Artificial Intelligence 2026

Last Updated May 21, 2026

Singapore

Law and Practice

Authors



Drew & Napier LLC is a full-service Singapore law firm, which was founded in 1889 and remains one of the largest law firms in the country. Drew & Napier has a highly regarded TMT practice group, which consistently ranks as the leading TMT practice in Singapore. The firm possesses unparalleled transactional, licensing and regulatory experience in the areas of telecommunications, technology, media, data protection and cybersecurity. The TMT practice is supported by more than ten lawyers and paralegals with extensive experience in infocommunications, data protection, technology, and sector-specific and general competition law. The TMT practice acts for a broad range of clients, spanning multinational corporations and local companies across industries. These clients include global and regional telecommunications service providers, sectoral regulators (both local and foreign), consultants, software houses, hardware manufacturers and international law firms.

General Legislation and Legal Principles

Organisations must comply with existing Singapore laws when deploying AI technology – for example, laws relating to:

  • safety;
  • IP;
  • personal data protection; and
  • fair competition.

Where the use of AI results in harm, existing legal principles (such as tort liability and contractual liability) will still apply.

AI-Specific Laws

Singapore does not have horizontal, omnibus laws applying the use of AI in general (in contrast to the EU). However, the following laws address specific applications of AI:

  • The Road Traffic Act 1961 was amended in 2017 in order to provide a regulatory sandbox for the trial and use of autonomous motor vehicles, which was previously done by way of exemptions.
  • The Health Products Act 2007 (HPA) requires medical devices incorporating machine learning technology (MLMDs) to be registered before they are used (see 15.3 Healthcare for further details).
  • The Elections (Integrity of Online Advertising) (Amendment) Act 2024 (in force as of 22 January 2025) is the first time the words “artificial intelligence” appeared in Singapore’s legislation – the act bans manipulated online election advertising containing realistic but fake representations of candidates, where generative AI technology is one of the “digital means” by which content could be generated or manipulated.
  • The Workplace Fairness Act 2025 protects against workplace discrimination based on protected characteristics across five categories - including age, nationality, sex, marital status, race, religion, disability and mental health conditions. In so far as AI is concerned, the Minister for Manpower has stated in response to a Parliamentary Question on 13 November 2024 that regardless of the technological tools used to aid employment decisions, such as hiring or promotions, employers must comply with the Tripartite Guidelines on Fair Employment Practices (the “Tripartite Guidelines”). Employers will be held responsible if they engage in discriminatory employment practices.
  • The Criminal Law (Miscellaneous Amendments) Act 2025 updates the Penal Code to facilitate enforcement where generative AI is used to generate entirely synthetic images or videos of a person (without making use of pre-existing images), or produce child abuse materials (whether or not an actual child was involved).
  • The Online Safety (Relief and Accountability) Act 2025 provides for a statutory tort of “inauthentic material abuse” (covering materials generated using generative AI).

Voluntary Guidelines and Testing Frameworks

Singapore also has a set of voluntary guidelines and testing frameworks in place for traditional/predictive AI (which makes predictions based on historical data instead of creating new content), generative AI and agentic AI, as follows.

For traditional/predictive AI:

  • the Model Artificial Intelligence Governance Framework (Second Edition) (the “Model Framework”) issued by the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC) in 2020, which states that the use of AI should be fair, explainable, transparent and human-centric;
  • the Implementation and Self-Assessment Guide for Organisations (ISAGO) – a companion to the Model Framework issued in 2020 – which sets out questions and examples for organisations to rely on when self-assessing how their AI governance practices align with the Model Framework; and
  • the AI Verify Testing Framework (“AI Verify”) – an AI governance testing framework and toolkit rolled out in May 2022, comprising both technical tests and process checks for organisations to assess their AI systems against 11 internationally-accepted AI ethics principles; Singapore aims to align its testing frameworks with the international community’s to reduce compliance costs for organisations to meet the requirements across multiple jurisdictions, and AI Verify has since been mapped to the US National Institute of Standards and Technology’s AI Risk Management Framework in October 2023 and the ISO/IEC 42001:2023 (the first international standard on the responsible adoption of AI within organisations) in June 2024.

For generative AI:

  • the IMDA paper, titled “Generative AI: Implications for Trust and Governance”, issued in June 2023, outlining six key risks brought about by generative AI and measures to address them;
  • the IMDA paper, titled“Cataloguing LLM Evaluations”, issued in October 2023, addressing baseline standards for evaluating large language models (LLMs);
  • the Model AI Governance Framework for Generative AI (the “Model Gen-AI Framework”) ‒ setting out nine dimensions to build trustworthy generative AI, as well as the actions the industry and policymakers must take to achieve this goal ‒ was released on 16 January 2024 for public consultation up to 15 March 2024 and was finalised on 20 May 2024;
  • “Project Moonshot”, one of the world’s first LLM evaluation toolkits to address security and safety challenges of LLMs, developed by the AI Verify Foundation, with curated benchmarks (similar to “exam questions”) for organisations to test their model across a variety of competencies (eg, summarisation, language, context), as well as modules for manual and automated red-teaming (adversarial attacks on the model) to flush out vulnerabilities in the LLM; and
  • the "Starter Kit for Testing LLM-Based Applications for Safety and Reliability", published by the IMDA in January 2026, consolidating best practices from industry and government when testing generative AI applications for five common risks: hallucination and inaccuracy, bias in decision-making, undesirable content, data leakage and vulnerability to adversarial prompts.

For agentic AI:

  • a discussion paper as well as guidelines (issued by the Cybersecurity Agency of Singapore (CSA) in October 2025) on securing agentic AI systems ; and
  • the Model AI Governance Framework for Agentic AI (issued by the IMDA in January 2026), setting out practical steps for organisations to manage the risks of agentic AI which now has the additional capability to plan and execute tasks without constant human intervention.

Guidance Notes

Regulators also issue guidance notes to organisations, such as the following ‒ of which, the first three are for general application, and the final three apply to specific industries.

  • The PDPC released the Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (the “PDPC AI Advisory Guidelines”) in March 2024, following a public consultation in July 2023.
  • The Intellectual Property Office of Singapore (IPOS) issued the IP and Artificial Intelligence Information Note to provide an overview of how AI inventions can receive IP protection, as well as three guidance infographics on IP issues arising from AI training and output.
  • The CSA released the Guidelines and Companion Guide on Securing AI Systems on 15 October 2024, which set out best practices for owners of AI systems to adopt to secure their AI systems at every stage from designing and deployment to disposal at the end of the life cycle.
  • The Ministry of Law launched the Guide for Using Generative Artificial Intelligence in the Legal Sector on 6 March 2026, setting out expectations on professional ethics, confidentiality and transparency.
  • The Monetary Authority of Singapore (MAS) released the Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore’s Financial Sector for voluntary adoption by firms providing financial products and services.
  • The Ministry of Health (MOH) and the Health Sciences Authority (HSA) co-developed the Artificial Intelligence in Healthcare Guidelines (Version 2.0) to set out good practices for AI developers, deployers and users, and complement the HSA’s regulation of MLMDs.

AI is deployed widely across industries in Singapore, from finance and healthcare to food service in restaurants. AI-enabled tools are also integrated into educational curriculums. The revised National AI Strategy (NAIS 2.0) encourages AI innovation and adoption across all sectors, with a focus on manufacturing, financial services, transport and logistics, and biomedical sciences.

The IMDA/PDPC have also published a Compendium of AI Use Cases (in two volumes) to demonstrate how the Model Framework’s AI governance principles have been applied by organisations.

Singapore has invested SGD70 million in the National Multimodal Large Language Model Programme, producing two national LLMs: MERaLiON and SEA-LION, which are adapted to the unique linguistic and cultural contexts of Singapore and the Southeast Asian region.

In the 2026 Budget speech, the government aimed to harness AI as a “strategic advantage” to address Singapore's structural constraints. Key measures announced included:

  • National AI Council: A new National AI Council, chaired by the Prime Minister and comprising key Cabinet ministers, tasked with providing strategic direction for Singapore's AI agenda, overseeing National AI Missions in four priority sectors (advanced manufacturing, connectivity and logistics, finance, and healthcare), and aligning the government's R&D, regulatory and investment promotion efforts.
  • Tax incentives: The Enterprise Innovation Scheme (EIS), which provides 400% tax deductions on qualifying innovation expenditures, will be expanded to include AI expenditures for Years of Assessment 2027 and 2028, subject to a cap of SGD50,000 per Year of Assessment.
  • Worker upskilling: Singaporeans enrolling in selected AI training courses will receive six months of free access to premium AI tools.

