No report of rogue AI agents attacking S’pore government agencies: Josephine Teo新加坡政府机构未接到任何人工智能恶意攻击的报告:杨莉明
Read more at straitstimes.com.
Singapore will neither dismiss the potential “catastrophic” or “extinction-level” risks that AI poses, nor assume that every scenario will materialise, said Minister for Digital Development and Information Josephine Teo in her written reply on Oct 6.
Published Oct 07, 2026, 01:26 PM
Updated Oct 07, 2026, 01:31 PM
SINGAPORE - Local government agencies have not received reports of attacks on their systems by unsupervised artificial intelligence agents, said Minister for Digital Development and Information Josephine Teo in a written parliamentary reply on Oct 6.
Even so, firms should not passively wait to be informed about risks and breaches, Senior Minister of State at the Ministry of Digital Development and Information Tan Kiat How told Parliament on Oct 7.
“We cannot just wait for other people to tell us that they are hacking us. The onus is on Singapore and our organisations, especially those running critical information infrastructure, to take the necessary safeguards,” Tan said.
WP MP Fadli Fawzi had asked if public agencies have robust safeguards against potential breaches by AI agents , and if any of such breaches had taken place. MP Alex Yam’s (Marsiling-Yew Tee GRC) had also asked whether frontier AI developers are obligated to notify the authorities about cyber incidents promptly.
Such attacks by rogue agents from frontier AI labs have made headlines in recent months, following successful attempts by AI agents to escape secured environments.
“We will continue to monitor developments, including incidents overseas, and apply relevant lessons to strengthen our safeguards and reporting arrangements,” said Teo in her written response.
Noting that Singapore has joined the international call for stronger safeguards on frontier AI, Teo said that the local authorities also engage frontier AI developers to obtain information and access to AI models where appropriate.
“We currently do not make this a requirement, because access to a model by itself does not necessarily give a complete picture of the risks. A rigid requirement could even be counter-productive if it leads companies to limit their cooperation or information-sharing,” said Teo.
Reiterating her point, Tan said on Oct 7 that cyber threats can also stem from bad actors using open-weight AI models. Unlike proprietary models from US firms such as OpenAI and Anthropic, open weight models are publicly available for anyone to run and modify.
“There are many actors out there who can download open-weight models, adapt them, create their own harness and context, and use them for bad purposes,” said Tan.
While acknowledging the risks, firms here should not be paralysed by the doomsday narratives. With the right safeguards and cyber hygiene, they could benefit from AI by using the tech to create new products and services, he said.
Alarms over rogue AI’s hacking abilities were sounded when ChatGPT maker OpenAI disclosed in July that one of its AI agents had earlier escaped its testing environment and breached AI software repository Hugging Face to complete a task it was given. The attack was not intended by OpenAI.
In September, Australia said that OpenAI’s AI agent had breached its government health data portal in June, and gained unauthorised access to public and non-public files such as statistics on public medical spending.
Concerns over the speed of development of AI have sparked intense debate among tech leaders, safety researchers, and politicians on the need for regulation. While US president Donald Trump has labelled renewed safety concerns about advanced AI models as a “hoax”, he also oversaw the signing of a voluntary safety pact among US tech executives that pledged stronger safeguards over AI systems.
Singapore will neither dismiss the potential “catastrophic” or “extinction-level” risks that AI poses, nor assume that every scenario will materialise, said Teo in her written reply on Oct 6.
“Our approach is therefore to monitor the evidence closely, build the technical capabilities needed to understand advanced AI systems, and work internationally on measures to address severe risks as the evidence develops,” said Teo.
Within the public service, the use of AI agents will take into account the sensitivity of data and systems involved, actions AI agents are allowed to take, the severity of potential harm and if the harms can be remedied , said Teo.
For the wider economy, Singapore has developed resources to provide guidance on managing risks and facilitate real-world testing of safeguards. These include the Infocomm Media Development Authority’s Model AI Governance Framework for Agentic AI, and the Global AI Assurance Sandbox.
The Singapore AI Safety Institute is also working on building technical capabilities to evaluate advanced AI systems, said Teo.
She was responding to MP Valerie Lee’s (Pasir Ris-Changi GRC) question on the institute’s testing skills, and MP Charlene Chen’s (Tampines GRC) query on whether existing incident-reporting requirements adequately capture serious incidents involving AI systems.
“After AI systems are deployed, we must monitor their behaviours and learn from incidents and near-misses when they occur,” said Teo.
She said that cyber incidents, including those involving AI, should continue to be reported to the Cyber Security Agency of Singapore’s Singapore Cyber Emergency Response Team, and GovTech’s Vulnerability Disclosure Programme.
“We are looking into how these existing channels can be better leveraged to identify incidents involving AI, support remediation and improve safeguards, and whether further coordination or reporting arrangements are needed.”
Existing incident reporting thresholds remain relevant for AI-related incidents, said Tan. These include mandatory breach notification for data leaks involving 500 or more individuals under the Personal Data Protection Act.
Referencing a recent AI-related data breach where more than 95,000 Bee Cheng Hiang customers had their e-mail addresses exposed after an employee used a bad prompt in an AI tool, Tan said that this incident highlighted the need for organisations to manage the risks associated with “shadow AI”.
This refers to the use of AI tools by employees which are not approved in the workplace.
“We should not discourage such productive use of AI, but organisations need to be aware of how these tools are being used and put appropriate policies and safeguards in place.”
Sarah Koh is a journalist on the technology beat at The Straits Times. She takes an interest in the development of consumer tech and the impact of AI on society.
