Skip to content
Is there an AI for this?

Jurisdiction

Singapore

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

Singapore regulates AI through binding general-purpose data protection law plus voluntary, fast-moving governance frameworks, not an AI act. The Personal Data Protection Act governs any personal data in an AI pipeline, and PDPC advisory guidelines translate it for recommendation systems and for generative AI. IMDA and the AI Verify Foundation publish the Model AI Governance Frameworks, now extended to agentic AI, with AI Verify supplying the testing method. MAS adds financial-sector expectations that are hardening into guidelines, and HSA regulates clinical AI as a software medical device. There is no adequacy list, so every cross-border transfer is answered by contract, certification or comparable law.

Region
Southeast Asia
ISO code
SG
Privacy framework
Personal Data Protection Act 2012 (Act 26 of 2012), supported by the Personal Data Protection Regulations 2021 (S 63/2021, in operation 1 February 2021). Consent, notification, purpose limitation, accuracy, protection, retention, transfer limitation and accountability obligations apply to any organisation processing personal data, including data used to train or run an AI system. The PDPC issues advisory guidelines that explain how those obligations land on AI — one set for AI recommendation and decision systems from March 2024, and one for generative AI published in July 2026. Sectoral layers sit above: the Cybersecurity Act for critical information infrastructure, HSA guidance for software medical devices, and the Health Information Act 2026 once it is brought into operation.
AI-specific rules
No omnibus AI statute. Binding law reaches AI through the PDPA, with PDPC advisory guidelines explaining how. Voluntary governance comes from IMDA and the AI Verify Foundation: the Model AI Governance Framework (second edition, 2020), the Model AI Governance Framework for Generative AI (2024) with its nine dimensions, and the Model AI Governance Framework for Agentic AI launched in January 2026 and updated in May 2026, which is explicit that humans remain accountable for what an agent does. AI Verify supplies a testing framework against eleven governance principles plus an open-source toolkit, and the Global AI Assurance Sandbox connects deployers with specialist testers. In financial services MAS has FEAT, an AI model risk management information paper, the SAFR agentic framework, and proposed AI Risk Management Guidelines that were consulted on and are not yet final.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

PDPA section 26 imposes the Transfer Limitation Obligation, with the mechanics in Part 3 of the Personal Data Protection Regulations 2021. A transferring organisation has to take appropriate steps to ascertain whether, and to ensure that, the recipient is bound by legally enforceable obligations giving protection comparable to the PDPA. The PDPC recognises four routes: contract terms including the ASEAN Model Contractual Clauses, specified certifications such as Global CBPR and Global PRP, comparable foreign law, and binding corporate rules. There is no adequacy list, so there is no shortcut and no country that is simply fine — the question is answered per recipient, and it has to be evidenced. Most hosted model deployments export personal data, which means the transfer analysis is part of vendor selection rather than something to settle afterwards.

Primary sources

  1. LegislationPersonal Data Protection Act 2012 — Singapore Statutes Online
  2. LegislationPersonal Data Protection Regulations 2021 (S 63/2021)
  3. StandardAI Verify Foundation — Model AI Governance Framework for Generative AI
  4. StandardAI Verify Foundation — AI Verify Testing Framework
  5. StandardAI Verify Foundation — Global AI Assurance Sandbox
  6. Regulator pageMDDI — Singapore launches new Model AI Governance Framework for Agentic AI
  7. Regulator guidanceMAS — FEAT Principles
  8. Regulator guidanceMAS — Artificial Intelligence Model Risk Management
  9. StandardMAS — Safeguards for Agentic Finance at Runtime
  10. Regulator pageMAS — Consultation on Guidelines on Artificial Intelligence Risk Management
  11. Regulator guidanceHSA — medical device guidance documents
  12. LegislationOnline Safety (Relief and Accountability) Act 2025
  13. LegislationCybersecurity Act 2018
  14. LegislationCybersecurity (Amendment) Act 2024
  15. LegislationHealth Information Act 2026