Singapore’s approach to regulating AI is that of “agility”, as set out in NAIS 2.0. Singapore’s priority is to deepen understanding of AI and discover and address its potential risks. At present, existing laws can cover its use and regulators will issue guidelines to organisations so that they have a clearer picture of how to conduct their affairs.

However, the government will enact legislation if it is necessary to do so, and this will be done “thoughtfully and in concert with others, accounting for the global nature of AI” (NAIS 2.0). The approach is dependent on the nature of the risk to and from AI, where some cases are best settled by voluntary guidelines, and others by legislation. Singapore has enacted legislation concerning specific applications of AI (see 1.1 General Legal Background), but has no immediate plans to enact omnibus legislation governing the use of AI across multiple sectors.

Singapore’s approach to AI so far has been to issue voluntary guidelines and guidance notes to aid industries in navigating this new technology and set out best practices. Guidelines are suitable for an area in which change is rapid, as they can be amended and issued quickly.

As mentioned in 1.1 General Legal Background, Singapore has not yet enacted legislation that regulates the use of AI in general. However, there is legislation that concerns specific applications of AI, namely:

  • digitally manipulated content in elections;
  • deepfakes (especially in the case of intimate images and child abuse materials);
  • autonomous vehicles (AVs) (see 15.4 Autonomous Vehicles); and
  • MLMDs (see 15.3 Healthcare).

Please refer to 1.1 General Legal Background for the key jurisdictional directives.

This is not applicable in Singapore.

This is not applicable in Singapore.

In relation to personal data that is used to train AI systems or that is processed by AI systems, Singapore’s Personal Data Protection Act 2012 (PDPA) will apply for private sector data. The PDPC has also issued its first PDPC AI Advisory Guidelines to set out best practices for organisations developing or deploying AI systems.

In relation to copyright issues arising from the use of data to train AI systems, Singapore has a computational data analysis exception under Section 244 of the Copyright Act 2021, which was introduced after a public consultation in 2019. This is independent of the fair use exception under Section 190 of the Copyright Act 2021. For more details, please refer to 16.3 Copyright and AI Training Data.

Please refer to 3.1 General Approach to AI-Specific Legislation.

Singapore does not yet have reported decisions on the use of AI and the surrounding IP rights. However, Singapore’s Court of Appeal has issued a key decision on the use of deterministic algorithms in contracting.

In Quoine Pte Ltd v B2C2 Ltd (2020), transactions on Quoine’s cryptocurrency exchange platform were conducted by algorithms for both Quoine and B2C2, with the algorithms giving trading instructions based on observations of market data. Owing to an oversight, Quoine failed to make certain changes to several critical operating systems on its platform, so it could not generate new orders. It is relevant that B2C2 had – back when designing its algorithm – set a virtual price of 10 Bitcoin for 1 Ethereum in the event that there was insufficient market data from Quoine to draw upon in order to price its trades.

Quoine’s oversight sparked off a chain of events that triggered buy orders for Ethereum being placed on behalf of some platform users – at 250 times the going market rate for purchasing Ethereum with Bitcoin – in favour of B2C2. This was the virtual price B2C2 had set to sell its Ethereum. Quoine cancelled the trades when it realised this and B2C2 sued Quoine as a result. Quoine argued that the contracts were void/voidable for unilateral mistake. It is important to note that all the algorithms functioned as they should and that the cause was actually human error.

The court described a deterministic algorithm as one that “will always produce precisely the same output given the same input”, where it “will do just what it was programmed to do and does not have the capacity to develop its own responses to varying conditions” and “hence, faced with any given set of conditions, it will always respond to that in the same way” (Quoine at (15)). The court held that where contracts are made by way of deterministic algorithms, in order to determine knowledge, the court would refer to the state of mind of the algorithm’s programmers from the time of the programming up to the point that the relevant contract is formed (see Quoine at(97) to (99)). The court upheld the contract, as it found that the programmer did not have actual or constructive knowledge of Quoine’s mistake, and hence did not unconscionably take advantage of it.

It would be interesting to see whether the same principles would apply in the case of a non-deterministic algorithm, as the outcome may not always be known and the computer could be said to “have a mind of its own” (see Quoine at (185)), or if there are multiple programmers – given that, in Quoine, the software used by B2C2 was devised almost exclusively by one of the founders.

Aside from Quoine, there are now several judicial decisions concerning the use of AI-generated output by lawyers and litigants that is incorrect (eg, the cases cited do not exist).

All ministries and statutory boards have a part to play in developing Singapore’s use of AI. The following is a non-exhaustive list of key regulatory agencies.

  • The Smart Nation and Digital Government Office (SNDGO) is under the Prime Minister’s Office, where it plans and prioritises key national projects and drives the digital transformation of the government. The SNDGO issued the National AI Strategies.
  • The Government Technology Agency (“GovTech”) is the implementing arm of the SNDGO and it develops products for the public and government, in addition to managing cybersecurity for the government.
  • The IMDA regulates the infocommunications and media sectors and drives Singapore’s digital transformation. The PDPC is part of the IMDA and it implements policies to balance the protection of an individual’s personal data with organisations’ need to use it.
  • The IPOS has initiated fast-track programmes for patent protection and copyright protection to support AI innovation.

Other bodies have also been set up that will complement the work of the regulatory agencies.

  • A new National AI Council (See 2.2 Involvement of Governments in AI Innovation).
  • AI Singapore, a national programme comprising a partnership between various government agencies (eg, the IMDA, Enterprise Singapore and the SNDGO) and academia, was launched in May 2017 to accelerate AI adoption by industry.
  • The AI Verify Foundation, a non-profit that is a wholly owned subsidiary of the IMDA, was launched in June 2023 to create a global open-source community to contribute to the use and development of AI testing frameworks, code base, standards and best practices. It has more than 100 corporate members ranging from multinational technology companies to banks and e-commerce companies.

Generally, Singapore’s regulatory agencies seek to build public trust in the use of AI and minimise the risks posed by AI. They do this by ensuring that:

  • the decision-making process is explainable, transparent and fair when AI is used to make decisions;
  • AI solutions are human-centric (ie, promote the well-being and safety of humans); and
  • there is accountability for all players in the AI development chain so that they are responsible towards end-users.

Singapore’s regulatory agencies frequently hold public consultations on their draft AI guidelines before releasing the finalised version incorporating the public feedback. For example, the CSA held a public consultation on securing AI systems between July and September 2024, before releasing the finalised guidelines in October 2024. The PDPC also held a public consultation from July to August 2023 before releasing the PDPC AI Advisory Guidelines in March 2024.

Enforcement action in Singapore presently concerns the use of generative AI without verifying the output. Both lawyers and litigants have been reprimanded by the court, and in some cases, made to pay personal costs.

Enterprise Singapore oversees the setting of standards in Singapore through the industry-led Singapore Standards Council (SSC).

On 31 January 2019, Enterprise Singapore published a Technical Reference for Autonomous Vehicles, known as “TR 68”. This was born out of a year-long industry-led effort administered by the SSC’s Manufacturing Standards Committee. The TR 68 was intended to set a provisional national standard to guide the industry in the development of fully autonomous vehicles. In 2021, following a review by the Land Transport Authority and the SSC, TR 68 was updated to include guidelines on the application of machine learning, software updates management, cybersecurity principles and testing framework.

The SSC has also published TR 99:2021, which provides guidance for assessing and defending against AI security threats.

In July 2025, the SSC elevated the Data Protection Trustmark to a new Singapore Standard (SS 714:2025), setting requirements for data protection governance including third-party management and overseas data transfers – both key risk areas in AI development and deployment.

Singapore actively participates in standard-setting and norm-shaping processes with key international organisations and standard-setting organisations such as the World Economic Forum, the OECD, the International Organisation for Standardisation (ISO), and the International Electrotechnical Commission (IEC).

AI Singapore (see 5.1 Regulatory Agencies) also actively participates in international standards bodies. In 2019, the AI Technical Committee (AITC) was formed to recommend the adoption of international AI standards for Singapore and support the development of new AI standards. To date, the AITC has contributed to the development and publication of two standards:

  • ISO/IEC TR 24030:2021 Information Technology – Artificial Intelligence (AI) – Use Cases; and
  • Singapore Standards TR 99:2021 Artificial Intelligence (AI) security – Guidance for assessing and defending against AI security threats.

