Key takeaways
- Singapore governs AI through a three-layer model — national strategy (NAIS 2.0), voluntary frameworks (the Model AI Governance Frameworks and AI Verify), and binding law drawn from existing statutes — rather than a dedicated AI act.
- The real legal exposure sits in the PDPA: financial penalties up to 10% of annual Singapore turnover for larger organisations, and a three-calendar-day breach-notification window.
- The voluntary frameworks are optional on paper but de-facto procurement standards — regulators cite them, large buyers write them into contracts, and departing from them is hard to defend after an incident.
- The Agentic AI framework (January 2026, revised 20 May 2026) is the most procurement-actionable instrument: it names controls — approval gates, action logging, override-rate monitoring — that buyers can demand as contract deliverables.
- Sector gates are binding where they apply: MAS supervises AI model governance in finance, HSA approval is mandatory for medical-device AI, election-content law prohibits candidate deepfakes, and workplace fairness legislation will reach algorithmic hiring.
- Because no statute defines "compliant AI", the contract is the compliance mechanism — liability allocation, test evidence and data-processing terms must be negotiated, not assumed.
Quick facts
| Fact | Detail (as of July 2026) |
|---|---|
| Dedicated AI statute | None — no omnibus AI act equivalent to the EU AI Act |
| Lead agencies | IMDA and PDPC issue frameworks and data-protection rules; the National AI Council under the Prime Minister's Office coordinates strategy |
| National strategy | National AI Strategy 2.0 (December 2023) |
| Voluntary frameworks | Model AI Governance Framework (2019, 2nd ed. 2020); Generative AI edition (May 2024); Agentic AI edition (January 2026, revised 20 May 2026) |
| Testing & assurance | AI Verify toolkit + Project Moonshot — open source, not a certification scheme |
| Main binding law | PDPA, applied to AI via PDPC advisory guidelines (March 2024) |
| Maximum PDPA penalty | 10% of annual Singapore turnover (above S$10m local turnover) or S$1m otherwise |
| Breach notification | Three calendar days from assessing a breach as notifiable |
| Key sector rules | MAS FEAT principles and Veritas (finance); CSA Guidelines on Securing AI Systems (October 2024); MOH healthcare guidelines (2021) and HSA medical-device approval; election-content law (2024); workplace fairness legislation (passed January 2025, not yet in force) |
The 2026 landscape: guidance moves faster than statute
Singapore made a deliberate bet against an omnibus AI act. Instead of one risk-tiered statute on the EU model, it iterates voluntary frameworks quickly and enforces through laws that already exist. The pace is measurable: the Model AI Governance Framework for Agentic AI was first published in January 2026 and revised on 20 May 2026 — four months later — to add safety-and-reliability expectations for agent features, multi-agent risk, and a split of responsibilities between platform providers and system deployers. No statute anywhere revises on that cycle. The anchor above it all is the National AI Strategy 2.0 (December 2023), which commits to roughly tripling the AI practitioner pool to 15,000 and to accelerating public-sector adoption, coordinated through the National AI Council under the Prime Minister's Office.
Two developments define the current period. First, an assurance market is forming around AI Verify: the open-source testing toolkit, the Project Moonshot LLM evaluation tooling, and pilot programmes pairing deployers with third-party testers. The AI Verify Foundation counts Tier-1 vendors — Google, IBM, Microsoft and Salesforce among its premier members — which is one reason AI Verify artefacts increasingly appear in enterprise contract language. Second, the binding perimeter is widening at the edges: election law now prohibits digitally manipulated content misrepresenting candidates (2024), workplace fairness legislation passed in January 2025 will reach algorithmic hiring decisions when it takes effect, and the Digital Infrastructure Bill — in public consultation until 22 July 2026 — would license the large cloud and data-centre operators that AI workloads run on.
