SINGAPORE — Singapore is stepping up efforts to safeguard against increasingly autonomous artificial intelligence systems, with Senior Minister of State for Digital Development and Information Tan Kiat How urging businesses to take action rather than wait for the next major AI-related cyberattack.
Speaking in Parliament on Wednesday (Oct. 7), Tan said Singapore is already running trials and experiments to understand how agentic AI can be deployed safely, while the Government reviews existing cybersecurity and AI governance frameworks to account for systems capable of acting with less human supervision.
His comments came after a series of incidents overseas raised concerns about increasingly capable AI agents being used to carry out cyberattacks and other harmful activities.
Singapore has not reported any cyberattack on government agencies involving an unsupervised AI agent so far. But ministers have stressed that the absence of a local incident does not mean the threat can be ignored.
What makes agentic AI different?
Unlike conventional AI systems that primarily respond to prompts, agentic AI systems can take actions, interact with external systems and adapt their behaviour to complete tasks.
That greater autonomy can make AI more useful, but it can also create new security risks.
An AI agent connected to computer systems, databases or other digital tools could potentially identify vulnerabilities, execute commands or carry out tasks with limited human intervention.
Tan said many of the risks associated with agentic AI are extensions of existing cybersecurity challenges, but the increased autonomy of these systems means Singapore must strengthen its safeguards accordingly.
Existing rules and risk-management processes already apply to AI systems, including requirements for human accountability, appropriate controls and cybersecurity protections.
However, the Government is reviewing how these frameworks should be adapted as AI systems become more capable and autonomous.
Singapore is running AI safety trials
Tan said the Government is not simply waiting for the technology or its risks to become clearer.
Government agencies, including the Government Technology Agency of Singapore (GovTech), are conducting trials and experiments to better understand what is required to deploy AI agents responsibly.
“We are developing capabilities to go beyond existing frameworks and approaches,” Tan said in Parliament, adding that the trials are intended to keep the Government abreast of rapidly evolving technology.
The experiments are designed to help policymakers understand both the opportunities and potential dangers associated with autonomous AI before such systems become more widely deployed.
Tan also encouraged private-sector organisations to adopt the same cautious approach.
He said companies should take appropriate care and responsibility when deploying AI agents or other AI systems, even if they do not operate critical information infrastructure or essential digital services.
No reported rogue AI attack on Singapore government systems
The Government’s latest assessment is that no Singapore government agency has reported being attacked by an unsupervised AI agent.
Minister for Digital Development and Information Josephine Teo said in a written parliamentary reply on Oct. 6 that Singapore would continue monitoring developments overseas and applying lessons from incidents elsewhere to strengthen its safeguards and reporting arrangements.
Teo also said Singapore would neither dismiss the possibility of severe AI risks nor assume that every worst-case scenario would happen.
The approach is to monitor evidence, develop technical capabilities to evaluate advanced AI systems and work with international partners on safeguards.
The Singapore AI Safety Institute is also developing technical capabilities to evaluate advanced AI systems and better understand their potential risks.
Overseas AI incidents raise alarm
Singapore’s renewed focus comes amid growing concern over AI agents being used in cyber-related incidents overseas.
One recent case involved an AI agent linked to a breach of an Australian government system.
The incident raised questions about whether existing cybersecurity and incident-reporting rules are adequate when an AI system, rather than a conventional human attacker, is responsible for carrying out unauthorised activity.
The episode has prompted governments and AI companies internationally to examine how autonomous systems should be monitored and how quickly serious incidents should be reported.
OpenAI and Anthropic have also faced increased scrutiny over the capabilities and safety of their increasingly autonomous AI systems.
For Singapore, the concern is that AI could eventually make cyberattacks faster, cheaper and more scalable.
AI could make cyberattacks more convincing
Teo has warned that malicious users could exploit increasingly powerful AI to cause harm in several ways.
These include using AI to search for weaknesses in computer systems, generate malicious code, automate portions of cyberattacks and make scams more convincing.