In May 2025, the IMDA released an updated AI Verify framework extended to cover generative AI risks, accompanied by a new crosswalk against the NIST AI Risk Management Framework: Generative AI Profile (NIST AI 600-1), reducing duplicative compliance effort for companies operating in both Singapore and the United States.

Singapore has also introduced Singapore Standard SS ISO/IEC 42001:2024 Information technology – Artificial Intelligence – Management System – an identical adoption of ISO/IEC 42001:2023, with a national Annex describing AI Verify as an example of a voluntary testing tool to align AI systems with the standard. A further new international standard ISO/IEC 42119-8 was introduced in April 2026 to standardise the testing of generative AI systems.

Across the Singapore government, AI solutions are being adopted, including the following.

  • The MAS is using machine learning models to analyse market trading data in order to identify potential instances of market collusion or manipulation for further investigations.
  • The Singapore Police Force partnered with the National Crime Prevention Council and GovTech to combat scams through the development of the “Scamshield” application, which uses AI to filter scam messages through the identification of keywords and blocks calls from blacklisted numbers.
  • The Land Transport Authority (LTA) uses AI to analyse footage from bus cameras to detect vehicles that encroach into bus lanes during operation hours.

The government also launched "Pair", a government AI chatbot assistant for public officers powered by LLMs, contextualised for Singapore government use cases. Pair speeds up tasks such as writing emails, research and idea generation, and has recorded over 11,000 users across 100+ agencies within its first two months.

The Singapore Courts are using AI to improve access to justice, working with Harvey.AI, an American start-up, to trial its technology to assist litigants-in-person at the small claims tribunal. In April 2025, they launched the first initiative offering AI-powered translation services for court users, where court documents will be translated into Chinese, Malay or Tamil from English. On 10 September 2025, they announced a generative AI tool that summarises case documents for Tribunal Magistrates and self-represented persons, providing factual summaries without offering case-specific legal advice.

The Singapore Courts have also issued the “Guide on the Use of Generative Artificial Intelligence Tools by Court Users”, effective 1 October 2024, and applying to both lawyers and self-represented persons. The courts do not prohibit the use of generative AI tools to prepare court documents, provided that the aforementioned guide is complied with. Users are expected to check and verify the AI-generated content, and responsibility for any AI-generated content (including infringements of personal data laws or IP laws) rests with the user. The court does not require a pre-emptive declaration of the use of generative AI, but court users are expected to answer truthfully if asked about such use by the court.

The Ministry of Defence and the Singapore Armed Forces (SAF) have been exploring the use of AI in military operations to enhance capabilities and stay ahead of potential security threats. One such example is the upgraded command and control information system that helps commanders make faster decisions through displaying a real-time battlefield picture integrated with the best options commanders can take to neutralise the threat. Additionally, to better utilise manpower, the SAF is also conducting trials on the use of AVs in military camps for the unmanned transportation of supplies and personnel.

For the discussion of IP issues, see 16.3 Copyright and AI Training Data, and for data protection issues, see 17.1 AI Training and Data Protection.

The Singapore Academy of Law released (in September 2024) a guide on prompt engineering for lawyers, giving lawyers tips and concrete examples on how to write more effective prompts for chat-based generative AI tools. The Singapore Courts have also issued guidance on the use of generative AI in preparing court documents (see 7.2 Judicial Decisions for details).

Following a public consultation in September 2025, the Ministry of Law launched the Guide for Using Generative AI in the Legal Sector on 6 March 2026. (See 1.1 General Legal Background).

General Considerations

Where the use of AI gives rise to personal injury, property damage or financial loss, the claimant can seek a remedy in tort (negligence) or contract. Singapore does not have product liability laws like those in the UK or the EU. Instead, remedies are available under statutes such as the Unfair Contract Terms Act 1977 and the Sale of Goods Act 1979, as well as specific legislation (eg, the HPA) and the common law (contract and tort).

Singapore has not amended its laws to provide for any special rules concerning liability arising from the use of AI. As yet, there have been no cases in court involving damages due to AI not performing as expected.

There are three features of AI that may affect the application of conventional principles of liability, as follows.

  • AI is a “black box” – it is not always possible to explain how or why an AI system reached a particular outcome and the type of model chosen affects how easily its workings can be explained.
  • AI is self-learning/autonomous – it has the ability to learn from the data it has been exposed to during its training and improve without being explicitly programmed, meaning the behaviour of the AI system is not always foreseeable.
  • AI has many people involved in its development – from procuring the datasets, to training the algorithm, to selecting the algorithm, to monitoring the performance of the algorithm. So who is to blame when the AI output is not as expected or causes harm?

Fault-Based Liability (Negligence)

Negligence requires that:

  • someone owes a duty of care;
  • there is breach of such duty (falling below the standard of care); and
  • the breach causes a loss.

Owing to the nature of AI, where many people are involved in its development, the plaintiff might find it difficult to identify the party at fault and the identified party could try to push the blame to a party upstream or downstream in the AI life cycle. However, the Model Gen-AI Framework suggests that liability could be allocated based on the level of control that each stakeholder has in the AI development chain.

Next comes the requirement to prove breach of the standard of care. However, if the opacity of AI makes it impossible to explain why it reached a particular outcome, then it may be difficult to prove that the behaviour of the AI was due to a defect in the code (rather than any other reason). As the use of AI is developing, it is not clear what standard of care will apply either. Furthermore, even where there is a human in the loop to review the outcome of the AI system, the human will not be able to determine whether the AI is making an error in time to prevent it if the AI is meant to exceed human capabilities.

Finally, there is a requirement to show that the breach caused the loss. Even though it could be argued that the autonomous nature of AI breaks the chain of causation, such an argument is unlikely to be accepted on public policy grounds. In contrast with the EU’s proposed AI Liability Directive (which has since been withdrawn in 2025), Singapore has not introduced any laws that introduce a rebuttable presumption of causality between the defendant’s fault and the damage resulting from the AI system’s output (or failure to produce one).

Contract Liability

With a contract, parties negotiate to pre-allocate the risk, so this may resolve some of the issues faced in tort regarding who is the responsible party. However, establishing whether there is a breach will depend on what parties have agreed to in the contract – for example, whether there are specific, measurable standards the AI system must meet.

Liability Independent of Fault (Strict Liability/Product Liability)

As mentioned previously, Singapore does not have product liability laws like those in the UK and EU. Nevertheless, the Singapore Academy of Law’s Law Reform Committee considered the application of those laws in its Report on the Attribution of Civil Liability for Accidents Involving Autonomous Cars (published September 2020) and found that product liability presents the same difficulties as negligence because the claimant generally still has to show some fault on the manufacturer’s part (ie, prove there is a “defect” with the software) (see (5.17)–(5.18) of the aforementioned report).

Whether there will be strict liability imposed for damage arising from the use of AI remains to be seen, as policymakers must strike a balance between ensuring that innovation is not stifled and obtaining a remedy with ease.

In May 2026, the Ministry of Transport commenced a public consultation on the regulatory and legal framework for AVs.

The Singapore Academy of Law’s Law Reform Committee has issued two reports that make recommendations on the application of the law to robotic and AI systems in Singapore, namely:

  • Criminal Liability, Robotics and AI Systems (February 2021); and
  • The Attribution of Civil Liability for Accidents Involving Autonomous Cars (September 2020).

Please refer to 1.1 General Legal Background.

Please refer to 10.1 General Theories of Liability as the principles apply equally to agentic AI.

The Model Framework highlights the risk of “bias” in the data used to train the AI model and proposes some solutions to minimise it. The IMDA/PDPC acknowledge the reality that virtually no dataset is completely unbiased; however, where organisations are aware of this possibility, it is more likely that they can take steps to mitigate it. Organisations are encouraged to collect data from a variety of reliable sources and to ensure that the dataset is as complete as possible. It is noted that premature removal of data attributes may make it difficult to identify inherent biases in the data.

In addition, the model should be tested on different demographic groups to see if any groups are being systematically advantaged or disadvantaged. Running through the questions in the ISAGO or AI Verify will also help organisations to reduce bias in the AI development process. In relation to LLMs, the IMDA’s October 2023 paper on “Cataloguing LLM Evaluations” sets out recommended evaluation and testing approaches for bias, as does its January 2026 paper “Starter Kit for Testing LLM-Based Applications for Safety and Reliability”.

