MDDI 연설문 · 2025-10-22

양리명 부장관의 AI 고급급 소위원회 회의 개막 인사말

Josephine Teo · 디지털 발전 및 뉴스 부장관 · AI 고급급 소위원회 회의

요점

  • 두 가지 기술이 「동시에」 세계를 재구성하고 있습니다——agentic AI + 양자 컴퓨팅. 둘 다 우리가 「수동적 규제」에서 「주도적 준비」로 전환할 것을 요구합니다.
  • Agentic AI의 거버넌스 목표 3가지: ①「보장」(assurance)으로 신뢰를 구축하되, 각 배포를 통제하지 않음; ②프레임워크와 테스트는 실제 시나리오에서 관련성 있고 견고해야 함(안전한 실험 공간 제공); ③시의적절한 행동——디지털 격차, 허위 정보, 사이버 사기의 전철을 밟지 않아야 합니다.
  • 싱가포르 Agentic AI 도구 스택: GovTech의 「Agentic Risk and Capability Framework」, IMDA의 AI Verify + Project Moonshot(red-teaming + 벤치마킹) + AI Assurance Sandbox + GovTech-Google Cloud 샌드박스. 원칙——「자율성이 높을수록 보장이 강합니다」.
  • 양자 보안: CSA가 공개 협의 중인 두 가지 새 도구——『Quantum Readiness Index』(자체 평가 도구) + 『Quantum-Safe Handbook』; 모두 MVP와 활문서로 간주됩니다.
  • 국제 협력: AI와 양자 모두 국경을 존중하지 않습니다. 싱가포르—NIST 상호운용성으로 기업들이 「한 번 테스트하면 전 세계 준수」할 수 있게 함; AI Verify는 ISO/IEC 42001 / G7 히로시마 AI 프로세스와 정렬됩니다; CSA는 Google, AWS, TRM Labs와 협력 양해각서를 체결——Google Play Protect의 강화된 사기 방지 기능은 2025년 9월 기준 싱가포르에서 622,000대 기기상의 278만 건의 악성 앱 설치를 차단했습니다.

전체 번역

MDDI 영어 원문의 번역 · 번역일: 2026-05-02

내 내각 동료 Goh Pei Ming 씨,

존경하는 부장님들, 각하님들,

존경하는 귀빈 여러분,

존경하는 동료 여러분과 친구 여러분:

「싱가포르국제사이버주간」(SICW) 둘째 날에 여러분을 환영합니다. 오늘 이렇게 많은 개발자, 보안 실무자 그리고 정책 입안자들이 함께 모인 모습을 보니 매우 기쁩니다.

저희는 특별한 기술의 시대를 살고 있습니다. 두 가지 일이 우리 눈앞에서 세계를 다시 쓰고 있습니다.

첫째는 「에이전틱 AI」(agentic AI)입니다. 이것은 단순히 분석하고 제안하는 것이 아니라 의사결정과 행동도 수행합니다.

이들은 이미 우리의 회의 일정을 잡아주고, 코드를 작성 및 배포하며, 전체 업무 프로세스를 자동화할 수 있습니다.

올바르게 구현된다면, 에이전틱 AI는 반가운 「팀 동료」가 될 수 있습니다. 인간의 능력을 확장하고, 반복적 작업에서 해방시키며, 복잡한 문제에 더 빠르게 대응하게 해줍니다.

하지만 시스템에 오류가 발생하고 인간이 통제력을 잃을 때, 「책임」의 문제가 생깁니다.

둘째는 「양자컴퓨팅」입니다.

이 기술은 「신뢰」에 대한 우리의 생각을 근본적으로 바꿀 것입니다. 특히 암호화와 안전한 통신 분야에서 그럴 것입니다.

의약품 발견과 금융 모델링에서의 혁명적 능력은 큰 기대를 모으고 있습니다. 하지만 기존 암호화를 뚫을 수도 있으며, 국가 안보와 상업적 운영을 위협할 수 있습니다.

두 기술 모두 거대한 가능성을 제공하는 동시에 심각한 위험도 안겨줍니다.

