MDDI 演講稿 · 2026-07-20

Josephine Teo部長在新加坡資料節(Sands Expo and Convention Centre)的開幕演講

Josephine Teo · 數碼發展及新聞部長 · 新加坡資料節在濱海灣金沙展覽中心

要點

  • 新加坡將「個人資料保護周」擴充套件為「新加坡資料節」,以應對更廣泛的資料和商業價值問題,特別是在支援人工智慧方面的努力。
  • 信息通信媒體發展局(IMDA)正在推出《企業數字孿生手冊》,一份實用指南,幫助組織結合人工智慧和資料來設計數字孿生以最佳化運營。
  • 設施管理公司Exceltec部署了一個數字孿生系統,從70多個站點的感測器資料中獲取資訊,通過自動化問題檢測,使檢查團隊每天節省約45分鐘。
  • 新加坡個人資料保護委員會(PDPC)正在釋出《生成式人工智慧中個人資料使用顧問指南》,要求組織在使用個人資料開發或改進人工智慧模型時提供明確和具體的通知。
  • 信息通信媒體發展局正在推出《生成式人工智慧聊天機器人透明度指南》,包含一個自願資訊卡格式,明確披露聊天機器人的目的、侷限性、資料處理和使用者補救選項。

完整譯文(繁體中文)

MDDI 英文原文譯文 · 翻譯日期: 2026-07-28

早上好,同事和朋友們。世界盃決賽是在不到四小時前舉行的。我為這個活動提前到達,因為我認為週一早上的交通會有一定的堵塞,但今天道路非常暢通。我希望你們支援的球隊贏了。

比分實際上相當有趣。西班牙上一次贏得世界盃時,他們的比分也是類似的。相當令人驚奇的是,資料顯示在贏得世界盃的過程中,他們沒有丟超過一個球。向西班牙隊致敬,也向你們致敬,你們依然在這裡。你們一定真的熱愛資料。你們值得掌聲。

今天我們許多朋友在我們以前舉辦個人資料保護周時曾經加入我們。今年,我們已經將該活動拓展為新加坡資料節。你們中的一些人向我指出了這一點。

這不是因為資料保護不再重要。它仍然是。

但組織們也在提出關於資料的更大問題,特別是如何支援他們的AI工作。

因此,資料節的設計目的是讓我們更好地認識資料的商業價值。同時,為了創造持久的價值,我們必須共同努力,在新加坡以及該地區建立可信的資料生態系統。那麼讓我們進一步討論資料作為商業價值的源泉。

資料作為商業價值的源泉

如你所知,企業一直在使用資料,無論他們是否這樣說。

零售商檢視銷售資料以評估不斷變化的客戶偏好,並相應調整其庫存水平。

銀行檢視交易資料以尋找欺詐證據,以判斷哪些賬戶和各方有問題,以及如何處理。

資料過去告訴企業發生了什麼。這一切都是過去式的。但現在,在技術的幫助下,企業幾乎可以即時看到發展的進展,資料在適當使用時,可以幫助企業及時採取正確的行動。

現在,我們都希望能夠這樣做,更快地採取行動而不是被意外所困。AI加快了這一過程。AI系統在其生命週期的每個階段都依賴於資料。事實上,IMDA一直在強調資料先於AI。但沒有好的資料,即使是最好的系統也會難以產生有用的結果。

