MDDI's Response to PQ on Providing Pre-Deployment Government Access to Frontier AI Models for Independent Evaluation of National Security Risks and Vulnerabilities
6 October 2026
Parliament Sitting on 6 October 2026
Question for Written Answer
33. Mr Fadli Fawzi asked the Minister for Digital Development and Information (a) whether AI companies make their latest frontier model available to the National AI Council or any other Government agency before deployment for an independent evaluation of national security risks or hidden vulnerabilities; (b) if not, whether the Government will seek such access from AI companies as countries like the US and UK have; and (c) if not, why not.
Answer
My response will cover the questions raised by Ms Valerie Lee, Dr Charlene Chen, Mr Alex Yam and Mr Fadli Fawzi in today’s Order Paper, and the related questions filed by Mr Yip Hon Weng, Dr Choo Pei Ling and Mr Saktiandi Supaat for subsequent sittings. If the Members are satisfied with the response, they may wish to withdraw their questions after this exchange.
Singapore’s approach to AI has always been to enable innovation while managing the risks. But the risks are evolving as AI systems become more capable and autonomous.
Such systems may act in unintended ways, be manipulated by malicious actors, or have unexpected interactions with other systems. Capabilities are also advancing rapidly, sometimes faster than governments and external evaluators can fully assess. We therefore need a risk-based and multi-layered approach.
Set Limits Based on Risk
First, in deploying AI, we must calibrate limits according to risk. We should consider the sensitivity of the data and systems involved, the degree of autonomy given to the AI system, and the severity and remediability of any potential harm. The greater the potential harm, the stronger the safeguards should be.
This is how we approach the deployment of AI agents within the Public Service. We consider what systems and data an agent can access, what actions it is allowed to take, and the consequences of unintended or unauthorised actions. These safeguards are complemented by policies and governance processes to ensure appropriate oversight and accountability.
For the broader economy, the Infocomm Media Development Authority’s (IMDA’s) Model AI Governance Framework for Agentic AI and Starter Kit for Testing LLM-Based Applications provide guidance on managing risks and maintaining meaningful human accountability. In addition, the Global AI Assurance Sandbox facilitates the real-world testing of risks of generative and agentic AI, including the robustness of their safeguards.
For essential services and other higher-risk applications, stronger safeguards are necessary. This could include more rigorous testing for risks, independently verifiable evidence that safeguards are effective, tighter deployment controls or tighter regulatory oversight. The Government will continue to study the need for new requirements especially in high-risk uses.
Strengthen our Defences Against Unintended Actions and Misuse
Second, we must strengthen our defences against unintended AI actions and misuse. We cannot rely on simply telling AI agents what to do. We must also deliberately limit what they can access and do, conduct appropriate test suites, retain appropriate human oversight, monitor their behaviour, and contain the consequences if something goes wrong.
At the same time, we must presume that malicious actors will use AI to cause harm more cheaply, quickly and at scale. Given how deeply digital services are embedded across our economy and society, we must continually strengthen our cybersecurity and also make effective use of AI for cyber defence. The Cyber Security Agency of Singapore (CSA) and the Government Technology Agency of Singapore (GovTech) are using AI to strengthen the security of Government systems and critical information infrastructure, including to identify vulnerabilities and detect potential threats more quickly. CSA has also strengthened cybersecurity requirements for critical information infrastructure operators, shared intelligence on active threats to help them take pre-emptive action, and issued practical guidance to help organisations strengthen their cyber defences and secure AI systems.
Detect Risks and Respond Early
Third, we need stronger capabilities to identify risks both before and after deployment.
The Singapore AI Safety Institute, or AISI, is building technical capabilities to evaluate advanced AI systems, and develop practical methods for testing and assurance. We will focus on capabilities relevant to Singapore’s needs, while working with researchers, industry and overseas counterparts to draw on their expertise and findings.
After AI systems are deployed, we must monitor their behaviours and learn from incidents and near-misses when they occur. In cybersecurity, for example, there are established channels through CSA, GovTech and the sector leads where cybersecurity incidents should be reported, including those that involve AI. We are looking into how these existing channels can be better leveraged to identify incidents involving AI, support remediation and improve safeguards, and whether further coordination or reporting arrangements are needed.
To the question by Mr Fadli Fawzi, no agency has received a report of a cyber attack against its systems involving an unsupervised AI agent so far. We will continue to monitor developments, including incidents overseas, and apply relevant lessons to strengthen our safeguards and reporting arrangements.
Work with International and Industry Partners
Fourth, we continue to work with international and industry partners. Frontier models are developed and deployed internationally, and no single country or company can fully assess or manage the risks on its own. This is why Singapore recently endorsed the international call for stronger safeguards around frontier AI.
Some scenarios involving rogue AI envisage catastrophic or even extinction-level risks. We do not dismiss these risks. Neither do we assume that every scenario will materialise. Our approach is therefore to monitor the evidence closely, build the technical capabilities needed to understand advanced AI systems, and work internationally on measures to address severe risks as the evidence develops. This work is part of our broader national approach to AI risk. The National AI Council provides strategic direction, while the relevant agencies develop and implement the necessary measures. We will continue to adjust our safeguards as AI capabilities and the evidence on risks evolve.
We also engage frontier AI developers to obtain information and access to their models where appropriate. We currently do not make this a requirement, because access to a model by itself does not necessarily give a complete picture of the risks. A rigid requirement could even be counter-productive if it leads companies to limit their cooperation or information-sharing. Our preference is therefore to build strong collaborative relationships with frontier AI labs that encourage substantive and timely information-sharing.
At the same time, we continue to build our own technical capabilities and draw on a wider range of sources to identify risks of relevance to Singapore. This includes the developers’ own assessments and testing, independent research and evaluations, as well as the work of other AI safety institutes and international partners. By drawing on these different sources, rather than relying on any single form of access or assessment, we can develop a more comprehensive understanding of emerging risks and the safeguards needed to address them.
We have stepped up efforts to engage these international counterparts. Our AISI was a founding member of the International Network of Advanced AI Measurement, Evaluation, and Science. Since 2025, we have convened global experts through the International Scientific Exchange on AI Safety and developed the Singapore Consensus on Global AI Safety Research Priorities. We have also hosted some of the world’s most significant scientific conferences over the last two years. These have helped build international alignment on the most important gaps in AI safety science between researchers, governments and companies, creating networks and a common basis to coordinate this important work.
Conclusion
In conclusion, as AI becomes more capable of acting on our behalf, we must correspondingly introduce more robust safeguards. We must be clear about what it is allowed to do, ensure that humans remain in control and accountable where it matters, and continue strengthening our ability to understand emerging risks and respond when problems occur. This will help build trust in AI as a technology that serves the public good.