더 중요한 것은, 두 기술 모두 우리에게 새로운 자세를 요구합니다. 「소극적 규제」에서 「능동적 준비」로의 전환입니다. 그 이유는 이들 기술의 영향을 완전히 예측할 수 없기 때문입니다.

이러한 전환은 우리의 열망이 될 수 있습니다. 그러나 집단의 의지, 지혜 그리고 행동이 필요합니다. 이 기술들이 「우리를 지배」하기 전에 우리가 「그들을 지배」할 수 있도록 말입니다.

국제 전망

좋은 소식은 많은 국가들이 이미 해답을 찾기 위해 노력하고 있다는 것입니다.

에이전틱 AI에 있어서, 우리는 모두 같은 근본적인 질문을 놓고 씨름하고 있습니다. 자율적으로 행동할 수 있는 AI를 어떻게 관리할 것인가입니다.

EU와 한국은 포괄적인 AI 규제를 이미 수립했습니다. 그러나 에이전틱 AI의 자율적 의사결정 능력은 「투명성, 인간 감시」 등 핵심 요구사항의 실무적 이행에 실질적 어려움을 초래합니다.

미국 국가표준기술원(NIST)은 AI 에이전트를 위한 시험 표준을 개발 중입니다. 규정적 규칙이 아닌 시험 기준 말입니다.

영국의 AI Security Institute는 AI 에이전트를 시험하기 위한 「샌드박스 툴킷」을 개발했습니다. 그러나 「시험 통과」가 바람직한 행동을 보장하는지는 아직 불명확합니다. 왜냐하면 에이전트는 계속 학습하고 진화하기 때문입니다.

양자 분야에서도 점점 더 큰 추진력이 있습니다.

유엔은 2025년을 「국제량자과학기술의해」로 선포했습니다. 이는 양자 변혁의 잠재력에 대한 국제사회의 놀라운 합의입니다.

EU는 「Quantum Europe Strategy」를 시작했습니다. 과학적 리더십을 산업적 우위로 전환하려는 것입니다.

한국은 「양자전략위원회」를 설립하고 상당한 자금을 배치했습니다. 일본은 2025년을 「양자산업화원년」으로 선포했습니다.

희망과 우려가 공존합니다. 사람들은 또한 양자 역량이 남용되어 암호화를 뚫고 우리 디지털 시스템의 기초를 위협할 수 있다고 걱정합니다.

우리는 궁금합니다. 「포스트-양자시대」에서 어떻게 번영할 것인가 말입니다. 기회를 활용하면서 동시에 위험을 관리하면서요. 질문은, 우리는 얼마나 오래 기다릴 수 있는가입니다.

우리의 거버넌스 목표

정책 입안자로서, 행동을 취할 때 「거버넌스 목표」를 명확히 해야 합니다. 에이전틱 AI든 양자컴퓨팅이든, 이 시점에서 3가지 목표가 있다고 제안합니다.

첫째——우리의 목표는 반드시 「보장을 통해 시민 신뢰를 구축하는 것」이어야 합니다——AI 지능형 에이전트와 양자 기술이 배포되는 모든 사례를 꼭 통제해야 한다는 것이 아닙니다.

양호한 거버넌스는 이렇게 시작합니다——우리가 통제하지 않더라도 위험을 이해해야 하고——위험을 체계적으로 관리할 도구를 구축해야 합니다.

우리는 시스템이 대규모로 배포되기 전에 이미 테스트, 검증 및 책임성의 실행 프레임워크를 구축해야 합니다——배포가 진행된 후에 위험을 완화하려고 하면 이미 늦을 수 있습니다.

둘째——우리는 프레임워크와 테스트가 실제 응용에서 관련성 있고 견고한지를 확보해야 합니다. 이는——적절한 보호장치를 갖춘——「안전 실험 공간」의 제공을 요구합니다.

셋째——우리는 「적시에 행동」을 보장해야 합니다. 여러 분야에서——우리는 이미 「행동이 너무 늦었을」 때의 대가가 무엇인지 알고 있습니다——디지털 격차, 허위 및 오도 정보, 온라인 피해, 사기. 우리는 지능형 에이전트 AI와 양자에 대해 같은 과오를 되풀이하지 않도록 최선을 다합니다.

