Singapore’s approach to governing artificial intelligence (“AI”) is indeed uniquely Singapore.
We want to embrace the use of AI cutting-edge technologies to boost innovation, productivity and transformation at the organisational, sectoral and national level.
But not without guardrails. These are not hard-coded as legislation. Singapore currently takes the soft-law approach of non-binding frameworks which were developed in collaboration with industry players (ranging from big Tech MNCs such as Google and Microsoft, Singapore local banks to Government research agencies).
As an organisation operating in Singapore that is providing or using AI solutions, what the basic building blocks to put in place an AI governance plan?
Step 1: Is what I am using even AI? What are the different types of AI?
In the Singapore Model AI Governance Framework, AI refers to “a set of technologies that seek to simulate human traits such as knowledge, reasoning, problem solving, perception, learning and planning, and, depending on the AI model, produce an output or decision (such as a prediction, recommendation, and/or classification)”.
If the solution you are using follows deterministic pre-programmed rules rather than leveraging machine learning and deep learning to provide probabilistic output that adapts over time, you are not actually using AI.
Traditional AI: AI models that make predictions by leveraging insights derived from historical data. Typical traditional AI models include logistic regression, decision trees and conditional random fields. Other terms used to describe this include Predictive AI and Discriminative AI.
Generative AI: AI models capable of generating text, images or other media types. They learn the patterns and structure of their input training data and generate new data with similar characteristics. Advances in transformer-based deep neural networks enable generative AI to accept natural language prompts as input, including large language models (LLM).
Agentic AI systems: Systems that can plan across multiple steps to achieve specified objectives, using AI agents. There is no consensus on what defines an agent, but there are certain common features – agents usually possess some degree of independent planning and action taking (e.g. searching the web or creating files) over multiple steps to achieve a user-defined goal.
Step 2: What is the AI system lifecycle and who is involved?

- Development stage:
- Planning and design (define objectives and consider user needs, checkpoints for human oversight and harm matrix)
- Data collection and preparation (obtain representative, comprehensive and accurate data and convert to usable data)
- Model development (develop AI models within AI system addressing needs such security and explainability/transparency concerns)
- Pre-Deployment stage:
- Model-testing (test for functionality, safety and security addressing bias concerns)
- Evaluation (benchmarking test, red teaming and industry-specific assessments)
- Deployment stage:
- Deployment (gradual deployment to control risk exposure)
- Post-Deployment stage:
- Monitoring and maintenance (continuous monitoring and logging of AI system’s output and behaviour with incident reporting processes).
Key Players in the ecosystem (referred to in Singapore’s Model AI Governance Framework):
AI Solution Providers: Entities or persons who develop AI solutions or application systems that make use of AI technology.
Organisations: Companies or other entities that adopt or deploy AI solutions in their operations.
Individuals/Customers: Persons to whom organisations intend to supply AI products and/or services, or persons who have already purchased the AI products and/or services.
Step 3: What is the current legal position on providing or using AI systems in Singapore?
There is currently no stand-alone legislation that is specific to provision/use of AI solutions and there are three voluntary and non-binding frameworks giving guidance to developers and deployers of AI solutions.
The Model AI Governance Framework (2nd Edition, 2020) remains the foundational baseline for all AI systems including “Traditional AI,” while the Model AI Governance Framework for Generative AI (2024) and the Framework for Agentic AI (2026) act as specialized extensions.
Sector specific guidelines (such as for finance, healthcare and legal sectors) have been issued and more are expected to be issued as AI is increasing deployed in various sectors.
Existing laws, such as laws on data protection, confidence, cybersecurity and computer misuse and intellectual property continue to apply.
Step 4: What are the fundamental principles for AI Governance?
AI-assisted decision-making should be explainable, transparent and fair; and AI systems should be human-centric and safe.
To promote responsible AI use, measures should be put in place over four key areas:
- Internal Governance Structures and Measures: Establish clear roles and responsibilities within the organisation, implement SOPs to monitor and manage risks and conduct training for personnel.
- Determining the level of human involvement in AI-augmented decision-making: Determining acceptable risks and identify an appropriate level of human involvement (human-in-the-loop (HITL), human-over-the-loop (HOTL) or human-out-of-the-loop (HOOTL)) in AI-augmented decision-making. Minimise risk of harm to individuals and implement controls that manage risk and mitigate bias.
- Operations Management & Data Accountability: Adopting responsible measures in managing AI systems, particularly regarding data management, development of explainability features, model maintenance, and bias minimisation.
- Stakeholder Interaction and Communication: Establish strategies for communicating with stakeholders and managing relationships to ensure transparency, trust, and accountability in the use of AI systems.
Step 5: Considerations for Generative AI
Use of generative AI has reinforced some of the same Traditional AI risks (such as bias, misuse, lack of explainability) and introduced new ones (such as hallucination, copyright infringement, value alignment). In addition to the baseline measures, for generative AI consider:
- Publishing transparency disclosures covering training data, safety measures, limitations and intended use to the extent appropriate to build trust with customers.
- Utilising privacy enhancing tools (PETs) to ensure compliance with data protection and confidentiality obligations as well as non-infringement of intellectual property rights.
- Implementing common safety practices and fine-tuning techniques such as Reinforcement Learning from Human Feedback (RLHF), input/output filters, Retrieval- Augmented Generation (RAG) techniques, forward alignment and backward alignment validation testing (as appropriate) to reduce harmful outputs and hallucinations.
Step 6: Considerations for Agentic AI
Agentic AI goes beyond traditional and generative AI – AI agents can reason and take actions to complete tasks on behalf of users (such as ordering supplies for inventories or making a payment). This means agentic AI may access sensitive data and make inherent changes to their environment and interact with third-parties.
This introduces potential new risks, such as erroneous or unauthorised actions, biased or unfair actions, data breaches or disruption to connected systems. In addition to the baseline measures, for agentic AI consider:
- Determine if particular work tasks or decisions are appropriate for agentic AI deployment by considering agent-specific factors (such as nature and level of impact from any errors, data sensitivity and autonomy level) and perform risk assessments at design stage.
- Apply limits on AI agents – access controls to ensure AI agent only has access to tools and data strictly necessary for the task. Define and enforce human-in-the-loop checkpoints, especially for high-stakes or irreversible actions.
- Assign unique agent identities tied to accountable human supervisors or departments and a robust permissions framework.
- Establish contractual accountability/liability provisions with third-party agent vendors covering security, data protection and performance guarantees.
In closing
While these model governance frameworks are non-binding, demonstrated adoption of these principles and best practices would establish trust and credibility of your work processes and services, internally within your organisation and externally with your customers.
The information given in this write-up is for guidance only and does not constitute legal or professional advice. SoYang Advisory assumes no responsibility for such information contained in this write-up and disclaims all liability in respect of such information.
© 2026 SoYang Advisory Pte. Ltd. No part of this write-up may be published, distributed, extracted, re-utilised, or reproduced in any material form without our express consent.