MDDI 演讲稿 · 2026-07-20

Josephine Teo部长在新加坡数据节(Sands Expo and Convention Centre)的开幕演讲

Josephine Teo部长在新加坡数据节(Sands Expo and Convention Centre)的开幕演讲

Josephine Teo · 数码发展及新闻部长 · 新加坡数据节在滨海湾金沙展览中心

要点

  • 新加坡将「个人数据保护周」扩展为「新加坡数据节」,以应对更广泛的数据和商业价值问题,特别是在支持人工智能方面的努力。
  • 信息通信媒体发展局(IMDA)正在推出《企业数字孪生手册》,一份实用指南,帮助组织结合人工智能和数据来设计数字孪生以优化运营。
  • 设施管理公司Exceltec部署了一个数字孪生系统,从70多个站点的传感器数据中获取信息,通过自动化问题检测,使检查团队每天节省约45分钟。
  • 新加坡个人数据保护委员会(PDPC)正在发布《生成式人工智能中个人数据使用顾问指南》,要求组织在使用个人数据开发或改进人工智能模型时提供明确和具体的通知。
  • 信息通信媒体发展局正在推出《生成式人工智能聊天机器人透明度指南》,包含一个自愿信息卡格式,明确披露聊天机器人的目的、局限性、数据处理和用户补救选项。

完整译文(中文)

MDDI 英文原文译文 · 翻译日期: 2026-07-28

早上好,同事和朋友们。世界杯决赛是在不到四小时前举行的。我为这个活动提前到达,因为我认为周一早上的交通会有一定的堵塞,但今天道路非常畅通。我希望你们支持的球队赢了。

比分实际上相当有趣。西班牙上一次赢得世界杯时,他们的比分也是类似的。相当令人惊奇的是,数据显示在赢得世界杯的过程中,他们没有丢超过一个球。向西班牙队致敬,也向你们致敬,你们依然在这里。你们一定真的热爱数据。你们值得掌声。

今天我们许多朋友在我们以前举办个人数据保护周时曾经加入我们。今年,我们已经将该活动拓展为新加坡数据节。你们中的一些人向我指出了这一点。

这不是因为数据保护不再重要。它仍然是。

但组织们也在提出关于数据的更大问题,特别是如何支持他们的AI工作。

因此,数据节的设计目的是让我们更好地认识数据的商业价值。同时,为了创造持久的价值,我们必须共同努力,在新加坡以及该地区建立可信的数据生态系统。那么让我们进一步讨论数据作为商业价值的源泉。

数据作为商业价值的源泉

如你所知,企业一直在使用数据,无论他们是否这样说。

零售商查看销售数据以评估不断变化的客户偏好,并相应调整其库存水平。

银行查看交易数据以寻找欺诈证据,以判断哪些账户和各方有问题,以及如何处理。

数据过去告诉企业发生了什么。这一切都是过去式的。但现在,在技术的帮助下,企业几乎可以实时看到发展的进展,数据在适当使用时,可以帮助企业及时采取正确的行动。

现在,我们都希望能够这样做,更快地采取行动而不是被意外所困。AI加快了这一过程。AI系统在其生命周期的每个阶段都依赖于数据。事实上,IMDA一直在强调数据先于AI。但没有好的数据,即使是最好的系统也会难以产生有用的结果。