The trade-off buyers inherit is certainty. Under this model there is no statutory meaning to "compliant AI"; a vendor claim of alignment with the Model Framework is a self-assessment, not a licence. That burden matters because the base rate of AI project failure is poor — 2025 reporting on MIT research found roughly 95% of enterprise generative-AI pilots produced no measurable P&L impact, and Gartner forecasts more than 40% of agentic AI projects will be cancelled by end-2027. In a jurisdiction where governance is voluntary, a vendor's documentation discipline is one of the few observable proxies for operational discipline.
How Singapore regulates AI without an AI act
Singapore AI regulation is a three-layer system: national strategy sets direction, voluntary frameworks set expected practice, and binding force comes from existing laws of general application plus sector-specific rules. The design principle, stated consistently since 2019, is that humans remain accountable for AI-driven decisions, and that frameworks should emphasise explainability, fairness, transparency and human oversight rather than prescribe technology.
New binding law is reserved for narrow, demonstrated harms — deepfakes in elections being the clearest example — rather than for AI as a category. The practical consequence: the same chatbot deployment can be simultaneously unregulated as "AI" and heavily regulated as data processing, financial advice or a health product, depending on what it touches.
| Layer | Main instruments | Legal force | What it means for buyers |
|---|---|---|---|
| National strategy | NAIS 2.0 (Dec 2023), National AI Council | None — policy direction | Signals where grants, talent programmes and public-sector demand will concentrate. |
| Voluntary frameworks | Model AI Governance Frameworks (2019/2020, GenAI 2024, Agentic AI 2026), AI Verify | Voluntary; de-facto standard | The reference point for vendor due diligence and contract schedules; departure is hard to defend after an incident. |
| Binding law | PDPA + PDPC advisory guidelines, MAS rules, CSA guidance under the Cybersecurity Act, MOH/HSA rules, election law | Enforceable, with financial penalties | Where the actual liability sits. Most AI compliance failures in Singapore are prosecuted as data or sector failures, not "AI" failures. |
The voluntary layer: frameworks that behave like standards
Four instruments matter. All are voluntary; none certifies anything. Their commercial weight comes from adoption — regulators cite them, government procurement references them, and large deployers write them into vendor contracts.
| Instrument | Issued | Scope | Core content |
|---|---|---|---|
| Model AI Governance Framework | 2019; 2nd edition 2020 | General AI deployment | Internal governance, human oversight levels, operations management, stakeholder communication. The template most Singapore AI governance policies are built on. |
| Model AI Governance Framework for Generative AI | May 2024 | Generative AI | Nine dimensions across the lifecycle: accountability, data, trusted development, incident reporting, testing, security, provenance, safety R&D, public-good deployment. |
| Model AI Governance Framework for Agentic AI | Jan 2026; updated 20 May 2026 | Autonomous AI agents | Four dimensions: bound risks up front, keep humans meaningfully accountable, apply technical controls (access controls, guardrails, human approvals, logging, monitoring including human override rates), define end-user responsibility. |
| AI Verify + Project Moonshot | 2022; Foundation 2023; Moonshot 2024 | Testing & assurance | Open-source process checks and technical tests for fairness, explainability, robustness; Moonshot adds LLM benchmarking and red-teaming. Not a certification. |
Read the fine print on what these frameworks do not do. They do not allocate liability between vendor and deployer — that stays in the contract. They do not set quantitative thresholds; "fairness" is a process obligation, not a metric. And self-declared alignment is unaudited: any vendor can claim it, and many do. The agentic framework's May 2026 revision is the most procurement-relevant document of the set because it names concrete controls — approval gates, action logging, override-rate monitoring — that a buyer can demand as contract deliverables rather than aspirations.
The binding layer: the PDPA is where the teeth are
The Personal Data Protection Act is the closest thing Singapore has to an AI enforcement statute, because most commercially useful AI touches personal data at training, testing or deployment. The PDPC's Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (March 2024) resolved the main ambiguity in the vendor's favour: the business-improvement and research exceptions can cover training models on personal data an organisation already holds, without fresh consent, subject to conditions. In exchange, the guidelines raise expectations at deployment — organisations should be able to explain how personal data feeds recommendations and decisions, and accountability documentation is expected, not optional.
