MDDI スピーチ · 2024-10-16
Janil Puthucheary 上級国務大臣によるシンガポール国際サイバーウィーク AI ハイレベル討論会でのキーノートスピーチ
要点
- • 中心的な問題:「AIは安全に利用できるか?」2022年のChatGPT登場以来、この問題は政府、産業、学界、ユーザー、採用のすべてにおいて極めて重要です。
- • シンガポールの国際的な足跡:2023年の英国AI安全サミットへの参加;英国NCSC、米国CISAとの『Guidelines for Secure AI System Development』の共同署名;2024年の生成AI統治フレームワーク(9次元)の発表。
- • 「信頼」はSmart Nation 2.0の中心的な原則です。AIは「従来のサイバーセキュリティリスク」(オープンソースコンポーネントのバックドア、モデル操作、支援ソフトウェアへの攻撃)に直面するだけでなく、AI特有のリスク(データ抽出、モデル操作)にも直面しています。
- • CSAは初版『AI保護ガイドラインと補完ガイドライン』を発表しました——ガイドラインは長期的に適用可能な中心原則を記載し、補完ガイドラインはコミュニティ協働の産物です(規制的ではなく、「実務的参考資料」です)。
- • CSA × Resaro(シンガポールAIセキュリティ企業)が共同で論文を発表しました——「AI安全とは本当は何か」および各方の役割を探討しています。
- • 7月から9月にかけてシンガポールが『Global Challenge for Safe and Secure LLMs』を主催します——国際参加者300人以上、100チーム以上——中国、ドイツ、日本、マレーシア、シンガポール、米国から。
全文翻訳
MDDI 英語原文の翻訳 · 翻訳日: 2026-05-03
デジタル開発及び報道省上級上級国務大臣Janil Puthucheary博士による「シンガポール国際サイバー週」(SICW)AI高級レベル会議でのキーノートアドレス(2024年10月16日)
AIは安全に利用できるでしょうか?
皆様方、
ゲストの皆様、
皆様へ:
おはようございます。
1. 人工知能に関する「高級レベル会議」にご出席できることを大変嬉しく存じます。
AI安全は国際的な関心事です。
2. 「AIは安全に利用できるのだろうか?」
a. これは我々の多くの人が考え続けてきた問題です。特に2022年にChatGPTが一般社会の視野に入って以来、政府、産業、学界の活動にとって重要であり、ユーザーとしての我々にとっても重要であり、AI採用に対する我々の信頼にとっても重要です。
b. 我々が関心を持つのは、AIが「安全にされ」、「信頼できるものにされ」、そして「善の力」となることができるかどうかです。
3. 過去2年間、多くのパートナーと友人がこのテーマに関する国際対話を主催してきました。シンガポールはその中で積極的な参加者として、AI統治における我々の既存の取り組みを前に進めています。
a. 2023年、我々は英国で開催されたAI安全サミットに参加しました。これは越境AI安全およびセキュリティ対話における重要なマイルストーンです。
b. 昨年11月、シンガポールは英国国家サイバーセキュリティセンター(NCSC)および米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)と共同で『Guidelines for Secure AI System Development』に署名するよう招待されました。このドキュメントは、システム所有者が「AI意思決定およびAI安全フレームワーク」において使用すべき原則を示しています。
c. 今年、AI安全の領域における国際的な協議プロセスを経て、シンガポールは生成AIのための初の『Model AI Governance Framework』を発表しました。これは生成AI統治のための最初の包括的なフレームワークであり、9つの次元を持ち、これらのモデルが「全体的に検討され対応される」ことを確保するものです。
AIへの信頼が採用を促進します。
4. 新興技術に対応する際、これは我々が持つべき重要な対話です。クラウドコンピューティング、人工知能、量子コンピューティングなどの技術は、我々の産業と経済に大きな利益をもたらします。しかし、リスクと「それらをどのように管理するか」について警戒を保つ必要があります。「困難な方法で教訓を学ぶ」べきではなく、事後に追い付くべきでもなく、危機と「物事が上手くいかないこと」を通じて発見されたギャップにパッチを当てるべきではないのです。
