Singapore and Japan are frequently described as the two leading examples of a "soft law" approach to AI governance in the Asia-Pacific region. Neither country has enacted a comprehensive, binding AI-specific statute of the kind the European Union adopted with the EU AI Act. Both instead rely primarily on voluntary guidance to shape how organisations build and deploy AI systems, while leaving enforceable obligations to general and sectoral laws that were mostly not written with AI in mind. That surface-level similarity, however, conceals two structurally different systems. Singapore's model is built around administrative frameworks issued by a digital economy regulator and layered over data protection law. Japan's model is built around a dedicated promotion statute layered over data protection and copyright law, with a separate voluntary guideline instrument doing the day-to-day normative work. For a multinational organisation operating in both markets, understanding that structural difference matters more than the shared "soft law" label suggests.
Philosophy and structure
Singapore's approach has been pro-innovation and framework-driven since its earliest AI-specific publication. The Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC) jointly issued the first edition of the Model AI Governance Framework in January 2019 and a second edition in January 2020, offering voluntary, cross-sector guidance organised around four pillars: internal governance, risk management, operations management, and stakeholder communication, built on the principles that AI decision-making should be explainable, transparent and fair, and that systems should remain human-centric (PDPC). IMDA has continued to lead the framework's subsequent iterations. In May 2022, IMDA and the PDPC launched AI Verify, a voluntary testing framework and open-source toolkit that lets organisations demonstrate responsible AI implementation through technical tests and process checks against internationally recognised principles, later stewarded by the AI Verify Foundation, established in 2023 (AI Verify Foundation). In May 2024, IMDA and the AI Verify Foundation published the Model AI Governance Framework for Generative AI, extending the earlier framework's principles to foundation models across dimensions including accountability, data quality, content provenance, incident reporting, and testing and assurance (IMDA and AI Verify Foundation). Most recently, IMDA launched a Model AI Governance Framework for Agentic AI on 22 January 2026, described as the first governance framework specifically addressing AI agents capable of autonomous planning and action, and updated it in May 2026 with additional case studies covering multi-agent systems and third-party agents (IMDA). Every one of these instruments is explicitly voluntary. None carries penalties for non-adoption in itself.
Japan's structure differs in a subtle but consequential way. Rather than relying solely on administrative frameworks, Japan enacted the AI Promotion Act (Act No. 53 of 2025), giving its national AI policy a statutory footing. The Act is nonetheless a promotion and framework law: it contains no penalties, no prohibitions, and no mandatory conformity assessment regime. The instrument that actually functions as the day-to-day standard of care for organisations is the voluntary AI Guidelines for Business, issued jointly by the Ministry of Economy, Trade and Industry (METI) and the Ministry of Internal Affairs and Communications (MIC), now at version 1.2 as of 31 March 2026. Strategic direction sits with the Cabinet-level, Prime Minister-chaired AI Strategy Headquarters, which produces the AI Basic Plan, a coordination and planning instrument rather than enforceable rules, with a first plan issued in December 2025 and a revision in July 2026. In other words, Japan has chosen to give its soft-law posture a legislative shell, while the substantive expectations still live in non-binding guidance, much as they do in Singapore. Both governments have converged on the same basic architecture, voluntary AI-specific norms sitting above binding general law, even though they arrived there by different legislative routes.
The binding layer versus the voluntary layer
In Singapore, nothing in the Model AI Governance Framework, AI Verify, or the Agentic AI framework is directly enforceable. What binds organisations is the Personal Data Protection Act (PDPA), administered by the PDPC within IMDA. The PDPA governs consent, notification and purpose limitation for personal data, and its penalty regime is substantial: financial penalties for organisations can reach the higher of a fixed cap or up to 10 percent of the organisation's annual turnover in Singapore. Recent enforcement illustrates how the PDPC weighs that framework's other factors, rather than the turnover ceiling itself: in October 2025, the PDPC imposed a S$315,000 penalty on Marina Bay Sands over a breach in which the personal data of 665,495 patrons was accessed and exfiltrated in October 2023, after a software migration error in March 2023 left an API exposed for roughly six months. The stolen data was later found for sale online, and the PDPC's October 2025 decision addressed that earlier 2023 breach rather than a fresh 2025 incident (PDPC). AI-specific guidance from the PDPC operates as an interpretive layer on top of that binding statute rather than as an independent source of obligation. The PDPC's Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, published in March 2024, and its proposed Advisory Guidelines on Use of Personal Data in Generative AI, opened for public consultation on 2 June 2026 and closed on 1 July 2026, both explain how the existing PDPA applies to AI use cases rather than creating new statutory duties (PDPC). IMDA itself has been explicit that compliance with the Agentic AI framework is voluntary, while noting that organisations remain legally accountable for their agents' behaviour and actions under existing law, a formulation that captures the entire Singapore model in miniature.
