Singapore’s Cybersecurity Agency Updates AI Guidance to Include Key Insights from the OpenPolicy Coalition

August 30, 2026

How can policymakers guarantee that autonomous agents are answerable to human principles, operate within authorized perimeters, and can be effectively identified, governed, and constrained? With the recent publishing of groundbreaking new policy guidance on Securing Agentic AI, Singapore’s Cybersecurity Agency (CSA) is at the forefront of tackling this challenge. Following OpenPolicy’s submission in response to CSA’s draft guidance, we are pleased to share that several of our recommendations were incorporated into the final version.

Since its founding just over a decade ago, CSA has been ahead of the curve on international cyber policy. CSA’s Guidelines and Companion Guide on Securing AI Systems, initially published in 2024, was among the first national-level AI security frameworks.

One year later, recognizing that the threat environment will only continue to progress, CSA began work on an addendum to its AI guidelines focused on securing agentic systems. This project was exceedingly timely: agentic AI’s market size reached USD 7.29 billion in 2025, and is expected to skyrocket to USD 139.19 billion by 2034.

However, this rapid proliferation is currently outpacing the development of necessary safeguards to secure the expanded attack surface. Nearly half of enterprise AI agents run ungoverned, resulting in real consequences for business continuity and data security. 

As OpenPolicy detailed in our recent white paper on agentic AI, existing cybersecurity frameworks and safeguards are based on assumptions that do not hold in the agentic web. Current cyber systems were simply not built with this expanded, unpredictable attack surface in mind. 

CSA’s Agentic AI Addendum to the Guidelines and Companion Guide on Securing AI Systems takes aim at this evolving challenge. Developed in partnership with practitioner communities, the addendum offers actionable, non-mandatory strategies designed to mitigate risk associated with AI agents and secure the environments in which they operate. Looking globally, CSA’s guidance is among the first concrete forays into the agentic AI policy space at the national level.

The OpenPolicy Coalition welcomed the opportunity to collaborate with the CSA and lend our expertise in agentic security, AI governance and cybersecurity to this important document. We are grateful that many of the technical suggestions we advocated for made it into the guidance’s final draft. These changes include: 

Supply chain security (Control 2.1): CSA extended zero-trust input handling to include firmware and hardware, and recommended package hash validation where possible. 

Continuous monitoring and logging (Control 4.3): CSA recommends the addition of key information as a component of agentic logs. Central monitoring and orchestration were also mentioned in Chapter 4.2 (Implementing Controls at Enterprise-scale), which was linked in Control 4.3. 

Authorisation and authentication (Control 2.6): CSA now references NIST’s AI Risk Management Framework (RMF) and Security and Privacy Controls for Information Systems and Organizations (SP 800-53) as technical resources. 

Limit agency (Control 2.7): CSA added “strict access of tools and API only when necessary” when scoping agent privileges.

Environment segmentation (Control 2.9): CSA included our recommendation for continuous update of segmentation policies.

Secure Use of External Tools: CSA added digital signatures and identities in Controls 2.6 (Authoriszation and Authentication) and 4.3 (Continuous monitoring and logging). Cryptographic verification through Mutual TLS is also recommended in Control 3.4 (Secure Inter-Agent Communication).

OpenPolicy extends our gratitude to all of our Coalition members who provided valuable real-world insights and technical expertise during this process. We also commend CSA for championing agentic security and partnering with the practitioner community on this important framework. As governments around the world continue adapting frameworks to reflect the evolving threat landscape, we look forward to offering further collaboration, feedback and direction.

Interested in joining the OpenPolicy coalition as we help shape the future of AI governance frameworks? Contact us for a demo of our platform today. 

Don’t just watch policy happen.

Understand it. Act on it. Build with it.

Request a Demo