What does a Singapore SME actually have to do, and by when, to comply with MAS AIRG, IMDA MGF for Generative AI, the EU AI Act, the PDPC AI Advisory Guidelines and the CSA-MAS Joint Advisory?
The Answer in 60 Seconds
Singapore's AI governance papers of March 2024 to November 2025 are mostly guidance: MAS information papers, an IMDA framework of practical suggestions and PDPC advisory guidelines. MAS's proposed AI Risk Management Guidelines would set supervisory expectations for financial institutions but had not been issued as at 1 October 2026, and the EU AI Act sets dated obligations for firms within its scope. (1) MAS Information Paper on AI Model Risk Management dated 5 December 2024 (Circular ID 18/24) sets out three pillars - governance & oversight, key risk management systems, development & validation controls - which MAS observed in a review of selected banks and encourages all financial institutions to reference when developing and deploying AI. (2) MAS Consultation Paper P017-2025, Guidelines on AI Risk Management (the "AIRG"), was issued on 13 November 2025; consultation closed 31 January 2026; MAS proposed a 12-month transition period after the Guidelines are issued, and had not issued them as at 1 October 2026. (3) IMDA Model AI Governance Framework for Generative AI (May 2024) offers practical suggestions for organisations developing and deploying generative AI, and the AI Verify Testing Framework (updated 29 May 2025 to cover generative AI) lets organisations assess an AI system against 11 governance principles. (4) PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (1 March 2024) clarifies the Business Improvement, Research and Legitimate Interests Exceptions, and is advisory and not legally binding. (5) The EU AI Act (Regulation 2024/1689) entered force 1 August 2024 and bites Singapore SMEs extraterritorially - prohibited practices since 2 February 2025, GPAI obligations since 2 August 2025, high-risk obligations from 2 December 2027 and, for high-risk AI in products covered by Annex I, from 2 August 2028 (dates set in July 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744). Maximum EU fine: €35 million or 7% of global turnover, whichever is higher. The CSA-MAS-SPF Joint Advisory on Scams Involving Digital Manipulation (12 March 2025) and the MAS Information Paper on Cyber Risks Associated with Generative AI (30 July 2024) supply the cyber-risk overlay. The ASEAN Guide on AI Governance and Ethics (February 2024, expanded January 2025) supplies the regional baseline. The EU AI Act binds SMEs within its scope and the PDPA binds any organisation using personal data; the MAS information papers, the IMDA framework and the PDPC advisory guidelines are guidance.

The Sourced Detail
Between March 2024 and the close of the AIRG consultation on 31 January 2026, Singapore's regulators published the guidance below, and MAS consulted on Guidelines that would set supervisory expectations for financial institutions. The IMDA framework offers practical suggestions and the PDPC guidelines are advisory and not legally binding; the PDPA itself, and the EU AI Act for SMEs within its scope, are law.
1. MAS Information Paper on AI Model Risk Management - 5 December 2024
The MAS Information Paper on AI Model Risk Management was issued on 5 December 2024 under Circular ID 18/24, which MAS's Insurance Department sent to the chief executives of all licensed insurers and the Lloyd's Asia Scheme. MAS encourages all financial institutions to reference the paper's good practices.
The MAS Information Paper on AI Model Risk Management sets out three pillars:
Pillar 1 - Oversight and governance. Cross-functional AI oversight forums; AI policies and standards; training programmes; senior management accountability for material AI systems.
Pillar 2 - Key risk management systems and processes. AI inventory; materiality assessment frameworks calibrated by impact, complexity and reliance; third-party AI vendor governance; data lineage and quality controls.
Pillar 3 - Development, validation and deployment. Pre-deployment testing; ongoing monitoring; model drift detection; human-in-the-loop checkpoints; explainability; documentation.
MAS's stated intent in the paper is that "the good practices highlighted in this information paper should generally apply to other financial institutions". The paper adds that MAS was considering supervisory guidance for all FIs building on its focus areas, and MAS's November 2025 consultation paper says the proposed Guidelines build on its information papers.
