{"id":50230,"date":"2025-09-10T17:30:29","date_gmt":"2025-09-10T16:30:29","guid":{"rendered":"https:\/\/www.intelligentcio.com\/apac\/?p=50230"},"modified":"2026-07-23T10:47:51","modified_gmt":"2026-07-23T09:47:51","slug":"ai-ambitions-at-risk-why-apacs-api-security-is-failing","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2025\/09\/10\/ai-ambitions-at-risk-why-apacs-api-security-is-failing\/","title":{"rendered":"AI ambitions at risk: Why APAC&#8217;s API security is failing"},"content":{"rendered":"\n<p><em>As agentic AI accelerates across the Asia-Pacific (APAC) region, a critical vulnerability is emerging. A new report from F5 reveals a dangerous gap in API security, threatening to stall the region&#8217;s technological ambitions. The findings urge businesses to take immediate action, strengthening governance and resilience to protect their AI-driven futures.<\/em><\/p>\n\n\n\n<p>The rapid adoption of Agentic AI in Asia Pacific (APAC) is creating a critical security blind spot: unsecured application programming interfaces (APIs). This was revealed by F5&#8217;s (NASDAQ: FFIV) latest 2025 Strategic Imperatives: Securing APIs for the Age of Agentic AI in APAC, which examines how growing AI adoption is reshaping the API threat landscape as APIs continue to power the region\u2019s digital experiences.<\/p>\n\n\n\n<p>More than 80% of APAC organizations now use APIs to deploy AI and machine learning models. Once simple data connectors, APIs have become critical execution surfaces \u2013 enabling Agentic AI systems to sense their environments, make decisions and execute actions autonomously at machine speed. Without strong safeguards, misaligned permissions or weak governance can trigger unintended and potentially damaging actions at scale.<\/p>\n\n\n\n<p>Despite recognizing the high stakes \u2013 with 63% of APAC organizations rating API security as &#8220;very important&#8221; for business continuity, regulatory compliance and AI transformation \u2013 execution lags dangerously behind. Only 33% of ANZ enterprises report mature API governance capabilities, while just 8.5% have established a dedicated API security function. This results in inconsistent enforcement and critical gaps in oversight, exposing organizations to greater operational and compliance risks.<\/p>\n\n\n\n<p>&#8220;Our research shows that many APAC organizations are not yet equipped to secure APIs at the pace and scale of AI adoption. Too often, they lack dedicated teams, consistent oversight, and advanced capabilities \u2013 gaps that quickly become strategic vulnerabilities in the era of Agentic AI. Addressing these weaknesses will require stronger governance and end-to-end lifecycle controls to protect business continuity, compliance, and trust,&#8221; said Manoj Menon, Founder and CEO at Twimbit.<\/p>\n\n\n\n<p>&#8220;As AI agents become more autonomous and embedded in digital services, the pressure and demand for API infrastructure has never been greater. Security can\u2019t be an afterthought. It needs to be the pillar around which APIs are designed, deployed, and scaled. Organizations need real-time visibility and control to ensure every interaction is trusted, whether it\u2019s machine or human-led. At F5, we\u2019re helping customers across Australia and New Zealand build that trust into the fabric of their digital ecosystems and to ensure they can drive innovation securely and sustainably,\u201d said Jason Baden, Regional Vice President for ANZ at F5.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Key findings<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Concern is high, but capabilities remain fragmented:<\/strong> ANZ enterprises reported high concerns across all API security pillars, but most rate their controls only somewhat effective. This indicates a growing awareness of the critical role API security plays in protecting digital assets, yet it also reveals a significant gap between perception and preparedness. Despite recognizing the risks, many organizations lack the cohesive strategies, tools, and processes needed to effectively mitigate threats.<\/li>\n\n\n\n<li><strong>Business logic vulnerabilities top API security concerns:<\/strong> One in three APAC organizations cite unrestricted access to sensitive flows (<strong>OWASP API6<\/strong>) as their top API security risk. Other key concerns include unrestricted resource consumption (<strong>OWASP API4<\/strong>) and security misconfiguration (<strong>OWASP API8<\/strong>), with over 30% citing risks from excessive resource usage and misconfigurations that weaken API-layer control planes. If exploited, these flaws could disrupt digital services and undermine customer trust, highlighting the urgent need for API-level governance.<\/li>\n\n\n\n<li><strong>Shadow and Zombie APIs create governance blind spots:<\/strong> Over a third (36%) of businesses rate undocumented Shadow APIs as a high-risk threat, yet only 38% have effective processes to find them. These ungoverned APIs, along with outdated Zombie APIs, create significant security gaps that are easily exploited.