MDDI 연설문 · 2026-07-20

싱가포르 데이터 페스티벌(Sands Expo and Convention Centre)에서의 조셉린 테오 장관 개회 연설

Josephine Teo · 디지털개발정보부 장관 · 싱가포르 데이터 페스티벌 at Sands Expo and Convention Centre

요점

  • 싱가포르는 「개인정보보호주간」(Personal Data Protection Week)을 「싱가포르 데이터 페스티벌」(Singapore Data Festival)로 확대하여 데이터와 비즈니스 가치에 관한 광범위한 질문들을 다루고 있으며, 특히 AI 노력을 지원하고 있습니다.
  • IMDA는 조직이 AI와 데이터를 결합하여 운영 최적화를 위한 디지털 쌍둥이를 설계할 수 있도록 돕기 위한 실용적인 가이드인 「엔터프라이즈용 디지털 쌍둥이 플레이북」(Digital Twin For Enterprises Playbook)을 출시하고 있습니다.
  • 시설관리 회사 Exceltec는 70개 이상의 현장에서 수집한 센서 데이터를 활용한 디지털 쌍둥이 시스템을 배포하여 문제 감지를 자동화함으로써 점검팀이 매일 약 45분을 절약할 수 있게 했습니다.
  • PDPC는 조직이 개인정보를 생성형 AI 모델을 개발하거나 개선하는 데 사용할 때 명확하고 구체적인 공지를 제공하도록 요구하는 「생성형 AI의 개인정보 사용에 관한 권고 지침」(Advisory Guidelines on the Use of Personal Data in Generative AI)을 발행하고 있습니다.
  • IMDA는 챗봇의 목적, 제한사항, 데이터 처리, 사용자 구제 방안을 명확히 공시하는 자발적 정보 카드 형식의 「생성형 AI 챗봇 투명성 지침」(Generative AI Chatbot Transparency Guidelines)을 출시하고 있습니다.

전체 번역

MDDI 영어 원문의 번역 · 번역일: 2026-07-28

안녕하세요, 동료 여러분, 친구 여러분. 월드컵 결승이 불과 4시간 전에 있었습니다. 저는 월요일 아침 교통이 어느 정도 있을 것으로 예상해서 일찍 도착했는데, 오늘은 도로가 매우 조용하네요. 여러분의 응원팀이 우승했기를 바랍니다.

스코어는 실제로 상당히 흥미로웠습니다. 스페인이 마지막으로 월드컵을 우승했을 때도 비슷한 스코어였습니다. 흥미롭게도 데이터에 따르면 월드컵 우승에 이르는 과정에서 1골 이상의 실점을 허용하지 않았습니다. 스페인 팀에 경의를, 그리고 여전히 여기 자리해주신 여러분에게도 경의를 드립니다. 정말 데이터를 사랑하시는군요. 박수를 받을 만합니다.

오늘 참석하신 많은 분들이 저희가 개인정보 보호 주간을 개최했을 때 함께해주셨습니다. 올해 저희는 이 행사를 싱가포르 데이터 페스티벌로 확대했습니다. 몇몇 분께서 이를 저에게 지적해주셨습니다.

이는 개인정보 보호가 더 이상 중요하지 않기 때문이 아닙니다. 여전히 중요합니다.

다만 조직들은 데이터에 관해 더 큰 질문을 던지고 있으며, 특히 자신들의 AI 사업을 어떻게 지원할지에 관해 묻고 있습니다.

따라서 데이터 페스티벌은 우리가 데이터의 비즈니스 가치를 더욱 잘 인식하도록 설계되었습니다. 동시에 지속가능한 가치를 창출하기 위해서는 싱가포르와 지역에서 신뢰할 수 있는 데이터 생태계를 구축하기 위해 함께 노력해야 합니다. 그래서 데이터를 비즈니스 가치의 원천으로 하는 부분에 대해 조금 더 이야기해보겠습니다.

