No AI Act Needed: Why Singapore's Three-Layer Governance Model Prizes Proof Over Statutes
Source: Tech For Good Institute
Most countries responding to the AI wave have reached for one big, comprehensive law. Singapore has deliberately done the opposite — and a new analysis from the Tech For Good Institute, written by SMU law and computer science professor Lim How Khang, lays out exactly how the model is supposed to work.

Most countries responding to the AI wave have reached for one big, comprehensive law. Singapore has deliberately done the opposite — and a new analysis from the Tech For Good Institute, written by SMU law and computer science professor Lim How Khang, lays out exactly how the model is supposed to work. The core argument: Singapore has not enacted a horizontal AI law, has no immediate plans to, and instead runs on three layers — an enforceable baseline of existing statutes, swift targeted legislation when gaps appear, and an assurance layer that lets firms prove their AI systems are safe.
The first layer leans on laws that predate the AI boom: the Personal Data Protection Act for data handling, the Cybersecurity Act for critical systems, the Online Criminal Harms Act for scam and impersonation activity, and POFMA for AI-generated falsehoods. Sector regulators layer AI-specific expectations on top — MAS in finance, for example — and the Workplace Fairness Act will bar algorithmic hiring decisions based on protected characteristics from late 2027. Enforcement is the credibility engine: the Personal Data Protection Commission has published decisions since 2016, including the S$1 million SingHealth penalty, while MAS hit nine financial institutions with S$27.45 million in composition penalties in July 2025.
The second layer is speed. When AI-generated deepfakes of candidates emerged as an election-integrity risk that existing falsehoods laws could not squarely cover, Parliament passed a targeted amendment to election advertising rules in about five weeks in late 2024. Persistent scam pressure produced the Protection from Scams Act 2025, which lets police issue time-bound Restriction Orders on bank accounts suspected of feeding fraud. The pattern, as the paper puts it, is to regulate the harm wherever it arises, whatever the technology behind it — and each targeted statute thickens the baseline the whole model rests on.
The third layer — assurance — is where Singapore is trying to build a global niche. Tools like AI Verify and the Global AI Assurance Sandbox let companies evidence how their systems perform against governance principles, turning trust into testable output that can support compliance, procurement and stakeholder confidence. Minister Josephine Teo has framed safety not as a brake on innovation but as part of Singapore's value proposition: businesses and citizens adopt AI only when they are confident it is governed. The bet, the author concludes, is that "the scarcest commodity is not regulation, but proof" — with the ASEAN Digital Economy Framework Agreement, slated for signature late this year, as the early test of whether regional rules converge on shared assurance standards.
Why it matters for Singapore: This three-layer architecture is the framework behind almost every AI policy story covered on this site — from IMDA's agentic AI guidance to MAS's AI risk guidelines and PDPC's data protection advisories. Understanding it matters because it predicts how Singapore will respond to the next AI crisis: not with a sweeping statute, but with a targeted fix and an assurance standard. For businesses, it means compliance is less about one big law and more about demonstrating, measurably, that their AI behaves as claimed.


