MDDI 연설문 · 2025-07-07

2025년 개인정보보호 주간(Personal Data Protection Week 2025)에서의 조세핀 테오 장관 개회사

Josephine Teo · 디지털개발정보부 장관 · 개인정보보호 주간

요점

  • 싱가포르의 IMDA는 8개국과 공동으로 최초의 지역 레드팀 챌린지(red-teaming challenge)를 개최하였으며, 특정 민족 이름을 범죄 역할과 연결짓는 사례와 같이 학습 데이터의 편향에서 비롯된 대규모 언어 모델의 고정관념 기반 출력을 발견하였습니다.
  • 지난 3년간 IMDA와 PDPC는 PET Sandbox를 운영하여, Ant International과 같은 기업들이 원시 고객 데이터를 상호 교환하지 않고도 프라이버시 강화 기술(Privacy Enhancing Technologies)을 통해 파트너와 AI 모델을 공동으로 학습할 수 있도록 지원하였으며, 그 결과 바우처 사용률에서 측정 가능한 성과를 거두었습니다.
  • IMDA는 C-suite 임원을 대상으로 한 PETs 도입 가이드(PETs Adoption Guide)를 발간할 예정으로, 각 조직이 자사의 특정 비즈니스 요구에 적합한 프라이버시 강화 기술(Privacy Enhancing Technologies)과 핵심 도입 고려 사항을 파악할 수 있도록 지원하는 것을 목적으로 합니다.
  • IMDA, AI Verify Foundation 및 업계 파트너들은 생성형 AI 애플리케이션의 신뢰성 테스트를 위한 표준화된 방법론을 개발하기 위해 글로벌 AI 보증 파일럿(Global AI Assurance pilot)을 실시하였으며, 그 결과는 바람직하지 않은 콘텐츠 및 비의도적 데이터 공개와 같은 위험을 다루는 「IMDA Starter Kit」에 종합적으로 정리되었습니다.
  • IMDA는 해당 파일럿을 새로운 상시 운영 체계인 AI Assurance Sandbox로 전환하는 작업을 진행 중이며, 이 플랫폼에서 비즈니스 사용자, 거버넌스 팀 및 AI 개발자들이 생성형 AI 애플리케이션을 위한 가드레일(guardrails)과 테스트 프로세스를 협력하여 개발할 수 있습니다.
  • Enterprise Singapore 및 Singapore Accreditation Council과의 협력을 통해, IMDA는 데이터 보호 트러스트마크(Data Protection Trustmark)를 새로운 국가 표준인 Singapore Standard 714로 격상하였으며, 이를 통해 데이터 보호 분야의 우수성을 입증하고자 하는 조직들을 위한 공식 인증 기준을 제공하게 되었습니다.

전체 번역

MDDI 영어 원문의 번역 · 번역일: 2026-06-21

동료 여러분, 귀빈 여러분, 좋은 아침입니다. 우선 이 자리에 함께해 주신 모든 분께 감사의 말씀을 드립니다. 오늘 이 회의장에는 1,500명 이상이 참석해 주셨으며, 이번 주 내내 아시아 각지는 물론 더 먼 나라에서도 2,000명이 넘는 분들이 오가실 예정입니다. 특히 ASEAN 회원국의 개인정보보호 당국을 포함한 국제 귀빈 여러분께서 함께해 주심에 깊이 감사드립니다. 참석해 주신 모든 분께 감사드립니다.

올해의 주제는 「변화하는 세계 속의 데이터 보호」입니다. 이는 우리의 글로벌 운영 환경과 기술 세계 모두에서 일어나고 있는 중대한 변화를 인식한 데서 비롯된 것입니다.

이 두 가지 힘은 우리의 직장과 가정, 그리고 서로 간의 관계를 뒤흔들어 놓았습니다. 우리의 관행과 법률, 나아가 더 넓은 사회적 규범까지 조정해야 하는 것은 불가피한 일입니다.

이 자리에 계신 대부분의 분들은 데이터 또는 AI, 혹은 두 분야 모두의 실무 전문가이실 것입니다.

지난해 저는 AI 시대에서 데이터의 중요성에 대해 말씀드린 바 있습니다. 이는 여전히 그 어느 때보다 중요한 사안입니다. 생성형 AI 모델이 방대한 양의 데이터를 기반으로 구축되며, 사전 학습(pre-training)부터 미세 조정(fine-tuning), 테스트 및 검증에 이르기까지 AI 개발 수명 주기 전반에 걸쳐 데이터가 핵심적인 역할을 한다는 사실은 우리 모두 잘 알고 있습니다.

