Skip to main content
ObligationGuidance

Perform threat modelling and taint tracing

Is this legally binding?

Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.

Organisations should use threat modelling, and taint tracing for complex multi-agent workflows, to systematically identify how attackers could compromise the system; CSA's Draft Addendum on Securing Agentic AI provides methods.

From the source

Common security threats to agentic systems include memory poisoning, tool misuse, and privilege compromise.

Section 2.1.1, p.10
imda.gov.sgShow it on the map

What this connects to

2 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.

Cites1

Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.