비즈니스 가치의 원천으로서의 데이터

아시다시피, 기업들은 그렇게 부르든 말든 항상 데이터를 사용해왔습니다.

소매업자들은 판매 데이터를 살펴보면서 고객 선호도의 변화를 파악하고 그에 따라 재고 수준을 조정합니다.

은행들은 거래 데이터를 살펴보면서 사기의 증거를 찾고, 어느 계좌와 거래 상대방이 문제가 되는지, 그리고 어떻게 대처할지를 결정합니다.

데이터는 예전에 기업들에게 무슨 일이 일어났는지를 알려주었습니다. 모두 과거형이었습니다. 하지만 이제 기술의 도움으로 기업들은 일어나는 일들을 거의 실시간으로 볼 수 있으며, 데이터를 적절히 활용하면 기업들이 늦게 행동하기보다는 빨리 올바른 행동을 취하도록 도울 수 있습니다.

우리 모두는 뜻밖의 상황에 놀라기보다는 먼저 행동할 수 있기를 원합니다. AI가 이 과정을 가속화합니다. AI 시스템은 생명주기의 모든 단계에서 데이터에 의존합니다. 실제로 IMDA는 AI 이전에 데이터에 관해 일관되게 이야기해왔습니다. 하지만 좋은 데이터 없이는 가장 좋은 시스템도 유용한 결과를 도출하기 어려울 것입니다.

그러므로 AI 시대에는 데이터 거버넌스의 중요성이 줄어드는 것이 아니라 오히려 더해집니다.

데이터는 신뢰가 있을 때만 가치를 창출합니다.

본질적으로 데이터 거버넌스는 신뢰에 관한 것입니다.

고객들은 조직이 그것을 적절히 보호하고 책임감 있게 사용할 것이라고 신뢰할 때만 데이터를 공유합니다.

기업들은 그 데이터가 자신들의 이익을 침해하기 위해 악용되지 않을 것이라고 신뢰할 때만 파트너와 데이터를 공유합니다.

이것이 싱가포르가 개인정보 보호를 정상적으로 작동하는 비즈니스 환경에 필수적인 것으로 항상 생각해온 이유입니다. 실제로 그것은 비즈니스 혁신의 핵심입니다.

신뢰할 수 있는 데이터 사용을 위한 올바른 조건 구축

우리는 또한 신뢰할 수 있는 데이터 거버넌스를 위해서는 올바른 역량과 명확한 책임성이 필요하다고 믿습니다. 이 두 가지가 동시에 존재해야 하므로, 이 분야들을 강화하고 있는 두 가지 방법을 강조하고자 합니다.

AI 및 데이터 역량 개발

첫 번째는 조직들이 데이터와 AI를 잘 활용하기 위한 노하우를 구축하도록 돕는 것입니다.

대부분의 조직들은 이미 AI와 데이터의 잠재력을 인식하고 있습니다.

더 어려운 질문은 어떻게 하면 그것을 최대한 활용하기 시작할 수 있는가 하는 것입니다.

디지털 트윈은 오늘날 기업들에게 하나의 실질적인 기회입니다.

디지털 트윈은 물리적 자산, 시스템 또는 프로세스의 실시간 가상 표현입니다.

기업들은 이를 사용하여 시나리오를 시뮬레이션하고, 운영을 최적화하며, 더 나은 결정을 내릴 수 있습니다.

디지털 트윈은 그리 드물지 않습니다. 어떤 F1 팀과 대화해도 그들은 디지털 트윈을 가지고 있는데, 그것은 공학적 개선 사항이 차량과 드라이버의 성능에 미치는 영향을 시뮬레이션해야 하기 때문입니다. 따라서 이러한 디지털 트윈은 기술에 정통하고 기술의 최전선에 있는 기업들이 사용해왔습니다. 그러나 우리는 오늘날에도 중소기업들이 자신들의 디지털 트윈을 구축할 수 있다는 것을 봅니다.