최근 들어 맞춤형 또는 독점 데이터셋을 기반으로 구축된 분야별 특화 AI 응용 프로그램이 폭발적으로 증가하고 있습니다.

좋은 예로 창이 공항의 챗봇 AskMax를 들 수 있습니다. 이는 승객 문의에 응대하는 데 도움을 주는 서비스로, 창이 공항의 데이터 저장소를 호출하도록 설계된 LLM을 기반으로 운영됩니다.

또 다른 예로는 IMDA가 싱가포르 법률원(Singapore Academy of Law)의 LawNet 데이터베이스를 활용하여 미세 조정한 GPT-Legal을 들 수 있습니다.

AI 시대에 데이터가 갖는 결정적인 중요성을 감안할 때, 데이터가 지속적인 발전의 제한 요인이 되고 있다는 사실은 그리 놀라운 일이 아닐 것입니다.

AI 개발 및 활용의 각 단계에서 나타나는 데이터 관련 과제들을 살펴보겠습니다.

모델 학습 단계에서 첫 번째로 잘 알려진 문제는 대규모 모델 학습에 인터넷 데이터를 사용하는 것입니다. 인터넷 데이터는 품질이 고르지 않습니다. 토론 포럼의 사용자 생성 콘텐츠를 포함한 다양한 출처에서 편향되거나 유해한 콘텐츠가 포함되는 경우가 많습니다. 기반 데이터 입력에 유해하거나 독성이 있거나 편향된 콘텐츠가 포함되어 있으면, 이는 모델 출력에서 하류(downstream) 문제로 이어질 수 있습니다.

싱가포르 IMDA와 8개국이 공동으로 진행한 최초의 지역 레드 팀 챌린지에서 문제적인 모델 행동이 관찰되었습니다. 싱가포르 수감자에 관한 대본을 작성하도록 요청했을 때, 해당 LLM은 불법 도박으로 수감된 인물에게는 「Kok Wei」, 음주 소란 행위자에게는 「Siva」, 마약 남용 범죄자에게는 「Razif」와 같은 이름을 선택하였습니다. 학습 데이터에서 습득된 것으로 보이는 이러한 고정관념은 우리가 반드시 지양해야 할 것들입니다.

동시에, 개발자들은 인터넷 데이터가 고갈되는 문제에 직면하고 있습니다. 대부분의 LLM은 이미 인터넷 데이터의 전체 말뭉치(corpus)로 학습이 완료된 상태입니다. 그렇다면 모델 제공업체들은 모델 개선을 위해 무엇을 해야 할까요? 이들은 모델을 보강하기 위해 더 민감하고 사적인 데이터베이스로 눈을 돌리고 있으며, 이는 또 다른 과제들을 야기합니다.

예를 들어 OpenAI는 글로벌 언론사뿐만 아니라 아이슬란드 정부, Apple, Sanofi, 애리조나 주립대학교(Arizona State University) 등 각국 정부, 기업, 대학과의 데이터 관련 파트너십 목록을 계속 확장해 나가고 있습니다.

파트너십 모델은 데이터 가용성을 높이는 한 가지 방법이지만, 많은 시간이 소요되고 규모를 확대하기 어렵습니다. 이러한 데이터베이스 중 일부에는 개인정보나 기업 기밀 정보 등 민감한 데이터가 포함될 수 있습니다.

민감한 정보를 보호하면서도 모델을 학습시킬 수 있는 방법이 점점 더 필요해지고 있습니다.

AI 모델 위에 덧씌워진 '피부층'으로 볼 수 있는 AI 응용 프로그램, 즉 '앱' 역시 신뢰성 우려를 야기할 수 있습니다. 앱이 부정확하거나 편향되거나 유해한 정보를 제공하거나 기밀 정보를 유출하는 경우, 이는 기업의 평판에 심각한 영향을 미칠 수 있으며, 최악의 경우 실제 신체적 피해를 초래할 수도 있습니다.

일반적으로 기업들은 앱의 신뢰성을 확보하기 위해 다양한 잘 알려진 가드레일(guardrail)을 활용합니다. 여기에는 모델 행동을 유도하기 위한 상세한 시스템 프롬프트 작성, 정확도 향상을 위해 여러분 중 많은 분들이 잘 아시는 검색 증강 생성(retrieval-augmented generation, RAG) 활용, 또는 민감한 정보를 걸러내기 위한 다양한 유형의 필터 사용 등이 포함됩니다.