In Japan, the binding layer is anchored principally in the Act on the Protection of Personal Information (APPI), enforced by the Personal Information Protection Commission (PPC), and in the Copyright Act. The Copyright Act is a particularly distinctive feature of Japan's binding layer for AI: Article 30-4, introduced in a 2018 amendment, permits the exploitation of copyrighted works "to the extent considered necessary" for purposes that do not involve a person enjoying the thoughts or sentiments expressed in the work, a provision that Japanese government guidance has since indicated extends to the training of generative AI models, subject to the qualification that such use must not unreasonably prejudice the interests of the copyright owner (Agency for Cultural Affairs). That is a materially different starting position from Singapore's PDPA, which contains no comparable AI-training carve-out and instead relies on general exceptions such as the "publicly available" basis that the PDPC's 2026 proposed generative AI guidelines discuss for web-scraped training data. The AI Guidelines for Business, like Singapore's Model AI Governance Framework, remains voluntary, and the AI Promotion Act deliberately withholds penalties and mandatory conformity assessment. The result is that both jurisdictions place their AI-specific instruments in the same non-binding category, but the underlying binding statutes they sit on top of, PDPA on one side, APPI and the Copyright Act on the other, impose different obligations, use different legal tests, and are enforced by different regulators.
Finance: where soft law meets supervision
The financial sector is the clearest illustration of how each country layers sector-specific oversight onto its general model, and of how supervisory guidance occupies a middle ground between pure voluntarism and hard law.
In Singapore, the Monetary Authority of Singapore (MAS) has been active in this space longer than most global peers. Its Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the use of AI and data analytics, published on 12 November 2018, remain the long-standing reference point for AI use in finance and were later operationalised through the industry-led Veritas initiative, which has produced quantitative fairness, ethics, accountability and transparency assessment methodologies for use cases such as credit risk scoring, customer marketing, predictive underwriting, and fraud detection (MAS). MAS's Technology Risk Management (TRM) Guidelines, first issued in 2001 and last revised in January 2021, sit alongside FEAT as supervisory expectations rather than legally binding rules, though MAS issued a consultation paper on 10 June 2026 proposing to move a substantial part of that content into a Technology Risk Management Notice, a legally binding instrument, across areas including IT asset management, incident management and continuous security monitoring (MAS). Most significantly for AI specifically, MAS published a consultation paper on proposed Guidelines on AI Risk Management on 13 November 2025, covering AI governance architecture, key risk management systems and processes, AI lifecycle controls, and institutional capability requirements, with the consultation closing on 31 January 2026 (MAS). As of this writing, those Guidelines have not been finalised; MAS has proposed a twelve-month transition period once they are issued. Like the TRM Guidelines, they will take the legal form of supervisory guidelines rather than a binding Notice, meaning non-compliance does not itself trigger enforcement but factors into MAS's supervisory assessment of an institution, a distinctly Singaporean blend of formally voluntary content backed by real supervisory weight.
Japan's Financial Services Agency (FSA) has taken a more deliberately exploratory posture to date. Rather than issuing guidelines with defined compliance expectations, the FSA published an AI Discussion Paper in March 2025 (FSA), followed by a version 1.1 in March 2026 (FSA), each framed explicitly as a basis for dialogue with financial institutions rather than a set of supervisory rules, and ran an AI Public-Private Forum from June to December 2025 to gather industry input on AI risk management and governance practices. The FSA's stated strategic priorities for the 2025 to 2026 period emphasise model risk control, data quality assurance and building specialised in-house expertise as areas for continued dialogue rather than codified requirement (FSA). In both countries, then, financial regulators have added an AI-specific layer on top of pre-existing, binding sectoral regimes, banking, insurance and securities law in Singapore, and Japan's equivalent financial regulatory statutes, but Singapore's regulator has moved further and faster toward defined supervisory expectations, while Japan's has so far prioritised structured consultation over prescriptive guidance.