Exceltec를 예로 들어보겠습니다. 싱가포르의 시설 관리 회사입니다.

이 회사는 고객 운영이 있는 70개 이상의 현장의 센서 데이터를 활용하는 디지털 트윈을 구축했습니다. 고객을 대신하여 시설 관리를 수행하므로, 70개 현장에 센서를 설치하고 센서 데이터를 활용할 수 있게 했습니다. 그들이 구축한 시스템은 이 데이터를 지속적으로 분석하고 운영 문제를 조기에 파악하도록 도와줍니다.

예를 들어, 건물의 냉방 시스템이 고장의 징후를 보이고 있습니까?

혹은 명백한 이유 없이 물 사용량이 급증한 것으로 보여 어딘가의 누수가 있음을 시사하고 있습니까?

수동 점검에 대한 과도한 의존과 비교할 때, Exceltec의 팀들은 이제 주의가 필요한 경우 자동으로 알림을 받을 수 있습니다.

이는 각 팀이 각 점검에서 하루에 약 45분을 절약하도록 도왔습니다.

많은 건물, 팀, 그리고 일에 걸쳐 이득은 누적됩니다.

더욱 중요하게도, 조직이 문제에 대응하는 것에서 더 일찍 탐지하고 더 빠르게 행동하는 것으로 전환됩니다.

Exceltec과 같이 더 많은 기업이 이익을 얻을 수 있도록 돕기 위해 IMDA는 Digital Twin For Enterprises Playbook을 출시하고 있습니다. 이는 조직이 AI와 데이터를 더 잘 결합하고 운영 병목 현상을 해결하기 위한 디지털 트윈을 설계할 수 있도록 돕는 실용적인 법률 가이드입니다. 이것이 우리가 하고자 하는 것들 중 하나입니다.

좋은 책임 추적성이 어떻게 보이는지를 명확히 하기

더 많은 조직이 생성형 AI 도구를 개발하고, 적응하고, 배포함에 따라 우리는 책임 추적성의 문제를 다루어야 합니다.

예를 들어, 통화 녹음을 사용하여 생성형 AI 모델을 개선하여 고객 질의에 더 빠르고 정확하게 대응할 수 있기를 원하는 고객 서비스 팀을 생각해 봅시다.

우리 모두 이러한 통화의 수신 끝에 있었고, 통화가 품질 점검 및 개선을 위해 녹음될 수 있다는 안내를 받거나 들었습니다. 하지만 우리는 또한 녹음에 우리의 이름, 주소, 청구 세부 정보와 같은 개인 정보가 포함될 수 있음을 알고 있습니다.

모델 훈련을 위해 고객 데이터를 사용하기 전에 이러한 고객 서비스 팀이 고객에게 가져야 할 의무는 무엇입니까?

오늘 PDPC는 생성형 AI에서 개인 정보 사용에 관한 권고 지침을 발표하고 있습니다.

업계 및 대중과 상담한 후, 우리는 조직이 데이터 소유자로부터 동의를 구하기 위한 PDPA의 기존 법적 요구 사항을 어떻게 충족할 수 있는지 명확히 하고 있습니다. 우리는 개인 정보가 생성형 AI 모델을 개발하거나 개선하는 데 사용되는 경우, 조직이 사용자가 인식하지 못하거나 이해하지 못할 수 있는 광범위한 설명에 의존하기보다는 명확하게 말해야 함을 명확히 하고 있습니다.

내가 설명한 예제의 고객 서비스 팀의 경우, 그들은 개인정보 보호 정책을 업데이트하여 동의하는 고객의 통화 녹음이 AI 모델을 훈련하고 개선하는 데 사용될 것임을 명시할 수 있습니다.

그들은 또한 동의를 구할 때 직원이 사용하는 스크립트를 업데이트할 수 있습니다.

그러면 고객은 동의를 제공하기 전에 목적을 이해하고 정보에 기초한 선택을 할 수 있습니다.

