Singapore's Model AI Governance Framework
9 min read · updated August 11, 2026
Singapore governs AI with published frameworks and a testing toolkit rather than an AI statute. That is a real strategy rather than an absence of one, and the frameworks matter commercially in a way that the word “voluntary” understates—but they are not what binds you.
Which document is which
Four artefacts circulate under similar names and conflating them produces confused compliance work.
- The Model AI Governance Framework, first published in January 2019 by the Personal Data Protection Commission and released in a second edition in January 2020. This is the original, aimed at traditional AI decision systems. The PDPC publishes it here.
- The Implementation and Self-Assessment Guide for Organisations (ISAGO) and a compendium of use cases, published alongside the second edition as the operational companions.
- The Model AI Governance Framework for Generative AI, published in May 2024 by IMDA and the AI Verify Foundation. This is a separate document, not a revision of the first.
- AI Verify, an open-source testing framework and toolkit released in 2022 and stewarded by the AI Verify Foundation, which turns parts of the framework into runnable technical tests plus a process checklist.
The direction of travel across all four is the same: describe what good governance looks like, make it testable, and let procurement and market pressure do the enforcement that a statute would otherwise do.
The four areas of the Model Framework
The second edition organises everything into four areas, and the ordering is itself an argument—governance first, because the rest is unenforceable inside an organisation without it.
- Internal governance structures and measures. Who is accountable, which existing committee owns AI risk, what the escalation path is, and how risk management and internal controls extend to AI.
- Determining the level of human involvement in AI-augmented decision-making. The framework’s most distinctive contribution; see below.
- Operations management. Data lineage and quality, model selection, training and testing, explainability, robustness, reproducibility, and monitoring after deployment.
- Stakeholder interaction and communication. Disclosure to individuals, channels for feedback and for querying a decision, and the design of the interaction itself.
The human involvement matrix
The framework asks organisations to decide, deliberately and in advance, how much human involvement a given decision needs, and gives three designs:
- Human-in-the-loop. A person retains full control and the model recommends. The decision does not happen without the human acting.
- Human-out-of-the-loop. The system decides with no human override in the flow.
- Human-over-the-loop. The system decides and a person monitors, with the ability to intervene, adjust parameters or stop the system during operation.
The choice is made using a matrix of the probability of harm against the severity of harm. High probability and high severity pushes towards human-in-the-loop; low on both permits human-out-of-the-loop. It is a simple device and a genuinely useful one, because it converts an argument—“should there be a human?”—into a documented decision with a stated reason, which is exactly the artefact a regulator or a buyer asks for. The European equivalent obligation is harder-edged but the design question is identical; see the AI Act’s human oversight requirement.
The generative AI framework
The 2024 generative AI framework works across nine dimensions: accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research and development, and AI for public good. Its framing is that generative AI breaks the assumption underlying the original framework—that the deploying organisation understands and controls the model it is using—and that responsibility therefore has to be allocated along a supply chain rather than assigned to one party.
Two dimensions are more concrete than the rest and are the ones worth reading in full. Incident reporting asks for a defined internal process, severity criteria and a reporting route before an incident happens rather than after. Content provenance points at technical marking of generated content, aligning Singapore with the direction the EU, China and Korea have each taken by different routes.
What actually binds in Singapore
The frameworks impose no legal obligation and carry no penalty. What binds is the Personal Data Protection Act 2012, as amended, and sectoral regulation.
The PDPA route most relevant to AI runs through its exceptions. The business improvement exception permits use of personal data without consent for defined internal purposes including improving or developing goods and services, subject to conditions, and the research exception permits use for research subject to its own conditions. The PDPC published Advisory Guidelines in March 2024 on the use of personal data in AI recommendation and decision systems, which set out how it reads those exceptions in an AI context and what it expects by way of accountability, including disclosure in a policy of the use of personal data in such systems. Advisory guidelines are not law, but they are the regulator’s stated interpretation of law that is, and departing from them is a position you have to be able to defend.
Copyright is separate again: Singapore’s Copyright Act 2021 contains a computational data analysis exception that is one of the more permissive text and data mining provisions anywhere, discussed in the computational data analysis exception. Financial services carry the Monetary Authority of Singapore’s FEAT principles and the Veritas work built on them, which for a regulated institution function much closer to expectations than to suggestions.
So the accurate account of “voluntary” in Singapore is this: no regulator will fine you for departing from the Model Framework, and a government or enterprise procurement may well decline to buy from you if you cannot describe your governance in its terms, while the PDPA underneath it is fully enforceable. Alignment with the framework is a commercial asset; compliance with the PDPA is not optional.