2. MAS Consultation Paper P017-2025 - Guidelines on AI Risk Management
On 13 November 2025, MAS issued Consultation Paper P017-2025, Consultation Paper on Guidelines on Artificial Intelligence Risk Management. The consultation closed on 31 January 2026; MAS had not issued the final guidelines (the "AIRG") as at 1 October 2026 (on 20 March 2026 it said it was reviewing the consultation responses), and it proposed a 12-month transition period after the Guidelines are issued.
The proposed AIRG, which MAS says builds on the FEAT principles, its work with industry and its information papers on AI risks (including the December 2024 Information Paper), would set MAS's supervisory expectations on AI risk management for all financial institutions (as defined in section 2 of the Financial Services and Markets Act 2022), applied in a proportionate manner across institutions of different sizes and risk profiles.
Per the MAS consultation paper on Guidelines on Artificial Intelligence Risk Management (P017-2025, 13 November 2025), the AIRG covers:
- AI inventory for all systems used by the FI, including third-party AI embedded in vendor products. Materiality dimensions: impact (severity if AI fails), complexity (interpretability of the model), reliance (degree of human-in-the-loop oversight).
- Board-level oversight with documented accountability for AI risk at senior management and board level.
- Clear roles and responsibilities for managing AI risks across business lines and functions, with a control function assigned to make sure risk materiality is assessed consistently.
- Full lifecycle controls from data acquisition through development, testing, deployment, monitoring and decommissioning.
- Third-party AI governance including testing third-party AI in the FI's own use cases, processes to receive notice of updates or changes to third-party AI, due diligence on the fairness practices of third-party AI providers, contingency plans for vendors discontinuing support, and legal agreements with clauses on matters such as performance guarantees, data protection, the right to audit and notification when AI is introduced.
- Generative AI and AI agents receive express treatment, drawing on MAS's Project MindForge (an MAS-led industry initiative whose consortium now spans banking, insurance and capital markets) and the FEAT principles (Fairness, Ethics, Accountability, Transparency), which MAS co-created with the industry in 2018 and which the Veritas Initiative helps FIs put into practice.
Project MindForge published its AI Risk Management Toolkit, including an AI Risk Management Operationalisation Handbook aligned with MAS's proposed Guidelines and a supplement of AI case studies, on 20 March 2026.
3. IMDA Model AI Governance Framework for Generative AI - 30 May 2024
The Model AI Governance Framework for Generative AI, released by the Infocomm Media Development Authority and the AI Verify Foundation on 30 May 2024 after consultation on a January 2024 draft, offers practical suggestions that any organisation developing or deploying generative AI can use, not only MAS-regulated FIs. The MGF for Generative AI is structured around nine governance dimensions:
- Accountability - clear allocation of responsibility across the AI value chain.
- Data - provenance, quality, bias, copyright and privacy of training and inference data.
- Trusted development and deployment - model cards, system cards, robust evaluation.
- Incident reporting - structured process for detecting, escalating and remediating AI incidents.
- Testing and assurance - pre-deployment and continuous testing aligned to AI Verify.
- Security - adversarial robustness, prompt injection defences, model and weight protection.
- Content provenance - watermarking, C2PA-style provenance tagging, deepfake disclosure.
- Safety and alignment R&D - investment in research into model alignment with developer/deployer intent.
- AI for public good - equitable access, bridging the digital divide, sustainable AI.
The companion AI Verify Testing Framework, rather than the MGF itself, is mapped to the NIST AI Risk Management Framework (and its Generative AI Profile), ISO/IEC 42001:2023 (the AI Management System standard) and the Hiroshima Process Code of Conduct, and the AI Verify Foundation describes it as aligned with frameworks from ASEAN, the EU, the OECD and the US.
The companion AI Verify open-source toolkit - administered by the AI Verify Foundation - provides 11 governance principles tested through 50+ technical and process tests, including hallucination/inaccuracy, bias detection, undesirable content classification, data leakage, adversarial vulnerability, transparency, explainability and human-AI configuration. The AI Verify Testing Framework was updated on 29 May 2025 to cover generative AI as well as traditional AI.
