MDDI 연설문 · 2026-02-20
Yang Liming 부장관의 「AI 에이전트 영향 모니터링: 글로벌 안전한 신뢰할 수 있는 AI 보장 격차 해소」 포럼 개막 기조 연설
요점
- • 에이전트 AI는 작년 Paris AI 행동 정상회담부터 오늘까지 비로소 진정한 성장을 이루었습니다. 그 「자율성」은 가치이자 위험의 원천입니다. 일단 통제를 잃으면, 영향은 종종 복잡하고 예측하기 어렵습니다.
- • 싱가포르의 자세: 「수동적 규제」에서 「주도적 준비」로의 전환. 정부는 선도자가 되어야 하고 뒤처지는 자가 아니어야 합니다——예를 들어, Google과의 협력을 통한 에이전트 AI 샌드박스는 정부가 「자신이 먼저 그 제품을 사용한다」는 방식입니다.
- • 싱가포르가 에이전트 AI를 위한 《Model Governance Framework》를 출시했으며, 이는 「살아있는 문서」로서 계속해서 피드백을 수집합니다.
- • 「보증 생태계」(assurance ecosystem)는 신뢰 구축의 핵심이며, 최소 3가지가 필요합니다: ①테스트(출력뿐만 아니라 추론과 조직도 살펴봐야 함); ②표준; ③제3자 보증 제공자(독립 감사, 테스터)——후자는 내부 능력을 보완하고 맹점을 찾습니다.
- • Josephine의 기업을 위한 말: 「높은 보안 보증」을 제공할 수 있는 회사는 경쟁사와 구별될 것입니다——이를 전략적 경쟁 우위로 봐야 하며, 마지못한 규정 준수의 부담이 아닙니다.
전체 번역
MDDI 영어 원문의 번역 · 번역일: 2026-05-02
「Partnership on AI」의 초대에 감사드립니다.
이 일련의 정상회담이 Bletchley Park에서 초기에 시작되었을 때, AI 에이전트(agents)는 아직 주역이 아니었습니다. 심지어 12개월 전 Paris에서 「AI 행동 정상회담」을 개최했을 때도, 그것은 거의 대화에 진입하지 못했습니다.
당시 모든 사람들이 관심 가진 것은 DeepSeek과 그것이 보여주는 것이었습니다. 중국에서 비롯된 역량이 어느 수준에서 나타나고 있는지입니다. 하지만 오늘날, 에이전트 시스템은 이미 급속도로 성장하고 있으며 점점 더 많이 사용되고 있습니다. 우리는 이 문제에 어떻게 대응할지 더 잘 파악할 필요가 있습니다.
에이전트 AI가 전략적으로 배포될 때, 「우리가 어떻게 업무를 위임하고 조율할 것인가」에 대해 혁신적인 가능성을 실제로 제공합니다. 소중한 「팀 동료」로서의 에이전트는 우리가 모두 더 원하는 것을 실현합니다—생산성 향상과 시간 절약.
하지만 제가 덧붙여야 할 말이 있습니다. 에이전트 AI를 우리에게 유용하게 만드는 본질은 「자율성」입니다. 이 자율성은 또한 새로운 위험을 가져옵니다. 시스템이 오류를 범하면서 인간의 감시가 부재하거나 크게 약화될 때, 해를 입힐 가능성은 커집니다. 그 영향은 복잡할 수 있으며, 완전히 예측 가능하지 않을 수 있습니다.
저와 동료들의 생각은 이렇습니다. 우리는 태도의 전환을 해야 합니다. 「사후 대응적 규제」(reactive regulation)에 의존하는 것에서, 「사전 예방적 준비」(proactive preparation)라는 다른 태도로 나아가야 합니다.
싱가포르에서, 이것이 바로 우리가 계속해오고 있는 일입니다. 우리는 에이전트 AI 시대의 새로운 위험을 사전에 관리하려고 노력하고 있습니다.