The penalty structure is material for enterprise deployments. Since the 2022 amendments took effect, financial penalties can reach 10% of annual Singapore turnover for organisations with local turnover above S$10 million, or S$1 million otherwise. Data breaches assessed as notifiable — significant harm, or significant scale at 500 or more individuals — must reach the PDPC within three calendar days of that assessment. An AI vendor with broad access to your customer data sits directly inside that exposure, which is why data-processing terms in AI contracts deserve more scrutiny than the model specifications.
Sector rules: finance first, then security, health and hiring
Sector regulators layer their own requirements on top, and finance is the deepest. MAS published the FEAT principles (fairness, ethics, accountability, transparency) in 2018 and built the Veritas methodology with a consortium of Tier-1 institutions to operationalise them. In December 2024 it published supervisory observations on AI model risk management from a thematic review of banks — effectively signalling that AI model governance is examined, not merely encouraged. Financial institutions should treat AI oversight as part of their existing technology-risk and model-risk obligations rather than a separate voluntary track.
Elsewhere: CSA's Guidelines on Securing AI Systems (October 2024) extend cybersecurity expectations across the AI lifecycle, covering adversarial attacks and supply-chain risk, with a companion guide of practical controls. In healthcare, the MOH's Artificial Intelligence in Healthcare Guidelines (2021) set development and deployment expectations, and AI that functions as a medical device is regulated by HSA under the Health Products Act — a genuinely binding gate. The Elections (Integrity of Online Advertising) amendments (2024) prohibit digitally manipulated election content that realistically misrepresents candidates. And workplace fairness legislation passed in January 2025 will, once in force, apply anti-discrimination obligations to hiring decisions regardless of whether a human or an algorithm made them.
Singapore vs the EU AI Act: two different bets
Multinationals deploying in both jurisdictions should not assume EU AI Act compliance covers Singapore, or vice versa. The instruments answer different questions: the EU regulates AI systems by risk class; Singapore regulates outcomes through whichever existing law the harm lands under.
| Dimension | Singapore | EU AI Act |
|---|---|---|
| Instrument | Voluntary frameworks + existing law (PDPA, sector rules) | Single binding regulation, risk-tiered, in force August 2024 with phased application through 2026–2027 |
| Prohibited practices | Narrow, harm-specific statutes (e.g. election deepfakes) | Categorical bans (social scoring, some biometric uses) |
| High-risk obligations | None as a class; sector regulators impose equivalents where they see fit | Conformity assessments, registration, post-market monitoring |
| Maximum penalties | PDPA: 10% of Singapore turnover or S$1m; sector penalties separate | Up to €35m or 7% of global turnover |
| Revision speed | Months (Agentic framework revised within four months of release) | Years (legislative amendment) |
| Buyer burden | High — buyer must define "acceptable" via contract and testing | Lower for classification, higher for paperwork |
Where the Singapore model is weak
A balanced read requires naming the costs of flexibility. First, voluntary frameworks generate compliance claims that are cheap to make and expensive to verify; there is no register of framework-aligned vendors and no audit regime behind the claim. Second, the model fragments: an AI deployment in a bank answers to MAS, PDPC, CSA guidance and IMDA frameworks simultaneously, each with different vocabulary, and no single regulator owns the whole system. Third, the absence of bright lines cuts both ways — it spares compliant vendors bureaucracy, but it also gives buyers no statutory floor to fall back on when a deployment goes wrong. Liability allocation is almost entirely contractual.
Against that, the enforcement that does exist is real. PDPA penalties scale with turnover, HSA approval is a hard gate for clinical AI, and MAS supervision reaches model governance in practice. The system is better described as selectively binding than light-touch: permissive where harms are speculative, enforceable where they are proven.
- Do not treat "voluntary" as ignorable. The Model Frameworks are what regulators, courts and counterparties will benchmark reasonable conduct against after an incident.
- Do not accept "AI Verify certified" claims. AI Verify is a testing toolkit, not a certification scheme. Ask for the actual test reports and the configurations tested.
