Back
Image Alt

The Singapore Law Gazette

Frameworks, frontlines and frontiers

Navigating the evolving world of AI governance and regulation

Introduction

As a young policy officer beginning his journey in AI governance and regulation nearly a decade ago, I was then struck by three observations. One, how simple it was for practically any government or organisation to make headlines by simply espousing a certain set of guiding (or “ethical”) principles. Two, how even then, Singapore had striven to value-add to the global discourse, not by creating yet another set of principles, but by thinking pragmatically, with the aim of helping organisations implement common principles effectively. Three, how “striking the right balance” was perhaps the most favoured phrase of any policymaker when speaking of regulating AI.

From these observations, I drew three lessons (that remain relevant today). First, that principles and policies are only as good as they are implemented. Second, how Singapore’s quest for relevance in the global AI space is a never-ending one – one always of becoming, and never of being. Third, that while much ink has been spilt on where the balance should be, the more pertinent question should be how we can continue to adjust the equilibrium coherently, amidst an ever-changing kaleidoscope of business, regulatory and technological changes.

The world of AI has changed dramatically since a decade ago. Instead of “machine learning”, we now talk of “agentic AI” and “world models”. Instead of just encouraging enterprise use cases, we tussle with the benefits and costs of ubiquitous society-wide AI use. Instead of debating whether a jurisdiction should regulate AI through specific hard laws, we talk today of possible fragmentation of AI laws (note the plural) in various jurisdictions – along with a maze of other soft law instruments, technical standards and existing laws (such as data protection, IP, competition and trade laws). Yet amidst this change, some things (about Singapore) remain the same. First, Singapore’s position as a small yet open city-state that cannot artificially insulate itself from technological developments. Second, Singapore’s position in the global AI ecosystem as primarily a “deployer” state, which limits the degree of influence Singapore has in shaping or regulating how AI is developed at source.

Given this context, this article examines AI governance in Singapore alongside the global regulatory context (particularly developments in China, the EU, and the US). This article then posits three ways lawyers can remain effective advisors to their clients in the present AI age.

Singapore adopts a blended regulatory approach that emphasises organisational guidance complemented by existing and new hard laws

Singapore’s AI regulatory approach is one that can be described as “light-touch”, “innovation-friendly” and “blended”. These terms, already familiar to those versed in the literature, essentially reflect Singapore’s use of “soft law” governance tools with technology-neutral (and as far as possible, existing) legislation.

The reasons for this approach stem from Singapore’s realities mentioned above. First, since Singapore (as a deployer state) cannot directly influence how AI systems are designed or developed at source, regulatory attention is instead directed towards how AI systems are deployed and used domestically. Second, since Singapore cannot insulate itself from technological developments, it must find ways to quickly understand the regulatable risks of technology (which often comes from observing its use first-hand and in situ). Third, to ensure a stable and business-friendly environment, Singapore relies on existing broad-based and technology-neutral laws as far as possible, and only introduces new hard law interventions where risks present a fresh, clear and present danger.

Conceptually, one could visualise Singapore’s approach as akin to John Braithwaite’s “regulatory pyramid” – a “dynamic regulatory model in which persuasion and / or capacity-building are tried before escalation up a pyramid of increasing levels of punishment”.1https://johnbraithwaite.com/wp-content/uploads/2017/06/ch07-of-Regulatory-Theory.pdf.

