MDDI 연설문 · 2025-03-07

자닐 푸투체어리 선임 정무차관의 2025년 예산공급위원회 토론 연설

Janil Puthucheary · MDDI 전 선임정무장관 · 공급위원회 심의

요점

  • 정부는 올해 디지털 인프라법(Digital Infrastructure Act)을 도입할 계획으로, 주요 클라우드 서비스 제공업체 및 데이터 센터를 대상으로 복원력·보안 조치를 의무화하고 서비스 중단 보고를 요구할 예정입니다.
  • 중앙 정부 시스템의 가용성은 지난 1년간 95%에서 99.5%로 향상되었으며, 각 서비스의 중요도에 맞춰 조정된 가동 시간 모니터링 도구에 대한 지속적인 투자가 이루어지고 있습니다.
  • IMDA는 전국 광대역 네트워크(Nationwide Broadband Network)를 업그레이드하기 위해 최대 S$1억을 투자하고 있으며, 이를 통해 현재 가정용 속도의 최대 10배에 달하는 속도를 구현할 수 있습니다. 10 Gbps 요금제는 현재 S$30~S$70에 제공되고 있으며, 이는 1년 전 S$100 이상에서 크게 낮아진 수준입니다.
  • IMDA는 2024년 12월 그린 데이터 센터 로드맵(Green Data Centre Roadmap)과 에너지 효율 보조금(Energy Efficiency Grant)을 출시하여, 싱가포르의 기후 공약을 이행하는 동시에 데이터 센터가 지속 가능한 AI 컴퓨팅 성장을 도모할 수 있도록 안내하고 있습니다.
  • 보안이 강화된 생성형 AI 어시스턴트 Pair Chat은 공공 서비스 인력의 절반 이상이 사용하고 있으며, 범정부 프롬프트 엔지니어링 경진대회에는 1,040명이 넘는 공무원이 참가하였고, 1위는 SCDF 소속 소방관이 차지하였습니다.
  • GovTech의 첫 번째 LAUNCH! 해커톤 프로그램은 공공 기관 직원들로부터 600개 이상의 아이디어를 수집하여 26개의 혁신적인 프로토타입을 탄생시켰으며, 그 중에는 초등학교 교사들이 공동 개발한 AI 구술 피드백 도구도 포함되어 있습니다.
  • GovTech는 두 가지 AI 안전 플랫폼을 구축하고 있습니다. 하나는 안전성 및 보안 테스트를 위한 Litmus(IMDA의 Moonshot과 공동 개발)이며, 다른 하나는 서비스형 가드레일(guardrails-as-a-service)을 위한 Sentinel로, 정부의 생성형 AI 애플리케이션이 공공 이용에 안전하도록 보장하기 위한 것입니다.

전체 번역

MDDI 영어 원문의 번역 · 번역일: 2026-06-21

1. 감사합니다, 의장님. 의원 여러분의 삭감 제안과 질문에 감사드리며, 오늘 답변을 통해 Jessica Tan 의원, Tin Pei Ling 의원, Ong Hua Han 의원, Sharael Taha 의원, Dennis Tan 의원, 그리고 Mariam Jaafar 의원께서 제출하신 삭감 제안에 대해 다루고자 합니다.

2. 의장님, 신뢰는 스마트 네이션(Smart Nation) 노력의 핵심입니다. 우리 시민과 기업들은 자신들이 의존하는 디지털 시스템과 서비스, 그리고 그 안에서 이루어지는 상호작용과 거래를 신뢰할 수 있다는 확신을 가져야 합니다.

3. 저는 MDDI가 이러한 신뢰를 구축하는 방법을 설명드리겠습니다. 핵심 디지털 인프라의 회복력, 보안성, 미래 대비 역량을 확보하고, 공공의 이익을 위한 정부의 AI 도입 및 혁신을 주도하는 것입니다.