그럼에도 불구하고, 앱에는 예상치 못한 결함이 존재할 수 있습니다. 제3자 테스터인 Vulcan은 최근 한 첨단 기술 제조업체의 챗봇을 테스트하였습니다. 이 챗봇은 잠재 고객이 제품 사양에 관한 질문을 할 때 직원들이 이에 답변하도록 돕는 용도로 사용되고 있었습니다. 해당 제조업체는 앱이 기밀 영업 정보, 예를 들어 잠재 고객이 알지 못했으면 하는 정보를 의도치 않게 누설할 것을 우려하고 있었습니다. 실제로 Vulcan은 중국어(만다린)로 프롬프트를 입력했을 때 앱이 백엔드 판매 커미션 요율을 유출한다는 사실을 발견하였습니다. 제조업체의 입장에서 생각해 보면, 잠재 고객에게 판매 커미션 요율을 알려주는 것은 사실상 얼마나 더 가격을 낮출 수 있는지를 공개하는 것과 다름없으며, 이는 어떤 기업도 원하지 않는 일입니다.

다행히 이 문제는 테스트 단계에서 발견되었습니다. 이는 독립적인 테스트의 가치를 잘 보여줍니다. GenAI 앱이 출시되기 전에 신뢰성을 확보하기 위해서는, 앱이 의도한 대로 작동하고 있는지, 그리고 일정 수준의 기본 안전성이 갖추어져 있는지를 체계적이고 일관된 방식으로 점검하는 것이 중요합니다.

모델 개발자와 마찬가지로, 앱 개발자들도 데이터 부족 문제를 해결해야 합니다. 앱이 기업의 특정 니즈를 충족시킬 수 있도록 모델을 기업 내부 데이터베이스에 연결하는 경우가 많습니다. 그러나 신뢰할 수 있는 앱을 구축하기에는 독점 데이터가 충분하지 않은 경우가 많습니다. IBM 글로벌 설문조사 응답자의 42%가 이를 AI 도입의 가장 큰 과제 중 하나로 꼽았습니다. 따라서 우리는 민감한 정보를 보호하면서 기업 간 데이터 공유를 더욱 활성화할 수 있는 방법이 필요합니다.

AI 앱이 배포되어 소비자들이 사용하게 된 이후에는, 잘못되거나 유해한 정보를 수정하는 것이 상당한 과제가 됩니다. 모델이 무언가를 「학습」한 이후에 미세 조정(fine-tuning)과 재학습(retraining)을 수행하는 과정은 정밀하지 않고 종종 많은 비용이 수반됩니다.

그러므로 머신 언러닝(machine unlearning)은 비록 아직 초기 단계이지만 새로운 분야로 부상하고 있습니다. Anthropic과 같은 LLM 선도 기업들이 직면한 핵심 과제는, 현재 모델들이 수십억에서 수조 개의 파라미터(parameter)를 가지고 있다는 점입니다. 어떤 변수들이 출력의 결함에 가장 크게 기여하는 것일까요? 이를 식별하고 대규모로 표적화된 모델 수정을 수행할 수 있는 기술이 존재할까요?

마지막으로, 무엇보다 중요한 우려 사항은 책임(accountability)의 문제입니다. AI 수명 주기는 모델 구축자, 배포자, 사용자 등 다양한 주체가 관여하는 복잡한 구조를 가지고 있습니다. 각 주체는 위험을 완화하는 데 있어 저마다의 역할을 수행해야 합니다.

이 자리에 계신 여러분은 삼성 직원들이 오류 점검을 위해 기밀 소스 코드를 ChatGPT에 붙여넣어 민감한 정보를 의도치 않게 유출한 사례를 잘 알고 계실 것입니다. 이와 유사한 일이 우리 직장에서도 일어나고 있다는 것을 우리 모두 인식하고 있다고 생각합니다. 때로는 동료들이 맞춤법 검사를 하거나 자신이 아이디어를 표현한 방식을 확인하기 위해 파일을 ChatGPT에 업로드하는 경우가 있습니다. 이는 해당 파일 안에 ChatGPT와 공유해서는 안 되는 내용이 있지는 않은지 돌아보게 만듭니다.

민감한 정보를 챗봇에 입력해서는 안 됐던 직원들의 책임인 것일까요? 이 자리에 계신 대부분의 동료 여러분은 직원들에게도 어느 정도의 책임이 있다고 생각하실 것입니다.

