Singapore stack
Singapore governs AI without an AI law.
Ten instruments, four agencies, one map.
519 NODES · 824 RELATIONS · 27 INSTRUMENTS · 9 AGENCIES · 61 BINDING · 17 BINDING SECTORAL · VERIFIED 2026-08-17
The short answer
Singapore has no AI statute. IMDA, PDPC, MAS and CSA govern AI through ten instruments. This map shows every one, from the binding PDPA to voluntary frameworks, with sources and verification dates.
Legal force, how to read
Binding61
Binding law. It applies to everyone in scope, whether or not anyone points at it.
Binding, sectoral17
Binding, but only for a defined population: one regulated sector, or the federal government and the vendors it buys from.
Supervisory expectation21
Not law. It is what your supervisor examines you against, which is not the same as optional.
Consultation44
Proposed, not final. Read it, plan for it, and do not treat it as settled.
Guidance358
Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
Standard14
A voluntary standard. It becomes an obligation the moment a contract or a regulator cites it.
Emerging4
Not in force yet. Expected, and not something you can be held to today.
519 of 519 nodes shown
519 nodes, 824 edges
Drag to pan. Ctrl or Cmd plus scroll to zoom. Tab to move between nodes, Enter to open. Dashed amber edge means GAGE analysis, not an official mapping.
Which instruments can actually bind me?
Personal Data Protection Act 2012 (No. 26 of 2012)
Singapore's general data protection law governing collection, use and disclosure of personal data by organisations. The only binding, economy-wide law in Singapore's AI governance stack; amended by the Personal Data Protection (Amendment) Act 2020.
MAS Notices on Technology Risk Management (TRM Notices)
Legally binding notices under s.29(1) Financial Services and Markets Act 2022, imposing technology risk management requirements on specified classes of financial institutions: critical-system identification, 4-hour maximum annual unscheduled downtime, 4-hour RTO, 1-hour incident notification to MAS, 14-day root cause report, and IT controls protecting customer information. Bind FIs only.
Vietnam Law on Artificial Intelligence No. 134/2025/QH15
Vietnam's standalone AI statute, passed 10 December 2025 by the 15th National Assembly (10th Session) and in force 1 March 2026 - the first binding AI law in ASEAN. Establishes risk-based classification (high/medium/low), transparency duties, provider and deployer obligations, penalties and transition periods. Binding law, in force.
Who issues what
Infocomm Media Development Authority (IMDA)
Singapore's Infocomm Media Development Authority; leads development of Singapore's AI governance instruments, including the Model AI Governance Framework family (2019-2026) and the world's first Model AI Governance Framework for Agentic AI.
Personal Data Protection Commission (PDPC)
Singapore's data protection authority. Administers and enforces the PDPA 2012, the only binding general law in Singapore's AI governance stack; issues advisory guidelines interpreting how PDPA obligations apply to AI systems.
AI Verify Foundation (AIVF)
Not-for-profit foundation launched by IMDA in June 2023 to steward the open-source AI Verify testing framework and toolkit, grow the global AI testing community, and run international assurance initiatives.
Monetary Authority of Singapore (MAS)
Singapore's central bank and integrated financial regulator. Issues binding notices to financial institutions under the Financial Services and Markets Act 2022 and other Acts, plus non-binding guidelines, information papers and consultation papers. legalForce value reflects that MAS issues BINDING-SECTORAL instruments; the actor node itself carries no obligation.
Association of Banks in Singapore (ABS)
Industry association representing banks in Singapore. Its Standing Committee on Data Management (SCDM) published the Handbook on Generative AI Guardrails in Banking. ABS is an industry body, not a regulator; its publications are non-binding industry guidance. legalForce=GUIDANCE reflects that character.
Cyber Security Agency of Singapore
Singapore's national cybersecurity agency, part of the Prime Minister's Office and managed by the Ministry of Digital Development and Information. Issued the Guidelines and Companion Guide on Securing AI Systems (2024) and the Addendum on Securing Agentic AI Systems (2026).
Enterprise Singapore / Singapore Standards Council
Singapore's national standards body administering Singapore Standards. Published SS ISO/IEC 42001:2024, the identical national adoption of ISO/IEC 42001:2023, prepared under the Information Technology Standards Committee.