這就是為什麼在AI時代,資料治理更加重要,而不是更加不重要。

資料只有在有信任的情況下才能創造價值

從根本上說,資料治理是關於信任的。

客戶只有在信任組織能夠妥善保護資料並負責任地使用資料時,才會分享資料。

企業只有在信任資料不會被濫用以損害其自身利益的情況下,才會與合作伙伴分享資料。

這就是為什麼新加坡一直將資料保護視為良好商業環境的必要條件。事實上,它是商業創新的關鍵。

為可信資料使用建立適當的條件

我們還相信,可信的資料治理需要正確的能力和明確的問責。我們需要這兩者同時存在,所以讓我強調我們加強這些領域的兩種方式。

發展AI和資料能力

第一是幫助組織掌握如何良好使用資料和AI。

大多陣列織已經認識到AI和資料的潛力。

更困難的問題是我們如何開始最大限度地利用它。

數字孿生是當今公司的一個實際機會。

數字孿生是物理資產、系統或流程的即時虛擬表示。

公司可以使用它來模擬場景、最佳化運營和做出更好的決策。

數字孿生並不少見。如果你與任何F1車隊交流,他們都有數字孿生,因為他們需要模擬工程改進對車輛和駕駛員效能的影響。因此,這些數字孿生已被技術精明且處於技術前沿的公司使用。但我們看到,即使是今天的SMEs也可能能夠構建自己的數字孿生。

以Exceltec為例。它是新加坡的一家設施管理公司。

它構建了一個數字孿生,該孿生利用來自該公司擁有客戶業務的70多個地點的感測器資料。它代表其客戶進行設施管理,因此在70個地點,它已經安裝了感測器並能夠利用感測器資料。他們構建的系統持續分析這些資料,並幫助及早識別操作問題。

例如,建築物的空調系統是否出現故障跡象?

或者水用量是否無明顯原因地突然增加,暗示某處有洩漏?

與嚴重依賴人工檢查相比,Exceltec 團隊現在可以在需要注意時自動收到警報。

這幫助每個團隊在每次檢查上每天節省約四十五分鐘。

在眾多建築、團隊和天數中,這些收益加起來。

更重要的是,組織從對問題的被動反應轉變為更早發現問題並更快採取行動。

為了幫助更多公司像 Exceltec 一樣受益,IMDA 正在推出《企業數字孿生手冊》。這是一份實用法律指南,幫助組織更好地結合人工智慧和資料,並設計數字孿生以解決其運營瓶頸。這是我們想做的事情之一。

澄清良好的問責制應該是什麼樣子

隨著越來越多的組織開發、調整或部署生成式人工智慧工具,我們必須解決問責問題。

以一個想要使用通話錄音來改進生成式人工智慧模型的客戶服務團隊為例,以便他們能夠更快更準確地回應客戶查詢。

我們都接過這樣的電話,被告知通話可能會被錄製以進行質量檢查和改進。但我們也知道這些錄音可能包含個人資料,例如我們的姓名、地址、賬單詳情。

這些客戶服務團隊在使用客戶資料進行模型訓練前對客戶有什麼義務?

今天,PDPC 正在釋出其《生成式人工智慧中個人資料使用建議指南》。

經過諮詢行業和公眾,我們明確了組織如何能夠履行《PDPA》中的現有法律要求,即應從資料所有者那裡徵求同意。我們明確表示,當個人資料被用於開發或改進生成式人工智慧模型時,組織應直言不諱,而不是依賴於使用者可能不會注意或理解的寬泛描述。