싱가포르는 모든 답을 가지고 있다고 가장하지 않습니다——하지만 우리는 이러한 문제들을 어떻게 생각하는지, 그리고 우리가 하고 있는 일을 공유하고 싶습니다.

우리의 지능형 에이전트 AI 거버넌스 접근법

인력이 부족한 국가라는 점에서——지능형 에이전트 AI는 거대한 잠재력을 제공합니다.

우리는 그것들이 다음과 같이 사용되는 것을 봅니다——공공 서비스 제공을 강화하고, 시민의 필요를 예측하며 개인화된 지원을 제공합니다.

우리의 중소기업은 더욱 자동화된 운영, 자원 최적화로부터 혜택을 받을 수 있습니다.

우리의 국가 사이버보안도 더욱 강화될 수 있습니다——지능형 에이전트가 「기계 속도」로 탐지, 방어, 대응합니다. GovTech는 이미 시범 운영 중입니다.

하지만 모든 새로운 능력은 새로운 위험을 가져옵니다. 지능형 에이전트 AI가 오류를 범했을 때 누가 책임을 집니까? 우리는 악의적 사용을 어떻게 방지합니까——자동화된 사이버 공격 또는 허위 정보 캠페인? 우리는 고용에 대한 체계적인 영향, 또는 잠재적인 「인류가 통제력을 잃는」 상황을 어떻게 관리합니까?

첫째——우리는 체계적으로 위험을 식별해야 합니다. 올해 GovTech는 「지능형 에이전트 위험 및 역량 프레임워크」(Agentic Risk and Capability Framework)를 도입했습니다——이는 지능형 에이전트 AI 시스템의 구성 요소와 능력을 정의하며 위험을 매핑하는 데 사용됩니다——그리고 보호 조치를 규정합니다. 원칙은: 우리가 「자율성」을 신뢰할 수 있기 전에 먼저 위험이 어디서 어떻게 나타나는지 이해해야 합니다.

둘째——보호 조치를 운영 가능하고 측정 가능하게 해야 합니다.

IMDA의 「AI Verify 프레임워크」와 「AI Assurance Sandbox」를 통해——우리는 개발자에게 도구를 개방하여 시스템의 견고성, 투명성 및 보안을 테스트합니다.

IMDA는 또한 「Project Moonshot」을 통해 AI Verify를 강화했으며 생성형 AI의 고유한 위험을 포함하도록 확대했습니다——벤치마크 테스트와 콘텐츠 레드팀을 결합합니다——환각 및 해로운 콘텐츠 생성 등의 문제를 테스트합니다.

우리는 또한 지능형 에이전트 AI를 위해 도구 및 보안 프레임워크를 개조하고 있습니다——CSA의 《AI 시스템 보호 지침 및 동반 가이드》(Guidelines and Companion Guide on Securing AI Systems)를 기반으로 합니다.

셋째——실제 배포를 통해 「실행하며 배우기」를 실천합니다.

GovTech-Google Cloud 샌드박스 이니셔티브를 통해——MDDI 산하 기관은 Google의 최신 지능형 에이전트 능력을 테스트 및 평가하고, 위험을 평가하며, 완화 조치를 개발하고, 학습한 내용을 싱가포르의 더 넓은 AI 실무 커뮤니티와 공유할 기회를 얻습니다.

이러한 시스템이 어떻게 작동하는지——그리고 때로 어떻게 실패하는지를 관찰함으로써——우리는 「실제로 필요한 보호장치」가 무엇인지 배울 수 있습니다.

넷째——우리는 일관되게 「위험 기반」의 거버넌스를 채택합니다.

우리는 거버넌스에 대해 「업계별」의 접근법을 채택합니다.

이러한 업계별 접근법은 거버넌스 조치와 위험이 비례함을 확보하기 위해 고안되었습니다.

예를 들어——생계에 영향을 미치는 금융 결정은 엔터테인먼트 추천보다 더 많은 검토를 받습니다; 의료 진단의 검증 기준은 물류 최적화보다 더 높습니다.

모든 규제 대상 산업에서——우리는 한 가지 원칙을 따릅니다: 「자율성이 높을수록 필요한 보호 조치가 더 강해야 합니다」.

