
Singapore is assessing whether high-risk uses of artificial intelligence require tougher safeguards, since AI systems now have greater autonomy and access to data, tools and business processes. Meanwhile, the country’s gambling regulator has detailed its own growing use of AI.
In a written parliamentary response on Tuesday, Minister for Digital Development and Information Josephine Teo said possible measures for essential services and other higher-risk applications include more rigorous testing, independently verifiable evidence that safeguards work, tighter deployment controls and stronger regulatory oversight.
Teo said no cyberattack on government agencies involving an unsupervised AI agent has been reported, but the government does not dismiss “catastrophic or even extinction-level” risks, nor does it assume they will materialize.
The Ministry of Digital Development and Information said in July that regulation depends on how AI is deployed, the nature of the harm and whether existing measures address it. Singapore has not said when, or whether, additional safeguards will become mandatory.
Trials come before new rules
Senior Minister of State for Digital Development and Information Tan Kiat How said on Wednesday that the government is reviewing its frameworks for autonomous systems.
“We are running trials and experiments to stay abreast of the evolving technology and to understand what it takes to implement agentic systems responsibly,” Tan said in response to a question from MP Charlene Chen (PAP-Tampines).
Tan said many agentic AI risks are extensions of existing challenges, and existing guidelines and regulations also apply to these systems.
“I encourage all private sector organisations, even those who are not running critical information infrastructure or essential digital services, to also take appropriate care and responsibility when deploying AI agents or systems within their operations,” he said.
A voluntary playbook for AI agents
Current guidance rests on the voluntary Model AI Governance Framework for Agentic AI, which the Infocomm Media Development Authority (IMDA) introduced in January.
It places responsibility for agents’ actions, such as updating customer databases or making payments, on their operators, and advises restricting agents’ autonomy and access, setting human approval checkpoints, and conducting baseline testing.
IMDA updated it in May after feedback from more than 60 organizations, including AWS, DBS, Google and Salesforce, and added more than 10 case studies.
In one case study, Singapore-based enterprise automation company Dayos lets its IT agent complete password resets automatically, requires human approval for moderate-risk proposals and blocks autonomous permission changes. Tencent’s CodeBuddy coding agent requires human approval by default for actions such as editing files.
What the sandbox revealed
An AI Agents Sandbox run by Google with the Cyber Security Agency of Singapore, GovTech and IMDA began in August 2025 and ran for about four months. It concluded that higher-risk actions can require prior approval, while lower-risk actions can proceed with post-event review when effects are reversible and redress is available.
It also identified indirect prompt injection, in which malicious instructions embedded in information can deceive an agent into actions such as remote code execution, along with possible data leakage.
The Monetary Authority of Singapore published its Safeguards for Agentic Finance at Runtime (SAFR) framework in July 2026, with proposed controls on authorization, human oversight and decision records for financial services.
Abroad, OpenAI and Anthropic told Australia’s parliament they would welcome laws requiring them to report data breaches by their agents. The comments came after an outcry over OpenAI taking months to inform Australia that one of its agents had breached the country’s main health portal.
Inside the GRA’s AI Masterplan
In its 2025/26 Annual Report, Singapore’s Gambling Regulatory Authority (GRA) described technology as a “strategic enabler of our work.”
CEO Daniel Tan said the regulator has rolled out an AI Masterplan to guide its technology roadmap. Over the past year, the GRA extended its use of Microsoft Copilot and other digital tools, deployed AI bots that help officers access corporate resources such as finance regulations, and introduced anomaly-flagging tools for audit log reviews.
“Empowering officers to experiment with and apply AI has strengthened their capabilities and confidence in using these technologies effectively and responsibly,” Daniel Tan said. He added that the GRA continues to ensure officers develop their core regulatory skills.
Through the past year, he added, the GRA has made progress on multiple fronts. The regulator renewed licenses for operators including Marina Bay Sands (MBS) and Singapore Pools, and worked with the Ministry of Home Affairs, MBS and Resorts World Sentosa to support Singapore’s Financial Action Task Force (FATF) Mutual Evaluation.
Chairman Hoong Wee Teck said casino-related crime remained low. The number of Singapore citizens and permanent residents visiting the casinos fell from around 94,000, or 2.8% of the adult population, in 2024 to about 91,000, or 2.7%, in 2025, according to figures for the 12 months ended March 31, 2026. Annual levy holders remained stable at about 6,700.
