Existing safeguards by AI companies insufficient as models grow more capable: Josephine Teo约瑟芬·特奥:随着人工智能模型能力的提升,现有安全措施已不足以应对人工智能公司面临的挑战。
Content filters, user verification and pre-release testing are among existing safeguards, but malicious users can bypass them by turning to openly available AI models, says the digital development and information minister.

Content filters, user verification and pre-release testing are among existing safeguards, but malicious users can bypass them by turning to openly available AI models, says the digital development and information minister.
Minister for Digital Development and Information Josephine Teo speaking to the media at the Ministry of Digital Development and Information on Aug 28, 2026. (File photo: CNA/Ooi Boon Keong)
This audio is generated by an AI tool.
SINGAPORE: Safeguards put in place by frontier artificial intelligence (AI) companies are important but insufficient to address the risks posed by increasingly capable systems, said Minister for Digital Development and Information Josephine Teo on Friday (Oct 2).
In a Facebook post, Mrs Teo said malicious users could misuse increasingly powerful AI to cause harm, such as by looking for weaknesses in computer systems, writing malicious code, automating parts of cyberattacks and making scams more convincing.
Such safeguards include filtering content that could facilitate harm, limiting what AI models can access and do, testing models before release, verifying users, detecting misuse and suspending accounts that break their rules.
"These safeguards are important, but insufficient. Malicious users can still turn to openly available models that can be downloaded and run independently by anyone, making it easier to bypass safeguards and hide misuse," said Mrs Teo.
CNA Games Guess Word Crack the word, one row at a time Buzzword Create words using the given letters Mini Sudoku Tiny puzzle, mighty brain teaser Mini Crossword Small grid, big challenge Word Search Spot as many words as you can Show More Show Less "At the same time, as AI becomes more capable of acting on our behalf, deliberate misuse is not the only concern. An AI system could also misunderstand an instruction, be tricked by malicious information, or take actions that its user or developer did not intend." Singapore therefore needs multiple lines of defence, including stronger cyber defences and a better understanding of what advanced AI systems are capable of, Mrs Teo added. MULTIPLE LINES OF DEFENCE Mrs Teo said many AI-related incidents today involve cyber threats. "There’s much more we can do to prevent our systems from being easy targets of attack. We must also become better at detecting attacks and recovering when they happen." This is especially important for government systems and essential services, where disruptions could have severe consequences for the public, she added. "We must carefully balance between convenience and security to ensure the quality of user experience does not come at the expense of effective safeguards." Mrs Teo noted that the Cyber Security Agency of Singapore (CSA) has issued guidance urging organisations to patch vulnerabilities, use strong authentication and tighten access controls to important systems. Organisations can also use AI defensively, such as to identify vulnerabilities before attackers do, she said. "In other words, just as attackers can use AI, so too can defenders. Even if an organisation does not have access to the most advanced AI models, it can already use available AI tools to improve its cyber defence." Safeguards become even more important when organisations give AI models access to their data, tools and processes, said Mrs Teo, noting that AI is increasingly being used to power agents that carry out tasks on behalf of humans. "An agent does not need to deliberately bypass its guardrails to cause harm. It might misunderstand an instruction, pursue a goal in ways its designers or users did not intend, be tricked by malicious information or simply be given too much authority or access to tools." For example, an AI agent used for online shopping could be tricked by malicious instructions on a website into making unintended purchases or revealing personal information, Mrs Teo said.
"At the same time, as AI becomes more capable of acting on our behalf, deliberate misuse is not the only concern. An AI system could also misunderstand an instruction, be tricked by malicious information, or take actions that its user or developer did not intend."
Singapore therefore needs multiple lines of defence, including stronger cyber defences and a better understanding of what advanced AI systems are capable of, Mrs Teo added.
MULTIPLE LINES OF DEFENCE
Mrs Teo said many AI-related incidents today involve cyber threats.
"There’s much more we can do to prevent our systems from being easy targets of attack. We must also become better at detecting attacks and recovering when they happen."
This is especially important for government systems and essential services, where disruptions could have severe consequences for the public, she added.
"We must carefully balance between convenience and security to ensure the quality of user experience does not come at the expense of effective safeguards."
Mrs Teo noted that the Cyber Security Agency of Singapore (CSA) has issued guidance urging organisations to patch vulnerabilities, use strong authentication and tighten access controls to important systems.
Organisations can also use AI defensively, such as to identify vulnerabilities before attackers do, she said.
"In other words, just as attackers can use AI, so too can defenders. Even if an organisation does not have access to the most advanced AI models, it can already use available AI tools to improve its cyber defence."