가장 중요한 것은——인간이 항상 최종 책임을 진다는 점입니다.

이러한 협력적 접근법은 포괄적인 거버넌스 생태계를 구축하기 위해 고안되었습니다——테스트 프레임워크, 보안 요구 사항, 배포 지침이 서로 협력할 수 있도록 합니다. 시간이 지남에 따라——우리는 『AI 능력과 위험에 따라 확장할 수 있지만 각 계층에서 인간의 책임을 유지하는』 「거버넌스 스택」을 구축하기를 원합니다.

우리의 양자 보안 접근법

양자 측면에서——우리도 구체적인 조치를 취하고 있습니다.

지난해 우리는 《국가 양자 전략》을 공표했습니다——5년 내 3억 싱가포르달러를 양자 연구 개발을 지원하기 위해 투입하기로 약속했습니다. 이러한 투자는 2000년대 초 이후로 마련된 기초 위에 구축되었습니다——학계에 과학의 경계를 밀어붙이기 위한 자원을 제공하고, 업계에 상업적 응용을 개발하는 능력을 부여합니다.

하지만 우리도 위험을 관리하고 있습니다.

양자 위협에 대한 인식이 높아지고 있지만, 실제로 「양자 안전 전환」을 시작한 조직은 많지 않습니다.

그 이유는 양자 개발의 불확실성과 구체적인 지침의 부재 때문일 수 있습니다.

CSA는 오늘 공개 의견 수렴을 위해 두 가지 자료를 출시함으로써 이 공백을 채울 것입니다.

첫째, 「양자 준비도 지수」(Quantum Readiness Index)는 자가평가 도구로서, 조직이 암호화 양자 위협에 대한 현재의 준비도를 이해하고 「양자 안전 시스템」으로의 전환 경로를 계획하는 데 도움을 줍니다.

둘째, 「양자 안전 핸드북」(Quantum-Safe Handbook)은 조직, 특히 중요 정보 기반시설 보유자와 정부 기관을 위해 「양자 안전 암호화」로의 전환에 대한 지침을 제공합니다. 이 핸드북은 CSA, GovTech, IMDA가 공동으로 개발했으며, 주요 기술 회사, 네트워크 보안 컨설팅 회사, 전문 협회와 협력하여 완성했습니다.

우리는 이 자료를 MVP, 즉 「최소 기능 제품」으로 보며, 공개 피드백을 통해 지속적으로 개선될 「살아있는 문서」입니다. 모든 분의 기여를 환영하며, 함께 학습해 봅시다.

국제 협력

이제 국제 협력이라는 중요한 주제에 대해 이야기하겠습니다.

우리가 오늘 논의하는 두 가지 기술에 대해, 근본적인 현실이 하나 있습니다:

에이전트 AI와 양자컴퓨팅은 국경을 존중하지 않습니다.

어디에서든 양자컴퓨팅의 돌파구는 모든 곳의 암호화에 영향을 미칩니다.

한 국가 시스템의 취약점은 전 세계 차원에서 연쇄적으로 확대될 수 있습니다.

이는 국제 협력이 「원칙」에서 「실천」으로 나아가야 함을 의미합니다.

한 가지 방법은 「서로 다른 시스템, 서로 다른 국가 간 상호운용 가능한 거버넌스 프레임워크」를 보장하는 것입니다. 예를 들어:

싱가포르와 NIST의 「상호운용 대조」(crosswalk)는 기업이 「한 번 테스트하고 전 세계 준수」(test once, comply globally)할 수 있기를 바랍니다.

AI Verify의 테스트 프레임워크는 ISO/IEC 42001 및 G7 「히로시마 AI 프로세스」 원칙을 포함한 국제 표준에 정렬됩니다.

이는 준수 부담을 줄이면서도 엄격한 표준을 유지합니다. 이는 우리가 항상 기억해야 할 실무적 고려사항입니다. 기업은 모든 행동(테스트 포함)에 대해 비용과 이익을 평가할 것입니다.

