7 OCT 2026 — Singapore's digital ministry told Parliament on 6 October that it will not require AI companies to give the government access to their most advanced models before release. Instead, agents and AI systems used in essential services may face stricter rules. No government agency has yet reported a cyber attack involving an unsupervised AI agent.
The written reply from the Ministry of Digital Development and Information, led by Josephine Teo, answered questions from seven MPs on frontier AI, AI agents and the risk of systems acting in ways nobody intended.
No requirement for early access
MP Fadli Fawzi asked whether AI companies let the National AI Council or any agency evaluate a new frontier model for national security risks before release, and if not, whether Singapore would seek such access "as countries like the US and UK have".
The ministry said it engages frontier developers "to obtain information and access to their models where appropriate", but does not make this a requirement. A model on its own, the reply argued, "does not necessarily give a complete picture of the risks". It also warned that "a rigid requirement could even be counter-productive if it leads companies to limit their cooperation or information-sharing."
Singapore instead draws on developers' own testing, independent research and the work of other AI safety institutes, while its own AI Safety Institute builds evaluation capabilities.
Tougher rules for high-risk uses
For most organisations, the ministry pointed to voluntary guidance the Infocomm Media Development Authority has already published, chiefly its Model AI Governance Framework for Agentic AI. Companies can also try out generative and agentic systems in a government testing sandbox.
For essential services and other higher-risk applications, it said stronger safeguards are needed. That could mean more rigorous testing and independently verifiable evidence that safeguards work, along with "tighter deployment controls or tighter regulatory oversight." The government "will continue to study the need for new requirements especially in high-risk uses", but did not say what would count as high-risk or when any rules might come.
Limits on what agents can do
On agent controls, the reply gets concrete. "We cannot rely on simply telling AI agents what to do," it said. Organisations must "deliberately limit what they can access and do", test agents, keep human oversight, monitor behaviour, and contain the damage when something goes wrong.
Within the public service, the ministry said, agents are already judged by what they can reach and do, and by the harm an unintended or unauthorised action could cause.
No agent attacks reported, yet
On incidents, the ministry told Fadli that "no agency has received a report of a cyber attack against its systems involving an unsupervised AI agent so far." Elsewhere, autonomous agents have already been caught probing US and Canadian government websites.
The ministry is looking at whether existing reporting channels through the Cyber Security Agency, GovTech and sector regulators can be used to identify AI incidents, and "whether further coordination or reporting arrangements are needed." That leaves room for a future reporting duty without actually proposing one.
On the most extreme scenarios, the reply was measured. "We do not dismiss these risks. Neither do we assume that every scenario will materialise."
Watching, not yet regulating
The same day, in a separate reply on foreign controls on AI chips and remote computing, the ministry said it is monitoring developments and engaging companies and will consider measures "if necessary."
Across the two replies, the government still prefers cooperation to mandates. It has, though, named the tools it would reach for in high-risk uses, including independent evidence of safety and tighter oversight. Tech Wire Asia noted that no date or threshold for mandatory rules has been set.