这就是为什么在AI时代,数据治理更加重要,而不是更加不重要。

数据只有在有信任的情况下才能创造价值

从根本上说,数据治理是关于信任的。

客户只有在信任组织能够妥善保护数据并负责任地使用数据时,才会分享数据。

企业只有在信任数据不会被滥用以损害其自身利益的情况下,才会与合作伙伴分享数据。

这就是为什么新加坡一直将数据保护视为良好商业环境的必要条件。事实上,它是商业创新的关键。

为可信数据使用建立适当的条件

我们还相信,可信的数据治理需要正确的能力和明确的问责。我们需要这两者同时存在,所以让我强调我们加强这些领域的两种方式。

发展AI和数据能力

第一是帮助组织掌握如何良好使用数据和AI。

大多数组织已经认识到AI和数据的潜力。

更困难的问题是我们如何开始最大限度地利用它。

数字孪生是当今公司的一个实际机会。

数字孪生是物理资产、系统或流程的实时虚拟表示。

公司可以使用它来模拟场景、优化运营和做出更好的决策。

数字孪生并不少见。如果你与任何F1车队交流,他们都有数字孪生,因为他们需要模拟工程改进对车辆和驾驶员性能的影响。因此,这些数字孪生已被技术精明且处于技术前沿的公司使用。但我们看到,即使是今天的SMEs也可能能够构建自己的数字孪生。

以Exceltec为例。它是新加坡的一家设施管理公司。

它构建了一个数字孪生,该孪生利用来自该公司拥有客户业务的70多个地点的传感器数据。它代表其客户进行设施管理,因此在70个地点,它已经安装了传感器并能够利用传感器数据。他们构建的系统持续分析这些数据,并帮助及早识别操作问题。

例如,建筑物的空调系统是否出现故障迹象?

或者水用量是否无明显原因地突然增加,暗示某处有泄漏?

与严重依赖人工检查相比,Exceltec 团队现在可以在需要注意时自动收到警报。

这帮助每个团队在每次检查上每天节省约四十五分钟。

在众多建筑、团队和天数中,这些收益加起来。

更重要的是,组织从对问题的被动反应转变为更早发现问题并更快采取行动。

为了帮助更多公司像 Exceltec 一样受益,IMDA 正在推出《企业数字孪生手册》。这是一份实用法律指南,帮助组织更好地结合人工智能和数据,并设计数字孪生以解决其运营瓶颈。这是我们想做的事情之一。

澄清良好的问责制应该是什么样子

随着越来越多的组织开发、调整或部署生成式人工智能工具,我们必须解决问责问题。

以一个想要使用通话录音来改进生成式人工智能模型的客户服务团队为例,以便他们能够更快更准确地回应客户查询。

我们都接过这样的电话,被告知通话可能会被录制以进行质量检查和改进。但我们也知道这些录音可能包含个人数据,例如我们的姓名、地址、账单详情。

这些客户服务团队在使用客户数据进行模型训练前对客户有什么义务?

今天,PDPC 正在发布其《生成式人工智能中个人数据使用建议指南》。

经过咨询行业和公众,我们明确了组织如何能够履行《PDPA》中的现有法律要求,即应从数据所有者那里征求同意。我们明确表示,当个人数据被用于开发或改进生成式人工智能模型时,组织应直言不讳,而不是依赖于用户可能不会注意或理解的宽泛描述。

