Live2h agoIMDA's Open Innovation Platform Bridges Singapore's AI Adoption Gap With Structured Challenge-Based Funding
← Back to stories

Singapore Unveils Sweeping AI Governance Overhaul: GenAI Data Rules and Chatbot 'Nutrition Labels'

Source: The Edge Singapore

Singapore has drawn a clearer line around how businesses can use personal data in artificial intelligence, releasing two major policy frameworks at the inaugural Singapore Data Festival that cover everything from web-scraping for model training to the labels on consumer chatbots. Together, the Personal Data Protection Commission's GenAI advisory guidelines and the Infocomm Media Development Authority's chatbot transparency code represent the most significant AI governance update since the National AI Strategy 2.0.

Singapore Unveils Sweeping AI Governance Overhaul: GenAI Data Rules and Chatbot 'Nutrition Labels'
SGAI Daily

Singapore has drawn a clearer line around how businesses can use personal data in artificial intelligence, releasing two major policy frameworks at the inaugural Singapore Data Festival that cover everything from web-scraping for model training to the labels on consumer chatbots. Together, the Personal Data Protection Commission's GenAI advisory guidelines and the Infocomm Media Development Authority's chatbot transparency code represent the most significant AI governance update since the National AI Strategy 2.0.

"Without good data, even the best systems will struggle to produce useful outcomes. Garbage in, garbage out. That is why data governance matters more, not less, in the age of AI," said Minister for Digital Development and Information Josephine Teo at the Data Festival, introducing the twin frameworks that address distinct parts of the AI lifecycle — how data enters models, and how those models communicate with users.

The PDPC guidelines tackle the thorniest question in GenAI regulation: when can companies scrape public data without consent, and what happens when they want to repurpose data they already hold? The guidance confirms that developers can rely on the Publicly Available Exception under the Personal Data Protection Act for open web data, but draws a firm line at information behind paywalls or registration gates. For data originally collected for other purposes — the more common scenario — organisations must obtain fresh consent through what PDPC calls "AI-Specific Notifications" that plainly explain what data is being used, how, and how individuals can opt out. The guidelines, which incorporate feedback from 40 organisations including Google, Meta, DBS, and Singapore Airlines, also map responsibility across the GenAI supply chain: model providers handle development obligations, system providers manage security, and system deployers carry primary compliance responsibility, including for agentic systems.

On the consumer-facing side, IMDA's voluntary transparency guidelines introduce a chatbot information card modelled after pharmaceutical labels — a single, plain-language document that tells users what a chatbot is designed for, when it might not be appropriate, how their data is handled, and how to report problems. "The label does not tell us every specific detail. Instead, it tells us the essentials," Teo said, positioning the card as an alternative to the scattered disclosures users currently navigate across privacy notices, terms of service, and help pages. OCBC, DBS, Google, Meta, and Singapore Airlines have all indicated they will use the guidelines as a reference over the next six to twelve months. OCBC's Group Chief Strategy and Transformation Officer Melvyn Low called it "a timely step in supporting the trusted adoption of AI-powered services."

PDPC also released updated guides on federated learning and synthetic data generation — two privacy-enhancing technologies that let organisations train AI without centralising sensitive data. The federated learning guide helps businesses assess whether the approach fits their needs, while the synthetic data guide expands on generation methods and re-identification prevention. IMDA's PET Sandbox, which has already supported 11 organisations including Singapore General Hospital and Ant International, provides a testing ground for these techniques. SGH used the sandbox to assess secure cloud processing of medical images through A*STAR's trusted execution environment, while Ant International tested multi-party computing to reduce sensitive data collection from merchant transactions.

Why it matters for Singapore: The dual frameworks signal that Singapore is moving beyond principle-level AI ethics into operational governance — specifying exactly how data protection law applies to each stage of the GenAI pipeline and what consumers should expect from the chatbots they interact with daily. The voluntary starting point for chatbot labels gives industry room to shape the standard before it potentially hardens into mandatory requirements, a pattern Singapore has used effectively with AI Verify and the Model AI Governance Framework. For businesses building on AI in Singapore, the message is clear: data governance is no longer a compliance back-office exercise but a product-design constraint that starts at the point of data collection.

Your daily AI edge in Singapore: in <5 minutes.

We do the reading so you don't have to. Get the essential TL;DR on local AI moves delivered to your inbox every morning.