MDDI スピーチ · 2025-10-22

Josephine Teo大臣による AI 首脳級小グループ会議での開幕致辞

楊莉明 · デジタル開発・ニュース相 · AI 首脳級小グループ会議

要点

  • 2つのテクノロジーが「同じ時刻」に世界を作り変えています——エージェンティック AI(agentic AI)+ 量子コンピューティングです。両者は私たちに「受動的規制」から「積極的準備」への転換を要求しています。
  • エージェンティック AI のガバナンス目標は 3 つです:①「保障」(assurance)で信頼を構築することであり、各デプロイメントを統制することではありません;②フレームワークとテストは実世界のシナリオにおいて堅牢である必要があります(安全な実験空間を提供する必要があります);③タイムリーな行動——デジタルデバイド、虚偽情報、サイバー詐欺の轍を踏むべきではありません。
  • シンガポールのエージェンティック AI ツールスタック:GovTech の「Agentic Risk and Capability Framework」、IMDA の AI Verify + Project Moonshot(レッドティーミング + ベンチマークテスト)+ AI Assurance Sandbox + GovTech-Google Cloud サンドボックスです。原則——「自主性が高いほど、保障が強い」。
  • 量子セキュリティ:CSA が 2 つの新しいツール『量子準備度指数』(Quantum Readiness Index、自己評価ツール)+『量子安全ハンドブック』(Quantum-Safe Handbook)について公開協議を実施しています;いずれも MVP およびリビングドキュメントと見なされています。
  • 国際協力:AI と量子は国境を尊重しません。シンガポール—NIST の相互運用性により、企業が「一度テストして世界中で合規」することが可能になります;AI Verify は ISO/IEC 42001 / G7 広島 AI プロセスと連携しています;CSA は Google、AWS、TRM Labs と協力覚書に署名しています——Google Play Protect の強化された不正行為対策機能は、2025 年 9 月時点でシンガポールで 622,000 台のデバイス上の 278 万件の悪質なアプリのインストールをすでにブロックしています。

全文翻訳

MDDI 英語原文の翻訳 · 翻訳日: 2026-05-02

私の内閣同僚である Goh Pei Ming 氏、

大臣の皆様、閣下各位、

ご来賓の皆様、

同僚および友人の皆様へ:

「シンガポール国際サイバー週間」(SICW)の第2日目へようこそ。本日は、これほど多くの開発者、セキュリティ実務家、および政策立案者が一堂に集う光景が見られ、私たちは非常に喜ばしく思っています。

私たちは、非凡な科学技術の時代を生きています。2つの事象が、目の前で世界を作り替えようとしています。

第1は「エージェント型AI」(agentic AI)です。それは単なる分析と提案にとどまらず、意思決定と行動を行います。

それらは既に、会議の手配、コード作成およびデプロイ、さらには業務運用全体の自動化を支援することができます。

適切に実装されれば、エージェント型AIは非常に望ましい「チームメイト」となる可能性が高いです。人間の能力を拡張し、反復的な作業から我々を解放し、複雑な問題への迅速な対応を可能にするでしょう。

しかし、システムが不具合を起こし、人間が制御を失う場合には、「説明責任」の問題ももたらされます。

第2は「量子コンピューティング」です。

この技術は、「信頼」についての我々の考え方を根本的に変えるでしょう。特に、暗号化とセキュアな通信の領域においてです。

医薬品開発と金融モデリングにおけるその革新的な能力は期待を呼んでいます。しかし、それは既存の暗号を突破する可能性もあり、国家安全保障および商業運用を脅かすかもしれません。

両技術とも巨大な可能性をもたらす一方で、深刻なリスクももたらします。

より重要なことに、両者とも新たな姿勢が必要です。「受動的な規制」から「積極的な準備」へのシフトが求められています。なぜなら、それらの影響は完全には予測不可能だからです。

この転換は私たちの目標となり得ます。しかし、集団的な意志、知恵、そして行動が必要です。これらの技術が「私たちを統治する」前に、「それらを統治する」ために。

国際的視点

良い知らせは、多くの国がすでに答えを求めているということです。

エージェント型AIについては、私たちはすべて同じ基本的な問題に取り組んでいます。自律的に行動できるAIをどのように統治するか、という問題です。

欧州連合と韓国は既に包括的なAI規制を確立しています。しかし、エージェント型AIの自律的な意思決定能力により、「透明性」および「人間による監督」などの重要要件の実装に実務的な課題が生じています。