많은 조직이 이미 오늘날 이러한 AI 특정 공지를 제공합니다. 따라서 지침은 더 나아갑니다.

그들은 또한 AI 가치 사슬 전반에 걸친 당사자들의 역할과 책임, 그리고 공개적으로 이용 가능한 데이터에 의존할 때의 실사를 다룹니다.

기존 요구 사항이 생성형 AI에 어떻게 적용되는지에 대한 더 명확한 이해로, 기업은 적절한 보호 장치로 더 나은 프로세스를 설계할 수 있습니다.

데이터 계층을 넘어, 우리는 또한 AI 애플리케이션에 대한 책임 추적성을 지원하고 있습니다.

대부분의 사용자에게, 그들이 가장 자주 만나는 생성형 AI 애플리케이션은 챗봇입니다.

우리는 애플리케이션을 사용하지만, 그 한계나 우리의 데이터에 어떤 일이 발생하는지 알지 못할 수 있습니다.

정보는 보통 존재합니다. 하지만 그것은 서비스 약관, 개인정보 보호 공지 및 기타 문서에 흩어져 있으며, 종종 일반 사용자에게는 너무 단순하거나 너무 기술적입니다.

이 격차를 해소하기 위해 IMDA는 첫 번째 단계로 생성형 AI 챗봇 투명성 지침을 출시하고 있습니다.

지침은 우리가 의약품 포장에서 자주 볼 수 있는 라벨처럼 작동하는 챗봇 정보 카드를 요구합니다.

라벨은 모든 과학적 세부 사항을 우리에게 알려주지 않습니다.

대신 그것은 우리에게 필수 사항을 알려줍니다: 약물이 무엇을 위한 것인지, 어떻게 복용하는지, 얼마나 권장되는지, 어떤 부작용을 주시해야 하는지, 언제 사용하지 않아야 하는지.

정보 카드는 같은 방식으로 작동하도록 의도되었습니다. 그것은 챗봇이 무엇을 위한 것인지, 무엇을 위한 것이 아닌지, 데이터가 어떻게 처리될 수 있는지, 그리고 사용자가 문제를 어떻게 보고할 수 있는지를 일반 언어로 설명합니다.

우리는 자발적 프레임워크로 시작하고 있으며, 관행이 성숙함에 따라 산업의 의견으로 그것을 개선할 것입니다.

DBS, Google, Meta, OCBC, SIA와 같은 기업들의 지원에 진심으로 감사합니다. 이들은 지침을 참고하여 챗봇의 투명성 관행을 계속 개선해 나갈 것입니다.

Google의 경우, Gemini 앱에 대한 주요 정보를 통합하고 사용자가 쉽게 접근하도록 함으로써 사용자들이 Gemini를 더욱 자신감 있게 사용할 수 있게 합니다.

Meta도 자체 AI 기반 도구와 제품의 작동 방식, 그리고 사용자들이 이와 상호작용할 수 있는 방법에 대해 명확하고 접근 가능한 정보를 제공할 것입니다.

제가 언급한 기업들은 데이터 및 AI 거버넌스에서 리더십을 발휘하는 초기 채택자들입니다. 더 많은 기업들이 이들의 발자취를 따를 것으로 기대합니다.

함께 생태계를 구축하기

신뢰할 수 있는 데이터 및 AI 생태계를 구축하는 데 있어 파트너십의 중요성에 관해, 마지막으로 한 가지 말씀드리고 싶습니다.

싱가포르든 다른 곳이든 우리의 AI 허브를 개발할 때, 기업, 기술 제공자, 연구자, 실무자, 표준 기관, 규제 기관으로 구성된 강력한 커뮤니티가 필요합니다. 우리는 서로에게서 배우고, 아이디어를 테스트하며, 함께 표준을 높여야 합니다.

좋은 예시로는 올해 1월에 개최된 AI Safety Red Teaming Challenge가 있습니다.

