
By Ewashi · Published 09/26
Enterprise AI deployments are accelerating across ASEAN and beyond — but the foundational security layer that makes AI safe to operate remains dangerously overlooked. This article examines why endpoint hygiene is the non-negotiable prerequisite for any serious AI adoption strategy.
Every week, another enterprise announces AI-assisted workflows — copilots in productivity suites, LLMs wired into customer service stacks, generative tools accessed through the same browser an employee uses to click phishing links on an unpatched device.
Boardroom conversations are almost entirely about capability: which model, which vendor, which use case moves fastest. Procurement evaluates features. Legal reviews agreements. IT is told to enable access by end of quarter.
What nobody is discussing with equal urgency: the security state of the endpoint where all that AI interaction is happening.
That is the gap. And in cybersecurity, gaps are not neutral — they are invitations.
Endpoint hygiene used to mean: is antivirus running, are patches current, is the firewall on. Those remain necessary. But in an environment where the browser has become the operating system for enterprise work, hygiene now covers a much wider surface.
In 2026, it means knowing what browser extensions are installed and what permissions they hold. Whether session cookies for AI platforms are stored in ways that make them exfiltrable. Whether the device accessing a sensitive AI interface is managed and monitored — or a personal device with minimal controls.
The real question: if a threat actor compromised this endpoint right now, what would they reach? For most mid-market enterprises that have moved aggressively into AI tooling without a corresponding security uplift, the answer is uncomfortable.
AI platforms occupy a qualitatively different risk category from standard SaaS. Three structural reasons explain why.
A compromised session exposes months of distilled queries: strategies, customer data, legal positions.
Copilot-style integrations hold broad read access to email, calendar, files, and comms — wide blast radius by default.
Business pressure compresses security review. Features ship before threat models are complete.
The AI layer is not the vulnerability. The endpoint through which AI is accessed — and the organisational security posture surrounding it — is where the exposure lives.
A mid-market financial services firm in Singapore deploys a leading AI productivity suite enterprise-wide. Data processing agreements signed. Acceptable use policy in place. PDPA obligations reviewed.
What their security team missed: a credential-harvesting browser extension, bundled with a free PDF converter, had been quietly exfiltrating session tokens from a senior relationship manager's device for eleven weeks.
The AI platform detected no anomaly. The data processing agreement remained intact. The breach, when discovered, had nothing to do with the AI vendor.
The exposure happened in the gap before that.
At the endpoint. Through a control that was never implemented because the security review focused on the AI platform — not the device accessing it.
Singapore's PDPA imposes accountability obligations regardless of where in the technical stack a breach originates. If an employee's compromised endpoint exposes personal data while accessing an AI tool, breach notification obligations are triggered. The AI vendor's secure infrastructure is not a defence.
Thailand's PDPA, Indonesia's evolving framework, and Malaysia's PDPA compound this for organisations operating across borders. AI adoption without endpoint hygiene is not just a security risk — it is a compliance risk with material financial and reputational consequences.
The PDPC has been explicit: reasonable security arrangements must cover the full data lifecycle. Securing the application layer while leaving the endpoint unaddressed does not meet that standard.
AI session tokens stored locally. Browser extensions run with broad permissions. Any process with local access can reach session cookies.
AI session runs in an isolated cloud container. No tokens on the device. Extensions can't reach the session. Endpoint compromise stays contained.
The control that would have actually helped: browser isolation moves the session off the endpoint entirely.
Browser isolation moves the AI session off the endpoint entirely — running in an isolated cloud container, with only a rendered visual stream reaching the device.
The endpoint can be compromised. The AI session remains intact.
Session tokens never reach the endpoint. Nothing to exfiltrate.
Browser extensions on the device cannot reach the isolated session.
Endpoint compromise does not propagate. Policy alone cannot achieve this.
This is Menlo Security's core architecture — and the category most ASEAN mid-market enterprises have not deployed. The gap between AI capability spend and security architecture is widening.
Assess your current posture by answering these questions honestly, not aspirationally.
Do you have a complete, current inventory of browser extensions across your managed fleet — including what permissions each holds?
For every AI platform deployed, do you know how session tokens are stored, and whether they're accessible to other processes on the endpoint?
Is device health verified at the moment of AI access, or was access provisioned once and never re-evaluated?
Are users accessing AI platforms from personal devices, and if so, are controls enforced architecturally — not just by policy?
Is browser or application isolation in place for AI tool access — and if not, has that decision been reviewed since AI adoption began?
If the honest answer to more than two of these is "we don't know," the organisation has a material gap between AI adoption and security posture. That gap is not a future risk — it is a present exposure.