Skip to main content

Singapore's Agentic AI Security Rulebook Is Live. Here's the Five-Question Vendor Test Hiding Inside It

Singapore finalized its Addendum on Securing Agentic AI Systems on 17 June 2026. Its five controls double as the sharpest questions a SOC can put to any AI SOC vendor.

Key takeaways
  • CSA finalized its Addendum on Securing Agentic AI Systems on 17 June 2026; a parallel MAS timetable suggests agentic AI controls become a standard audit question well before 2027.
  • The addendum's five controls double as a vendor checklist: workflow mapping, capability-based risk, human oversight, auditable trails, and data boundaries.
  • Banning agentic AI outright is a weaker audit position than governed deployment — shadow-AI usage plus a ban reads as unmanaged risk on the record.
  • A vendor answering all five questions with evidence, not a roadmap, is necessary but not sufficient — regulatory alignment doesn't guarantee production performance.

Singapore finalized its Addendum on Securing Agentic AI Systems on 17 June 2026, the latest move in a regulatory arc that already includes the world's first dedicated agentic AI governance framework and direct guidance to critical infrastructure owners on frontier AI risk. The addendum sets five practical controls for anyone deploying agentic AI systems. Those same five controls double as the sharpest questions a SOC can put to any AI SOC vendor, including security vendors selling agentic tooling, and for regulated Singapore financial institutions, a parallel MAS timetable suggests "show us your agentic AI controls" becomes a standard audit question well before 2027.

Singapore finished the rulebook before most SOCs deployed an agent

The regulatory arc runs five moves in twenty months. The Cyber Security Agency of Singapore published its Guidelines and Companion Guide on Securing AI Systems in October 2024. Singapore launched the Model AI Governance Framework for Agentic AI at the World Economic Forum on 22 January 2026, described by Hogan Lovells as the world's first dedicated governance model built specifically for agentic AI. In May 2026, the Commissioner of Cybersecurity issued guidance to all critical information infrastructure owners on the security implications of frontier AI. On 17 June, CSA published the finalized Addendum on Securing Agentic AI Systems, following a public consultation that ran from 22 October 2025 to 31 December 2025. And on 30 June, the Singapore Cyber Landscape 2025/2026 report named agentic AI a key driver of risk, warning that autonomous systems can compress attacks "that previously unfolded over days into hours."

The same report found infected infrastructure detected in Singapore rose to 284,300 in 2025, up 142% year over year, while ransomware cases climbed slightly to 165. David Koh, Commissioner of Cybersecurity and CE of CSA, framed the response in the report:

"We need to lock down, find first, and fix fast. We must tighten up and harden systems before threat actors can find footholds… This cycle should be continuous, rather than point-in-time checks."

The addendum itself sets out capability-based risk framing that treats agentic systems differently from assistive models, workflow mapping to surface where autonomy creates exploitable risk points, human-in-the-loop oversight, scenario-based testing, and lifecycle controls, illustrated with worked examples covering coding assistants, automated client onboarding, and fraud detection.

It's worth being direct about the limits here. The addendum is voluntary guidance, not regulation, and frameworks written this early can misfit the technology they're meant to govern within eighteen months. Gartner places AI SOC agents at just 1 to 5% market adoption, which cuts both ways: the rules genuinely arrived before mass deployment, and that is either foresight or a guess made too early to test. The enforcement surface forming around the guidance is real, though. Singapore's Cyber Trust Mark and Cyber Essentials certifications were both expanded in 2025 to include mandatory cloud and AI security requirements, and all CII owners must hold CTM certification by the end of 2027.

Why banning agentic AI won't survive an audit

For Singapore's financial institutions, the shift from voluntary guidance to expected control isn't a prediction, it's a published timetable. The Monetary Authority of Singapore ran a consultation on its Guidelines on AI Risk Management from 13 November 2025 to 31 January 2026. The draft explicitly covers generative AI and autonomous agents, expects boards to maintain a credible AI inventory, and states plainly that relying on a vendor, cloud provider, or open-source model does not reduce the institution's accountability. Once finalized, expected sometime in 2026 with a proposed 12-month transition, the guidelines become supervisory expectations MAS checks during inspections. Malaysia is moving on a parallel, slower track: Bank Negara Malaysia's revised Risk Management in Technology policy, issued 28 November 2025, expanded applicability and heightened cybersecurity controls while explicitly facilitating secure adoption of new technologies.

The propagation path matters more than the MAS timetable on its own. Audit expectations at regulated institutions tend to travel outward through procurement questionnaires and vendor due-diligence templates to everyone else, the same route PDPA and cloud-outsourcing expectations already took. That creates an uncomfortable position for organizations that responded to agentic AI by banning it outright. Verizon's 2026 Data Breach Investigations Report found shadow AI detections rose fourfold in a year, with 45% of employees now regular AI users on corporate devices. IBM's Cost of a Data Breach Report 2025 found organizations with high levels of shadow AI saw roughly $670,000 higher average breach costs, one in five organizations reported a breach involving shadow AI, and only 37% had any policy to manage AI or detect it. A ban plus documented shadow-AI usage reads, on an auditor's page, as an unmanaged risk on the record. Governed deployment with workflow mapping is the more defensible position, and it maps directly onto what the addendum already asks for.