ASEAN Secretariat
Secretariat of the Association of Southeast Asian Nations (ten member states, eleven including Timor-Leste as observer). Hosts the ASEAN AI governance instruments: the 2024 Guide, the 2025 Generative AI expanded edition, the Responsible AI Roadmap 2025-2030, and DEFA negotiations.
National Assembly of Vietnam
Vietnam's legislature. Passed the Law on Artificial Intelligence No. 134/2025/QH15 on 10 December 2025 (15th National Assembly, 10th Session), in force 1 March 2026 - the first binding AI statute in ASEAN.
Every entry on this map
The whole dataset as text, grouped by legal force, heaviest first. Each entry has its own page with the source, the verified date and everything it connects to.
Binding law. It applies to everyone in scope, whether or not anyone points at it.
61- Personal Data Protection Commission (PDPC)
- Personal Data Protection Act 2012 (No. 26 of 2012)
- Part 3, General Rules on Protection of and Accountability for Personal Data
- Part 4, Collection, Use and Disclosure of Personal Data
- Part 5, Access to and Correction of Personal Data
- Part 6, Care of Personal Data
- Part 6A, Notification of Data Breaches
- Part 9, Do Not Call Registry
- Part 9C, Enforcement
- Consent Obligation (s 13)
- Limits on Obtaining Consent (s 14)
- Deemed Consent (ss 15, 15A)
- Withdrawal of Consent (s 16)
- Collection, Use and Disclosure Without Consent (s 17; Schedules)
- Purpose Limitation Obligation (s 18)
- Notification Obligation (s 20)
- Access Obligation (s 21)
- Correction Obligation (s 22)
- Accuracy Obligation (s 23)
- Protection Obligation (s 24)
- Retention Limitation Obligation (s 25)
- Transfer Limitation Obligation (s 26)
- Accountability Obligation (s 11)
- Designated Individual / DPO Requirement (s 11(3)-(5))
- Policies and Practices Obligation (s 12)
- Duty to Assess Data Breaches (s 26C)
- Duty to Notify Notifiable Data Breaches (s 26D)
- Do-Not-Call Compliance (Part 9)
- 'Personal Data' (s 2(1))
- 'Data Intermediary' (s 2(1); s 4(2))
- 'Publicly Available' Personal Data (s 2(1))
- 'Organisation' (s 2(1); s 4)
- 'Notifiable Data Breach' (s 26B)
- Financial Penalties (s 48J)
- Directions for Non-Compliance (s 48I)
- PDPA Enacted (2012); Main Obligations in Force 2 Jul 2014
- Personal Data Protection (Amendment) Act 2020
- Breach Notification Regime in Force (1 Feb 2021)
- Enhanced Financial Penalties in Force (1 Oct 2022)
- National Assembly of Vietnam
- Vietnam Law on Artificial Intelligence No. 134/2025/QH15
- National Assembly passage (10 December 2025)
- Entry into force (1 March 2026)
- Risk-based classification: high, medium, low
- High-risk AI: pre-deployment assessment, registration, human oversight
- Transparency and AI-generated content labelling
- Foreign providers: local presence or representative
- Violations and liability (Article 29)
- Prohibited AI practices
- Relationship to Digital Technology Industry Law
- Regulation (EU) 2024/1689 - EU Artificial Intelligence Act (extern crosswalk target)
- Article 4: AI literacy
- Article 6 + Annex III: High-risk AI systems
- Article 9: Risk management system
- Article 10: Data and data governance
- Article 12: Record-keeping
- Article 14: Human oversight
- Article 15: Accuracy, robustness and cybersecurity
- Article 17: Quality management system
- Article 26: Obligations of deployers
- Article 72: Post-market monitoring
Binding, but only for a defined population: one regulated sector, or the federal government and the vendors it buys from.
17- Monetary Authority of Singapore (MAS)
- MAS Notices on Technology Risk Management (TRM Notices)
- Notice FSM-N05 Technology Risk Management (banks)
- Notice FSM-N21 Technology Risk Management (capital markets FIs)
- Notice FSM-N13 Technology Risk Management (designated payment systems and DPT service licensees)
- Notice FSM-N03 Technology Risk Management (licensed insurers)
- TRM notice family across FI classes
- Identify critical systems
- Maximum 4 hours unscheduled downtime per critical system in any 12 months
- Recovery time objective of 4 hours or less per critical system
- 1-hour incident notification to MAS (the '1-hour rule')
- Root cause and impact analysis report within 14 days
- IT controls to protect customer information
- Definition: relevant incident
- Definition: critical system
- Incident notification instructions and reporting template
- Circular on Financial Institution Incident Reporting (16 Dec 2025)
Not law. It is what your supervisor examines you against, which is not the same as optional.
21- Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of AI and Data Analytics in Singapore's Financial Sector
- FEAT principle: Fairness
- FEAT principle: Ethics
- FEAT principle: Accountability
- FEAT principle: Transparency
- FEAT Principle 01: Fairness - justifiability)
- FEAT Principle 02: Fairness - justifiability)
- FEAT Principle 03: Fairness - accuracy and bias)
- FEAT Principle 04: Fairness - accuracy and bias)
- FEAT Principle 05: Ethics)
- FEAT Principle 06: Ethics)
- FEAT Principle 07: Accountability - internal)
- FEAT Principle 08: Accountability - internal)
- FEAT Principle 09: Accountability - internal)
- FEAT Principle 10: Accountability - external)
- FEAT Principle 11: Accountability - external)
- FEAT Principle 12: Transparency)
- FEAT Principle 13: Transparency)
- FEAT Principle 14: Transparency)
- Definition of AIDA
- FEAT Principles published (12 Nov 2018)
Proposed, not final. Read it, plan for it, and do not treat it as settled.
44- Proposed Model AI Governance Framework for Generative AI released for consultationSuperseded
- Public Consultation Opened (2 Jun 2026)Consultation
- Development, Collecting and Using Personal Data to Develop Generative AI ModelsConsultation
- Publicly Available Exception for GenAI Training DataConsultation
- 'Digital Barrier' (Definition)Consultation
- General Notifications Insufficient for GenAI Training Consent (Draft Statement)Consultation
- 'User Data' (Personal Data From Products/Services)Consultation
- Generative AI Stakeholders: Model Providers, System Providers, System DeployersConsultation
- System Deployer Primary ResponsibilityConsultation
- Access and Correction Obligations Apply Despite GenAI Technical ChallengesConsultation
- Agentic Functionality Heightens Data Protection RiskConsultation
- Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management for Financial Institutions (P017-2025)Consultation
- P017-2025 consultation opened (13 Nov 2025)Consultation
- P017-2025 consultation closed (31 Jan 2026); still not finalised as of 2026-08-17Consultation
- Applicability and proportionality (Consultation Paper Section 3; proposed Guidelines Section 1)Consultation
- Proposed Guidelines Section 2: AI oversightConsultation
- Proposed Guidelines Section 3: key AI risk management systems, policies and proceduresConsultation
- Proposed Guidelines Section 4: key AI life cycle controlsConsultation
- Proposed Guidelines Section 5: AI capability and capacityConsultation
- Annex: proportionate application of the proposed GuidelinesConsultation
- Proposed scope of AI: model, system, use caseConsultation
- Risk materiality dimensions: impact, complexity, relianceConsultation
- Proposed 12-month transition periodConsultation
- Proposed: board senior mgmt oversightConsultation
- Proposed: dedicated ai committeeConsultation
- Proposed: basic ai policiesConsultation
- Proposed: ai identificationConsultation
- Proposed: ai inventoryConsultation
- Proposed: risk materiality assessmentConsultation
- Proposed: data managementConsultation
- Proposed: transparency explainabilityConsultation
- Proposed: fairness controlsConsultation
- Proposed: human oversightConsultation
- Proposed: third party ai managementConsultation
- Proposed: selection evaluation testingConsultation
- Proposed: technology cybersecurityConsultation
- Proposed: reproducibility auditabilityConsultation
- Proposed: pre deployment reviewsConsultation
- Proposed: post deployment monitoringConsultation
- Proposed: incident management kill switchConsultation
- Proposed: change management decommissioningConsultation
- Proposed: capabilities trainingConsultation
- Proposed: technology infrastructureConsultation
- Consultation P012-2026: proposed amendments to TRM Notices (10 Jun - 31 Jul 2026, closed)Consultation
Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
358- Infocomm Media Development Authority (IMDA)
- AI Verify Foundation (AIVF)
- Model AI Governance Framework, 2nd Edition (2020)
- Guiding principles of the Model Framework
- Principle: explainable, transparent and fair
- Principle: human-centric AI
- Sector- and technology-agnostic design
- Area 1: Internal Governance Structures and Measures
- Adapt or set up internal governance structures