There have not been any reported regulatory actions or judicial decisions with regard to algorithmic bias in Singapore.

Generally, biometric data such as fingerprints and likeness – when associated with other information about an individual – will form personal data under the PDPA. As such, any organisation that collects, uses or discloses such data will be subject to the obligations under the PDPA.

The PDPC has released the Guide on Responsible Use of Biometric Data in Security Applications. This guide specifically addresses:

  • the use of biometric data in relation to security cameras and CCTVs for security monitoring; and
  • facial or fingerprint recognition systems for security purposes to control movement in and out of premises.

It highlights certain risks of using such data (eg, identity spoofing, errors in identification where the threshold for matching is set too high or too low) and measures that organisations may implement to mitigate the risks.

Singapore has enacted several laws to specifically target deepfakes and synthetic media (see 1.1 General Legal Background). For example:

  • The Elections (Integrity of Online Advertising) (Amendment) Act 2024 bans AI-generated or manipulated content in online election advertising.
  • The Criminal Law (Miscellaneous Amendments) Act 2025 accounts for technological advances, making it clear that undesirable images are not only those created by altering existing images or recordings, but can also be completely synthetically generated. It criminalises the production of AI-generated intimate images without consent and child abuse material.
  • The Online Safety (Relief and Accountability) Act 2025 creates a statutory tort of “inauthentic material abuse”. This covers the communication of inauthentic material of a victim that a reasonable person would conclude is likely to cause the victim harassment, alarm, distress or humiliation because it is false or misleading. The victim may bring civil proceeding against a person who communicates that material, as well as against administrators of online locations and online service providers.

The Model Framework encourages organisations to disclose their use of AI so that persons are aware that they are interacting with it and, in particular, to:

  • explain how AI is used in the decision-making process and what factors are taken into account in making the decision;
  • offer an option to opt out from the use of AI, if it is feasible to so; and
  • allow affected persons to appeal against an AI decision that materially affects them ‒ the person should be given enough information about the reasons for the previous decision so that the person can effectively craft their appeal.

The ASEAN Guide on AI Governance and Ethics recommends that deployers who procure AI systems from third-party developers should “appropriately govern their relationships with these developers through contracts that allocate liability in a manner agreed between parties”. The deployer should also require the developer to assist it in meeting its transparency and explainability obligations to both customers and regulators. The ASEAN Guide also recommends that deployers and developers collaborate to conduct joint audits and assessments of the AI system, and testing frameworks such as Singapore’s AI Verify may be used for this purpose.

This is reinforced in the Model Governance Framework for Agentic AI, where organisations are reminded to clarify the distribution of obligations in contracts between themselves and any third party assisting them with deploying agents – “In particular, organisations should consider provisions to address any security arrangements, performance guarantees, or data protection and confidentiality. Where there are gaps, the organisation should reassess if the agentic deployment meets its risk tolerance.”

Please refer to 13.1 AI Procurement Standards and Contracting. In general, companies will allocate their responsibilities in contract. The contractual terms (such as indemnities and performance guarantees – eg, 80% accuracy, responsibility to monitor the AI system’s output) will depend on their bargaining power.

The Tripartite Guidelines set out fair employment practices for employers to abide by. Employees must be selected on the basis of merit (ie, skills and experience), regardless of their age, race, gender, religion, marital status and family responsibilities, or disability. Therefore, automated employment screening tools must not take into account such characteristics (with the exception of gender where it is a practical requirement of the job – for example, hiring a female masseuse to do spa treatments for female customers).

In October 2025, The Tripartite Alliance for Fair and Progressive Employment Practices (TAFEP) published guidance specifically addressing AI in hiring (“Fair Hiring First, AI Second”), affirming that employers – not algorithms – remain accountable for hiring decisions, and that all hiring decisions (whether or not AI is used) must be anchored in the Tripartite Guidelines and the Workplace Fairness Act.

The Ministry of Manpower (MOM) can take action against employers who do not follow the Tripartite Guidelines by curtailing their work pass privileges, preventing them from applying for new work passes or renewing the work passes of their existing employees. Singapore also passed the Workplace Fairness Act on 8 January 2025, to complement the existing Tripartite Guidelines. The act is expected to take effect at the end of 2027.

Although organisations will require consent to collect, use or disclosepersonal data, they may also rely on two exceptions under the PDPA to do so without obtaining consent from the individual. However, the organisation must still act based on what a reasonable person considers appropriate in the circumstances – it does not have carte blanche to collect every single piece of personal data about an employee through its employee monitoring software. This is because the employer’s monitoring of the employee’s email account, internet browsing history, etc, can reveal very private information about the employee, including private medical information that may not be relevant to the employee’s workplace performance.

  • The first exception is where the collection, use or disclosure of personal data is for the purpose of managing or terminating an employment relationship between the organisation and the individual. However, to rely on this exception, the organisation must inform its employees of the purposes of such collection, use or disclosure ‒ for example, through the employment contract or employee handbooks.
  • The second exception is where the collection, use or disclosure of personal data about an individual is necessary for evaluative purposes (ie, for determining the suitability or eligibility of the individual for employment, promotion, or continuance in employment).

Although consent may not be needed to collect such data, organisations should be aware that other obligations under the PDPA – for example, the protection obligation to prevent unauthorised access to the data – continue to apply.

A Parliamentary question of 12 September 2022 concerned whether the government will:

  • consider regulating platform companies to ensure they do not encourage excessive risk-taking (eg, taking on too many jobs in an hour or riding during dangerous weather) by the workers to fulfil orders; and
  • study the AI and algorithms used by such companies to ensure this is not the case.

The MOM responded that it will be “cautious” about regulating the incentives and algorithms used by such companies. The MOM would resolve the issue through discussions with tripartite partners and strengthening protections for workers, “rather than jump to regulation and risk over-regulation”.

The government has since accepted the recommendations of the Advisory Committee on Platform Workers in November 2022, thereby strengthening protections for platform workers in terms of:

  • financial protection in case of work injury;
  • improving housing and retirement adequacy; and
  • enhancing representation for such workers.

The Platform Workers Act 2024 was subsequently introduced to implement the recommendations of the Advisory Committee.

MAS Guidance

Firms that use AI and data analytics to offer financial products and services should reference the following guidelines published by MAS:

  • Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore’s Financial Sector (2018);
  • Information Paper on Artificial Intelligence Model Risk Management (December 2024);
  • Draft Guidelines on Artificial Intelligence Risk Management for Financial Institutions (released for public consultation from November 2025 to January 2026).

They may also reference the white papers that MAS has published with the industry under the Veritas Initiative and Project Mindforge.

Digital Advisers

Digital advisers (or robo-advisers) are automated, algorithm-based tools with limited or no human adviser interaction. Where such tools are used to provide advice on investment products, the MAS Guidelines on Provision of Digital Advisory Services state that they should minimally provide the client with the following information:

  • assumptions, limitations and risks of the algorithms;
  • circumstances under which the digital advisers may override the algorithms or temporarily halt the digital advisory service; and
  • any material adjustments to the algorithms.

As mentioned in 1.1 General Legal Background, the HPA requires medical devices to be registered. MLMDs are a type of “medical device” (as defined in the HPA) – hence they must be registered – and they are subject to further requirements for registration by the HSA’s Regulatory Guidelines for Software Medical Devices including Machine Learning-Enabled Medical Devices (Dec 2025). Under these guidelines, additional information must be submitted when registering the MLMD – for example, information on the datasets used for training and testing and a description of the machine-learning model that is used in the MLMD.

Singapore’s Road Traffic Act 1961 provides a regulatory sandbox for the use and testing of AVs – see Sections 2(1), 6C, 6D and 6E, and the Road Traffic (Autonomous Motor Vehicles) Rules 2017 (the “Rules”). The Rules prohibit the trial or use of an AV without authorisation and, among other things, set out:

  • the application process for authorisation;
  • the conditions of authorisation (eg, requiring a qualified safety driver to be seated in the AV to monitor its operation and take over if necessary);
  • that a data recorder must be installed in the AV;
  • that there must be liability insurance or security in lieu of liability insurance; and
  • that any incident or accident involving the AV must be reported to the Land Transport Authority.

