跳到正文
非凡资本

UNIQUE RESEARCH / ENGLISH ARTICLE

$400M in Revenue, Genuine SAP, Then Pirated Software — Just Because AI Can't Handle an Invoice?

Original · Unique Research · 2026-06-23

Editor's note: The first-person report and its judgments belong to the original Chinese author. This English rendition retains the SAP/Vietnam anecdote, the four themed sections, the four panelists' closing lines, and the full more-dialogue-details transcript. All named people, companies, and frameworks are preserved. Panelist statements are source attributions, not independently verified findings.

AI Industry Observation

SAP needs pirated software too? The survival wisdom of a $400M-revenue company.

Technology changes features, compliance changes trust, people change everything.

When Jonathan first heard this story, he thought he'd misheard. It was a manufacturing company with $400 million in annual revenue, more than a dozen factories worldwide, and management processes that couldn't be more "proper." They bought the genuine core modules of SAP — the books must be clean, the auditors are watching. But the peripheral modules? All pirated. A self-modified pirated version that couldn't even connect to the Vietnamese tax system.

What were they after? Just the ability to issue "red invoices" recognized by the Vietnamese government.

In Vietnam, invoices aren't something you can just issue. The tax authority has an extremely local set of rules for invoice format, numbering, and issuance flow, and the proper SAP system doesn't line up with them. So what did the company do? Bought the genuine software, then paid someone to make a pirated patch that forcibly modified the invoicing module into the shape Vietnam required. This is how surreal compliance cost can be.

Jonathan is co-founder of Accredify and has spent eight years doing enterprise software in Southeast Asia. He says the ten ASEAN countries look like one market, but are actually ten completely different sets of rules. Thailand's invoice is called a "tax invoice," Malaysia's is "e-Invoice," Indonesia has its own e-Faktur; every country's data format, upload interface, and compliance requirement is different.

"Many people think going-global AI is a technology competition," Jonathan says. "Only after you arrive do you find your competitor isn't another AI company, but a local compliance analyst earning $1,200 a month."

Singapore's MNCs (multinational corporations) are indeed willing to pay — a compliance analyst can earn up to $12,000 a month, digitalization is high, and acceptance of AI tools is high. But look at local manufacturing in Thailand, Malaysia, and Vietnam? Many still track inventory on paper, calculate payroll in Excel, and reconcile accounts over WhatsApp.

"Singapore is our highest-revenue market," Jonathan says bluntly, "because clients there can afford it and understand the value of SaaS. But if you only stare at Singapore, the market is too small. To scale, you have to go down-market — to markets with low digitalization, fragmented regulation, and extremely low labor cost."

In plain terms, the first lesson of the ASEAN market is: there's no standard answer here, only local solutions.

Localization Isn't Translation; It's "Going Into the Factory to Look"

Sit down and talk; there's no other shortcut.

Francis Zhang is founder of zCloak.AI and has seen too many AI products that "thought they were ready." One company said confidently its solution was polished and ready to launch into the ASEAN market. Francis asked only one question: "Have you been to your clients' factories?"

They paused. No. They hadn't.

Francis's approach is to send staff directly into business owners' factories and restaurants to sit and talk. Not a PPT demo, but watching how they use Excel to manage inventory, how they reconcile over WhatsApp, how they fill out tax forms by hand.

"You'll never figure it out sitting in your office — that a food-processing factory in Malaysia has a boss who spends three hours every day cross-checking suppliers' WhatsApp messages against paper delivery notes," Francis says. "This isn't a technology problem; it's a workflow problem. What you need to change isn't his tool, but his habit."

Counterintuitively, Singapore — the most developed market in all of Southeast Asia — has its own bottleneck. Many Singaporean SMEs Francis has touched aren't unaware of AI — the bosses know ChatGPT, know what an LLM is, and some even use one. But the moment you ask how it connects to their company's ERP, accounting system, and inventory-management system, they get stuck. "They know how to chat with AI, but they don't know how to let AI chat with their data."