  • At the base sits a range of policy strategy and governance frameworks. For instance, Singapore’s high-level AI policy direction is articulated in the National AI Strategy 2.0 (2023).2https://file.go.gov.sg/nais2023.pdf. From a governance perspective, organisations can draw guidance from the Model AI Governance Framework (Model Framework). The Model Framework’s Second Edition was published in 2020.3https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/resource-for-organisation/ai/sgmodelaigovframework2.pdf. There are also technology-specific Model Frameworks for generative AI and agentic AI.4https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf. See also https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf.
  • Sitting above these frameworks are initiatives such as sandboxes, testing frameworks and tools. Specifically, Singapore’s AI governance testing initiative AI Verify5https://aiverifyfoundation.sg/what-is-ai-verify/. – along with the Global AI Assurance Sandbox6https://aiverifyfoundation.sg/ai-assurance/. – provide verifiability and assurance over the performance of AI systems. They also build the foundations of interoperability (and possibly, mutual recognition) of global AI regulatory frameworks in the future.
  • Legislatively, to deal with most AI-related risks and harms, Singapore relies on existing statutes such as the Personal Data Protection Act 2012 (2020 Rev Ed)7https://sso.agc.gov.sg/Act/PDPA2012. and the Copyright Act 2021,8https://sso.agc.gov.sg/Act/CA2021. whose provisions apply across multiple stages of the AI lifecycle. While the author is not yet aware of direct enforcement action against AI companies under these laws, the PDPA has been considered and applied in a case involving AI-facilitated credit facility assessments. This exemplifies how existing laws provide a firmament for AI regulation, even in the absence of an AI-specific statute.9https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/commissions-decisions/decision–hsbc-bank-singapore-limited–10032021.pdf
  • Where new, real and discrete harms emerge, Singapore has introduced targeted legislative interventions. The Elections (Integrity of Online Advertising) (Amendment) Act 2024 (ELIONA),10https://sso.agc.gov.sg/Bills-Supp/29-2024/Published/20240909?DocDate=20240909. which criminalises certain manipulated online election advertisements that realistically depict candidates (including through the use of deepfakes), reflects a preference for targeted legislative interventions that do not induce widespread regulatory or compliance uncertainty.

Hence, for lawyers and in-house counsel advising companies on AI development, deployment and use, Singapore’s “regulatory pyramid” means having to appreciate the interplay of soft law frameworks and hard legislation in risk management and governance design. This, however, is not all, as practitioners must also stay alive to extraterritorial developments.

Global divergence in AI regulation further complicates cross-border deployment for Singapore-based businesses

The cross-border nature of AI development and deployment means that any legal analysis of risk must be done with a cross-border lens. In this regard, the global landscape is being defined by increasingly different regulatory approaches. This can in turn affect deployment decisions, shape organisations’ compliance risks, and even influence considerations around the evolution of Singapore’s own regulatory framework. While the following sub-sections could each warrant an entire article, for brevity, the following paragraphs provide a whistle-stop update of the distinct regulatory approaches in China, the EU, the US and the rest of the Asia-Pacific.

1. China governs AI through a set of binding, technology-specific rules backed by strong enforcement powers

Rather than adopting a single omnibus AI statute, China takes a hard-yet-vertical regulatory approach.11Although China had appeared to be considering introducing a single unifying AI law – as evidenced by pronouncements by the State Council as recent as 2024 – the inclination appears to have subsided in recent months. The Cyberspace Administration of China (CAC) has issued targeted administrative regulations for specific technologies, namely recommendation algorithms (2021),12http://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm. deep synthesis (including deepfakes) (2023),13http://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm. and generative AI (2023).14https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm. The CAC also published new draft measures on human-like interactive AI services in December 2025.15https://www.cac.gov.cn/2025-12/27/c_1768571207311996.htm. These rules impose concrete obligations relating to algorithmic registration, content labelling, data governance, intellectual property, children’s privacy and security controls.

Alongside these binding measures, China also relies on local pilot zones in cities such as Shanghai and Beijing.16https://journalsonline.academypublishing.org.sg/e-First/Singapore-Academy-of-Law-Journal/ctl/eFirstPDFPage/mid/568/ArticleId/2590?Citation=Published+on+e-First+27+January+2026, para 69. In these pilot zones, AI applications may be tested under more flexible, policy-supported conditions, allowing experimentation to proceed within defined regulatory boundaries.

2. The European Union’s comprehensive, risk-based AI regime remains influential despite recent efforts to soften compliance burdens

The European Union (EU) has pursued a horizontal and comprehensive framework anchored by the EU AI Act, which officially entered into force on 1 August 2024.17https://artificialintelligenceact.eu/ai-act-explorer/. The Act categorises AI systems by risk level and imposes corresponding ex-ante obligations regarding data governance and human oversight (among other areas). While the EU is traditionally a global rule-maker, recent political shifts have introduced a momentum toward deregulation to boost competitiveness. The proposed Digital Omnibus Regulation aims to simplify compliance under the EU AI Act, and introduce EU-level regulatory sandboxes.18https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0836.

