Singapore has run its data-centre sector on persuasion. Green roadmaps, capacity calls, voluntary efficiency targets — carrots, mostly. The Digital Infrastructure Bill would end that arrangement. On 1 July 2026, the Ministry of Digital Development and Information and the Infocomm Media Development Authority opened a consultation on a Bill that would license the physical and virtual layers of the country's digital economy, with binding obligations and financial penalties behind them. The window closed on 22 July. What comes next is drafting, then codes of practice.
The design is deliberate. Singapore has declined to pass a horizontal AI act, preferring to fold AI into the statutes that already govern each sector. The Bill is that method applied at the compute layer. It targets neither models nor training data. It would license the data centres and cloud platforms those models run on — and in doing so pull the security, resilience and energy footprint of AI infrastructure into regulatory view.
What does the Digital Infrastructure Bill actually do?
The Bill would create two licences under one Act, both administered by IMDA, each aimed at a different failure mode: service outage and energy waste.
The first is a Major Foundational Digital Infrastructure licence, for operators whose outage would ripple through the economy. The second is a DC Operator licence, aimed at the sector's power and water draw. They can apply to the same building. A colocation operator that both runs a large facility and sells capacity to third parties would hold both, and IMDA has said it will streamline a joint application rather than run two processes. The Bill sits alongside the 2024 Cybersecurity Act amendments — it complements that regime, it does not fold into it.
Two verbs carry the weight here: license and enforce. IMDA would gain the power to grant, suspend and revoke licences, issue binding codes of practice, open investigations, and levy financial penalties. The numbers that will decide who passes — the exact PUE thresholds, the reporting timelines, the precise test for critical IT load — are not in the Bill. They come later, through separate regulations and codes of practice, after further consultation with operators. The statute builds the cage; the codes decide where the bars sit.
Which data centres and cloud providers fall in scope?
Scope turns on two numbers — a 3 MW power floor and a S$100 million revenue line — plus a 10 MW threshold that separates an ordinary facility from a systemically important one.
The DC Operator licence casts the widest net. Any data centre with a critical IT load of at least 3 megawatts falls in. That is a low bar. It captures mid-tier colocation providers and larger enterprise facilities, not just the named hyperscalers — the point worth underlining for any company running a sizeable private or on-premise data hall. Cross the line, and facility-level efficiency obligations attach.
The Major FDI licence is narrower and heavier. It captures data-centre facility services with a critical IT load of at least 10 megawatts that serve other parties, and cloud providers earning at least S$100 million a year from Singapore users through Infrastructure-as-a-Service and Platform-as-a-Service. The revenue figure is an average over the three preceding years, not a single spike, and SaaS is excluded. Clear the threshold on power or on revenue, and the security-and-resilience duties attach: physical and cyber controls, business continuity and disaster recovery, and mandatory reporting of cyber incidents and service disruptions to IMDA.
| Licence aspect | Major FDI Licence | DC Operator Licence |
|---|---|---|
| Primary concern | Security & resilience | Sustainability & efficiency |
| Who is captured | DC facilities ≥ 10 MW critical IT load (third-party); cloud IaaS/PaaS ≥ S$100M/yr from SG users (3-yr avg) | Any data centre ≥ 3 MW critical IT load |
| Core obligations | Physical + cyber security; business continuity & disaster recovery; incident & disruption reporting to IMDA | Facility-level PUE; water, renewables, GHG and economic-contribution factors |
| What it changes | New statutory duties alongside the Cybersecurity Act | Voluntary Green Data Centre Roadmap targets become enforceable |
| Penalty exposure | Higher of S$1M or 10% of Singapore turnover | Higher of S$1M or 10% of Singapore turnover |
What does non-compliance cost?
The penalty ceiling is the higher of S$1 million or 10 percent of the licensee's annual Singapore turnover — a figure built to bite a global platform, not just the operator that leases the hall.
A flat million-dollar fine is a rounding error to a global cloud provider. The turnover-linked alternative is not. For a platform booking hundreds of millions in Singapore revenue, that ceiling turns a licensing breach into a board-level number, echoing the turnover-linked approach regulators have reached for elsewhere. IMDA's other levers are quieter and sharper. A suspended or revoked licence is an existential event for a business whose product is uptime.
The obligations themselves read like a resilience checklist that many operators already run informally. The change is that they become auditable licence conditions, checked by a regulator with investigation powers, rather than commitments in a slide deck. Business continuity and disaster recovery move from best practice to filed evidence. Incident reporting acquires a statutory clock. For the compliance function, the Bill converts a set of assumptions into a schedule of obligations that someone has to own.
Why is Singapore regulating compute now?
Because the grid math has become impossible to ignore. Data centres account for roughly 7 per cent of Singapore's electricity consumption — the share the Ministry of Trade and Industry gave Parliament when it paused new builds — against 1 to 2 per cent in most countries. Analysts have projected that reaching about 12 per cent by 2030.
In absolute terms, Ember models Singapore's data-centre demand rising from roughly 5 TWh toward 8.4 TWh, against the 60 TWh of gross electricity the country generated in 2024. Higher numbers circulate: one press forecast put data centres at nearly 20 per cent of the national grid in 2026. That figure carries no stated source and implies around 12 TWh of demand — more than double what the modelled estimates support — so we report the sourced range and flag the gap rather than take the largest available number.
