Liability and Governance · Updated 2026-04-26

Digital Infrastructure Bill (DIB, draft)

Governance In consultation 2026-07 Ministry of Digital Development and Information (MDDI) / Infocomm Media Development Authority (IMDA)

Core Point

Licenses data centres and cloud services, bringing the AI compute layer under hard-law regulation for the first time; energy-efficiency requirements shift from voluntary to mandatory.

Detailed Note

On 1 July 2026, MDDI and IMDA opened public consultation on the draft Digital Infrastructure Bill, closing 22 July. Two licences: (1) **major FDI licence** — data centre facility services in DCs with a critical IT load of ≥10MW serving unrelated third parties, plus IaaS/PaaS cloud services earning ≥S$100m a year in Singapore, must implement physical and cybersecurity measures, business continuity and disaster recovery plans, and notify IMDA of security incidents and service disruptions; (2) **DC licence** — every data centre operator with a critical IT load of ≥3MW falls in scope and must meet facility-level PUE efficiency requirements, with IMDA also weighing the renewability of energy sources and greenhouse gas emissions when assessing applications. The Bill concurrently amends the Cybersecurity Act 2018 and its 2024 amendment to align the definitions of "foundational digital infrastructure service" and "data centre facility service". IMDA gains full powers to grant and revoke licences, issue codes of practice and directions, impose financial penalties, and conduct enforcement investigations. Why it matters for AI: this is Singapore's "no horizontal AI act, regulate through existing sector statutes" methodology applied at the compute layer — it says nothing about models or training, yet pulls the security, resilience and energy footprint of AI infrastructure into regulatory view.

Position in the Legal Framework

A gradual path from principles to tools to enforcement — FEAT → Veritas → MindForge → AI Risk Management Guidelines.

Related Legal Cards

More on these topics