- Do not assume consent is the only lawful basis for training data. The PDPC's 2024 guidelines allow specific exceptions — but conditions apply, and deployment-stage obligations remain.
What buyers should require from AI vendors
Because the frameworks are voluntary, the contract is the compliance mechanism. The practical move is to convert framework language into deliverables. From the agentic framework: named human approval points for consequential actions, action logging the buyer can access, and monitoring that reports human override rates. From the PDPC guidelines: a data-flow map showing what personal data the system touches and under which lawful basis, plus breach-notification clauses that fit inside the three-calendar-day PDPA window. From AI Verify: test reports for the deployed configuration — fairness and robustness results on your use case, not marketing benchmarks.
Vendor due diligence should also check regulatory adjacency: whether the vendor's cloud and data-centre dependencies would fall under the proposed Digital Infrastructure Bill, whether any healthcare functionality crosses into HSA territory, and — for financial-sector work — whether the vendor has delivered under FEAT/Veritas-style model documentation before. A vendor that has never produced model-risk documentation will not learn on your deployment cheaply.
Buyer checklist for AI procurement in Singapore
Cost of compliance: where the money actually goes
None of Singapore's AI governance instruments carries a licence fee. The Model AI Governance Frameworks are free publications, and AI Verify and Project Moonshot are open-source software. The cost of compliance is therefore almost entirely internal effort and professional services, and it scales with the risk profile of the deployment rather than with company size. There are no authoritative published benchmarks for AI governance spend in Singapore; treat any vendor-quoted "compliance package" price with the same scepticism as any other unaudited claim.
The recurring cost drivers, roughly in the order organisations encounter them:
- Governance staffing. The PDPA already requires every organisation to designate a data protection officer; in practice AI governance accountability usually lands on or near that role, plus a senior business owner. Larger deployers add model owners and a review committee.
- Documentation and testing. Risk assessments, data-flow maps, human-oversight design and AI Verify test runs are effort-intensive the first time and cheaper on repetition. This is the bulk of the baseline cost.
- Legal review. Converting framework language into contract schedules — liability allocation, breach-notification clocks, audit rights — is specialist drafting work, and the most consequential money spent in the whole exercise.
- Third-party assurance. Independent testing engagements are optional today but increasingly requested by enterprise counterparties. Pricing is bespoke professional-services work; no public rate card exists.
- Sector overlays. Financial institutions absorb AI into existing model-risk programmes (incremental cost, not greenfield); medical-device AI carries HSA regulatory submission costs and timelines that dwarf the governance baseline.
Implementation: standing up AI governance that survives contact
For an organisation deploying rather than building AI, a defensible governance baseline is a sequencing problem more than a technology problem. The pattern that works in practice:
- Inventory first. List every AI system in use or in procurement, including AI features embedded inside SaaS you already licence — those are the ones governance programmes miss.
- Classify against binding law. For each system, determine which enforceable rules apply: PDPA (almost always), MAS expectations, CSA guidance, MOH/HSA gates, election or hiring rules. This classification drives everything downstream.
- Adopt a framework baseline. Map each system to the relevant Model AI Governance Framework edition — general, generative or agentic — and record where your practice departs from it and why. A documented departure is defensible; an undocumented one is not.
- Assign accountability. A named executive owner per system, the DPO for data obligations, and explicit human approval points for consequential decisions. The frameworks are consistent on this: accountability must be human and traceable.
- Build the evidence pipeline. Testing (AI Verify or equivalent), action logging for agents, and monitoring that would surface drift or rising human override rates. Evidence generated continuously is cheap; evidence reconstructed after an incident is not.
- Remediate contracts. Bring existing AI vendor agreements up to the checklist above at renewal; hold new procurement to it from the first draft.
Stakeholders beyond IT: legal and the DPO own the PDPA analysis, procurement owns the contract schedule, security owns the CSA-aligned controls, and the business owner accepts residual risk in writing. A governance baseline for a first deployment is measured in weeks; MAS-supervised or HSA-gated deployments run months, driven by the regulator's clock rather than yours. Budget training time as well — the frameworks' human-oversight expectations assume the humans doing the overseeing know what the system does and when to intervene.
