
By Lim How Khang, Assistant Professor of Law and Computer Science (Practice); Director, BSc (Computing & Law) Programme, Singapore Management University
At a glance
- Existing Powers Move into Enforcement: Singapore is using established online safety and platform governance powers, including implementation and disabling directions under the Online Criminal Harms Act, enhanced supervision of major platforms.
- AI, Cybersecurity and Data Governance Strengthen Assurance: AI governance is moving towards more concrete expectations around accountability, testing and third-party assurance, while cybersecurity and data protection measures increasingly rely on certification, higher security baselines and clearer implementation deadlines.
- New Obligations Are Being Introduced in Stages: Singapore is sequencing the implementation of new regulatory frameworks, with several laws enacted but not yet commenced and obligations phased in over time, while continuing to strengthen institutional capacity and international interoperability.
Share this insight
In the first half of 2026, Singapore repeatedly used powers already on the books while placing several other broader new duties on a later timetable. The main laws enacted during the period did not come into force immediately. A few quieter requirements did apply — telecommunications operators began enforcing an aggregate cap of ten postpaid SIM cards per individual for new subscriptions, and designated app stores had to start checking users’ ages from April. None makes for a dramatic headline on its own. However, they show existing machinery in use while the next layer of obligations was being prepared.
Key Policy Trends
AI Governance: Building Assurance and Accountability
AI governance became more specific about delegated action and responsibility. The Infocomm Media Development Authority (IMDA) issued, then updated, a Model AI Governance Framework for Agentic AI, and published a discussion paper on legal responsibility for AI agents. The discussion paper consolidates expert views on who answers for a decision an autonomous system makes. Together these documents develop practical AI governance guidance and explore how existing civil liability laws could apply to agentic AI deployments.
Alongside these frameworks, Singapore is also strengthening assurance mechanisms. A new programme to accredit third-party AI testers is intended to establish which independent testing results deployers and regulators can trust. These moves sit on top of over SGD 1 billion (USD 7.8 million) AI research and a National AI Impact Programme to help businesses adopt the technology.
Sector-specific governance and implementation also proceeded in parallel. MAS published a non-binding AI risk toolkit for financial services and worked with banks on a proof of value for financial-crime detection, while the Ministry of Transport consulted on a future autonomous-vehicle law without committing to final positions on liability or insurance.
Cybersecurity and Data Protection: Raising the Assurance Baseline
Cybersecurity moved on two tracks at once: responding to an active campaign while raising baseline expectations elsewhere. The Cyber Security Agency of Singapore (CSA) and IMDA disclosed Operation CYBER GUARDIAN, an eleven-month response after the advanced persistent threat actor UNC3886 targeted all four major telecommunications operators.
CSA then announced tiered Cyber Trust Mark requirements for the non-CII systems supporting critical-information-infrastructure owners’ business operations, for approved CII auditors at organisation level, and for licensed cybersecurity providers. CSA and IMDA separately announced that residential routers would move to a higher mandatory security baseline by the end of 2027, and Singapore agreed with Japan to recognise specified Internet-of-Things cybersecurity labels.
The Government also announced plans for a Digital Infrastructure Act for data centres and major cloud-service providers. This might signal an expansion of baseline assurance requirements across critical digital infrastructure.
Data protection tightened in a similar way, by extending what already exists rather than starting over. New regulations recognise four certification systems that organisations may rely on when transferring personal data outside Singapore.
The Personal Data Protection Commission (PDPC) announced a 31 December 2026 deadline for organisations to stop using NRIC numbers for authentication, with stepped-up enforcement from 2027. It also opened consultation on how the Personal Data Protection Act 2012 applies to generative-AI development and deployment, rather than proposing a separate AI data law.
This reflects an intentional direction in terms of security and protection. While maintaining its foundational regulatory frameworks, Singapore is relying more on certification, enforceable baselines, and implementation deadlines to enhance digital assurance.
Digital Platforms and Online Safety: Existing Powers Move into Enforcement
Existing platform and online-safety powers have increasingly been exercised. The OCHA Competent Authority, sited within the Singapore Police Force, issued a second Implementation Directive to Meta, requiring expanded facial-recognition measures and priority review of impersonation-scam reports. The Police separately issued disabling directions over religiously offensive content on Meta and inflammatory racial content on Facebook, YouTube and X: three uses of the Online Criminal Harms Act 2023 in a span of six months.
