'Cannot wait for others to tell us': Tan Kiat How on safeguarding against AI cyber threats“迫不及待想听别人告诉我们”:陈杰豪谈防范人工智能网络威胁
A "rouge" artificial intelligence (AI) agent hacked an Australian government system in June, shining a spotlight on the risks and threats posed by increasingly autonomous AI systems.The incident prompted at least three MPs to file parliamentary questions at the latest sitting, seeking clarification on the Singapore Government's assessment and management of agentic AI risks.To date, no Singapore government agency has...

A "rouge" artificial intelligence (AI) agent hacked an Australian government system in June, shining a spotlight on the risks and threats posed by increasingly autonomous AI systems.
The incident prompted at least three MPs to file parliamentary questions at the latest sitting, seeking clarification on the Singapore Government's assessment and management of agentic AI risks.
To date, no Singapore government agency has received a report of a cyber-attack involving an unsupervised AI agent, said Minister for Digital Development and Information Josephine Teo in a written parliamentary response on Tuesday (Oct 6).
Teo also said Singapore is continuing to study stronger safeguards for high-risk AI use.
AI is being to strengthen the security of government systems and critical information infrastructure here, including identifying vulnerabilities and detecting potential threats.
Senior Minister of State for Digital Development and Information Tan Kiat How told Parliament on Wednesday that the risks of agentic AI and autonomous systems are "extensions of existing challenges".
"We are reviewing how to adapt and strengthen [regulatory] frameworks and systems to account for increased autonomy of agentic systems, while also monitoring international developments in this emerging field," he said.
Tan added that Singapore is conducting trials and experiments to develop internal capabilities and understand how agentic AI systems can be implemented responsibly.
'Cannot wait for others to tell us that they are hacking us'
MP Alex Yam (Marsiling-Yew Tee GRC) also raised a supplementary question on whether AI developers are required to promptly notify local authorities of any incidents.
In the Australian case, developer OpenAI discovered the breach in August and only alerted Australian authorities weeks later.
In response, Tan said Singapore "certainly welcomes" frontier AI companies taking responsibility and rectifying issues as soon as possible.
Pointing out the broader threat landscape, he said malicious cyber actors can use and adapt public AI models to spread harm.
"So, we cannot just wait for other people to tell us that they are hacking us. It is an onus on Singapore and our organisations, especially those running critical information infrastructure, to take the necessary safeguards," Tan said.
These include maintaining good cyber hygiene and deploying AI capabilities within Singapore's system to ensure vulnerabilities are detected earlier.
Tan added that incident reporting frameworks under the existing rules and regulations will continue to be reviewed for possible updates.
He also urged organisations to manage risks associated with personal use of AI tools, citing an incident where a Bee Cheng Hiang employee's use of an AI-generated email distribution script led to the exposure of more than 95,000 customers' email addresses.
"As AI tools become more accessible, employees must may use them for their own initiative, which is something commendable…But organisations need to be aware of how these tools are being used and put appropriate policies and safeguards in place."
lim.kewei@asiaone.com
今年 6 月,一个“失控”的人工智能 (AI) 代理入侵了澳大利亚政府系统,这凸显了日益自主的 AI 系统所带来的风险和威胁。
该事件促使至少三名国会议员在最近一次会议上提交议会质询,要求新加坡政府澄清其对人工智能代理风险的评估和管理。
新加坡数码发展及新闻部长杨莉明周二(10月6日)在国会书面答复中表示,迄今为止,新加坡政府机构尚未收到任何涉及不受监督的人工智能代理的网络攻击报告。
张志贤还表示,新加坡正在继续研究加强对高风险人工智能应用的保障措施。
人工智能正在加强政府系统和关键信息基础设施的安全,包括识别漏洞和检测潜在威胁。
数码发展及新闻部高级政务部长陈杰豪周三在国会表示,智能人工智能和自主系统的风险是“现有挑战的延伸”。
他说:“我们正在研究如何调整和加强(监管)框架和系统,以应对代理系统日益增强的自主性,同时也在关注这一新兴领域的国际发展。”
谭补充说,新加坡正在进行试验和实验,以发展内部能力并了解如何负责任地实施智能人工智能系统。
“迫不及待地想听听别人怎么说,说他们入侵了我们的系统。”
国会议员严亚明(马西岭-油池集选区)还提出了一个补充问题,即人工智能开发商是否必须及时向地方当局报告任何事件。
在澳大利亚的案例中,开发商 OpenAI 在 8 月份发现了数据泄露,但几周后才通知澳大利亚当局。
对此,谭表示,新加坡“当然欢迎”前沿人工智能公司承担责任并尽快纠正问题。
他指出更广泛的威胁形势,并表示恶意网络行为者可以利用和改造公共人工智能模型来散播危害。
“所以,我们不能只是等着别人告诉我们他们正在攻击我们。新加坡和我们的机构,特别是那些运营关键信息基础设施的机构,有责任采取必要的安全措施,”陈先生说。
这些措施包括保持良好的网络安全习惯,并在新加坡的系统中部署人工智能技术,以确保及早发现漏洞。
Tan补充说,现有规章制度下的事件报告框架将继续接受审查,以便进行可能的更新。
他还敦促各组织管理与个人使用人工智能工具相关的风险,并举例说明,美成香的一名员工使用人工智能生成的电子邮件分发脚本,导致超过 95,000 名客户的电子邮件地址泄露。
“随着人工智能工具变得越来越普及,员工可能会主动使用它们,这固然值得称赞……但企业需要了解这些工具的使用方式,并制定适当的政策和保障措施。”
lim.kewei@asiaone.com