4. PDPC Advisory Guidelines on Use of Personal Data in AI - 1 March 2024
The PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, issued on 1 March 2024, are advisory and not legally binding: they explain when organisations can use personal data to develop and deploy AI systems under the existing PDPA.
The Advisory Guidelines clarify three exceptions to the consent requirement under the PDPA:
- Business Improvement Exception (PDPA First Schedule Part 5, and Division 2 of Part 2 of the Second Schedule). Permits use of personal data for product/service improvement, subject to assessment that benefits are commensurate with privacy intrusion.
- Research Exception (PDPA Second Schedule Part 2 Division 3). Permits research use subject to safeguards.
- Legitimate Interests Exception (PDPA First Schedule Part 3). Permits use where the legitimate interest of the organisation outweighs the adverse effect on the individual, subject to a documented assessment.
For each exception, the PDPC sets transparency, accountability and Data Protection Impact Assessment (DPIA) expectations. The PDPC encourages organisations using personal data to develop AI systems to conduct a Data Protection Impact Assessment.
The guidelines also articulate explainability expectations: the level of explainability provided to affected individuals should be calibrated to the impact of the AI decision on them. Where an outcome has a higher impact on the individual, the guidelines suggest organisations consider explaining the accountability, human oversight and safeguards in place.
5. CSA-MAS-SPF Joint Advisory on Scams Involving Digital Manipulation - 12 March 2025
The CSA-MAS-SPF Joint Advisory on Scams Involving Digital Manipulation of 12 March 2025 is the operational counterpart to the MAS Information Paper on Cyber Risks Associated with Generative AI issued on 30 July 2024.
The MAS July 2024 paper identifies four categories of GenAI-driven cyber risk:
- Deepfakes and GenAI-enabled phishing, including impersonation of people the victim trusts.
- Malware generation and enhancement.
- Data leakage from GenAI deployment, including through prompt injection attacks.
- GenAI model and output manipulation, such as data poisoning.
The March 2025 Joint Advisory advises businesses to set protocols for staff to verify video calls and messages said to come from senior executives, to verify sudden or urgent fund-transfer instructions through established channels, and to alert staff who make fund transfers. The Singapore Police Force Annual Scams and Cybercrime Brief 2024 reported at least S$1.1 billion in scam losses in 2024, up 70.6% from at least S$651.8 million in 2023, and said the increase was driven by a small number of cases with very high losses.
6. EU AI Act - extraterritorial reach for Singapore SMEs
The EU AI Act, Regulation (EU) 2024/1689, was published in the Official Journal of the European Union on 12 July 2024 and entered force on 1 August 2024. Its phased commencement runs as follows:
- 2 February 2025 - prohibited AI practices apply (social scoring, real-time remote biometric ID in public spaces, manipulative AI exploiting vulnerabilities, etc.).
- 2 August 2025 - General Purpose AI (GPAI) obligations and the new EU AI Office's powers come into effect.
- 2 December 2027: high-risk AI obligations apply to Annex III systems (moved from 2 August 2026 by Regulation (EU) 2026/1744; the main compliance burden for most SMEs in scope).
- 2 August 2028: high-risk obligations for AI in products covered by the Union harmonisation legislation in Annex I, such as medical devices and toys (moved from 2 August 2027 by Regulation (EU) 2026/1744).
The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025, was adopted as Regulation (EU) 2026/1744 of 8 July 2026 (published 24 July 2026), which moved the high-risk dates to 2 December 2027 (Annex III systems) and 2 August 2028 (Annex I products).
A Singapore SME falls within the AI Act's scope when any of the following apply:
- It places an AI system on the EU market (sells, licenses, deploys, makes available - even free of charge);
- The AI system's output is used in the EU (regardless of where the SME is based);
- The SME is a distributor making an AI system available on the EU market (importers and authorised representatives are, by definition, located or established in the EU).
A Singapore SaaS SME with EU customers - even one EU customer - falls within scope if the AI system's output is used by that customer in the EU, per the extraterritorial provisions of Article 2 of the EU AI Act (Regulation (EU) 2024/1689).
Maximum penalties under Article 99 of the AI Act:
- €35 million or 7% of global turnover, whichever is higher, for prohibited AI practices.