- Define clear roles and responsibilities
- Maintain SOPs to monitor and manage AI risks
- Train staff on AI governance
- Periodically review internal governance structures
- Area 2: Determining the Level of Human Involvement in AI-augmented Decision-making
- Assess probability and severity of harm to individuals
- Determine the appropriate degree of human involvement
- Human-in-the-loop
- Human-over-the-loop
- Human-out-of-the-loop
- Severity-probability of harm matrix
- Area 3: Operations Management
- Minimise bias in data and model
- Ensure data quality
- Document data lineage and provenance
- Use distinct datasets for training, testing and validation
- Apply risk-based measures: explainability, robustness, regular tuning
- Document model development choices and trade-offs
- Monitor and regularly review deployed models
- Area 4: Stakeholder Interaction and Communication
- Make AI policies known to users
- Adopt a policy on explaining AI decisions
- Make communications easy to understand
- Allow users to provide feedback
- Consider offering opt-out where feasible
- Continuously review communication effectiveness
- Annex A: Compilation of AI ethical principles
- Annex B: Algorithmic accountability and audits
- Launch of Model AI Governance Framework, 1st editionSuperseded
- Launch of Model AI Governance Framework, 2nd edition
- Implementation and Self-Assessment Guide for Organisations (ISAGO), 2020
- ISAGO as companion guide to the Model Framework
- ISAGO Section 1: Objectives of deploying AI
- ISAGO Section 2: Internal governance structures and measures
- ISAGO Section 3: Human involvement in AI-augmented decision-making
- ISAGO Section 4: Operations management
- ISAGO Section 5: Stakeholder interaction and communication
- Define business objectives and weigh benefits against risks
- Consider ethical implications of the AI use case
- Identify existing relevant governance structures
- Put in place an AI governance structure with clear roles
- Self-assess the level of human involvement
- Self-assess data management practices
- Self-assess model lifecycle practices
- Self-assess stakeholder communication practices
- Launch of ISAGO at WEF Davos
- Model AI Governance Framework for Generative AI (2024)
- Fostering a trusted AI ecosystem
- Dimension 1: Accountability
- Dimension 2: Data
- Dimension 3: Trusted Development and Deployment
- Dimension 4: Incident Reporting
- Dimension 5: Testing and Assurance
- Dimension 6: Security
- Dimension 7: Content Provenance
- Dimension 8: Safety and Alignment R&D
- Dimension 9: AI for Public Good
- Allocate responsibility ex-ante across the development chain
- Consider ex-post safety nets for end-users
- Clarify how personal data laws apply to generative AI
- Balance copyright with data accessibility
- Adopt industry best practices in development and evaluation
- Provide 'food label'-type transparency and disclosure
- Establish incident monitoring and reporting structures
- Use incidents for continuous improvement
- Adopt third-party testing and assurance
- Develop common AI testing standards
- Adapt information security frameworks to generative AI
- Develop new security testing tools
- Deploy digital watermarking and cryptographic provenance
- Enable informed consumption of online content
- Accelerate safety and alignment R&D investment
- Cooperate globally on AI safety R&D
- Democratise AI access and support public sector adoption
- Upskill the workforce and develop AI sustainably
- Discussion Paper 'Generative AI: Implications for Trust and Governance'Superseded
- Finalised MGF for Generative AI released
- Model AI Governance Framework for Agentic AI
- Dimension 1: Assess and bound the risks upfront
- Dimension 2: Make humans meaningfully accountable
- Dimension 3: Implement technical controls and processes
- Dimension 4: Enable end-user responsibility
- Component: Model
- Component: Instructions
- Component: Memory
- Component: Planning and reasoning
- Component: Tools
- Component: Protocols
- Component: Controls (added in v1.5)
- Component: Logging and monitoring (added in v1.5)
- Multi-agent pattern: Sequential
- Multi-agent pattern: Supervisor
- Multi-agent pattern: Swarm
- Systemic risks of multi-agent systems (v1.5)