Singapore's accounting rules are unified and its digital infrastructure is good, so a solution, once polished, can be batch-replicated. That's the good news. The bad news is — outside Singapore, this whole thing doesn't work at all.

"You can't build a product well in Singapore and expect it to run in Jakarta," Francis says. "Indonesia's tax rules are completely different from Singapore's, and Malaysian SMEs speak another language — not English, not Malay, but 'business language.' You have to send someone there, sit across from them, and understand their pain point."

Andy Tan is Aurora Mobile's Director of Solutions and Partnerships and chose a heavier path. The company set up a regional service center in Malaysia to cover the entire Asia-Pacific market. In his view, enterprise customers aren't just buying software; they're buying a promise that someone can actually solve the problem. As he puts it: "We don't sell software; what we sell is — someone can get it done for you."

Andy's core model is called "Train the Trainer" — working with local system integrators (SIs) and independent consultants, teaching them first, then letting them serve local clients. Local SIs know the regulation, have the relationships, and speak the local language; Andy's team knows the product and knows AI — put the two together and a deal gets done.

"There's no silver bullet for B2B localization," Andy says directly. "You think your AI product is great, but the client doesn't care how many parameters your model has. He cares whether, when something goes wrong, he can find a person; whether that person speaks his language; whether that person can show up at his office within 24 hours."

The truth of B2B AI going global is a completely different world from consumer internet. The consumer side can do "product-led growth" — ship an app to market, get data feedback, iterate fast. B2B? Every customer is a long conversation; every close is the start of a relationship.

In Asia-Pacific, Trust Is Built by Talking

Jonathan ran an experiment whose results surprised even himself.

He split his sales team in two: one group followed up prospects with traditional email, the other with WhatsApp. Same client base, same product, same quote. Three months later, the WhatsApp group closed deals 60% faster than the email group.

"It's not that WhatsApp is magical," Jonathan says. "It's that in Southeast Asia, people look at their phones far more than their computers. An email might go unanswered for three days; a WhatsApp message is read within three minutes. That's reality."

Even better are WhatsApp group chats. Jonathan's team pulls clients, technical owners, and implementation consultants into one group and @-mentions someone directly when an issue arises. In Malaysia, Indonesia, and Thailand, this makes clients feel "you're always there." But in Australia — same company, same product — this playbook completely fails.

"Australian clients feel WhatsApp group chats are harassment. They prefer formal email correspondence, a weekly call, with an agenda and minutes. Pull him into a group and his first reaction is: how is this company so unprofessional?" Jonathan smiles. "So the same product, the same team, is WhatsApp culture in Asia-Pacific but must switch back to email culture in Australia. There's no unified best practice, only one-size-fits-all clumsy methods."

There's another counterintuitive principle for B2B sales in Asia-Pacific: clients don't want to be the first.

Jonathan says no product feature is as effective as a case study in the same industry. "You tell him how smart your AI is; he's half-skeptical. You tell him the factory next door, the same size, went live on this system three months ago and now saves two full-time heads — his eyes light up immediately."

Francis's understanding of trust is more fundamental. "Many people treat trust as something emotional — wining and dining, calling each other brothers. No. Trust is built on a verifiable foundation. He says his system can automate reports? Have him run it live. He says his data is secure and compliant? Have him produce the audit report. Blind trust in promises is the biggest trap in doing business; verifying it yourself is the only real trust."

In Asia-Pacific, this "relationship" isn't built over drinks; it's built promise by promise verified, problem by problem solved, on-site visit by on-site visit.

The New Rules of the Data-sovereignty Era

When it comes to compliance, you can't avoid a harder topic — security.

The Singapore government's investment in AI compliance resources is leading in all of Asia. IMDA (the Infocomm Media Development Authority) launched the AI Verify framework to help enterprises test the fairness, explainability, and safety of AI systems; MAS (the Monetary Authority of Singapore) has the Veritas project, dedicated to ethical and compliant AI in finance.