5. これが、我々が「信頼」を中核原則として位置付ける理由です。これはシンガポール「Smart Nation 2.0」計画の中核的な部分です。すべてのユーザー、大規模な組織と個人は、以下を信頼できなければなりません。技術(新興技術を含む)は安全で信頼でき、彼らの安全と福祉が確保されることを。
6. これは信頼を与えます。新しいユースケースを試み、次の成長の波で新技術を導入し、我々のSmart Nation 2.0計画における大きな目標に接続するための信頼を与えます。つまり、我々がコミュニティのために何ができるか、我々の社会と機会にどのような成長をもたらすことができるかについての目標に接続するのです。
7. したがって、これは成長と生産性だけではなく、これらは必然的な結果ですが、「AIを上手く実装する」ことについてもあります。我々は知っています。医療などの特定分野では、重大なリスクに対処するため、より高いAI安全標準を採用する必要があることを。
a. 我々はAIシステムを悪意のあるサイバー攻撃から保護する必要があります。我々は知っています。脅威行為者がオープンソースのAIコンポーネントにバックドアを挿入でき、最終的なモデルが操作または破壊される可能性があり、脅威行為者がAIの支援ソフトウェアに対して従来の攻撃を実行する可能性があることを。古いリスクは消えていません。それらは「積み重ねられ」ているだけです。したがって、これらのシステムはすべて更新とパッチが必要です。
b. 我々はAIモデルを保護する必要があります。データ抽出の試みから。これらすべては、「AIソリューション上の長期的信頼を強化する」ための必要な取り組みです。
8. これは、サービスプロバイダー、産業プレイヤー、および公共部門の技術パートナー間の緊密な協力を必要とします。例えば、シンガポールにおけるヘルスケアテクノロジー機関Synapxeと政府技術局(GovTech)の間の協力などです。
9. AIはまた多くの業界に、そして生態系全体にわたって成長しています。したがって、業界固有のリスク以外に、我々はシステミックリスクにも直面しています。これらは我々の思考の最前線に上昇しました。これは共同で対処する必要のある国際的な課題です。
a. ひとたび、重要なAI基盤インフラの重要な部分が混乱を受けると、多くの企業がモデル、ツール、およびサービスへのアクセスを失う可能性があります。
b. ユーザーもまた、AIの周りにビジネスモデルやプロセスモデルを構築していた場合、AIソリューションが破壊されると、彼らの活動を続けることが困難になります。これらのサービスの修復と回復には、いくらかの時間が必要になる可能性があります。これは配置されている安全性と復元力の対策に依存します。
c. この事態が発生した場合、それは多くの人々に影響を与えます。彼らの住む場所やAIモデルが配置される場所に関わらず。
10. これが、AIを安全にし、信頼できるものにすることが我々の優先事項にならなければならない理由です。もし我々がこれらのリスクについて継続的に心配し続けるなら、誰もがAIを採用するのは困難でしょう。
11. これらはAI採用の必要条件です。我々は実践的なステップを取る必要があります。「信頼」の基盤を構築するために。
AI安全における我々の進展
12. 「グラス半分」という観点を描いた後、実のところ私たちは大きな進展を見てきました。AI は世界規模でますます速い速度で採用されています。これは「グラス半分満ちている」ことです。いくつかの国では、AI が重要インフラストラクチャーにおける採用も見られています。
13. 私たちは知っています——このような採用は多くの古典的なサイバーセキュリティリスクを増幅する可能性があり——AI の「機密性、完全性、可用性」(C/I/A)に影響を与える可能性があります。さらに、AI モデルとシステムに固有の、許可されていない新しいリスクもあります。
14. しかし、私たちは白紙から始めているわけではありません。AI セキュリティは古典的なサイバーセキュリティと比べてまだ若い——しかし既に多くの既存の取り組みがあります——開発者が適切なガードレールを設置し、彼らのモデルとシステムを保護するのを支援しています。私が強調した多くの対話は、このプロセスの一部です。
a. 例として——米国国立標準技術研究所(NIST)は『AI リスク管理フレームワーク』を発表しました——ユーザーが潜在的な AI リスクを管理するのを支援しています。
b. 韓国科学技術情報通信部は『信頼できる AI を実現する戦略』(Strategy to Realise Trustworthy AI)を宣言しました——AI をより安全で、より信頼できるものにするために。