- Action-space (authority, capabilities)
- Autonomy (decision-making)
- Four levels of human involvement with agents
- Five types of agentic AI risk
- Automation bias
- Agent identity and access management
- Responsibility allocation across the agentic AI value chain
- Computer use agent
- Determine suitable use cases via agent-specific risk factors
- Perform threat modelling and taint tracing
- Bound risks through agent limits
- Implement agent identification and authorisation
- Evaluate and accept residual risk
- Clearly allocate responsibilities within and outside the organisation
- Practise adaptive governance
- Define significant human-approval checkpoints
- Regularly audit the effectiveness of human oversight
- Monitor human override rates and response times (v1.5)
- Implement technical controls during design and development
- Test agents for baseline safety and reliability before deployment
- Roll out gradually and monitor continuously
- Maintain change management for evolving agents (v1.5)
- Inform users of agent actions, data access and user responsibilities
- Train users to manage human-agent interactions
- Maintain tradecraft and foundational skills
- Launch of MGF for Agentic AI v1.0 at WEF DavosSuperseded
- MGF for Agentic AI v1.5 update
- PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (1 Mar 2024)
- Part II, Legal Effect and Scope
- Part III, Using Personal Data in AI System Development, Testing and Monitoring
- Part IV, Deployment: Collection and Use of Personal Data in AI Systems
- Part V, Procurement of AI Systems (B2B Service Providers)
- Meaningful Consent as the Default Basis for AI Uses
- Business Improvement Exception (as Applied to AI Development)
- Conditions for Relying on the Business Improvement Exception
- Using the Business Improvement Exception for Testing and Bias Assessment
- Research Exception (as Applied to AI R&D)
- Conditions for Relying on the Research Exception
- Legitimate Interests Exception (Deployment Context)
- Data Minimisation in AI Development (Good Practice)
- Data Protection Controls in the AI Development Environment
- Anonymisation of Datasets for AI Development
- Notification Content for AI System Deployment
- Accountability and Written Policies for AI Systems
- Service Providers as Data Intermediaries
- Data Mapping, Labelling and Provenance Records (Service Providers)
- Using AI Verify to Support PDPA Compliance Claims
- Public Consultation on Proposed Guidelines (18 Jul - 31 Aug 2023)
- Guidelines Issued (1 Mar 2024)
- PDPC Advisory Guidelines on Use of Personal Data in Generative AI (final, 20 Jul 2026)
- Public Consultation Closed (1 Jul 2026; 40 Organisations + 3 Individuals)
- Final Guidelines Published (20 Jul 2026, Singapore Data Festival)
- Deployment, Data Protection Responsibilities of Generative AI Stakeholders
- Post-Deployment, Addressing Individuals' Requests About Personal Data
- Documented Assessment (DPIA or Written Record) for Data Behind Digital Barriers
- AI-Specific Notifications for GenAI Training Use
- Consent for GenAI Training Cannot Be a Condition of Service
- Fresh Consent Where AI Use Departs Significantly From Original Purposes
- Anonymisation Accepted as Alternative to Data Minimisation
- Model Provider Responsibilities
- System Provider Responsibilities
- AI Verify Testing Framework and Toolkit
- AI Verify Toolkit (Open Source)
- Technical Tests (Explainability, Robustness, Fairness)
- Process Checks and Documentary Evidence
- International Alignment of the Testing Framework
- 1. Transparency
- 2. Explainability
- 3. Repeatability / Reproducibility
- 4. Safety
- 5. Security
- 6. Robustness
- 7. Fairness
- 8. Data Governance
- 9. Accountability
- 10. Human Agency and Oversight
- 11. Inclusive Growth, Societal and Environmental Well-being
- 12. Organisational Considerations
- AI Verify MVP Launched (25 May 2022)
- AI Verify Open-Sourced on GitHub (7 Jun 2023)
- Crosswalk to NIST AI RMF Published (Oct 2023)
- Crosswalk to ISO/IEC 42001 Published (Jun 2024)
- Enhanced Testing Framework for GenAI (29 May 2025)
- Project Moonshot, LLM Evaluation Toolkit
- Moonshot (Software)
- Benchmarking ('Exam Questions' for LLMs)
- Red Teaming (Adversarial Prompting)
