Detailed overview
Singapore does not currently have a single comprehensive AI Act equivalent to the EU AI Act. Instead, Singapore uses a strong governance-based approach built around official AI frameworks, AI testing tools, data-protection guidance and sectoral rules. This approach is designed to support responsible AI deployment without creating a broad AI licensing regime.
Model AI Governance Framework
Singapore's Model AI Governance Framework provides practical guidance for organisations using AI. It focuses on explainability, transparency, fairness and human-centred governance. The framework covers internal governance, roles and responsibilities, human involvement in AI-augmented decision-making, operations management, bias reduction, robustness, stakeholder communication and feedback channels.
Generative AI
Singapore has also developed a Model AI Governance Framework for Generative AI. It addresses generative AI systems that can produce text, images, audio, video or other media. The framework identifies risks such as bias, hallucination, lack of explainability, copyright issues, privacy and confidentiality risks, misuse, deepfakes and value-alignment concerns. Its governance dimensions include accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for public good.
Agentic AI
Singapore also has a framework for agentic AI, meaning AI systems that can perform tasks more autonomously and act on behalf of users or organisations. The official framework focuses on bounding risks upfront, keeping humans meaningfully accountable, setting technical controls throughout the lifecycle and helping end-users understand their responsibilities through transparency and training.
Data protection
Where AI processes personal data, Singapore's Personal Data Protection Act and PDPC guidance are important. PDPC's advisory guidelines on AI recommendation and decision systems address data minimisation, consent, notification, legitimate interests, privacy by design, security, pseudonymisation, anonymisation, data-protection impact assessments and protection against AI privacy attacks such as model inversion.
Penalties
Singapore's AI governance frameworks are not a single AI penalty regime. Penalties may arise under the Personal Data Protection Act where AI involves unlawful personal-data processing, and under other applicable laws where AI affects consumers, financial services, healthcare, cybersecurity, intellectual property, online content or sector-specific obligations.
Practical requirements & details
Sourced from the Model AI Governance Framework (PDPC/IMDA, 2nd edition 2020), the Model AI Governance Framework for Generative AI (May 2024), the Framework on Agentic AI (2025), the PDPA, PDPC's Advisory Guidelines on AI recommendation and decision systems, and AI Verify.
Model AI Governance Framework (foundational)
- Internal governance structures and measures.
- Determining the level of human involvement in AI-augmented decision-making.
- Operations management (data quality, model selection, monitoring).
- Stakeholder communication and feedback.
Generative AI Framework β 9 dimensions
- Accountability; Data; Trusted Development and Deployment; Incident Reporting; Testing and Assurance; Security; Content Provenance; Safety and Alignment R&D; AI for Public Good.
Agentic AI Framework
- Bound risks upfront via design choices and safety constraints.
- Keep humans meaningfully accountable through clear ownership and override mechanisms.
- Apply technical controls across the agent lifecycle.
- Support end-users via transparency, training and observability.
PDPA + Advisory Guidelines
- Lawful basis (consent or legitimate interests business-improvement/research exceptions for AI).
- Notification, data minimisation, purpose limitation, security.
- Privacy by design, pseudonymisation/anonymisation, DPIAs for high-risk AI.
- Protection against model inversion, membership inference and other AI privacy attacks.
AI Verify and AI Verify Project Moonshot
- Open-source testing toolkit aligning AI systems with international principles.
- Project Moonshot: pre-deployment evaluation for generative-AI safety, bias and robustness.
Penalties
- PDPA breach: up to SGD 1 million or 10% of annual turnover in Singapore (whichever is higher).
- Cybersecurity Act, Computer Misuse Act, IP Act, Securities and Futures Act, MAS sectoral rules apply as relevant.