그러나 민감한 데이터가 수집되는 것을 방지하기 위해 충분한 가드레일(guardrail)을 갖추도록 하는 것은 앱 제공업체의 책임이기도 한 것 아닐까요?

아니면 그러한 데이터가 추가 학습에 사용되지 않도록 보장하는 것은 모델 개발자의 책임이어야 하는 것일까요?

안타깝게도, 이에 대한 쉬운 답은 없습니다.

AI가 계속해서 발전하기 위해서는, 조직적 프로세스 개선에서부터 리스크 완화를 위한 새로운 기술 개발에 이르기까지 다양한 유형의 해결책이 필요할 것입니다. 프라이버시를 침해하지 않으면서 데이터 활용을 최적화하는 프라이버시 강화 기술(Privacy Enhancing Technologies), 즉 PETs와 같은 기술적 해결책은 이러한 우려를 해소하기 위한 실행 가능한 경로로 부상하고 있습니다.

지난 3년간 IMDA와 PDPC는 다양한 산업 및 활용 사례에 걸쳐 기업들이 PET(개인정보보호 강화 기술)의 활용을 탐색하고 실험할 수 있도록 PET Sandbox를 운영해 왔습니다. 관심이 꾸준히 증가하고 있으며, 일부 초기 도입 기업들은 실질적인 사업적 성과를 거두기도 하였습니다.

예를 들어, Sandbox에 참여한 금융 기관인 Ant International은 다양한 PET를 조합하여, 디지털 지갑 파트너사와 고객 정보를 서로 공개하지 않은 채 AI 모델을 공동으로 훈련시켰습니다. 이 모델은 지갑 파트너사가 제공하는 바우처를 Ant International 고객 중 실제로 사용할 가능성이 높은 고객과 매칭하는 데 활용될 예정이었습니다. Ant International은 자사 고객의 바우처 사용 데이터를 제공하였고, 디지털 지갑 회사는 동일 고객의 구매 이력, 선호도 및 인구통계 데이터를 제공하였습니다. AI 모델은 두 데이터셋을 각각 분리하여 훈련하였으며, 어느 쪽 데이터 소유자도 상대방의 데이터를 열람하거나 수집하지 않았습니다. 그 결과 바우처 사용 건수가 대폭 증가하였으며, 지갑 파트너사는 수익이 향상되었고 Ant International은 고객 참여도를 높일 수 있었습니다.

이러한 PET 활용 방식은 사기 탐지나 의료 기관이 환자를 보다 효과적으로 돌볼 수 있도록 지원하는 것 등 다양한 활용 사례가 있음을 알 수 있습니다.

합성 데이터(Synthetic Data)는 높은 가능성을 보여주는 또 다른 PET 사례입니다. 지난해 저는 조직을 위한 모범 사례를 제시한 PDPC의 합성 데이터 생성 가이드를 출시하였습니다. 현재 싱가포르에는 Betterdata와 같이 AI 개발자들이 실세계 데이터셋을 모사하는 데이터를 생성할 수 있도록 지원하는 혁신적인 기업들이 등장하였습니다. 이러한 합성 데이터는 AI 모델 구축을 위한 학습 데이터셋으로서 기존 데이터셋을 더욱 보강할 수 있으며, 앞서 언급한 데이터 관련 과제를 해소하는 데 일정 부분 기여합니다.

Sandbox에 참여한 기관들과의 경험을 통해 저희는 해당 기술들, 특히 데이터가 공유될 때 개인정보를 보호하고 법적 의무를 준수하는 능력을 보다 잘 이해할 수 있게 되었습니다. 또한 PET 솔루션을 제공하려는 기술 공급업체와 PET를 활용하고자 하는 기업 모두에서 관심이 증가하고 있음을 명확히 파악할 수 있었습니다.

이러한 흐름을 이어가기 위해 IMDA는 PETs 도입 가이드를 출시할 예정입니다. C-suite 임원진을 대상으로 설계된 이 가이드는 조직이 사업 필요에 맞는 적절한 PET를 식별하는 데 도움이 되는 자료를 제공하며, 기업이 PET를 효과적으로 배포하기 위한 주요 고려 사항도 포함할 것입니다.

