SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
default, and that security should be addressed holis - tically across the AI system lifecycle. The Guidelines on Securing AI Systems address potential security risks through the AI lifecycle and help to protect AI systems against traditional cybersecurity risks, such as supply chain attacks, as well as novel risks such as Adversarial Machine Learning. Key recommenda - tions include taking a lifecycle approach to consider security risks, starting with a risk assessment. Furthermore, in October 2025, the CSA launched a public consultation on Securing Agentic AI – An Addendum to the Guidelines and Companion Guide on Securing AI Systems. This addendum is meant to be read together with the Guidelines on Securing AI Systems and advises system owners on securing their agentic AI systems. It also outlines how risks can be identified and assessed based on the capabilities of agentic AI systems, and provides practical controls to mitigate relevant risks across the development life - cycle. The Engaging with Artificial Intelligence guide, which was published on 25 January 2024 by the Australian Signals Directorate’s Australian Cyber Security Centre in conjunction with the CSA and other international agencies, also provides organisations with guidance on how to use AI systems securely. The guide sum - marises some important threats related to AI systems and prompts organisations to consider the steps they can take to engage with AI while managing risk. The document provides cybersecurity mitigations to assist organisations that use self-hosted and/or third-party hosted AI systems. A Model Governance Framework for Agentic AI was published by the IMDA on 22 January 2026. The framework provides a structured overview of the risks of agentic AI and emerging best practices in managing such risks. In particular, it highlights that agentic com - ponents are different from simple LLM-based applica - tions and necessitate additional controls throughout the entire lifecycle. In particular, it recommends the following. • Pre-deployment, test agents for safety and secu - rity, eg, test for new dimensions such as overall task execution and tool use accuracy and test at
different levels across varied datasets to capture the full spectrum of agent behaviour. • When deploying, gradually roll out agents and con - tinuously monitor them in production. 6.3 Cybersecurity in the Healthcare Sector While there are no specific cybersecurity obligations pertaining to the healthcare sector, the healthcare sec - tor has been gazetted as one of 11 sectors providing essential services. As such, designated owners of CII (and other designated entities under the Cybersecurity Act) within the healthcare sector are subject to the same requirements as laid out in 2.2 Critical Infra- structure Cybersecurity Requirements . Where applicable, healthcare providers must also comply with the National Telemedicine Guidelines, which include data protection and security require - ments. In so far as a medical device is used by an organisation to collect personal data (eg, device test results are uploaded onto a server owned by the organisation), the organisation must comply with the protection obligation under the PDPA (as described in 6.1 Cybersecurity and Data Protection ). The Cyber and Data Security Guidelines for Health - care Providers (the “Healthcare Guidelines”) provide guidance on the cyber and data security measures to be put in place for the proper storage, access, use and sharing of health information to improve the security posture among healthcare providers. Healthcare pro - viders can also refer to the Cyber and Data Security Guidebook for healthcare providers for explanations and references to resources from the CSA and the PDPC. While not mandatory, the requirements within the Healthcare Guidelines will eventually be imposed as regulatory requirements under the forthcoming Health Information Act. In October 2024, the Cybersecurity Labelling Scheme for Medical Devices (CLSMD), jointly developed by the CSA, the Ministry of Health, the Health Sciences Authority and Synapxe, was launched. Under this vol - untary scheme, medical devices are rated according to four levels of cybersecurity provisions. The label aims to improve security awareness by making the cybersecurity provisions of medical devices more transparent. The CLSMD applies to medical devices
295 CHAMBERS.COM
Powered by FlippingBook