對於我描述的例子中的客戶服務團隊,他們可以更新隱私政策,說明已同意的客戶的通話錄音將被用於訓練和改進人工智慧模型。

他們還可以更新員工在徵求同意時使用的指令碼。

客戶隨後可以理解目的,在給予同意前做出知情選擇。

許多組織今天已經提供了這樣的人工智慧專項通知。因此,該指南進一步延伸。

它們還涵蓋人工智慧價值鏈中各方的角色和責任,以及在依賴公開可用資料時的盡職調查。

由於對現有要求如何適用於生成式人工智慧有了更清晰的理解,公司可以設計具有適當防護措施的更好流程。

超越資料層,我們還支援人工智慧應用程式的問責制。

對於大多數使用者來說,他們最常接觸的生成式人工智慧應用是聊天機器人。

我們使用這個應用程式,但可能不知道它的侷限性,或我們的資料會發生什麼。

這些資訊通常是存在的。但它散佈在服務條款、隱私通知和其他檔案中,對於普通使用者來說,通常要麼過於簡單,要麼過於技術性。

為了填補這一空白,IMDA 作為第一步推出了《生成式人工智慧聊天機器人透明度指南》。

該指南要求提供一張聊天機器人資訊卡,其工作方式類似於我們經常在藥品包裝上找到的標籤。

標籤不會告訴我們每個科學細節。

相反,它告訴我們要點:藥物的用途、如何使用、建議用量、要注意的副作用、何時不使用。

資訊卡的工作方式應該相同。它用清晰的語言說明了聊天機器人的用途、不用於什麼、資料可能如何處理,以及使用者如何報告問題。

我們從自願框架開始,隨著實踐的成熟,將根據行業意見對其進行改進。

我們為 DBS、Google、Meta、OCBC 和新航等公司的支援感到欣慰,他們將把《指南》作為參考,繼續改進其聊天機器人的透明度實踐。

就 Google 而言,這意味著整合有關 Gemini 應用程式的關鍵資訊,使使用者能夠輕鬆獲取這些資訊,以便他們能夠更有信心地使用 Gemini。

Meta 也將為人們提供清晰且易獲取的資訊,說明其 AI 驅動的工具和產品如何運作,以及人們與之互動的方式。

我提到的這些公司是早期採用者,在資料和 AI 治理方面展現了領導力。我們希望更多公司能夠追隨他們的腳步。

共同構建生態系統

這讓我想到了今天最後要表達的一點,即在構建可信任的資料和 AI 生態系統中夥伴關係的重要性。

在開發我們的 AI 中心(無論是在新加坡還是其他地方)時,我們需要一個由企業、技術提供商、研究人員、從業者、標準制定機構和監管機構組成的強大社群。我們需要相互學習、測試想法並共同提高標準。

一個很好的例子是今年 1 月舉辦的 AI 安全紅隊挑戰賽。

超過 80 名專家參加了該活動。

他們來自所有東盟國家,以及中國、印度、日本和韓國。

他們的任務是測試生成式 AI 應用程式是否會洩露不應該洩露的資料。

參與者不僅包括研究人員和網路安全專家。還包括瞭解本地語言、文化和背景的語言學家和社會學家。事實證明這產生了真正的影響。

一些團隊發現,有害請求在英文中被拒絕了,但在柬埔寨語中卻被回答了。

其他團隊發現,隨意的本地措辭可以繞過正式措辭無法繞過的安全防護。

換句話說,模型對正式請求的響應方式是正確的,但當用本地措辭提出請求時,模型的安全防護失效了。

這個漏洞以及許多其他已識別的漏洞不僅是技術問題,也是語言和文化問題。

這是我們今天想要分享的更廣泛的教訓。

我們無法僅通過關注自身範圍來建立可信任的資料生態系統。

只有當我們匯聚來自該地區的各種專家時,我們才能看到模型風險的完整多樣性。

當新加坡明年擔任東盟主席國時,我們將與地區夥伴合作,加強條件,使資料在整個地區能夠被自信地使用。這意味著:

使我們的方法更加接近,

為企業減少不必要的摩擦,以及

為我們的數字經濟創造更多增長空間。

最終,沒有任何手冊、指南或技術標準能夠獨自取得成功。只有當人們和組織將其付諸實踐、分享他們學到的知識並共同提高標準時,這些才會變得有意義。

這就是為什麼這個節日很重要。

它匯聚了保護資料的人、使用資料的人、構建 AI 系統的人,以及監管其使用的人。

這將幫助我們將好的想法轉化為更好的實踐,為新加坡和該地區的可信任資料使用建立更堅實的基礎。

那麼,我祝願各位在本次節日中度過卓有成效的一天。再次感謝各位的出席。

英文原文

MDDI 官網原始記錄 · 抓取日期: 2026-07-28

Good Morning, colleagues and friends. It was less than four hours ago that the World Cup had its finals. And I was early for this event because I thought the Monday morning traffic would be at a certain level, but today the roads were very quiet. I hope your favourite team won.

The scoreline was actually quite interesting. The last time that Spain won the World Cup, they had a similar scoreline. Quite amazingly, the data shows that on the way to winning the World Cup, they did not drop more than one goal. Kudos to the Spanish team, and kudos to you, for still being here. You must really love data. You deserve a round of applause.

