AI Governance & Regulation · 2026-07-20 · 10:40

Singapore introduces generative AI guidelines on use of personal data, chatbots

Speaker
Aldrina Thirunagaran
CNA Reporter
Type
Industry Leader
Source
CNA

In Brief

Singapore introduces new guidelines for generative AI use of personal data, aiming to help businesses adopt AI responsibly while building public trust.

Readable transcript

Caption language: en · Fetched: 2026-07-28

And welcome back. AI models learn from data, but new guidelines are setting clearer boundaries on what personal information can be used and how users are told about it. Chatbots will also come with more information for users similar to a nutrition label showing what the technology can do and how it handles data. The new guidelines aim to help businesses adopt Gen AI responsibly when building public trust. Well, Aldrina Thiagarajan with more from the Singapore Data Festival. >> Everyday millions of people share personal information with AI tools. But do you know what happens to that data used for product development or services? Singapore's new guidelines aim to answer those questions, setting clearer expectations for businesses developing generative AI, such as how data can be collected and used to develop Gen AI models.

>> We can see that without good data, even the best systems will struggle to produce useful outcomes. Garbage in, garbage out. That is why data governance matters more, not less, in the age of AI. At its heart, data governance is about trust. >> Chatbot providers will also need to be more transparent about how they use personal data. For example, info cards like this one will be provided to consumers to enable them to make more informed decisions and include what type of data they choose to share with such services. >> It fits in with our principles in in terms of governance, privacy, transparency, and some of this are already inbuilt within our chatbot. so it it only takes this further. So, we're very excited about this development.

>> However, building a trusted data governance framework will take time as companies look to use these guidelines to continuously improve their transparency practices over the next year. Other initiatives unveiled include a guide on federated learning, a type of privacy-enhancing technology or PET, where AI developers can tap private databases without risking data leakages. At Singapore General Hospital's Anatomical Pathology Lab, PETs were used to analyze gastric biopsies, a task which saved 60% of the team's time. >> We need the algorithm to actually work fast and actually able to analyze many slides at the same time. We also actually need to ensure that environment is actually secure enough for us to actually put patient data into the cloud resources for the analysis to happen.

>> The team is continuing to work with A*STAR to explore next steps such as more sophisticated encryption processes for greater data security. >> And we're going into a deeper discussion on data use with Denise Wong, who is the Commissioner, Personal Data Protection Commission and Assistant Chief Executive, Data Innovation and Protection Group at IMDA. And also with us is Prof Simon Chesterman, Vice Provost, the Educational Innovation at NUS and Dean at the NUS College. Welcome to the show. Let's start off with you, Denise. Uh AI developers currently can collect online data for training when such data may not always be publicly available and in what's called web scraping. Tell us what is web scraping.

>> Well, if you think about a person reading a newspaper and then clipping out the articles that they're interested in, except this person is a web program and they're scanning billions of web pages on the internet and picking out the relevant information, compiling a data set for GenAI training. So, web scraping is a common way of training GenAI and gathering the data that's needed for it. Now, under the Personal Data Protection Act, actually, consent is needed by and large most of the time from the people whom the personal information belongs to. But, where the information is in the public domain, already out there, then you can rely on what is known as the publicly available exception. So, consent is not needed.

So, what we're clarifying in the guidelines is that you can take personal data where it is in the public domain on the internet and use that for GenAI training. >> Now, one new idea is the chatbot information card, which I understand. What should consumers expect to see on it and how can they tell if it's genuinely useful or just an exercise to tick the box? >> That's a great question. And we had extensive consultations with both focus groups, consumers, as well as the industry. And we found that there are really four areas that people care about. One is what the chatbot is and isn't. So, for example, you can use this chatbot to check prices of products, but you can't use it for health advice. And the second area is really what is this chatbot safe and reliable? So, for example, are there parental controls?

Are there you know, content that children shouldn't look at? Third area is how's the data going to be used? And the fourth area is is Is a channel such as an email address if you want to give user feedback? So, users can expect that information in these four areas will be provided in a way that's easy to access. Now, we will allow organizations, of course, to decide the depth of disclosure, but at the end of the day, the information must be substantial enough for users to understand the chatbot that they're using so that they can make informed choices about what they're using and know how to use it properly. And the aim is really to standardize transparency across different chatbots. A lot of times this information is already out there, but may not be easily accessible or maybe in different locations.