In May 2026, the Ministry of Transport commenced a public consultation on the proposed legal and regulatory framework for AVs in Singapore, covering four critical areas:

  • responsibility and accountability of key players in the AV ecosystem, namely (a) the entities in-charge of AV technology, (b) fleet operators, (c) onboard safety operators, and (d) remote operators;
  • compensation and insurance;
  • data and cybersecurity management; and
  • liability issues when accidents happen during the handovers between the human drivers and conditional automated systems.

The Competition and Consumer Commission of Singapore (CCS), in collaboration with the IMDA, launched the AI Markets (AIM) Toolkit in September 2025. This is a voluntary self-assessment tool for AI model developers and deployers to assess their compliance with the Competition Act 2004 and the Consumer Protection (Fair Trading) Act 2003 (CPFTA).

In 2025, the CCS took action against a company under the CPFTA for posting fake 5-star reviews about its business on Sgcarmart.com. The company had used ChatGPT to generate the reviews, and then posted the reviews using its customers’ details without their consent. The company gave undertakings to remove the fake reviews, notify the affected customers and publish notices on the same forums online that it had posted fake reviews.

Please see 1.1 General Legal Background where sector-specific legislation and guidelines will apply.

Protecting AI Innovations Through Patents

Under Section 13 of the Patents Act 1994, an invention must fulfil the following three conditions to be patentable:

  • the invention must be new;
  • the invention must involve an inventive step; and
  • the invention must be capable of industrial application.

However, not all inventions are eligible for patent protection (even if they meet the three conditions). The Examination Guidelines for Patent Applications of the IPOS are instructive. Neural networks, support vector machines, discriminant analysis, decision trees, k-means and other such computational models and algorithms applied in machine learning are mathematical methods in themselves and are thus not considered to be inventions by the IPOS.

However, where the claimed subject matter relates to the application of a machine-learning method to solve a specific (as opposed to a generic) problem, this could be regarded as an invention because the actual contribution of the claimed subject matter goes beyond the underlying mathematical method. Solving a generic problem by using the method to control a system, for example, is unlikely to cross the threshold. The application must be a specific one, such as using the method to control the navigation of an AV.

Protecting AI Innovations Through Copyright

Source codes and AI algorithms are protected by copyright.

Protecting AI Innovations Through Trade Secrets

AI innovations may also be protected under the law of confidence, as set out in the IPOS's IP and Artificial Intelligence Information Note. Generally, confidential information refers to non-trivial, technical, commercial or personal information that is not known to the public, whereas trade secrets usually describe such information with commercial value.

Information will possess the quality of confidence if it remains relatively secret or inaccessible to the public in comparison with information already in the public domain. Therefore, it is important to secure the confidential information by:

  • implementing non-disclosure agreements;
  • encrypting materials; and
  • classifying information so as to limit access to only select groups of people.

However, it is not possible to protect an AI innovation under both patent and the law of confidence because the former requires public disclosure, which destroys the quality of confidence. Therefore, when deciding which regime to use to protect their work, AI innovators should consider whether the invention constitutes patentable subject matter and if the invention is likely to be made public soon or can be easily derived by others through reverse engineering.

This is a developing area of law both overseas and in Singapore. IPOS has issued a guidance note on “How does Singapore law treat AI-generated content?”.

In relation to copyright, the current position under the Copyright Act 2021 is that the author must be a natural person. Hence, whether copyright can subsist in the output of generative AI is likely to depend on two factors:

  • the extent to which the human involved in prompting the generative AI exercised creativity in the prompting process and the subsequent editing of the output; and
  • the nature of the output of the generative AI (as not all works are by their nature protected by copyright).

In relation to patents, the inventor must also be a natural person under Singapore law. As with copyright, the output may be protected depending on the level of involvement of the human who prompted the generative AI.

Use of Copyrighted Content to Train a Generative AI System

In Singapore, under Section 244 of the Copyright Act 2021, making a copy of any copyrighted work is permissible if it is for the purpose of:

  • computational data analysis (as defined in Section 243 of the Copyright Act 2021 – eg, using images to train a computer program to recognise images) or
  • preparing the work for computational data analysis, provided that certain conditions are met.

Singapore also has the fair use exception under Section 190 of the Copyright Act 2021. Both Sections 190 and 244 of the Copyright Act 2021 have not yet been tested in Singapore courts in the context of training generative AI systems.

Liability for Copyright Infringement in AI Outputs

This is still a developing area of law. IPOS has issued guidance on “How does Singapore law treat AI-generated content that may infringe copyright?”, with different considerations for users and developers/deployers. Factors that would lower infringement risk would be to:

  • create output in a generic style rather than replicate specific works (for users); or
  • have guardrails to prevent models from reproducing existing copyrighted works (developers).

See 16.2 AI as Inventor/Author.

The Model Gen-AI Framework proposes a “shared responsibility” approach, where liability can be allocated based on each stakeholder's level of control in the development chain. Where open-source or open-weights models are used, application deployers have more control over the model (including the ability to modify it), and should only download models from reputable platforms to minimise the risk of tampered models. In contrast, with closed-source models, the model developer has more control as they do not disclose the weights, and access is often via the application programming interface (API) only.

The PDPA applies to the collection, use and disclosure of personal data by organisations. The PDPC AI Advisory Guidelines provide further guidance to organisations on how they may use personal data in developing AI systems, as well as inputting personal data into AI systems already deployed.

Where it comes to using personal data to train AI systems, in lieu of obtaining consent from the individual, organisations often rely on the business improvement exception to use personal data they have collected in accordance with the PDPA to improve existing goods/services or develop new ones based on customer preferences. Organisations may also rely on the legitimate interests exception after conducting a risk assessment to ensure that the legitimate interests of the organisation outweigh any adverse effects to the individual.

The PDPC also encourages organisations to use anonymised data when developing, testing and monitoring AI systems as much as possible. Anonymised data is not considered personal data for the purposes of the PDPA. However, there is always a risk of re-identification in combination with other data about the individual – especially where AI makes connections between different datasets and creates a profile about the person, whereby the data that is anonymised now becomes personal data subject to the PDPA.

It remains to be seen if courts or regulators in Singapore will order deletion of the entire AI model or cease the use of such AI model if it is trained on illegally obtained personal data. However, given that there have been reported instances of this in other jurisdictions, such a response cannot be ruled out locally if the situation warrants it.

Singapore does not have a right to not to be subject to a decision solely based on automated processing, unlike Article 22 of the GDPR. However, regulators have issued guidelines to organisations encouraging them to allow individuals to opt-out from the use of AI, if feasible – please see 12.4 Transparency and Disclosure for details.

On children’s data, the PDPC's Advisory Guidelines on the PDPA for Children's Personal Data (28 March 2024) define a child as an individual below 18 years of age. Children aged 13 to 17 may give valid consent if they understand the relevant data policies; for children below 13, parental or guardian consent is required. Organisations are encouraged to conduct data protection impact assessments (DPIAs) before releasing products likely to be accessed by children.

There are three key mechanisms for legal transfers of personal data out of Singapore:

  • the receiving organisation is bound by legally enforceable obligations, which may take the form of contract (most common), binding corporate rules, or specified certifications like under the APEC Cross-Border Privacy Rules System;
  • consent from the individual, where he/she is given a reasonable summary in writing of the extent to which his/her personal data will be protected to a comparable standard as the PDPA;
  • exceptions to consent – eg, where the transfer is necessary to fulfil a contract with the individual.

In terms of DPIAs, the PDPC AI Advisory Guidelines recommend conducting one where raw personal data is used in developing, testing and monitoring AI systems. The PDPC has released a complementary “Guide to Data Protection Impact Assessments” to illustrate how this may be done.

Pricing Algorithms

Pricing algorithms range from those that monitor and extrapolate trends in prices in the market to those that can weigh information such as supply and demand, customer profile and competitor pricing in order to make real-time adjustment to prices. Such algorithms raise three key issues of concern when it comes to competition law. The CCS launched the AI Markets (AIM) Toolkit in September 2025 for organisations to test for potential anticompetitive behaviour in their AI systems – see 15.5 Retail and Consumer.

Algorithmic collusion

The individual use of a pricing algorithm does not fall foul of competition law. However, where organisations have an explicit agreement to collude and use pricing software to implement their agreement, the CCS has unequivocally stated that this will contravene Section 34 of the Competition Act 2004 as an agreement that prevents, restricts or distorts competition.

If organisations use a distinct algorithm with no prior or ongoing communication, but achieve an alignment of market behaviour, the CCS will take a fact-centric approach to determine whether the collusive outcomes can be attributed to the organisations.