80명 이상의 전문가가 참여했습니다.

ASEAN의 모든 국가, 그리고 중국, 인도, 일본, 한국에서 온 전문가들이었습니다.

그들의 임무는 생성형 AI 애플리케이션이 누출하면 안 되는 데이터를 누출할 수 있는지 테스트하는 것이었습니다.

참여자들은 단순히 연구자와 사이버 전문가만이 아니었습니다. 현지 언어, 문화, 맥락을 이해하는 언어학자와 사회학자도 포함되었습니다. 이것이 실제로 큰 차이를 만들었습니다.

일부 팀은 영어에서는 거부된 해로운 요청이 크메르어에서는 답변된 것을 발견했습니다.

다른 팀은 형식적인 표현은 차단하는 안전장치를 비공식적인 현지 표현이 빠져나갈 수 있음을 발견했습니다.

즉, 모델은 형식적인 요청에 대해 올바르게 대응했지만, 현지 표현으로 요청했을 때 모델의 안전장치가 작동하지 않았습니다.

이 취약점과 파악된 다른 많은 취약점들은 단순히 기술적인 것만이 아니라 언어적이고 문화적이었습니다.

그것이 우리가 오늘 전하고 싶은 더 광범위한 교훈입니다.

우리는 자국 경계 내만 보면서는 신뢰할 수 있는 데이터 생태계를 구축할 수 없습니다.

지역의 다양한 전문가들을 함께 모을 때만 우리는 모델 위험의 더 완전한 범위를 볼 수 있습니다.

싱가포르가 내년 ASEAN 의장국을 맡게 되면서 우리는 지역 파트너들과 협력하여 우리 지역 전체에서 데이터를 신뢰와 함께 사용할 수 있는 조건을 강화할 것입니다. 이는 다음을 의미합니다:

우리의 접근 방식을 더욱 가깝게 조율하기,

기업을 위한 불필요한 마찰 감소, 그리고

우리 디지털 경제의 성장을 위한 더 많은 공간 창출.

결국 어떤 플레이북, 지침, 기술 표준도 혼자만으로는 성공할 수 없습니다. 사람과 조직이 이들을 실제로 적용하고, 배운 점을 공유하며, 함께 표준을 높일 때만 의미를 갖습니다.

그것이 이 페스티벌이 중요한 이유입니다.

데이터를 보호하는 사람들, 데이터를 활용하는 사람들, AI 시스템을 구축하는 사람들, 그리고 그 사용을 관리하는 사람들을 모두 한데 모읍니다.

이는 우리가 좋은 아이디어를 더 나은 관행으로 구체화하고, 싱가포르와 지역에서 신뢰할 수 있는 데이터 사용을 위한 더 강한 기반을 마련하는 데 도움이 될 것입니다.

이러한 바탕에서 페스티벌에서 매우 보람 있는 하루가 되기를 바랍니다. 오늘 함께해주셔서 진심으로 감사드립니다.

영어 원문

MDDI 공식 웹사이트 원문 · 수집일: 2026-07-28

Good Morning, colleagues and friends. It was less than four hours ago that the World Cup had its finals. And I was early for this event because I thought the Monday morning traffic would be at a certain level, but today the roads were very quiet. I hope your favourite team won.

The scoreline was actually quite interesting. The last time that Spain won the World Cup, they had a similar scoreline. Quite amazingly, the data shows that on the way to winning the World Cup, they did not drop more than one goal. Kudos to the Spanish team, and kudos to you, for still being here. You must really love data. You deserve a round of applause.

Many of our friends today have joined us on previous occasions when we held the Personal Data Protection Week. This year, we have broadened the event into the Singapore Data Festival. Some of you pointed this out to me.

This is not because data protection is no longer important. It still is.

But organisations are also asking bigger questions about data, especially how to support their AI endeavours.