米国国立標準技術研究所(NIST)は、AIエージェント向けの試験基準を開発しています。規定的なルールではなく。

英国の AI Security Institute はAIエージェントをテストするための「サンドボックスツールキット」を開発しています。しかし、「テストに合格する」ことが良好な行動を保証できるかどうかは不確かです。なぜなら、エージェントは学習と進化を続けているからです。

量子領域においても、ますます大きな可能性が生まれています。

国連は2025年を「国際量子科学技術年」と宣言しています。これは量子変革の可能性に対する国際社会の卓越した合意です。

欧州連合は「Quantum Europe Strategy」を開始しています。科学的リーダーシップを産業力に転換するためです。

韓国は「量子戦略委員会」を設立し、相応する資金を配置しています。日本は2025年を「量子産業化元年」と宣言しています。

希望と恐怖が共存しています。量子能力が悪用され、既存の暗号を突破し、デジタルシステムの基盤を脅かされるのではないかという懸念もあります。

私たちは知りたいのです。「ポスト量子未来」でいかに繁栄するか、機会を活かしつつリスクを管理する方法です。問題は、我々はどれだけ待つことができるか、ということです。

私たちのガバナンス目標

政策立案者として、行動を取る際には「ガバナンス目標」について明確である必要があります。エージェント型AIであれ量子コンピューティングであれ、この時点で3つの目標があると提案します。

まず――私たちの目標は「保障を通じて市民の信頼を構築する」ことでなければなりません――AIエージェントと量子技術の展開されるあらゆるインスタンスを制御する必要はありません。

適切なガバナンスは――たとえ私たちが制御しなくても、リスクを理解し――リスクを体系的に管理するためのツールを構築する――ことから始まります。

システムの大規模展開前に、テスト、検証、および説明責任の実用的なフレームワークを確立する必要があります――展開が始まると、その後リスクを補正することは遅すぎるかもしれません。

第二に――私たちは、フレームワークとテストが実世界のアプリケーションで関連があり堅牢であることを保証する必要があります。これは――適切なガードレールを備えた――「安全な実験空間」を提供することが必要です。

第三に――私たちは「タイムリーな行動」を確保する必要があります。複数の分野で――「行動が遅すぎる」ことの代価が何であるかを既に知っています――デジタル格差、虚偽および誤導的な情報、オンライン上の危害、詐欺。私たちはAIエージェントおよび量子の分野でこの二の舞を踏みたくありません。

シンガポールはすべての答えを持っているふりをしません――しかし私たちはこれらの問題についてどのように考えているか、そして私たちが現在何をしているかを共有したいと考えています。

AIエージェント・ガバナンスに対する私たちのアプローチ

人手不足の国にとって――AIエージェントは大きな可能性を提供します。

私たちはそれらが使用されているのを見ています――公共サービスの提供を強化し、市民のニーズを予測して個別対応サポートを提供するために。

私たちの中小企業は、より自動化された運営と資源最適化から利益を得ることができます。

私たちの国のサイバーセキュリティもより強くなる可能性があります――エージェントが「マシンスピード」で検出、防御、対応するために。GovTechは既に試用中です。

しかし、新しい機能には新しいリスクが伴います。AIエージェントが失敗したときは誰が責任を負いますか。悪用を防ぐにはどうすればいいですか――自動化されたサイバー攻撃または虚偽情報キャンペーン?雇用への体系的な影響、または潜在的な「人類が制御を失う」ことにどのように対処しますか?