- €15 million or 3% of global turnover for high-risk AI obligations breaches.
- €7.5 million or 1% of global turnover for incorrect or misleading information to authorities.
For a Singapore SME, Article 99(6) caps each fine at whichever of the two figures is the lower - so for an SME with S$50 million in global turnover, the prohibited-practice exposure is approximately S$3.5 million (7% of turnover), broadly comparable to the equivalent PDPA cap of S$5 million (10% of annual Singapore turnover).
7. ASEAN Guide on AI Governance and Ethics - regional baseline
The ASEAN Guide on AI Governance and Ethics was endorsed by ASEAN Digital Ministers on 2 February 2024. The expanded ASEAN Guide on AI Governance and Ethics - Generative AI supplements the 2024 Guide with policy considerations for generative AI.
The Guide does not have legal force but provides a regional baseline that ASEAN members (Singapore, Malaysia, Indonesia, Thailand, the Philippines, Vietnam, Brunei, Cambodia, Laos, Myanmar and, since 26 October 2025, Timor-Leste) can use to align national approaches. For Singapore SMEs operating cross-border in ASEAN, the Guide is a practical reference for vendor and partner due diligence in jurisdictions whose national AI frameworks are less mature.
The Compliance Timeline - Month-by-Month
The following calendar consolidates the key dates. Dates marked (LIVE) are already in force or, for guidance papers, already published; dates marked (SCHEDULED) are formally announced; dates marked (EXPECTED) are reasonably foreseeable based on consultation timelines and government statements.
Already in force or published
- 1 March 2024 (LIVE) - PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems. Action: DPIA programme, transparency disclosures, explainability documentation, consent or exception assessment.
- 30 May 2024 (LIVE) - IMDA Model AI Governance Framework for Generative AI. Action: align governance to nine dimensions; run AI Verify against customer-facing AI.
- 30 July 2024 (LIVE) - MAS Information Paper on Cyber Risks Associated with Generative AI. Action: assess GenAI-specific cyber controls; deepfake training; prompt injection defences.
- 1 August 2024 (LIVE) - EU AI Act enters force. Action: scoping assessment for any EU touchpoint.
- 2 February 2025 (LIVE) - EU AI Act prohibited practices. Action: confirm no prohibited use cases (social scoring, real-time biometric ID, manipulative AI etc.).
- 5 December 2024 (LIVE) - MAS Information Paper on AI Model Risk Management (Circular ID 18/24). Action: align governance to three pillars; AI inventory; materiality assessment; FEAT integration.
- 12 March 2025 (LIVE) - CSA-MAS-SPF Joint Advisory on Scams Involving Digital Manipulation. Action: callback verification; multi-channel approval; deepfake training.
- 2 August 2025 (LIVE) - EU AI Act GPAI obligations. Action: if you place a GPAI model on the EU market, technical documentation, copyright compliance, training-data summaries.
Currently scheduled or expected
- 31 January 2026 (PASSED) - MAS AIRG consultation closed.
- Not yet issued (as at 1 October 2026): MAS issues final AIRG; on 20 March 2026 MAS said it was reviewing the consultation responses. The proposed 12-month transition begins on issuance.
- 2 December 2027 (SCHEDULED, moved from 2 August 2026 by Regulation (EU) 2026/1744): EU AI Act high-risk obligations apply to Annex III systems. Action for SMEs serving EU: CE-equivalent conformity assessment, technical documentation, registration, post-market monitoring.
- 20 March 2026 (PUBLISHED): Project MindForge AI Risk Management Toolkit, including an AI Risk Management Operationalisation Handbook aligned with MAS's proposed Guidelines.
- End-2027 (SCHEDULED) - Workplace Fairness Act 2025 + Workplace Fairness (Dispute Resolution) Act 2025 commence (relevant to AI hiring tools - see article on AI bias in hiring).
- 12 months after the final AIRG is issued (proposed): MAS AIRG transition period ends.
- 2 August 2028 (SCHEDULED, moved from 2 August 2027 by Regulation (EU) 2026/1744): EU AI Act high-risk obligations apply to AI in Annex I products.
