AI is quickly moving beyond the role of a simple assistant. Increasingly, autonomous AI agents can approve transactions, move money, interact with systems and complete multi-step workflows with relatively little human involvement. That creates a new governance problem for organisations across Asia Pacific: when an AI agent makes a decision, can the business prove exactly what happened and who was ultimately responsible?
According to Sumsub's latest APAC State of Digital Trust: AI Governance Benchmark, organisations broadly understand the importance of accountability. Around 98.6% of respondents said they are likely to adopt technology capable of linking AI actions back to a responsible human identity. The bigger problem is that many businesses still lack the systems required to provide that evidence when something goes wrong.
AI Accountability Is Becoming More Than A Policy Exercise
The report surveyed 720 senior professionals working across technology, product, compliance, risk and operations in nine APAC markets. Organisations were assessed across three areas: Autonomy, Responsibility and Traceability, with each receiving a score out of 100.
The results reveal an interesting imbalance. Businesses are becoming increasingly comfortable allowing AI to operate autonomously and are generally clear about who should be responsible for those systems. However, their ability to reconstruct exactly what an AI did remains noticeably weaker.
Autonomy and Responsibility both scored close to 70, while Traceability fell to 61.0. Sumsub describes this gap as an "Accountability Asymmetry": organisations may accept responsibility for their AI systems, but they cannot always produce convincing evidence showing how those systems reached a particular outcome.
That distinction matters much more once regulators, customers or shareholders start asking difficult questions.
Knowing What AI Did Is Not The Same As Being Able To Prove It
The biggest concern identified by respondents was incorrect or unreliable AI decisions, cited by 52% of organisations. Regulatory and compliance risks followed at 44%, while poor data quality reached 43% and lack of transparency came in at 33%.
All four concerns point toward the same underlying problem. An AI decision may appear perfectly normal when it happens, only for a problem to surface later during an investigation or audit.
Many organisations believe they can explain their AI systems, but the evidence behind that confidence is considerably weaker. The report found that while 95% believe they can explain an AI decision, only around half can reconstruct the complete path that produced it. Even fewer—just 38%—maintain a tamper-resistant audit trail.
That could become increasingly important as AI agents perform more consequential tasks. Being able to say why a model probably acted a certain way is very different from producing a verified record showing exactly what data it received, what actions it took, which systems it accessed and under whose authority it was operating.
Financial Services Are Already Treating AI Governance More Seriously
Unsurprisingly, financial services emerged as one of the strongest sectors for AI governance.
The sector recorded a Traceability score of 63.3, a Responsibility score of 72.4 and the highest overall governance score at 69.6. Financial institutions are also among the most aggressive adopters, with 72% already operating multi-step AI systems in production.
That combination of greater autonomy and stronger oversight makes sense. Banks and financial institutions operate in heavily regulated environments where an unexplained automated payment, approval or transaction could quickly become a compliance or liability issue.
Financial firms therefore appear more likely to maintain records of AI decisions. According to the report, 68% keep AI audit trails, compared with 59% in IT, 55% in mobility and 50% in e-commerce.
When AI starts touching money, organisations simply cannot afford to rely on "the model said so" as an explanation.
Traceability Needs To Be Built In From The Start
One of the clearest lessons from the report is that traceability cannot be treated as something organisations add after an AI system has already been deployed.
Businesses need to determine who owns each AI-driven outcome before the system goes live. Logging, identity, monitoring and audit capabilities should then become part of the architecture rather than optional compliance features.
A useful test is whether an independent reviewer could reconstruct an AI decision without asking the AI itself to explain what happened.
If the answer is no, the organisation may have explainability, but it does not necessarily have evidence.
That difference will become increasingly important as autonomous agents interact with financial systems, customer records, suppliers and other businesses.
Regulators May Eventually Care More About Evidence Than Written Policies
AI governance discussions often revolve around policies, frameworks and internal guidelines. Those remain important, but documented intentions alone are unlikely to be enough.
Regulators may increasingly expect organisations to demonstrate that governance actually happened.
That could mean maintaining immutable activity records, verified identities for AI agents, clear chains of authority and reproducible decision histories.
In other words, future AI governance may start looking less like a policy document and more like traditional cybersecurity auditing.
Instead of asking only, "Do you have an AI governance policy?", organisations may increasingly need to answer, "Show me exactly what this AI did."
Good AI Governance Could Become A Business Advantage
Traceability is not necessarily just another compliance burden.
As autonomous agents begin communicating and transacting with other companies, organisations may become reluctant to allow unknown or poorly governed AI systems into their environments.
A business that can prove which AI agent performed an action, who authorised it and what decisions led to the outcome immediately becomes easier to trust.
That could eventually turn verified AI governance into a competitive advantage.
The same records that satisfy a regulator could also reassure customers and business partners that an organisation's autonomous systems operate within clearly defined boundaries.
Final Thoughts
AI agents are becoming capable of doing increasingly meaningful work without a human manually approving every individual step. That is useful, but autonomy also changes what businesses need from governance.
Simply assigning responsibility to a person or department is no longer enough. Organisations increasingly need technical evidence connecting an AI action to its decision history and the human authority behind it.
The APAC market clearly understands that challenge, but Sumsub's findings suggest many organisations still have work to do before their traceability capabilities match their ambitions for autonomous AI.
As agents begin making more decisions and transactions at scale, the companies best prepared may not necessarily be those deploying the most AI. They may be the ones capable of proving, clearly and independently, exactly what their AI did and why it was allowed to do it.


Comments 0