The Data Festival is therefore designed for us to better recognise the business value of data . At the same time, to create lasting value, we must work together to build a trusted data ecosystem in Singapore, as well as the region. So let’s talk a little more about data as a source of business value.

Data as a source of business value

As you know, businesses have always used data, whether they speak of it as such or not.

Retailers look at sales data to assess changing customer preferences and adjust their stock levels accordingly.

Banks look at transactions data for evidence of fraud, to decide which accounts and parties are problematic, and what to do about them.

Data used to tell businesses what happened. It was all in the past tense. But now, with the help of technology, businesses can see developments as they happen, almost in real time, and data, when used appropriately, can help businesses take the right action sooner rather than later.

Now, we all like to be able to do that, act sooner rather than be caught by surprise. AI accelerates this process. AI systems depend on data at every stage of their lifecycle. In fact, IMDA has consistently talked about data before AI. But without good data, even the best systems will struggle to produce useful outcomes.

That is why data governance matters more, not less, in the age of AI.

Data creates value only when there is trust

At its heart, data governance is about trust.

Customers share data only if they trust the organisation to safeguard it properly and use it responsibly.

Businesses share data with partners only if they trust that the data will not be abused to compromise their own interests.

This is why Singapore has always thought of data protection as essential to a well-functioning business environment. In fact, it is key to business innovation.

Building the right conditions for trusted data use

We also believe that trusted data governance comes with the right capabilities and clear accountability. We need these two to be present at the same time, so let me highlight two ways we are strengthening these areas.

Developing AI and data capabilities

The first is helping organisations build the know-how to use data and AI well.

Most organisations already recognise the potential of AI and data.

The harder question is how do we begin to make the most of it.

Digital twins are one practical opportunity for companies today.

A digital twin is a real-time virtual representation of physical assets, systems, or processes.

Companies can use it to simulate scenarios, optimise operations, and make better decisions.

Digital twins are not so uncommon. If you talk to any F1 team, they do have digital twins, because they need to simulate the engineering improvement impact on the performances of both the vehicle, as well as the driver. So, these digital twins have been used by companies that are tech-savvy and at the frontier of technology. But we see that even SMEs today could potentially build their own digital twins.

You take Exceltec. It is a facilities management company in Singapore.

It built a digital twin that draws on sensor data from more than 70 sites where the company has customer operations. It conducts facilities management on behalf of its clients, so at 70 sites, it has inserted sensors and is able to harness the sensor data. The system that they built analyses this data continuously, and helps identify operational problems early.

For example, is a building’s air-conditioning system showing signs of a breakdown?

Or does water usage appear to have spiked for no apparent reason, suggesting a leakage somewhere?

Compared to the heavy reliance on manual inspections, teams at Exceltec can now be alerted automatically when something needs attention.

This has helped each team save about forty-five minutes a day on each inspection.

Across many buildings, teams, and days, the gains add up.

More importantly, the organisation moves from reacting to problems, to detecting them earlier and acting faster.

To help more companies benefit like Exceltec, IMDA is launching a Digital Twin For Enterprises Playbook. It is a practical legal guide to help organisations better combine AI and data, and design digital twins to address their operational bottlenecks. That’s one of things we would like to do.

Clarifying what good accountability looks like

As more organisations develop, adapt or deploy generative AI tools, we must address the question of accountability.

Take for example, a customer service team that wants to improve a Generative AI model using call recordings, so that they can respond more quickly and accurately to customer queries.

We have all been at the receiving end of these calls, and being asked or told that the call may be recorded for quality checks and improvement. But we also know that the recordings may contain personal data, such as our names, addresses, billing details.

What are the obligations that these customer service teams have to the customers before using their data for model training?

Today, the PDPC is issuing its Advisory Guidelines on the Use of Personal Data in Generative AI.

Having consulted industry and the public, we are making clear how organisations can fulfil an existing legal requirement in the PDPA for consent to be sought from the data owner. We are making it clear that where personal data is used to develop or improve a Generative AI model, organisations should say so plainly, rather than rely on broad descriptions that users may not notice or understand.

