MDDI スピーチ · 2026-02-20
Josephine Teo大臣の「エージェント影響の監視:グローバルなセーフで信頼できるAI保障のギャップを埋める」フォーラムでの基調講演
要点
- • Agentic AIは去年のパリAI Action Summitから今日まで、ようやく本当に離陸しました。その「自律性」は価値であると同時にリスクの源です――一度制御を失うと、影響は複雑で予測が難しいことがよくあります。
- • シンガポールの姿勢:「受動的な規制」から「プロアクティブな準備」へ。政府は後発者ではなく先行者になるべき――例えば Google との協力による AI エージェント サンドボックスは、政府が「自分たちで試す」やり方です。
- • シンガポールは AI エージェント向けの『Model Governance Framework』を推出し、「生きた文書」として継続的にフィードバックを収集しています。
- • 「保障エコシステム」(assurance ecosystem)は信頼を構築するための鍵であり、少なくとも3つの要素が必要です:①テスト(出力だけでなく、推論とオーケストレーションも確認);②標準;③第三者保障提供者(独立監査、テスト者)――後者は内部能力を補完し、盲点を見つけます。
- • Josephine から企業へのメッセージ:「高いセキュリティ保証」を提供できる企業は競争相手と区別される――それを不本意なコンプライアンス負担ではなく、戦略的競争優位として見なしてください。
全文翻訳
MDDI 英語原文の翻訳 · 翻訳日: 2026-05-02
「Partnership on AI」からのご招待をありがとうございます。
このシリーズのサミットが最初にBletchley Parkで立ち上げられた時、AIエージェント(agents)はまだ主役ではありませんでした――12ヶ月前にパリで「AI Action Summit」を開催した時でさえ、ほぼ対話に入っていませんでした。
当時、皆の関心はすべてDeepSeekと、それが示してくれたもの――中国からの能力がどのレベルに現れているか――に向けられていました。しかし今日、agentic システムは既に離陸し、ますます多く使用されており、このテーマにどう対応するかをより良く理解する必要があります。
Agentic AIが戦略的に配置される時、「どのように仕事を委譲し調整するか」について、確かに変革的な可能性を提供しています。エージェントは無価の「チームメート」として、私たちが皆より多く望んでいることを解き放つことができます――生産性向上と時間節約。
しかし、これもお伝えする必要があります:エージェントを私たちにとって有用にする本質は「自律性」です。この自律性はまた新しいリスクをもたらします。システムが失敗し、人間の監督が不在または大幅に弱まっている場合、害をもたらす可能性は大きくなります。その影響は複雑で、完全に予測できない場合があります。
私と同僚たちの考えは――私たちは姿勢上の転換をする必要があります:「reactive regulation」(受動的規制)への依存から、別の姿勢へ――「proactive preparation」(主動的準備)。
シンガポールでは、これがまさに私たちずっと試みている事柄です。私たちはagentic AI時代の新しいリスクを主動的に管理しようとしています。
これは政府自身から始める必要があると考えます――政府はagentic AIの利用で先導者たる必要があります、後発者ではなく。これらのソリューションがどのようにして公共サービスの提供を改善できるかを見るために、テストする必要があります。同時により多くの制御を確立します。
政府は高リスク環境です。なぜなら、市民との接点が非常に敏感だからです。政府が市民と対話する際に重大な誤りを犯したいとは思いません――健康、社会保障、福祉に関する不正確な情報を彼らに告げ、これらの誤りが市民に知らせられるだけでなく、それに基づいて行動を取られるときです。「私たちが何をしているかを明確に確保すること」のこの要件は非常に高いです。そして、私たちは業界と一緒にこれを行うことを考えています。
例えば、Googleとシンガポール政府の間にはAgentic AIサンドボックスがあります。これは「自分たち自身が最初に自分たちのツールを試す」方法の一つです――その効果は良いでしょうか?それが私たちに重大な害をもたらすでしょうか?もし私たち自身がこれができなければ、agentic AIを管理しようとすることに信頼性がありません。しかし、その影響が完全に明らかになるのを待つこともできません。
同時に、私の同僚たちはagentic AIのための「Model Governance Framework」をまとめました――企業に実践的な支援を提供し、責任を持って自律的なエージェントを配置しリスクを軽減できるようにします。これは完全な解決策ではないことを私たちは知っているので、このドキュメントは「ライブドキュメント」(live document)である必要があります。私たちはフィードバックを非常に歓迎し、それによって企業への指導を継続的に改善します。
この事柄の意義と目的は何ですか?最終的に、agentic AIシステムの使用に対する信頼を構築することです。多くのレベルで、この信頼は提示され示されなければなりません――組織の取締役会、顧客、その他のステークホルダーに。「リスクが良好に管理されている」ことをどのように示しますか?