"These resources are public, free, and written quite practically," Francis says. "But many going-global companies don't even know they exist. If you do AI in Singapore and don't look at IMDA's docs, you've paid for something others give you for free."

These frameworks aren't just for Singaporean companies. For AI firms wanting to use Singapore as a springboard into Asia-Pacific, AI Verify test results are a "regionally credible" admission ticket — when a client asks "how does your AI guarantee fairness," you can produce credentials.

But that's only the start. Asked whether there's a unified standard for AI data security, Francis's answer is blunt: no. And there won't be one anytime soon. The US has its own framework, Europe has GDPR and the coming AI Act, and Asia-Pacific countries go their own ways. "Don't wait for others to give you a standard; use first principles to think."

His method sounds simple but requires hard work: trace your data path — in transit, at rest, in computation — where is the data? Who controls it? Who can see it? From a user's question to an AI's answer, how many stages does it pass through? Model provider, router, UI layer, vector database, cloud platform... every stopping point of data on this chain is a potential risk point.

"When many companies do a security assessment," Francis says, "they ask 'are we compliant?' That question is itself wrong. They should ask: if an auditor sat across from me tomorrow, could I draw the complete path of every data request over the past 30 days?"

This isn't being difficult. Francis has seen too many clients who "thought their data was in their hands" — they used some SaaS product, thought data on the cloud was safe, when in reality the provider had servers in three countries, and even its own support couldn't explain the backup strategy.

Andy offers a pragmatic solution from another angle. His company builds a PaaS platform, so it naturally can't avoid the old cloud-security questions. "We borrowed the cloud 'shared responsibility' model, but the AI era is more complex than the cloud era."

What does that mean? The cloud vendor's standard model is — we handle infrastructure security, you handle application-layer security, draw a clear line, and when something breaks you each go your own way. But clients are often more unfamiliar with the data flow of AI systems than with traditional IT; draw a line and say "this side is yours," and he may not even know where "this side" is.

"We don't just tell him 'this is your responsibility,'" Andy says. "We also help him do data-flow checks, understand which data goes over public APIs and which should stay in a private environment, and build a compliance strategy that fits him."

For a financial client, for example, core transaction data must be processed by a private model and must never go over a public cloud API; but for non-sensitive scenarios like marketing copy generation and customer-service conversation summaries, a public model is perfectly sufficient and an order of magnitude cheaper. The point isn't to take a side of "all public" or "all private," but to know which data belongs on which road.

The reality is that regulation across markets differs to a headache. US clients care about SOX, HIPAA, and state privacy laws; Europe opens with GDPR and the AI Act — whether your system is "high-risk" or "limited-risk" directly determines regulatory intensity; Singapore requires PDPA, Indonesia mandates that certain industry data stay onshore, and Malaysia, Thailand, and the Philippines each have their own data-protection laws... each regulation is a completely different game; data must be physically and logically isolated, and ideally the teams too.

Prof. Zhu Feida (朱飞达) of Singapore Management University offers a framework from institutional economics. He says whether an AI system can be trusted in a commercial setting depends on three rulers — auditable, priceable, explainable.

"Auditable" means you can track the whole chain: where data comes from and how the model decides.

"Priceable" means the value AI produces can be quantified — how much labor saved, how much efficiency gained, with numbers that can be stated.

"Explainable" means when AI gives a conclusion, users can understand why — even just "because your inventory turnover is 15% below the industry average" is a hundred times better than black-box output.

He says for an AI system to run in the real commercial world, three conditions are indispensable: technical verifiability, institutional compliance, and consistency of business value.

Technical verifiability means you can prove you've reached the claimed security level — not by thumping your chest, but by being auditable, testable, reproducible. Institutional compliance means you know the rules in every jurisdiction and actually follow them. Consistency of business value is the easiest thing technicians overlook — all the security investment you make must align with the client's business interests. If the market he's in doesn't care about a certain compliance certification, spending big money on it may just be self-satisfaction.