Many of our friends today have joined us on previous occasions when we held the Personal Data Protection Week. This year, we have broadened the event into the Singapore Data Festival. Some of you pointed this out to me.

This is not because data protection is no longer important. It still is.

But organisations are also asking bigger questions about data, especially how to support their AI endeavours.

The Data Festival is therefore designed for us to better recognise the business value of data . At the same time, to create lasting value, we must work together to build a trusted data ecosystem in Singapore, as well as the region. So let’s talk a little more about data as a source of business value.

Data as a source of business value

As you know, businesses have always used data, whether they speak of it as such or not.

Retailers look at sales data to assess changing customer preferences and adjust their stock levels accordingly.

Banks look at transactions data for evidence of fraud, to decide which accounts and parties are problematic, and what to do about them.

Data used to tell businesses what happened. It was all in the past tense. But now, with the help of technology, businesses can see developments as they happen, almost in real time, and data, when used appropriately, can help businesses take the right action sooner rather than later.

Now, we all like to be able to do that, act sooner rather than be caught by surprise. AI accelerates this process. AI systems depend on data at every stage of their lifecycle. In fact, IMDA has consistently talked about data before AI. But without good data, even the best systems will struggle to produce useful outcomes.

That is why data governance matters more, not less, in the age of AI.

Data creates value only when there is trust

At its heart, data governance is about trust.

Customers share data only if they trust the organisation to safeguard it properly and use it responsibly.

Businesses share data with partners only if they trust that the data will not be abused to compromise their own interests.

This is why Singapore has always thought of data protection as essential to a well-functioning business environment. In fact, it is key to business innovation.

Building the right conditions for trusted data use

We also believe that trusted data governance comes with the right capabilities and clear accountability. We need these two to be present at the same time, so let me highlight two ways we are strengthening these areas.

Developing AI and data capabilities

The first is helping organisations build the know-how to use data and AI well.

Most organisations already recognise the potential of AI and data.

The harder question is how do we begin to make the most of it.

Digital twins are one practical opportunity for companies today.

A digital twin is a real-time virtual representation of physical assets, systems, or processes.

Companies can use it to simulate scenarios, optimise operations, and make better decisions.

Digital twins are not so uncommon. If you talk to any F1 team, they do have digital twins, because they need to simulate the engineering improvement impact on the performances of both the vehicle, as well as the driver. So, these digital twins have been used by companies that are tech-savvy and at the frontier of technology. But we see that even SMEs today could potentially build their own digital twins.

You take Exceltec. It is a facilities management company in Singapore.

It built a digital twin that draws on sensor data from more than 70 sites where the company has customer operations. It conducts facilities management on behalf of its clients, so at 70 sites, it has inserted sensors and is able to harness the sensor data. The system that they built analyses this data continuously, and helps identify operational problems early.

For example, is a building’s air-conditioning system showing signs of a breakdown?

Or does water usage appear to have spiked for no apparent reason, suggesting a leakage somewhere?

Compared to the heavy reliance on manual inspections, teams at Exceltec can now be alerted automatically when something needs attention.

This has helped each team save about forty-five minutes a day on each inspection.

Across many buildings, teams, and days, the gains add up.

More importantly, the organisation moves from reacting to problems, to detecting them earlier and acting faster.

To help more companies benefit like Exceltec, IMDA is launching a Digital Twin For Enterprises Playbook. It is a practical legal guide to help organisations better combine AI and data, and design digital twins to address their operational bottlenecks. That’s one of things we would like to do.

Clarifying what good accountability looks like

As more organisations develop, adapt or deploy generative AI tools, we must address the question of accountability.

Take for example, a customer service team that wants to improve a Generative AI model using call recordings, so that they can respond more quickly and accurately to customer queries.

We have all been at the receiving end of these calls, and being asked or told that the call may be recorded for quality checks and improvement. But we also know that the recordings may contain personal data, such as our names, addresses, billing details.

What are the obligations that these customer service teams have to the customers before using their data for model training?

Today, the PDPC is issuing its Advisory Guidelines on the Use of Personal Data in Generative AI.