핵심 디지털 인프라 및 서비스의 회복력과 보안성 유지

4. 정부는 사이버 공격 및 서비스 장애를 포함한 디지털 인프라·서비스의 위험을 줄이기 위한 기존 규정을 두고 있습니다. 예를 들면 다음과 같습니다.

a. 통신법(Telecommunications Act)에 따라, IMDA는 광대역 및 이동통신망 사업자에게 장애를 최소화하기 위한 선제적 조치를 취하도록 요구하고 있습니다.

b. 또한 금융기관에 대한 MAS의 IT 회복력 및 보안 요건과 같이, 디지털 서비스에 관한 부문별 규정도 마련되어 있습니다.

5. 그러나 디지털 환경은 훨씬 광범위하며 끊임없이 진화하고 있습니다. 데이터센터(data centres)와 클라우드 서비스(cloud services)와 같은 디지털 인프라는 전자금융 및 결제, 차량 호출 서비스, 전자상거래, 디지털 신원 확인을 비롯한 다양한 기능을 가능케 하는 데 있어 중요한 역할을 담당하게 되었습니다. 이러한 기능들은 시민들이 일상적인 필요를 편리하고 효과적으로 충족할 수 있도록 해줍니다. 또한 기업의 성장에도 도움이 됩니다. 그러나 디지털 인프라의 규모와 복잡성이 증가함에 따라 사이버 공격에 노출되는 공격 표면도 넓어지고, 하드웨어 장애, 잘못된 구성 설정 및 기타 문제로 인한 장애 발생 위험도 높아지고 있습니다. 이러한 장애가 발생할 경우, 해당 서비스의 이용이 점점 증가하고 있는 만큼 그 영향도 더욱 커지게 됩니다.

6. 지난해 우리는 운영 환경의 새로운 도전에 대응하기 위해 사이버보안법(Cybersecurity Act)을 개정하였습니다.

a. 올해 후반 발효될 예정인 이번 개정안은 CSA(사이버보안청, Cybersecurity Agency)가 주요정보통신기반시설(Critical Information Infrastructure)을 넘어 중요 기관 및 시스템의 사이버보안을 더욱 효과적으로 보장할 수 있도록 권한을 부여합니다. 여기에는 데이터센터(data centres)와 클라우드 서비스(cloud services)가 포함됩니다. 이는 나아가 싱가포르와 우리 디지털 경제에 대한 신뢰와 확신을 높이는 데 기여합니다. 또한 우리는 주요정보통신기반시설 운영자들이 자신의 비즈니스 모델을 재검토할 기회를 갖기를 바랍니다. 상용 클라우드 솔루션(commercial cloud solutions)과 같은 신기술 도입을 염두에 두고 비즈니스 모델을 재검토하도록 장려되기를 희망합니다.

7. 사이버 위협 외에도, 화재와 같은 물리적 위험 요소와 하드웨어 장애, 시스템 잘못된 구성 설정과 같이 가시성이 낮은 위험 등, 디지털 인프라 및 서비스에 대한 접근을 방해하는 위험 요소들을 경계해야 합니다.

8. 이러한 위험은 디지털 인프라와 서비스에 대한 우리의 의존도에서 비롯되는 것입니다. 위험을 완전히 제거하는 것은 불가능하므로, 장애 발생 빈도와 영향을 줄임으로써 대비 역량을 강화해 나가야 합니다.

9. 올해 우리는 디지털 인프라법(Digital Infrastructure Act)이라는 새로운 법률을 도입하기 위해 노력하고 있습니다. 이 법은 싱가포르의 디지털 회복력과 보안성을 향상시킬 것입니다. 동 법은 주요 클라우드 서비스 제공업체와 데이터센터(data centres)를 시작으로 기반이 되는 디지털 인프라를 대상으로 합니다.

a. 동 법은 주요 운영업체들이 회복력과 보안성을 유지하고 장애를 최소화하기 위한 조치를 이행하도록 요구할 것입니다.

b. 우리는 주요 운영업체들이 장애 사항을 정부에 보고하도록 하는 요건을 검토하고 있습니다. 이를 통해 해당 사건으로부터 더 잘 배우고 개선해 나가며, 필요한 경우 대응 및 복구 노력을 지원할 수 있도록 하기 위함입니다.

c. 저희는 2024년 중반부터 디지털 인프라 공급업체와 일부 고객사로부터 의견을 수렴해 왔습니다.