Personalised pricing

Where an organisation with a dominant position in the market utilises AI to implement personalised pricing, it may be deemed an exclusionary abuse of dominance and infringe Section 47 of the Competition Act 2004. Specifically, if personalised pricing is used to set discounts that foreclose all or a substantial part of a market, the CCS may find that the organisation has abused its dominance in the market.

Liability where AI learns collusive behaviour

If an AI system autonomously learns and implements collusive behaviour, the CCS is unlikely to find no fault on the part of the organisation that deploys the AI system. Although it is non-binding, the Model Framework states that organisations should be able to explain decisions made by AI. Accordingly, organisations are unlikely to be able to disclaim responsibility for the decisions made by the AI they deploy.

Singapore’s Cybersecurity Act 2018 (CA) sets out the requirements for certain organisations (eg, owners of critical information infrastructure) to take measures to prevent, manage and respond to cybersecurity threats and incidents, as well as to regulate cybersecurity service providers, amongst other matters. Amendments to the CA were introduced in May 2024 to expand the regulatory ambit of the CA to four new entities, including entities that are major foundational digital infrastructure service providers (eg, cloud computing services or data centre facility services). The amendments will progressively come into operation.

The CA is technology-agnostic. So long as an organisation falls within the description of an entity the CA seeks to regulate (regardless of whether or not it develops, deploys or uses AI), the obligations under the CA will apply. These obligations include:

  • providing information;
  • reporting incidents; and
  • complying with codes, standards and directions, etc.

The Computer Misuse Act 1993 (CMA) complements the CA, where it targets cybercrime in Singapore. Unauthorised access (ie, hacking) or modification of computer material is an offence, as is unauthorised interference with or obstruction of the lawful use of a computer (eg, launching cyber-attacks).

The CSA released the Guidelines and Companion Guide on Securing AI Systems on 15 October 2024, which set out best practices for owners of AI systems to adopt to secure their AI systems at every stage from design and deployment to disposal at the end of the life cycle. The CSA emphasises that AI systems should be “secure by design and secure by default”, and that AI systems are not just vulnerable to classic cybersecurity risks, but also to new forms of attacks like data poisoning (injecting corrupted data into training data sets) or extraction attacks (where the model is probed to expose sensitive or restricted data). An addendum for agentic AI was released in October 2025.

Various sectoral regulators also issue sector-specific cybersecurity guidelines (which are general in nature without solely focusing on AI), such as the MAS with Technology Risk Management Guidelines and Cyber Hygiene Guidelines.

With Singapore’s goal of net-zero emissions by 2045, the IMDA has highlighted the need for “Green AI”, where organisations develop energy-efficient AI systems powered by low- or zero-carbon energy sources. Data centres are a priority for the IMDA as while they are essential to powering AI and digital services, they also consume large amounts of power and water and produce a large carbon footprint. The IMDA has introduced the “Green Data Centre Roadmap” (2024) for data centres to reduce their environmental impact, as well as the Tropical Data Centre Standard (SS 697:2023) – the world’s first sustainability standard for data centres in tropical climates (as tropical climates present additional challenges in operating the data centre cooling systems).

With the abundance of AI guidelines and frameworks introduced across jurisdictions, it can be difficult for organisations to pick one to start with, especially if they intend to deploy their AI solution across multiple jurisdictions. Nevertheless, it is good to take one framework as a starting point or baseline and make improvements/adjustments from there, incorporating recommended actions from other jurisdictions that may not be found locally. Singapore’s ISAGO is useful for both developers and deployers of AI solutions, and it is broadly aligned to the AI governance frameworks in key AI jurisdictions. Organisations may also assess their systems with AI Verify (although the ISAGO is simpler, as it is a checklist with no technical tests).

Organisations should also create a generative AI use policy to set common expectations for employees on how they may use (or not use) generative AI tools, given the prevalent use of such tools.

Organisations deploying agentic AI should also consider the Model AI Governance Framework for Agentic AI, which provides structured guidance on:

  • risk bounding;
  • human accountability;
  • technical controls; and
  • end-user responsibility.
Drew & Napier LLC

10 Collyer Quay
10th Floor
Ocean Financial Centre
Singapore 049315

+65 6531 4110

+65 6535 4864

chongkin.lim@drewnapier.com www.drewnapier.com
Author Business Card

Trends and Developments


Authors



Drew & Napier LLC is a full-service Singapore law firm, which was founded in 1889 and remains one of the largest law firms in the country. Drew & Napier has a highly regarded TMT practice group, which consistently ranks as the leading TMT practice in Singapore. The firm possesses unparalleled transactional, licensing and regulatory experience in the areas of telecommunications, technology, media, data protection and cybersecurity. The TMT practice is supported by more than ten lawyers and paralegals with extensive experience in infocommunications, data protection, technology, and sector-specific and general competition law. The TMT practice acts for a broad range of clients, spanning multinational corporations and local companies across industries. These clients include global and regional telecommunications service providers, sectoral regulators (both local and foreign), consultants, software houses, hardware manufacturers and international law firms.

Singapore’s Approach to AI Adoption and AI Governance

Singapore has a highly supportive climate for the development and use of AI, both in terms of funding and policies. Singapore has also developed a comprehensive AI governance testing framework for traditional AI systems (AI Verify), expanded it for generative AI systems (Project Moonshot) and is working hard to ensure its AI governance frameworks are interoperable/aligned with the international community’s.

By way of example, Singapore actively participates in international fora and recently mapped the AI Verify framework to the USA’s National Institute of Standards and Technology AI Risk Management Framework, declaring them interoperable. The AI Verify Foundation has stated that this “is an important step towards harmonisation of international AI governance frameworks to reduce industry’s cost to meet multiple requirements.” This will help organisations that offer AI systems in multiple markets, as their preparations to meet the requirements of country A’s AI governance and legislative frameworks can go some way in helping them meet the requirements of country B’s. In keeping with its international outlook, the AI Verify framework has also been mapped to ISO/IEC 42001:2023 (the first international standard on the responsible adoption of AI within organisations) in June 2024.

In relation to generative AI, Singapore published the Model AI Governance Framework for Generative AI (the “Model Gen-AI Framework”) in May 2024, after a round of public feedback. Singapore has also developed testing tools for large language models (LLMs), with Project Moonshot released in May 2024 to address security and safety challenges of LLMs. A further Model AI Governance Framework for Agentic AI was released in January 2026, to keep up with technological developments.

When it comes to regulating the use of AI, Singapore has yet to enact legislation governing the general use of AI. Instead, Singapore takes a measured approach, examining the use cases of AI first to see what risks arise that cannot be adequately addressed or mitigated by existing laws in areas such as:

  • data protection;
  • IP protection; and
  • consumer protection.

For example, AI-enabled medical devices are regulated under the Health Products Act 2007, as it applies to all medical devices (whether AI-enabled or not) to ensure their safety. Like most countries, Singapore also has legislation concerning the use/testing of autonomous vehicles (AVs) – given that its road traffic laws were premised on there being a human driver.

Nevertheless, in order to guide industries with regard to deploying AI, regulators in Singapore have issued guidelines for the development and deployment of:

  • traditional;
  • generative; and
  • agentic AI systems.

The strength of Singapore’s approach to AI lies in its adaptability. Guidelines can be amended (or new guidelines issued) quickly to adapt to any changes. The technology, its use cases, and the issues arising from the use cases can be carefully studied before making any legislative changes that are more permanent in nature. Singapore also ensures that guidelines are formulated in close consultation with the industry, taking into account any feedback.

In the meantime, the Infocomm Media Development Authority (IMDA) and Personal Data Protection Commission (PDPC) are also working on testing methodologies in order to ensure that the use of AI is in line with the governance principles. This will also prevent Singapore from enacting legislation that cannot be enforced.

Approaches to Regulating the Use of AI

With legislation and guidelines on the use of AI being issued across the world at such a rapid pace, is it possible to anchor knowledge about AI? It is helpful to consider the AI landscape in terms of the following four key questions.