"Many people think security and compliance are technical problems," Prof. Zhu says. "They aren't. They're trust problems. And trust problems are, essentially, people problems."

This sentence gathers together all the loose threads from before.

Breaking Through — A Counterintuitive Truth

Look back at all the stories above and you'll find a pattern: almost no one is truly stuck on "technology."

Jonathan's manufacturing clients aren't too poor for AI — they can even afford genuine SAP. The question is whether your AI can issue an invoice the Vietnamese government recognizes. Francis's SME bosses aren't unable to use ChatGPT — they know it better than you do. The question is how your AI connects to the Excel inventory table they've used for twenty years. Andy's clients don't distrust cloud computing — they just don't know how many countries' servers the data passes through on the API call to GPT.

The fact is, in this war of going-global AI, many people misjudged the battlefield from the start.

You think the competition is: whose model is smarter, whose RAG architecture is more elegant, whose prompt engineering is more refined. You think if you just tune the model, translate the UI, and find a local agent, you can replicate domestic success.

But the real battlefield is — you're talking to a factory owner who still keeps accounts on paper about digitalization; talking to a company using pirated SAP just to get around local tax law about "going to the cloud"; talking to a client who cares more about your WhatsApp response speed than your technical white paper when you talk about trust.

None of these three things has much to do with "AI technology."

The core of this is —

Technology changes features, compliance changes trust, people change everything.

No matter how strong your model, it only changes "what this product can do." But what actually determines whether you win that Malaysian food-processing factory is whether the boss trusts you — trusts that you understand his regulation, that you'll show up when something goes wrong, that you won't let his data inexplicably flow to a data center he's never heard of.

What does this mean? It means the competitive threshold of going-global AI has quietly migrated from "model capability" to "institutional-design capability."

The future winner isn't the one with the largest parameters, but the one who best understands local rules, best finds a path through fragmented regulation, and best makes complex systems auditable — the one who makes the boss dare to use it, pass compliance, and land trust.

The name of this game changed long ago.

Four Panelists, Four Sentences

Each panelist left one sentence. All instinctive reactions of people who do real work —

Jonathan says: "When you're lost, go talk to customers."

No methodology, no strategic framework. Return to the most basic fact: it's the customer who pays you, not the investor. Don't know where to go next? Ask those who've already paid, or who should pay but haven't. Their WhatsApp messages hold all the answers you need.

Francis says: "Education is the key — two-way education."

The market needs educating — too many companies still understand AI as "a smarter search engine." But at the same time, you also need educating by the market. Francis himself goes to training courses to learn the latest AI technology, not because he's short of class, but to understand what the young people selling him AI systems are saying. "When both sides speak the same language, trust becomes possible."

Andy says: "Start small, move fast."

Don't wait for perfection before setting out. Andy has seen too many teams nursing a big move — spending eighteen months polishing a "complete solution," only to find at launch that customers wanted something else entirely. Start with one scenario, get one client working, get the first real feedback. "If you don't start, you never know where your capability is or where the customer's goal is."

Prof. Zhu says: "Before scaling, build trust first."

Technology is the base color, but trust is the multiplier. Without trust, no matter how good the technology, it's just a pretty PPT; with trust, even if the product isn't perfect, the client is willing to iterate with you.

In the end, this whole matter of going-global AI has little to do with AI when you break it down.

What truly decides your life and death is whether you dare walk into that factory, sit down, and talk to the boss for three hours. Whether, in a WhatsApp message, you can reply "I'm here" within three minutes. Whether you're willing to spend time understanding an invoice regulation that has nothing to do with your technology.

And the more cutting part is — the model capability you spent so much time optimizing is, in the eyes of that factory owner keeping accounts on paper, less important than replying to his WhatsApp.

