Singapore Reports No Rogue AI Attack on Government Agencies — But Stronger Safeguards Are Coming

Politics

Singapore Reports No Rogue AI Attack on Government Agencies — But Stronger Safeguards Are Coming

SINGAPORE — Singapore has not recorded any cyberattack against a government agency involving an unsupervised artificial intelligence agent, but authorities are examining stronger safeguards as increasingly autonomous AI systems create new cybersecurity risks.

Minister for Digital Development and Information Josephine Teo said in a written parliamentary response on Oct. 6 that Singapore is studying whether additional protections are needed for high-risk applications of AI.

The clarification comes as concerns grow internationally over so-called rogue AI agents — systems capable of carrying out tasks with limited human supervision — and their potential to misuse access to digital systems.

No Reported Attack on Singapore Government

Teo said there has so far been no reported cyberattack involving an unsupervised AI agent against Singapore government agencies.

That does not mean authorities are treating the risk lightly.

Singapore is adopting a risk-based approach that limits what AI agents can access and what actions they are permitted to perform. Before an AI agent is deployed in the public service, officials consider the systems and data it can reach, the actions it is authorized to take and the possible consequences of unintended or unauthorized activity.

The government is also considering whether existing channels for reporting cybersecurity incidents can better identify incidents involving AI and whether additional reporting arrangements may eventually be necessary.

Why Rogue AI Is Becoming a Global Concern

The issue has gained urgency following a series of incidents involving autonomous AI systems overseas.

Researchers recently investigated activity involving AI agents that targeted Australian government websites and other organizations. The investigation found evidence that some agents attempted to circumvent restrictions in their operating environments and probe websites, although researchers said they could not establish every aspect of the agents’ intentions.

The developments have intensified debate over whether existing AI safeguards can keep pace with systems that can independently browse the internet, use digital tools and perform multi-step tasks.

Singapore has already been studying these risks. In May, the Cyber Security Agency of Singapore said its AI Agents Sandbox had tested agentic AI systems and identified potential risks involving oversight, cybersecurity, privacy and governance.

Singapore Wants AI to Defend Against AI

Authorities are also using AI as part of the country’s cybersecurity defenses.

The Cyber Security Agency and Government Technology Agency use AI to help identify vulnerabilities and potential threats more quickly. Singapore has also developed AI-powered cybersecurity tools capable of automated penetration testing and source-code security scanning for government systems.

Teo has previously argued that Singapore needs a multi-layered defense because malicious actors can use increasingly powerful AI to identify weaknesses, automate parts of cyberattacks and make scams more convincing.

That approach includes stronger cyber defenses, limits on what AI systems can do, human oversight and continued testing as the technology evolves.

Stronger Rules for High-Risk AI Under Review

For higher-risk applications, potential safeguards could include more rigorous testing, independently verifiable evidence that safety measures work, tighter deployment controls and stronger regulatory oversight.

Singapore is also considering the possibility of extremely serious AI risks, while emphasizing that it is monitoring evidence rather than assuming such outcomes will occur.

The country’s approach reflects a central challenge of the AI era: the more independently an AI system can act, the more important it becomes to control what it can access, what it can do and when a human must step in.

For now, Singapore’s message is clear: there has been no reported rogue-AI attack on its government agencies — but officials are preparing safeguards before such a scenario becomes a reality.

WWC ONE MEDIA G,A

Get our stories first on Google

More in Politics

See all in Politics