Either way the direction is the same, and it is the pressure behind the sustainability half of the Bill. A land- and power-constrained island cannot let unmetered demand run against a decarbonising grid. Singapore paused new data-centre builds between 2019 and 2022 over exactly this tension, then reopened capacity through green-conditioned allocation calls. The Bill is the next turn of that ratchet: it takes the Green Data Centre Roadmap and prior voluntary standards and makes them a legally enforceable baseline across the sector.
The resilience half answers a different anxiety. As more of the economy runs on a handful of cloud platforms and colocation campuses, their failure stops being a private commercial matter. Licensing is how a government asserts a public interest in infrastructure it does not own. The chosen method — sector statute, not omnibus AI law — keeps Singapore's regulatory surface narrow while extending its reach to the layer where AI actually consumes power and concentrates risk.
What it means for enterprise buyers and vendors
The obligations land on infrastructure providers, but the contractual pressure will travel downstream to everyone who buys from — or connects to — them.
Expect enterprise buyers to push the new expectations into their contracts. Tighter service-level commitments, explicit incident-notification clauses, and documented business-continuity evidence move from nice-to-have to procurement requirement, and not only for the licensed provider. The same demands flow to connectivity and backhaul partners, because a business-continuity obligation is only as strong as the diversity of the network paths beneath it. Every clause that demands path diversity becomes fresh demand for diverse subsea capacity, protected wavelengths, and multi-cable-system resilience sold into Singapore's hyperscalers and colocation operators.
The 3 MW line deserves a second look from anyone who assumed this was only a hyperscaler story. It is low enough to catch mid-tier operators and substantial private facilities. A company running its own large data hall may find itself inside a licensing regime it was not watching. The reach may also extend past the shoreline: Dentons Rodyk has flagged that the draft carries extraterritorial reach and imposes new statutory duties on providers — worth checking for any group whose overseas headquarters routes cross-border cloud or data-centre services to Singapore customers.
Preparing for the licensing regime?
Compare Singapore data-centre, cloud and cybersecurity providers that can evidence resilience, business continuity and incident response before the codes of practice land.
Get matched with a provider →The detail that will decide the sector's economics is still missing. The PUE thresholds, the reporting windows, the exact test for critical IT load — all of it waits on codes of practice that follow the Bill, not precede it. Operators are being asked to accept the frame before they can read the numbers inside it. What is already fixed is the line. At three megawatts, a Singapore data centre stops being a private asset and becomes a licensed one.
Frequently asked questions
When does Singapore's Digital Infrastructure Bill take effect?
It has not yet been enacted. The draft ran through public consultation from 1 to 22 July 2026. Detailed technical requirements, including the specific Power Usage Effectiveness thresholds, will be set later through separate regulations and codes of practice after the Bill is passed.
Does a 3 MW data centre really need a licence?
Under the draft, any data centre with a critical IT load of at least 3 megawatts would need a DC Operator licence. That threshold reaches mid-tier colocation and larger private or on-premise facilities, not only the largest operators.
What is the difference between the Major FDI licence and the DC Operator licence?
The Major FDI licence focuses on security and resilience for large or systemically important providers — data-centre facilities of at least 10 MW serving third parties, or cloud providers earning at least S$100 million a year from Singapore users through IaaS and PaaS. The DC Operator licence focuses on energy efficiency and sustainability for any data centre of at least 3 MW.
What is the penalty for breaching the regime?
The draft provides for a financial penalty up to the higher of S$1 million or 10 percent of the licensee's annual Singapore turnover, alongside IMDA's power to grant, suspend and revoke licences and to issue binding codes of practice.
Sources and further reading
- Primary source MDDI — Public Consultation on Digital Infrastructure Bill
- Primary source REACH — Public Consultation on the Digital Infrastructure Bill
- Primary source IMDA — Green Data Centre Roadmap
- Baker McKenzie — Singapore: MDDI and IMDA Consult on Digital Infrastructure Bill
- Allen & Gledhill — MDDI and IMDA seek comments on draft Digital Infrastructure Bill
- Dentons Rodyk — MDDI and IMDA consult on proposed Digital Infrastructure Bill
- Eco-Business — Singapore moves to strengthen data centre sustainability and resilience under new Digital Infrastructure Bill
- W.Media — Singapore's Digital Infrastructure Bill introduces S$1 million fine under new licensing regime
- CNA — Singapore puts 'temporary pause' on new data centres (MTI: data centres about 7 per cent of total electricity consumption)
- EMA — Singapore Energy Statistics, electricity generation (60 TWh gross output, 2024)
- Ember — ASEAN data-centre electricity demand (Singapore ~5 TWh rising toward 8.4 TWh)
- Nikkei Asia — Will Singapore warm to nuclear as 20% of electricity goes to data centers? (unsourced 2026 forecast, not corroborated)
Related resources
Go deeper on this topic
Vendor directories
Ready to move
Directory next step
Find Singapore providers for this work
Find Singapore providers that can evidence resilience, business continuity, incident response and energy-efficiency credentials as the licensing regime takes shape.
Compare data-centre, cloud and cybersecurity providers →Reader notes
Questions, corrections, and field notes
Curated notes from verified readers. Submissions are reviewed before publication.
Loading reader notes...