But look at it another way — maybe that's a good thing. Technology is always changing; today's model is obsolete tomorrow. But the factories you've walked, the bosses you've talked to, the regulations you've understood, the trust you've banked — these don't go obsolete; they're the moat.

More Conversation Details

Panelists: Jonathan Liem (Inflect/Nex Founder); Francis (zCloak.AI Founder); Andy Tan (Aurora Mobile Head of Solutions & Partnership); Prof. Feida Zhu (Singapore Management University Associate Dean, SCIS)

Host: Chelsea (tech self-media)

Chelsea: This panel's theme is localization, trust, and security. Our lineup is very diverse — some are my university professors, some are very close friends, and some are very young founders. Before we start, I'd like everyone to introduce yourself and talk about what you're doing. Let's start with Prof. Zhu.

Prof. Feida Zhu: I'm Feida Zhu. I'm currently a professor and associate dean at Singapore Management University. Over the past 25 years, my work has heavily involved data and artificial intelligence. I work mainly in this field, but since 2015 I've also been very focused on blockchain and Web3. I hope we can explore some interesting topics here.

Andy: I'm Andy. I started out as a systems engineer, working in early data centers. Later I moved from data centers into digital transformation and cloud computing, and now into AI. I've watched technology trends evolve, moving from a technician to a project manager, and now mainly responsible for regional go-to-market. I have experience managing businesses in Asia-Pacific and China. It's a pleasure to share my experience here. I was based in Beijing for four years, in Singapore for eight years, and worked in Malaysia for two. Based on my experience, I think I can offer a very good perspective on how to go global.

Francis: I'm Francis. I have a computer science background, mainly researching distributed systems and cryptography. I'm currently a visiting lecturer at the National University of Singapore (NUS) and founder of zCloak Network. What we mainly do is provide reliable AI for Singaporean enterprises, in the form of AI brains and digital employees.

Jonathan: Hi, I'm Jonathan. My career started interestingly. I worked for a diplomat, mainly on technical systems such as autonomous drones. I'm now co-founder of Nex, and recently founded another company called Inflect in the US. About Nex, we mainly help companies prevent fraud before payment, mainly serving oil companies, HVAC companies, and industrial manufacturers.

Chelsea: A quick intro of myself: I'm Chelsea, also an AI safety engineer at ByteDance. In my spare time I do AI content creation, focusing on technology trends and founder stories. I'm very much looking forward to today's discussion of trust, compliance, and localization. Our first question is: which markets are you currently in, and in entering this market, what's the deepest lesson you've learned about localization? No empty talk, only real stories. Maybe we start with Jonathan.

Jonathan: I think it depends on which market we're talking about. For example, if we localize into the ASEAN context, you'll find many local-vendor-type solutions that need customized compliance for local regulations and laws. To give an example, in the Vietnamese market they have many customized accounting rules, such as red invoices. There's also the question of how the market actually adopts and localizes solutions. I worked with a company whose revenue was around $400 million, quite large. They spent money on SAP's core modules, but all the surrounding modules they either built in-house or used localized versions (essentially pirated SAP), purely to get around local regulations. Overall, it's a very fragmented market. I think working with some local partners really helps accelerate these complex sales cycles.

Chelsea: So which markets in Asia do you cover?

Jonathan: We've touched Vietnam, parts of Malaysia, Thailand, and Singapore. Recently we've focused more on the US market because it's relatively easier.

Chelsea: For the Asian market, which do you think is easiest, or which has so far brought you the highest revenue?

