Live4h agoIMDA's Open Innovation Platform Bridges Singapore's AI Adoption Gap With Structured Challenge-Based Funding
← Back to stories

Singapore Finalises AI Training Data Guidelines, Launches Federated Learning Guide and PET Sandbox Expansions

Source: IAPP

Singapore's Personal Data Protection Commission has finalised its Advisory Guidelines on Personal Data in Generative AI, covering the full AI lifecycle from training data collection through model deployment. Alongside the guidelines, the PDPC released a new Federated Learning Guide enabling privacy-preserving collaborative AI training, while IMDA expanded its PET Sandbox with new health data and payment processing use cases.

Singapore Finalises AI Training Data Guidelines, Launches Federated Learning Guide and PET Sandbox Expansions
SGAI Daily

Singapore's approach to AI governance has always been more carrot than stick — frameworks, sandboxes, and guidance over rigid prohibitions. But the latest wave of releases from this week's IAPP Asia Forum 2026 suggests the regulator is moving from laying groundwork to actively building the scaffolding, with the finalised Advisory Guidelines on Personal Data in Generative AI arriving alongside an entirely new playbook for privacy-preserving AI development.

The Personal Data Protection Commission's finalised guidelines cover the full generative AI lifecycle — from development through deployment and post-deployment — clarifying how the Personal Data Protection Act applies to training data collection, model building, and system deployment. A key focus is the Publicly Available Exception, which allows organisations to process accessible personal data without consent when scraping the web for AI training. The final version requires companies using this exception to explicitly state the purpose of their data collection and the steps taken to mitigate risks, closing a loophole that 40 responding organisations flagged during the public consultation.

Alongside the guidelines, the PDPC released a new Federated Learning Guide — a technical framework that lets organisations train AI models collaboratively without sharing raw sensitive data. By keeping data local and sharing only model updates, federated learning enables banks, hospitals, and government agencies to pool AI capabilities across institutional boundaries while staying compliant with data protection rules. The Infocomm Media Development Authority simultaneously added new use cases to its Privacy-Enhancing Technologies Sandbox, focusing on protecting sensitive health data and payment processing systems — signalling that Singapore sees PETs as a critical enabler for AI adoption in regulated sectors.

The Cybersecurity Agency of Singapore also weighed in with revisions to its Cybersecurity Code of Practice for Critical Information Infrastructure, updating requirements to address advanced persistent threats and AI-enabled harms. The coordination between PDPC, IMDA, and CSA on a single policy day underscores how Singapore's regulators view AI governance as a horizontal issue — data protection, cybersecurity, and digital infrastructure are increasingly inseparable.

Why it matters for Singapore: These releases move Singapore's AI governance from principle to practice. The Federated Learning Guide, in particular, is a genuinely practical tool that could accelerate AI adoption in Singapore's healthcare and financial sectors — two industries where data sensitivity has historically been a barrier. For a market that positions itself as a trusted AI hub, having these operational guardrails in place is what separates Singapore from jurisdictions that talk about responsible AI but leave companies to figure out compliance on their own.

Your daily AI edge in Singapore: in <5 minutes.

We do the reading so you don't have to. Get the essential TL;DR on local AI moves delivered to your inbox every morning.