Governments have focused on regulating the companies building AI in the past few years. Singapore is now turning its attention to a different question: How do ordinary people know what an AI system is doing with their personal data?
From July 20, organisations using personal data to train generative AI models will have to inform consumers here that their information is being used, part of a broader push to make AI more transparent and accountable.
The move marks a shift in AI governance. Rather than introducing another layer of regulation, Singapore is trying to make AI easier for consumers to understand before they decide whether to trust it.

“As more organisations develop, adapt or deploy generative AI tools, we must address the question of accountability,” said Minister for Digital Development and Information, Josephine Teo, at the inaugural Singapore Data Festival on July 20.
The new requirement, known as AI-specific notifications, is contained in advisory guidelines released by the Personal Data Protection Commission (PDPC) following a public consultation. This new rule took effect from July 20.
The PDPC said consumers should be informed because sensitive personal information including children’s data, health records and credit information, could potentially be exposed or reconstructed from generative AI models. Once data has been incorporated into a model, it may also be difficult to remove or correct.
Previously, organisations could rely on broad privacy notices covering activities such as product development or service personalisation.
Under the new guidelines, they will need to explicitly notify consumers when personal data is used to train or improve generative AI systems.
Notably, the PDPC has avoided prescribing exactly how organisations should comply. Companies have flexibility to use channels such as in-app notifications or dedicated webpages, reflecting Singapore’s preference for principles-based regulation over highly prescriptive rules.
The government also released voluntary transparency guidelines encouraging providers of public-facing AI chatbots to publish a chatbot information card explaining, in plain language, what the chatbot can and cannot do, how user data may be handled and how users can report problems.
Teo compared the concept to a medicine label. Consumers do not need every scientific detail; they need the information required to use the product safely and appropriately.
“The information usually exists,” she said. “But it is scattered across terms of service, privacy notices and other documents, and is often either too simplistic or too technical for ordinary users.”
The recommendation applies to both general-purpose AI assistants developed by frontier AI companies and specialised chatbots used by banks, airlines, insurers and retailers.
Technology companies including Google and Meta, together with DBS, OCBC, Singapore Airlines and Synapxe, have committed to rolling out their own chatbot information cards with improved chatbot transparency practices over the next six to 12 months.
Google, for example, will consolidate key information about the Gemini app, and make that information easily accessible to users so that they can use this foundation model with greater confidence, said the Minister.
Public agencies, including the National Library Board and the Health Promotion Board, will also adopt the guidance.
Singapore’s approach differs from jurisdictions such as the European Union, whose AI Act focusses largely on obligations for AI developers and providers. Instead, Singapore is moving ahead on creating trust in AI by building clearer communication with users.
“The companies I mentioned are early adopters who are demonstrating leadership in data and AI governance. We hope many more will follow,” said Teo.