Jonathan: Highest revenue, interestingly, is actually Singapore. Singapore has many large MNCs and, honestly, they're willing to pay far more than elsewhere in the market. When you sell in ASEAN, one recurring problem is that you're competing with human and labor cost. When you're selling some SaaS solution, or a services solution at a 6x markup, if the local labor cost is only one or two thousand dollars per person per month, it's hard to sell. But compare that to a market like Singapore, where an experienced compliance analyst can cost over $12,000 a month. So the economics of system adoption make more sense, and generally most of them are more digitalized, so it's easier to plug into our solution. By contrast, in some markets, especially manufacturing in places like Thailand, Malaysia, and Vietnam, many still use paper and pencil. So even if you want to do some AI or ERP digitalization, you have to start from scratch, completing the whole end-to-end process, which usually takes quite a long time.

Chelsea: Interesting view. Next, Francis. Which markets have you touched, and what's your experience in them?

Francis: Specifically, our current target is the Singapore SME market. On localization, one bit of experience is that you really need to sit down with Singaporean business owners, because we're a B2B company. We sit with the bosses to understand their pain points, talk to them, understand their workflows — what they want to do and how they want to use AI in their daily production or workflow. We send staff to their factories, shops, and restaurants to understand their pain points. In this process we found that many companies in Singapore want to use AI, but you often find the bottleneck stuck at the "last mile." They know how to use large language models (LLMs), know how to chat, but when it comes to interacting with their own data systems or training their own workflows, maybe only 5% of the existing system needs changing, and we help them do that. At the same time, we also find training and education very important. That's why we work with local institutions to provide training for company bosses and CTOs — what an LLM is, how to use AI Agents to automate workflows, and what security and privacy issues to watch for in the process. Education and deep conversation with business owners helped us a lot with localization in Singapore.

Chelsea: Following up on your answer, this seems like a general method for entering a market. Do you think this general method of talking to clients works for every market? Or are there things business owners in the Singapore market need to pay special attention to?

Francis: In Singapore, for some industries like accounting, there's a universal set of national rules. Once you get a workflow running for one or two companies, it basically applies to all similar companies, and we can replicate the technology and work accumulated for one or two companies to many others. But outside Singapore, say Indonesia or Malaysia, if we want to provide solutions for companies there, we also need to send staff over or have local contacts. For a B2B business, if you want to enter a specific market, you really need to get hands-on working with locals.

Chelsea: Andy, what markets have you touched, and what's your experience in them?

Andy: We started expanding internationally in 2024, and now we have a footprint in Taiwan, Japan, Thailand, Indonesia, Malaysia, and Singapore. Our strongest regions are Malaysia and Singapore. Why? Because we're essentially an AI-building platform. As Francis shared, we need to actually deeply understand client needs. So we need a lot of people. You need business analysts (BAs), you need a delivery team to understand client needs and build for them. Because of population, it's hard to hire enough talent in Singapore. So we set up a service center in Malaysia, though our headquarters is in Singapore. As the service center in Malaysia, our team can cover the whole Asia-Pacific. When we localize, as everyone said, it's very hard to enter directly under our own new name. So our approach is to enter with local partners. Before this, we'd already built up a certain ecosystem. We know who the right partners are, so we work with local partners (like system integrators or consultants) who can bring us to the clients, because there's a trust basis. Clients trust the consultant, clients trust the SI, so why not work with them instead of me fighting alone? I empower these SIs or consultants — it's exactly like "Train the Trainer." The trainers can train clients and help them. Our coverage is currently quite broad, though we've only done it two years. We focus on education: we work with universities, train students, train trainers. For government, we go in and share ideas, brainstorm. For enterprises too. For SMBs, we work with local SIs to build out-of-the-box solutions specifically for some industries, like customer service, sales assistant, after-sales service, even automating internal processes like finance or HR. These are things we've been pushing forward with many partners. I see the momentum building. If you want to quickly capture market share, this is the shortcut, because by working with local partners we share ideas, share revenue — it's a three-win: our partners win, the client wins, I win. That's how we do localization.

Chelsea: How big is your team in Malaysia, and what's the team structure? Is it 50% sales, or what ratio?