まず――私たちはリスクを体系的に識別する必要があります。今年、GovTechは「エージェント・リスク・アンド・キャパビリティ・フレームワーク」(Agentic Risk and Capability Framework)を導入しました――これはAIエージェント・システムのコンポーネントと機能を定義し、リスクをマッピングするために使用されます――そして保障措置を規定します。原則は:私たちが「自律性」を信頼できるようになる前に、リスクがどこにあり、どのように発生するかを最初に理解する必要があります。

第二に――保障を実行可能で測定可能にすることです。

IMDAの「AI Verifyフレームワーク」と「AI Assurance Sandbox」を通じて――私たちは開発者にツールを提供し、システムの堅牢性、透明性、セキュリティをテストできるようにしています。

IMDAはまた「Project Moonshot」を通じてAI Verifyを強化し、生成型AIの独特なリスクをカバーするようにしました――ベンチマークテストとコンテンツ・レッドティーミングを組み合わせて――幻覚と有害なコンテンツ生成などの問題をテストします。

私たちはまたAIエージェント向けにツールとセキュリティフレームワークを改造しています――CSAの『AIシステム保護ガイドラインと関連ガイド』(Guidelines and Companion Guide on Securing AI Systems)に基づいて。

第三に――実際の展開を通じて「学習する」。

GovTech-Google Cloudサンドボックス・イニシアティブを通じて――MDDI傘下の機関は、Googleの最新のエージェント機能をテスト・評価し、リスクを評価し、緩和措置を開発し、学んだことをシンガポール広域のAI実務コミュニティと共有する機会を得ています。

これらのシステムがどのように機能するか――そして時には失敗する方法――を観察することで、「本当に必要なガードレール」が何であるかを学ぶことができます。

第四に――私たちは「リスク・ベースド」のガバナンスを一貫して採用しています。

私たちはガバナンスに「セクター別」のアプローチを採取しています。

このセクター別アプローチは、ガバナンス措置がリスクに比例することを確保することを目的としています。

例えば――生計に影響を与える金融上の決定はエンターテインメント・レコメンデーションよりも多くの精査を受けます。医療診断の検証基準は物流最適化よりも高いです。

すべての規制対象の業界において――私たちは1つの原則に従っています:「自律性が高いほど、必要な保障は強い」。

最も重要なことは――人間が常に最終的な責任者であるということです。

このコーディネートされたアプローチは、包括的なガバナンス・エコシステムを作成することを目的としています――テストフレームワーク、セキュリティ要件、実装ガイダンスが相互に協力できるように。時間の経過とともに――私たちは「AI能力とリスクとともに拡張でき、各層で人間の説明責任を保持する」「ガバナンス・スタック」を構築することを望んでいます。

量子セキュリティに対する私たちのアプローチ

量子の分野では――私たちも具体的な行動を取っています。

昨年、私たちは『国家量子戦略』を公開しました――5年以内に3億シンガポール・ドルを量子研究開発支援に投じることをコミットしました。これらの投資は2000年代初期から築いてきた基礎の上に成り立っています――学界に科学の境界線を押し広げるためのリソースを提供し、業界に商用アプリケーションを開発する能力を提供します。

しかし、我々はリスク管理を行っています。

量子脅威に対する認識は高まっていますが、「量子セキュリティ移行」を実際に開始した組織はほとんどありません。

その理由は、量子開発の不確実性と、具体的なガイダンスの不足にあると考えられます。

CSA は本日、2つのリソースを立ち上げ、公開の意見募集を通じてこの空白を埋めます。

第一に、「量子準備度指数」(Quantum Readiness Index)という自己評価ツールは、組織が暗号への量子脅威に対する現在の準備状況を理解し、「量子安全システム」への移行経路を計画するのに役立ちます。

第二に、「量子安全ハンドブック」(Quantum-Safe Handbook)は、組織(特に重要情報基盤の所有者と政府機関)が「量子安全暗号学」へ移行するためのガイダンスを提供します。このハンドブックは、CSA、GovTech、IMDA が共同開発し、大手テクノロジー企業、サイバーセキュリティコンサルティング企業、専門団体との協力で完成しました。

これらのリソースを MVP「最小限実行可能製品」と考えており、公開フィードバックを通じて継続的に改善される「活きた文書」です。貢献をお待ちしています。一緒に学びましょう。

国際協力

ここで、国際協力という重要なテーマについてお話しします。

本日議論している2つの技術に関しては、根本的な現実があります。

エージェント AI と量子コンピューティングは、いずれも国境を尊重しません。

量子コンピューティングがどこかで突破すれば、すべての場所の暗号に影響します。

1つの国のシステムの脆弱性は、グローバル規模で連鎖的に拡大する可能性があります。

これは、国際協力が「原則」から「実践」へ移行しなければならないことを意味しています。

1つの方法は、「異なるシステム間、異なる国間で相互運用可能なガバナンスフレームワーク」を確保することです。例えば:

シンガポール と NIST の「相互参照」(crosswalk)は、企業が「一度テストして、グローバルに対応する」(test once, comply globally)ことを目指しています。

AI Verify のテストフレームワークは、ISO/IEC 42001 および G7「広島 AI プロセス」原則を含む国際標準と整合しています。

これにより、コンプライアンスの負担が軽減され、同時に厳格な基準が維持されます。これは常に念頭に置く必要がある実務的な考慮事項です。企業は、テストを含むすべてのアクションについて、コストと効果を評価します。

オーストラリア、英国などの国と署名した『デジタル経済協定』(DEA)を通じ、ガバナンス原則を貿易関係に組み込んでいます。2024年に『ASEAN AI ガバナンスと倫理ガイドライン』を発表し、東南アジアの実践を協調させ、2025年にはジェネレーティブ AI をカバーするまで拡張しました。

「エージェント AI の安全」という点について、我々は国際的にも積極的な対策を講じています。

CSA は公開の意見募集を行っており、「エージェント AI の保護」に関する文書を発表する予定です。

この文書は『AI システム保護ガイドラインと付随ガイダンス』の「附録」であり、エージェント AI システムの固有のリスクを特に対象としています。

これはまた招待状でもあり、政府、研究者、産業パートナーに対して「エージェント AI の保護」に関するグローバルリファレンスを共同で形成するよう招待しています。

量子コンピューティングについては、NIST の新「耐量子暗号標準」が、共通の技術基盤を提供しています。

しかし、基準だけでは十分ではありません。

地域および国際的なレベルで協力し、移行に関する提案を策定・調整する必要があります。

これは、ASEAN の同僚がさらに議論することを望んでいる分野であり、我々はそのような対話を促進する方法を検討します。

政府間協力の他に、産業界との実務レベルのパートナーシップを深化させています。

CSA は、Google、AWS、TRM Labs を含む複数の大手テクノロジー企業と協力覚書に署名し、AI 駆動のサイバー脅威インテリジェンス共有を強化し、悪意のある活動に対する共同行動を開始します。

Google とのパートナーシップは具体的な効果を示しています。「Google Play Protect」の「強化された不正検出保護」機能は、2025年9月時点で、シンガポール内の622,000台のデバイスで278万件の悪意のあるアプリインストールをブロックしています。

結論

まとめに入らせていただきます。

エージェント AI 時代は既に到来しています――量子セーフティへの準備の時刻は今です。それらは多くの約束をもたらしています――また多くの未知ももたらしています。

「上昇の最大化、下降の最小化」――これが私たちの共通の利益です。緊迫感と目的意識を持ちながら協働することで、私たちはより速く学び、より大きな成功確率をつかむことができるのです。

再度、SICW へのご参加をありがとうございます――皆様によるより多くの実りのある討論をお祈りしています。

英語原文

MDDI 公式サイト原文 · 取得日: 2026-05-02

My Cabinet colleague, Mr Goh Pei Ming

Fellow Ministers, excellencies,

Distinguished guests,

Colleagues and friends

Welcome to Day 2 of the Singapore International Cyber Week. We are glad to see so many developers, security practitioners, and policymakers gathered here today.

We are living through an extraordinary moment in technology. Two developments are reshaping our world right before our eyes.

The first is agentic AI – systems that do not just analyse and recommend, but decide and take action.

They can already help us schedule meetings, write and deploy code, even automate entire business operations.

Implemented properly, agentic AI will likely be a welcomed teammate that amplifies human abilities, freeing us from repetitive work and enabling faster responses to complex problems.

But there are also questions of accountability when systems malfunction, and humans lose control.

The second is quantum computing.

This technology will fundamentally change how we think about trust, especially in cryptography and secure communications.

While it promises revolutionary capabilities in drug discovery and financial modelling, it could also break current encryption, potentially compromising both national security and business operations.

Both technologies offer tremendous promise. But they also pose serious risks.

More significantly, both demand something new from us: a shift from reactive regulation to proactive preparation when their implications cannot be fully predicted.

