Singapore governs artificial intelligence through a pro-innovation, framework-driven model rather than a standalone AI Act: influential voluntary frameworks and a testing toolkit led by IMDA and the AI Verify Foundation, sitting on top of binding law such as the Personal Data Protection Act and sector regulators like the Monetary Authority of Singapore. This page sets out the instruments, the dates, and which ones are binding versus guidance, with links to the primary sources for each.
Last reviewed: 21 July 2026 · A factual snapshot; AI policy is evolving, so confirm against the primary sources linked below
Singapore has deliberately chosen not to enact an AI-specific statute. Instead it governs AI in three layers: a binding layer of existing law, principally the Personal Data Protection Act (PDPA), applied to AI the same way it applies to any other data processing; a sector layer, most visibly the Monetary Authority of Singapore and its FEAT principles for financial services; and a voluntary framework layer led by IMDA and the AI Verify Foundation.
That framework layer is where Singapore has been most influential internationally: the Model AI Governance Framework (first published in 2019 and revised in 2020), its 2024 edition for generative AI, and the AI Verify testing toolkit. These are guidance and tools rather than law, but they are widely referenced and, together with the PDPC’s guidance on personal data in AI, they set the practical expectations an organisation operating in Singapore is measured against.
Singapore published one of Asia’s first national AI governance frameworks, developed by the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC). It is a voluntary, principles-based guide for deploying AI responsibly, not a law.
A revised second edition broadened and deepened the guidance, cementing Singapore’s pro-innovation, framework-driven approach: shape good practice through voluntary frameworks and tools rather than a prescriptive AI statute.
IMDA introduced AI Verify, an AI governance testing framework and software toolkit, later stewarded by the not-for-profit AI Verify Foundation. It lets organisations test their AI systems against internationally aligned governance principles and produce evidence of responsible practice.
Singapore refreshed its national blueprint (NAIS 2.0), building on the 2019 strategy and framing AI as a force for good across the economy and society, with twin goals of excellence and empowerment.
The PDPC issued Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, clarifying how the Personal Data Protection Act (PDPA) applies when organisations use personal data to develop, train and deploy such systems, including relevant consent exceptions and best practices. The guidelines are advisory rather than a new statute.
IMDA and the AI Verify Foundation published a generative-AI edition of the Model AI Governance Framework, addressing risks specific to large language models and generative systems: hallucinations, bias, intellectual property, content provenance, cybersecurity and systemic risk, across nine dimensions.
The distinction that matters most for compliance is whether an instrument carries legal force or is guidance an organisation is encouraged to follow. The table below sorts the main instruments accordingly.
| Instrument | Status | Applies to / owner |
|---|---|---|
| Personal Data Protection Act (PDPA) | Binding | Any organisation using personal data, including in AI (enforced by the PDPC) |
| MAS guidance for AI in financial services (FEAT principles, Veritas) | Supervisory guidance | Financial institutions regulated by the Monetary Authority of Singapore |
| Model AI Governance Framework (2019, revised 2020) | Voluntary framework | All organisations (IMDA and PDPC) |
| Model AI Governance Framework for Generative AI (May 2024) | Voluntary framework | Providers and deployers of generative AI (IMDA and the AI Verify Foundation) |
| AI Verify testing framework and toolkit | Voluntary testing tool | Organisations testing and evidencing AI governance (AI Verify Foundation) |
| PDPC Advisory Guidelines on personal data in AI (Mar 2024) | Guidance on the PDPA | Organisations using personal data in AI recommendation and decision systems |
| National AI Strategy 2.0 (Dec 2023) | National strategy, not a rule | Whole-of-government direction, not an obligation on firms |
For the financial-services expectations specifically, see our deep dive on the MAS FEAT principles and the PDPC profile.
Two practical points follow. First, the obligations that can actually be enforced against an organisation today come from the laws and sector regulators that already apply to it, above all the PDPA for personal data and the MAS expectations for financial institutions, applied to its use of AI. Second, the national AI-specific layer is, by design, voluntary framework and tooling: organisations are strongly encouraged to align to the Model AI Governance Framework and to test with AI Verify, but those are not, in themselves, law.
Because much of the Singapore layer is voluntary, the weight of day-to-day AI governance sits with each organisation’s own framework and controls. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model, which is useful precisely because so much of the national guidance is voluntary.
No standalone AI Act. Singapore takes a pro-innovation, framework-driven approach: AI is governed by existing law such as the Personal Data Protection Act, by sector regulators such as the Monetary Authority of Singapore for financial services, and by voluntary frameworks and tools led by IMDA and the AI Verify Foundation, rather than by a single AI statute.
There is no single AI regulator. IMDA and its not-for-profit subsidiary the AI Verify Foundation lead the national frameworks and the AI Verify testing toolkit; the PDPC administers the Personal Data Protection Act and has issued guidance on using personal data in AI; and the Monetary Authority of Singapore sets expectations for AI in financial services. The Smart Nation effort sets overall national strategy.
No. Both the original Model AI Governance Framework (2019, revised 2020) and the 2024 edition for generative AI are voluntary, principles-based guidance. They are influential and widely referenced, but they do not carry legal force on their own; binding obligations come from laws such as the PDPA and from sector regulators.
The Personal Data Protection Act is binding and applies in full to personal data used in AI. On 1 March 2024 the PDPC issued Advisory Guidelines clarifying how the PDPA applies to AI recommendation and decision systems, covering matters such as consent and relevant exceptions, data protection impact assessments, minimisation and transparency. The guidelines are advisory, but the underlying PDPA obligations are enforceable.
AI Verify is Singapore’s AI governance testing framework and software toolkit, stewarded by the AI Verify Foundation. It lets an organisation run technical tests and process checks against internationally aligned governance principles and generate a report, so it can test and demonstrate responsible AI practice. Using it is voluntary.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, useful precisely because much of Singapore’s national guidance is voluntary.
This page is general information describing the state of Singapore AI policy as at 21 July 2026, not legal or compliance advice. Policy and regulatory positions change; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.