What AI Verify Is
AI Verify is Singapore's AI governance testing framework and accompanying software toolkit. It was launched in May 2022 by the Infocomm Media Development Authority (IMDA) together with the Personal Data Protection Commission (PDPC), and Singapore's government has described it as the world's first AI governance testing framework and toolkit of its kind. Rather than creating new legal obligations, AI Verify gives organisations a structured, voluntary way to test an AI system against a defined set of governance principles and to produce documentary and technical evidence that the system was built and deployed responsibly. (PDPC, May 2022)
The toolkit combines two kinds of checks. Process checks ask an organisation to produce documentary evidence, such as internal policies, risk assessments and records of testing, that maps to a defined governance outcome. Technical tests run automated evaluations against the AI system itself, for the subset of principles that can be measured quantitatively. This dual structure is intended to bridge the gap between an organisation's internal governance claims and independently verifiable evidence. (AI Verify Foundation)
From an IMDA Pilot to an Independent Foundation
AI Verify began as an IMDA led pilot in 2022, tested and refined with feedback from around ten companies across sectors, including AWS, DBS Bank, Google, Meta, Microsoft, Singapore Airlines, NCS, Standard Chartered Bank, UCARE.AI and X0PA.AI. (Ministry of Digital Development and Information) The toolkit then opened to a wider international pilot that separate industry reporting described as drawing interest from more than fifty organisations.
In June 2023, IMDA established the AI Verify Foundation, a not-for-profit entity that operates as a wholly owned subsidiary of IMDA, to steward the toolkit's continued development as an open source, internationally contributed project rather than a purely government run one. The Foundation's stated mission centres on harnessing global open source collaboration to develop AI testing frameworks, codebase, standards and best practices, and on providing a neutral platform where industry, researchers and policymakers can work on the toolkit together. (AI Verify Foundation)
Its governance follows a tiered membership model. A small group of premier members, originally comprising IMDA, Aicadium (Temasek's AI centre of excellence), IBM, Microsoft, Google, Red Hat and Salesforce, guides the strategic direction and roadmap of AI Verify. A larger tier of general members, which numbered more than sixty organisations at launch, including Adobe, DBS, Meta, SenseTime and Singapore Airlines, contributes code, testing feedback and use cases, and has continued to expand since, with additional organisations such as Zypero Intellect joining in 2026, though the Foundation has not published a precise updated membership total. (Microsoft News Center) (GlobeNewswire, July 2026)
Available public reporting does not show the AI Verify Foundation as a project of the Linux Foundation or a comparable umbrella consortium. It is best understood as a Singapore government backed but operationally independent non-profit, with its own open source repositories and its own membership base of corporate and institutional participants, which separately aligns its technical output with international reference frameworks such as the United States' NIST AI Risk Management Framework, discussed further below.
What AI Verify Actually Tests
The AI Verify testing framework organises its checks around eleven AI governance principles that the Foundation says are consistent with internationally recognised frameworks from bodies such as the OECD and the European Union, as well as with Singapore's own Model AI Governance Framework: transparency, explainability, repeatability and reproducibility, safety, security, robustness, fairness, data governance, accountability, human agency and oversight, and inclusive growth together with societal and environmental well-being. (AI Verify Foundation)
Not every principle lends itself to the same kind of check. Some, such as fairness or robustness in a conventional machine learning model, can be tested with automated technical tests that probe the system directly, for example by measuring performance across demographic subgroups or by running adversarial inputs against a model. Others, such as accountability or human oversight, are process principles, assessed through process checks that require documentary evidence of governance structures, escalation paths and internal sign off procedures rather than a direct technical measurement. Organisations self assess against the applicable mix of process checks and technical tests for their system type, generating a report that can be shared with regulators, customers or business partners as evidence of due diligence. (AI Verify Foundation)
In May 2025, IMDA and the AI Verify Foundation released an updated version of the testing framework, extending the same eleven principle structure to generative AI systems, alongside a published crosswalk mapping the enhanced framework to the United States' NIST AI Risk Management Framework Generative AI Profile, a step both sides framed as reaffirming alignment between their respective approaches to AI governance. (The Legal Wire)
Extending the Toolkit: Project Moonshot and the Global AI Assurance Sandbox
Two further initiatives sit alongside the core testing framework. Project Moonshot, launched on 31 May 2024 and developed with industry partners including DataRobot, IBM, Singtel and Temasek, is an open source large language model evaluation toolkit that combines benchmarking and red teaming. It tests LLM based applications against four risk areas identified in IMDA's LLM starter kit for safety testing, namely hallucination, undesirable content, data disclosure and vulnerability to adversarial prompts, drawing on more than one hundred benchmark datasets and offering both a web interface and a command line tool. (AI Verify Foundation) (DataRobot)
The Global AI Assurance Sandbox, piloted from February 2025 and formally launched on 7 July 2025, extends AI Verify's technical testing approach into a matching service that pairs organisations building or deploying generative AI applications with specialist third party testing vendors, drawn from a global panel of specialist testing vendors that has included firms such as PwC. The pilot phase paired seventeen AI deployers with sixteen specialist technical testing vendors, spanning Singapore and eight other geographies across ten industries, and focused on risks including hallucination, undesirable content, data disclosure, adversarial prompt vulnerability and broader use case concerns such as regulatory compliance and human oversight. (Digital Policy Alert)
