Jurisdiction
Singapore
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Singapore regulates AI through binding general-purpose data protection law plus voluntary, fast-moving governance frameworks, not an AI act. The Personal Data Protection Act governs any personal data in an AI pipeline, and PDPC advisory guidelines translate it for recommendation systems and for generative AI. IMDA and the AI Verify Foundation publish the Model AI Governance Frameworks, now extended to agentic AI, with AI Verify supplying the testing method. MAS adds financial-sector expectations that are hardening into guidelines, and HSA regulates clinical AI as a software medical device. There is no adequacy list, so every cross-border transfer is answered by contract, certification or comparable law.
- Region
- Southeast Asia
- ISO code
- SG
- Privacy framework
- Personal Data Protection Act 2012 (Act 26 of 2012), supported by the Personal Data Protection Regulations 2021 (S 63/2021, in operation 1 February 2021). Consent, notification, purpose limitation, accuracy, protection, retention, transfer limitation and accountability obligations apply to any organisation processing personal data, including data used to train or run an AI system. The PDPC issues advisory guidelines that explain how those obligations land on AI — one set for AI recommendation and decision systems from March 2024, and one for generative AI published in July 2026. Sectoral layers sit above: the Cybersecurity Act for critical information infrastructure, HSA guidance for software medical devices, and the Health Information Act 2026 once it is brought into operation.
- AI-specific rules
- No omnibus AI statute. Binding law reaches AI through the PDPA, with PDPC advisory guidelines explaining how. Voluntary governance comes from IMDA and the AI Verify Foundation: the Model AI Governance Framework (second edition, 2020), the Model AI Governance Framework for Generative AI (2024) with its nine dimensions, and the Model AI Governance Framework for Agentic AI launched in January 2026 and updated in May 2026, which is explicit that humans remain accountable for what an agent does. AI Verify supplies a testing framework against eleven governance principles plus an open-source toolkit, and the Global AI Assurance Sandbox connects deployers with specialist testers. In financial services MAS has FEAT, an AI model risk management information paper, the SAFR agentic framework, and proposed AI Risk Management Guidelines that were consulted on and are not yet final.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
PDPA section 26 imposes the Transfer Limitation Obligation, with the mechanics in Part 3 of the Personal Data Protection Regulations 2021. A transferring organisation has to take appropriate steps to ascertain whether, and to ensure that, the recipient is bound by legally enforceable obligations giving protection comparable to the PDPA. The PDPC recognises four routes: contract terms including the ASEAN Model Contractual Clauses, specified certifications such as Global CBPR and Global PRP, comparable foreign law, and binding corporate rules. There is no adequacy list, so there is no shortcut and no country that is simply fine — the question is answered per recipient, and it has to be evidenced. Most hosted model deployments export personal data, which means the transfer analysis is part of vendor selection rather than something to settle afterwards.
Regulators
Primary sources
- LegislationPersonal Data Protection Act 2012 — Singapore Statutes Online
- LegislationPersonal Data Protection Regulations 2021 (S 63/2021)
- StandardAI Verify Foundation — Model AI Governance Framework for Generative AI
- StandardAI Verify Foundation — AI Verify Testing Framework
- StandardAI Verify Foundation — Global AI Assurance Sandbox
- Regulator pageMDDI — Singapore launches new Model AI Governance Framework for Agentic AI
- Regulator guidanceMAS — FEAT Principles
- Regulator guidanceMAS — Artificial Intelligence Model Risk Management
- StandardMAS — Safeguards for Agentic Finance at Runtime
- Regulator pageMAS — Consultation on Guidelines on Artificial Intelligence Risk Management
- Regulator guidanceHSA — medical device guidance documents
- LegislationOnline Safety (Relief and Accountability) Act 2025
- LegislationCybersecurity Act 2018
- LegislationCybersecurity (Amendment) Act 2024
- LegislationHealth Information Act 2026
02Regulations and guidance
| Instrument | Status |
|---|---|
| AI VerifyA testing framework and open-source toolkit that assesses an AI system against eleven internationally recognised governance principles, each with desired outcomes, processes and documentary evidence. It is how a Singapore deployment demonstrates governance rather than asserting it. | In force |
| MAS AI Model Risk PaperMAS’s thematic review of how banks manage AI and generative AI model risk, setting out the practices it observed and expects. It is the most concrete statement of what a Singapore financial institution has to be able to show about a model it deploys. | In force |
| MAS AI Risk Guidelines (proposed)MAS’s proposed guidelines on AI risk management for financial institutions, covering generative AI and AI agents. Consulted on and not yet finalised, so it is a signal of where supervision is going rather than a rule anyone has to meet today. | Proposed |
