Skip to main content
ConceptGuidance

SaaS agentic AI and shared responsibility

Is this legally binding?

Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.

For SaaS agentic AI, detailed threat modelling may be impractical due to limited visibility; organisations should use the Addendum's processes to articulate security concerns to vendors, seek transparency on controls, and apply red teaming. Formal risk acceptance required for unaddressed risks.

csa.gov.sgAddendum, Section 4.1 Risk Management for SaaS EnvironmentsShow it on the map

What this connects to

1 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.

Maps across to1

Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.