RatedWithAI

RatedWithAI

Accessibility scanner

Global AI RegulationSeptember 6, 2026

Singapore Never Passed an AI Law. Its Buyers Ask Harder Questions Than Brussels.

There is no statute to comply with, no risk tiers, no registration, no conformity assessment. There is a privacy act with real penalties, three widely-adopted governance documents, and a testing toolkit that has quietly become the APAC procurement gate.

No AI act
Regulated through PDPA and sector law instead
PDPA
Applies to foreign providers serving Singapore users
DPO required
Named individual with public contact details

The Deliberate Absence

Singapore has had every opportunity to pass an AI act and has consistently declined. The stated reasoning is that the harms AI produces — discriminatory outcomes, privacy violations, unsafe medical advice, misleading marketing, financial mis-selling — are already illegal under instruments that exist, and that a horizontal AI statute would freeze definitions faster than the technology moves.

What Singapore built instead is a governance stack: enforceable privacy law at the base, regulator guidance above it explaining how that law lands on AI specifically, a voluntary framework describing what good governance looks like, and a testing toolkit that turns the framework into a report you can hand someone. It is a soft-law pyramid sitting on a hard-law foundation, and US vendors consistently misjudge which layer they are being asked about.

The Four Layers

1

PDPA — the enforceable base

Consent, notification, purpose limitation, accuracy, protection, retention limitation, transfer limitation, and access and correction rights. Enforced by the PDPC with financial penalties, and reaching organisations outside Singapore that carry on activities in respect of individuals here. There is also a mandatory data breach notification regime and an accountability obligation to have policies and to name a responsible individual.

2

PDPC advisory guidelines on personal data in AI systems

The document that answers the question US teams actually have: when can you use personal data to develop, test and deploy AI recommendation and decision systems, and what must you tell people. It works through the business improvement and research exceptions, consent framing, and what a reasonable notification about an AI-driven decision looks like. Guidance, not statute — but it is the PDPC telling you in advance how it reads the statute.

3

Model AI Governance Framework (incl. the generative AI edition)

Voluntary, principles-based, organised around internal governance, human involvement in decisions, operations management, and stakeholder communication — with a later edition extending it to generative AI across accountability, data, testing, incident reporting, provenance, and evaluation. Nobody enforces it. Everybody's procurement team quotes it.

4

AI Verify

A testing framework and open-source toolkit that runs technical tests and process checks against governance principles and produces a report. Voluntary. Its function in a sales cycle is to convert 'we take AI governance seriously' into an artifact with sections a buyer's risk team can tick off.

The Training-Data Question Is the Whole Ballgame

Almost every Singapore AI compliance conversation collapses into one issue: can you use personal data you already hold to build or improve an AI system, without going back for fresh consent?

The PDPA's answer is conditional. There are exceptions capable of supporting internal development work — notably business improvement and research — and the PDPC's AI guidance walks through their edges. What they do not do is bless a general "we train on customer data" posture. The tests are purpose-bound and they ask uncomfortable questions.

Strengthens your position
  • Improving or developing a product the individual already uses
  • A documented conclusion that the purpose needs this data
  • Minimisation, de-identification, or synthetic substitution attempted first
  • Model outputs that cannot regurgitate identifiable records
  • A written assessment made before training, not after a question
Weakens it badly
  • Training a shared model that serves other customers
  • Data acquired for one product, reused for an unrelated one
  • Sensitive categories swept in because the pipeline was easy
  • Consent language that never mentioned model development
  • No record of who approved the use or on what basis

The artifact that resolves this is a short written assessment, dated before the training run, recording the purpose, the exception relied on, what was minimised, and who signed off. It is perhaps two pages. Its absence is what turns a routine regulator question into an investigation.

The Cheap Obligations US Companies Skip

  • Name a data protection officer and publish their business contact. Required, trivially satisfied, and routinely absent from US SaaS sites
  • Have written policies and practices. The accountability obligation is about documents existing, not about them being clever
  • Know your breach notification triggers. Singapore has a mandatory regime with defined thresholds and timelines; discovering this during an incident is expensive
  • Check your transfer position. Sending Singapore personal data abroad requires comparable protection standards, which means looking at your model vendor's terms
  • Answer access and correction requests. Including for inferences an AI system generated about a person, which most products cannot currently retrieve

Why the Guidance Outranks the Statute in Practice

Singapore's economy runs on regional headquarters, banks, insurers, telcos, and government agencies — all of which buy software and all of which have compliance functions that read IMDA and PDPC publications. When one of them evaluates your AI feature, the questionnaire is built from the Model Framework's structure, not from any law. A US vendor who prepared a legal memo about "Singapore AI regulation" arrives with an answer to a question nobody asked, and no answer to the twelve they did.

A Practical Order of Operations

  1. Appoint and publish the DPO. One line on your privacy page. Do it this week.
  2. Write the training-data assessment. Purpose, exception, minimisation, approver, date. Before the next model run, not after.
  3. Map transfers and check model-vendor terms. Comparable protection is a contractual question you may currently be failing silently.
  4. Build access and correction for AI-generated inferences. If a person asks what your system concluded about them, you need a way to answer.
  5. Map your controls onto the Model Framework's four pillars. This becomes the pre-written answer to every APAC procurement questionnaire.
  6. Consider AI Verify if you sell to regulated buyers. Voluntary, but it produces the artifact the buyer's risk team wants to file.

Frequently Asked Questions

If none of the AI guidance is binding, why spend time on it?

Two reasons. It tells you how the regulator interprets the binding law, which makes it the cheapest available prediction of enforcement. And it is the source of the vendor questionnaires that gate your APAC revenue. Non-binding on the PDPC is not the same as optional for your pipeline.

How does Singapore compare to Korea and Japan for a US SaaS company?

Korea generates an actual compliance project: a binding statute with extraterritorial reach, generative-AI disclosure duties, and a domestic representative requirement above a size threshold. Japan generates a privacy review, because its AI statute has no penalties. Singapore generates a governance-documentation exercise on top of a real privacy law. Only one of the three requires you to appoint anyone.

We only sell to Singapore enterprises, not consumers. Does the PDPA still matter?

Yes. The PDPA protects individuals' personal data regardless of whether your customer is a business — your customer's employees, their end users, and the contact records in your CRM are all individuals. B2B does not mean no personal data; it usually means personal data you did not label as such.

Does Singapore require AI-generated content to be labelled?

There is no general statutory labelling mandate of the kind China imposes. Provenance and disclosure feature in the generative AI framework as good practice, and sector rules and election-related measures address specific contexts. Disclosure remains the right default because other markets you serve do mandate it.

What do PDPA penalties look like?

The PDPC can impose financial penalties, and the ceiling was raised to a percentage-of-turnover model for larger organisations subject to a floor amount, rather than a flat cap. Published enforcement decisions are the more useful guide than the ceiling — they show the PDPC weighing whether the organisation had documented practices and a named responsible person, which is exactly the evidence this article is telling you to create.

Soft Law Is Still a Gate

US teams triage international AI work by penalty size, which puts Brussels first and everything else in a backlog. That model predicts fines well and predicts revenue badly. The jurisdictions with no AI statute still have buyers, and those buyers still have checklists.

A single feature inventory with a purpose note, a data-flow map, and a named owner per AI feature answers Singapore, Japan, Korea and the EU. Everything after that is formatting.

This article is general information about a rapidly changing regulatory area, not legal advice. PDPC guidance and penalty provisions are periodically revised — verify current requirements with Singapore counsel before relying on an exception.