Back to Policy Library 🏢 Sector Regulation 2024-10

Policy / Project Profile

Guidelines on Securing AI Systems

Best-practice guidelines for end-to-end security across the AI system lifecycle.

Why it matters

CSA finalized the Agentic AI Security Guidelines in eight months; soft law-first approach establishes Singapore's model for autonomous agent risk governance

Category
Sector Regulation
Published / Updated
2024-10
Issuing body
Cyber Security Agency (CSA)

Detailed Notes

In October 2024, CSA released the Guidelines on Securing AI Systems together with a companion practice handbook, filling a governance gap in the AI security space. The guidelines cover the full AI system lifecycle: threat modelling at the planning and design stage, data and model security during development, security testing at deployment, and monitoring and incident response in operations. They focus on AI-specific risks including adversarial attack defence, data poisoning prevention, model theft protection, and supply chain security.

The companion addendum "Securing Agentic AI" was issued in draft for public consultation on 22 October 2025 (closing 31 December 2025), and the finalised version was released on 17 June 2026, extending the guidelines to agentic AI: identifying and assessing risk according to agent capabilities, mapping workflows to surface exploitable weak points, and setting out controls across the development lifecycle for different levels of autonomy.

Resources

More in This Category

Cite this record

Singapore AI Observatory. Guidelines on Securing AI Systems. Retrieved 2026-08-31, https://sgai.md/policies/guidelines-on-securing-ai-systems/

More on these topics