10. 정보통신미디어개발청(IMDA)은 최근 클라우드 서비스 제공업체 및 데이터 센터를 위한 권고 지침을 발표하였습니다. 이 지침에는 이해관계자들과 협의해 온 핵심 조치들이 담겨 있습니다.

a. 해당 지침은 데이터 센터 운영자들이 견고한 업무 연속성 체계를 갖추고, 기업 고객에 대한 높은 가용성을 보장하도록 권고하고 있습니다.

b. 클라우드 서비스 제공업체 역시 데이터 보안 위험을 관리하고 업무 연속성 계획을 수립하도록 권고받고 있습니다.

c. 모든 운영자들이 이러한 조치를 이행하도록 권고받고 있으며, Microsoft, Equinix, Keppel을 비롯한 다수의 공급업체와 해당 기업 고객들은 새로운 권고 지침이 목적에 부합하고 국제 기준에도 일치한다고 판단하여 지지 의사를 표명하였습니다.

11. 저희는 또한 싱가포르 국민들이 온라인으로 정부와 상호작용할 때 신뢰와 확신을 가질 수 있도록 정부 시스템의 복원력을 강화하고 있습니다.

a. 저희는 각 기관이 사용하는 중앙 시스템의 복원력을 개선하였습니다. 해당 시스템의 서비스 가용성은 지난 1년간 95%에서 99.5%로 향상되었습니다. 저희는 시스템 가동 시간을 모니터링하는 도구를 비롯하여 정부 애플리케이션의 복원력을 높이는 도구의 도입을 지속적으로 확대해 나갈 것입니다.

b. 복원력 조치에는 비용이 수반되는 만큼, 저희의 접근 방식은 균형 있게 조정되어야 합니다. 저희는 중요한 서비스를 제공하는 기관들이 적절한 경우 더욱 정교한 조치를 이행할 수 있도록 지원할 것입니다.

12. 개인에 관한 정보는 사기 수법에 악용될 수 있으므로, 정부는 해당 정보에 대한 접근을 관리할 필요가 있습니다.

a. 저희는 개인 데이터를 포함한 데이터가 신중하고 책임감 있게 관리될 수 있도록 최선을 다하고 있습니다.

b. 데이터가 수반되는 디지털 서비스를 정부가 제공함에 있어, 각 기관은 MDDI가 제시한 지침과 안전장치에 따라 서비스 접근성과 데이터 보호라는 이중 목표를 달성하기 위해, 각 활용 사례에서 편익과 위험 간의 적절한 균형을 평가해야 합니다.

디지털 인프라의 미래 대비 태세 확보

13. 의장님, 저희의 디지털 인프라는 안전하고 복원력을 갖추는 것에 그치지 않고, 싱가포르가 미래를 선도하는 위치를 점할 수 있도록 해야 합니다.

14. 지난해 저희는 IMDA가 전국 광대역 네트워크(NBN) 업그레이드에 최대 1억 달러를 투자할 것이라고 발표하였습니다. 이를 통해 현재 대부분의 가정에서 이용하는 속도보다 최대 10배 빠른 광대역 속도가 구현될 것입니다.

a. 운영업체들은 더 낮은 가격에 더 높은 속도의 광대역 서비스를 제공하기 시작하고 있습니다. 10 Gig 요금제는 현재 30달러에서 70달러 사이로, 1년 전의 100달러 이상에 비해 크게 낮아졌습니다.

15. 미래 지향적 디지털 인프라를 발전시키는 것은 성장을 추구하는 동시에 자원 제약 문제를 해결하는 일도 수반합니다. 우리는 기후 공약을 준수하면서 싱가포르의 AI 야망을 지원하는 방법을 모색하는 한편, 디지털 인프라 성장과 환경적 지속가능성 사이의 균형을 유지해야 합니다.

