KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
AI adoption has moved quickly from experimentation to everyday business use in Singapore. ESET’s Enterprise Cybersecurity Report 2026, based on responses from 400 cybersecurity decision-makers, found that 97% of organisations are already using or piloting AI across areas such as customer service, analytics, software development and threat detection. Yet 79% said they had experienced at least one AI-related cyber threat in the previous 12 months. The findings, covered in Singapore Business Review’s report on AI cyber threats, suggest that deployment is moving considerably faster than oversight.
The more revealing figure may be 49%. That is the proportion of Singapore organisations that reportedly have measures to monitor access to AI tools and their outputs. The gap matters because AI cyber threats do not come only from attackers outside the organisation. They can also emerge when employees expose sensitive information, use unapproved services or rely on outputs without understanding how those systems handle corporate data.
The difference between 97% adoption and 49% monitoring reveals an important governance problem. Organisations appear comfortable allowing AI into business processes without always establishing equivalent visibility over how it is being used.
That matters because AI changes data movement. An employee using a conventional enterprise application normally operates within an environment designed and governed by the organisation. A generative AI tool can introduce an entirely new destination for information. Employees may paste customer records, internal correspondence, source code or business documents into prompts simply because doing so improves the response.
Around four in ten organisations surveyed reported employee misuse of generative AI and data leakage through AI platforms. The problem is therefore not hypothetical. AI cyber threats increasingly include routine employee behaviour that may never resemble a traditional cyberattack.
AI-generated phishing and impersonation were the most commonly reported AI cyber threats in the survey, affecting 46% of organisations. Financial services recorded particularly high exposure at 62%, while technology companies followed at 55%.
Phishing itself is not new. What AI changes is the effort required to make phishing persuasive. Attackers can improve grammar, localise language, rapidly generate variations and personalise messages using publicly available information. Voice cloning and deepfakes add another layer by weakening familiar methods of verification.
This creates an uncomfortable shift for employee awareness programmes. Traditional advice to look for awkward wording or obvious formatting mistakes becomes less reliable when AI can generate professional communications instantly. Training increasingly needs to focus on behaviour instead. Unexpected payment instructions, requests for credentials, unusual changes to procedure and pressure to bypass normal approval channels remain warning signs regardless of how polished the message appears.
The survey also found that 41% of respondents experienced threats involving exploitation of AI-powered tools, including prompt injection. This illustrates why AI cyber threats cannot be handled solely through conventional endpoint protection.
Prompt injection attempts to manipulate an AI system through instructions embedded in user inputs or external content. Depending on how an AI application is connected to corporate data or other systems, successful manipulation could influence its behaviour or potentially expose information it was not intended to reveal.
The risk grows as organisations move from simple chatbots towards AI systems connected to databases, documents, APIs and automated workflows. An AI assistant that can only answer questions presents one level of exposure. An agent capable of retrieving files, changing records or triggering business processes introduces an entirely different security boundary. Access permissions therefore need to reflect what the AI can actually do, not merely who can open the application.
The ESET findings suggest AI is amplifying a cybersecurity weakness that already existed. Seventy-one per cent of Singapore organisations experienced at least one major cybersecurity incident during the previous year, while 25% experienced three or more.
More importantly, 55% identified delayed detection as a challenge, while 49% cited poor visibility across environments. If organisations already struggle to understand activity across cloud systems, endpoints and networks, adding AI tools introduces another layer of complexity.
This explains why monitoring AI access alone is insufficient. Organisations also need to understand what information employees submit, what AI systems can access and what actions those systems can perform. The objective is not surveillance of every employee prompt. It is establishing enough visibility to identify behaviour that creates genuine security or data protection risk.
The natural response to rising AI cyber threats is often another security product. Yet the ESET findings point towards a more fundamental issue. Technology cannot compensate indefinitely for unclear ownership, fragmented visibility or weak processes.
Security teams need an inventory of approved AI tools, clear rules about what information can be submitted and access controls based on business need. Employees also need practical guidance that reflects how they actually use AI, rather than policies written so broadly that staff ignore them.
The strongest AI governance programmes will therefore treat cybersecurity as an operating discipline. New tools should be assessed before deployment, permissions should be periodically reviewed, and unusual activity should trigger investigation. Most importantly, organisations need clear responsibility for deciding what happens when an AI-related incident is detected.
Managed Detection and Response appears to be gaining attention as organisations recognise this visibility problem. According to the survey, 43% planned to adopt MDR capabilities within the next 12 months.
The appeal is understandable. AI cyber threats can evolve quickly, while internal security teams may already face skills shortages and large volumes of alerts. Better detection can help identify suspicious behaviour earlier, but response capability remains equally important. An alert has limited value if nobody can quickly determine which accounts, data or systems are affected.
Cyber insurance trends reinforce the same message. An overwhelming 97% of respondents reported challenges obtaining or maintaining coverage, and stricter security requirements were among the reasons cited. Insurers increasingly want evidence that cybersecurity controls exist in practice, not merely in policy documents.
The rise of AI cyber threats reinforces the connection between cybersecurity and responsible data handling. Privacy Ninja helps organisations strengthen both sides of that equation without unnecessarily complicating the role of internal teams.
Our DPO-as-a-Service provides a dedicated point of contact to keep PDPA compliance on track, maintain essential data protection policies and practices, and handle data protection queries consistently. This becomes particularly relevant when employees use AI tools with personal data or when an AI-related incident creates potential data exposure.
On the technical side, Privacy Ninja’s vulnerability assessment and penetration testing services help organisations identify weaknesses before attackers can exploit them. Together, clearer governance and technical assurance can help organisations adopt AI without allowing rapid innovation to create unmanaged security exposure.
The most significant finding is not simply that 79% of Singapore organisations encountered AI cyber threats. It is the contrast between widespread AI adoption and limited oversight. When 97% are using or testing AI but only 49% monitor access and outputs, the security challenge becomes one of visibility and control.
AI will continue to make phishing, impersonation and other established techniques easier to scale. At the same time, employees and organisations will continue using AI because of its genuine business value. The objective should therefore not be to resist adoption, but to make governance catch up with it. Organisations that understand where AI is used, what data reaches it and how suspicious activity will be detected will be far better positioned to benefit from AI without allowing convenience to become exposure.