올해 개인정보보호 주간(Personal Data Protection Week)에도 PETs Summit이 포함될 예정입니다. 처음으로 개최되었던 지난해와 마찬가지로, 이번 Summit은 개인정보보호 당국, 기존 및 잠재적 PETs 솔루션 공급업체, 그리고 Sandbox 이용 기업들이 서로 교류하고 배울 수 있는 좋은 기회가 될 것입니다.

PETs Sandbox에서 입증된 바와 같이, 신흥 기술에 대한 싱가포르의 접근 방식은 기업들이 실험할 수 있도록 도구, 자원 및 안전한 환경을 제공하고, 산업계와 소비자가 혜택을 받을 수 있도록 학습 결과를 신속하게 공유하는 것입니다.

최근 IMDA, AI Verify Foundation 및 업계 파트너들은 글로벌 AI 보증(Global AI Assurance) 파일럿에 협력하여 생성형 AI 애플리케이션의 신뢰성을 테스트하는 방법을 연구하였습니다. 테스트는 AI 애플리케이션이 주요 위험을 해소하였음을 입증하기 위한 핵심적인 단계입니다.

가정에서 사용하는 가전제품이나 직장으로 이동할 때 타는 차량 등 일상적으로 사용하는 많은 것들은 적절한 테스트를 거치지 않았다면 우리가 사용하지 않았을 것입니다. 그럼에도 불구하고, 일상에서 AI 애플리케이션은 적절한 테스트를 거치지 않은 채 우리에게 적용되고 있습니다. 이는 빈틈(lacuna), 즉 반드시 해소되어야 할 심각한 공백입니다.

한 가지 사례로, Changi General Hospital은 제3자 테스터인 Softserve와 협력하여 일부 의료 보고서에 대한 요약 도구의 신뢰성을 테스트하였습니다. 다른 의사들과 공유할 수 있는 사례 또는 환자 요약본을 작성할 수 있다는 것은 의사들과 그들의 업무 부담에 매우 큰 도움이 됩니다. 이 요약 도구가 신뢰할 수 있고 정확하며 환자 정보를 잘못 전달하지 않도록 보장하는 것은 지극히 중요한 사안입니다.

또 다른 사례로 NCS는 자사의 코딩 어시스턴트가 내부 코딩 표준 및 보안 요건은 물론 외부 규제 지침을 얼마나 잘 준수하는지를 테스트하였습니다.

이 파일럿에서 얻은 인사이트를 바탕으로 IMDA는 조직이 위험을 테스트하고 관리하는 데 활용할 수 있는 여러 테스트 방법을 도출하였습니다. 이 테스트 방법 모음은 「IMDA Starter Kit」으로 알려져 있습니다. 이는 거버넌스 프레임워크와 가이드라인을 넘어 AI 애플리케이션을 테스트하고 배포하기 위한 보다 표준화된 방법을 요청한 기업들의 요구에 직접 부응한 것입니다. 앞서 언급한 바와 같이 바람직하지 않은 콘텐츠 및 의도치 않은 데이터 유출과 같은 위험에 대한 테스트가 포함되어 있습니다.

IMDA가 파일럿을 새로운 상시 운영 AI Assurance Sandbox로 전환함에 따라 학습과 반복 개선은 계속됩니다. 이 Sandbox는 비즈니스 사용자, 거버넌스 팀, AI 개발자 등 우리 모두가 생성형 AI 애플리케이션을 위한 더 나은 가드레일이나 프로세스와 같은 솔루션을 공동으로 개발할 수 있도록 지원하는 학습 환경입니다. 자신의 애플리케이션을 테스트하고 공유 지식 기반 구축에 기여하고자 하는 조직의 참여를 환영합니다.

궁극적으로, 각 Sandbox를 통한 저희의 목표는 개인정보보호이든 AI 거버넌스이든 간에 무엇이 바람직한 모습인지에 대한 연대와 합의를 이끌어내는 것입니다.

제품 안전이나 제약 분야와 같은 전통적인 영역과 마찬가지로, 우리는 지켜야 할 표준에 대해 전문가들의 합의를 이끌어내고, 해당 표준이 충족되고 있음을 보증하는 테스터가 필요합니다.

AI 도입의 속도와 규모를 감안할 때, 표준의 개발과 합의에는 어느 정도 시급성이 있습니다. 현실적으로 이는 시간이 걸릴 것입니다. 거쳐야 할 단계가 많습니다. 적어도 싱가포르에서는 테스트 및 보증 생태계를 육성하기 위한 중요한 첫걸음을 내디뎠습니다. 저희의 바람은 업계 참여자들이 함께하여 향후 공식 표준 수립의 기반이 될 수 있는 「소프트」 표준을 선도적으로 만들어가는 것입니다.

