In brief

On 17 June 2026, the Cyber Security Agency of Singapore (CSA) announced its release of the finalised Addendum to the Guidelines and Companion Guide on Securing AI Systems ("Addendum"). This follows the public consultation held by CSA in 2025, which we outlined in our client alert here.

The Addendum was developed by the CSA in collaboration with industry, government, and international partners to support system owners in securing their agentic AI systems. It is designed to be read alongside the Guidelines and Companion Guide on Securing AI Systems.

In detail

Purpose and scope of Addendum

The Addendum curates practical measures and controls that system owners can use to secure their adoption of agentic AI systems. These measures and controls are voluntary, and may not be applicable to all organisations and environments.

The measures and controls within the Addendum address the cybersecurity threats and risks relevant to agentic AI systems. It does not specifically address AI safety, or other common attendant considerations for AI such as fairness, transparency or inclusion. It also does not cover the misuse of AI to conduct cyberattacks and scams.

Security threats to agentic AI systems

Agentic AI systems face both traditional and novel security challenges. There are classical cybersecurity risks, inherited risks from large language model components and new risks specific to agentic AI systems. The two primary risks arising from agentic AI systems are rogue actions and sensitive data disclosure. Rogue actions occur when agents perform unintended or harmful tasks. Meanwhile, sensitive data disclosure occurs when attackers manipulate agents into exposing sensitive information.

Securing Agentic AI

The Addendum builds on the two principles set out in CSA's Guidelines and Companion Guide on Securing AI Systems: (i) taking a lifecycle approach and (ii) starting with a risk assessment. Given the dynamic nature of agentic AI systems, the Addendum adds additional considerations to support the risk assessment. This includes:

  1. Assessing the autonomy level of the system.
  2. Performing threat modelling to identify areas of interest, which will identify where security risks might occur in the system's workflows.
  3. Identifying the risks associated with the agent(s)'s capabilities.
  4. Identifying and implementing additional controls that seek to address risks specific to agentic capabilities, components, and design. For example, for organisations using Software-as-a-Service (SaaS) agentic AI systems, the threat modelling and risk assessment processes outlined in this document will help organisations to articulate specific security concerns to vendors, and seek support on appropriate mitigations or transparency about existing controls.

Key takeaways

The Addendum serves as a useful reference point for organisations securing their agentic AI systems, with practical examples showing how it can be applied across different scenarios and levels of system autonomy. There is no one size fits all solution. Organisations should also continue to periodically re-evaluate the risks posed and consider whether the current controls (e.g., supply chain security, access controls, environment segmentation, input/output validation, model and system hardening, human-in-the loop oversight and continuous logging and monitoring etc., amongst others) implemented remain adequate as AI capabilities evolve and following significant system changes.

Related content

Our previous client alert regarding the public consultation on the Addendum can be accessed here.

© 2026 Baker & McKenzie. Wong & Leow. All rights reserved. Baker & McKenzie. Wong & Leow is incorporated with limited liability and is a member firm of Baker & McKenzie International, a global law firm with member law firms around the world. In accordance with the common terminology used in professional service organizations, reference to a "principal" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as "Attorney Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.

Explore More Insight