호주, 영국 등 국가와 체결한 「디지털 경제협정」(DEA)을 통해 우리는 거버넌스 원칙을 무역 관계에 내장했습니다. 우리는 2024년 「ASEAN AI 거버넌스 및 윤리 지침」을 발표했으며, 동남아시아의 접근 방식을 조율하기 위해 2025년에는 생성형 AI를 포함하도록 확대했습니다.

「에이전트 AI 보안」 문제에서 우리도 국제적으로 선제적인 조치를 취하고 있습니다.

CSA는 공개 의견 수렴을 진행 중이며, 「에이전트 AI 보호」에 관한 문서를 발표하고 있습니다.

이 문서는 「AI 시스템 보호 지침 및 지원 지침」의 「부록」으로, 에이전트 AI 시스템의 독특한 위험을 특별히 다룹니다.

이는 또한 정부, 연구자, 산업 파트너를 초대하는 초대장으로, 「에이전트 AI 보호」의 글로벌 참고 자료를 함께 구축하는 것입니다.

양자컴퓨팅에서 NIST의 새로운 「양자 내성 암호화 표준」은 우리에게 공통의 기술 기초를 제공합니다.

하지만 표준만으로는 부족합니다.

우리는 지역 및 국제적 차원에서 협력해야 하며, 마이그레이션 권고사항을 수립하고 조율해야 합니다.

이는 제 ASEAN 동료들이 더욱 논의하고 싶은 영역이며, 우리는 이러한 대화를 촉진하는 방법을 연구할 것입니다.

정부 간 협력 외에도 우리는 산업계와의 실무 차원의 파트너십을 심화하고 있습니다.

CSA는 Google, AWS, TRM Labs를 포함한 여러 주요 기술 회사와 협력 양해각서를 체결하여 AI 기반 사이버 위협 정보 공유를 강화하고 악의적 활동에 대한 연합 행동을 시작할 것입니다.

구글과의 파트너십은 실질적인 이점을 보여줍니다. 「Google Play Protect」의 「강화된 사기 방지 보호」 기능은 2025년 9월 기준으로 싱가포르의 622,000대 기기에서 278만 건의 악의적 앱 설치를 차단했습니다.

맺음말

마무리하겠습니다.

지능형 에이전트 시대가 도래했습니다——양자 안전 준비의 시간은 지금입니다. 이들은 많은 약속을 가져옵니다——또한 많은 미지수를 가져옵니다.

「상향을 극대화하고 하향을 최소화한다」——이것이 우리의 공동 이익입니다. 긴박감과 목적감을 가지고 함께 협력할 때——우리는 더 빠르게 배우고 더 큰 성공 확률을 잡을 수 있습니다.

SICW에 참석해주신 여러분께 다시 한번 감사드립니다——더 많은 성과 있는 논의를 나누시기를 바랍니다.

영어 원문

MDDI 공식 웹사이트 원문 · 수집일: 2026-05-02

My Cabinet colleague, Mr Goh Pei Ming

Fellow Ministers, excellencies,

Distinguished guests,

Colleagues and friends

Welcome to Day 2 of the Singapore International Cyber Week. We are glad to see so many developers, security practitioners, and policymakers gathered here today.

We are living through an extraordinary moment in technology. Two developments are reshaping our world right before our eyes.

The first is agentic AI – systems that do not just analyse and recommend, but decide and take action.

They can already help us schedule meetings, write and deploy code, even automate entire business operations.

Implemented properly, agentic AI will likely be a welcomed teammate that amplifies human abilities, freeing us from repetitive work and enabling faster responses to complex problems.

But there are also questions of accountability when systems malfunction, and humans lose control.

The second is quantum computing.

This technology will fundamentally change how we think about trust, especially in cryptography and secure communications.

While it promises revolutionary capabilities in drug discovery and financial modelling, it could also break current encryption, potentially compromising both national security and business operations.

Both technologies offer tremendous promise. But they also pose serious risks.

More significantly, both demand something new from us: a shift from reactive regulation to proactive preparation when their implications cannot be fully predicted.

This shift can be our aspiration, but it will take collective will, wisdom and action to govern these technologies before they govern us.

INTERNATIONAL SCAN

Fortunately, many countries are already seeking answers.