a. IMDA는 데이터 센터들이 에너지 효율을 개선하고 친환경 에너지를 활용하여 AI 컴퓨팅 역량을 지속가능하게 성장시킬 수 있도록 안내하기 위해 지난해 Green Data Centre Roadmap을 발표하였습니다. 상당한 진전을 이루었습니다. 예를 들어, 데이터 센터에 대한 BCA-IMDA Green Mark는 데이터 센터 지속가능성의 기준을 높이기 위해 지난 10월에 개편되었습니다. 또한 IMDA는 기업들이 보다 에너지 효율적인 IT 장비로 업그레이드하는 것을 지원하기 위해 지난 12월 데이터 센터 부문을 위한 Energy Efficiency Grant를 출시하였습니다.

b. MDDI는 규제를 통해 데이터 센터의 지속가능성을 향상시키는 추가적인 방법을 모색하고 있습니다. 우리는 다른 관할권을 검토하고 있으며, 싱가포르의 상황에 맞는 프레임워크를 개발하기 위해 업계와 초기 협의를 진행 중입니다.

디지털 정부를 다르게 실천하기

16. 의장님, 우리는 디지털 정부로서 솔선수범해야 합니다. 공공 부문이 AI를 창출하고 실험할 수 있는 역량을 지속적으로 구축하고, 시민 중심의 솔루션을 발굴해야 합니다.

a. 우리는 공공 서비스 내에서 최고 수준의 AI 및 대형 언어 모델(LLM) 도구에 대한 접근권을 제공하였습니다. Pair Chat은 현재 공공 서비스의 절반 이상이 사용하는 빠르고 안전한 생성형 AI 어시스턴트입니다. 지난해 우리는 정부 전체를 아우르는 프롬프트 엔지니어링 대회를 개최하였으며, 1,040명 이상의 공무원이 참가하였습니다. 이 사실만으로도 우리가 「디지털 정부 실천」 방식에서 얼마나 독특한지를 잘 보여줍니다. 정부 내에서 프롬프트 엔지니어링 대회가 열렸고, 1,040명의 공무원이 참가하였다는 점이 그것입니다. 결선 진출자들은 LLM 도구를 활용하여 10분 이내에 행사 홍보 웹사이트를 구축하는 과제를 수행하였습니다. 이 대회의 우승자는 SCDF 소속 소방관인 Muhammad Naim Bin Zahari였습니다. 대회 당시 그는 막 24시간 근무를 마친 직후였습니다. 2위는 MOM 소속 재무 담당 공무원인 Rachel Tiang이었습니다. 두 사람 모두 AI를 다루는 기술 직무에 종사하고 있지 않았습니다. 그러나 두 사람을 비롯한 모든 참가자들은 이러한 AI 및 LLM 보강 도구를 활용하여 10분 이내에 기능하는 홍보 웹사이트를 충분히 구축할 수 있었습니다.

b. 우리는 비기술직 공무원들을 디지털 제품 개발에 적극적으로 참여시키고 있습니다. 지난해 GovTech는 공무원을 위한 최초의 해커톤 시리즈인 LAUNCH! Programme을 개최하였습니다. 이 프로그램은 600개 이상의 아이디어를 모았고, 26개의 혁신적인 프로토타입을 탄생시켰습니다. 예를 들어, 초등학교 교사 2명과 GovTech 직원 1명으로 구성된 팀은 학생들의 구술 능력 수행에 대해 즉각적인 맞춤형 피드백을 제공하는 AI 도구를 시제품으로 개발하였습니다.

c. 또한 우리는 공무원들이 AI를 활용하여 더 잘, 더 빠르게 혁신할 수 있는 방법을 모색하고 있습니다. 최근 Hack for Public Good 해커톤에서 나온 프로토타입 중 하나는 Spaceship으로, 공무원들이 프로토타이핑에 대한 부담을 덜 수 있도록 돕는 도구입니다. Spaceship은 공무원들이 AI 에이전트를 활용하여 LLM 기반 도구를 포함한 완전한 기능을 갖춘 프로토타입 애플리케이션을 구축하고 배포할 수 있게 합니다. 이 모든 것이 평범한 영어만으로 가능합니다. 이는 비기술직 공무원들이 아이디어에서 불과 몇 분 만에 실용적인 앱을 만들어낼 수 있는 도구이며, 오직 평범한 영어만 사용하면 됩니다. 저도 이 프로토타입을 직접 사용해 보았는데, 국회의원 연설 시간을 제한하는 포털을 코딩해 보도록 하였습니다. 스프레드시트에 적절한 필터를 삽입하긴 하였으나, 현재 기술의 한계는 거기까지인 것 같습니다.