Andy: We don't have many salespeople; the great majority are technical. We have business analysts (BAs) and a delivery team. Our business development (BD) mainly focuses on partnership building, making connections, bringing in engineers, training trainers. Currently the Malaysia team is about twenty-plus people, while in other countries it's only two to three each. We at least have some momentum and demand-collection capability so we can send people from Malaysia to different countries. We hope to grow the team to fifty this year.

Chelsea: Next let's talk about "trust." Starting a company is one thing, but truly building trust with B2B clients is another. This trust can be built through technology (like verification) or through human touch. I'd like everyone to share your experience in truly building trust. Let's start with Prof. Zhu. For multinational AI systems, how do you actually build trust? What do founders tend to underestimate?

Prof. Feida Zhu: It's a fairly complex question, because you need to look at it from different angles. Technically, you need to examine technical verifiability. Institutionally, you ensure the institution has proper compliance. Commercially, you examine whether business value is fully aligned. Not only that, we also need to know where data is obtained, which model processes it, who is responsible if something goes wrong, how to explain this to regulators, and finally how to audit. As we handle all these underlying components of the system, these questions surface naturally. I think many teams underestimate how hard building trust is, treating it purely as a technical problem. Most of us have technical backgrounds — security, cryptography — but I want to emphasize the importance of non-technical aspects. For example, how do you design a system so it forms an audit trail with provenance and data lineage? These things become extremely real. Especially when companies enter a market like Singapore, where we have very complete data regulations. For over ten years we've had the Personal Data Protection Act (PDPA) and cross-border data rules. In recent years, IMDA released AI Verify and MAS released the Veritas framework guiding responsible use of AI in finance. All these are local regulations governing how AI and data run locally. I think many companies, when just entering Singapore, tend to overlook how much effort they need to put into compliance, and get into trouble later. So I'd say that in future cross-border AI deployments, don't only look at how smart the AI system is, but at who can build a trustworthy AI system that can be audited, priced, and explained.

Chelsea: Following up, this is a very complex problem to solve. For founders wanting to enter the Singapore market, what's your most practical advice? Find a CISO who understands security, find an external consultancy, or must the founder personally understand all the compliance, technology, and audit?

Prof. Feida Zhu: First, I think the Singapore government does a very good job providing resources to companies entering the market. If founders look at IMDA, MAS, or the Singapore Economic Development Board (EDB), they've all published good documents. Another thing is to often attend conferences like this, or come to universities — we offer various certified training. Francis just mentioned he's doing similar work with NUS; we at SMU also offer a full set of courses on AI verifiability. I'm also on the board of the Singapore Blockchain Association, and with government support we provide AI-readiness certification for SMEs. So founders can tap a lot of resources.

Chelsea: My next question is for Jonathan. Beyond the technical angle, how do you actually build trust among clients in Asian countries? Do you have to find local sales, host dinners and private social events? What's the style in these countries?

Jonathan: I think it entirely depends on the kind of sale you're doing. SME sales differ from enterprise sales. Andy just mentioned a very good point about system integrators. They're very valuable because they've built that relationship over time. Honestly, in Asia-Pacific, relationships matter enormously. The US is a product-led market; Asia-Pacific is a relationship-led market. If you're doing enterprise sales, hosting those kinds of private events is a very good way. Here, getting things done in an informal environment is far easier than trying to sell directly at the start. You see this everywhere. In some places, like Australia, if you contact them or create a WhatsApp group chat, they'll strongly resent it. But in Asia-Pacific, doing this actually helps push sales faster. I ran an experiment in my company: we tried a few deals purely via email and a few purely via WhatsApp. We found WhatsApp closed deals about 60% faster, simply because people check their phones more often. These are small details. If you're talking about building trust mainly from a compliance angle, especially for enterprise business, client case studies are very important. Many people don't want to be the first to try a new system, but if they hear their competitor is using it, they suddenly get interested. So there are many angles to consider; it really depends, on the industry, domain, or the specific person you're selling to.