02Regulations and guidance

15 instruments
InstrumentStatus
AI VerifyA testing framework and open-source toolkit that assesses an AI system against eleven internationally recognised governance principles, each with desired outcomes, processes and documentary evidence. It is how a Singapore deployment demonstrates governance rather than asserting it.In force
MAS AI Model Risk PaperMAS’s thematic review of how banks manage AI and generative AI model risk, setting out the practices it observed and expects. It is the most concrete statement of what a Singapore financial institution has to be able to show about a model it deploys.In force
MAS AI Risk Guidelines (proposed)MAS’s proposed guidelines on AI risk management for financial institutions, covering generative AI and AI agents. Consulted on and not yet finalised, so it is a signal of where supervision is going rather than a rule anyone has to meet today.Proposed
Cybersecurity ActRegulates measures against cybersecurity threats and incidents, persons responsible for certain computers and computer systems, and cybersecurity service providers. It reaches an AI deployment when the system it runs on is designated critical information infrastructure.Partly in force
Cybersecurity (Amendment) ActAmends the Cybersecurity Act 2018, extending the regime beyond systems the owner physically controls — which is the change that matters when critical infrastructure runs on a third party’s cloud or a third party’s model.Partly in force
AI Assurance SandboxAn IMDA and AI Verify Foundation initiative matching builders and deployers of generative AI applications with specialist technical testers, aimed at reducing testing barriers and feeding eventual technical testing standards. It covers applications, not the underlying foundation models.In force
Health Information ActProvides for a national electronic health records system and for the collection, disclosure and use of health information about individuals. Passed and assented but not yet brought into operation, so it sets the direction for clinical AI in Singapore rather than binding it today.Adopted, not yet applicable
MGF for Agentic AIIMDA’s framework for deploying AI agents, building on the 2020 Model AI Governance Framework. It recommends technical and non-technical measures to mitigate agent risks and is explicit that humans remain accountable for what an agent does.In force
MGF for GenAIIMDA and the AI Verify Foundation’s framework for generative AI, structured around nine dimensions covering accountability, data, trusted development, incident reporting, testing and assurance, security, content provenance, safety research and public good. Voluntary, and the reference a Singapore regulator would measure against.In force
OSRAA 2025Creates an office of the Commissioner of Online Safety and gives people affected by online harmful activity routes to redress, including rights of action in court. It reaches a generative product through what that product publishes or enables others to publish.Partly in force
PDPASingapore’s general data protection statute. Consent, notification, purpose limitation, accuracy, protection, retention, transfer limitation and accountability obligations apply to any organisation processing personal data, including data used to train or run an AI system.In force
PDP Regulations 2021Subsidiary legislation under the PDPA. Part 3 carries the mechanics of the Transfer Limitation Obligation — the requirements for a transfer, what counts as legally enforceable obligations on the recipient, and which specified certifications a recipient may hold instead.In force
MAS FEAT PrinciplesThe Monetary Authority of Singapore’s founding AI expectations for financial institutions, covering fairness, ethics, accountability and transparency in the use of artificial intelligence and data analytics. Still current, and still the vocabulary a MAS supervisor uses.In force
HSA SaMD GuidelinesThe Health Sciences Authority’s life-cycle guidance for software medical devices, which is where clinical AI in Singapore is actually regulated. It covers the product from development through change management, not only at first registration.In force
SAFRMAS’s framework for governing AI agents in financial services, defining how agents should behave at runtime rather than only how they are approved. It is the sectoral counterpart to IMDA’s agentic framework and is aimed at the same problem from the supervisor’s side.In force

03Common enterprise issues

5
  • Personal data

    Where the training data came from is a PDPA question

    Web-scraped personal data may fall within the publicly available exception, but material behind a paywall or a registration barrier may not. Re-using existing customer data to build a generative feature generally needs consent or a notification designed for that purpose, and neither is retrofitted easily.

  • Automated decision-making

    People have to be told, at a meaningful level, that a system decides about them

    The PDPC expects an organisation to tell individuals that their personal data feeds a system that makes or supports decisions about them, in terms that mean something. "We use technology to improve your experience" does not discharge it, and the notice usually has to be written before the feature ships.

  • Cross-border transfers

    There is no adequacy shortcut for a hosted model

    Most hosted model deployments export personal data out of Singapore. With no adequacy list, each recipient needs contract terms, a recognised certification, comparable law or binding corporate rules, and the evidence has to exist per recipient — including the vendor’s own subprocessors.

  • Human oversight

    Agentic deployments now have explicit official expectations

    IMDA’s framework for agentic AI expects bounded autonomy, human approval at significant decisions, lifecycle technical controls and disclosure to the end user, and says plainly that humans remain accountable. It is voluntary, and it is the standard a Singapore regulator will reach for.

  • Sector rules

    MAS expectations are hardening beyond FEAT

    FEAT and the 2024 AI model risk paper are current, and MAS consulted in late 2025 on AI Risk Management Guidelines covering generative AI and agents. A financial institution building now will save rework by designing to the consultation draft rather than to FEAT alone.


04Vendor restrictions

0

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

No vendor restriction has been recorded for this jurisdiction.


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 15 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.