Safeguards become even more important when organisations give AI models access to their data, tools and processes, said Mrs Teo, noting that AI is increasingly being used to power agents that carry out tasks on behalf of humans.
"An agent does not need to deliberately bypass its guardrails to cause harm. It might misunderstand an instruction, pursue a goal in ways its designers or users did not intend, be tricked by malicious information or simply be given too much authority or access to tools."
For example, an AI agent used for online shopping could be tricked by malicious instructions on a website into making unintended purchases or revealing personal information, Mrs Teo said.
"The bigger the potential impact of an AI-enabled action, the stronger the safeguards and human oversight should be."
Mrs Teo also cited the Infocomm Media Development Authority's Model AI Governance Framework for Agentic AI, which sets out safeguards for organisations deploying such systems.
These include limiting what an agent can access and do, requiring human approval for higher-risk actions, testing agentic systems before deployment and monitoring their actions.
TESTING ADVANCED AI MODELS
Singapore also needs to go "further upstream" to understand what increasingly capable AI models can do, their limitations and how they behave in different situations, said Mrs Teo.
Singapore's AI Safety Institute is building the country's technical capabilities to evaluate advanced AI systems, together with international partners and third-party testers, she added.
Mrs Teo said international collaboration on testing and evaluation would allow Singapore to pool expertise, compare findings and build a stronger shared understanding of emerging risks.
She said Singapore was interested in working with leading scientific experts to develop stronger safeguards and technical standards to support policymakers, pointing to proposals in the Singapore Consensus on Global AI Safety Research Priorities report.
Singapore also recently backed an international call initiated by Norway and Finland for stronger safeguards around frontier AI .
"Whether the concern is deliberate misuse or unintended actions by increasingly autonomous AI, no single safeguard will be enough. We need a multi-layered approach comprising stronger cyber defences, clear limits on what AI can do, appropriate human oversight, and the capabilities to test, monitor and learn as the technology evolves," said Mrs Teo.
"As AI becomes more capable and autonomous, so must our safeguards. It is the only way to build trust in AI as a technology that serves the public good."
Get our pick of top stories and thought-provoking articles in your inbox
Stay updated with notifications for breaking news and our best stories