3. The US has shifted toward a fragmented, growth-oriented AI governance landscape driven by sectoral and state-level rules

The US approach is characterised by a lack of omnibus federal AI legislation and favours a pro-innovation stance. Under America’s AI Action Plan released by the Trump administration in July 2025,19https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf. the focus is on reducing bureaucratic hurdles and accelerating infrastructure development. However, this federal restraint has resulted in a fragmented patchwork of state-level laws. States such as Colorado, California, New York and Texas have enacted their own AI statutes, introducing risk-based obligations and sandbox regimes.20https://fpf.org/wp-content/uploads/2025/10/The-State-of-State-AI-2025.pdf.

For practitioners, this creates an increasingly complicated compliance environment in which limited federal intervention contrasts with increasingly active state-level enforcement.

4. Across the Asia-Pacific, AI governance frameworks vary significantly, requiring careful jurisdictional assessment

Even within the Asia-Pacific, AI regulatory approaches appear to be fragmenting.

  • South Korea enacted its AI Framework Act,21https://aibasicact.kr/explorer/. which is a legislative framework that (among other aspects) targets “high-impact AI” with limited obligations and relatively modest penalties.
  • Japan has taken an innovation-first approach anchored in its AI Promotion Act and voluntary guidelines. The AI Promotion Act is aimed in part at empowering internal government coordination on AI, and does not come with any compliance obligations.22https://laws.e-gov.go.jp/law/507AC0000000053.
  • More recently, Vietnam introduced the Law on Artificial Intelligence (No. 134/2025/QH15).23https://english.luatvietnam.vn/law-no-134-2025-qh15-dated-december-10-2025-of-the-national-assembly-on-artificial-intelligence-422299-doc1.html. This is one of the Asia-Pacific region’s most stringent AI compliance regimes, and has significant similarities with the EU AI Act. For instance, the Law adopts a risk-based approach with prohibited practices, extensive compliance obligations for high-risk systems, and revenue-based penalties.
  • Beyond these jurisdictions, most Asia-Pacific jurisdictions continue to adopt a soft-law approach to AI. It remains to be seen, however, whether the current state will continue to hold true.

This fragmentation reinforces the need to assess AI risk through a jurisdiction-specific lens, rather than assuming regional convergence or regulatory equivalence.

Lawyers should focus on three shifts – the conceptual, technical and geographical

Against this fragmented and evolving regulatory backdrop, lawyers increasingly function as business translators of regulatory risk across jurisdictions (rather than operating within the confines of a single jurisdiction). Such a role is particularly pertinent given the borderless nature of the AI lifecycle – an AI product could be designed in Texas, developed and tested in California, and deployed in Singapore while being trained on datasets from Europe, China, India and South Korea.

To navigate this complex landscape as effectively as possible, lawyers must be prepared to make three strategic shifts in our advisory practice.

1. Our advisory envelope must extend beyond black-letter law to encompass policy directions, soft law guidance, technical standards, and long-term regulatory alignment.

The first shift is conceptual. We must broaden our scope from strict statutory compliance to a holistic view of regulatory risk. In Singapore, soft-law instruments like the Model AI Governance Framework may set de facto standards of reasonable behaviour in future (even if they act merely as voluntary guidance today). Similarly, as foreign as the language of data protection impact assessments and AI technical testing tools, benchmarks, metrics and standards may presently be to us, the day these become mainstays of regulatory compliance is not very far away.

More importantly, rather than advising on the checking of compliance boxes, lawyers should encourage client organisations towards developing virtuous cycles of trust. This entails girding clients for the “known-unknowns”24https://www.usatoday.com/story/news/politics/2021/06/30/donald-rumsfelds-most-famous-and-infamous-quotes/7811766002/?gnt-cfr=1&gca-cat=p of AI incidents. Regardless of how robust ex-ante governance may be, data incidents and AI harms will occur. Lawyers should help organisations shape and implement incident response plans that prioritise transparency, contextual explainability and transparency, so that customers and users continue to trust AI use because of their demonstrated accountability and responsibility. It also means having to read the tea leaves of shifting regulatory expectations – and be it the EU’s or Vietnam’s conformity assessments, South Korea’s impact assessments or China’s algorithmic registrations, to advise client organisations how to align themselves accordingly.