- Starter Kit for LLM-Based App Testing
- Project Moonshot Launched in Open Beta (May 2024)
- Global AI Assurance Pilot (Feb 2025)
- Pilot Launched at Paris AI Action Summit (Feb 2025)
- Tester-Deployer Pairing Model
- Pilot Insights: Context-Dependent GenAI Risk
- Pilot Converted to Global AI Assurance Sandbox (7 Jul 2025)
- Association of Banks in Singapore (ABS)
- Financial services sector (Singapore)
- Veritas Initiative (MAS-led consortium)
- Veritas Phase 1: fairness assessment methodology (concluded 6 Jan 2021)
- Veritas Phase 2: full FEAT assessment methodology and Toolkit v1 (concluded 4 Feb 2022)
- Veritas Phase 3: Toolkit v2.0 and integration pilots (concluded 26 Jun 2023)
- Veritas Toolkit (open source, v2.0)
- FEAT Fairness assessment methodology
- FEAT Ethics & Accountability assessment methodology
- FEAT Transparency assessment methodology
- Veritas use case: credit risk scoring
- Veritas use case: customer marketing
- Veritas use case: insurance predictive underwriting
- Veritas use case: fraud detection
- MindForge AI Risk Management Toolkit (Project MindForge phase 2)
- AI Risk Management: Executive Handbook (Nov 2025)
- AI Risk Management: Operationalisation Handbook (Mar 2026)
- AI Risk Management: Implementation Examples (case studies)
- Handbook Section 1: Scope and AI oversight
- Handbook Section 2: AI risk management
- Handbook Section 3: AI lifecycle management
- Handbook Section 4: Enablers
- Handbook practice: define oversight responsibilities
- Handbook practice: ai policies standards
- Handbook practice: org level risk management
- Handbook practice: third party ai risk
- Handbook practice: usecase level risk management
- Handbook practice: ai inventory capabilities
- Handbook practice: data acquisition processing
- Handbook practice: onboarding build review
- Handbook practice: deployment controls
- Handbook practice: usage monitoring change
- Handbook practice: skills culture
- Handbook practice: manage ai infrastructure
- AI Card template (Handbook Appendix E)
- Library of AI metrics (Handbook Appendix F)
- MindForge AI risk taxonomy (Handbook Appendix B)
- Project MindForge phase 2 concluded; toolkit published (20 Mar 2026)
- MAS to establish AI risk management workgroup under BuildFin.ai (announced 20 Mar 2026)
- ABS Handbook on Generative AI Guardrails in Banking
- Handbook Section 02: use case and risk identification
- Handbook Section 03: guardrails design
- Handbook Section 04: applying guardrails to use case categories
- Use case studies: document extraction/summarisation and code generation
- Guardrail approach: Enterprise Governance and Training
- Guardrail approach: Filtering and Control
- Guardrail approach: Customised Model Design
- Guardrail approach: Red Teaming
- Guardrail approach: Prompt Design
- Guardrail approach: Monitoring and Validation
- Guardrail approach: Human-in-the-Loop Moderation
- Guardrail approach: User Feedback and Iterative Improvement
- Guardrail approach: User Transparency and Consent
- Seven enterprise Gen AI use case categories
- Guardrails and Controls Excel tool
- Handbook published May 2025; current edition posted 24 Mar 2026
- Cyber Security Agency of Singapore
- ASEAN Secretariat
- CSA Guidelines and Companion Guide on Securing AI Systems
- Launch at SICW 2024 (15 October 2024)
- Public consultation (31 July - 15 September 2024)
- Secure by design and secure by default
- Take a lifecycle approach
- Start with a risk assessment
- Stage 1: Planning and Design
- Stage 2: Development
- Stage 3: Deployment
- Stage 4: Operations and Maintenance
- Stage 5: End of Life
- Step 1: Conduct risk assessment focused on AI security risks
- Step 2: Prioritise areas to address
- Step 3: Identify and implement relevant actions
- Step 4: Evaluate residual risks for mitigation or acceptance
- Raise awareness and competency on security risks
- Conduct security risk assessments
- Secure the supply chain
- Consider security benefits and trade-offs when selecting the model
- Identify, track and protect AI-related assets
- Secure the AI development environment
- Secure the deployment infrastructure and environment
- Establish incident management procedures
- Release AI systems responsibly