That means the threat does not necessarily come from an AI system acting independently.
A malicious human could potentially use an AI model as a force multiplier, allowing relatively sophisticated cyber activity to be carried out more quickly or at greater scale.
This creates a broader cybersecurity challenge for governments, businesses and individuals.
Singapore wants AI to help fight AI
The Government is also looking at using AI as part of its defensive strategy.
Singapore’s cybersecurity authorities have been exploring technologies that can help defenders detect threats and respond more efficiently.
In March, Tan announced that the Cyber Security Agency of Singapore (CSA) would work with critical information infrastructure owners to test technologies such as AI to improve cybersecurity operations.
The Government has also begun deploying proprietary threat-detection tools to selected critical infrastructure operators, while considering broader deployment and possible funding support.
These tools are intended to complement commercial cybersecurity systems and help organisations detect malicious activity, including attacks associated with sophisticated state-backed threat actors.
The strategy reflects a growing recognition that cybersecurity defenders may need to use AI themselves to keep pace with increasingly automated attacks.
Critical infrastructure remains a major concern
Singapore’s critical information infrastructure — including systems supporting essential services — remains a major focus of the Government’s cybersecurity efforts.
Tan has warned that attackers are increasingly targeting systems outside formally designated critical infrastructure because weaker systems can provide potential entry points into more important networks.
The Government is therefore reviewing cybersecurity standards and obligations to potentially cover interconnected non-CII systems as well.
The authorities are also providing selected critical infrastructure operators with threat intelligence and specialised detection capabilities.
The goal is to strengthen the entire ecosystem rather than leave individual companies to defend themselves against sophisticated attackers alone.
Businesses are being told not to wait
Tan’s message to businesses was particularly direct: organisations should not assume they need to wait for new regulations or a major incident before strengthening their AI safeguards.
Existing cybersecurity principles remain relevant even as the technology evolves.
These include maintaining clear human accountability, establishing appropriate controls and guardrails, protecting the systems connected to AI agents and regularly testing whether safeguards actually work.
For companies deploying autonomous AI, the challenge is therefore not simply choosing the right model.
They must also understand what the system can access, what actions it is permitted to take and what happens if it behaves unexpectedly.
Frontier AI companies face greater responsibility
Tan also called on companies developing the most advanced AI models to take greater responsibility for identifying emerging risks.
He said frontier AI developers should work to understand new capabilities and potential dangers early, and introduce safeguards before their systems are widely deployed.
Where AI systems cause harm or have an impact on others, he said developers should take responsibility and work to rectify the problem quickly.
This reflects a broader international debate over whether AI companies should be required to report incidents involving autonomous systems and whether voluntary safety measures are sufficient.
Singapore is balancing AI opportunities with AI risks
Despite the warnings, Singapore is not taking a position against the deployment of AI.
The Government sees advanced AI as an important technology for improving productivity, developing new services and strengthening Singapore’s digital economy.
The challenge is ensuring that those benefits do not come at the expense of cybersecurity or public safety.
Singapore’s approach is therefore increasingly focused on responsible deployment rather than simply restricting the technology.
That means testing systems before wider use, strengthening safeguards, maintaining human oversight and adapting regulations as AI capabilities change.
A threat that is evolving faster than the rules
The rapid development of agentic AI is creating a difficult problem for regulators.
Traditional cybersecurity rules were largely designed around human users and conventional software systems.
Autonomous AI introduces another layer: systems that can make decisions, interact with other systems and potentially carry out actions without a person approving every individual step.
That does not necessarily make every AI agent dangerous.
But it does mean that the consequences of a mistake, compromise or malicious use could potentially spread much faster.
For Singapore, the strategy is to build the ability to identify and manage those risks before they become widespread.
As Tan put it, the Government is developing capabilities beyond existing frameworks while running trials to understand what responsible deployment of agentic AI should look like.
For businesses and organisations adopting the technology, the message is equally clear: AI may be developing quickly, but cybersecurity safeguards cannot afford to lag behind.