None of this makes prohibition indefensible everywhere. For a low-maturity team without the capacity to govern agentic AI yet, an outright ban is a legitimate interim control while that capacity gets built. The argument here is against treating a ban as a permanent answer, not against using one as triage.

The credibility gap agentic AI security vendors would rather not discuss

Any checklist for evaluating agentic AI lands in a market with a documented trust problem. A March 2026 report by Anton Chuvakin, from Google Cloud's Office of the CISO, and Oliver Rochford, based on more than 30 vendor briefings and interviews with practitioners actually running AI SOC tools in production, concluded that "AI SOC marketing is better understood as prophetic rather than technical." The patterns they documented are specific: deployments stalling at enrichment and summarization rather than full investigation, demo workflows that break on incomplete data, alert-volume reduction that can mask signal suppression instead of better detection, and analyst judgment eroding when confidence-weighted AI output gets treated as authoritative rather than provisional.

Governance data backs up the skepticism. Gravitee's State of AI Agent Security research found only 14.4% of organizations have full security approval for their entire AI agent fleet, and only 37.8% have a named person accountable for agent behavior. One widely circulated practitioner test, run informally and shared on Reddit, pointed an LLM at 348 known false positives plus a single planted true positive; it hit 71% accuracy and missed the real incident. It's colour, not a benchmark, and should be read that way, but it illustrates why "trust the model" isn't an answer regulators or buyers are inclined to accept anymore.

"If low adoption is blamed on user psychology, change resistance, or fear of AI, it's a red flag. A lot of AI products simply aren't enterprise-ready." — Oliver Rochford

Five questions from the regulator, applied to any AI SOC vendor

CSA's addendum was written to help system owners secure their own agentic AI deployments, not as a vendor-evaluation checklist. But the same five controls translate directly into buyer-side questions, and they work on any agentic security tool, including a vendor's own AI agents:

Five questions from the CSA agentic AI security addendum, applied as an AI SOC vendor checklist: map the workflow, assess risk by capability, enforce human oversight, keep auditable trails, control data boundaries
  1. Map the workflow. Can the vendor show, step by step, what its agent does with an alert, and where a threat actor could subvert that flow?
  2. Assess risk by capability. What can the agent actually do: read, recommend, or act? What are the autonomy boundaries, and are there circuit breakers when confidence drops?
  3. Enforce human oversight. Where exactly does a human approve, override, or take over? Is "human-in-the-loop" architecture, or marketing copy?
  4. Keep auditable trails. Can every query, finding, and verdict be reproduced and interrogated after the fact? A real answer sounds like "mean time to verdict reduced to 7 minutes during account hijack triage," not "50% faster investigations."
  5. Control data boundaries. Where does alert data physically go, and under whose jurisdiction?

A tool can answer all five questions and still underperform in production. Regulatory alignment is necessary, not sufficient. But a vendor that can't answer them with evidence, only a roadmap, is telling a buyer something useful before the tool ever gets tested.

Where SQUDO AI answers the checklist

SQUDO AI®, an Agentic AI SOC Platform developed by ITNB AG and deployed in Southeast Asia through Nexulis, is one concrete example of architecture built against these same five questions, not a substitute for asking them of every vendor.

On human oversight: SQUDO AI recommends actions; it does not execute containment unilaterally. Human-in-the-loop is a core design principle rather than a setting that can be toggled off, which answers question 3 directly.

On auditable trails: every investigation produces a structured report with a timeline, the hypothesis evolution, a verdict with a confidence level, MITRE ATT&CK mapping, and a full evidence log, the kind of record that satisfies question 4's reproducibility test rather than a vague speed claim.

On data boundaries: SQUDO AI is deployed on sovereign infrastructure with Swiss and EU data residency by default, which is the architecture question 5 is actually asking, not a checkbox layered on afterward.

In benchmarks, SQUDO AI reduces per-alert investigation time from the 40-minute industry average to 4-10 minutes, the one metric on the facts sheet measured rather than projected, worth naming here because it's the kind of falsifiable claim the checklist rewards over a vague efficiency pitch.

The honest caveat still applies to SQUDO AI as much as to any other vendor in this category: passing five regulator-derived questions is necessary, not sufficient, and the market's credibility problem doesn't resolve itself just because one vendor can answer a checklist. What the addendum offers, and what this piece has tried to use it for, is a way to ask better questions before deployment rather than after an incident. See how SQUDO AI approaches human oversight, audit trails, and data residency on the SQUDO AI product page.

Link copied