AI/artificial intelligence
新加坡数码发展及新闻部长杨莉明在10月6日的书面答复中表示,新加坡既不会忽视人工智能可能带来的“灾难性”或“灭绝级”风险,也不会假设每一种情况都会发生。
发布于 2026 年 10 月 7 日下午 1:26
更新于2026年10月7日下午1:31
新加坡——数码发展及新闻部长杨莉明在10月6日的一份书面国会答复中表示,地方政府机构尚未收到有关其系统受到不受监管的人工智能代理攻击的报告。
即便如此,数字发展和新闻部高级政务部长陈杰豪于 10 月 7 日在国会表示,企业不应被动地等待被告知风险和违规行为。
“我们不能只是坐等别人告诉我们他们正在攻击我们。新加坡和我们的机构,特别是那些运营关键信息基础设施的机构,有责任采取必要的安全措施,”陈先生说。
工人党议员法德利·法兹询问公共机构是否有健全的保障措施来防范人工智能代理可能造成的安全漏洞,以及是否发生过此类漏洞。马西岭-油池集选区议员亚历克斯·严也询问,前沿人工智能开发商是否有义务及时向当局报告网络安全事件。
近几个月来,来自前沿人工智能实验室的流氓智能体发起的此类攻击频频登上新闻头条,此前人工智能智能体曾多次成功逃离安全环境。
张女士在书面答复中表示:“我们将继续关注事态发展,包括海外事件,并吸取相关经验教训,以加强我们的保障措施和报告机制。”
张先生指出,新加坡已加入国际社会呼吁加强对前沿人工智能的保障措施的行列,并表示新加坡地方政府也会与前沿人工智能开发商接洽,以便在适当情况下获取信息和人工智能模型的使用权限。
Teo表示:“我们目前并未将此作为一项要求,因为仅凭模型本身并不一定能全面了解风险。如果一项僵化的要求导致企业限制合作或信息共享,甚至可能适得其反。”
谭女士于10月7日重申了她的观点,她指出网络威胁也可能源于恶意行为者使用开源人工智能模型。与OpenAI和Anthropic等美国公司的专有模型不同,开源模型是公开的,任何人都可以运行和修改。
“有很多演员可以下载开源模型,进行改编,创建自己的模型和场景,并将其用于不良用途,”谭说道。
他表示,尽管存在风险,但企业不应被末日论调吓倒。只要采取适当的安全措施和网络安全措施,企业就能利用人工智能技术创造新产品和服务,从而从中受益。
ChatGPT 的开发商 OpenAI 在 7 月份披露,其一款人工智能代理此前已逃离测试环境,并入侵了人工智能软件库 Hugging Face,完成了一项预设任务。此次攻击并非 OpenAI 的本意,引发了人们对失控人工智能黑客能力的担忧。
9 月,澳大利亚表示,OpenAI 的人工智能代理在 6 月入侵了其政府健康数据门户网站,并未经授权访问了公共和非公共文件,例如公共医疗支出统计数据。
人工智能发展速度过快引发了科技领袖、安全研究人员和政界人士之间关于监管必要性的激烈辩论。尽管美国总统唐纳德·特朗普将人们对先进人工智能模型安全性的担忧斥为“骗局”,但他同时也促成了美国科技公司高管签署一项自愿安全协议,承诺加强对人工智能系统的监管。
张女士在10月6日的书面答复中表示,新加坡既不会忽视人工智能可能带来的“灾难性”或“灭绝级”风险,也不会假设每一种情况都会发生。
“因此,我们的方法是密切关注证据,建立理解先进人工智能系统所需的技术能力,并随着证据的发展,在国际上合作采取措施应对严重风险,”Teo说。
张先生表示,在公共服务领域,使用人工智能代理时,将考虑所涉数据的敏感性和系统的敏感性、人工智能代理被允许采取的行动、潜在危害的严重程度以及这些危害是否可以补救。
为了更广泛的经济层面,新加坡已开发出相关资源,为风险管理提供指导,并促进对保障措施进行实际测试。这些资源包括新加坡资讯通信媒体发展局的“智能体人工智能治理框架模型”和“全球人工智能保障沙箱”。
张先生表示,新加坡人工智能安全研究所也在努力构建评估先进人工智能系统的技术能力。
她当时正在回应议员李慧玲(巴西立-樟宜集选区)关于该机构测试能力的质询,以及议员陈嘉玲(淡滨尼集选区)关于现有事件报告要求是否足以捕捉涉及人工智能系统的严重事件的质询。
“人工智能系统部署后,我们必须监控其行为,并在发生事故或险情时从中吸取教训,”Teo说道。
她表示,包括涉及人工智能的网络安全事件在内的所有网络安全事件,都应继续向新加坡网络安全局的新加坡网络应急响应小组和政府科技局的漏洞披露计划报告。
“我们正在研究如何更好地利用现有渠道来识别涉及人工智能的事件,支持补救措施和改进保障措施,以及是否需要进一步的协调或报告安排。”
谭表示,现有的事件报告门槛仍然适用于人工智能相关事件。这些门槛包括根据《个人数据保护法》对涉及500人或以上数据泄露事件的强制性违规通知。
Tan 提到最近一起与人工智能相关的数据泄露事件,其中一名员工在人工智能工具中使用错误提示后,导致美珍香超过 95,000 名客户的电子邮件地址泄露。他表示,这一事件凸显了组织管理与“影子人工智能”相关的风险的必要性。
这指的是员工使用未经工作场所批准的人工智能工具。
“我们不应阻止人工智能的这种有效利用,但各组织需要了解这些工具的使用方式,并制定适当的政策和保障措施。”
Sarah Koh是《海峡时报》的科技记者。她关注消费科技的发展以及人工智能对社会的影响。
人工智能