2. Meaningful AI governance advice requires lawyers to understand how AI systems are built, deployed, and governed in practice.

The second shift is technical. Going forward, a baseline level of AI literacy is necessary to appreciate hard AI laws, or ask the right questions about technical matters such as training data, data provenance and data logs and system limitations.

Consider, for instance, Article 13(1) of Vietnam’s Law on Artificial Intelligence, which states:25https://vanban.chinhphu.vn/?pageid=27160&docid=216334&classid=1&typegroupid=3.

“Article 13. Conformity assessment for high-risk artificial intelligence systems

  1. High-risk artificial intelligence systems must undergo conformity assessment in accordance with the provisions of this Law prior to being put into use or when significant changes occur during use. Where technical standards or specifications for artificial intelligence systems exist, conformity assessment must also be conducted in accordance with the provisions of the law on technical standards and specifications.” [emphasis added]

This conformity assessment requirement is substantially similar to, and is likely to have been inspired by, Article 16 (read with Article 43) of the EU AI Act.26https://artificialintelligenceact.eu/article/16/.

Thus, going forward, familiarity with testing tools such as those in the AI Verify testing toolkit will allow lawyers to advise clients on concrete validation and assurance mechanisms that can serve as evidence of due diligence.27https://aiverifyfoundation.sg/what-is-ai-verify/toolkit/. This technical fluency is critical to addressing information asymmetries between technology vendors and non-technical clients, and for ensuring that contractual risk allocation meaningfully reflects how AI systems operate in practice.

3. Effective AI governance advice must anticipate how foreign regimes intersect with Singapore’s legal requirements and expectations.

The final shift is geographical. AI systems are inherently cross-border in their development and deployment. A system trained in one jurisdiction and hosted in another may trigger overlapping regulatory obligations across its lifecycle. The relevant inquiry is therefore not confined to current Singapore law, but extends to any jurisdiction connected to the system.

As a small and highly interconnected economy, Singapore has designed its AI governance framework with interoperability in mind. Even without an omnibus AI statute, aspects of Singapore’s regulatory approach may develop in response to regulatory developments in major jurisdictions. Lawyers should therefore pay close heed to the emergence of regionally or internationally recognised standards or good practices from the outset. Deepening familiarity with crosswalks, such as the mapping between AI Verify and the US NIST AI Risk Management Framework, can allow lawyers to position organisations to meet evolving global regulatory expectations.

The next phase of Singapore’s AI regulatory journey will be highly multi-dimensional

It would be difficult to predict specifically how Singapore’s AI regulation journey will unfold. After all, it was not possible (at least for most people) to have foreseen the emergence of the EU AI Act, or of new technologies such as generative or agentic AI.

What is clear, however, is that the next phase of Singapore’s AI regulatory journey promises to be multi-dimensional. In particular, it will be shaped by the interaction between binding statutory obligations, soft law frameworks and guidance, technical evaluations and benchmarks, and enforcement practice. It will also be shaped by developments elsewhere, including regulatory developments in other major jurisdictions. Amidst such complexity, Singapore will strive to ensure – as observed above – that implementation can be achieved pragmatically and effectively, that initiatives move needles rather than simply turn heads, and more importantly, that it continues to position itself in a way that attracts other jurisdictions and companies to have an interest in our success.

For lawyers navigating this kaleidoscope of evolving regulatory dynamics, this requires multi-layered, multi-disciplinary and multi-jurisdictional thinking. Legal advisors who can navigate these dimensions will be well-positioned to provide commercially relevant and forward-looking advice to clients in an evolving regulatory environment.

 

The author is an Adjunct Lecturer teaching AI Law, Policy and Ethics at the Singapore Management University Yong Pung How School of Law. He is also Managing Director (Asia-Pacific) at the Future of Privacy Forum. While the author is grateful to Lauren Koek for her assistance in the writing of this article, all errors remain the author’s own. Nothing in this article should be attributed to any organisation, past or present, to which the author is affiliated.