これが「保証エコシステム」(assurance ecosystem)の出番です。これは中長期的に信頼を構築するために絶対に必要な部分です、agentic AIシステムがより容易に広く採用され、より容易に取得されるための基盤です。
また、このことを考えている企業に言いたいのは――これらのエージェントシステムを信頼したい場合、「安全性」はこの側面で軽視されることはできないということです。
私ははっきり言うことができます――「セキュリティ保証」で高度な保証を提供できる企業は、競争相手と差別化されるでしょう;これはその製品とサービスに対する強い関心に変わる可能性が高いです。
それを不本意な遵守の対象として扱う代わりに、それを戦略的競争優位として見なすことができます――この考え方は私たちに信頼を持ってそれを前面に押し出すことを与えます。
しかし、問題は:このことについて、私たちに先例は全くないのか?答えはいいえです。
航空と医療分野では、乗客と患者に保証を提供するための多くの対策が既に存在しています――搭乗する時、通常、到着することが期待されます;病院に行く時、まだよく理解されていない病気を除いて、通常、治癒されることが期待されます。
これらのシステムへの信頼は一定期間に蓄積され、何らかの形の「保証」の存在なしにはありません。問題は――AI、特にagentic AIについて、「保証エコシステム」を構成する部件は何であるべきか?どのような組み合わせが十分に堅牢ですか?
私たちは少なくとも3つのコンポーネントがあると考えています。
第一に、テストが必要です。システムの技術的評価を何らかの方法で行う必要があり、堅牢性、信頼性、安全性を確保します。この空間にはまだ多くの作業があります――テスト方法論の開発、テストデータセットの構築、およびagentic システムのテストの確保――これらのシステムは複数のエージェントを関与させるため、はるかに複雑です。
例えば、「出力」だけを見るのではなく、「中間ステップ」も見なければなりません――推理がどのように行われているか、agentic システムではどのような「オーケストレーション」が構築されているか。
第二に、最終的に私たちは標準が必要です。「何が十分に良いか」について単に異なる意見を述べることはできません。また、ユーザーに保証する必要があります――安全性と信頼性の期待に達していることを。このセクションはまだ非常に初期段階です。
第三に、私たちはこのエコシステムは「第三者保証提供者」なしにはいられないと考えています。「自分のagentic AIシステムが安全だと主張する」ことと「他の人にそれの安全性を証明させる」ことは別のことです。これらの役割は技術テスト者、監査人です――彼らは独立性を提供し、内部能力を補い、盲点を識別するのを支援します。また、このセクションの才能を拡大する必要があります。
私はこのような一文で演説を締めくくります――シンガポールはこれらのコンポーネントを積極的に構築しています。
私たちはパートナーと同僚との対話を歓迎します。なぜなら、私たちはこのことが一国では独力では完成できないことを知っているからです。また、3つの分論坛での議論を期待しています――agentic AIの「保証」テーマでどのように意味のある協力ができるか。
再度、皆さんに感謝します。
英語原文
MDDI 公式サイト原文 · 取得日: 2026-05-02
Thank you, Partnership on AI, for the invitation.
When this series of summits first began in Bletchley Park, AI agents were not a thing. Nobody was talking about them, even just 12 months ago when we had the AI Action Summit in Paris, it had barely crept into the conversation.
At the time, the preoccupation was all around DeepSeek, and what it told us about the capabilities that are emerging out of China. But today, agentic systems have taken off. They are increasingly being used, and we need to have a better grasp on how to deal with this issue.
Agentic AI certainly offers transformative possibilities in how we delegate and orchestrate work when deployed strategically. Agents function as invaluable teammates, unlocking productivity gains and time savings, which we all want more of.