For the customer service team in the example that I described, they can update the privacy policy to state that call recordings of consenting customers will be used to train and improve AI models.

They can also update the scripts that staff use when seeking consent.

Customers can then understand the purpose and make an informed choice before giving consent.

Many organisations already provide such AI-specific notices today. Therefore, the Guidelines go further.

They also cover the roles and responsibilities of parties across the AI value chain, and due diligence when relying on publicly available data.

With greater clarity on how existing requirements apply to Generative AI, companies can design better processes with the right safeguards.

Beyond the data layer, we are also supporting accountability for AI applications.

For most users, the Generative AI application they meet most often is the chatbot.

We use the application, but may not know itslimitations , or what happens to our data.

The information usually exists. But it is scattered across the terms of service, privacy notices and other documents, and is often either too simplistic or too technical for ordinary users.

To close this gap, IMDA is launching the Generative AI Chatbot Transparency Guidelines as a first step.

The Guidelines call for a Chatbot Information Card that works like the label we often find on the packaging of medicinal products.

The label does not tell us every scientific detail.

Instead, it tells us the essentials: what the medicine is for, how to take it, how much is recommended, what side effects to watch for, when not to use it.

The Information Card is meant to work the same way. It sets out in plain language what the chatbot is for, what it is not for, how data may be handled, and how users can report issues.

We are starting with a voluntary framework, and will refine it with industry inputs as practices mature.

We are heartened by the support from companies like DBS, Google, Meta, OCBC and SIA, who will be using the Guidelines as a point of reference as they continue improving transparency practices for their chatbots.

In Google’s case, this means consolidating key information about the Gemini app, and making that information easily accessible to users, so that they can use Gemini with greater confidence.

Meta will also provide people with clear and accessible information about how its AI-powered tools and products work and the ways people can interact with them.

The companies I mentioned are early adopters who are demonstrating leadership in data and AI governance. We hope many more will follow their tracks.

Building the ecosystem together

This brings me to a final point I would like to make today about the importance of partnership in building trusted data and AI ecosystems.

In developing our AI hubs, whether Singapore or elsewhere, we need a strong community of businesses, technology providers, researchers, practitioners, standards bodies and regulators. We need to learn from one another, test ideas, and raise standards together.

One good example is this year’s AI Safety Red Teaming Challenge held in January.

More than 80 experts took part.

They came from all ASEAN countries, as well as China, India, Japan, and Korea.

Their task was to test whether Generative AI applications could leak the data they were not supposed to.

The participants were not only researchers and cyber experts. They also included linguists and sociologists who understood local language, culture, and context. That turned out to have made a real difference.

Some teams found that a harmful request refused in English was answered in the Khmer language.

Others found that casual local phrasing could slip through the safeguards that a formal-sounding request could not.

In other words, the model responded to a formal request the way it should, but when the request was put to it with local phrasing, the model safeguards failed.

This vulnerability, and many others that were identified, were not only technical; they were also linguistic and cultural.

That is the wider lesson we would like to share today.

None of us can build a trusted data ecosystem by looking only within our own borders.

We see the fuller variety of model risks only when we bring together a range of experts from the region.

As Singapore assumes the ASEAN Chairmanship next year, we will work with regional partners to strengthen the conditions for data to be used with confidence across our region. This means:

Bringing our approaches closer together,

Reducing unnecessary friction for businesses, and

Creating more room for our digital economies to grow.

Ultimately, no playbook, guideline or technical standard succeeds on its own. They become meaningful only when people and organisations put them into practice, share what they have learnt, and collectively raise standards.

That is why this Festival matters.

It brings together those who protect data, use data, build AI systems, and govern their use.

This will help us turn good ideas into better practice and build a stronger foundation for trusted data use in Singapore and the region.

And so, on that note, I wish you all a very fruitful day ahead at the Festival. Thank you once again for being here.