“No matter how hidden the AI tool is, it must communicate via the organisation’s DNS, and this makes protective DNS an extremely critical tool for CIOs to keep out shadow AI. But it’s also important to know that technology alone isn’t a silver bullet.” – Lee Anstiss, regional director, Southeast Asia and Korea, Infoblox.
The artificial intelligence arms race has officially moved beyond pilot projects. In 2026, as agentic AI systems begin acting with autonomy and intention, the competitive advantage in Asia no longer comes from model speed or scale—it comes from trust.
Across Southeast Asia and Korea, CIOs are confronting a new mandate: AI integrity, defined as the act of ensuring AI systems are free from secret or unauthorized modifications that could compromise their behaviour.
This convergence of data provenance, bias mitigation, explainability, and regulatory resilience is rapidly becoming the defining challenge of the year.
For many CIOs, the most immediate integrity risk isn’t a rogue nation-state or a faulty algorithm—it’s their own employees. The phenomenon of “Shadow AI” is arguably the greatest blind spot in enterprise governance.
Anstiss draws a stark analogy: where traditional security is the front door, Shadow AI is like a trusted employee who is already inside the building, moving freely without triggering perimeter alarms.
This threat often starts innocently. An employee downloads an unapproved productivity tool to automate emails or coding tasks, focusing on efficiency rather than business risk. However, this creates a hidden layer of governance risk. “People don’t want to be left behind,” Anstiss notes, explaining the psychology behind the rapid adoption of unsanctioned tools. In Singapore, for instance, 68% of workers use AI frequently at work, but only 14% use company-provided tools exclusively.
The risk is substantial. Research indicates that breaches involving Shadow AI cost approximately $670,000 more on average, and a staggering 97% of organisations breached through AI lacked proper access controls. According to industry analysis, the median enterprise now has between 40% and 70% of its AI usage outside the sanctioned envelope, with the true extent often unknown to security teams. As Gartner predicts, by 2030, more than 40% of organisations will hit a security or compliance incident caused by unauthorised AI.
Reclaiming visibility through network fundamentals
If Shadow AI is invisible to traditional security tools, how can CIOs regain control? Anstiss suggests looking at a fundamental piece of infrastructure that is often overlooked: the Domain Name System (DNS).
Every device and application, no matter how hidden, must communicate via the network’s DNS to function. This makes protective DNS an extremely critical tool. “To give that full visibility, the business should work from the DNS and DHCP and use that as a single source of truth,” Anstiss advises.
By analysing DNS logs, organisations can detect anomalies—a sudden surge of traffic to a specific AI domain or unusual lookup patterns that signal a new agentic tool being integrated into a workflow.
However, technology alone isn’t the cure. Anstiss warns against treating this as a silver bullet. “It has to go hand in hand with continuous employee training and ensuring that the business is fostering an AI-positive culture,” he says.
Bans are ineffective; they simply push usage underground. Instead, organisations should set explicit policies on approved use cases and empower employees to suggest new tools for adoption, transforming the workforce from a liability into a human firewall.
Navigating a fragmented regulatory landscape
One of the most complex challenges for regional CIOs in 2026 is the diverging regulatory environment. While Europe has a unified AI Act, Asia remains a patchwork of different rules.
In this fragmented landscape, the CIO’s first step is to focus on what they can control. “This starts with regaining visibility of all the AI assets, identities, and data, being able to quickly respond to any regulatory change,” says Anstiss.
By standardising internal AI policies and maintaining a clear list of approved tools, CIOs can build a central governance framework that can adapt to varying local laws.
From accuracy to integrity scorecards
As organisations race to deploy AI, there is a significant pressure on CIOs to implement models quickly. However, this speed to value often undermines robustness. “The output for AI-driven operations will only ever be as good as its input,” Anstiss states. He warns that companies that succeed with AI will be the ones that can “ground automation in trusted data.”
This shift requires a fundamental change in evaluation metrics. Firms like Commvault note that AI integrity will become a central pillar of resilience in 2026, with a focus on the ability to trace, verify, and restore the truth in machine learning models.
Moving beyond raw accuracy to an “integrity scorecard”—measuring bias, explainability, and robustness—is becoming essential for boards and regulators alike.
Trust as the defining language of leadership
By 2030, IDC forecasts that half of the region’s digital value will come from organisations that scale AI responsibly. That responsibility rests on resilience, sovereignty, and quantum readiness. For CIOs in 2026, safeguarding AI integrity is no longer an IT function; it is a core pillar of governance and competitive advantage.
As Anstiss concludes, tackling the Shadow AI surge requires a mix of technical and human intervention. By building safe and visible pathways, leaders can stop trying to police the shadows and start leading towards a secure, AI-powered future.
Click on the PodChats player to listen to Anstiss’ tips for safeguarding AI integrity.
Do Asia’s CIOs and CISOs know exactly which AI models are running across all our business units—or is shadow AI already creating integrity risks we cannot see?
Given the fragmented state of each model’s regulatory status, what options are there for CIOs as they navigate fragmented rules with fragmented data?
In your view, are enterprises in Asia prioritizing raw accuracy over an “integrity scorecard” that includes bias, explainability, and robustness—and if so, are CIOs trusting models that are fast but not fair?
Based on current technologies and practices, can CIOs trace every piece of training data, including synthetic data, back to its source? Do organisations have blind spots where hidden bias or poisoned inputs could enter?
Can CIOs test their production AI for bias against local languages and cultural norms in each market? Can they produce an audit trail for any regulator who asks?
If a regulator demands proof of real-time bias disclosure tomorrow, is there a way for enterprises to have automated logs mapped to specific legal articles?
Should organisations maintain a human-in-the-loop for high-stakes decisions, with override logs that feed back into retraining? How risky is using the discipline of oversight as a checkbox?
Our topic is “tips on how to safeguard AI integrity” Can you share some of the most common or practical tips for CIOs, heads of AI, for ensuring or safeguarding AI integrity.