Back to Resources
AI Governance12 min read

AI Governance and the EU AI Act: What Singapore Businesses Actually Need

Singapore has no AI act. The EU's applies to you anyway if you sell into Europe — and grant reviewers increasingly ask. A proportionate governance position for an SME.

Haojun See
Haojun See

Founder & Director, On The Ground

Updated 5 August 2026

The honest starting position

Singapore has no AI act. There is no local statute that says what you may or may not build with a language model. That leads a lot of businesses to conclude there's nothing to do, which is wrong for three separate reasons: 1. The PDPA already applies. It governs personal data regardless of whether AI is involved, and "we put it in a chatbot" is not a lawful basis. 2. The EU AI Act has extraterritorial reach. If your output is used in the EU, it can apply to you even with no EU entity. 3. Buyers and grant reviewers now ask. Increasingly a governance question appears in procurement and in grant applications, and "we hadn't considered it" is a scoring problem regardless of the legal position. None of this requires a compliance function. It requires a written position, which most SMEs don't have and could produce in a morning.

What the EU AI Act actually does

It's a risk-tiered product-safety law, not a data-protection law. That distinction matters because the obligations attach to *what the system decides*, not to what data it holds. Four tiers, simplified: - Unacceptable — prohibited outright. Social scoring, certain biometric categorisation, manipulative systems targeting vulnerability. - High-risk — permitted with substantial obligations. This is the tier that matters commercially: employment and recruitment decisions, credit scoring, education access, essential services, certain safety components. - Limited risk — transparency duties. Chatbots must not pretend to be human; synthetic media must be disclosed. - Minimal risk — the overwhelming majority. Spam filters, recommendation engines, most internal productivity tooling. Where the tiers get misread: most SME use of Claude — drafting, summarising, internal tools, code — sits in minimal risk. The tier jumps when a system materially affects a person's access to a job, credit, education or a service. A CV-screening tool is high-risk. A tool that drafts the job advert is not. If you're sorting applications by any criterion, read the high-risk annex properly rather than assuming.

Does it reach you?

Three questions, in order: Do you place an AI system on the EU market? Selling or providing software with an AI component to EU customers, including free. Is the output used in the EU? This is the one people miss. A Singapore firm producing AI-assisted output for an EU client can be in scope even with no EU presence. Are you a deployer inside the EU? Only relevant if you have an EU entity or staff. If all three are no, the Act isn't your concern — write that down with the date and revisit it when you take an EU customer. That note is itself the deliverable: it shows the question was asked. The extraterritorial reach is genuinely broad, and this is the point at which "check before concluding" stops being boilerplate. If you sell software and you're unsure, get an actual opinion.

What Singapore expects instead

The PDPA is the binding instrument. The relevant obligations are unremarkable and predate AI: consent or another lawful basis, purpose limitation, reasonable security arrangements, and accountability. What AI changes is how easily personal data ends up somewhere unintended — pasted into a prompt, sitting in a chat history, retained by a vendor. IMDA's Model AI Governance Framework is voluntary and genuinely useful as a structure: internal governance, deciding the level of human involvement, operations management, and stakeholder communication. It's designed to be adopted proportionately. AI Verify is a testing framework and toolkit. Relevant if you're building systems whose behaviour you need to evidence to a third party. Most SMEs don't need it; those selling into government procurement should know it exists. ISO 42001 is the certifiable AI management system standard. Reading its structure is instructive. Certifying is a commercial decision — pursue it when a customer requires it, not as general prudence.

A proportionate position for a small business

What we'd actually recommend, and what we do ourselves. Five things, roughly a morning: 1. An inventory. One page. Every AI system in use, what it touches, whether personal data is involved, and whether any decision affecting a person depends on it. Most SMEs discover they have more than they thought — someone's using a transcription tool nobody approved. 2. A human-in-the-loop rule for consequential decisions. Anything affecting someone's employment, credit, or access to a service gets a named human who decides and is accountable. Not a review step nobody performs — a person. 3. A personal-data rule for prompts. No identifiers in prompts unless there's a specific reason and a lawful basis. Practically: redact before pasting. A system prompt that interrupts you when you forget is more effective than a policy nobody rereads. 4. Vendor tier awareness. Know whether your plan excludes your inputs from training. Consumer tiers and business tiers differ, and the difference is material if you handle client information. 5. Write it down, and date it. Two pages. What you use, what you decided, what you ruled out and why. This is what a grant reviewer or a procurement questionnaire is actually looking for, and its absence is what looks bad — not the sophistication of what's in it. What we would not do at SME scale: hire a compliance consultant, pursue certification speculatively, or build a governance committee. The failure mode for small businesses isn't insufficient process; it's having no written position at all.

The two mistakes worth avoiding

Assuming no local law means no obligation. The PDPA applies, EU reach is real, and buyers ask. A one-page position closes all three cheaply. Over-engineering governance you can't sustain. A policy document nobody follows is worse than a short one that's actually true, because the first creates a documented gap between what you claim and what you do. Write what you actually do. Improve it when something changes. The proportionate answer for most Singapore SMEs sits between those two, and it's much closer to the light end than compliance marketing suggests. This isn't legal advice. It's a practitioner's read of where the obligations sit. If you're building anything that touches employment, credit, education access, or biometrics, get a qualified opinion — that's exactly the tier where the cost of being wrong stops being theoretical.

Where to take this next

For the data-handling layer, see the PDPA Prompting Checklist. For how governance shows up in funding applications, see Singapore & Malaysia AI Grants for SMEs. If you'd rather understand the systems well enough to govern them yourself, the Build School cohort covers what production systems actually do — logs, data, and what breaks — which is the knowledge governance documents usually lack.

Frequently asked questions

Does the EU AI Act apply to a Singapore company?

It can. The Act reaches providers and deployers placing AI systems on the EU market or whose output is used in the EU, regardless of where the company sits. If you have no EU customers and no EU users, it doesn't apply — but check before concluding that, particularly if you sell software.

Does Singapore have an equivalent law?

No binding AI act. Singapore's approach is framework-based and voluntary — IMDA's Model AI Governance Framework and AI Verify. What is binding is the PDPA, which applies to personal data whether or not AI touches it.

What's the minimum a small business should actually do?

Know which systems you use and what they touch, don't use AI for consequential decisions about people without a human in the loop, keep personal data out of prompts, and write down what you decided. Four things, roughly a morning's work.

Do we need ISO 42001 certification?

Almost certainly not, unless a customer contractually requires it or you sell into regulated procurement. It's a real standard with real cost. Reading its structure is useful; certifying against it is a decision driven by a specific commercial requirement, not by prudence.

Want to Apply This to Your Business?

We're a Singapore AI development and automation agency. Let's discuss how we can help solve your specific challenges.