The honest starting position
Singapore has no AI act. There is no local statute that says what you may or may not build with a language model.
That leads a lot of businesses to conclude there's nothing to do, which is wrong for three separate reasons:
1. The PDPA already applies. It governs personal data regardless of whether AI is involved, and "we put it in a chatbot" is not a lawful basis.
2. The EU AI Act has extraterritorial reach. If your output is used in the EU, it can apply to you even with no EU entity.
3. Buyers and grant reviewers now ask. Increasingly a governance question appears in procurement and in grant applications, and "we hadn't considered it" is a scoring problem regardless of the legal position.
None of this requires a compliance function. It requires a written position, which most SMEs don't have and could produce in a morning.
What the EU AI Act actually does
It's a risk-tiered product-safety law, not a data-protection law. That distinction matters because the obligations attach to *what the system decides*, not to what data it holds.
Four tiers, simplified:
- Unacceptable — prohibited outright. Social scoring, certain biometric categorisation, manipulative systems targeting vulnerability.
- High-risk — permitted with substantial obligations. This is the tier that matters commercially: employment and recruitment decisions, credit scoring, education access, essential services, certain safety components.
- Limited risk — transparency duties. Chatbots must not pretend to be human; synthetic media must be disclosed.
- Minimal risk — the overwhelming majority. Spam filters, recommendation engines, most internal productivity tooling.
Where the tiers get misread: most SME use of Claude — drafting, summarising, internal tools, code — sits in minimal risk. The tier jumps when a system materially affects a person's access to a job, credit, education or a service. A CV-screening tool is high-risk. A tool that drafts the job advert is not.
If you're sorting applications by any criterion, read the high-risk annex properly rather than assuming.
Does it reach you?
Three questions, in order:
Do you place an AI system on the EU market? Selling or providing software with an AI component to EU customers, including free.
Is the output used in the EU? This is the one people miss. A Singapore firm producing AI-assisted output for an EU client can be in scope even with no EU presence.
Are you a deployer inside the EU? Only relevant if you have an EU entity or staff.
If all three are no, the Act isn't your concern — write that down with the date and revisit it when you take an EU customer. That note is itself the deliverable: it shows the question was asked.
The extraterritorial reach is genuinely broad, and this is the point at which "check before concluding" stops being boilerplate. If you sell software and you're unsure, get an actual opinion.
What Singapore expects instead
The PDPA is the binding instrument. The relevant obligations are unremarkable and predate AI: consent or another lawful basis, purpose limitation, reasonable security arrangements, and accountability. What AI changes is how easily personal data ends up somewhere unintended — pasted into a prompt, sitting in a chat history, retained by a vendor.
IMDA's Model AI Governance Framework is voluntary and genuinely useful as a structure: internal governance, deciding the level of human involvement, operations management, and stakeholder communication. It's designed to be adopted proportionately.
AI Verify is a testing framework and toolkit. Relevant if you're building systems whose behaviour you need to evidence to a third party. Most SMEs don't need it; those selling into government procurement should know it exists.
ISO 42001 is the certifiable AI management system standard. Reading its structure is instructive. Certifying is a commercial decision — pursue it when a customer requires it, not as general prudence.
A proportionate position for a small business
What we'd actually recommend, and what we do ourselves. Five things, roughly a morning:
1. An inventory. One page. Every AI system in use, what it touches, whether personal data is involved, and whether any decision affecting a person depends on it. Most SMEs discover they have more than they thought — someone's using a transcription tool nobody approved.
2. A human-in-the-loop rule for consequential decisions. Anything affecting someone's employment, credit, or access to a service gets a named human who decides and is accountable. Not a review step nobody performs — a person.
3. A personal-data rule for prompts. No identifiers in prompts unless there's a specific reason and a lawful basis. Practically: redact before pasting. A system prompt that interrupts you when you forget is more effective than a policy nobody rereads.
4. Vendor tier awareness. Know whether your plan excludes your inputs from training. Consumer tiers and business tiers differ, and the difference is material if you handle client information.
5. Write it down, and date it. Two pages. What you use, what you decided, what you ruled out and why. This is what a grant reviewer or a procurement questionnaire is actually looking for, and its absence is what looks bad — not the sophistication of what's in it.
What we would not do at SME scale: hire a compliance consultant, pursue certification speculatively, or build a governance committee. The failure mode for small businesses isn't insufficient process; it's having no written position at all. The two mistakes worth avoiding
Assuming no local law means no obligation. The PDPA applies, EU reach is real, and buyers ask. A one-page position closes all three cheaply.
Over-engineering governance you can't sustain. A policy document nobody follows is worse than a short one that's actually true, because the first creates a documented gap between what you claim and what you do. Write what you actually do. Improve it when something changes.
The proportionate answer for most Singapore SMEs sits between those two, and it's much closer to the light end than compliance marketing suggests.
This isn't legal advice. It's a practitioner's read of where the obligations sit. If you're building anything that touches employment, credit, education access, or biometrics, get a qualified opinion — that's exactly the tier where the cost of being wrong stops being theoretical.
Where to take this next
For the data-handling layer, see the PDPA Prompting Checklist. For how governance shows up in funding applications, see Singapore & Malaysia AI Grants for SMEs.
If you'd rather understand the systems well enough to govern them yourself, the Build School cohort covers what production systems actually do — logs, data, and what breaks — which is the knowledge governance documents usually lack. Want to Apply This to Your Business?
We're a Singapore AI development and automation agency. Let's discuss how we can help solve your specific challenges.