Endnotes

Endnotes
↑1 https://johnbraithwaite.com/wp-content/uploads/2017/06/ch07-of-Regulatory-Theory.pdf.
↑2 https://file.go.gov.sg/nais2023.pdf.
↑3 https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/resource-for-organisation/ai/sgmodelaigovframework2.pdf.
↑4 https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf. See also https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf.
↑5 https://aiverifyfoundation.sg/what-is-ai-verify/.
↑6 https://aiverifyfoundation.sg/ai-assurance/.
↑7 https://sso.agc.gov.sg/Act/PDPA2012.
↑8 https://sso.agc.gov.sg/Act/CA2021.
↑9 https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/commissions-decisions/decision–hsbc-bank-singapore-limited–10032021.pdf
↑10 https://sso.agc.gov.sg/Bills-Supp/29-2024/Published/20240909?DocDate=20240909.
↑11 Although China had appeared to be considering introducing a single unifying AI law – as evidenced by pronouncements by the State Council as recent as 2024 – the inclination appears to have subsided in recent months.
↑12 http://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm.
↑13 http://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm.
↑14 https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm.
↑15 https://www.cac.gov.cn/2025-12/27/c_1768571207311996.htm.
↑16 https://journalsonline.academypublishing.org.sg/e-First/Singapore-Academy-of-Law-Journal/ctl/eFirstPDFPage/mid/568/ArticleId/2590?Citation=Published+on+e-First+27+January+2026, para 69.
↑17 https://artificialintelligenceact.eu/ai-act-explorer/.
↑18 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0836.
↑19 https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf.
↑20 https://fpf.org/wp-content/uploads/2025/10/The-State-of-State-AI-2025.pdf.
↑21 https://aibasicact.kr/explorer/.
↑22 https://laws.e-gov.go.jp/law/507AC0000000053.
↑23 https://english.luatvietnam.vn/law-no-134-2025-qh15-dated-december-10-2025-of-the-national-assembly-on-artificial-intelligence-422299-doc1.html.
↑24 https://www.usatoday.com/story/news/politics/2021/06/30/donald-rumsfelds-most-famous-and-infamous-quotes/7811766002/?gnt-cfr=1&gca-cat=p
↑25 https://vanban.chinhphu.vn/?pageid=27160&docid=216334&classid=1&typegroupid=3.
↑26 https://artificialintelligenceact.eu/article/16/.
↑27 https://aiverifyfoundation.sg/what-is-ai-verify/toolkit/.

Chairperson, Asia-Pacific Legal Innovation and Technology Association (ALITA)
Co-Founder, LawTech.Asia

Josh is the Managing Director (APAC) of the Future of Privacy Forum and Advisor (Technology, Media and Telecommunications) in Rajah & Tann Asia. Prior to this, Josh was a policymaker in the Singapore Government. He also practiced as an international arbitration and disputes lawyer.

Josh is the current Director and founding Chairperson of the Asia-Pacific Legal Innovation and Technology Association. Josh also co-founded LawTech.Asia, a virtual publication on law and technology in Asia. In 2023 and 2019, Josh was identified by Asia Law Portal as one of Asia’s “Top 30 To Watch” in legal innovation and the business of law.

Josh presently serves as a council member of Singapore’s 7th Media Literacy Council. Josh is also a member of Singapore’s Law Reform Subcommittee for Robotics and AI, and an adjunct faculty member and Senior Research Affiliate of the Singapore Management University Yong Pung How School of Law, where he teaches AI law, policy and ethics. Josh was also a chapter author for the pioneering book Law and Technology in Singapore.

Josh obtained his LL.M. (with a specialization in Law and Technology) from Berkeley Law in 2022 as a Richard Buxbaum Fellow and a Kathryn Aguirre Worth Scholar. He was also named to the school’s 2022 Dean’s List, and was the LL.M. Editor of the Berkeley Technology Law Journal. A member of Asia Society’s Asia 21 Next Generation Fellows Class of 2024 and a recipient of the National Youth Council’s ASEAN Youth Fellowship, Josh received his LL.B from the Singapore Management University Yong Pung How School of Law in 2015, and was called to the Singapore Bar in 2016.