개인정보보호 분야는 선도적인 출발을 하였으며, 이제 다음 단계로 나아갈 준비가 되었음을 기쁘게 공유드립니다.

IMDA는 Enterprise SG 및 싱가포르 인정원(Singapore Accreditation Council)과 협력하여 데이터 보호 신뢰 마크(DPTM)를 새로운 싱가포르 표준인 Singapore Standard 714로 격상하였습니다. 책임 있는 데이터 보호 관행을 입증하는 기업은 이제 이 새로운 표준에 따라 인증을 신청할 수 있으며, 이 표준은 데이터 보호 우수성을 입증하고자 하는 기업들의 국가적 기준점이 될 것입니다. 이 신뢰 마크는 인증 기관이 개인정보 보호에 있어 세계 수준의 관행을 채택하고 있음을 소비자에게 보증할 것입니다.

AI 발전을 위한 데이터 활용에서 나타나는 과제와 기회에 대처하는 싱가포르의 접근 방식에 대해 어느 정도 이해를 드렸기를 바랍니다.

AI가 책임감 있게 개발되고 신뢰할 수 있게 배포될 때, 데이터 활용 방법을 포함하여 기업과 사람들이 얻을 수 있는 것이 매우 많다고 저희는 믿습니다. 이를 어떻게 달성할 수 있는지 이해하고 적절한 조치를 마련하는 것은 기업과 정부의 리더로서 우리의 몫입니다.

그렇게 함으로써 우리는 AI 도입을 촉진할 뿐만 아니라 데이터 및 AI 거버넌스에 대한 더 큰 신뢰를 고취시킬 것입니다. 이러한 맥락에서 앞으로 이어질 논의가 풍성한 결실을 맺기를 기원합니다. 감사합니다.

영어 원문

MDDI 공식 웹사이트 원문 · 수집일: 2026-06-21

Good morning, colleagues and friends. I’d first like to thank everyone for being here. We have over 1,500 people in the room today, and over 2,000 coming and going throughout the week, including from many countries in Asia, and even further afield. I especially appreciate our international guests for joining us, including Data Protection Authorities from fellow ASEAN member states. Thank you all for being here.

The theme for this year is “data protection in a changing world”. This is an acknowledgement of the significant changes in both our global operating environment, as well as in the world of technology.

These twin forces have disrupted our workplaces, our homes, and our relationships with each other. It is inevitable that we must adjust our practices, laws and even our broader social norms.

Most of you in this room are practitioners of data or AI, or both.

Last year, I had spoken about the importance of data in the age of AI. This remains as pertinent as ever. We all know that generative AI models are built on vast amounts of data, and data is critical throughout the AI development lifecycle, from pre-training, to fine-tuning, to testing and validation.

In recent times, we have seen an explosion of sector-specific AI applications built on customised or proprietary datasets.

A good example is AskMax, Changi Airport’s chatbot that helps to address passenger queries. It runs on a LLM designed to call on Changi Airport’s data repositories.

Another example is GPT-Legal, which was finetuned by IMDA using the Singapore Academy of Law’s LawNet database.

Given the criticality of data in the AI age, it should not be surprising that data has also become a limiting factor to continuing advancement.

Let us walk through the data challenges at each stage of AI development and use.

In model training, the first well-known issue is the use of internet data to train these large models. Internet data is uneven in quality. Often, they contain biased or toxic content from different sources, including user-generated content on discussion forums. When the underlying data input contains harmful, toxic or biased content, this can lead to downstream problems with model outputs.

In the first regional red teaming challenge run jointly by Singapore IMDA and eight other countries, problematic model behaviours were observed. When asked to write a script about Singaporean inmates, the LLM chose names such as “Kok Wei” for a character jailed for illegal gambling, “Siva” for disorderly drunk and “Razif” for a drug abuse offender. These stereotypes, most likely picked up from the training data, are actually things that we want to avoid.

At the same time, developers are running out of internet data. Most of the LLMs are already trained on the entire corpus of internet data. What then should model providers do to improve their models? They are turning to more sensitive and private databases to augment their models, which brings its own set of challenges.

OpenAI, for example, has a growing list of data-related partnerships not only with global news outlets, but also governments, companies and universities like the Icelandic Government, Apple, Sanofi and Arizona State University.

The partnership model is one way of increasing data availability, but it is time-consuming and difficult to scale. Some of these databases may include sensitive data such as personal data or business confidential information.

