SLW LB_Navigating AI, Workplace Fairness and Workplace Investigations

Close

HEADLINES

Headlines published in the last 30 days are listed on SLW.

No report of rogue AI agents attacking S’pore government agencies: Josephine Teo

No report of rogue AI agents attacking S’pore government agencies: Josephine Teo

Source: Straits Times
Article Date: 08 Oct 2026
Author: Sarah Koh

Attacks by rogue agents from frontier AI labs have made headlines in recent months, following successful attempts by AI agents to escape secured environments.

Local government agencies have not received reports of attacks on their systems by unsupervised artificial intelligence agents, Minister for Digital Development and Information Josephine Teo said in a written parliamentary reply on Oct 6.

Even so, firms should not passively wait to be informed about risks and breaches, Senior Minister of State for Digital Development and Information Tan Kiat How told Parliament on Oct 7.

“We cannot just wait for other people to tell us that they are hacking us. The onus is on Singapore and our organisations, especially those running critical information infrastructure, to take the necessary safeguards,” he said.

Workers’ Party MP Fadli Fawzi (Aljunied GRC) had asked if public agencies have robust safeguards against potential breaches by AI agents, and if any such breaches have taken place.

MP Alex Yam (Marsiling-Yew Tee GRC) had also asked whether frontier AI developers are obligated to promptly notify the authorities about cyber incidents.

Attacks by rogue agents from frontier AI labs have made headlines in recent months, following successful attempts by AI agents to escape secured environments.

In her written response, Teo said: “We will continue to monitor developments, including incidents overseas, and apply relevant lessons to strengthen our safeguards and reporting arrangements.”

Noting that Singapore has joined the international call for stronger safeguards on frontier AI, she added that the local authorities also engage frontier AI developers to obtain information and access to AI models where appropriate.

“We currently do not make this a requirement because access to a model by itself does not necessarily give a complete picture of the risks. A rigid requirement could even be counter-productive if it leads companies to limit their cooperation or information-sharing,” said Teo.

Reiterating Teo’s point, Tan said on Oct 7 that cyberthreats can also stem from bad actors using open-weight AI models.

Unlike proprietary models from US firms such as OpenAI and Anthropic, open-weight models are publicly available for anyone to run and modify.

Tan said: “There are many actors out there who can download open-weight models, adapt them, create their own harness and context, and use them for bad purposes.”

Even with the risks, firms in Singapore should not be paralysed by the doomsday narratives. With the right safeguards and cyber hygiene, they can benefit from AI by using the tech to create new products and services, he added.

Alarm over rogue AI’s hacking abilities was sounded when ChatGPT maker OpenAI disclosed in July that one of its AI agents had earlier escaped its testing environment and breached AI software repository Hugging Face to complete a task it was given. The attack was not intended by OpenAI.

In September, Australia said that OpenAI’s agent had breached its government health data portal in June, and gained unauthorised access to public and non-public files, such as statistics on public medical spending.

Concerns over the speed of AI’s development have sparked intense debate among tech leaders, safety researchers and politicians on the need for regulation.

While US President Donald Trump has labelled renewed safety concerns over advanced AI models as a “hoax”, he also oversaw the signing of a voluntary safety pact among US tech executives that pledged stronger safeguards over AI systems.

Singapore will neither dismiss the potential “catastrophic” or “extinction-level” risks that AI poses, nor assume that every scenario will materialise, Teo said in her written reply on Oct 6.

“Our approach is therefore to monitor the evidence closely, build the technical capabilities needed to understand advanced AI systems, and work internationally on measures to address severe risks as the evidence develops,” said Teo.

Within the public service, the use of AI agents will take into account the sensitivity of data and systems involved, the actions AI agents are allowed to take, the severity of potential harm and whether the harms can be remedied, she added.

For the wider economy, Singapore has developed resources to provide guidance on managing risks and facilitate real-world testing of safeguards. These include the Infocomm Media Development Authority’s Model AI Governance Framework for Agentic AI and the Global AI Assurance Sandbox.

The Singapore AI Safety Institute is also working on building technical capabilities to evaluate advanced AI systems, said Teo.

She was responding to MP Valerie Lee’s (Pasir Ris-Changi GRC) question on the institute’s testing skills, and MP Charlene Chen’s (Tampines GRC) query on whether existing incident-reporting requirements adequately capture serious incidents involving AI systems.

“After AI systems are deployed, we must monitor their behaviours and learn from incidents and near-misses when they occur,” said Teo.

She said that cyber incidents, including those involving AI, should continue to be reported to the Cyber Security Agency of Singapore’s Singapore Cyber Emergency Response Team, as well as GovTech’s Vulnerability Disclosure Programme.

“We are looking into how these existing channels can be better leveraged to identify incidents involving AI, support remediation and improve safeguards, and whether further coordination or reporting arrangements are needed.”

Existing incident reporting thresholds remain relevant for AI-related incidents, said Tan. These include mandatory breach notifications for data leaks involving 500 or more individuals under the Personal Data Protection Act.

Referencing a recent AI-related data breach where more than 95,000 customers of food distributor Bee Cheng Hiang had their e-mail addresses exposed after an employee used a bad prompt in an AI tool, Tan said that this incident highlighted the need for organisations to manage the risks associated with “shadow AI”.

This refers to the use of AI tools by employees that are not approved in the workplace.

Tan added: “We should not discourage such productive use of AI, but organisations need to be aware of how these tools are being used and put appropriate policies and safeguards in place.”

Source: The Straits Times © SPH Media Limited. Permission required for reproduction.

 

Print
1

Latest Headlines

No content

A problem occurred while loading content.

Previous Next
SLW RT_LIFTED Training Roadmap
SLW Lead Gen_Bottom Banner

Terms Of Use Privacy Statement Copyright 2026 by Singapore Academy of Law
Back To Top