对于我描述的例子中的客户服务团队,他们可以更新隐私政策,说明已同意的客户的通话录音将被用于训练和改进人工智能模型。

他们还可以更新员工在征求同意时使用的脚本。

客户随后可以理解目的,在给予同意前做出知情选择。

许多组织今天已经提供了这样的人工智能专项通知。因此,该指南进一步延伸。

它们还涵盖人工智能价值链中各方的角色和责任,以及在依赖公开可用数据时的尽职调查。

由于对现有要求如何适用于生成式人工智能有了更清晰的理解,公司可以设计具有适当防护措施的更好流程。

超越数据层,我们还支持人工智能应用程序的问责制。

对于大多数用户来说,他们最常接触的生成式人工智能应用是聊天机器人。

我们使用这个应用程序,但可能不知道它的局限性,或我们的数据会发生什么。

这些信息通常是存在的。但它散布在服务条款、隐私通知和其他文件中,对于普通用户来说,通常要么过于简单,要么过于技术性。

为了填补这一空白,IMDA 作为第一步推出了《生成式人工智能聊天机器人透明度指南》。

该指南要求提供一张聊天机器人信息卡,其工作方式类似于我们经常在药品包装上找到的标签。

标签不会告诉我们每个科学细节。

相反,它告诉我们要点:药物的用途、如何使用、建议用量、要注意的副作用、何时不使用。

信息卡的工作方式应该相同。它用清晰的语言说明了聊天机器人的用途、不用于什么、数据可能如何处理,以及用户如何报告问题。

我们从自愿框架开始,随着实践的成熟,将根据行业意见对其进行改进。

我们为 DBS、Google、Meta、OCBC 和新航等公司的支持感到欣慰,他们将把《指南》作为参考,继续改进其聊天机器人的透明度实践。

就 Google 而言,这意味着整合有关 Gemini 应用程序的关键信息,使用户能够轻松获取这些信息,以便他们能够更有信心地使用 Gemini。

Meta 也将为人们提供清晰且易获取的信息,说明其 AI 驱动的工具和产品如何运作,以及人们与之互动的方式。

我提到的这些公司是早期采用者,在数据和 AI 治理方面展现了领导力。我们希望更多公司能够追随他们的脚步。

共同构建生态系统

这让我想到了今天最后要表达的一点,即在构建可信任的数据和 AI 生态系统中伙伴关系的重要性。

在开发我们的 AI 中心(无论是在新加坡还是其他地方)时,我们需要一个由企业、技术提供商、研究人员、从业者、标准制定机构和监管机构组成的强大社区。我们需要相互学习、测试想法并共同提高标准。

一个很好的例子是今年 1 月举办的 AI 安全红队挑战赛。

超过 80 名专家参加了该活动。

他们来自所有东盟国家,以及中国、印度、日本和韩国。

他们的任务是测试生成式 AI 应用程序是否会泄露不应该泄露的数据。

参与者不仅包括研究人员和网络安全专家。还包括了解本地语言、文化和背景的语言学家和社会学家。事实证明这产生了真正的影响。

一些团队发现,有害请求在英文中被拒绝了,但在柬埔寨语中却被回答了。

其他团队发现,随意的本地措辞可以绕过正式措辞无法绕过的安全防护。

换句话说,模型对正式请求的响应方式是正确的,但当用本地措辞提出请求时,模型的安全防护失效了。

这个漏洞以及许多其他已识别的漏洞不仅是技术问题,也是语言和文化问题。

这是我们今天想要分享的更广泛的教训。

我们无法仅通过关注自身范围来建立可信任的数据生态系统。

只有当我们汇聚来自该地区的各种专家时,我们才能看到模型风险的完整多样性。

当新加坡明年担任东盟主席国时,我们将与地区伙伴合作,加强条件,使数据在整个地区能够被自信地使用。这意味着:

使我们的方法更加接近,

为企业减少不必要的摩擦,以及

为我们的数字经济创造更多增长空间。

最终,没有任何手册、指南或技术标准能够独自取得成功。只有当人们和组织将其付诸实践、分享他们学到的知识并共同提高标准时,这些才会变得有意义。

这就是为什么这个节日很重要。

它汇聚了保护数据的人、使用数据的人、构建 AI 系统的人,以及监管其使用的人。

这将帮助我们将好的想法转化为更好的实践,为新加坡和该地区的可信任数据使用建立更坚实的基础。

那么,我祝愿各位在本次节日中度过卓有成效的一天。再次感谢各位的出席。

英文原文

MDDI 官网原始记录 · 抓取日期: 2026-07-28

Good Morning, colleagues and friends. It was less than four hours ago that the World Cup had its finals. And I was early for this event because I thought the Monday morning traffic would be at a certain level, but today the roads were very quiet. I hope your favourite team won.

The scoreline was actually quite interesting. The last time that Spain won the World Cup, they had a similar scoreline. Quite amazingly, the data shows that on the way to winning the World Cup, they did not drop more than one goal. Kudos to the Spanish team, and kudos to you, for still being here. You must really love data. You deserve a round of applause.

Many of our friends today have joined us on previous occasions when we held the Personal Data Protection Week. This year, we have broadened the event into the Singapore Data Festival. Some of you pointed this out to me.

This is not because data protection is no longer important. It still is.