On agentic AI, we wrestle with the same basic question: how to govern AI that can act autonomously?

The EU and South Korea have established comprehensive AI regulations, but agentic AI's autonomous decision-making capabilities create practical challenges in meeting key requirements like transparency and human oversight.

The US National Institute of Standards and Technology (NIST) is developing testing standards for AI agents rather than prescriptive rules.

The UK's AI Security Institute has developed sandboxing toolkits for testing AI agents, though it is not known if “passing” a test guarantees good behaviour as the agents learn and evolve.

In quantum, there is also growing momentum.

The UN has declared 2025 the International Year of Quantum Science and Technology – an extraordinary international consensus on quantum's transformative potential.

The EU launched its Quantum Europe Strategy to turn scientific leadership into industrial strength.

South Korea established a Quantum Strategy Committee backed by significant funding. Japan declared 2025 the first year of quantum industrialisation.

Along with hope, there is fear that quantum capabilities can be misused to break encryption and threaten the foundation of our digital systems.

We want to know how to thrive in a post-quantum future – both in terms of harnessing the opportunities and managing the risks. The question is: how long can we afford to wait for the answers?

OUR GOVERNANCE OBJECTIVES

As policymakers, we should always strive to be clear about our governance objectives when taking actions. Whether for agentic AI or quantum computing, I suggest that there are three objectives at this juncture.

First, our goal must be to build trust with citizens through assurance, and not necessarily control all the instances where AI agents and quantum technologies are deployed.

Good governance begins with understanding risks even when we do not exercise control, and building the tools to manage the risks systematically.

We need practical frameworks for testing, validation, and accountability before systems are deployed at scale, because it may be too late to address the risks by then.

Second, we must ensure that the frameworks and tests are relevant and robust in real-world applications. This calls for the provision of safe spaces for experimentation, with appropriate guardrails.

Third, we want to ensure timely action. In several areas, we know the costs of not having acted early enough – the digital divide, misinformation, disinformation, online harms, and scams, for example. Let us try not to make the same mistakes with agentic AI and quantum.

Singapore will not pretend to have all the answers. But we would like to share how we are thinking about these issues and what we are doing in response.

OUR APPROACH TO AGENTIC AI GOVERNANCE

For a country with insufficient manpower, agentic AI offers tremendous potential.

We can see them being used to enhance public service delivery, to anticipate citizens’ needs and provide personalised support.

Our SMEs can benefit from more automated operations and resource optimisation.

Our national cybersecurity can be stronger with the use of intelligent agents to detect, defend and respond at machine speed. GovTech is already experimenting.

But every new capability brings new risks. Who is accountable when agentic AI malfunctions? How do we prevent malicious use – automated cyberattacks or misinformation campaigns? How do we manage systemic impacts on jobs or potential loss of human control?

First, we must identify risks systematically. This year, GovTech launched the Agentic Risk and Capability Framework. It defines components and capabilities of agentic AI systems, to map risks, and prescribes safeguards. The principle is that we must understand where and how risks arise before we can trust autonomy.

Second, making assurance practical and measurable.

Through the IMDA’s AI Verify Framework and AI Assurance Sandbox, we give developers open tools to test their systems for robustness, transparency, and safety. systems for robustness, transparency, and safety.

IMDA had also enhanced AI Verify to cover generative AI's unique risks through Project Moonshot, which combines benchmarking and content red-teaming to test for issues like hallucination and harmful content generation.

We are adapting our tools and security frameworks for agentic AI – building on the CSA’s Guidelines and Companion Guide on Securing AI Systems.

Third, learning by doing with real deployment.

Through the GovTech-Google Cloud sandbox initiative, MDDI agencies have a chance to test and evaluate Google’s latest agentic capabilities, assess the risks, develop mitigation measures, and share the lessons learned with the broader community of AI practitioners in Singapore.

By observing how these systems behave – and sometimes fail – we learn what guardrails are truly needed.

Fourth, we are applying risk-based governance consistently.

We take a sector-specific approach to governance.

This sector-specific approach is designed to ensure that governance measures are proportionate to the risks.

For example, financial decisions affecting livelihoods receive more scrutiny compared with entertainment recommendations, and medical diagnoses demand higher validation standards than logistics optimisation.