15. 昨日——SICW 開幕式で——テオ・チー・ヘアン シニア・ミニスターが発表しました——シンガポール サイバーセキュリティ庁(CSA)が『AI 保護ガイドラインおよび補足ガイド』(Guidelines and Companion Guide for Securing AI)の初版を発表したことを。
a. これらのガイドラインは、システム保有者が使用すべき、重要かつ長期的に適用可能な原則を列挙しており——AI セキュリティへのアプローチを指導し——セキュリティ制御とベストプラクティスをどのように実装するかを含みます。
b. 補足ガイドは「コミュニティ主導の取り組み」であり——システム保有者に実用的な対策と制御項目を提供しています。それは規定的ではなく——システム保有者が「この若い分野を進む」のをサポートするリソースです。
c. 私は国際パートナー、業界プレイヤー、専門家からのコメントに感謝したいと思います。初期案に関して肯定的なフィードバック、および改善方法についての提案を受け取りました。
d. 私たちはフィードバックに対応するための努力をしました——そしてこれらの文書を「コミュニティ主導のリソース」として発表しました。私たちは引き続き協力することを望んでいます——AI を実践でより安全にするために。
16. また、私たちは、シンガポール AI 保証スペースの企業 Resaro と CSA が協力して——「AI セキュリティリスク」に関する論文を共同執筆することを発表できて嬉しいです。この論文は「AI のセキュリティとは何か」、およびこの分野でステークホルダーが担うべき役割について探求しています。ガイドライン、補足ガイド、およびこの議論論文は——すべて皆様のお座席のカードにリンクされています。論文と補足ガイドはオンラインで入手可能です。
17. 私たちは、AI を保護する新しい技術を発見するため、ローカルのサイバーセキュリティ専門コミュニティも発展させています。
a. たとえば——7 月から 9 月にかけて——シンガポールは『安全で信頼できる大規模言語モデルのためのグローバルチャレンジ』(Global Challenge for Safe and Secure Large Language Models)を主催しました。自信を持って共有できるのは——このチャレンジは 300 人以上の国際参加者を惹きつけ——堅牢なセキュリティ対策と革新的方法を開発し——大規模言語モデルへのジェイルブレイク攻撃を緩和し、LLM をより安全にしました。
b. このチャレンジには 100 以上のチームが参加しました——中国、ドイツ、日本、マレーシア、シンガポール、米国などからのチームを含む——これは AI チャレンジに対処するグローバルな努力を反映しています。
c. 私たちのトップチームは今日ここにいます。私と一緒に彼らを祝福し、感謝してください——彼らが AI をより安全にするための取り組みについて。
d. その後、パネルディスカッションがあります——ディスカッション後に——受賞者が賞を受け取ります。彼らを祝福し、サポートし、励まし続けてください——彼らの優れた仕事のために——また、彼らが今後も続けるよう励ましてください。
『AI における官民対話』を推進する
18. 本日のパネルディスカッション——は、政府関係者と業界専門家、研究者との間で開かれた対話を行う重要な機会です——AI をより安全にする方法を共に探求するために。また、ゲストが『私たちが優先すべき重要な対策』と『今までのところ最も効果的なこと』について意見を共有することも期待しています。
19. さらに重要なことに——私は、この対話が——ステークホルダーがどのように引き続き協力し、『政府機構、サプライヤー、システム保有者、業界プレイヤー、ユーザー』の間の関係を改善するかについて議論することを期待しています——AI の開発、展開、および使用を保護するために。
a. 誰もが『AI の信頼構築における』利害関係を持っています。私たちは同じ船に乗っています——現在、AI の開発、展開、および採用の重要な時期にあります。私たちは協力します——業界横断的に、司法管轄区域を超えて——早期にこれらの問題に対応するために。
20. 今日への招待をありがとうございます。皆様の会議が充実し、サイバーセキュリティウィークが楽しくなることを祈っています。
英語原文
MDDI 公式サイト原文 · 取得日: 2026-05-02
Keynote Address by SMS Janil Puthucheary at the Singapore International Cyber Week (SICW) High-Level Panel on AI on 16 Oct 2024
CAN AI BE SECURE?