Common mistakes Singapore AI buyers make
- Reading "no AI law" as "no obligations". The PDPA, sector rules and general law apply in full. Most AI enforcement in Singapore arrives dressed as a data-protection or sector case.
- Accepting framework alignment as a claim rather than evidence. There is no register of aligned vendors and no audit behind the claim. Ask for the governance documentation itself.
- Believing "AI Verify certified". No such certification exists. The correct artefact is a test report for your deployed configuration.
- Assuming EU AI Act work covers Singapore. The regimes answer different questions; EU conformity paperwork says nothing about PDPA lawful bases or MAS model-risk expectations, and vice versa.
- Discovering the sector gate late. HSA approval for clinical AI and MAS scrutiny for financial models are schedule-defining. Classify before you shortlist vendors, not after.
- Leaving liability to the statute. No Singapore statute allocates responsibility for model errors, hallucinations or misuse between vendor and deployer. If the contract is silent, the deployer usually holds the exposure.
- Vendor notification clauses that miss the PDPA clock. A vendor promising breach notice "without undue delay" can still leave you unable to meet the three-calendar-day PDPC window. Put the number in the contract.
- Treating governance as a one-off project. The frameworks revise on cycles of months. A posture certified against the January 2026 agentic framework was already out of date by May 2026.
Outlook to 2030: where the regime is heading
Three trajectories are visible in the current instruments. First, the assurance market hardens. AI Verify started as a toolkit, gained a foundation with Tier-1 vendor members, and now anchors pilots pairing deployers with specialist third-party testers. The direction of travel is toward testing evidence as table stakes in enterprise procurement, and plausibly toward an accreditation regime for testers — at which point today's voluntary artefacts become tomorrow's tender requirements.
Second, the binding perimeter keeps widening at the edges, following the established pattern of legislating narrow, proven harms. Workplace fairness legislation will bring algorithmic hiring under anti-discrimination law when it takes effect. The Digital Infrastructure Bill — in consultation until 22 July 2026 — would license the major cloud and data-centre operators AI workloads run on, giving AI deployments an inherited resilience obligation. Buyers should expect the next narrow statutes to target harms that crystallise in production agentic systems, because that is where the framework activity already is.
Third, standards convergence does the work statute doesn't. ISO/IEC 42001, the international AI management system standard published in December 2023, is appearing in cross-border procurement alongside ISO 27001 and SOC 2, and IMDA has published crosswalk mappings between its testing framework and the NIST AI Risk Management Framework. For multinationals, the pragmatic 3–5 year strategy is to build one governance programme against the international standards and map it to Singapore's frameworks, rather than maintaining a Singapore-specific compliance track. What will not change is the cadence: expect the Model Frameworks to keep revising on months-long cycles, which makes governance a maintained posture, not an achieved state.
FAQ
Does Singapore have an AI law?
No. Singapore has no omnibus AI statute equivalent to the EU AI Act. AI is governed through voluntary frameworks from IMDA and the AI Verify Foundation, binding general laws — chiefly the PDPA — and sector rules from MAS, CSA, MOH and election law.
Is the Model AI Governance Framework mandatory in Singapore?
No. All three Model AI Governance Frameworks — general, generative AI and agentic AI — are voluntary. They still matter commercially: regulators reference them, large buyers write them into contracts, and departing from them is difficult to defend after an incident.
What is AI Verify?
AI Verify is an open-source AI governance testing framework and software toolkit maintained by the AI Verify Foundation. It combines process checks with technical tests for fairness, explainability and robustness. It is not a certification scheme and does not attest that a system is safe.
Can companies train AI models on personal data under the PDPA?
Yes, with conditions. PDPC advisory guidelines from March 2024 confirm the business-improvement and research exceptions can cover training on personal data an organisation already holds, without fresh consent. Conditions apply, and transparency and accountability obligations continue at deployment.
