Assurance as Infrastructure: How Singapore Governs AI in Practice

As Singapore’s AI ecosystem continues to expand rapidly, regulatory frameworks are evolving to keep pace with new risks and opportunities in artificial intelligence (AI). This article examines Singapore’s distinctive tech governance architecture and explores how combining enforceable legal baselines, targeted interventions, and measurable AI assurance can build a safe and resilient digital economy even without an overarching AI law.

By Lim How Khang, Assistant Professor of Law and Computer Science (Practice); Director, BSc (Computing & Law) Programme, Singapore Management University

At a glance

  • No Horizontal AI Act: Rather than enacting an overarching AI law, Singapore relies on a dense baseline of existing, domain-specific legislation covering data protection, cybersecurity and online safety. Singapore has not introduced a horizontal AI law and continues to monitor whether one is needed.

  • Targeted Interventions: Parliament has shown that it can enact narrowly targeted legislation within weeks when a specific gap becomes urgent, such as election deepfakes and persistent financial scams.

  • Proof as Infrastructure: Tools such as AI Verify help firms assess, document and demonstrate responsible AI practices, translating governance principles into testable evidence that can support compliance processes, procurement decisions and stakeholder trust.

  • The Fragility of Trust: The model’s long-term agility depends on sustaining public confidence, managing unmapped model-level risks and achieving cross-border interoperability via international frameworks and the ASEAN DEFA.

Share this insight

Singapore has not enacted a horizontal AI law and has no immediate plans to do so. Instead, the nation has built a calibrated governance model relying on three core components: 1) an enforceable, tested baseline of laws; 2) swift, targeted legislative interventions; and 3) an assurance layer that equips firms to evidence how their AI systems have been assessed, tested and governed. The premise underneath the three components is that demonstrable trust can do some of the work that a comprehensive horizontal statute might otherwise do.

Layer 1:  The Enforced Floor – Baseline of existing laws

While binding AI legislation and instruments are emerging across parts of Southeast Asia, Singapore has opted for a different approach that does not involve a dedicated AI Act.  The starting point, as articulated in May 2024 by Josephine Teo (then Minister for Communications and Information and now Minister for Digital Development and Information), is that the country is “not starting at ground zero”. Many key AI-enabled harms are already covered by existing law i.e.:

For other risks, Singapore applies existing frameworks adapted for AI rather than new, broad legislation. Specifically:

Crucially, Singapore maintains a strong track record on enforcement. The Personal Data Protection Commission (PDPC) has published enforcement decisions since 2016, imposing penalties totalling S$1 million in the landmark SingHealth case. More recently, in July 2025, the Monetary Authority of Singapore (MAS) imposed S$27.45 million in composition penalties across nine financial institutions in a co-ordinated set of actions.

Furthermore, under OCHA, authorities issued the Act’s first implementation directive to Meta in September 2025 over impersonation scams; by early 2026, it had issued three more directives to Meta, Apple and Google. Separately, a code of practice pushed child-safety obligations upstream directly to designated app stores.

Layer 2: The Buttress – Swift Targeted Laws

The actively enforced baseline forms the first component of the model. The second activates when a specific harm outstrips this baseline: the Parliament intervenes by legislating quickly and narrowly.

When AI-generated deepfakes of candidates emerged as an election-integrity risk that existing falsehoods laws could not squarely address, the Parliament passed the Elections (Integrity of Online Advertising) (Amendment) Bill in approximately five weeks in late 2024—a targeted prohibition confined strictly to election advertising. Similarly, to combat persistent scam harms, the Protection from Scams Act 2025 granted the Police the power to issue time-bound Restriction Orders to banks. This operational intervention limits an individual’s banking and credit facilities within running systems if there is reason to believe funds may be transferred to a scammer.

The regulatory pattern remains consistent: Singapore regulates the harm wherever it arises, whatever the technology behind it. Once enacted and enforced, each targeted statute thickens the baseline upon which the model rests. The system moves most rapidly in addressing the harms most visible to citizens, such as scams, platform-enabled impersonation and salient emerging risks like election deepfakes.

Layer 3: The Proving Ground – Demonstrated Safety

The third component, i.e. assurance, equips firms (and, in some regulated, procurement or contractual settings, requires them) to demonstrate how their AI systems have been assessed, tested and governed.. Simultaneously, it acts as the mechanism that enables AI adoption and deployment. As Minister Teo frames it, safety is “not viewed as a brake on innovation” but as part of Singapore’s value proposition. Businesses, public agencies and citizens will integrate AI deeply into important systems only if they are confident those systems are reliable and governed. Demonstrable safety clears the path to deployment.

Various instruments build this confidence in stages:

Instrument / Initiative

Core Function & Governance Objective

AI Verify

A government-developed testing framework and toolkit (now stewarded by the AI Verify Foundation) that provides a structured way to evidence how a system performs against governance principles.

Global AI Assurance Sandbox

Pairs specialist testers with real-world deployers, turning one-off evaluations into shared, practical norms for generative AI that others can reuse.

Sectoral Guidelines & Sandboxes

Sector regulators drive testable requirements. The MAS consulted on AI risk-management guidelines for financial institutions in November 2025, while the Health Sciences Authority (HSA) runs a scoped sandbox for AI medical software developed by selected public healthcare institutions—exchanging licensing and registration for safeguards like clinician oversight, quality-system attestations and pre-deployment notification.