- Monitor AI system inputs
- Monitor AI system outputs and behaviour
- Adopt a secure-by-design approach to updates and continuous learning
- Establish a vulnerability disclosure process
- Ensure proper data and model disposal
- Companion Guide on Securing AI Systems
- Threat scope: supply chain attacks and Adversarial Machine Learning
- Securing Agentic AI - Addendum to the Guidelines and Companion Guide on Securing AI Systems
- Public consultation (22 October - 31 December 2025)
- Official publication of Addendum v1.0 (17 June 2026)
- Rogue actions
- Sensitive data disclosure through agent manipulation
- Three layers of agentic AI security risk
- Baseline components of agentic AI systems
- Component: Large Language Model
- Component: Instructions
- Component: Tools
- Component: Memory
- Component: Protocols
- Capability class: Cognitive
- Capability class: Interaction
- Capability class: Operational
- Autonomy levels of agentic AI systems
- Assess the autonomy level of the system
- Perform threat modelling of agentic workflows
- Apply taint tracing to track untrusted data
- Identify risks associated with the agent's capabilities
- Step 1: Conduct a risk assessment focused on agentic AI security risks
- Step 2: Prioritise areas to address
- Step 3: Identify and implement relevant actions
- Step 4: Evaluate residual risks; re-evaluate periodically
- Agentic controls: Planning and Design
- Agentic controls: Development
- Agentic controls: Deployment
- Agentic controls: Operations and Maintenance
- SaaS agentic AI and shared responsibility
- Use case examples
- Definition: agentic AI systems
- ASEAN Guide on AI Governance and Ethics (2024)
- Endorsement at 4th ADGMIN (February 2024)
- Principle 1: Transparency and Explainability
- Principle 2: Fairness and Equity
- Principle 3: Security and Safety
- Principle 4: Human-centricity
- Principle 5: Privacy and Data Governance
- Principle 6: Accountability and Integrity
- Principle 7: Robustness and Reliability
- Component: Internal governance structures and measures
- Component: Determining the level of human involvement
- Component: Operations management
- Component: Stakeholder interaction and communication
- Annex A: AI Risk Impact Assessment Template
- National-level recommendations
- Regional-level recommendations
- Use cases (Annex B)
- Expanded ASEAN Guide on AI Governance and Ethics - Generative AI (2025)
- Launch at 5th ADGMIN (January 2025)
- Focus area 1: Accountability
- Focus area 2: Data
- Focus area 3: Trusted Development and Deployment
- Focus area 4: Incident Reporting
- Focus area 5: Testing and Assurance
- Focus area 6: Security
- Focus area 7: Content Provenance
- Focus area 8: Safety and Alignment Research & Development
- Focus area 9: AI for Public Good
- Six GenAI risk categories
- Use cases
- ASEAN Responsible AI Roadmap (2025-2030)
- Adoption of the Roadmap (5 March 2025)
- Focus area: Policy and regulatory foundations
- Focus area: Targeted actions, initiatives and outcomes
- Readiness Assessment Framework
- NIST AI Risk Management Framework 1.0 (extern crosswalk target)
- Function: GOVERN
- Function: MAP
- Function: MEASURE
- Function: MANAGE
- Note: NIST AI 600-1 Generative AI Profile (July 2024)
A voluntary standard. It becomes an obligation the moment a contract or a regulator cites it.
14- Enterprise Singapore / Singapore Standards Council
- SS ISO/IEC 42001:2024 - Information technology, Artificial intelligence, Management system
- Annex ZA (national, informative): AI Verify as example testing tool
- Voluntary nature of Singapore Standards
- Publication of SS ISO/IEC 42001:2024
- Scope: AI management system requirements
- ISO/IEC 42001:2023 - AI management system (extern crosswalk target)
- Clause 4: Context of the organization
- Clause 5: Leadership
- Clause 6: Planning
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance evaluation
- Clause 10: Improvement
Not in force yet. Expected, and not something you can be held to today.
4- ASEAN Digital Economy Framework Agreement (DEFA)Not yet in force
- DEFA negotiations concluded (29 May 2026)Not yet in force
- Expected signature: 49th ASEAN Summit, November 2026Not yet in force
- Scope: emerging areas including AINot yet in force