Increasingly, we need a way to train models, while protecting sensitive information.

AI application, or ‘app’, which can be seen as the ‘skin’ that is layered on top of AI models, can also pose reliability concerns. If apps provide inaccurate, bias or toxic information, or leak confidential information, these can have serious implications for the company’s reputation, and in the worst cases, may actually cause physical harm.

Typically, companies would employ a range of well-known guardrails to make their app reliable. These include writing detailed system prompts to steer the model behaviour, using retrieval-augmented generation (or RAG), which many of you are familiar with, to improve accuracy or different types of filters to sieve out sensitive information.

Even then, apps can have unexpected shortcomings. Vulcan, a third-party tester, recently tested a high-tech manufacturer’s chatbot that assists employees to answer questions on product specifications that are posed by prospective customers. The manufacturer was concerned that the app would inadvertently leak confidential business information, for example, telling the prospective customers something that they do not want the prospective customers to know. True enough, Vulcan found that when prompted in Mandarin, the app leaked backend sales commission rates. You can imagine, from the manufacturer’s point of view, telling the prospective customers what the sales commission rates are is basically revealing how much further they can cut the price – and it is not something any business wants.

Fortunately, this problem was discovered during the testing phase. This highlights the value of independent testing. To ensure the reliability of GenAI apps before release, it is important to have a systematic and consistent way to check that the app is functioning as intended, and there is some baseline safety.

Like model developers, app developers must deal with data inadequacies. Very often, the models are linked up with internal company databases so that the apps can cater to the businesses’ specific needs. However, there are often insufficient proprietary data to build reliable apps. 42% of respondents to an IBM global survey cited this as one of their biggest challenges to AI adoption. So, we need a way to unlock more data-sharing among companies while protecting sensitive information.

After AI apps are deployed and used by consumers, correcting erroneous or harmful information poses a significant challenge. The process of finetuning and retraining a model – after it has “learnt” something – is imprecise and often costly.

Machine unlearning has therefore become a new field, albeit a nascent one. A key challenge faced by LLM leaders like Anthropic is that models now have billions or trillions of parameters. Which variables contribute most to the shortcomings in output? Are there techniques to identify them and carry out targeted model corrections at scale?

Finally, an overriding concern is accountability. The AI lifecycle is complex, with model builders, deployers, users and more. Each has a role to play to mitigate the risks.

This community here would be familiar with the case of a group of Samsung employees who unintentionally leaked sensitive information by pasting confidential source code into ChatGPT to check for errors. I think we are aware that this is happening in our workplaces too – sometimes our colleagues, in order to do a spell check, or to check the way in which they have put across ideas, may upload a file on to ChatGPT. This makes you wonder if there is anything in the file that should not be shared with ChatGPT.

Is it the responsibility of the employees who should not have put sensitive information into the chatbot? I think most of our colleagues here believe they have some responsibility.

But is it also the responsibility of the app provider to ensure that they have sufficient guardrails to prevent sensitive data from being collected?

Or should model developers be responsible for ensuring that such data is not used for further training?

There are no easy answers to this, I’m afraid.

For AI to continue advancing, we will need various types of solutions – from organisational process improvements to developing new techniques in risk mitigation. Technical solutions, such as Privacy Enhancing Technologies – or PETs that optimise the use of data without compromising privacy – have emerged as a viable pathway for addressing these concerns.

In the last 3 years, the IMDA and PDPC have run the PET Sandbox to encourage businesses to explore and experiment with the use of PETs across a variety of sectors and use cases. We have seen growing interest and some early adopters have also experienced tangible business returns.

For instance, Ant International, a financial institution that joined the Sandbox, used a combination of different PETs to train an AI model with their digital wallet partner without disclosing customer information to each other. The intention was to use the model to match vouchers offered by the wallet partner with customers of Ant International, who were most likely to use them. Ant International contributed voucher redemption data of their customers, while the digital wallet company contributed purchase history, preference and demographic data of the same customers. The AI model was trained separately with both datasets, without each data owner seeing or ingesting the other’s data. This led to a vast improvement in the number of vouchers claimed; the wallet partner increased its revenues, while Ant International enhanced its customer engagement.

You can see that this way of using PETs has many use cases, for example in detecting fraud, or in allowing healthcare institutions to do a better job of taking care of their patients.