But organisations are also asking bigger questions about data, especially how to support their AI endeavours.

The Data Festival is therefore designed for us to better recognise the business value of data . At the same time, to create lasting value, we must work together to build a trusted data ecosystem in Singapore, as well as the region. So let’s talk a little more about data as a source of business value.

Data as a source of business value

As you know, businesses have always used data, whether they speak of it as such or not.

Retailers look at sales data to assess changing customer preferences and adjust their stock levels accordingly.

Banks look at transactions data for evidence of fraud, to decide which accounts and parties are problematic, and what to do about them.

Data used to tell businesses what happened. It was all in the past tense. But now, with the help of technology, businesses can see developments as they happen, almost in real time, and data, when used appropriately, can help businesses take the right action sooner rather than later.

Now, we all like to be able to do that, act sooner rather than be caught by surprise. AI accelerates this process. AI systems depend on data at every stage of their lifecycle. In fact, IMDA has consistently talked about data before AI. But without good data, even the best systems will struggle to produce useful outcomes.

That is why data governance matters more, not less, in the age of AI.

Data creates value only when there is trust

At its heart, data governance is about trust.

Customers share data only if they trust the organisation to safeguard it properly and use it responsibly.

Businesses share data with partners only if they trust that the data will not be abused to compromise their own interests.

This is why Singapore has always thought of data protection as essential to a well-functioning business environment. In fact, it is key to business innovation.

Building the right conditions for trusted data use

We also believe that trusted data governance comes with the right capabilities and clear accountability. We need these two to be present at the same time, so let me highlight two ways we are strengthening these areas.

Developing AI and data capabilities

The first is helping organisations build the know-how to use data and AI well.

Most organisations already recognise the potential of AI and data.

The harder question is how do we begin to make the most of it.

Digital twins are one practical opportunity for companies today.

A digital twin is a real-time virtual representation of physical assets, systems, or processes.

Companies can use it to simulate scenarios, optimise operations, and make better decisions.

Digital twins are not so uncommon. If you talk to any F1 team, they do have digital twins, because they need to simulate the engineering improvement impact on the performances of both the vehicle, as well as the driver. So, these digital twins have been used by companies that are tech-savvy and at the frontier of technology. But we see that even SMEs today could potentially build their own digital twins.

You take Exceltec. It is a facilities management company in Singapore.

It built a digital twin that draws on sensor data from more than 70 sites where the company has customer operations. It conducts facilities management on behalf of its clients, so at 70 sites, it has inserted sensors and is able to harness the sensor data. The system that they built analyses this data continuously, and helps identify operational problems early.

For example, is a building’s air-conditioning system showing signs of a breakdown?

Or does water usage appear to have spiked for no apparent reason, suggesting a leakage somewhere?

Compared to the heavy reliance on manual inspections, teams at Exceltec can now be alerted automatically when something needs attention.

This has helped each team save about forty-five minutes a day on each inspection.

Across many buildings, teams, and days, the gains add up.

More importantly, the organisation moves from reacting to problems, to detecting them earlier and acting faster.

To help more companies benefit like Exceltec, IMDA is launching a Digital Twin For Enterprises Playbook. It is a practical legal guide to help organisations better combine AI and data, and design digital twins to address their operational bottlenecks. That’s one of things we would like to do.

Clarifying what good accountability looks like

As more organisations develop, adapt or deploy generative AI tools, we must address the question of accountability.

Take for example, a customer service team that wants to improve a Generative AI model using call recordings, so that they can respond more quickly and accurately to customer queries.

We have all been at the receiving end of these calls, and being asked or told that the call may be recorded for quality checks and improvement. But we also know that the recordings may contain personal data, such as our names, addresses, billing details.

What are the obligations that these customer service teams have to the customers before using their data for model training?

Today, the PDPC is issuing its Advisory Guidelines on the Use of Personal Data in Generative AI.