Much of this assurance layer is not binding in a statutory sense. Voluntary guidance and frameworks—such as advisory guidelines for cloud services and data centres, or the living framework for agentic AI—signal an “audit-ready” direction. These frameworks identify current good practice and could harden into de facto requirements through procurement, insurance and enterprise due diligence. Singapore may hasten this hardening by building its own tools into public-sector deployment and testing workflows.

Through this approach, regulators discover what works practically before deciding what to mandate, allowing firms to engineer against testable requirements rather than legal guesswork. The result is what I have elsewhere called  “sovereignty-by-assurance”. Instead of relying on direct ownership or rigid data localisation, the state maintains control by making safety measurable. For instance, where an essential service relies on cloud or outsourced infrastructure, the regulated Singapore deployer stays accountable, and designated foundational providers can face codes, standards and incident-reporting duties, wherever the service is hosted.

Why It Fits Singapore

This tailored model is particularly well suited to Singapore’s constraints:

  • A small, open economy cannot alter how frontier models are built globally through domestic statutes alone.
  • For a hub economy, regulatory predictability and institutional trust are key factors that help attract international firms to establish their AI operations in Singapore.
  • A talent and resource conscious economy like Singapore sees AI adoption as a key productivity driver, which informs a regulatory approach designed to facilitate, rather than hinder, the deployment of these technologies..
  • This responsive regulatory stance depends on a credible mechanism for intervention, underpinned by active enforcement capabilities, existing legal structures, and a swift legislative process.

Singapore pursues agility by using assurance alongside an enforceable statutory baseline, reserving additional legislation for risks that existing tools cannot adequately address. This model, however, may not be a universal template, but it can serve as a practical reference point built on three principles:

  1. Prioritise enforceable digital foundations.
  2. Build measurable trust through assurance.
  3. Deploy legislation only when existing tools are insufficient.

What the Model Rests On

Even when earned, that trust is not permanent. The entire governance model rests on three conditional pillars, none of which are guaranteed:

  • Public Trust: A model governed by trust must consistently deliver its values. Public support is contingent on tangible results: whether AI drives economic opportunity rather than job displacement, ensures equitable public services, and effectively reduces daily harms like scams and fraud. If these outcomes falter, the policy flexibility that the entire model relies upon is likely to narrow.
  • The Shape of the Risk: Most AI harms arrive where a system enters a specific domain like a bank, a clinic or a workplace—a place a domain regulator can see and weigh, which is why sectoral supervision has been able to stretch to cover it. However, a foundational model-level failure, or an adversarial use that scales cheaply and strikes from outside the perimeter (such as a model-enabled cyberattack launched from abroad), may lack a readily identifiable Singapore-based deployer or clear sectoral owner. These risks are the hardest for a deployer-centred assurance model to reach, falling instead to cyber and security agencies, or to future legislation.
  • International Recognition: Assurance is worth little if no one else honours it; a model built on proof must work outward so that an evaluation done in Singapore is accepted abroad. Bilaterally, that work is well underway, with ongoing bilateral initiatives to align local frameworks with US standards for mutual recognition.

The open question is whether this legibility can be built regionally. If regional rules fragment into duplicate audits and rival labels, proof becomes a compliance cost rather than shared infrastructure. If they converge, Singapore’s frameworks offer a practical reference point for aligning the region’s diverse regulatory approaches.

The ASEAN Digital Economy Framework Agreement (DEFA), slated for signature in late 2026, will be an early indicator. While focused on digital trade and non-binding AI cooperation, its interoperability machinery—such as cross-border data flows and common standards—could facilitate mutual assurance if the final text extends to AI testing and evaluation.

Ultimately, Singapore’s wager remains the same: that in the AI era, the scarcest commodity is not regulation, but proof.

 

The views and recommendations expressed in this article published in August 2026 are solely of the author and do not necessarily reflect the views and position of the Tech for Good Institute.

Share this insight

Discover

How is Tech for Good Institute enabling digital economy and society in Southeast Asia?

Cite this article

Khang, L. H. (2026, August 12). Assurance as Infrastructure: How Singapore Governs AI in Practice. Tech For Good Institute. Retrieved from https://techforgoodinstitute.org/insights/country-spotlights/assurance-as-infrastructure-how-singapore-governs-ai-in-practice/

Keep pace with the digital pulse of Southeast Asia!

Never miss an update or event!

Mouna Aouri

Programme Fellow

Mouna Aouri is an Institute Fellow at the Tech For Good Institute. As a social entrepreneur, impact investor, and engineer, her experience spans over two decades in the MENA region, South East Asia, and Japan. She is founder of Woomentum, a Singapore-based platform dedicated to supporting women entrepreneurs in APAC through skill development and access to growth capital through strategic collaborations with corporate entities, investors and government partners.

Dr Ming Tan

Senior Fellow & Founding Executive Director

Dr Ming Tan is Senior Fellow at the Tech for Good Institute; where she served as founding Executive Director of the non-profit focused on research and policy at the intersection of technology, society and the economy in Southeast Asia. She is concurrently a Senior Fellow at and the Centre for Governance and Sustainability at the National University of Singapore and Advisor to the Founder of the COMO Group, a Singaporean portfolio of lifestyle companies operating in 15 countries worldwide. Ming was previously Managing Director of IPOS International, part of the Intellectual Property Office of Singapore. Prior to joining the public sector, she was Head of Stewardship of the COMO Group.


Ming also serves on the boards of several private companies, Singapore’s National Volunteer and Philanthropy Centre, Singapore Network Information Centre (SGNIC), and on the Digital and Technology Advisory Panel for Esplanade–Theatres on the Bay, Singapore’s national performing arts centre. Her current portfolio spans philanthropy, social impact, sustainability and innovation.