>> Professor, let's bring you into this conversation. Now, in Singapore, it has consistently chosen guidelines over regulations over for AI. Why do you think that this is a better approach? >> Well, I think in any emerging technology, any emerging practice, there's a tension. Do you underregulate and expose people to risk or do overregulate and constrain innovation or potentially drive it elsewhere? And so, I think Singapore throughout has tried to navigate this space, but I wouldn't say there's complete lack of regulation at the moment. There is the Personal Data Protection Act, that's the baseline legislation. We've got specific laws governing sensitive data like in medicine and healthcare.

But you're right, in emerging areas, there's been this tendency to to go slowly, to consult with industry, with consumers, and to try to start with guidelines. So, at the moment, the guidelines are helpful in interpreting those baseline laws in new use cases like the web scraping that Denise was just describing. And it's true that it is entirely voluntary in areas like the the new model card for for chatbots, but that's a very emerging area where I think it's sensible to experiment a little bit. And that's really what you want to encourage, appropriate levels of experimentation on the part of industry, while at the same time protecting the the rights and of individuals and users. >> Now, Denise, the guidelines are meant to protect people's privacy without showing AI innovation. How do you strike that balance?

>> I like to think about it as seat belts in the car. Now, seat belts in the car protect the drivers, they protect the passengers, and in fact allows the car to go faster, not slower. So, the guidelines are really explanations of how existing legal requirements under under the personal data protection act can be complied with. It sets boundaries, and those boundaries provide clarity that then allow businesses the confidence to innovate and to use this technology for their commercial operations. And that that also allows companies flexibility to understand what they can do within their own operational requirements. So, we don't think that it will actually create too much hassle. In fact, the clarity brings confidence in use. >> Now, very quick question, last one for both of you.

Firstly, will this create extra work for businesses, especially SMEs, with these new guidelines? Professor? >> So, hopefully not. I mean, yes, there'll be a little bit of additional work, but that's only if you're changing the use case for existing data. I mean, the the reality is the reason this is needed is we're changing our relationship to data. It used to be the case that if you collected data, you could have a safe data set, and that was all you really needed. Now, with dynamic data, you need to have ongoing processes, but for the most part, this should be a hopefully modest investment. And as Denise says, a bit like it costs money to put a seat belt into a car, anti-lock braking systems, but all of that both keeps the driver safer and enables the car to go faster, and that's what we want.

>> Well, thank you very much, Denise and Professor for joining us today, giving us insights on this. We've been speaking to Denise Wong from IMDA and Professor Simon Chesterman from NUS. Thank you. Now, companies in manufacturing, the built environment, and logistics now have a clearer roadmap for adopting digital twin technology. A new playbook helps businesses decide if the technology fits their needs, assess their data readiness, and implement projects that improve operations. The guide was launched by the Infocomm Media Development Authority and it's aimed at non-ICT enterprises. Digital twins are virtual replicas that can mirror factory machines, building equipment, and supply chains using real-time data. Firms can use this to spot problems earlier and test changes before applying them.

For Excel Tech Property Management, which manages more than 100 sites, their digital twin saves technicians 45 minutes daily. It flags early signs of equipment failure, allowing teams to deploy resources more suitably, and remove the need for manual pump inspections.

Related Videos

Singapore Streamlines Construction Robotics Regulations

2026-07-17 · Nikhil Khattar · 03:02

Singapore streamlines construction regulations to hasten robotics adoption, supporting firms to scale successful trials and identify trusted technologies.

The AI 'news anchors' spreading misleading claims about Singapore on TikTok

2026-07-17 · CNA · 02:17

CNA's investigation uncovered over 550 TikTok videos using AI-generated female personas, with nearly 9 in 10 spreading false or misleading claims about Singapore and Malaysia.

Man in the loop a must when using AI in defence

2026-06-26 · Chan Chun Sing · 01:12

Singapore's Defence Minister Chan Chun Sing argues that humans must remain in control of decision-making when AI is used in military operations.

Masagos: No Vulnerable Group Should Be Left Behind in AI Push

2026-05-08 · Masagos Zulkifli · 02:33

Minister for Social and Family Development Masagos Zulkifli, speaking at the St Gallen Symposium, stressed that AI rollouts must include vulnerable groups so that the technology gains do not bypass them.

Over 250 AI experts gather in Singapore to set global testing standards

2026-04-20 · CNA · 03:46

Singapore-proposed AI safety testing standards take centre stage at an ISO international meeting, drawing over 250 experts from the US, China, Japan, South Korea and beyond — the working group's first session in ASEAN. Nearly 100 AI standards are now published or in development, triple the count of a year ago.

Josephine Teo on enterprise AI adoption and online safety regulation

2026-03-31 · Josephine Teo · 02:30

Josephine Teo says the government is prepared to intervene if enterprise AI adoption falls short of expected outcomes, while releasing IMDA's second Online Safety Assessment Report.

More on these topics