이것은 정부 스스로에서 시작되어야 한다고 생각합니다. 정부는 에이전트 AI를 사용하는 선도자여야 하지, 낙후된 주체가 아니어야 합니다. 우리는 이를 테스트하고, 이러한 솔루션이 공공 서비스 제공을 어떻게 개선할 수 있는지 살펴봐야 합니다. 동시에 더 많은 통제를 수립해야 합니다.
정부는 높은 위험 시나리오입니다. 시민과의 접점이 매우 민감하기 때문입니다. 어떤 정부도 시민과의 상호작용에서 심각한 오류를 범하고 싶지 않습니다. 건강, 사회보장, 복지에 관한 부정확한 정보를 알려주고, 이러한 오류가 단순히 시민들에게 전달되는 것뿐만 아니라 그에 따라 행동까지 취해질 때 말입니다. 「우리가 무엇을 하는지 명확히 해야 한다」는 요구사항은 매우 높으며, 우리도 생각하고 있습니다. 산업계와 함께 이를 해야 합니다.
예를 들어, Google과 싱가포르 정부 사이에는 에이전트 AI 샌드박스가 있습니다. 이것은 「우리가 먼저 우리 자신의 개밥을 맛본다」는 방식 중 하나입니다. 맛이 괜찮습니까? 우리에게 심각한 해를 끼칠까요? 우리 스스로 이것을 할 수 없다면, 에이전트 AI를 관리하려는 우리의 신뢰성은 의문의 여지가 있습니다. 하지만 우리는 또한 개밥의 결과가 우리 몸에 완전히 나타날 때까지 기다릴 수 없습니다.
한편, 제 동료들은 에이전트 AI를 위한 「Model Governance Framework」를 정리했습니다. 기업들이 자율 에이전트를 책임감 있게 배포하고 위험을 완화할 수 있도록 실질적인 지원을 제공합니다. 우리는 이것이 완전한 솔루션이 아니라는 것을 알고 있으므로, 이 문서는 반드시 「활성 문서」(live document)여야 합니다. 우리는 피드백을 매우 환영하며, 이를 통해 기업을 위한 지침을 지속적으로 개선합니다.
이것의 의의와 목적은 무엇입니까? 궁극적으로, 에이전트 AI 시스템의 사용에 대한 신뢰를 구축하는 것입니다. 여러 수준에서 이 신뢰는 다음에게 제시되고 입증되어야 합니다. 조직의 이사회, 고객, 기타 이해관계자들입니다. 「위험이 잘 관리되었다」는 것을 어떻게 보여줄 수 있을까요?
이것이 「보증 생태계」(assurance ecosystem)가 등장하는 곳입니다. 중장기적으로 신뢰를 구축하기 위해 절대 필요한 부분이며, 에이전트 AI 시스템이 더 광범위하게 채택되고 더 쉽게 접근할 수 있는 기초입니다.
저는 또한 말하고 싶습니다. 이 문제를 생각하고 있는 기업들을 위해. 우리가 이러한 에이전트 시스템을 신뢰하려면, 「보안」 부분을 무시할 수 없습니다.
저는 심지어 감히 말합니다. 「안전 보증」에서 높은 수준의 보장을 제공할 수 있는 기업은 경쟁사와 자신을 차별화할 것입니다. 이는 자신의 제품과 서비스에 대한 더 강한 관심으로 더 가능성 높게 전환될 것입니다.
이를 마지못해 준수해야 할 대상으로 취급하기보다는, 전략적 경쟁 우위로 봐야 합니다. 이러한 마음가짐은 우리에게 이를 전면에 내놓을 자신감을 줄 것입니다.
하지만 문제는 이렇습니다. 이 문제에서 우리는 완전히 선례가 없습니까? 답은 '아니오'입니다.
항공과 의료 분야에서는 이미 승객과 환자에게 보증을 제공하기 위한 많은 조치가 있습니다. 우리가 비행기를 탈 때, 우리는 일반적으로 도착할 것으로 예상합니다. 우리가 병원에 갈 때, 아직 잘 이해되지 않은 질병이 아니라면, 우리는 일반적으로 치유될 것으로 예상합니다.