Having consulted industry and the public, we are making clear how organisations can fulfil an existing legal requirement in the PDPA for consent to be sought from the data owner. We are making it clear that where personal data is used to develop or improve a Generative AI model, organisations should say so plainly, rather than rely on broad descriptions that users may not notice or understand.

For the customer service team in the example that I described, they can update the privacy policy to state that call recordings of consenting customers will be used to train and improve AI models.

They can also update the scripts that staff use when seeking consent.

Customers can then understand the purpose and make an informed choice before giving consent.

Many organisations already provide such AI-specific notices today. Therefore, the Guidelines go further.

They also cover the roles and responsibilities of parties across the AI value chain, and due diligence when relying on publicly available data.

With greater clarity on how existing requirements apply to Generative AI, companies can design better processes with the right safeguards.

Beyond the data layer, we are also supporting accountability for AI applications.

For most users, the Generative AI application they meet most often is the chatbot.

We use the application, but may not know itslimitations , or what happens to our data.

The information usually exists. But it is scattered across the terms of service, privacy notices and other documents, and is often either too simplistic or too technical for ordinary users.

To close this gap, IMDA is launching the Generative AI Chatbot Transparency Guidelines as a first step.

The Guidelines call for a Chatbot Information Card that works like the label we often find on the packaging of medicinal products.

The label does not tell us every scientific detail.

Instead, it tells us the essentials: what the medicine is for, how to take it, how much is recommended, what side effects to watch for, when not to use it.

The Information Card is meant to work the same way. It sets out in plain language what the chatbot is for, what it is not for, how data may be handled, and how users can report issues.

We are starting with a voluntary framework, and will refine it with industry inputs as practices mature.

We are heartened by the support from companies like DBS, Google, Meta, OCBC and SIA, who will be using the Guidelines as a point of reference as they continue improving transparency practices for their chatbots.

In Google’s case, this means consolidating key information about the Gemini app, and making that information easily accessible to users, so that they can use Gemini with greater confidence.

Meta will also provide people with clear and accessible information about how its AI-powered tools and products work and the ways people can interact with them.

The companies I mentioned are early adopters who are demonstrating leadership in data and AI governance. We hope many more will follow their tracks.

Building the ecosystem together

This brings me to a final point I would like to make today about the importance of partnership in building trusted data and AI ecosystems.

In developing our AI hubs, whether Singapore or elsewhere, we need a strong community of businesses, technology providers, researchers, practitioners, standards bodies and regulators. We need to learn from one another, test ideas, and raise standards together.

One good example is this year’s AI Safety Red Teaming Challenge held in January.

More than 80 experts took part.

They came from all ASEAN countries, as well as China, India, Japan, and Korea.

Their task was to test whether Generative AI applications could leak the data they were not supposed to.

The participants were not only researchers and cyber experts. They also included linguists and sociologists who understood local language, culture, and context. That turned out to have made a real difference.

Some teams found that a harmful request refused in English was answered in the Khmer language.

Others found that casual local phrasing could slip through the safeguards that a formal-sounding request could not.

In other words, the model responded to a formal request the way it should, but when the request was put to it with local phrasing, the model safeguards failed.

This vulnerability, and many others that were identified, were not only technical; they were also linguistic and cultural.

That is the wider lesson we would like to share today.

None of us can build a trusted data ecosystem by looking only within our own borders.

We see the fuller variety of model risks only when we bring together a range of experts from the region.

As Singapore assumes the ASEAN Chairmanship next year, we will work with regional partners to strengthen the conditions for data to be used with confidence across our region. This means:

Bringing our approaches closer together,

Reducing unnecessary friction for businesses, and

Creating more room for our digital economies to grow.

Ultimately, no playbook, guideline or technical standard succeeds on its own. They become meaningful only when people and organisations put them into practice, share what they have learnt, and collectively raise standards.

That is why this Festival matters.

It brings together those who protect data, use data, build AI systems, and govern their use.

This will help us turn good ideas into better practice and build a stronger foundation for trusted data use in Singapore and the region.

And so, on that note, I wish you all a very fruitful day ahead at the Festival. Thank you once again for being here.