17. 정부 내 AI 활용이 증가함에 따라, AI 애플리케이션에 내재된 위험을 이해하고 완화하는 것이 매우 중요합니다. GovTech는 정부의 생성형 AI 애플리케이션이 안전하게 시장에 출시될 수 있도록 역량을 구축하고 있습니다.

a. 우리에게는 AI 안전성 및 보안 테스트 도구인 Litmus가 있습니다. 우리는 AI 애플리케이션이 사용자를 오도하거나 명성에 피해를 주는 위험에 저항력을 갖출 수 있도록 테스트 세트를 정교하게 구성하였습니다. Litmus는 IMDA의 Moonshot과 협력하여 구축되었으며, 올해 출시될 예정입니다. 기관들과의 테스트를 통해 Litmus가 사전에 잠재적인 안전 문제를 파악하여 선제적으로 조치를 취할 수 있게 해주는 것을 확인하였습니다. 이는 본질적으로 서비스로서의 AI 테스팅입니다.

b. Litmus는 AI 위험에 대한 진단을 제공하지만, 해당 위험이 탐지된 후에는 해결책도 필요합니다. AI 분야에서 가드레일(guardrails)은 AI 시스템이 윤리적·법적·기능적 경계 내에서 작동하도록 보장합니다. 우리는 정부 AI 애플리케이션을 위한 서비스로서의 가드레일을 제공하는 플랫폼인 Sentinel을 구축하고 있습니다. 제품 팀은 최고의 AI 개발사가 제공하는 가드레일과 LionGuard와 같은 현지화된 가드레일을 포함한 엄선된 목록에서 선택하여 자신들의 애플리케이션에 손쉽게 통합할 수 있습니다. Sentinel은 시스템 침투 시도나 AI 모델을 속여 부적절한 출력을 생성하게 만들려는 시도를 정확하게 식별할 수 있음을 입증하였습니다.

c. Litmus와 Sentinel은 우리가 일반 시민을 포함한 모든 사용자에게 안전하게 사용할 수 있는 정부 생성형 AI 애플리케이션을 어떤 방식으로 개발하고자 하는지를 잘 보여줍니다.

결론

18. 의장님, 우리의 디지털 인프라는 시민과 기업이 의존하는 핵심 기능을 뒷받침합니다. 이에 따라 우리는 핵심 디지털 인프라의 보안, 회복력 및 미래 대비 역량을 강화하는 데 적극적으로 투자해 왔습니다. 또한 공공 부문의 역량을 지속적으로 구축하고, AI를 활용한 실험과 혁신을 수용하여 싱가포르 시민에게 더 나은 서비스를 제공하고 있습니다. 스마트 네이션 여정을 계속해 나가면서 이러한 노력이 우리의 디지털 미래에 대한 신뢰를 구축할 것이라고 기대합니다.

19. 감사합니다.

영어 원문

MDDI 공식 웹사이트 원문 · 수집일: 2026-06-21

1. Thank you, Mr Chairman. I thank the Members for their cuts and questions, and I hope in my response today to be addressing cuts filed by Ms Jessica Tan, Ms Tin Pei Ling, Mr Ong Hua Han, Mr Sharael Taha, Mr Dennis Tan and Ms Mariam Jaafar.

2. Sir, trust is at the heart of our Smart Nation efforts. Our citizens and businesses must be confident that the digital systems and services that they rely on, and the interactions and transactions that they engage in, can be trusted.

3. I will explain MDDI’s approach to building this trust: by ensuring the resilience, security and future-readiness of key digital infrastructure, and by driving Government AI adoption and innovation for the public good.

Upholding Resilience and Security of Key Digital Infrastructure and Services

4. The Government has existing regulations to reduce risks to digital infrastructure and services, including cyber-attacks and service disruptions. For example:

a. Under the Telecommunications Act, IMDA requires broadband and mobile network operators to take proactive measures to minimise disruptions.

b. There are also sectoral regulations for digital services, such as MAS’ IT resilience and security requirements for financial institutions.