Your excellencies,
Distinguished guests,
Ladies and gentlemen,
Good morning.
1. It is my pleasure to be here with you at this High-Level Panel on Artificial Intelligence.
AI Security is an International Concern
2. “Can AI be Secure?”
a. This is a question many of us have grappled with, more so since the explosion of ChatGPT into our consciousness in 2022, but it’s been relevant to our work in the government, industry, academia, and it is relevant to us as users, and relevant in our trust in the adoption of AI.
b. We are concerned with whether AI can be made safe, can be made secure, and be a force for good.
3. Many of our partners and friends have hosted international discussions on this topic in the past two years. Singapore has been an active participant in this space, building on our existing work in AI governance.
a. In 2023, we joined our counterparts at the AI Safety Summit, hosted by the UK. This was an important milestone in dialogues on AI safety and security, across borders.
b. In November of last year, Singapore was also invited to co-seal the “Guidelines for Secure AI System Development”, developed by the UK’s National Cyber Security Centre, or the NCSC, and the US’s Cybersecurity and Infrastructure Security Agency. This document outlines principles that system owners should use to guide their decision-making about AI, and their frameworks for AI safety.
c. This year, for AI safety, Singapore has launched a Model AI Governance Framework for Generative AI, following an international consultation process. This is the first comprehensive framework for the governance of Generative AI. It has nine dimensions to ensure that these models are seen and addressed in totality.
Trust in AI will Enable Adoption
4. In addressing emerging technologies, these are the sorts of critical conversations we need to have. Technologies like cloud computing, Artificial Intelligence, and quantum computing promise significant benefits to our industries and economies. However, we must be clear-eyed about the risks, and how we will manage them, rather than learn the lessons the hard way, subsequently try to play catch up, and patch the vulnerabilities that we discover through crisis and something going wrong.
5. This is why we have made trust a core principle, a core part of Singapore’s plan for Smart Nation 2.0. All users – large organisations and individuals – must be able to trust that technology, including emerging technology, will be secure and reliable, that their safety and well-being are assured.
6. This provides the confidence to try new use cases and deploy new technologies in the next bound of growth, and this feeds into some of our larger aims in developing this Smart Nation 2.0 plan—what we can do for our communities, and what we can do to grow our society and our opportunities.
7. So, this is not just about growth and productivity—those are necessary outcomes, but this is also about implementing AI well. We know that we must adopt a higher standard for safety and security of AI in certain domains, such as healthcare, to address key risks.
a. We must protect our AI systems against malicious cyberattacks. We know threat actors can insert backdoors into open-source AI components, final models can be manipulated or disrupted. Threat actors could also mount classical attacks on the software supporting AI. The old risks haven’t gone away. They’ve just been added to, so these systems all need to be updated. They need to be patched.
b. We must protect AI models against attempts to extract data. And all these are necessary efforts to strengthen long-term trust in AI-based solutions.
8. This requires close partnership between service providers, industry players, and public sector technology partners, such as what we have in Singapore, Synapxe, our Healthcare Technology Agency and the Government Technology Agency of Singapore.
9. AI has also grown in many sectors, and across our entire ecosystem. Therefore, there are not just the sector-specific risks, we also face systemic risks. These have come to the fore in our thinking, and this is really an international challenge that we have to tackle together.
a. If there are disruptions to key parts of our critical AI infrastructure, many companies can lose access to their models, tools, and services.
b. And users will find it difficult to continue with their activities, if they build their business model, process model around AI and the AI solutions have been corrupted. Efforts to repair and restore these services could take some time, depending on the security and resilience measures that are in place.
c. And as this happens, it affects many people, regardless of where they reside and where the AI models have been deployed.
