Companies across this region are not short of interest in AI. What slows adoption is two questions a buyer asks before they ask what the product can do. Can we control it? And can we get it working without starting a project? The first decides whether AI gets approved. The second decides how much of the market can use it at all.
When AI starts acting, the question changes
For the last few years, most business AI answered questions. You asked, it replied, a person decided what to do with the answer. The risk was a wrong answer, and a careful reader could catch it.
That is changing. AI is moving from answering to acting: sending the email, updating the customer record, booking the meeting, publishing the post. Once a tool acts on its own, the buyer's question is no longer "is it right?" It is "who let it do that?"
That shift puts security, privacy and control at the front of every enterprise conversation. Not as a compliance box at the end of the sale, but as the condition for having the conversation at all.
The bad choice most companies face today
The pattern we see is that many companies are stuck between two poor options.
They can ban the public AI tools. Staff then use them anyway, on personal accounts, pasting in customer data and internal documents the company never sees again. Or they can allow the tools and accept that they have little idea what information went where, or what was done in the company's name.
Neither option is a policy anyone is happy with. That discontent is the opening. The buyer is not asking for a cleverer model. They are asking for one they can supervise.
What control looks like in practice
When we look at an AI product aimed at companies, we look for four things.
Scoped access. The AI sees what it has been given and nothing else. Not the whole drive, not every inbox, just the work it was brought in to do.
Approval on the actions that matter. Reading and drafting are low risk. Sending, paying, booking and publishing are not, and the customer should decide which of those need a person to say yes.
A complete record. Every action logged, so that when something goes wrong, someone can see exactly what happened and when.
Choice over the engine. Some companies have already chosen an AI provider and want their work to stay inside that relationship. A product that lets them bring their own account removes a whole round of security review.
None of this is glamorous. It is also very hard to add later. A product built without it tends to stay stuck at the pilot stage, because the people who sign off on risk never get comfortable.
Why setup decides how big the market gets
Control gets a product approved. It does not get it used.
The largest companies in this region can fund an AI programme: an integration partner, an internal team, months of configuration. They are a small part of the market. Most businesses in Malaysia, Thailand, the Philippines and Japan are mid-sized, run lean, and have nobody whose job is AI. The training gap is real, and a more capable model does not close it on its own.
For those companies, ease of setup is the product. A tool that works inside the email, chat, CRM and accounting systems they already use asks them to change very little. That is evolutionary change: it slots into the working day, removes a task, and meets little resistance. A tool that asks them to move their work somewhere new, or wait weeks for a first result, is asking for a change programme they do not have the people to run.
So we expect the market for enterprise AI to grow from the easy end. Every step taken out of setup brings in a group of buyers who would never have started an AI project.
What this looks like in our portfolio
Zunou, which we backed out of Tokyo, is built around both questions.
It is a shared workspace where a company's people and its AI agents work side by side. Each agent has a name, a job and a manager. On control, Zunou's agents see only the rooms and information they are given. Sending, booking and publishing each need a grant, and a team can require approval every time. Every turn is logged. Customers can connect their own Claude or ChatGPT account rather than handing their work to an engine they did not choose.
On setup, the starting point is a short conversation rather than an implementation plan: create a workspace, hire a first agent by giving it a role, permissions and a first task, and start working. The agents use the tools a company already runs, from Gmail and Slack to HubSpot and Xero, rather than replacing them. And Zunou pairs the software with a forward-deployed strategist who learns how the company works and helps design its AI team, which is an honest answer to the training gap rather than a denial of it.
What this means for how we underwrite
When we meet a founder building AI for companies, we ask a short set of questions before we ask about the model.
What can the product do without asking, and who decides that? Can the customer see everything it did? How long from sign-up to the first piece of useful work? Does it ask the customer to change the tools they use every day? And who helps them when they get stuck?
A founder with good answers to the first two has a product a cautious buyer can approve. A founder with good answers to the last three has a product a busy buyer will actually use. We want both.
The challenge
If you are building AI for businesses, look at your demo. If it opens with what the model can do, try opening with what it will not do without permission, and how quickly someone with no AI team can switch it on. That is the version your buyer is waiting to see.