However, I should also add that the very nature of how agents can be helpful to us, is autonomy. This autonomy also introduces new risk. The potential for harm increases when systems malfunction and human oversight is no longer present or at least diminished to a very large extent. The implications may be complex and not fully predictable.
The way my colleagues and I have been thinking about this is that there needs to be a shift, in terms of how we might want to rely on reactive regulation, to a different kind of stance, which is proactive preparation.
And in Singapore, that's what we've been trying to do. We have tried to be proactive about governing the new risks in the era of agentic AI.
I think it starts with the Government itself being a leader and not a laggard in using agentic AI. We need to test it. We need to look at how the solutions can enhance public service delivery but also put in place more controls.
Government is high-risk because the touch point with citizens is very sensitive. No government wants to make serious mistakes when it interacts with its citizens – telling them things about their health, social security, or things to do with their benefits that are not accurate, and having these mistakes not just told to citizens but acted upon. This need to ensure that we know what we're doing is a very high one, and the way we are also thinking about it is to work with the industry.
For example, between Google and the Singapore Government, we have a sandbox on agentic AI. It's one of the ways in which we think we can, in a way, try our own dog food. Try it to see if it tastes alright? Does it hurt us in a very significant way? Because if we were not able to do so, I don't think we have a lot of credibility in terms of how we want to govern agentic AI. But we can't wait for the dog food to materialise its consequences for ourselves.
In the meantime, my colleagues have put together a Model Governance Framework for agentic AI. It is meant to provide practical support to enterprises so that they can also deploy autonomous agents responsibly and mitigate the risk. We know that this is not a complete solution, and this document that we put out, has to be a live document. We very much encourage feedback as a way for us to keep improving the guidance to enterprises.
As we do this work, what is the meaning and purpose behind it? Ultimately, it is to build confidence in the use of agentic AI systems. At many levels, this confidence has to be presented and demonstrated to boards of organisations, customers, and other stakeholders. How do we demonstrate that the risks have been managed well?
That is where the assurance ecosystem comes in. It is an absolutely essential part of building trust over the medium to longer term, so that there is a foundation upon which agentic AI systems can be made more readily adopted and available.
I should also say that for companies that are thinking about it, if we are to trust these agentic systems, the safety aspects should not be downplayed.
I would venture to say that a company that is able to give a high assurance on safety will find itself being differentiated from its competitors, and this is more likely to translate into stronger interest in its products and services.
Rather than think of it as something that you are unhappy to comply with, think of it as a strategic competitive advantage, and the way that will give us the confidence to put it forward.
The question, however, is: are we completely without experience in this regard? The answer is no.
In aviation and healthcare, there are a lot of measures being put in place to give assurance to passengers that when we board a plane, we usually expect to arrive, or when we visit the hospital, we generally expect to be treated, except for disease conditions that are not yet well understood.
The trust in these systems has to be built over time, and it doesn't come without some assurance being put in place. The question is, for AI, and specifically agentic AI, what would be the components? What leads to an assurance ecosystem that would be robust enough?
We think that there are at least three components.
The first is that there must be testing. We need some way of making sure that there are technical assessments of the system to make sure that the systems are robust, reliable and safe. A lot more work needs to be done in this space – developing the testing methodology, building the testing data sets, and also making sure that the testing of agentic systems takes into account that these systems are going to be much more complex because they involve multiple agents.
For example, it's not just the output, but the in-between steps – how the reasoning takes place and what is the orchestration that is being built into the agentic systems.
The second is that eventually we will need standards. We cannot just define what is good enough. We also need to assure the users that it has met expectations for safety and reliability, and so these are still very early days.
Third, we think that this ecosystem cannot do without third party assurance providers. It's one thing to claim that your agentic AI system is safe, but another to have someone attest to the safety of it. So these could be technical testers, auditors, and they provide independence, augment in-house capabilities, and also help to identify the blind spots. And it's necessary for us to strengthen this pool as well.
I want to conclude my remarks by saying that Singapore is actively building these components.
We welcome conversations with partners and colleagues, because we know that we cannot do this alone. We look forward to discussions in the three panels on how we can meaningfully collaborate on assurance for agentic AI.
Thank you very much once again.