Governance Meets Reality: Singapore’s Evolving Tech Governance

In the last of our six-part country spotlight series under Tech Governance in Southeast Asia-6, Lim How Khang, Assistant Professor of Law and Computer Science (Practice); Director, BSc (Computing & Law) Programme, Singapore Management University, examines how Singapore’s tech governance landscape is evolving at mid-2026.

By Lim How Khang, Assistant Professor of Law and Computer Science (Practice); Director, BSc (Computing & Law) Programme, Singapore Management University

At a glance

  • Existing Powers Move into Enforcement: Singapore is using established online safety and platform governance powers, including implementation and disabling directions under the Online Criminal Harms Act, enhanced supervision of major platforms.
  • AI, Cybersecurity and Data Governance Strengthen Assurance: AI governance is moving towards more concrete expectations around accountability, testing and third-party assurance, while cybersecurity and data protection measures increasingly rely on certification, higher security baselines and clearer implementation deadlines.
  • New Obligations Are Being Introduced in Stages: Singapore is sequencing the implementation of new regulatory frameworks, with several laws enacted but not yet commenced and obligations phased in over time, while continuing to strengthen institutional capacity and international interoperability.

Share this insight

In the first half of 2026, Singapore repeatedly used powers already on the books while placing several other broader new duties on a later timetable. The main laws enacted during the period did not come into force immediately. A few quieter requirements did apply — telecommunications operators began enforcing an aggregate cap of ten postpaid SIM cards per individual for new subscriptions, and designated app stores had to start checking users’ ages from April. None makes for a dramatic headline on its own. However, they show existing machinery in use while the next layer of obligations was being prepared.

Key Policy Trends

AI Governance: Building Assurance and Accountability

AI governance became more specific about delegated action and responsibility. The Infocomm Media Development Authority (IMDA) issued, then updated, a Model AI Governance Framework for Agentic AI, and published a discussion paper on legal responsibility for AI agents. The discussion paper consolidates expert views on who answers for a decision an autonomous system makes. Together these documents develop practical AI governance guidance and explore how existing civil liability laws could apply to agentic AI deployments.

Alongside these frameworks, Singapore is also strengthening assurance mechanisms.  A new programme to accredit third-party AI testers is intended to establish which independent testing results deployers and regulators can trust. These moves sit on top of over SGD 1 billion (USD 7.8 million) AI research and a National AI Impact Programme to help businesses adopt the technology.

Sector-specific governance and implementation also proceeded in parallel. MAS published a non-binding AI risk toolkit for financial services and worked with banks on a proof of value for financial-crime detection, while the Ministry of Transport consulted on a future autonomous-vehicle law without committing to final positions on liability or insurance.

Cybersecurity and Data Protection: Raising the Assurance Baseline

Cybersecurity moved on two tracks at once: responding to an active campaign while raising baseline expectations elsewhere. The Cyber Security Agency of Singapore (CSA) and IMDA disclosed Operation CYBER GUARDIAN, an eleven-month response after the advanced persistent threat actor UNC3886 targeted all four major telecommunications operators.

CSA then announced tiered Cyber Trust Mark requirements for the non-CII systems supporting critical-information-infrastructure owners’ business operations, for approved CII auditors at organisation level, and for licensed cybersecurity providers. CSA and IMDA separately announced that residential routers would move to a higher mandatory security baseline by the end of 2027, and Singapore agreed with Japan to recognise specified Internet-of-Things cybersecurity labels.

The Government also announced plans for a Digital Infrastructure Act for data centres and major cloud-service providers. This might signal an expansion of baseline assurance requirements across critical digital infrastructure.

Data protection tightened in a similar way, by extending what already exists rather than starting over. New regulations recognise four certification systems that organisations may rely on when transferring personal data outside Singapore.

The Personal Data Protection Commission (PDPC) announced a 31 December 2026 deadline for organisations to stop using NRIC numbers for authentication, with stepped-up enforcement from 2027. It also opened consultation on how the Personal Data Protection Act 2012 applies to generative-AI development and deployment, rather than proposing a separate AI data law.

This reflects an intentional direction in terms of security and protection. While maintaining its foundational regulatory frameworks, Singapore is relying more on certification, enforceable baselines, and implementation deadlines to enhance digital assurance.

Digital Platforms and Online Safety: Existing Powers Move into Enforcement

Existing platform and online-safety powers have increasingly been exercised. The OCHA Competent Authority, sited within the Singapore Police Force, issued a second Implementation Directive to Meta, requiring expanded facial-recognition measures and priority review of impersonation-scam reports. The Police separately issued disabling directions over religiously offensive content on Meta and inflammatory racial content on Facebook, YouTube and X: three uses of the Online Criminal Harms Act 2023 in a span of six months.

The Broadcasting Act 1994 was invoked to block six inauthentic websites, and the Competition and Consumer Commission of Singapore (CCS) obtained undertakings from three online retailers to stop using misleading online practices.

Singapore also proposed amending the Foreign Interference (Countermeasures) Act 2021 to permit anticipatory directions against online communications media before a hostile information campaign causes harm. The proposal signals a shift from reactive content intervention to a more preventive approach for online platforms.

