← Articles

Articles

Google–Singapore AI Agents Sandbox

The Google–Singapore AI Agents Sandbox was a joint practical trial by Google, CSA, GovTech and IMDA, launched in August 2025 to study computer-use agents in real-world government settings and inform safer development and deployment.

Last verified: 2026-08-31 Status: verified

Google–Singapore AI Agents Sandbox

The AI Agents Sandbox was a joint practical trial involving Google and three Singapore Government agencies: the Cyber Security Agency of Singapore (CSA), the Government Technology Agency (GovTech) and the Infocomm Media Development Authority (IMDA). It launched in August 2025 and studied computer-use agents in real-world settings, with the stated aim of informing how such agents are developed, deployed and governed (IMDA, 20 May 2026).

What the sandbox tested

The trial ran for approximately four months and examined three use cases with different levels of risk exposure. The first was automated quality assurance for government digital services: the agent tested response times, search functions and page integrity, including intentionally seeded inactive pages, filler text and staging-URL mismatches. The second was AI safety testing, where agents performed large-scale testing of chatbot software across languages and formats before deployment. The third was social-assistance applications, where an agent guided applicants or social workers through complex application processes (IMDA, 20 May 2026).

The trial findings show potential, not a guarantee that computer-use agents can replace human staff or operate without controls. IMDA reports that the agent successfully evaluated government websites and that agent-assisted safety testing could reduce manual effort, while also noting that the safety-testing implementation was not error-free. The social-assistance trial demonstrated the ability to guide users through complex processes; the factsheet presents this as potential to reduce assistance and follow-up burdens, not as a launched public entitlement or universal automated service (IMDA, 20 May 2026).

Risks and governance lessons

Common risk themes from the sandbox included human oversight, customisation and control, cybersecurity, and data protection and privacy. IMDA specifically identifies indirect prompt injection as a cybersecurity risk: an agent could be deceived into taking unintended actions, including remote code execution. The factsheet therefore supports controlled testing, incremental deployment and risk-based oversight rather than assuming that an agent should receive unrestricted authority (IMDA, 20 May 2026).

The sandbox also highlighted a systems problem: much digital infrastructure is designed for human users, whereas agentic interaction may require stronger identity, authentication, permission and access-control arrangements. It raised longer-term questions about multi-agent interoperability, privacy-preserving personalisation and the technical limits of screenshot-based perception. These are research and governance considerations, not evidence that Singapore has adopted a general AI-agent licensing regime or a single mandatory technical standard (IMDA, 20 May 2026).

Relationship to other Singapore AI initiatives

The sandbox findings were published as AI Agents Insights and informed a shared Google Whitepaper on AI Agents. The sandbox should be kept separate from the MDDI–Google National AI Partnership, which is a broader announced collaboration with objectives covering public benefit, workforce readiness and a trusted ecosystem. It is also separate from IMDA’s Model AI Governance Framework for Agentic AI and from any specific government digital service: participation by the same companies or agencies does not merge their scopes or create public eligibility (IMDA, 20 May 2026; National AI Partnership with Google; Securing Agentic AI Addendum 2026).

Record details

Also known as
["AI Agents Sandbox","Google AI Agents Sandbox","Singapore Government and Google AI Agents Sandbox","computer-use agents sandbox"]
Jurisdiction
SG

Dates describe this record’s own period and applicability. A verification date does not mean a rule is currently in force.

Sources

Collection as of 2026-10-07 · An expanding collection. Published counts show available knowledge, not complete coverage of Singapore.