  • “What is AI?” It is important to know what the technology actually is, so as to understand what it can and cannot do and how its features may affect the way existing laws are applied (eg, tort, product liability). Also, if the use of AI (as opposed to AI itself) is to be regulated, AI must be clearly defined in order to determine whether or not a particular use is covered based on the underlying technology.
  • “How should the use of AI be governed?” This is an exploration of the principles that govern the use of AI, with the aim of making the use of AI as safe as possible. Many countries around the world have set out their own frameworks. From Singapore’s voluntary Model Framework to the Artificial Intelligence Act in the EU, there is an emerging global consensus on how the use of AI should be governed.
  • “Is (the use of) AI what it is claimed to be?” For guidelines or legislation on AI governance to be effective, there must be a means to measure compliance with them, which is where testing and auditing come in. Singapore has developed self-assessment guides for organisations, as well as the aforementioned series of process and technical checks known as AI Verify. By way of another example, the EU has introduced the concept of “conformity assessments”, which evaluate how the AI system complies with the requirements in the EU’s AI Act before the AI system is placed on the market.
  • “What happens when things go wrong?” Every effort is made to ensure that the use of AI is as safe as possible. Nonetheless, there will still be cases where the use of AI results in harm to a person or property, because risks can be reduced but not eliminated entirely – even though the governance principles certainly help with this. The harm could materialise as death, injury or property damage; however, there is also a risk of discrimination against a person. Therefore, there must be remedies available to ensure that the injured party is restored – whether via tort law, contract, etc.

Accordingly, recent trends and developments in Singapore will be discussed in this context.

Definition of AI and How This Affects the Way Existing Laws Are Applied

Many countries are aligning their definition of AI systems with the OECD’s, which defines AI by its unique traits of autonomy and adaptiveness, and ASEAN (a political and economic union of ten South-East Asian nations, including Singapore) is no exception. The ASEAN Guide on AI Governance and Ethics defines an AI system as “a machine-based system that is capable of influencing the environment by producing an output (predictions, recommendations or decisions) for a given set of objectives”, which “uses machine and/or human-based data and inputs to (i) perceive real and/or virtual environments; (ii) abstract these perceptions into models through analysis in an automated manner (eg, with machine learning), or manually; and (iii) use model inference to formulate options for outcomes” – further noting that “AI systems are designed to operate with varying levels of autonomy”.

Three unique features require a closer look at how existing laws (especially those concerning fault-based liability) might apply to AI, as follows.

  • AI is a “black box” – this affects how its workings are explained, as it is not always possible to explain how or why the AI system reached a particular outcome and the type of model chosen affects how easily its workings can be explained.
  • AI is self-learning/autonomous – it is able to learn from the data it has been exposed to during its training and improve without being explicitly programmed, so the behaviour of the AI system is not always foreseeable.
  • AI has many people involved in its development – from procuring the datasets, training and selecting the algorithm, to monitoring the performance of the algorithm. So who should be held responsible if the AI causes harm or its output is not as expected?

How Should the Use of AI Be Governed

This will be addressed in two parts – the first covering traditional AI systems and the second covering generative AI systems.

Traditional AI systems

In relation to traditional AI systems, this is covered by the second edition of the above-mentioned Model Framework issued by the IMDA/PDPC in January 2020 (the first edition was issued in January 2019). The Model Framework is sector-agnostic, meaning regulators can also issue guidance relevant to their sector as needed.

The Model Framework sets out ethics and governance principles for the use of AI, alongside practical recommendations that organisations can adopt to fulfil these principles. It is based on two high-level guiding principles that aim to promote public trust in and understanding of the use of AI, as follows.

  • First, organisations using AI in decision-making must ensure that the decision-making process is:
    1. explainable – ensuring that the reasons behind the decision can be explained in non-technical terms;
    2. transparent – informing people that AI is being used in respect of them and how it affects them; and
    3. fair – ensuring that decisions do not create discriminatory or unjust impacts across different demographic lines (eg, race or        sex).
  • Second, AI solutions must be “human-centric” – meaning that the protection of human interests (including well-being and safety) should be the primary consideration when designing, developing and deploying AI.

The Model Framework also sets out four key areas in which organisations should follow its recommendations so as to promote the responsible use of AI:

  • adapting or setting up internal governance structures and measures to incorporate values, minimise risks and allocate responsibilities relating to the use of AI;
  • determining the appropriate level of human involvement in AI-augmented decision-making;
  • operations management (ranging from selecting the datasets to choosing the algorithm), whereby the organisation must be alert to potential issues when developing, selecting and maintaining AI models; and
  • interacting and communicating with the organisation’s stakeholders who are affected by the use of AI.

It is recommended that these measures be explored throughout the development and deployment of AI – the life cycle of which can be summarised as follows.

  • Stage 1 (gathering input) – selecting data that is to be input into the model for training purposes and, subsequently, when the model is deployed. As the accuracy of an AI model’s output depends on the data that it is trained on, it is important to ensure that the data used is neither inaccurate (ie, drawn from incomplete records or outdated) nor biased (ie, not drawn from a representative group). Personal data must be processed in compliance with the Personal Data Protection Act 2012. Organisations must also consider intellectual property issues when it comes to the input data, such as whether they have the necessary permissions to use the material subject to copyright, or whether inputting the material may be in breach of confidentiality agreements with the owner of that material.
  • Stage 2 (setting the decision-making process) – choosing the model, training the model, and calibrating the model based on the results of the training. The organisation must consult persons with expertise in order to identify suitable algorithms to analyse the data, and thereafter train the model and evaluate its performance until it produces a satisfactory level of accuracy.
  • Stage 3 (output) – being able to explain why and how the model produced any output (eg, what factors it takes into account), so as to build trust in the use of AI and ensure that a person has sufficient information to frame their appeal if they wish to challenge the decision. If explainability is not possible, given the state of technology, the repeatability of the results should be demonstrated instead (where the same scenario will consistently give rise to the same outcome).
  • Stage 4 (human review) – whether it is necessary for a human to review the decision made by the AI system before the decision is implemented will depend on a number of factors, including:
    1. the severity of the harm to the individual – for example, compare               the impact of a medical diagnosis with that of an online shopping               recommendation;
    2. the probability of the harm materialising;
    3. the nature of the harm (eg, physical or intangible);
    4. the reversibility of the harm and the availability of recourse; and
    5. whether it is operationally feasible to involve a human in the                      decision-making process – for example, in the case of a ride-hailing transportation service, there would be thousands of trip allocations per minute.

As regards general governance principles, the organisation must ensure it has robust oversight over its use of AI. This means that all persons involved in AI development and deployment should have clear roles and responsibilities, adequate training and resources, and the organisation’s top management/board of directors must also play an active role in setting AI governance policies.

Organisations also need to keep records of the AI development process, starting with a data provenance record to track the origin/source of the (training) data and any changes made to it. The model training and selection process should be documented – along with the reasons why certain decisions were made and measures taken to address any risks identified. These records might be used in the future to troubleshoot where the AI system does not perform as expected or to defend against liability.

Finally, strong personal data protection and cybersecurity practices are required to be in place when using AI. However, given that such requirements are not unique to the use of AI, they are not discussed in this article.

Generative AI systems

In relation to generative AI systems, the Model Gen-AI Framework sets out the following nine areas to focus on to achieve trustworthy generative AI, along with the recommended actions to take for both industry and regulators.

  • Accountability – responsibility should be allocated across the multiple players in the AI development chain (eg, model developers, deployers, and cloud service providers who host AI applications), based on the level of control each player has in the chain (drawing parallels with the cloud industry).
  • Data – the quality of the data used in model training will affect the quality of its output; hence, while there is a need to increase data accessibility, there is also a corresponding need to ensure data (including personal data and data subject to copyright) is used lawfully.
  • Trusted model development and application deployment – the industry must adopt best practices such as retrieval-augmented generation to reduce hallucinations and have a standardised way to evaluate the performance and safety of generative AI models.
  • Incident reporting – AI developers must report (and then patch) safety vulnerabilities in their AI systems and deployers must report serious incidents arising from their use of the AI system.
  • Testing and assurance – both regulators and international standard-setting organisations should develop common standards for AI testing to be carried out by independent third parties.
  • Security – tools must be developed to address the threats specific to generative AI.
  • Content provenance – consumers should be aware they are interacting with AI-generated content and this calls for solutions such as watermarking, cryptographic provenance and public education.
  • Safety and alignment R&D – this should be done to improve model safety, with global co-operation.
  • AI for the public good – AI should improve people’s lives and be environmentally sustainable.

Does Singapore Take a Different Approach to the Regulation of AI Use?

