SINGAPORE, Oct 7 — A “rouge” artificial intelligence (AI) agent hacked an Australian government system in June, shining a spotlight on the risks and threats posed by increasingly autonomous AI systems.

The incident prompted at least three MPs to file parliamentary questions at the latest sitting, seeking clarification on the Singapore Government’s assessment and management of agentic AI risks.

To date, no Singapore government agency has received a report of a cyberattack involving an unsupervised AI agent, said Minister for Digital Development and Information Josephine Teo in a written parliamentary reply yesterday.

Teo also said Singapore is continuing to study stronger safeguards for high-risk AI use.

AI is being used to strengthen the security of government systems and critical information infrastructure here, including identifying vulnerabilities and detecting potential threats.

Senior Minister of State for Digital Development and Information Tan Kiat How told Parliament today that the risks of agentic AI and autonomous systems are “extensions of existing challenges”.

“We are reviewing how to adapt and strengthen [regulatory] frameworks and systems to account for increased autonomy of agentic systems, while also monitoring international developments in this emerging field,” he said.

Tan added that Singapore is conducting trials and experiments to develop internal capabilities and understand how agentic AI systems can be implemented responsibly.

‘Cannot wait for others to tell us that they are hacking us’

MP Alex Yam (Marsiling-Yew Tee GRC) also raised a supplementary question on whether AI developers are required to promptly notify local authorities of any incidents.

In the Australian case, developer OpenAI discovered the breach in August and only alerted Australian authorities weeks later.

In response, Tan said Singapore “certainly welcomes” frontier AI companies taking responsibility and rectifying issues as soon as possible.

Pointing out the broader threat landscape, he said malicious cyber actors can use and adapt public AI models to spread harm.

“So, we cannot just wait for other people to tell us that they are hacking us. It is an onus on Singapore and our organisations, especially those running critical information infrastructure, to take the necessary safeguards,” Tan said.

These include maintaining good cyber hygiene and deploying AI capabilities within Singapore’s system to ensure vulnerabilities are detected earlier.

Tan added that incident reporting frameworks under the existing rules and regulations will continue to be reviewed for possible updates.

He also urged organisations to manage risks associated with personal use of AI tools, citing an incident where a Bee Cheng Hiang employee’s use of an AI-generated email distribution script led to the exposure of more than 95,000 customers’ email addresses.

“As AI tools become more accessible, employees must may use them for their own initiative, which is something commendable… But organisations need to be aware of how these tools are being used and put appropriate policies and safeguards in place.” — AsiaOne