This shift can be our aspiration, but it will take collective will, wisdom and action to govern these technologies before they govern us.

INTERNATIONAL SCAN

Fortunately, many countries are already seeking answers.

On agentic AI, we wrestle with the same basic question: how to govern AI that can act autonomously?

The EU and South Korea have established comprehensive AI regulations, but agentic AI's autonomous decision-making capabilities create practical challenges in meeting key requirements like transparency and human oversight.

The US National Institute of Standards and Technology (NIST) is developing testing standards for AI agents rather than prescriptive rules.

The UK's AI Security Institute has developed sandboxing toolkits for testing AI agents, though it is not known if “passing” a test guarantees good behaviour as the agents learn and evolve.

In quantum, there is also growing momentum.

The UN has declared 2025 the International Year of Quantum Science and Technology – an extraordinary international consensus on quantum's transformative potential.

The EU launched its Quantum Europe Strategy to turn scientific leadership into industrial strength.

South Korea established a Quantum Strategy Committee backed by significant funding. Japan declared 2025 the first year of quantum industrialisation.

Along with hope, there is fear that quantum capabilities can be misused to break encryption and threaten the foundation of our digital systems.

We want to know how to thrive in a post-quantum future – both in terms of harnessing the opportunities and managing the risks. The question is: how long can we afford to wait for the answers?

OUR GOVERNANCE OBJECTIVES

As policymakers, we should always strive to be clear about our governance objectives when taking actions. Whether for agentic AI or quantum computing, I suggest that there are three objectives at this juncture.

First, our goal must be to build trust with citizens through assurance, and not necessarily control all the instances where AI agents and quantum technologies are deployed.

Good governance begins with understanding risks even when we do not exercise control, and building the tools to manage the risks systematically.

We need practical frameworks for testing, validation, and accountability before systems are deployed at scale, because it may be too late to address the risks by then.

Second, we must ensure that the frameworks and tests are relevant and robust in real-world applications. This calls for the provision of safe spaces for experimentation, with appropriate guardrails.

Third, we want to ensure timely action. In several areas, we know the costs of not having acted early enough – the digital divide, misinformation, disinformation, online harms, and scams, for example. Let us try not to make the same mistakes with agentic AI and quantum.

Singapore will not pretend to have all the answers. But we would like to share how we are thinking about these issues and what we are doing in response.

OUR APPROACH TO AGENTIC AI GOVERNANCE

For a country with insufficient manpower, agentic AI offers tremendous potential.

We can see them being used to enhance public service delivery, to anticipate citizens’ needs and provide personalised support.

Our SMEs can benefit from more automated operations and resource optimisation.

Our national cybersecurity can be stronger with the use of intelligent agents to detect, defend and respond at machine speed. GovTech is already experimenting.

But every new capability brings new risks. Who is accountable when agentic AI malfunctions? How do we prevent malicious use – automated cyberattacks or misinformation campaigns? How do we manage systemic impacts on jobs or potential loss of human control?

First, we must identify risks systematically. This year, GovTech launched the Agentic Risk and Capability Framework. It defines components and capabilities of agentic AI systems, to map risks, and prescribes safeguards. The principle is that we must understand where and how risks arise before we can trust autonomy.

Second, making assurance practical and measurable.

Through the IMDA’s AI Verify Framework and AI Assurance Sandbox, we give developers open tools to test their systems for robustness, transparency, and safety. systems for robustness, transparency, and safety.

IMDA had also enhanced AI Verify to cover generative AI's unique risks through Project Moonshot, which combines benchmarking and content red-teaming to test for issues like hallucination and harmful content generation.

We are adapting our tools and security frameworks for agentic AI – building on the CSA’s Guidelines and Companion Guide on Securing AI Systems.

Third, learning by doing with real deployment.

Through the GovTech-Google Cloud sandbox initiative, MDDI agencies have a chance to test and evaluate Google’s latest agentic capabilities, assess the risks, develop mitigation measures, and share the lessons learned with the broader community of AI practitioners in Singapore.

By observing how these systems behave – and sometimes fail – we learn what guardrails are truly needed.

Fourth, we are applying risk-based governance consistently.

We take a sector-specific approach to governance.

This sector-specific approach is designed to ensure that governance measures are proportionate to the risks.