A clear example of legislation becoming operational came on 29 June 2026. The Online Safety Commission opened with the first five of the Online Safety (Relief and Accountability) Act 2025’s thirteen categories of online harm in force. IMDA also followed through on its second Online Safety Assessment Report by placing X and TikTok under enhanced supervision (X for weak detection of child sexual exploitation and abuse material, and TikTok for weak handling of terrorism content).

Cross-cutting Governance Trends

Institutional Change: Building Capacity Around Emerging Governance Functions

Singapore is building standing institutional capacity around online safety, cybercrime and national AI policy. The Online Safety Commission’s launch was the clearest example, but a Police Cyber Command was also announced for July, and the National AI Council, established in February, now provides strategic direction for the refreshed National AI Strategy.

Another notable  institutional update is the decision to rename the Ministry of Trade and Industry (MTI) to the Ministry of Energy, Trade and Industry (METI), reflecting a growing focus on energy as a strategic priority for economic and digital transformation.

Staged Implementation: Sequencing New Obligations

New regulatory obligations are being progressively rolled out instead of all at once. This phased approach and deliberate sequencing allows the Government to signal intent by first establishing the regulatory framework before bringing obligations into force, giving regulators and affected businesses time to prepare for implementation and to comply with the new requirements.

Several developments during the first half of 2026 highlight this approach. Parliament passed the Bills that became the Health Information Act 2026, the Public Sector (Governance) (Amendment) Act 2026 and the Info-communications Media Development Authority (Amendment) Act 2026. All three resulting Acts had been published by 30 June, but none had commenced. In other areas, implementation timelines were similarly phased. Online Safety Commission commenced its operations in June 2026, initially focusing on five out of the 13 categories of online harm with plans to gradually introduce the remaining categories.

In addition, private organisations are required to cease the use of full or partial NRIC numbers for authentication by 31 December 2026. Following this deadline, the PDPC will enhance enforcement measures starting from 1 January 2027. Meanwhile, it is anticipated that the mandatory cybersecurity requirements for residential routers will increase from Cybersecurity Labelling Scheme Level 1 to Level 2 by the end of 2027.

Regional and International Coordination: Linking Domestic Governance with Interoperability

Singapore remains connected to the global digital economy by keeping its domestic systems interoperable with those of its trading partners, reducing the legal and technical friction of cross-border digital transactions. The EU-Singapore Digital Trade Agreement entered into force, while the EFTA-Singapore Digital Economy Agreement took effect for Singapore and Norway.

On the regional front, ASEAN concluded negotiations on its Digital Economy Framework Agreement, and Singapore moved forward on Peru’s accession to the Digital Economy Partnership Agreement and on the WTO Agreement on E-Commerce.

OCEANS-X and the TradeTrust Readiness Programme performed a related but different function as they put maritime data exchange and electronic trade documents into operational use through infrastructure and adoption support rather than new regulatory duties. The common feature was a preference for building practical systems alongside formal rules.

Moving forward

No single law or measure defines the first half of 2026. What stands out instead is the staging and deployment of the model developed in earlier years. Powers already on the books were used in relation to platforms, websites and online retailers. The Online Safety Commission opened its doors. Three newly enacted laws remained on the statute book awaiting commencement, while further obligations on digital infrastructure, cyber assurance and autonomous vehicles entered the policy pipeline.

Internationally, agreements with the EU and EFTA entered into force, while negotiations advanced through ASEAN and DEPA. These developments continued Singapore’s attempt to combine domestic assurance with external recognition, rather than choosing between openness and control.

 

The views and recommendations expressed in this article, published in September 2026, are solely of the author and do not necessarily reflect the views and position of the Tech for Good Institute.

Share this insight

Discover

How is Tech for Good Institute enabling digital economy and society in Southeast Asia?

Cite this article

Khang, L. H. (2026, September 18). Governance Meets Reality: Singapore’s Evolving Tech Governance. Tech For Good Institute. Retrieved from https://techforgoodinstitute.org/insights/country-spotlights/governance-meets-reality-singapores-evolving-tech-governance/

Keep pace with the digital pulse of Southeast Asia!

Never miss an update or event!

Mouna Aouri

Programme Fellow

Mouna Aouri is an Institute Fellow at the Tech For Good Institute. As a social entrepreneur, impact investor, and engineer, her experience spans over two decades in the MENA region, South East Asia, and Japan. She is founder of Woomentum, a Singapore-based platform dedicated to supporting women entrepreneurs in APAC through skill development and access to growth capital through strategic collaborations with corporate entities, investors and government partners.

Dr Ming Tan

Senior Fellow & Founding Executive Director

Dr Ming Tan is Senior Fellow at the Tech for Good Institute; where she served as founding Executive Director of the non-profit focused on research and policy at the intersection of technology, society and the economy in Southeast Asia. She is concurrently a Senior Fellow at and the Centre for Governance and Sustainability at the National University of Singapore and Advisor to the Founder of the COMO Group, a Singaporean portfolio of lifestyle companies operating in 15 countries worldwide. Ming was previously Managing Director of IPOS International, part of the Intellectual Property Office of Singapore. Prior to joining the public sector, she was Head of Stewardship of the COMO Group.


Ming also serves on the boards of several private companies, Singapore’s National Volunteer and Philanthropy Centre, Singapore Network Information Centre (SGNIC), and on the Digital and Technology Advisory Panel for Esplanade–Theatres on the Bay, Singapore’s national performing arts centre. Her current portfolio spans philanthropy, social impact, sustainability and innovation.