There are two issues to consider when comparing Singapore’s approach towards regulating the use of AI with approaches taken by other jurisdictions. The first looks at what kind of AI governance principles should apply and the second concerns how to implement those principles (ie, whether by means of legislation or guidelines only).

Singapore broadly resembles countries around the world in terms of the principles it believes should apply to the use of AI. There is broad international consensus in respect of the following principles.

  • High-risk uses of AI should be subject to more requirements/safeguards than low-risk uses, where the concept of “risk” refers to the severity of the impact of the use of AI on the human.
  • Decisions made by AI should be explainable, so that people know how and why the AI system makes a decision.
  • The use of AI to make decisions should be fair and aim to minimise bias.
  • The use of AI should be disclosed to persons affected by it (transparency).
  • There must be means of applying for an appeal or review of the decision where it has a significant impact on the person.

However, when it comes to implementing these principles, approaches vary. The EU has introduced legislation – the EU AI Act – that regulates high-risk uses of AI and imposes certain obligations (generally) on the developers of such AI systems. However, Singapore and Australia have yet to take legislative steps and instead have issued guidelines and notices – while monitoring the industry to see if further action is necessary.

Each approach has its own strengths. Ultimately, it is up to each country to find the right balance between encouraging innovation and ensuring safety in the use of AI. However, the one consistent objective that countries are moving towards is interoperability in their AI governance, safety and testing standards, so as to remain attractive to foreign companies wishing to operate in their jurisdiction and also so that local companies can easily export their AI technology.

How Compliance With AI Governance Principles Is Measured

Testing is a very important component of AI governance, as it enables various parties – including regulators, the organisation deploying the AI system, and the persons who are subject to decisions made by the AI system – to find out whether or not the AI system does indeed conform to the governance principles. In other words, it lets people see if the expectation matches up to the reality.

Testing matters because, if the use of AI is to be regulated through legislation (with sanctions for non-compliance), there needs to be a reliable and objective method to ascertain that it does indeed live up to the standards. Testing can be by way of self-assessment, or conducted by a third party, and it can be done by a series of process checks – for example, reviewing documentation – or technical tools (or a combination of both).

In Singapore, the Model Framework is to be read in tandem with the Implementation and Self-Assessment Guide for Organisations (ISAGO), which sets out a series of questions for organisations to review in order to self-assess their compliance with the principles contained within the Model Framework.

May 2022 saw the launch of AI Verify, which consists of technical tests and process checks that let AI developers validate their claims about their AI systems against a set of 11 internationally accepted principles. The test results are not pass/fail, and do not guarantee that the AI system is free from bias or is completely safe, but confer the following positives:

  • the results can be used to identify potential areas for improvement, as they come with recommendations for organisations; and
  • the results are an objective and verifiable way for an organisation to demonstrate that it has implemented AI responsibly and ethically.

Project Moonshot was launched in 2024, with curated benchmarks (similar to “exam questions”) for organisations to test their LLM across a variety of competencies (eg, summarisation, language, context), as well as modules for manual and automated red-teaming (adversarial attacks on the model) to flush out vulnerabilities in the LLM. In February 2025, Singapore published a paper on the effectiveness of LLM guardrails for non-English languages in partnership with eight other Asia-Pacific countries.

Liability When AI Does Not Perform As Expected

The use of AI carries two types of risks – namely, safety risks (eg, death, bodily injury, or property damage) and “fundamental rights risks” (to borrow the EU’s description of rights risks such as discrimination, manipulation, or loss of privacy). The type of risk presented depends on how the AI system is used – for example, whether it is controlling an AV or screening CVs for recruitment.

Whether in the form of guidelines or legislation, the AI governance principles are there to ensure that the use of AI is as safe as possible and thereby minimise the likelihood of a risk occurring. An organisation can reduce the likelihood of a decision with discriminatory effects occurring by, for example, ensuring that the datasets used to train its AI model are representative of the population for which it is intended. The output produced by the AI system will be more accurate a result and therefore less likely to have an incorrect outcome and cause loss or damage.

However, despite every effort to ensure that the datasets are representative and testing is sufficient, there will still be adverse outcomes sometimes. It is worth bearing in mind that the same risks come with decisions or actions carried out by humans, who of course have their own unconscious bias. Hence, when the harm sought to be prevented arises, the focus must switch to compensating – or restoring – the affected party.

There is no quick or easy solution to this issue. In September 2022, the EU AI Liability Directive introduced a presumption of causality and powers to order disclosure of evidence to aid plaintiffs in bringing claims, but in February 2025 the directive was withdrawn.

Singapore is also undertaking many studies on the allocation of liability. However, in the meantime, the Singapore courts will be able to apply existing legal principles to this AI technology. Parliament has expressed this view when discussing liability for AV accidents in 2017:

“The traditional basis of claims for negligence may not work so well where there is no driver in control of a vehicle. When presented with novel technologies, courts often try to draw analogies to legal constructs in other existing technologies. In the case of AVs, the courts have autopilot systems for airplanes and autopilot navigational systems for maritime vessels, and product liability law to draw references from. As with accidents involving human-driven vehicles, it is likely that issues of liability for AVs will be resolved through proof of fault, and existing common law.”

Liability for AI-Generated Content

To the extent a person publishes AI-generated content, they can be liable as though they had generated the content themselves if the content is:

  • false;
  • defamatory; or
  • harmful/toxic (eg, content that is an offence to post publicly under Singapore’s laws).

However, when stepping back to look at the developer/deployer of the generative AI system, whether liability arises for AI-generated content may depend on whether the person deploying the AI system had a duty to provide correct information to the recipient of information from the AI system (such as in a company-customer relationship – eg, an airline providing information to its customers on special airfare rates through an AI-powered chatbot – or if there was a professional duty to provide correct information), as they cannot delegate that duty to a generative AI system and then blame the developer. It may also turn on whether the output that is wrong is so harmless or trivial that reliance on it would not affect the recipient’s rights (eg, the right to claim compensation).

To the extent that the output is toxic (eg, identity attacks, sexually explicit content, or language that incites violence), it is arguable that the developer of the generative AI system will not be liable for the output if the developer had:

  • implemented technological methods commonly used in the industry to reduce such toxic output (eg, content filters);
  • posted clear warnings to users that the content may be offensive or inaccurate and made it a condition of use that they do not circumvent any guardrails (eg, content filters) in place;
  • a mechanism for users to report any toxic content generated; and
  • taken prompt action on any reports of toxic content generated.

Conclusion

AI is definitely here to stay, as Singapore now sees it as a necessity – rather than something just “good to have” – and champions its responsible use. While countries are free to decide what regulatory levers are most appropriate to shape its use (legislation or voluntary guidelines), there will also be concerted efforts to ensure technical and safety standards are harmonised, given how easily the technology flows across geographical borders.

Drew & Napier LLC

10 Collyer Quay
10th Floor
Ocean Financial Centre
Singapore 049315

+65 6531 4110

+65 6535 4864

chongkin.lim@drewnapier.com www.drewnapier.com
Author Business Card

Law and Practice

Authors



Drew & Napier LLC is a full-service Singapore law firm, which was founded in 1889 and remains one of the largest law firms in the country. Drew & Napier has a highly regarded TMT practice group, which consistently ranks as the leading TMT practice in Singapore. The firm possesses unparalleled transactional, licensing and regulatory experience in the areas of telecommunications, technology, media, data protection and cybersecurity. The TMT practice is supported by more than ten lawyers and paralegals with extensive experience in infocommunications, data protection, technology, and sector-specific and general competition law. The TMT practice acts for a broad range of clients, spanning multinational corporations and local companies across industries. These clients include global and regional telecommunications service providers, sectoral regulators (both local and foreign), consultants, software houses, hardware manufacturers and international law firms.

Trends and Developments

Authors



Drew & Napier LLC is a full-service Singapore law firm, which was founded in 1889 and remains one of the largest law firms in the country. Drew & Napier has a highly regarded TMT practice group, which consistently ranks as the leading TMT practice in Singapore. The firm possesses unparalleled transactional, licensing and regulatory experience in the areas of telecommunications, technology, media, data protection and cybersecurity. The TMT practice is supported by more than ten lawyers and paralegals with extensive experience in infocommunications, data protection, technology, and sector-specific and general competition law. The TMT practice acts for a broad range of clients, spanning multinational corporations and local companies across industries. These clients include global and regional telecommunications service providers, sectoral regulators (both local and foreign), consultants, software houses, hardware manufacturers and international law firms.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.