What this means for a multinational organisation
The practical consequence for any organisation operating AI systems in both Singapore and Japan is that governance built to satisfy one jurisdiction does not automatically satisfy the other, even though both jurisdictions look similar from a distance as "voluntary framework" countries. The binding layers are different statutes administered by different regulators with different substantive requirements. A data governance program built around PDPA consent and notification obligations will not, without modification, satisfy APPI's requirements administered by the Personal Information Protection Commission, and a training-data legal basis that relies on Japan's Article 30-4 text and data mining exception has no direct equivalent in Singapore's PDPA, which instead requires organisations to work through exceptions such as the "publicly available" basis or contractual and consent mechanisms. Copyright risk in particular needs jurisdiction-specific analysis: Japan's statutory TDM exception for AI training is comparatively permissive by international standards, and Singapore's copyright treatment of AI training data does not track it. The voluntary layers diverge as well. Singapore has built a family of discrete, purpose-specific instruments, the Model AI Governance Framework for general AI governance structures, AI Verify for testable technical and process evidence, and a separate Agentic AI framework for autonomous systems, each with its own scope and update cycle. Japan has consolidated its day-to-day expectations into a single, periodically revised document, the AI Guidelines for Business, sitting underneath a statute whose primary function is coordination rather than obligation. An organisation that has run its Singapore deployment through AI Verify's testing framework has produced evidence relevant to Singapore's expectations, but that evidence package does not map cleanly onto what Japan's AI Guidelines for Business asks for, and vice versa.
In the financial sector specifically, an institution operating under both MAS and the FSA should expect materially different supervisory postures in the near term: MAS's FEAT principles, TRM Guidelines and the AI Risk Management Guidelines, once finalised, will likely be treated as concrete supervisory expectations factored into examinations, while the FSA's AI Discussion Paper process indicates a regulator still in a dialogue phase, with its own model risk and explainability expectations, reportedly including emerging expectations around explainability for AI-driven credit decisions, developing through engagement rather than published guidelines. Treating the two as interchangeable risks either under-preparing for Singapore's more codified supervisory expectations or misjudging the direction Japan's dialogue-based approach may take.
The practical implication is that multinational organisations should build a governance program with two layers of its own: a substantive core, addressing fairness, transparency, accountability, human oversight, testing and incident response, that can be reused across jurisdictions because the underlying principles are genuinely convergent, and a jurisdiction-specific compliance layer mapped separately to each binding statute, each regulator's current guidance, and each sector regulator's supervisory posture. Assuming that satisfying Singapore's voluntary frameworks automatically satisfies Japan's, or the reverse, is the most common and most consequential governance error organisations make when they treat "APAC soft law" as a single regulatory environment rather than two distinct ones that happen to share a philosophy.
The bottom line
Singapore and Japan have each concluded that a comprehensive, binding AI-specific statute is premature or undesirable, and both have chosen to govern AI primarily through voluntary guidance layered over pre-existing general and sectoral law. That shared philosophy, however, produces two governance environments with different legal architecture, different binding statutes, different regulators, and, in the financial sector, different supervisory postures. Neither model is more or less developed than the other; they reflect different institutional traditions and different sequencing choices, Singapore's administrative frameworks built up over seven years of iteration since 2019, Japan's newer promotion statute paired with a business guideline document still being refined. For organisations operating across both markets, the practical task is not to pick which model is "ahead," but to map governance obligations separately against each jurisdiction's actual binding law and current guidance, rather than assuming that compliance in one soft-law jurisdiction travels automatically to the other.
Related articles
- AI Verify: Inside Singapore's AI Governance Testing Framework and Toolkit
- Singapore's PDPA and AI Systems: The Binding Layer Behind the Voluntary Frameworks
- Japan's AI Promotion Act vs the EU AI Act: A Comparison of Two Governance Models
- Japan's AI Promotion Act 2025: The World's Most Innovation-Friendly AI Law
- Singapore AI Policy: The Full Governance Landscape
- Japan AI Policy: The Full Governance Landscape