Liability and Governance · Updated 2026-04-26

Guidelines and Companion Guide on Securing AI Systems

Governance Issued 2024-10 Cyber Security Agency of Singapore (CSA)

Core Point

Best practices for AI system security across the full lifecycle — filling a gap in AI security governance.

Detailed Note

Issued by CSA in October 2024, the guidelines cover the full AI system lifecycle: threat modelling at the planning and design stage, data and model security during development, security testing at deployment, and monitoring and incident response in operations. Particular focus is given to AI-specific risks such as adversarial attacks, data poisoning, model theft and supply-chain security. The companion addendum "Securing Agentic AI" was issued in draft for public consultation on 22 October 2025 (closing 31 December 2025), with the finalised version released on 17 June 2026, extending the framework to agentic AI use cases.

Position in the Legal Framework

A gradual path from principles to tools to enforcement — FEAT → Veritas → MindForge → AI Risk Management Guidelines.

Related Legal Cards

More on these topics