10. This is why it must be a priority for us to make AI secure, and trustworthy. If we had to worry constantly about such risks, it would be difficult for any of us to adopt AI.
11. These are the necessary conditions for AI adoption, and we need to take practical steps to provide a base of trust.
Our Progress in AI Security
12. Having painted the “glass half-empty” picture, actually we are seeing quite a bit of progress. There is a lot of AI adoption across the globe at an increasing pace. This is now the “glass half-full”. In some countries, we are seeing AI adoption in critical infrastructure.
13. Now we know that this adoption increases many classical cybersecurity risks. This can affect the confidentiality, integrity, and availability of AI. There are new risks unique to AI models and systems which are not authorised.
14. But we are not starting from zero. AI security is relatively nascent compared to the classical cybersecurity, but there are many existing efforts to help developers put the right guardrails in place, and to secure their models, secure their systems, and the many conversations that I’ve highlighted are part of this process.
a. The examples continue: the US National Institute of Standards and Technology has released an AI Risk Management Framework. This will help users to manage potential AI risks.
b. The Ministry of Science and Technology in South Korea has also announced its plans to make AI more safe, secure, and trustworthy, in its “Strategy to Realise Trustworthy AI”.
15. Yesterday, at the SICW Opening Ceremony, Senior Minister Teo Chee Hean announced that the Cybersecurity Agency of Singapore is publishing the first edition of our Guidelines and Companion Guide for Securing AI.
a. These guidelines set out key, evergreen principles that system owners should use to guide their approach to security of AI, including how they implement security controls and best practices.
b. The companion guide is a community effort to provide system owners with practical measures, and controls. This is not meant to be prescriptive, but is a resource to support system owners to navigate this nascent space.
c. I would like to thank our international partners, industry players, and professionals for their comments. We received positive feedback on our initial draft, along with suggestions on how to improve it.
d. We have taken effort to address the feedback, and have put the documents out as a community-led resource. We hope to continue working together to make AI more secure in practice.
16. I am also pleased to announce that CSA has worked with Resaro, a Singaporean company in the AI assurance space, to co-author a paper on AI security risks. This paper explores what security of AI means, and discusses the role that all stakeholders should play in this space. The Guidelines, the Companion Guide, and this discussion paper are all linked on the card that you may have seen on your seats. The paper and the companion guide are available online.
17. We are also developing our local community of cybersecurity professionals, to discover new techniques for securing AI.
a. For example, from July to September, Singapore hosted a Global Challenge for Safe and Secure Large Language Models, or LLMs. I am proud to share that this challenge saw more than 300 international participants to developing robust security measures and innovative approaches to mitigate jailbreaking attacks on LLMs, and to make LLMs more secure.
b. We had more than 100 teams in this challenge, including groups from China, Germany, Japan, Malaysia, Singapore, and the United States. This is a reflection of the global effort to tackle the challenges of AI.
c. Our top teams are in the audience with us today. Please join me in congratulating them and thanking them for their effort to make AI more secure.
d. We will have the panel discussion after this and after the panel discussion, the winners will receive their prizes. Please stay on and congratulate them, support them and encourage them for the great work that they have done, which we will encourage them to keep on doing.
Facilitating a Public-Private Conversation on AI
18. The panel today is an important opportunity for us as government officials to have an open dialogue with industry professionals, together with researchers, and explore how AI can be made more secure. I look forward to our panellists’ comments on the key measures we should prioritise, and what has been most effective so far.
19. More importantly, I look forward to how the dialogue can discuss how stakeholders should continue to work together and improve their relationships across government agencies, vendors, system owners, industry players, and users, to safeguard the development, deployment and the use of AI.
a. Everyone has a stake in building trust in AI. We are in this together and we are at a critical period for the development, deployment, and adoption of AI. We will work together to address these issues early – across sectors, and across jurisdictions.
20. Thank you for inviting me to be with you today. I wish you all a fruitful session, and a wonderful Cyber Week.