How AI Verify Relates to the Model AI Governance Framework
AI Verify is best understood as the operational, testable counterpart to Singapore's Model AI Governance Framework, rather than a separate or competing instrument. IMDA and PDPC first issued the Model AI Governance Framework in 2019, with a second edition in 2020, as voluntary, cross sector guidance covering internal governance structures, human oversight, risk management and transparency in communication with users, with organisations expected to calibrate the depth of these measures to the risk posed by a given AI use case. (PDPC)
Where the Model AI Governance Framework sets out what responsible practice should look like, AI Verify supplies a way to demonstrate, through process checks and technical tests rather than a bare assertion, that a specific AI system actually meets that standard. IMDA has extended the same pairing of governance framework and testable toolkit as AI use cases have evolved. A Model AI Governance Framework for Generative AI was issued on 30 May 2024, addressing generative AI specific concerns such as hallucination, intellectual property, content provenance and cybersecurity, and a Model AI Governance Framework for Agentic AI followed on 22 January 2026, addressing AI agents capable of autonomous planning and action through four dimensions: bounding risk upfront, keeping humans meaningfully accountable, implementing technical controls, and enabling end user responsibility. (AI Verify Foundation) (IMDA)
As of mid-2026, the testing framework's technical tests remain built around traditional and generative AI systems. IMDA has described the agentic framework as a living document and has been gathering industry feedback and case studies to refine it, which suggests that dedicated technical tests for agentic AI capabilities are still less developed than the process level guidance already published for that category.
Who Uses It, and How Adoption Has Grown
Adoption has broadened in stages rather than through a single mandate, consistent with the voluntary character of Singapore's overall approach to AI governance. The 2022 pilot involved around ten companies testing the framework directly, with the subsequent international pilot drawing interest from more than fifty organisations according to separate industry reporting. When the AI Verify Foundation was established in June 2023, it launched with seven premier members and more than sixty general members; general membership has continued to grow since, spanning cloud providers, financial institutions, consulting firms, AI vendors and research institutions, though the Foundation has not published a precise updated total. (AI Verify Foundation)
Because AI Verify remains voluntary, usage is best read as an indicator of market interest and procurement influence rather than compliance coverage. IMDA and the Foundation continue to run new cohorts through the Global AI Assurance Sandbox and to draw contributors to Project Moonshot's open source repositories, even though the toolkit itself creates no legal obligation to use it.
AI Verify Compared to Other Testing and Assurance Approaches
AI Verify sits closer in character to the United States' NIST AI Risk Management Framework than to the European Union's AI Act conformity assessment regime, and the comparison illustrates two different points on the same spectrum rather than competing claims to rigour. NIST released AI RMF 1.0 in January 2023 as voluntary, non sector specific guidance organised around four functions, Govern, Map, Measure and Manage, with no certification process and no penalty attached to non-use. (NIST) AI Verify and NIST AI RMF are directly linked through IMDA's published crosswalk of the AI Verify framework to the NIST Generative AI Profile, reflecting deliberate technical alignment between the two voluntary regimes.
The EU AI Act's conformity assessment regime is structurally different in kind, not only in detail. Under Article 43 of the Act, providers of high risk AI systems must complete a conformity assessment before the system is placed on the EU market, a mandatory legal gate rather than a voluntary reputational exercise. Depending on the category of high risk system, this can require an internal control assessment against harmonised standards or, for certain systems such as those in the biometrics category listed in Annex III, involvement of an independent notified body, backed by CE marking, registration obligations and a statutory penalty regime for non-compliance. (EU Artificial Intelligence Act)
The practical distinction is therefore not about which regime tests more rigorously in the abstract, but about legal force and consequence. AI Verify is a self assessment toolkit that an organisation anywhere in the world can use to generate evidence of responsible AI practice, with no obligation to use it and no penalty for choosing not to. The EU AI Act's conformity assessment is a mandatory precondition for lawfully placing certain AI systems on the EU market, enforced through market surveillance and financial penalties. An organisation operating in both Singapore and the EU could reasonably use AI Verify as part of its internal testing and governance evidence base while still needing to complete a separate, legally mandatory EU conformity assessment for any high risk system it places on the EU market, since satisfying one does not substitute for the other.
Singapore's own ground truth is unchanged by any of this. There is no domestic statute compelling the use of AI Verify or the Model AI Governance Framework, and the binding backstop for organisations operating in Singapore remains general law, principally the Personal Data Protection Act enforced by the PDPC, rather than the testing toolkit itself. AI Verify's role is to make Singapore's voluntary, framework driven approach to AI governance operationally testable, not to replace or substitute for the country's binding legal obligations.
Related articles
- AI Verify: Inside Singapore's AI Governance Testing Framework and Toolkit
- Singapore vs Japan: Two Models of AI Governance Compared
- Singapore's AI Governance Framework: What Businesses in Asia-Pacific Need to Know
- MAS and AI in Singapore Financial Services: FEAT Principles, Veritas, and Regulatory Expectations
- Singapore AI Policy: The Full Governance Landscape