What Singapore SMEs Can Do Now: A 7-Step Operational Programme
The following programme is calibrated to a Singapore SME with 25-250 employees. Smaller SMEs may compress steps; larger SMEs may need additional resources but the structure remains.
Step 1 - Establish board-level AI oversight (next 30 days)
In an SME, AI decisions can fall to whoever happens to be running the deployment - an HR director picks Workday, a marketing lead picks Midjourney, a software lead picks GitHub Copilot. MAS's proposed AIRG would expect financial institutions to set clear roles and responsibilities for managing AI risks, and accountability is the first of the IMDA MGF's nine dimensions.
The minimum structure: a designated AI risk owner at C-suite level (in MAS-regulated FIs, the Chief Risk Officer or equivalent; in non-regulated SMEs, typically the CFO or COO); a documented AI policy approved at board level; quarterly board reporting on AI risk.
For SMEs <25 employees, the AI risk owner may be the founder/CEO.
Step 2 - Build the AI inventory (next 60 days)
The AI inventory is the foundation of every other control. The minimum data fields:
- AI system name, vendor and version.
- Business owner.
- Use case description (what the AI does, who it affects, what decisions it informs or makes).
- Data inputs (personal data flag; PDPA categorisation; cross-border flow flag).
- Data outputs (downstream system; affected individuals).
- Materiality dimensions per AIRG: impact (severity if AI fails - none / low / medium / high / critical); complexity (interpretability - fully transparent / partially interpretable / black-box); reliance (human oversight - full / sample / none).
- Risk classification under EU AI Act if any EU touchpoint (prohibited / high-risk / limited risk / minimal risk).
- Vendor warranties summary (training data IP, indemnification, breach notification, exit).
- Last AI Verify or equivalent test date.
- Last DPIA date.
The inventory itself is often the most valuable artefact.
Step 3 - Run AI Verify on at least one customer-facing AI system (next 90 days)
The AI Verify open-source toolkit is free. Run it against your highest-impact customer-facing AI - typically a customer-service chatbot, a recommendation engine, or a content-generation tool. The output is a structured report covering hallucination/inaccuracy, bias, undesirable content, data leakage and adversarial vulnerability. It will surface concrete remediation items.
For SMEs serving the EU, the AI Verify Foundation describes its testing framework as aligned with international frameworks, including those of the European Union.
The Global AI Assurance Pilot (Feb-May 2025, with subsequent expansions) paired 17 deployers across 10 sectors with 16 specialist testers, and named an accreditation framework for testers as an area for future work.
Step 4 - Audit existing insurance for AI gaps (next 90 days)
Walk the existing tower:
- Professional Indemnity / Tech E&O - does the wording expressly cover AI-driven errors? Or is AI silent? Are there AI sub-limits? Lockton's Preet Gill noted in the Financial Times that "a general policy that covers up to $5mn in losses might stipulate a $25,000 sublimit for AI-related liabilities." Identify any sub-limit and quantify the gap.
- Cyber Liability - does the wording cover AI-as-attack-surface (deepfake-enabled FTF, AI-driven phishing, prompt injection)? What is the FTF sub-limit? Is the social-engineering endorsement bought?
- Media / Multimedia Liability - for content-generating SMEs, does the wording cover AI-output IP claims? "Intentional infringement" exclusions are a frequent friction point.
- D&O - does the wording respond to a shareholder or regulator action arising from an AI governance failure? Singapore SMEs heading toward IPO or regulated counterparty relationships should review.
- EPL - does the wording cover algorithmic bias claims under the WFA 2025? Retroactive date alignment with the WFA commencement (end-2027) is critical.
Step 5 - Build vendor warranty discipline (next 120 days)
Every AI procurement contract from this point should include:
- Training-data IP provenance warranty - vendor confirms training data was lawfully obtained and does not infringe third-party IP.
- Hallucination / error-rate warranty - vendor confirms tested error rates at deployment; obligation to report material increases.
- Bias testing obligations - vendor commits to defined bias-testing cadence and disclosure (critical for HR / lending / insurance underwriting use cases under Singapore WFA 2025 and PDPC March 2024 guidelines).