Across our regulated sectors, we follow the principle that the higher the autonomy, the stronger the assurance needed.

Most importantly, humans remain ultimately responsible.

This coordinated approach aims to create a comprehensive governance ecosystem where testing frameworks, security requirements, and practical implementation guidance work together. Over time, we hope to build a governance stack that scales with AI capability and risk, while maintaining human accountability at every level.

OUR APPROACH TO QUANTUM SAFE

In quantum, we are also taking concrete action.

Last year, we announced the National Quantum Strategy with S$300 million committed over five years to quantum research and development. These investments build on foundations dating back to the early 2000s to give academia resources to push scientific boundaries, and support industry with capabilities to develop commercial applications.

But we are also managing the risks.

While there is growing awareness of the quantum threat, few organisations have embarked on quantum safe migration.

This is likely because of uncertainty over quantum developments and the lack of specific guidance.

CSA will plug this gap by launching two resources for public consultation today.

First, the Quantum Readiness Index is a self-assessment tool that helps organisations understand their current preparedness for quantum threats to encryption, and chart their migration journey towards quantum-safe systems.

Second, the Quantum-Safe Handbook provides guidance for organisations, particularly Critical Information Infrastructure owners and government agencies, to ready themselves for the transition to quantum-safe cryptography. This handbook was jointly developed by CSA, GovTech, and IMDA, in collaboration with leading technology companies, cybersecurity consultancies, and professional associations.

We consider these resources to be MVP – minimum viable products – live documents that get improved through public feedback. And we welcome you to contribute so we can all learn together.

INTERNATIONAL COOPERATION

Let me now turn to the important topic of international cooperation.

There is a fundamental reality about both technologies that we have discussed today.

Neither agentic AI nor quantum computing respects borders.

A breakthrough in quantum computing anywhere affects encryption everywhere.

A vulnerability in one country's systems can cascade globally.

This means international cooperation must turn from principle to practice.

One way is to ensure interoperable governance frameworks that work across different systems and countries. For example:

Singapore’s crosswalk with NIST hopes to enable companies to "test once, comply globally".

AI Verify's testing framework aligns with international standards including ISO/IEC 42001 and the G7's Hiroshima AI Process principles.

This reduces compliance burden while maintaining rigorous standards. It is a practical consideration that we must keep in mind. Companies always evaluate the cost and benefit of any action, including testing.

Through Digital Economy Agreements with countries like Australia and the UK, we also embed governance principles into trade relationships. We published the ASEAN Guide on AI Governance and Ethics in 2024 to harmonise Southeast Asian approaches, with a further expansion in 2025 to cover generative AI.

On agentic AI security specifically, we are taking proactive steps to address the challenges internationally.

CSA is releasing for public consultation a document on securing agentic AI.

This document is an addendum to its Guidelines and Companion Guide on Securing AI Systems, to cover the unique risks of agentic AI systems.

It is also an invitation – to governments, researchers, and industry partners – to help shape a global reference for securing agentic AI.

On quantum computing, the new NIST quantum-resistant cryptographic standards give us a common technical foundation.

But standards alone are insufficient.

We need to work regionally and internationally to develop and coordinate migration advice.

This is an area that my ASEAN colleagues have asked for further discussions on, and we will see how to facilitate.

Besides inter-governmental cooperation, we are deepening practical partnerships with industry.

CSA will be signing memoranda of cooperation with major technology companies, including Google, AWS, and TRM Labs, to enhance AI-driven intelligence sharing on cyber threats and enable joint operations against malicious activities.

Our partnership with Google demonstrates the tangible benefits – the Enhanced Fraud Protection feature within Google Play Protect has blocked 2.78 million malicious app installations across 622,000 devices in Singapore as of September 2025.

CONCLUSION

Let me conclude.

The age of agentic AI is upon us and the time for quantum-safe preparation is now. They bring much promise but also many unknowns.

We have a collective interest in maximising the upsides while minimising the downsides. By working together with a sense of urgency and purpose, we will learn faster and better our chances of success.

On that note, I thank you once again for being part of SICW and wish you many more fruitful discussions.