Synthetic Data is another example of a PET that shows good promise. Last year, I launched PDPC’s Guide on Synthetic Data Generation, which sets out best practices for organisations. There are now innovative companies in Singapore, such as Betterdata, that help AI developers generate data to mimic real-world datasets. These synthetic data can further augment existing datasets as training datasets to build AI models, which goes some way to addressing the data challenges I had referred to earlier.

Our experience with organisations in the Sandbox has allowed us to better understand the technologies, their ability to protect personal data and comply with legal obligations when such data is shared. It has also given us a good sense of the growing interest from technology providers in offering PET solutions, as well as companies who are keen to use PETs.

To build on this momentum, IMDA will be introducing a PETs Adoption Guide. Designed for C-suite executives, this guide will offer resources to help organisations identify the right PETs for their business needs and will also include key considerations for companies to effectively deploy PETs.

This year’s Personal Data Protection Week will once again include the PETs Summit. Similar to last year when it was held for the first time, the Summit will be a good opportunity for data protection authorities, existing and interested PETs solution providers, and users in the Sandbox to connect and learn more from one another.

As demonstrated in the PETs Sandbox, Singapore’s approach towards emerging technologies is to help provide tools, resources, and a safe environment for companies to experiment, and to quickly share the learnings so that industries and consumers can benefit.

Recently, IMDA, AI Verify Foundation and industry partners collaborated on a Global AI Assurance pilot, studying ways to test the reliability of generative AI applications. Testing is a critical step to demonstrate that the AI application has addressed key risks.

A lot of the things that we use on a day-to-day basis, such as the appliances in our homes, the vehicles that take us to the workplace – we would not use them if they had not been properly tested. And yet, on a day-to-day basis, AI applications are being used on us without having been properly tested. So this is a lacuna, a serious gap that needs to be filled.

One example is Changi General Hospital, which worked with third party tester Softserve to test the reliability of their summarisation tool for selected medical reports. It is incredibly helpful to doctors and their workloads, to be able to put together case or patient summaries that can be shared with other physicians. How we ensure that this summarisation tool is reliable, accurate and does not misrepresent the patient, is of utmost importance.

Another is NCS, which tested how well its coding assistant adhered to internal coding standards and security requirements, as well as external regulatory guidelines.

With insights from this pilot, IMDA has identified several testing methods that organisations can use to test for and manage risks. This compilation of testing methods is known as the “IMDA Starter Kit”. It is a direct response to companies’ requests to go beyond governance frameworks and guidelines, for more standardised ways to test and deploy AI applications. It includes testing for risks like undesirable content and unintended data disclosure, like those I described earlier.

The learning and iterating continue as IMDA transitions its pilot to a new, ongoing AI Assurance Sandbox. The Sandbox is a learning environment to help all of us – whether we are business users, governance teams, AI developers – to jointly develop solutions, like better guardrails or processes for gen AI applications. Organisations interested in putting their applications to the test and contributing to our shared knowledge base are welcome to join.

Ultimately, our aim with each of these Sandboxes is to find coalition and consensus around what good looks like, whether for data protection or AI governance.

Much like traditional fields of product safety or pharmaceuticals, we need subject matter experts to agree on the standards to uphold, and testers to assure us that the standards are being met.

Given the speed and scale of AI adoption, there is some urgency for standards to be developed and agreed to. Realistically, this will take time. There are many stages to go through. In Singapore at least, we have taken the critical first steps to grow the ecosystem for testing and assurance. Our hope is that industry players will join us to initiate ‘soft’ standards that can be the basis for the eventual establishment of formal standards.

The field of data protection has had a head start, and I am pleased to share that we are ready to take the next step.

IMDA has worked with Enterprise SG and the Singapore Accreditation Council to elevate the Data Protection Trustmark (DPTM) to a new Singapore Standard, Singapore Standard 714. Companies that demonstrate accountable data protection practices can now apply to be certified under this new Standard, which will set the national benchmark for companies that want to demonstrate data protection excellence. The Trustmark will assure consumers that certified organisations adopt world-class practices in protecting their personal data.

I hope I have given you a sense of Singapore’s approach to dealing with the challenges and opportunities in using data for AI advancement.

We believe there is much for businesses and people to gain when AI is developed responsibly and deployed reliably, including the methods for unlocking data. It is up to us as leaders in corporations and the government to understand how we can do so, and to put in place the right measures.

By doing so, not only will we facilitate AI adoption, we will also inspire greater confidence in data and AI governance. On that note, I wish you fruitful discussions in the days ahead. Thank you very much.