Having consulted industry and the public, we are making clear how organisations can fulfil an existing legal requirement in the PDPA for consent to be sought from the data owner. We are making it clear that where personal data is used to develop or improve a Generative AI model, organisations should say so plainly, rather than rely on broad descriptions that users may not notice or understand.

For the customer service team in the example that I described, they can update the privacy policy to state that call recordings of consenting customers will be used to train and improve AI models.

They can also update the scripts that staff use when seeking consent.

Customers can then understand the purpose and make an informed choice before giving consent.

Many organisations already provide such AI-specific notices today. Therefore, the Guidelines go further.

They also cover the roles and responsibilities of parties across the AI value chain, and due diligence when relying on publicly available data.

With greater clarity on how existing requirements apply to Generative AI, companies can design better processes with the right safeguards.

Beyond the data layer, we are also supporting accountability for AI applications.

For most users, the Generative AI application they meet most often is the chatbot.

We use the application, but may not know itslimitations , or what happens to our data.

The information usually exists. But it is scattered across the terms of service, privacy notices and other documents, and is often either too simplistic or too technical for ordinary users.

To close this gap, IMDA is launching the Generative AI Chatbot Transparency Guidelines as a first step.

The Guidelines call for a Chatbot Information Card that works like the label we often find on the packaging of medicinal products.

The label does not tell us every scientific detail.

Instead, it tells us the essentials: what the medicine is for, how to take it, how much is recommended, what side effects to watch for, when not to use it.

The Information Card is meant to work the same way. It sets out in plain language what the chatbot is for, what it is not for, how data may be handled, and how users can report issues.

We are starting with a voluntary framework, and will refine it with industry inputs as practices mature.

We are heartened by the support from companies like DBS, Google, Meta, OCBC and SIA, who will be using the Guidelines as a point of reference as they continue improving transparency practices for their chatbots.

In Google’s case, this means consolidating key information about the Gemini app, and making that information easily accessible to users, so that they can use Gemini with greater confidence.

Meta will also provide people with clear and accessible information about how its AI-powered tools and products work and the ways people can interact with them.

The companies I mentioned are early adopters who are demonstrating leadership in data and AI governance. We hope many more will follow their tracks.

Building the ecosystem together

This brings me to a final point I would like to make today about the importance of partnership in building trusted data and AI ecosystems.

In developing our AI hubs, whether Singapore or elsewhere, we need a strong community of businesses, technology providers, researchers, practitioners, standards bodies and regulators. We need to learn from one another, test ideas, and raise standards together.

One good example is this year’s AI Safety Red Teaming Challenge held in January.

More than 80 experts took part.

They came from all ASEAN countries, as well as China, India, Japan, and Korea.

Their task was to test whether Generative AI applications could leak the data they were not supposed to.

The participants were not only researchers and cyber experts. They also included linguists and sociologists who understood local language, culture, and context. That turned out to have made a real difference.

Some teams found that a harmful request refused in English was answered in the Khmer language.

Others found that casual local phrasing could slip through the safeguards that a formal-sounding request could not.

In other words, the model responded to a formal request the way it should, but when the request was put to it with local phrasing, the model safeguards failed.

This vulnerability, and many others that were identified, were not only technical; they were also linguistic and cultural.

That is the wider lesson we would like to share today.

None of us can build a trusted data ecosystem by looking only within our own borders.

We see the fuller variety of model risks only when we bring together a range of experts from the region.

As Singapore assumes the ASEAN Chairmanship next year, we will work with regional partners to strengthen the conditions for data to be used with confidence across our region. This means:

Bringing our approaches closer together,

Reducing unnecessary friction for businesses, and

Creating more room for our digital economies to grow.

Ultimately, no playbook, guideline or technical standard succeeds on its own. They become meaningful only when people and organisations put them into practice, share what they have learnt, and collectively raise standards.

That is why this Festival matters.

It brings together those who protect data, use data, build AI systems, and govern their use.

This will help us turn good ideas into better practice and build a stronger foundation for trusted data use in Singapore and the region.

And so, on that note, I wish you all a very fruitful day ahead at the Festival. Thank you once again for being here.