- Security and breach notification - aligned to PDPA section 26D 3-day notification.
- Indemnification for IP and privacy claims - including third-party copyright, trademark, defamation arising from AI output.
- Data residency for PDPA compliance - confirmation of where training and inference data are processed.
- Exit and transition - data return, model deletion, runoff support.
Major vendor commitments to look for: Adobe Firefly indemnity (commercial-safe training); Microsoft Customer Copyright Commitment for Copilot output (announced September 2023); OpenAI Copyright Shield; Anthropic indemnification. These are useful starting points but each has carve-outs that SMEs should review with counsel.
Step 6 - Update incident-response playbook (next 120 days)
MAS's proposed AIRG would expect policies for updating the Board and senior management on AI-related incidents, and incident reporting is one of the IMDA MGF's nine dimensions. The minimum incident-response playbook:
- AI-incident definition - error, hallucination, bias finding, data leakage via AI output, adversarial attack, agent rogue action, deepfake-driven fraud attempt.
- Detection mechanisms - observability tooling, customer complaints, regulatory notice, third-party security researcher disclosure.
- Triage - first-hour assessment of impact, scope, regulatory triggers (PDPC s.26D, MAS incident reporting if FI (see MAS's Circular on Financial Institution Incident Reporting, 16 December 2025), EU AI Act incident reporting if EU touchpoint).
- Containment - kill-switch protocols, model rollback, public-facing advisory.
- Notification - PDPC within 3 calendar days if PDPA breach; insurer within policy notification window; affected individuals; regulators.
- Documentation - Annex B-style structured documentation for PDPC; AIRG-aligned root-cause analysis.
Step 7: Plan for the final AIRG and the EU AI Act high-risk dates (next 12 months)
For MAS-regulated FIs: MAS has proposed a 12-month transition from issuance of the final AIRG, which had not been issued as at 1 October 2026. SMEs should map current state against the consultation paper now, not wait for the final text.
For SMEs serving the EU: the high-risk deadline (2 December 2027 for Annex III systems, under Regulation (EU) 2026/1744) requires a conformity-assessment-equivalent process for any high-risk AI system. Singapore's MGF and AI Verify do not substitute for the EU's specific conformity-assessment pathway.
Singapore Insurance Market Context
The Singapore commercial insurance market in late 2025 / early 2026 is in a soft phase: per the Marsh Global Insurance Market Index Q4 2025, Asia composite rates fell 5%; Asia cyber rates fell 10%; global cyber rates fell 7%. This is the sixth consecutive quarter of global rate decline.
Per Mordor Intelligence's Singapore Cyber Liability Insurance Market report (January 2026), the Singapore cyber market is projected to grow from USD 56.72 million in 2025 to USD 94.73 million by 2031 - an 8.93% CAGR. Standalone cyber covers held 53.65% market share in 2025; BFSI accounted for 29.55%.
The soft market presents Singapore SMEs with a time-limited window to negotiate affirmative AI wording into existing PI / Tech E&O / Cyber / Media policies before insurers harden their position. Marsh reported for Asia in Q4 2025 that insurers updated cyber policies for generative AI risks.
For SMEs needing dedicated AI cover today, the Singapore-distribution status of named products is:
- AXA XL CyberRiskConnect with Gen AI Endorsement - confirmed available in Asia per AXA XL's own 21 October 2024 press release. Targets businesses developing their own Gen AI models; AXA XL describes its clients as mid-sized companies through to large multinationals. Note: AXA XL is the global commercial / specialty arm of AXA Group, separate from the former AXA Insurance Singapore retail business that was acquired by HSBC in 2022 and rebranded HSBC Life Singapore.
- Munich Re aiSure / Mosaic-aiSure - global product launched 26 February 2026 with EUR/USD/CAD 15 million in initial capacity; distributed via Mosaic's cyber specialists worldwide.
- Armilla AI Liability with Chaucer - standalone product launched 30 April 2025, underwritten by Lloyd's underwriters including Chaucer; since 10 February 2026 also offered with Chaucer's cyber and technology E&O cover as Vanguard AI, with AI liability aggregate limits of US$25 million or more per organisation. Lockton offers Armilla's products to its clients; Armilla says its products may not be available in all jurisdictions.