이러한 시스템에 대한 신뢰는 시간이 지남에 따라 축적되며, 어떤 형태의 「보증」의 존재와는 불가분의 관계가 있습니다. 문제는 다음과 같습니다. AI, 특히 에이전트 AI의 경우, 「보증 생태계」를 구성하는 요소들은 무엇이어야 할까요? 충분히 견고한 조합은 무엇일까요?
우리는 최소한 세 가지 요소가 있다고 생각합니다.
첫째, 테스트가 필수적입니다. 우리는 시스템이 견고하고, 신뢰할 수 있으며, 안전한지 확인하기 위해 시스템을 기술적으로 평가할 수 있는 방법이 필요합니다. 이 분야에는 여전히 많은 작업이 필요합니다. 테스트 방법론 개발, 테스트 데이터 세트 구축, 그리고 에이전트 시스템의 테스트가 다음을 고려해야 하도록 보장하는 것입니다. 이러한 시스템은 여러 에이전트를 포함하기 때문에 훨씬 복잡해집니다.
예를 들어, 「출력」만 보는 것이 아니라 「중간 단계」도 봐야 합니다. 추론이 어떻게 발생하는지, 에이전트 시스템에서 어떤 종류의 「조율」이 구축되었는지입니다.
둘째, 궁극적으로 우리는 표준이 필요합니다. 「무엇이 충분히 좋은가」에 대해 각각 다르게 말할 수는 없습니다. 우리는 또한 사용자에게 이것이 안전성과 신뢰성에 대한 기대를 충족한다는 것을 보증해야 합니다. 이 분야는 여전히 매우 초기 단계입니다.
셋째, 우리는 이 생태계가 「제3자 보증 제공자」 없이는 불가능하다고 생각합니다. 「자신의 에이전트 AI 시스템이 안전하다고 주장하는 것」과 「다른 사람들이 그 안전성을 증명하도록 하는 것」은 다릅니다. 이러한 역할은 기술 테스트 기관, 감시인이 될 수 있습니다. 그들은 독립성을 제공하고, 내부 역량을 보완하며, 맹점을 식별하는 데 도움을 줍니다. 우리는 이러한 인재 풀을 발전시킬 필요가 있습니다.
저는 다음과 같은 말로 발언을 마치겠습니다. 싱가포르는 이러한 요소들을 적극적으로 구축하고 있습니다.
우리는 파트너 및 동료들과의 대화를 환영합니다. 이것은 한 국가가 독자적으로 완성할 수 없다는 것을 알기 때문입니다. 우리는 또한 세 개의 분회장에서의 논의를 기대합니다. 에이전트 AI의 「보증」 문제에서 우리가 어떻게 의미 있게 협력할 수 있을지에 대해서입니다.
다시 한 번 감사드립니다.
영어 원문
MDDI 공식 웹사이트 원문 · 수집일: 2026-05-02
Thank you, Partnership on AI, for the invitation.
When this series of summits first began in Bletchley Park, AI agents were not a thing. Nobody was talking about them, even just 12 months ago when we had the AI Action Summit in Paris, it had barely crept into the conversation.
At the time, the preoccupation was all around DeepSeek, and what it told us about the capabilities that are emerging out of China. But today, agentic systems have taken off. They are increasingly being used, and we need to have a better grasp on how to deal with this issue.
Agentic AI certainly offers transformative possibilities in how we delegate and orchestrate work when deployed strategically. Agents function as invaluable teammates, unlocking productivity gains and time savings, which we all want more of.
However, I should also add that the very nature of how agents can be helpful to us, is autonomy. This autonomy also introduces new risk. The potential for harm increases when systems malfunction and human oversight is no longer present or at least diminished to a very large extent. The implications may be complex and not fully predictable.
