Representatives from 22 local technology firms, three research institutes and four civil society organisations met at one-north on Tuesday to outline voluntary safety practices for generative artificial intelligence deployed in customer-facing products. The forum did not produce binding regulation — IMDA and the Personal Data Protection Commission attended as observers — but participants said the commitments will inform a broader industry code expected before year-end.
What companies agreed to document
The published summary, released Wednesday morning, lists five areas of common practice: dataset documentation for training and fine-tuning; pre-launch red-team testing for harmful outputs; incident reporting timelines when models produce unsafe content at scale; human review pathways for high-risk use cases; and clear labelling when content is AI-generated in consumer interfaces.
Each participating company submitted a one-page statement describing how it applies these practices internally. The statements are not audited by regulators and will not be published individually; only aggregate themes appear in the summary. A spokesperson for one participating fintech firm said the value lies in establishing shared vocabulary before formal guidance arrives. "Regulators have asked what 'reasonable testing' means — this forum is an attempt to show what firms already do," the spokesperson said on background.
Research and civil society perspectives
Researchers from a local university's AI ethics lab presented findings on bias testing in multilingual models used for customer service chatbots in Singlish and Mandarin code-switching contexts. Their paper, shared with attendees but not yet peer-reviewed, found higher error rates in financial product explanations when queries mixed languages — a gap that standard English-only benchmarks did not capture.
A digital rights group present at the forum asked for mandatory disclosure when AI systems influence credit scoring or hiring recommendations. That recommendation was noted in the summary but did not receive consensus support from corporate participants, who argued sector-specific rules may be more appropriate than horizontal requirements.
Regulatory context in Singapore
IMDA has previously issued model AI governance frameworks for organisations, updated in 2024, but compliance remains advisory rather than compulsory for most private-sector deployments. PDPC continues to enforce the Personal Data Protection Act where AI systems process personal data; the commission issued two enforcement decisions this year involving inadequate consent for automated profiling, though neither case involved generative models specifically.
The Cyber Security Agency separately publishes advisories on AI-related phishing templates — a topic our desk covered last week when payroll staff across several SMEs received deepfake voice messages impersonating finance directors. CSA's guidance emphasises verification callbacks rather than technical controls alone.
Small business exposure
Enterprise Singapore's SME sentiment survey for the second quarter showed 58 percent of respondents expecting stable or higher export orders in the following six months, down from 64 percent in the first quarter. Firms with revenue below $10 million cited payment delays from overseas buyers as a growing concern, particularly in consumer goods categories. The survey is indicative rather than predictive; we cite it to show how trade headline numbers interact with smaller firms that employ a significant share of Singapore's manufacturing workforce.
What comes next
IMDA said it will review the forum summary alongside feedback from a public consultation that closes 30 September. Participants expect a draft code of practice by November, potentially covering incident reporting channels and minimum documentation standards for firms above a yet-to-be-defined revenue threshold.
For organisations evaluating AI deployments, PDPC's data protection guidelines and IMDA's model governance framework remain the primary reference documents. Our technology desk translates agency advisories into plain-English summaries when major updates are published.