-quarters still at basic use. Until recently, not much was written for the person who has to ask that question out loud in a meeting.
Which is why the Singapore Institute of Directors’ AI Guide for Boards in Singapore, published in 2026, is worth a section of its own. It treats shallow adoption as a board problem rather than a technology one. After a fortnight in this data, that felt like someone opening a window.
I’m an SID Accredited Director, so weigh that as you like. I had no hand in writing it and won’t reproduce its roadmap or checklists here. Four things in how it is built line up with what the regional evidence shows.
It runs conformance and performance through one lens
The guide makes risk and growth one board job, held in the same discussion. Conformance is the compliance-and-risk side; performance is the strategy-and-returns side. The alternative is two committees that meet separately and disagree in private. In a region where breadth is high and value capture is low, that is the correct instinct. Governing the risk without governing the return produces precisely the pattern every regional survey keeps finding.
It names pilot purgatory
Pilot purgatory is AI work that runs as a trial forever and never reaches everyday use. The guide tackles it head-on. Set that against 8% fully scaled and the aim is unusually well judged. Most governance material braces for risks that haven’t happened yet. This one addresses a failure mode that’s already the regional default.
It separates best-in-class from only-in-class
The guide separates AI that makes existing work a little faster from AI that creates new business models. AWS measures that same distinction in every country and finds it missing in three-quarters of adopters. Boards have mostly lacked the words for it. Shared vocabulary is most of what a board needs in order to ask a useful question.
It scales oversight to impact
Oversight effort should match how much damage a system could do. The guide tiers its governance by risk rather than applying one uniform process to everything. That is what makes it usable by a 40-person company and not only a listed one. In a region whose business population is overwhelmingly small, that is not a detail. Directors who want to build the underlying literacy first will find it in my guide to AI fluency for board directors.
Why a depth instrument was needed is answered, uncomfortably, by AWS’s own Singapore study. Among Singapore SMEs that have adopted AI, only around 30% have a clearly defined person responsible for overseeing whether the AI is right. Six in ten would face significant or moderate disruption if that person left. About one in ten say their AI work would stop altogether. AWS’s own reading is that the ability to question an AI output “may still depend too heavily on individual confidence rather than a clear channel for raising concerns” (AWS, May 2026).
In other words, in the region’s most mature market, AI accountability is often one person. That person hasn’t been told it’s their job, and could resign on Friday.
That is a small-company finding, and the comfortable objection is that larger organisations have it solved. They have not.
The Sumsub benchmark assembled roughly the most AI-forward sample the region can offer. It surveyed 720 senior leaders in financial services, IT and software, e-commerce and mobility platforms. 60% of them were at enterprises rather than smaller firms. Then it asked what they could actually produce. 95% were confident they could explain an AI decision. 50% could reconstruct the decision pathway. 38% held a tamper-proof audit trail. Over the same twelve months, 92% had stretched an AI system past its original purpose. And 63% had already watched an autonomous action produce an unintended or problematic outcome, 31% of them more than once (Sumsub and Blackbox Research, 2026).
Read those in order and the board problem states itself. Confidence is close to universal, evidence is not, and the systems running today have drifted away from the ones that were signed off. The report calls that gap the accountability asymmetry: owning an outcome without being able to reconstruct it. It is a better name than anything I had for it.
It also closes a question the regional depth data leaves open. Shallow use is not a small-company condition, and it is not a poor-market one. This is the sample most likely to have got past it. Yet only 31% report AI that initiates or completes tasks across several steps with limited human input. The rest top out at rule-based execution or routine automation. Different instrument, different definition, three countries the regional depth data never reached, and still no more than a third at the top.
One caveat, because it cuts both ways. Sumsub sells identity verification, and the report lands on binding every AI action to a verified human identity, which is the product. The fieldwork was run independently by Blackbox Research, with the sample, the method and the dates all disclosed. That is more than most vendor research offers. And the central finding is uncomfortable enough for Sumsub’s own buyers that I am inclined to trust the direction of it. Read the numbers, discount the conclusion.
Citation capsule
Across nine Asia-Pacific markets, 95% of organisations say they are confident they can explain an AI decision, but only 50% can reconstruct the decision pathway and just 38% hold a tamper-proof audit trail. Within the same twelve months, 92% had expanded an AI system beyond its intended use and 63% had experienced an autonomous AI action with an unintended or problematic outcome. Only 31% report AI that initiates or completes tasks across multiple steps with limited human input. The survey covered 720 senior technology, product, risk, compliance and operations leaders in financial services, IT and software, e-commerce and mobility, fielded April to June 2026 by Blackbox Research for Sumsub in partnership with the Singapore FinTech Association. (Sumsub and Blackbox Research, 2026)
Then the guidance problem. Of the SMEs that found industry-specific AI guidance at all, around two-thirds had to adapt it significantly before it was usable. Only a minority found it directly applicable: 20% in healthcare, 17% in financial services, 13% in manufacturing. Guidance written for a sector in the abstract does not survive contact with a particular business. Guidance written for a role has a better chance, and a board is a role.
The biggest challenge is turning AI from a powerful tool into a system-level solution. This requires not only technical integration with hospital infrastructure, but also alignment with clinical workflows and reimbursement models.
Reimbursement models. No AI vendor’s deployment guide has a section on reimbursement models, and no generic sector playbook could. The answer differs by country, by insurer and by procedure. That is the adaptation tax those Singapore SMEs were describing, expressed by someone paying it.
For the accountability structures underneath all this, see my guide to AI agent governance for Singapore boards.