The way my colleagues and I have been thinking about this is that there needs to be a shift, in terms of how we might want to rely on reactive regulation, to a different kind of stance, which is proactive preparation.
And in Singapore, that's what we've been trying to do. We have tried to be proactive about governing the new risks in the era of agentic AI.
I think it starts with the Government itself being a leader and not a laggard in using agentic AI. We need to test it. We need to look at how the solutions can enhance public service delivery but also put in place more controls.
Government is high-risk because the touch point with citizens is very sensitive. No government wants to make serious mistakes when it interacts with its citizens – telling them things about their health, social security, or things to do with their benefits that are not accurate, and having these mistakes not just told to citizens but acted upon. This need to ensure that we know what we're doing is a very high one, and the way we are also thinking about it is to work with the industry.
For example, between Google and the Singapore Government, we have a sandbox on agentic AI. It's one of the ways in which we think we can, in a way, try our own dog food. Try it to see if it tastes alright? Does it hurt us in a very significant way? Because if we were not able to do so, I don't think we have a lot of credibility in terms of how we want to govern agentic AI. But we can't wait for the dog food to materialise its consequences for ourselves.
In the meantime, my colleagues have put together a Model Governance Framework for agentic AI. It is meant to provide practical support to enterprises so that they can also deploy autonomous agents responsibly and mitigate the risk. We know that this is not a complete solution, and this document that we put out, has to be a live document. We very much encourage feedback as a way for us to keep improving the guidance to enterprises.
As we do this work, what is the meaning and purpose behind it? Ultimately, it is to build confidence in the use of agentic AI systems. At many levels, this confidence has to be presented and demonstrated to boards of organisations, customers, and other stakeholders. How do we demonstrate that the risks have been managed well?
That is where the assurance ecosystem comes in. It is an absolutely essential part of building trust over the medium to longer term, so that there is a foundation upon which agentic AI systems can be made more readily adopted and available.
I should also say that for companies that are thinking about it, if we are to trust these agentic systems, the safety aspects should not be downplayed.
I would venture to say that a company that is able to give a high assurance on safety will find itself being differentiated from its competitors, and this is more likely to translate into stronger interest in its products and services.
Rather than think of it as something that you are unhappy to comply with, think of it as a strategic competitive advantage, and the way that will give us the confidence to put it forward.
The question, however, is: are we completely without experience in this regard? The answer is no.
In aviation and healthcare, there are a lot of measures being put in place to give assurance to passengers that when we board a plane, we usually expect to arrive, or when we visit the hospital, we generally expect to be treated, except for disease conditions that are not yet well understood.
The trust in these systems has to be built over time, and it doesn't come without some assurance being put in place. The question is, for AI, and specifically agentic AI, what would be the components? What leads to an assurance ecosystem that would be robust enough?
We think that there are at least three components.
The first is that there must be testing. We need some way of making sure that there are technical assessments of the system to make sure that the systems are robust, reliable and safe. A lot more work needs to be done in this space – developing the testing methodology, building the testing data sets, and also making sure that the testing of agentic systems takes into account that these systems are going to be much more complex because they involve multiple agents.
For example, it's not just the output, but the in-between steps – how the reasoning takes place and what is the orchestration that is being built into the agentic systems.
The second is that eventually we will need standards. We cannot just define what is good enough. We also need to assure the users that it has met expectations for safety and reliability, and so these are still very early days.
Third, we think that this ecosystem cannot do without third party assurance providers. It's one thing to claim that your agentic AI system is safe, but another to have someone attest to the safety of it. So these could be technical testers, auditors, and they provide independence, augment in-house capabilities, and also help to identify the blind spots. And it's necessary for us to strengthen this pool as well.
I want to conclude my remarks by saying that Singapore is actively building these components.
We welcome conversations with partners and colleagues, because we know that we cannot do this alone. We look forward to discussions in the three panels on how we can meaningfully collaborate on assurance for agentic AI.
Thank you very much once again.