Skip to main content
ConceptGuidance

Secure by design and secure by default

Is this legally binding?

Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.

Foundational principle: AI should be secure by design and secure by default, as with all software systems, so system owners manage security risks upstream. Security must be considered holistically at system level.

From the source

“as a key principle, AI should be secure by design and secure by default, as with all software systems”

Guidelines, Section 1 Introduction
csa.gov.sgShow it on the map

Learn this properly

This page tells you what Secure by design and secure by default is and whether it binds you. The AI Governance program teaches the whole discipline, with dedicated coverage of the Singapore governance stack and the MAS regime, and every topic is passed by explaining it back in your own words, graded against the source.

See the AI Governance program

Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.

Useful to someone you work with?

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.