AI agents that move between apps on your behalf were the sharpest topic at the Technology Diffusion and Asia Prosperity seminar in Singapore on February 27, 2026 — the launch event for Edge Research's Asia Prosperity Initiative. The takeaway from the policymakers, academics and industry leaders in the room: the screen-reading, click-simulating agents you can download today are the riskiest way to hand an AI your accounts, and a very different, protocol-based approach is already replacing them.

What cross-app access actually means for AI agents
Two very different designs hide behind the phrase "cross-app access":
Screen-reading agents. These computer-use agents see your screen the way you do and simulate clicks and keystrokes to get things done. As Huang Jingyang, assistant professor at The Chinese University of Hong Kong (Shenzhen), pointed out at the seminar, this mechanism was originally built for accessibility — helping people who struggle with standard interfaces. Repurposed for commercial automation, it means the agent technically sees everything you see: your messages, your banking tab, the password your browser autofilled.
Protocol-based agents. Instead of looking at pixels, the agent calls apps through defined interfaces — MCP (Model Context Protocol) for connecting agents to tools and data, and A2A (Agent2Agent) for agent-to-agent work. Every call is structured, scoped and can be logged. If the agent only needs calendar access, the protocol can grant exactly that; a screen-reader agent cannot make that promise.
I've run a browser-use agent on a test machine to draft and send email, and the moment it opened my logged-in mailbox, the privacy trade-off stopped being theoretical. It worked, but I knew it could read every other thread in there too.
Why every added tool widens the attack surface
Alvin Chia, Head of APAC Digital Asset Innovation at Northern Trust, described the efficiency gains from agent deployment in financial services — and the catch. Each tool you wire into an agent increases the potential attack surface. In a bank, an unauthorized operation isn't just an annoyance; it's a compliance incident or a fraud event.
There's a technique worth naming here because it keeps coming up: prompt injection. An attacker hides instructions — in an email, a web page, a calendar invite — and an agent that reads that content may follow them. No password stolen, no code exploited; the agent is simply talked into acting against your interest. That's why permission scoping matters more for agents than for ordinary apps: a misused tool grant converts instantly into a real-world action.
The accountability black box
Wang Yin emphasized at the seminar that the black-box nature of AI agents complicates accountability. When an agent does something wrong, responsibility could sit with the developer who built the model, the company that deployed it, or the user who gave it the job — and that question is unresolved in every jurisdiction so far. Zhang Fan compared AI agents to butlers: useful precisely because they act for you, dangerous for the same reason, which is why autonomy has to be balanced against security and privacy safeguards.
The standards race: MCP, A2A and Cross-App Access
The protocols the seminar flagged as alternatives are moving fast:
- MCP started at Anthropic. In April 2026 it was donated to the Agentic AI Foundation at the Linux Foundation, with OpenAI, Google, Microsoft and Amazon backing the move — the protocol is now vendor-neutral rather than one company's project.
- A2A, Google's agent-to-agent protocol, joined the same foundation on August 17, 2026. Between them, MCP and A2A now cover how agents reach tools and how agents talk to each other.
- Cross-App Access (XAA) is the newest layer: an IETF OAuth working-group draft, formally the Identity Assertion JWT Authorization Grant, led by Okta engineers. The idea is to put the enterprise identity provider back in the authorization path when an agent calls a third-party app — the agent gets short-lived, scoped tokens issued against a signed identity assertion instead of a user clicking through one broad OAuth consent screen. The MCP ecosystem has already adopted XAA as the standard under Enterprise-Managed Authorization, and Okta ships it as "Agent SSO."
The direction of travel is clear: less screen-scraping, more issued-and-scoped credentials, with the same directory that manages your employees also managing your agents.
Governance: Asia's framework-first approach
Regulators haven't waited for the standards to settle. Singapore's IMDA published its Model AI Governance Framework for Agentic AI on January 22, 2026 — billed as the world's first governance framework built specifically for agentic AI — and updated it to version 1.5 in May. Its themes line up almost one-to-one with the seminar's concerns: bound how much autonomy an agent has, define when a human stays in the loop, and pin down who answers when it goes wrong.
Benjamin Goh highlighted at the seminar how the EU AI Act keeps shaping global discussions, while Asian economies adapt governance to their own institutional contexts. India's AI Impact Summit has taken up data-sharing rules, and Southeast Asia's mixed institutional capacity is offset, participants argued, by strengths in application-layer innovation, localization and market diversity.
The workforce thread
The seminar also connected AI diffusion to jobs. Professor Lawrence Loh observed that frontier innovation has shifted from universities to corporations — Google in the US, Alibaba and Tencent in China now lead — and entry-level roles face the most displacement pressure, which sharpens competition among graduates. Zhang Fan cited US research suggesting generative AI hits junior positions hardest, and pointed to Palantir's recruitment of high-school graduates into structured training as the kind of alternative talent pathway companies may need to build. For readers starting careers, the practical read is that the routine, multi-app coordination work agents do cheapest is exactly the work to avoid being the human version of.
What to actually do about agent privacy
The debate sounds abstract until you're one consent screen away from handing an agent your accounts. A few defaults that track what the experts above described:
- Ask how it connects. If a vendor's agent works by screen-reading your logged-in browser, it sees everything you see. Prefer tools that integrate through scoped APIs.
- Never hand over a standing password. An agent that needs your password to work is doing access control backwards.
- Keep irreversible actions human. Payments, deletions, mass sends — those should require your click, not the agent's.
- Audit quarterly. Agents accumulate permissions the way apps do. Revoke what you stopped using.
For businesses, the IMDA framework is a useful checklist even outside Singapore — expect questions about agent autonomy and oversight to show up in security reviews and procurement questionnaires.
Related reading
- AI Agent Orchestration: The Next Generation of Business Automation
- How Autonomous AI Agents are Transforming Financial Analytics
- Tencent Hy3 WorkBuddy: Free Agentic AI Workspace Access
- Data Privacy in the Digital Age: Protecting Your Information Online
Frequently asked questions
What is Cross-App Access for AI agents?
It's the informal name for an IETF OAuth working-group draft (the Identity Assertion JWT Authorization Grant) that lets an agent call a third-party app's APIs using short-lived, scoped tokens issued by your organization's identity provider, rather than a per-user OAuth consent screen or screen-reading. The goal is enterprise-controlled, auditable agent access. Okta ships an implementation as "Agent SSO," and the MCP ecosystem uses it for Enterprise-Managed Authorization.
Are screen-reading AI agents safe to use?
They can be acceptable for low-stakes, personal tasks if you understand the trade: the agent sees your whole screen, including logged-in sessions and autofilled passwords, and its clicks are hard to audit. The risk scales with what's on the screen. For anything touching money, work documents or private messages, scoped protocol-based access is the safer design.
What is the IMDA Model AI Governance Framework for Agentic AI?
A governance framework from Singapore's Infocomm Media Development Authority, published January 22, 2026 and updated to v1.5 in May 2026. It's the first national framework aimed specifically at agentic AI, with guidance on bounding autonomy, keeping humans in the loop, and assigning accountability across developers, deployers and users.
What's the difference between MCP and A2A?
MCP (Model Context Protocol) connects an agent to tools, data sources and APIs — how an agent reaches your calendar or database. A2A (Agent2Agent) is about agents collaborating with other agents across different vendors. Both now sit under the Linux Foundation's Agentic AI Foundation after Anthropic donated MCP in April 2026 and Google's A2A joined in August 2026.
If you take one thing from the Singapore debate, make it this: the safest agent is the one that asks for less — scoped tokens, named tools, human approval on anything it can't undo.

