On 17 June 2026, the Cyber Security Agency of Singapore (CSA) announced its release of the finalised Addendum to the Guidelines and Companion Guide on Securing AI Systems ("Addendum"). This follows the public consultation held by CSA in 2025, which we outlined in our client alert here.
The Addendum was developed by the CSA in collaboration with industry, government, and international partners to support system owners in securing their agentic AI systems. It is designed to be read alongside the Guidelines and Companion Guide on Securing AI Systems.
In detailPurpose and scope of Addendum
The Addendum curates practical measures and controls that system owners can use to secure their adoption of agentic AI systems. These measures and controls are voluntary, and may not be applicable to all organisations and environments.
The measures and controls within the Addendum address the cybersecurity threats and risks relevant to agentic AI systems. It does not specifically address AI safety, or other common attendant considerations for AI such as fairness, transparency or inclusion. It also does not cover the misuse of AI to conduct cyberattacks and scams.
Security threats to agentic AI systems
Agentic AI systems face both traditional and novel security challenges. There are classical cybersecurity risks, inherited risks from large language model components and new risks specific to agentic AI systems. The two primary risks arising from agentic AI systems are rogue actions and sensitive data disclosure. Rogue actions occur when agents perform unintended or harmful tasks. Meanwhile, sensitive data disclosure occurs when attackers manipulate agents into exposing sensitive information.
Securing Agentic AI
The Addendum builds on the two principles set out in CSA's Guidelines and Companion Guide on Securing AI Systems: (i) taking a lifecycle approach and (ii) starting with a risk assessment. Given the dynamic nature of agentic AI systems, the Addendum adds additional considerations to support the risk assessment. This includes:
The Addendum serves as a useful reference point for organisations securing their agentic AI systems, with practical examples showing how it can be applied across different scenarios and levels of system autonomy. There is no one size fits all solution. Organisations should also continue to periodically re-evaluate the risks posed and consider whether the current controls (e.g., supply chain security, access controls, environment segmentation, input/output validation, model and system hardening, human-in-the loop oversight and continuous logging and monitoring etc., amongst others) implemented remain adequate as AI capabilities evolve and following significant system changes.
Related contentOur previous client alert regarding the public consultation on the Addendum can be accessed here.

© 2026 Baker & McKenzie. Wong & Leow. All rights reserved. Baker & McKenzie. Wong & Leow is incorporated with limited liability and is a member firm of Baker & McKenzie International, a global law firm with member law firms around the world. In accordance with the common terminology used in professional service organizations, reference to a "principal" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as "Attorney Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Singapore: MAS Publishes Agentic AI Safeguards for Financial Institutions | 0 | 10 | 17-07-2026 |
| 2 | Singapore: AI-Specific Notification Requirement | 0 | 35 | 29-07-2026 |
| 3 | Singapore: New Transparency Guidelines for Generative AI Chatbots | 0 | 10 | 29-07-2026 |
| 4 | Singapore: CSA Cyber Landscape Report 2025/2026 | 0 | 26.67 | 29-07-2026 |
| 5 | Singapore: HSA Consults on Complementary Health Products Regulation | 0 | 10 | 30-07-2026 |
| 6 | AI Agent Governance: Securing Autonomous Agents in Production | 0 | 10.41 | 24-07-2026 |
| 7 | How IAM providers are preparing for agentic AI | 0 | 5 | 29-06-2026 |
| 8 | Singapore: Enforcement Action Against False Origin Declaration | 0 | 10 | 20-07-2026 |
| 9 | Singapore: MAS Publishes AML/CFT Expectations for DPT Service Providers | 0 | 10 | 31-07-2026 |
| 10 | The Agentic Insider: Why AI Tech Stacks Are the Ultimate Insider Threat | 0 | 5.76 | 15-07-2026 |