The Broadcasting Act 1994 was invoked to block six inauthentic websites, and the Competition and Consumer Commission of Singapore (CCS) obtained undertakings from three online retailers to stop using misleading online practices.
Singapore also proposed amending the Foreign Interference (Countermeasures) Act 2021 to permit anticipatory directions against online communications media before a hostile information campaign causes harm. The proposal signals a shift from reactive content intervention to a more preventive approach for online platforms.
A clear example of legislation becoming operational came on 29 June 2026. The Online Safety Commission opened with the first five of the Online Safety (Relief and Accountability) Act 2025’s thirteen categories of online harm in force. IMDA also followed through on its second Online Safety Assessment Report by placing X and TikTok under enhanced supervision (X for weak detection of child sexual exploitation and abuse material, and TikTok for weak handling of terrorism content).
Cross-cutting Governance Trends
Institutional Change: Building Capacity Around Emerging Governance Functions
Singapore is building standing institutional capacity around online safety, cybercrime and national AI policy. The Online Safety Commission’s launch was the clearest example, but a Police Cyber Command was also announced for July, and the National AI Council, established in February, now provides strategic direction for the refreshed National AI Strategy.
Another notable institutional update is the decision to rename the Ministry of Trade and Industry (MTI) to the Ministry of Energy, Trade and Industry (METI), reflecting a growing focus on energy as a strategic priority for economic and digital transformation.
Staged Implementation: Sequencing New Obligations
New regulatory obligations are being progressively rolled out instead of all at once. This phased approach and deliberate sequencing allows the Government to signal intent by first establishing the regulatory framework before bringing obligations into force, giving regulators and affected businesses time to prepare for implementation and to comply with the new requirements.
Several developments during the first half of 2026 highlight this approach. Parliament passed the Bills that became the Health Information Act 2026, the Public Sector (Governance) (Amendment) Act 2026 and the Info-communications Media Development Authority (Amendment) Act 2026. All three resulting Acts had been published by 30 June, but none had commenced. In other areas, implementation timelines were similarly phased. Online Safety Commission commenced its operations in June 2026, initially focusing on five out of the 13 categories of online harm with plans to gradually introduce the remaining categories.
In addition, private organisations are required to cease the use of full or partial NRIC numbers for authentication by 31 December 2026. Following this deadline, the PDPC will enhance enforcement measures starting from 1 January 2027. Meanwhile, it is anticipated that the mandatory cybersecurity requirements for residential routers will increase from Cybersecurity Labelling Scheme Level 1 to Level 2 by the end of 2027.
Regional and International Coordination: Linking Domestic Governance with Interoperability
Singapore remains connected to the global digital economy by keeping its domestic systems interoperable with those of its trading partners, reducing the legal and technical friction of cross-border digital transactions. The EU-Singapore Digital Trade Agreement entered into force, while the EFTA-Singapore Digital Economy Agreement took effect for Singapore and Norway.
On the regional front, ASEAN concluded negotiations on its Digital Economy Framework Agreement, and Singapore moved forward on Peru’s accession to the Digital Economy Partnership Agreement and on the WTO Agreement on E-Commerce.
OCEANS-X and the TradeTrust Readiness Programme performed a related but different function as they put maritime data exchange and electronic trade documents into operational use through infrastructure and adoption support rather than new regulatory duties. The common feature was a preference for building practical systems alongside formal rules.
Moving forward
No single law or measure defines the first half of 2026. What stands out instead is the staging and deployment of the model developed in earlier years. Powers already on the books were used in relation to platforms, websites and online retailers. The Online Safety Commission opened its doors. Three newly enacted laws remained on the statute book awaiting commencement, while further obligations on digital infrastructure, cyber assurance and autonomous vehicles entered the policy pipeline.
Internationally, agreements with the EU and EFTA entered into force, while negotiations advanced through ASEAN and DEPA. These developments continued Singapore’s attempt to combine domestic assurance with external recognition, rather than choosing between openness and control.
The views and recommendations expressed in this article, published in September 2026, are solely of the author and do not necessarily reflect the views and position of the Tech for Good Institute.
