I recently came across Digital Realty’s The State of Data and AI in Asia Pacific. This report makes clear that across APAC, 65 percent of surveyed companies are actively executing a formal data strategy for current or planned IT locations, and 67 percent are actively executing a formal AI strategy tied to operational efficiency, new business offerings, or both. Nearly half have already deployed and monetized a trained AI model.
For compliance professionals, the lesson is direct: AI governance is no longer a future-state exercise. It is a current control environment issue. Equally importantly, I found the report provided compliance professionals with several key lessons around the role of data and data governance in AI governance.
1. AI governance starts with data governance
Compliance teams have long understood that poor data quality undermines monitoring, investigations, third-party risk management, and internal controls. AI raises the stakes. If data is inaccurate, incomplete, biased, poorly permissioned, or housed in unmanaged systems, the resulting AI output can magnify those weaknesses at enterprise scale. The report notes that APAC leaders see data strategy, AI investment, C-suite education, and the ability to deal with data-related regulations as critical requirements for data-driven insights. That is a compliance roadmap. The chief compliance officer should not wait for a model failure to ask where the data came from, who owns it, what restrictions apply, how it was validated, and whether it can be used for the intended purpose.
2. Infrastructure is part of compliance
Too often, compliance professionals view infrastructure as the province of IT. That is a mistake. The report identifies lack of investment in data systems, infrastructure, and analytics tools as the top obstacle to drawing insights from data. It also highlights the importance of IT locations, data proximity, and storage capacity for AI success. These are not merely technical issues. They are control issues. Data storage, access management, logging, resilience, latency, localization, encryption, and retention all affect whether a company can meet legal, regulatory, contractual, and audit obligations. A compliance program that does not understand the architecture supporting AI cannot credibly assess AI risk.
3. Localization
The report states that 77 percent of APAC companies follow a distributed data approach, and 72 percent tie data location strategy to AI strategic plans. This matters because data sovereignty, privacy, and cross-border transfer rules are increasingly central to AI deployment. For multinational companies, one global AI policy will not be enough. Compliance leaders need jurisdiction-specific data maps, use-case inventories, transfer assessments, and escalation protocols. The board should know where sensitive data resides, where AI training and inference occur, and what regulatory obligations attach to each location.
4. AI is now a business strategy, not a technology pilot
APAC respondents expect AI to improve customer experiences, build AI capabilities into products and services, and make operations more efficient. That means compliance must be embedded at the design stage. Product counsel, privacy, cybersecurity, compliance, internal audit, and business leadership should review AI use cases before launch. The review should cover lawful basis for data use, human oversight, explainability, records retention, third-party dependencies, cybersecurity, discrimination risk, and customer-facing disclosures.
5. Third-party risk
AI ecosystems rely on cloud providers, data centers, analytics vendors, model developers, integration partners, and managed service providers. The report emphasizes secure data exchange among users, networks, clouds, and IT providers. Compliance teams should translate that into contract rights, auditability, incident notification, data use limitations, subcontractor controls, model documentation, and exit planning. A company cannot outsource accountability for AI controls.
Finally, compliance must help the Board ask better questions. The Board does not need to understand every technical feature of AI infrastructure. It does need to understand enterprise risk. Directors should ask: What AI systems are already in production? What data feeds them? Which systems affect customers, employees, payments, safety, pricing, investigations, or regulatory reporting? Who can stop deployment? What metrics show whether controls are working?
The compliance opportunity is clear. AI can strengthen monitoring, speed investigations, improve risk sensing, and enhance program effectiveness. But without governance, AI becomes another uncontrolled system. The winning compliance function will not say “no” to AI. It will build the guardrails that allow the business to say “yes” responsibly.


