
Singapore is moving to sharpen the rules around how companies use personal data in generative AI, as the country tries to square two competing realities: businesses want more data to build AI systems, while users are increasingly asked to trust tools they barely understand.
At the Singapore Data Festival on Monday, Minister for Digital Development and Information Josephine Teo announced three new initiatives: advisory guidelines on the use of personal data in generative AI, transparency guidelines for AI chatbots, and a Digital Twin for Enterprises Playbook aimed at helping companies deploy real-time virtual models of physical operations.
Also Read: Beyond the hype: What generative AI is actually changing in startups
The announcements are not a dramatic regulatory crackdown. They are closer to a tightening of expectations. But for startups, banks, telcos, SaaS firms, customer service platforms, and AI application developers in Southeast Asia, they point to where Singapore wants the market to go: more disclosure, clearer consent, and fewer vague privacy notices hiding broad data use.
“Without good data, even the best systems will struggle to produce useful outcomes,” Teo said. “That is why data governance matters more, not less, in the age of AI.”
Consent can no longer hide in boilerplate
The most consequential move is the Personal Data Protection Commission’s Advisory Guidelines on the Use of Personal Data in Generative AI.
Under Singapore’s Personal Data Protection Act, organisations already need consent to collect, use or disclose personal data unless exceptions apply. The new guidelines clarify what that means when companies use personal data to develop, improve or fine-tune generative AI models.
Teo used the example of a customer service team wanting to train a generative AI model on call recordings. Such recordings often contain names, addresses, billing information and other personal details. Under the new guidance, companies should not rely on generic wording buried in privacy policies. They should state clearly that customer data may be used to train or improve AI models.
That matters because the generative AI supply chain is messy. A startup may build an app using a third-party large language model, fine-tune it with customer conversations, host it on cloud infrastructure, and integrate analytics from another vendor. When something goes wrong, such as data leakage, hallucinated advice or inappropriate use of public datasets, accountability can quickly become diluted.
The PDPC guidelines also address roles and responsibilities across the AI value chain, as well as due diligence when organisations rely on publicly available data.
Also Read: Without governance, AI agents risk becoming enterprise chaos engines
For Southeast Asia, this is not an abstract compliance problem. The region’s digital economy is projected to reach around US$1 trillion by 2030, according to regional policy and industry estimates, and much of that growth will depend on cross-border data flows, platform trust and AI-enabled services. Yet data protection rules remain uneven across ASEAN, with Singapore, Malaysia, Thailand, Indonesia, Vietnam and the Philippines at different stages of enforcement and regulatory maturity.
Singapore is effectively trying to set the operating standard before bad practices become entrenched.
Chatbots may soon come with ‘information cards’
IMDA is also launching Generative AI Chatbot Transparency Guidelines, beginning as a voluntary framework.
The key idea is a Chatbot Information Card. Teo compared it to the label on medicinal products: not a full technical manual, but a plain-language summary of what the chatbot is for, what it is not for, how data may be handled, and how users can report issues.
This targets a real gap. Most users do not read terms of service documents. Even if they do, the relevant information is often scattered across privacy notices, AI disclaimers and product documentation. For consumer-facing AI services, the result is a dangerous grey zone: users may disclose sensitive information without understanding how it is stored, reviewed or used to improve systems.
DBS, Google, Meta, OCBC and Singapore Airlines are among the early adopters that will use the guidelines as a reference point. Google is expected to consolidate key information about its Gemini app, while Meta will provide clearer information on how users interact with its AI-powered products.
The competitive implications are broader. Gemini competes directly with OpenAI’s ChatGPT, Anthropic’s Claude and Microsoft Copilot, all of which are fighting for enterprise and consumer adoption in Asia. Meta AI is being pushed through social platforms with massive regional reach, particularly in markets where Facebook, Instagram and WhatsApp remain default digital infrastructure.
For banks such as DBS and OCBC, the pressure is also regional. Rivals including UOB, Maybank, CIMB and Kasikornbank are all experimenting with AI across fraud detection, customer engagement and operations. A chatbot transparency norm in Singapore could quickly become a benchmark for financial institutions operating across ASEAN.
Digital twins move beyond large enterprises
The third initiative, IMDA’s Digital Twin for Enterprises Playbook, is aimed at a different but related problem: helping companies turn operational data into useful AI systems.
Also Read: Why emerging markets need AI governance infrastructure before AI scale
A digital twin is a real-time virtual representation of physical assets, systems or processes. Large industrial companies, logistics operators, airlines and Formula One teams have used such systems for years. The government now wants smaller enterprises to see them as practical tools rather than futuristic toys.
Teo cited Exceltec, a Singapore facilities management company that built a digital twin drawing on sensor data from more than 70 customer sites. The system monitors issues such as air-conditioning faults or unusual water usage that may indicate leaks. According to Teo, the system saves each team about 45 minutes a day on each inspection.
Exceltec operates in a crowded facilities management and building services market that includes players such as CBM, C&W Services, ENGIE Services, Sodexo and Surbana Jurong-linked service providers. For smaller operators, digital twins could become a way to compete on predictive maintenance rather than manpower-heavy inspection routines.
Across Southeast Asia, the timing is relevant. Cities are adding sensors to buildings, utilities and transport networks, while property owners face rising energy costs and pressure to improve sustainability reporting. In markets such as Singapore, Malaysia, Thailand and Vietnam, digital twins are likely to be pulled into smart building, manufacturing and logistics use cases.
But the playbook’s “legal guide” framing is telling. The government is not just pushing adoption; it is warning companies that data architecture, consent, security and accountability cannot be bolted on later.
ASEAN context: AI safety is local, not universal
Teo also pointed to January’s AI Safety Red Teaming Challenge, where more than 80 experts from all ASEAN countries, as well as China, India, Japan and Korea, tested whether generative AI applications could leak protected data.
The findings underline a problem global AI companies often underplay: model safety does not travel neatly across languages and cultures. Some harmful requests refused in English were answered in Khmer. Casual local phrasing could bypass safeguards that worked against formal prompts.
Also Read: Safeguarding your organisation in the age of increasing AI
That is a serious issue for Southeast Asia, where hundreds of languages and dialects sit alongside uneven digital literacy and fast AI adoption. Guardrails built primarily for English-speaking users may fail in local contexts.
“None of us can build a trusted data ecosystem by looking only within our own borders,” Teo said.
Singapore will assume the ASEAN Chairmanship next year and has signalled that trusted data use will be part of its regional digital agenda. The challenge will be moving beyond voluntary frameworks and high-level alignment. For startups and enterprises, the direction is already clear: if AI is trained on user data, users need to be told plainly; if chatbots interact with the public, their limits must be visible; and if companies want to extract value from operational data, governance has to start before deployment, not after the first breach.
The post Singapore turns AI scrutiny towards chatbots, personal data, and digital twins appeared first on e27.