| Cybersecurity ActRegulates measures against cybersecurity threats and incidents, persons responsible for certain computers and computer systems, and cybersecurity service providers. It reaches an AI deployment when the system it runs on is designated critical information infrastructure. | Partly in force |
| Cybersecurity (Amendment) ActAmends the Cybersecurity Act 2018, extending the regime beyond systems the owner physically controls — which is the change that matters when critical infrastructure runs on a third party’s cloud or a third party’s model. | Partly in force |
| AI Assurance SandboxAn IMDA and AI Verify Foundation initiative matching builders and deployers of generative AI applications with specialist technical testers, aimed at reducing testing barriers and feeding eventual technical testing standards. It covers applications, not the underlying foundation models. | In force |
| Health Information ActProvides for a national electronic health records system and for the collection, disclosure and use of health information about individuals. Passed and assented but not yet brought into operation, so it sets the direction for clinical AI in Singapore rather than binding it today. | Adopted, not yet applicable |
| MGF for Agentic AIIMDA’s framework for deploying AI agents, building on the 2020 Model AI Governance Framework. It recommends technical and non-technical measures to mitigate agent risks and is explicit that humans remain accountable for what an agent does. | In force |
| MGF for GenAIIMDA and the AI Verify Foundation’s framework for generative AI, structured around nine dimensions covering accountability, data, trusted development, incident reporting, testing and assurance, security, content provenance, safety research and public good. Voluntary, and the reference a Singapore regulator would measure against. | In force |
| OSRAA 2025Creates an office of the Commissioner of Online Safety and gives people affected by online harmful activity routes to redress, including rights of action in court. It reaches a generative product through what that product publishes or enables others to publish. | Partly in force |
| PDPASingapore’s general data protection statute. Consent, notification, purpose limitation, accuracy, protection, retention, transfer limitation and accountability obligations apply to any organisation processing personal data, including data used to train or run an AI system. | In force |
| PDP Regulations 2021Subsidiary legislation under the PDPA. Part 3 carries the mechanics of the Transfer Limitation Obligation — the requirements for a transfer, what counts as legally enforceable obligations on the recipient, and which specified certifications a recipient may hold instead. | In force |
| MAS FEAT PrinciplesThe Monetary Authority of Singapore’s founding AI expectations for financial institutions, covering fairness, ethics, accountability and transparency in the use of artificial intelligence and data analytics. Still current, and still the vocabulary a MAS supervisor uses. | In force |
| HSA SaMD GuidelinesThe Health Sciences Authority’s life-cycle guidance for software medical devices, which is where clinical AI in Singapore is actually regulated. It covers the product from development through change management, not only at first registration. | In force |
| SAFRMAS’s framework for governing AI agents in financial services, defining how agents should behave at runtime rather than only how they are approved. It is the sectoral counterpart to IMDA’s agentic framework and is aimed at the same problem from the supervisor’s side. | In force |
03Common enterprise issues
Personal data
Where the training data came from is a PDPA question
Web-scraped personal data may fall within the publicly available exception, but material behind a paywall or a registration barrier may not. Re-using existing customer data to build a generative feature generally needs consent or a notification designed for that purpose, and neither is retrofitted easily.
Automated decision-making
People have to be told, at a meaningful level, that a system decides about them
The PDPC expects an organisation to tell individuals that their personal data feeds a system that makes or supports decisions about them, in terms that mean something. "We use technology to improve your experience" does not discharge it, and the notice usually has to be written before the feature ships.
Cross-border transfers
There is no adequacy shortcut for a hosted model
Most hosted model deployments export personal data out of Singapore. With no adequacy list, each recipient needs contract terms, a recognised certification, comparable law or binding corporate rules, and the evidence has to exist per recipient — including the vendor’s own subprocessors.
Human oversight
Agentic deployments now have explicit official expectations
IMDA’s framework for agentic AI expects bounded autonomy, human approval at significant decisions, lifecycle technical controls and disclosure to the end user, and says plainly that humans remain accountable. It is voluntary, and it is the standard a Singapore regulator will reach for.
Sector rules
MAS expectations are hardening beyond FEAT
FEAT and the 2024 AI model risk paper are current, and MAS consulted in late 2025 on AI Risk Management Guidelines covering generative AI and agents. A financial institution building now will save rework by designing to the consultation draft rather than to FEAT alone.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.