Does your board need to get current on AI governance quickly, without a stock deck? I run customised board and C-suite sessions built around your actual deployments, your sector and your regulatory exposure. As an SID Accredited Director who builds and runs these systems day to day, I can brief a board from both sides of the table. Get in touch.
Does the guide travel across ASEAN?
The architecture travels. The statutory layer does not.
A board in Ho Chi Minh City or Bangkok can’t lift a Singapore guide wholesale, because it’s built on Singapore’s law. What does travel is the shape of it. Treat risk and growth as one job. Tier your oversight by how much damage a system could do. Name who is answerable, and make that name hard to pass on. Set how often the board looks. What stays behind is PDPA, MAS guidance and AI Verify.
That split matters more each quarter, because ASEAN is drifting apart on AI rules rather than together. Seven of the ten member states now have an AI governance policy: Brunei, Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam. Brunei was the latest to move, releasing its guide in late 2025. Cambodia, Laos and Myanmar are still writing theirs. Timor-Leste, the newest member, has a digital strategy that doesn’t yet mention AI at all (ISEAS Perspective 2026/13, 2026).
And the seven have not moved in step. Vietnam passed a risk-based law, in force from March 2026. It has fewer risk tiers than the EU model and a test based on impact rather than on use case. Thailand drafted its law on the EU template, let it sit for two years, and is now reworking it to fit local circumstances. Indonesia wants each sector to define its own high-risk uses. Singapore, Malaysia and Brunei have stayed voluntary, though Malaysia is the one to watch. Its National AI Office put a statutory AI Governance Bill out for public consultation on 10 July 2026. The bill is tiered across three risk levels and built on four defined harms, with incident reporting and enforcement attached. Consultation closed on 31 July, and the Ministry of Digital says the bill will be refined before it is finalised. Nothing is in force and no tabling date has been announced (Ministry of Digital, 2026). If your regional compliance plan assumes these converge, it rests on a forecast rather than a fact.
The seven pillars that do travel
The ASEAN Guide on AI Governance and Ethics gives every board in the region one shared reference point. Published in February 2024, with a generative AI supplement the year after, it sets out seven shared pillars. They are transparency, fairness, security, robustness, human-centricity, privacy and accountability. In plainer terms: say what the system does, treat people fairly, keep it safe and working, keep a human in charge, protect the data, and answer for the result. Singapore’s AI Verify maps to EU, G7, OECD and US principles, and that mapping is what makes the model portable. Build your oversight on those seven and you can change the legal stack underneath it market by market without starting again.
One last thing about the coverage gap, because it compounds. Cambodia, Laos and Myanmar have neither a national AI policy nor a business AI survey. No evidence and no rules, in exactly the markets least able to absorb the cost of getting this wrong.
Citation capsule
ASEAN AI governance is diverging rather than converging. Seven of ten member states have AI governance policies in place: Brunei, Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam. Vietnam has adopted a risk-based law effective March 2026, Thailand is redrafting an EU-template law to fit local circumstances, Indonesia has proposed a sectoral framework, and Singapore, Malaysia and Brunei run voluntary frameworks. Cambodia, Laos and Myanmar are still developing national AI strategies, and Timor-Leste’s digital strategy does not yet cover AI. (ISEAS Perspective 2026/13, 2026)
Frequently Asked Questions
What is shallow AI adoption?
Shallow AI adoption is when a company uses AI, but only at a basic level, without scaling it into everyday operations or new business models. The pattern is the Southeast Asian default. Roughly 8% of enterprises in the region have fully scaled AI, and roughly three-quarters of the businesses that have adopted it at all remain at basic use. Adoption is broad, depth is rare, and the depth is where the value sits.
How can a board tell if its AI adoption is deep or shallow?
Ask what the AI actually does and who answers for it. Shallow adoption looks like rule-based execution and routine automation, often with no clearly defined person accountable for the output. Deep adoption looks like AI that initiates or completes tasks across several steps with limited human input. It also has a named owner and a decision pathway the company can reconstruct. Even in the most AI-forward Asia-Pacific sample, only 31% reached that top tier. Only 50% could reconstruct a decision pathway and only 38% held a tamper-proof audit trail.
What is AI pilot purgatory?
AI pilot purgatory is when AI projects run as trials indefinitely and never reach everyday use. It is already the regional default in Southeast Asia, where roughly 8% of enterprises have fully scaled AI. The SID AI Guide for Boards in Singapore names the problem directly. It treats stalled pilots as a board oversight matter rather than a technology one, which makes it unusual among governance guidance.
Is the SID AI Guide for Boards useful outside Singapore?
Its architecture is portable, its statutory layer is not. The conformance and performance lens, risk tiering by impact, defined accountability roles and board oversight cadence all transfer to a board in Jakarta or Bangkok. The specific legal references, PDPA, MAS guidance and AI Verify, do not. Because AI Verify is aligned to EU, G7, OECD and US principles, a board can keep the structure and swap the legal stack underneath it.
Which ASEAN countries have AI governance policies?
Seven of ten. Brunei, Indonesia, Malaysia, the Philippines, Singapore, Thailand and Vietnam have AI governance policies in place. Cambodia, Laos and Myanmar are still developing national strategies, and Timor-Leste, the newest member, has a digital strategy that does not yet cover AI. The seven that have moved have taken different approaches, from Vietnam’s risk-based law effective March 2026 to Indonesia’s proposed sectoral framework and the voluntary frameworks used in Singapore, Malaysia and Brunei.