Join our channel for the top reads for the day on your preferred chat app
数字发展和信息部长表示,内容过滤器、用户验证和预发布测试等都是现有的安全措施,但恶意用户可以通过使用公开可用的 AI 模型来绕过这些措施。
2026年8月28日,新加坡数码发展及新闻部长杨莉明在数码发展及新闻部接受媒体采访。(资料照片:CNA/Ooi Boon Keong)
这段音频由人工智能工具生成。
新加坡:数码发展及新闻部长杨莉明周五(10月2日)表示,前沿人工智能(AI)公司采取的保障措施固然重要,但不足以应对日益强大的系统带来的风险。
张女士在 Facebook 上发帖称,恶意用户可能会滥用日益强大的 AI 来造成危害,例如寻找计算机系统中的漏洞、编写恶意代码、自动化网络攻击的部分过程以及使诈骗更具说服力。
这些安全措施包括过滤可能造成伤害的内容、限制人工智能模型可以访问和执行的操作、在发布前测试模型、验证用户、检测滥用行为以及暂停违反规则的帐户。
“这些安全措施固然重要,但还不够。恶意用户仍然可以利用公开可用的模型,任何人都可以下载并独立运行这些模型,从而更容易绕过安全措施并隐藏滥用行为,”张女士说。
CNA游戏 猜词游戏 逐行破解单词 流行词游戏 用给定的字母组成单词 迷你数独 小谜题,脑力挑战 迷你填字游戏 小方格,大挑战 单词搜索 尽可能多地找出单词 显示更多 显示更少 “与此同时,随着人工智能越来越能够代表我们行事,蓄意滥用并非唯一的担忧。人工智能系统也可能误解指令、被恶意信息欺骗,或采取用户或开发者意想不到的行动。” 张女士补充说,因此,新加坡需要多重防御,包括更强大的网络防御和对先进人工智能系统能力的更深入了解。 多重防御 张女士表示,如今许多与人工智能相关的事件都涉及网络威胁。“我们可以做更多的事情来防止我们的系统成为攻击的易受攻击目标。我们还必须提高检测攻击和在攻击发生时进行恢复的能力。” 她补充说,这对于政府系统和重要服务尤为重要,因为这些系统的中断可能会对公众造成严重后果。 “我们必须谨慎权衡便利性和安全性,确保用户体验的质量不会以牺牲有效的安全保障为代价。”张女士指出,新加坡网络安全局 (CSA) 已发布指南,敦促各机构修补漏洞、使用强身份验证并加强对重要系统的访问控制。她表示,各机构还可以将人工智能用于防御,例如在攻击者之前识别漏洞。“换句话说,正如攻击者可以使用人工智能一样,防御者也可以使用。即使机构无法使用最先进的人工智能模型,也可以利用现有的人工智能工具来增强其网络防御能力。”张女士指出,当机构允许人工智能模型访问其数据、工具和流程时,安全保障就显得尤为重要。她还指出,人工智能越来越多地被用于驱动代表人类执行任务的智能体。“智能体无需故意绕过其防护措施即可造成损害。它可能误解指令,以设计者或用户意想不到的方式追求目标,被恶意信息欺骗,或者仅仅是被赋予了过多的权限或工具访问权限。”张女士说,例如,用于网上购物的人工智能代理可能会被网站上的恶意指令欺骗,从而进行非预期购买或泄露个人信息。
“与此同时,随着人工智能越来越能够代表我们行事,蓄意滥用并非唯一的担忧。人工智能系统也可能误解指令、被恶意信息欺骗,或者采取用户或开发者意想不到的行动。”
因此,新加坡需要多重防御措施,包括更强大的网络防御和对先进人工智能系统能力的更深入了解,张女士补充道。
多重防线
张女士表示,如今许多与人工智能相关的事件都涉及网络威胁。
“我们还可以采取更多措施来防止我们的系统成为攻击的轻易目标。我们还必须提高检测攻击和在攻击发生后进行恢复的能力。”
她补充说,这一点对于政府系统和基本服务尤其重要,因为中断可能会对公众造成严重后果。
“我们必须在便利性和安全性之间谨慎权衡,以确保用户体验的质量不会以牺牲有效的安全保障为代价。”
张女士指出,新加坡网络安全局 (CSA) 已发布指导意见,敦促各组织修补漏洞、使用强身份验证并加强对重要系统的访问控制。
她表示,组织还可以将人工智能用于防御目的,例如在攻击者之前识别漏洞。
换句话说,正如攻击者可以使用人工智能一样,防御者也可以使用人工智能。即使一个组织无法获得最先进的人工智能模型,它也可以利用现有的人工智能工具来改进其网络防御。
张女士表示,当组织允许人工智能模型访问其数据、工具和流程时,安全保障措施就显得更加重要。她指出,人工智能正越来越多地被用于驱动代表人类执行任务的代理。
“智能体无需故意绕过安全防护措施就能造成危害。它可能误解指令,以设计者或用户意想不到的方式追求目标,被恶意信息欺骗,或者仅仅是被赋予过多的权限或工具访问权限。”
张女士说,例如,用于网上购物的人工智能代理可能会被网站上的恶意指令欺骗,从而进行非预期购买或泄露个人信息。
“人工智能赋能的行动可能产生的影响越大,就应该加强保障措施和人工监督。”
张女士还提到了新加坡资讯通信媒体发展局的《智能体人工智能治理框架模型》,该框架为部署此类系统的组织制定了保障措施。
这些措施包括限制代理可以访问和执行的操作,要求对高风险操作进行人工批准,在部署前测试代理系统并监控其操作。
测试高级人工智能模型
张女士表示,新加坡还需要“进一步向上游”了解日益强大的AI模型能做什么,它们的局限性以及它们在不同情况下的表现。
她补充说,新加坡人工智能安全研究所正与国际合作伙伴和第三方测试人员一起,构建该国评估先进人工智能系统的技术能力。
张女士表示,在测试和评估方面开展国际合作,将使新加坡能够汇集专业知识,比较研究结果,并对新出现的风险建立更深入的共同认识。
她表示,新加坡有兴趣与顶尖科学专家合作,制定更强有力的保障措施和技术标准,以支持政策制定者,并提到了《新加坡全球人工智能安全研究优先事项共识》报告中的提议。
新加坡最近也支持了挪威和芬兰发起的一项国际呼吁,即加强对前沿人工智能的保障措施。
“无论是出于故意滥用还是人工智能日益自主化导致的意外行为,任何单一的保障措施都不足以应对。我们需要多层次的应对方案,包括更强大的网络防御、对人工智能能力的明确限制、适当的人工监督,以及随着技术发展进行测试、监控和学习的能力,”张女士说。
“随着人工智能能力的增强和自主性的提高,我们的安全保障措施也必须相应加强。这是建立公众对人工智能这项服务于公共利益的技术的信任的唯一途径。”
订阅我们的邮件,即可获取精选热点新闻和引人深思的文章。
订阅通知,第一时间获取突发新闻和精彩报道。
加入我们的频道,即可在您常用的聊天应用上获取当日热门文章。