Chelsea: Interesting. Most panelists have broadly touched on compliance, but AI compliance requirements keep changing; compliance hasn't caught up with technology. My question for Francis is: how do you handle changing compliance requirements? How would you advise your clients to handle these requirements that aren't yet fully settled?

Francis: It's a very good question. When you focus on compliance and know technology develops very fast, and we happen to have some clients from finance with very strict compliance requirements, my advice to them is: use first principles. Ignore everything else and start thinking about your system's data path. When your data is in transit, at rest, in computation, where is it? At each stage, what measures have you taken to ensure data is secure, or to ensure it's you (not someone else) controlling the data? The AI systems we see now are getting more and more complex. We have model providers, routers, UIs, databases, platforms, and so on. Your data is everywhere. So talking about compliance, the first thing you need to do is identify the key data paths in your product and think about how to address privacy and security at each step. We do this from a technical angle. For our own clients, as with the trust issue you just mentioned, don't blindly trust anyone who makes you a promise; actually try to verify yourself whether it's real, because we believe trust can only be built on our own verification. On compliance, keep data in your own hands, ensure your data is protected at every stage. Identify the real problem or concern.

Chelsea: From a data angle.

Francis: Yes.

Chelsea: Because time is running out. Our last question is about security. Who should be responsible for security? I want to put the question to Andy. As you mentioned, you previously worked in the cloud industry. In the cloud era we had the "shared responsibility" model, where the cloud provider handles infrastructure and the client handles their own data. But AI currently seems to have no such agreed rules. How do you handle security? Are you fully responsible for client security, or are clients responsible for their own things?

Andy: It's a very good question. We always try to follow existing frameworks. For example, we follow the cloud computing framework, because essentially we're a PaaS (platform as a service). So we use the same framework. Though we'll tell clients "this is your responsibility," I'll provide consulting. I'll help you check — as Francis mentioned — I'll look at your data flow, where your data is, and whether you're compliant. We come from China, so we also examine ourselves. If I want to go global, how do I isolate my data? How do I manage my data within China and in international markets? International markets include Europe, Asia-Pacific, the US, and you need to follow different regulations. For compliance, we always sit down and dig deep, because once you introduce AI — for example, we're working with some car companies that use AI in their apps — your data is really everywhere. When you're in the US, you follow US rules; when you're an Asia-Pacific client, you follow Asia-Pacific rules. We always try to advise clients on how to design their infrastructure, applications, and how data flows to the LLM. We also watch data sensitivity; for very critical data, we suggest using a private model. Though our platform is a PaaS, we also support private models. So we step in and understand your end-to-end process, then provide the best solution.

Chelsea: It's a very customized, data- and privacy-focused solution. Okay, before we end today, I'd like each panelist to give one sentence of advice to founders and builders who want to do localization well. Shall we start with Jonathan?

Jonathan: One piece of advice I'd give is, if you feel lost, spend more time talking to your clients; it really solves most of your problems. You can get a lot of advice — you have investors, board members, and so on — but just chat with your clients, because ultimately they're the ones who pay you.

Francis: If I give one piece of advice, it's that education is the key. Like in China, I think the Singapore government takes training its citizens on the latest AI technology very seriously. So be sure to go to those training institutions to learn the latest AI technology.

Andy: For me, I just heard Jonathan say no one wants to be the first to eat the crab. So my advice is: start small, move faster. That's how you benefit from AI. If you don't start anything, you can't know where the capability is, where your goal is, or how to plan your path. If you never start, you'll never know. So start small, move fast.

Prof. Feida Zhu: For founders and everyone who actually uses AI, before scaling, you should build trust first. I think it's always a combination of technology, governance, and many other factors. I agree with Francis that education is very important. That's why we recently launched the world's first and only DBA program focused on technology. If you're interested, you can consult us.

Originally published by Unique Research on Unique Research Substack on June 23, 2026. This page preserves the public article for reading on UniqueCapital.

View the original publication ↗
← Back to English research