- Coalition Active Cyber Policy with Affirmative AI Endorsement - US Surplus Lines and Canada only.
- Coalition Deepfake Response Endorsement - US, UK, Canada (incl. Quebec), Australia, Germany, Denmark, Sweden, France only. Not Singapore.
What This Means for Your Business
Five practical points.
MAS's proposed AIRG transition would begin on issuance, not on the consultation paper date. SMEs that are MAS-regulated should treat the 12 months after the final AIRG is issued as the implementation window; MAS had not issued it as at 1 October 2026. Map current state to the consultation paper now to avoid a last-minute scramble.
The PDPA applies to every Singapore SME that uses personal data in AI, not just FIs, and the PDPC's March 2024 guidelines explain how. A marketing agency, an HR consultancy or a software firm that feeds personal data into an AI system is bound by the PDPA; the PDPC guidelines are advisory, and the IMDA MGF offers practical suggestions any organisation can use.
The EU AI Act reaches providers and deployers outside the EU. A Singapore SaaS SME with even one EU customer using AI output in the EU is in scope. The high-risk deadline, now 2 December 2027 for Annex III systems under Regulation (EU) 2026/1744, requires conformity-assessment readiness; AI Verify output does not substitute for it.
Your existing PI / Tech E&O / Cyber / Media / D&O / EPL stack needs a deliberate AI gap audit. The soft market gives you negotiating room now; that window will close as insurers harden wordings.
A licensed adviser can match your current programme to an AI-aware programme. Where you ask, Covarage introduces you to a licensed adviser, who gives the advice and places the cover; Covarage does not recommend a specific product.
Questions to Ask Your Adviser
- Does my current PI / Tech E&O wording expressly cover AI-driven errors, hallucinations, defamation arising from AI output, IP infringement from AI output, and bias claims - or is AI silent? What is the AI sub-limit?
- Does my cyber wording respond to deepfake-driven funds-transfer fraud, prompt injection, and AI-driven privacy breaches? What is the FTF sub-limit and is the social-engineering endorsement bought?
- Does my D&O wording respond to a shareholder or regulator action arising from an AI governance failure under MAS AIRG?
- Does my EPL wording respond to algorithmic bias claims under the Workplace Fairness Act 2025 / WFDRA 2025? What is the retroactive date and does it align with the WFA commencement (end-2027)?
- Is the AXA XL CyberRiskConnect Gen AI Endorsement available through my broker, and does my Singapore SME meet AXA XL's underwriting threshold?
- If I serve EU customers, does my current programme respond to EU AI Act regulatory defence costs and fines (where insurable)?
- Where my AI vendor offers indemnification (Adobe Firefly, Microsoft Copyright Commitment, OpenAI Copyright Shield, Anthropic indemnification), how does the indemnity interact with my own insurance - does my insurer require subrogation, and does the vendor's cap leave a residual gap I should insure?
Related Information
- Cybersecurity (Amendment) Act 2024: What's In Force Now (and What Isn't)
- PDPA Amendment: 10% Turnover Penalty for Data Breaches
- Workplace Fairness (Dispute Resolution) Act 2025: Statutory Tort of Discrimination, ECT Jurisdictional Uplift, and EPL Cover for Singapore SMEs
- When Your Chatbot Lies: Misrepresentation Liability for Singapore SMEs
- When Your AI Agent Goes Rogue: Insurance Implications for Singapore SMEs After the Replit Database Wipe
- Deepfake Funds-Transfer Fraud: What Singapore SMEs Need to Know About Cyber, Crime, and Social Engineering Insurance
- AI-Generated Content and Copyright: Where a Singapore SME's Exposure Sits in 2026, and What the Published Wordings Say
- When the Algorithm Says No: AI Bias in Hiring and Promotion as an EPL Risk for Singapore SMEs
- AI-Generated Code Security Vulnerabilities: A Cyber, Tech E&O, PI and Product Liability Risk for Singapore SMEs