5. But the digital landscape is much bigger, and constantly evolving. Digital infrastructure like data centres and cloud services have become important in enabling many functions including e-banking and payments, ride-hailing, e-commerce, and digital identity. These functions allow citizens to meet their day-to-day needs and do so conveniently and effectively. They help businesses to grow. However, the growing scale and complexity of our digital infrastructure also mean an increased surface area for cyber-attacks, and a higher risk of disruptions arising from hardware failures, misconfigurations, and other problems. Should these disruptions occur, the impact is higher given the increasing utilisation of these services.

6. Last year, we amended the Cybersecurity Act to address new challenges in our operating environment.

a. These amendments, which are expected to come into force later this year, will empower CSA, the Cybersecurity Agency, to better ensure the cybersecurity of important entities and systems beyond the Critical Information Infrastructure. These include data centres and cloud services. This in turn improves trust and confidence in Singapore and our digital economy. Owners of Critical Information Infrastructure also have the opportunity, we hope, to review their business models. We hope that they will be encouraged to review their business models and do so with a view to using new technologies such as commercial cloud solutions.

7. Beyond cyber threats, we must guard against risks that disrupt access to digital infrastructure and services, including physical hazards like fires, and less visible risks like hardware failure and system misconfiguration.

8. These are risks as a result of our dependence on digital infrastructure and services. We cannot eliminate risk completely, so we must enhance our preparedness by reducing the occurrence and the impact of disruptions.

9. We are working towards introducing a new law this year, called the Digital Infrastructure Act. This will improve Singapore’s digital resilience and security. The Act targets foundational digital infrastructure, starting with major cloud service providers and data centres.

a. The Act will require major operators to implement measures to uphold their resilience and security, and to minimise disruptions.

b. We are studying requirements for major operators to report disruptions to the Government, so that we can better learn and improve from these incidents, and support response and recovery efforts where needed.

c. We have been seeking feedback from digital infrastructure providers and some of their customers, since mid-2024.

10. The Infocomm Media Development Authority, IMDA, recently released Advisory Guidelines for cloud service providers and data centres. These guidelines contain key measures that we have been consulting stakeholders on.

a. The guidelines encourage data centre operators to have a robust business continuity system and ensure high availability for their enterprise customers.

b. Cloud service providers are also encouraged to manage data security risks, and ensure business continuity planning.

c. All operators are encouraged to implement the measures, and many providers including Microsoft, Equinix and Keppel, and their enterprise customers, have expressed support for the new Advisory Guidelines, which they find to be fit for purpose and aligned with international standards.

11. We are also strengthening the resilience of our Government systems to ensure that Singaporeans have trust and confidence when interacting with the Government online.

a. We have improved the resilience of central systems used by Agencies. Service availability for these systems rose from 95% to 99.5% in the last year. We will continue to increase the adoption of tools to improve the resilience of Government applications, including those that monitor system uptime.

b. As resilience measures incur costs, our approach must be calibrated. We will support Agencies providing important services to implement more sophisticated measures where appropriate.

12. There is a need for Government to manage access to information about individuals, as such information could be exploited in scam tactics.

a. We are committed to ensure that data, including personal data, is managed carefully and responsibly.

b. In the Government’s provision of the digital services involving data, Agencies must assess the right balance between the benefits and risks in each use case, to achieve the dual objectives of service accessibility and data protection, in line with the guidelines and safeguards that MDDI has provided.

Ensuring Future-Readiness of our Digital Infrastructure

13. Sir, our digital infrastructure must not only be secure and resilient, but also position Singapore for the future.

14. Last year, we announced that IMDA is investing up to $100 million to upgrade our Nationwide Broadband Network (NBN). This will enable broadband speeds up to 10 times faster than what most households have today.

a. Operators are starting to offer higher speed broadband services at lower prices. A 10 Gig plan now costs between $30 to $70, compared to more than $100 a year ago.