<\/li>\n\n\n\n<li><strong>Preparedness remains low, with limited confidence across key API risks:<\/strong> While APAC enterprises recognize the severity of API security threats, operational readiness remains inconsistent. Only 36% report advanced preparation for most <strong>OWASP<\/strong> API security risks, while 14% are still operating at initial readiness stages. Many enterprises still rely heavily on traditional perimeter-based controls, such as Web Application Firewalls (51%) and Identity and Access Management solutions (42%), which are ill-suited for governing dynamic, autonomous API interactions \u2013 leaving a dangerous gap as AI adoption accelerates.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Strategic imperatives for agentic AI<\/strong><\/h3>\n\n\n\n<p>Over the next year, 69% of APAC enterprises anticipate moderate to significant increases in API security spending, signaling that APIs are increasingly regarded as a boardroom priority. However, unified oversight is vital to ensure that bigger budgets don\u2019t fuel fragmented efforts instead of strengthening cyber resilience.<\/p>\n\n\n\n<p>To address the governance gaps that could derail AI transformation initiatives, F5 recommends that enterprises focus on five strategic imperatives:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Assign C-level ownership for end-to-end API governance:<\/strong> Replace fragmented oversight across DevOps, Security, and Infrastructure teams with unified governance that aligns API policy with enterprise AI, risk and transformation strategies.<\/li>\n\n\n\n<li><strong>Prioritize lifecycle controls across discovery, posture, runtime, and testing:<\/strong> Implement comprehensive API security that includes automated discovery, posture policies for access scopes and rate limits, runtime threat detection and pre- and post-deployment testing.<\/li>\n\n\n\n<li><strong>Embed agent-aware observability into API traffic monitoring:<\/strong> Deploy systems that detect autonomous behavior patterns, log actions in context and enable real-time traceability across both human and machine activity.<\/li>\n\n\n\n<li><strong>Enforce OWASP-based policies across both human and agent API usage:<\/strong> Implement runtime controls for function-level authorization and misconfiguration detection that apply consistently whether APIs are accessed by human users or AI agents.<\/li>\n\n\n\n<li><strong>Link API behavior to agent intent and business outcomes through governance architecture:<\/strong> Define clear boundaries for what autonomous systems can do, under what conditions, and with appropriate oversight mechanisms that tie agent actions to business policy.<\/li>\n<\/ul>\n\n\n\n<p>To evaluate the current landscape of API security in the age of agentic AI within the APAC region, Twimbit conducted research on behalf of F5 in H1 of 2025, surveying 1000 professionals from various sectors, including security, DevOps, SecOps and application development. Respondents were distributed across 10 APAC markets: Australia, China, India, Indonesia, Japan, Korea, Malaysia, New Zealand, Singapore and Taiwan.<\/p>\n\n\n\n<p>Download the full 2025 Asia-Pacific API Security Report <a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__www.f5.com_go_report_2025-2Dstrategic-2Dimperatives-2Dsecuring-2Dapis-2Dfor-2Dthe-2Dage-2Dof-2Dagentic-2Dai&amp;d=DwMFAg&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=LuNhHTilh6sX9H3W656XXAGJB1Vp64aeqHeCePCvN2g&amp;m=YtimK_x0BOfCmxzWNPlFZd0R3pIuFMARO3AknDnbmq65ftyZgi_e3b-HcngB9Yom&amp;s=EZzqL4MjpKmxbOhNNJ5hRMW0mfSPh1qFvOX5-MmvXjc&amp;e=\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As agentic AI accelerates across the Asia-Pacific (APAC) region, a critical vulnerability is emerging. A new report from F5 reveals a dangerous gap in API security, threatening to stall the region&#8217;s technological ambitions. The findings urge businesses to take immediate action, strengthening governance and resilience to protect their AI-driven futures. The rapid adoption of Agentic [&hellip;]<\/p>\n","protected":false},"author":4017,"featured_media":50231,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[7027,1463,8219,3559,4664,15,56,18,55,53,62,59,44,54],"tags":[7965,1108,157,1864,4618,457,174,192,249,4502,2930,3617,9590,1841,264,92,4248],"class_list":["post-50230","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-intelligent-technologies-ai","category-apac","category-compliance-regulatory","category-cybersecurity","category-intelligent-technologies-data","category-digital-transformation","category-east-asia","category-enterprise-security","category-oceania","category-regional-news-newsletter","category-south-asia","category-south-east-asia","category-top-stories","category-used","tag-agentic-ai","tag-ai","tag-apac","tag-api","tag-api-security","tag-asia-pacific","tag-cybersecurity","tag-digital-transformation","tag-f5","tag-governance","tag-innovation","tag-it-security","tag-owasp","tag-report","tag-security-2","tag-technology","tag-threat-landscape"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/50230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/4017"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=50230"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/50230\/revisions"}],"predecessor-version":[{"id":51272,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/50230\/revisions\/51272"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/50231"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=50230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=50230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=50230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}