What penalties apply when an AI system misuses personal data in Singapore?
PDPA financial penalties reach 10% of annual Singapore turnover for organisations with local turnover above S$10 million, or S$1 million otherwise. Notifiable data breaches must be reported to the PDPC within three calendar days of being assessed notifiable.
Who regulates AI in Singapore?
No single AI regulator exists. IMDA and the PDPC issue the governance frameworks and data-protection rules, the National AI Council under the Prime Minister's Office coordinates strategy, and sector regulators — MAS for finance, CSA for cybersecurity, MOH and HSA for healthcare — apply their own binding requirements on top.
What is the Model AI Governance Framework for Agentic AI?
A voluntary framework for autonomous AI agents published in January 2026 and revised on 20 May 2026 — the first national framework dedicated to agentic AI. It sets four expectations: bound agent risks up front, keep humans meaningfully accountable, apply technical controls such as approval gates and action logging, and define end-user responsibilities.
Does the EU AI Act apply to Singapore companies?
It can. The EU AI Act reaches Singapore organisations that place AI systems on the EU market or whose systems' output is used in the EU. Compliance with one regime does not satisfy the other — multinationals must map Singapore's PDPA-and-frameworks model and the EU's risk-tiered regulation separately.
What is Singapore's National AI Strategy 2.0?
NAIS 2.0, launched in December 2023, is the national strategy coordinated by the National AI Council under the Prime Minister's Office. It targets roughly tripling the AI practitioner pool to 15,000 and accelerating public-sector adoption. It creates no legal obligations, but signals where grants, talent programmes and government demand will concentrate.
Is ISO/IEC 42001 required in Singapore?
No. ISO/IEC 42001, the international AI management system standard published in December 2023, is voluntary in Singapore. It is increasingly requested in enterprise and cross-border procurement because it offers an auditable governance signal that Singapore's voluntary frameworks, which have no audit regime, do not provide.
Final recommendations
Every organisation deploying AI that touches personal data — which is nearly all commercially useful AI — should treat the PDPA and the PDPC's 2024 AI guidelines as its baseline compliance obligation, adopt the relevant Model AI Governance Framework edition as its reference practice, and convert framework language into contract deliverables: named approval gates, accessible logs, test reports for the deployed configuration, and breach-notification clauses that fit the three-calendar-day window.
Financial institutions should fold AI into existing model-risk and technology-risk governance and assume MAS will examine it. Healthcare deployers should classify against the HSA medical-device gate before shortlisting vendors. Multinationals should build one governance programme against ISO/IEC 42001 and the NIST AI RMF and map it to Singapore's frameworks, rather than running a parallel local track.
Organisations running small internal pilots with no personal data and no consequential decisions can defer the heavier machinery — but should still keep the inventory and a one-page risk record per system, because pilots that succeed become deployments, and the paper trail is cheaper to start than to reconstruct. Across all cases, the operating assumption should be that Singapore's frameworks will keep revising on months-long cycles: budget for governance as a maintained posture, not a one-off certification exercise. This guide is buyer education, not legal advice; for deployments with material regulatory exposure, engage Singapore-qualified counsel.
Selected sources
- Smart Nation Singapore — National AI Strategy 2.0
- AI Verify Foundation — frameworks, toolkit and Project Moonshot
- PDPC — Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (2024)
- Singapore Statutes Online — Personal Data Protection Act 2012
- MAS — FEAT principles, Veritas, and AI model risk management observations (Dec 2024)
- CSA — Guidelines and Companion Guide on Securing AI Systems (Oct 2024)
- MOH — Artificial Intelligence in Healthcare Guidelines (2021)
- IMDA — Model AI Governance Frameworks and Digital Infrastructure Bill consultation
Find AI vendors and governance support
Browse Singapore AI and automation vendors, LLM providers and system integrators that can evidence governance documentation, testing artefacts and data-protection terms — the concrete items on the checklist above.
Browse AI & automation vendors →