15. Developing our future-ready digital infrastructure also entails addressing resource constraints as we pursue growth. We must explore ways to support Singapore’s AI ambitions while keeping to our climate commitments, as well as balance digital infrastructure growth with environmental sustainability.

a. IMDA launched the Green Data Centre Roadmap last year to guide data centres to improve energy efficiency and use green energy to grow AI compute capacity sustainably. We have made good progress. For example, the BCA-IMDA Green Mark for data centres was refreshed last October to raise the bar for data centre sustainability. IMDA also launched the Energy Efficiency Grant for the data centre sector last December to support businesses’ upgrades to more energy efficient IT equipment.

b. MDDI is exploring further ways to uplift data centre sustainability through regulations. We are studying other jurisdictions and are in early engagement with industry to develop a framework for Singapore’s context.

Doing Digital Government Differently

16. Sir, we have to lead by example, as a Digital Government. We must continue to build the capabilities for the public sector to create and experiment with AI, and unlock citizen-centric solutions.

a. We have made available within the Public Service access to best-in-class AI and Large Language Model tools, LLM tools. Pair Chat is a fast and secure generative AI assistant used by more than half the Public Service today. Last year, we organised a whole-of-government prompt engineering competition. This attracted over 1,040 officers. The fact that I can say this already makes us quite unusual in terms of how we ‘do Digital Government’ – that we have a prompt engineering competition within Government and that there were 1,040 officers who participated. The finalists were tasked to build an event publicity website within 10 minutes using LLM tools. The winner of this competition was Muhammad Naim Bin Zahari, a firefighter with SCDF. At the time of the competition, he had just completed a 24-hour shift. In second place was Rachel Tiang, a finance officer at MOM. Neither were in technical roles dealing with AI. Both of them and all the competitors were more than capable of building this functioning publicity website within 10 minutes using these AI and LLM-augmented tools.

b. We actively involve non-technical public officers in creating digital products. Last year, GovTech held its inaugural series of hackathons for public officers, called the LAUNCH! Programme. It gathered more than 600 ideas and birthed 26 innovative prototypes. For example, a team of two primary school teachers and a GovTech officer prototyped an AI tool to provide students with immediate customised feedback on their oral skills performance.

c. We are also exploring how officers can innovate better and faster with AI. One of the prototypes from our recent Hack for Public Good hackathon was Spaceship, a tool to make prototyping less daunting for public officers. Spaceship enables officers to use AI agents to build and deploy fully functional prototype applications, including LLM-based tools. They do this using just plain English. This is a tool for non-technical public officers to get from an idea to a workable app in minutes using just plain English. I tried out this prototype, and I tried to have it code a portal that restricted the length of MPs’ speeches. It put the appropriate filter into the spreadsheet, but I think that is the limit of the technology today.

17. As we increase the use of AI in Government, it is critical to understand and mitigate the risks in AI applications. GovTech is building the capabilities to ensure that the Government’s Generative AI applications go-to-market safely.

a. We have Litmus, a tool for AI safety and security testing. We have curated a set of tests to ensure our AI applications are resistant to risks that mislead users or cause reputational harm. Litmus is built in partnership with IMDA’s Moonshot, and will be launched this year. Based on tests with Agencies, we have seen how Litmus can spot potential safety issues ahead of time, allowing us to act proactively. Essentially this is AI testing as a service.

b. Litmus provides a diagnosis of the AI risks, but we also need a solution once those risks are detected. In the AI world, guardrails ensure that AI systems operate within ethical, legal, and functional boundaries. We are building Sentinel, a platform that provides guardrails as a service for the Government’s AI applications. Product teams can choose from a curated list of guardrails, including those from top AI developers and localised ones like LionGuard, and easily integrate these into their applications. Sentinel has been able to accurately identify attempts to infiltrate systems or trick AI models into producing inappropriate output.

c. Litmus and Sentinel demonstrate how we want to develop Government Generative AI applications that are safe for use, including by members of the public.

Conclusion

18. Sir, our digital infrastructure underpins key functions that citizens and businesses rely on. We have therefore actively invested in enhancing the security, resilience and future-readiness of our key digital infrastructure. We also continue to build capabilities in the public sector, and embrace experimentation and innovation with AI, to better serve Singaporeans. I am hopeful that this will build trust in our digital future as we continue on our Smart Nation journey.

19. Thank you.