For example, financial decisions affecting livelihoods receive more scrutiny compared with entertainment recommendations, and medical diagnoses demand higher validation standards than logistics optimisation.

Across our regulated sectors, we follow the principle that the higher the autonomy, the stronger the assurance needed.

Most importantly, humans remain ultimately responsible.

This coordinated approach aims to create a comprehensive governance ecosystem where testing frameworks, security requirements, and practical implementation guidance work together. Over time, we hope to build a governance stack that scales with AI capability and risk, while maintaining human accountability at every level.

OUR APPROACH TO QUANTUM SAFE

In quantum, we are also taking concrete action.

Last year, we announced the National Quantum Strategy with S$300 million committed over five years to quantum research and development. These investments build on foundations dating back to the early 2000s to give academia resources to push scientific boundaries, and support industry with capabilities to develop commercial applications.

But we are also managing the risks.

While there is growing awareness of the quantum threat, few organisations have embarked on quantum safe migration.

This is likely because of uncertainty over quantum developments and the lack of specific guidance.

CSA will plug this gap by launching two resources for public consultation today.

First, the Quantum Readiness Index is a self-assessment tool that helps organisations understand their current preparedness for quantum threats to encryption, and chart their migration journey towards quantum-safe systems.

Second, the Quantum-Safe Handbook provides guidance for organisations, particularly Critical Information Infrastructure owners and government agencies, to ready themselves for the transition to quantum-safe cryptography. This handbook was jointly developed by CSA, GovTech, and IMDA, in collaboration with leading technology companies, cybersecurity consultancies, and professional associations.

We consider these resources to be MVP – minimum viable products – live documents that get improved through public feedback. And we welcome you to contribute so we can all learn together.

INTERNATIONAL COOPERATION

Let me now turn to the important topic of international cooperation.

There is a fundamental reality about both technologies that we have discussed today.

Neither agentic AI nor quantum computing respects borders.

A breakthrough in quantum computing anywhere affects encryption everywhere.

A vulnerability in one country's systems can cascade globally.

This means international cooperation must turn from principle to practice.

One way is to ensure interoperable governance frameworks that work across different systems and countries. For example:

Singapore’s crosswalk with NIST hopes to enable companies to "test once, comply globally".

AI Verify's testing framework aligns with international standards including ISO/IEC 42001 and the G7's Hiroshima AI Process principles.

This reduces compliance burden while maintaining rigorous standards. It is a practical consideration that we must keep in mind. Companies always evaluate the cost and benefit of any action, including testing.

Through Digital Economy Agreements with countries like Australia and the UK, we also embed governance principles into trade relationships. We published the ASEAN Guide on AI Governance and Ethics in 2024 to harmonise Southeast Asian approaches, with a further expansion in 2025 to cover generative AI.

On agentic AI security specifically, we are taking proactive steps to address the challenges internationally.

CSA is releasing for public consultation a document on securing agentic AI.

This document is an addendum to its Guidelines and Companion Guide on Securing AI Systems, to cover the unique risks of agentic AI systems.

It is also an invitation – to governments, researchers, and industry partners – to help shape a global reference for securing agentic AI.

On quantum computing, the new NIST quantum-resistant cryptographic standards give us a common technical foundation.

But standards alone are insufficient.

We need to work regionally and internationally to develop and coordinate migration advice.

This is an area that my ASEAN colleagues have asked for further discussions on, and we will see how to facilitate.

Besides inter-governmental cooperation, we are deepening practical partnerships with industry.

CSA will be signing memoranda of cooperation with major technology companies, including Google, AWS, and TRM Labs, to enhance AI-driven intelligence sharing on cyber threats and enable joint operations against malicious activities.

Our partnership with Google demonstrates the tangible benefits – the Enhanced Fraud Protection feature within Google Play Protect has blocked 2.78 million malicious app installations across 622,000 devices in Singapore as of September 2025.

CONCLUSION

Let me conclude.

The age of agentic AI is upon us and the time for quantum-safe preparation is now. They bring much promise but also many unknowns.

We have a collective interest in maximising the upsides while minimising the downsides. By working together with a sense of urgency and purpose, we will learn faster and better our chances of success.

On that note, I thank you once again for being part of SICW and wish you many more fruitful discussions.