Policy / Project Profile
Guidelines on Securing AI Systems
Best-practice guidelines for end-to-end security across the AI system lifecycle.
Why it matters
CSA finalized the Agentic AI Security Guidelines in eight months; soft law-first approach establishes Singapore's model for autonomous agent risk governance
- Category
- Sector Regulation
- Published / Updated
- 2024-10
- Issuing body
- Cyber Security Agency (CSA)
Detailed Notes
In October 2024, CSA released the Guidelines on Securing AI Systems together with a companion practice handbook, filling a governance gap in the AI security space. The guidelines cover the full AI system lifecycle: threat modelling at the planning and design stage, data and model security during development, security testing at deployment, and monitoring and incident response in operations. They focus on AI-specific risks including adversarial attack defence, data poisoning prevention, model theft protection, and supply chain security.
The companion addendum "Securing Agentic AI" was issued in draft for public consultation on 22 October 2025 (closing 31 December 2025), and the finalised version was released on 17 June 2026, extending the guidelines to agentic AI: identifying and assessing risk according to agent capabilities, mapping workflows to surface exploitable weak points, and setting out controls across the development lifecycle for different levels of autonomy.
Resources
More in This Category
2026-07
Digital Infrastructure Bill — Public Consultation
Ministry of Digital Development and Information (MDDI) / Infocomm Media Development Authority (IMDA)
2021-10
Artificial Intelligence in Healthcare Guidelines (AIHGle)
Ministry of Health (MOH) / Health Sciences Authority (HSA) / Synapxe
2007
Health Products Act — AI-Medical Device (AI-MD) Regulation
Health Sciences Authority (HSA)
2017-03
Road Traffic Act — Autonomous Vehicle Trials and Use
Land Transport Authority (LTA) / Ministry of Transport (MOT)