SINGAPORE Trends and Developments Contributed by: Sheena Jacob, Sherman Poon and Andre Choo, CMS
Cybersecurity (Amendment) Act 2024 On 31 October 2025, key provisions of the Cyber - security (Amendment) Act 2024 came into force, significantly expanding the operational scope of the Cybersecurity Act 2018. The commencement intro - duced new regulatory regimes for third-party-owned CII, systems of temporary cybersecurity concern, and monitoring powers over licensed cybersecurity ser - vice providers. Provisions relating to entities of special cybersecurity interest and major foundational digital infrastructure service providers remain pending. Under the new regime for third-party-owned CII, organisations relying on CII they do not own must secure upstream commitments from third-party pro - viders, ensuring accountability “through the chain” for outsourced or third-party-hosted critical systems. The regime for systems of temporary cybersecurity con - cern provides targeted intervention during heightened threat periods. Practically, the amendments require organisations to identify non-owned systems critical to essential ser - vices and prepare upstream agreements, implement mechanisms to detect and report prescribed cyberse - curity incidents, and establish procedures to comply with commissioner directions and track evolving legal requirements. Overall, the amendments deepen operational levers for the commissioner and broaden the scope of accountability across third-party infrastructure and high-risk systems. The Digital Infrastructure Act Singapore is preparing a Digital Infrastructure Act (DIA), intended to complement the Cybersecurity Act 2018 by regulating foundational digital infrastructure such as cloud service providers and data centres (see here ). The purpose of the DIA is to improve resiliency and security across systems that underpin the digital economy. While full details and the timing of enact - ment are still evolving, the DIA represents an effort to integrate cybersecurity requirements with resilience and stability obligations for critical digital platforms. In February 2025, the Infocomm Media Development Authority issued advisory guidelines for cloud servic -
es and data centres (see here, here and here ). These guidelines set out recommended measures that cloud service providers and data centre operators in Singa - pore are encouraged to implement to strengthen the resilience and security of their services, reduce the likelihood of service disruptions, and limit potential In October 2025, the Singapore parliament tabled the Online Safety (Relief and Accountability) Bill to establish a new online safety commission with author - ity to tackle harmful online content and behaviours, expanding the regulatory environment around digital harms that also intersect with cybersecurity concerns impacts on the economy and society. Proposed new online safety legislation As organisations deploy AI across operations, cus - tomer engagement, and decision-making, AI systems themselves have emerged as valuable attack targets. Risks include data poisoning, model manipulation, unauthorised access, and exploitation of AI outputs. In 2024, the CSA published Singapore’s Guidelines on Securing Artificial Intelligence Systems to help organi - sations adopt AI in a secure manner (see here and here ). The guidelines lay out the foundational security principles for system owners to secure the use of AI throughout its lifecycle, while the companion guide provides practical measures and controls that system owners may consider when observing the guidelines. In 2025, the CSA released an addendum for public consultation to support system owners in securing agentic AI systems (see here ). This was driven by the emergence of agentic AI, which is able to under - stand context, formulate plans, and autonomously take actions to achieve specified objectives, thereby introducing new risks with potentially greater impact due to its expanded capabilities and access to tools and data. Regulators are increasingly focused on ensuring AI governance frameworks integrate cybersecurity by design rather than as an afterthought. (see here and here ). Securing AI systems
301 CHAMBERS.COM
Powered by FlippingBook