← Articles

Articles

Securing Agentic AI Addendum 2026

Singapore's Cyber Security Agency published a 2026 addendum to its Guidelines and Companion Guide on Securing AI Systems, giving system owners agentic-AI risk-assessment methods and practical lifecycle controls for systems that can plan and act with access to tools and data.

Last verified: 2026-09-12 Status: verified

Securing Agentic AI Addendum 2026

Singapore's Cyber Security Agency (CSA) Securing Agentic AI Addendum was published on 17 June 2026 as an addition to CSA's Guidelines and Companion Guide on Securing AI Systems. The addendum is intended for system owners securing agentic-AI systems and is designed to be read alongside the 2024 guidelines and companion guide (CSA, accessed 27 August 2026).

What makes agentic AI a distinct security issue

CSA describes agentic AI as having sophisticated abilities to understand context, formulate plans and take independent actions to achieve specified objectives. Those abilities can increase the potential impact of security failures because an agent may have access to tools and data (CSA, accessed 12 September 2026). The addendum therefore supplements foundational lifecycle security guidance; it is not a new licensing regime or a statement that every AI system is agentic.

The distinction is about system capability and autonomy, not a product label or industry sector. A system owner should first establish what the system can do, which tools and data it can reach, and how an agentic workflow can change outcomes; the addendum’s risk framing is consequently relevant to systems with different levels of autonomy. It should not be applied as proof that an ordinary rules-based application is automatically an agentic system (CSA, Securing Agentic AI Addendum, 17 June 2026).

Risk assessment and lifecycle controls

The addendum explains how system owners can identify and assess risk according to an agentic system's capabilities, including mapping agentic workflows to locate points where threat actors could exploit vulnerabilities. It also provides practical controls to mitigate relevant risks across the development lifecycle, with examples showing how the guidance can apply across different scenarios and levels of system autonomy (CSA, accessed 12 September 2026). CSA developed the publication with industry, government and international partners.

This makes the document a companion for security design and review rather than a one-time pass/fail test. The workflow-mapping approach helps a system owner relate threats to the system’s actual actions, tools and data access, while the lifecycle controls provide considerations for development and deployment stages. The page does not promise that following the examples eliminates risk or that CSA has assessed a particular company’s implementation (CSA, Securing Agentic AI Addendum, 17 June 2026).

Examples and status of the guidance

CSA gives app-development and coding assistants, automated client-onboarding systems and automated fraud-detection systems as example use cases for applying the addendum (CSA, accessed 12 September 2026). The CSA page says the addendum was released on 17 June 2026 to support system owners and records a public consultation conducted from 22 October to 31 December 2025. The page’s release and consultation language should not be converted into a claim that the document is a universal certification, statutory approval or guarantee that a deployment is secure. Organisations should also distinguish this addendum from the foundational 2024 guidelines and companion guide, which remain the documents the addendum is designed to accompany (CSA, Securing Agentic AI Addendum, 17 June 2026).

Record details

Also known as
["Securing Agentic AI Addendum","CSA Agentic AI Addendum","Agentic AI security guidance"]
Jurisdiction
SG

Dates describe this record’s own period and applicability. A verification date does not mean a rule is currently in force.

Sources

Collection as of 2026-10-07 · An expanding collection. Published counts show available knowledge, not complete coverage of Singapore.