AI Policy Wiki
Dashboard

Singapore Model AI Governance Framework for Generative AI (2024)

high confidence · updated 2026-06-06

Singapore IMDA / AI Verify Foundation framework for trusted generative AI, organised around nine dimensions. Extends the 2019/2020 Model AI Governance Framework.

The Model AI Governance Framework for Generative AI is non-binding government guidance issued on 30 May 2024 by Singapore's Infocomm Media Development Authority (IMDA) and the AI Verify Foundation. It extends the earlier Model AI Governance Framework to generative AI and foundation models across the AI lifecycle, and organises its guidance around nine dimensions. The framework is non-prescriptive government guidance that creates no legal obligations.

Full title: Model AI Governance Framework for Generative AI Enacting body: Infocomm Media Development Authority (IMDA) and AI Verify Foundation Date: 30 May 2024 (issued) Legal status: Non-prescriptive government guidance; non-binding Scope: Generative AI / foundation models across the AI lifecycle

Status and lineage

The framework extends Singapore's first-edition Model AI Governance Framework, published in 2019 and refined in a second edition in January 2020, to cover generative and foundation models. The generative AI extension was developed through a public consultation that ran from 16 January to 15 March 2024 and through engagement with the Frontier Model Forum and industry. It is accompanied by companion initiatives, including the AI Verify testing framework and toolkit (2023) and the Gen AI Evaluation Sandbox.

The nine dimensions

The framework's substantive guidance is organised around nine dimensions:

  1. Accountability — allocation of shared responsibility across model developers, application deployers, and cloud providers, drawing an analogy to cloud computing's Shared Responsibility Model and to product safety regimes.
  2. Data — data quality, trusted sources, respect for personal data and copyright, and dataset governance.
  3. Trusted Development and Deployment — evaluation, safety fine-tuning, system cards, model cards, and lifecycle disclosure.
  4. Incident Reporting — structured incident-reporting processes modelled on aviation and cybersecurity regimes.
  5. Testing and Assurance — third-party testing and common AI testing standards, complementing the AI Verify toolkit.
  6. Security — prompt injection, model theft, adversarial attacks, and novel misuse vectors.
  7. Content Provenance — watermarking, C2PA-style cryptographic provenance, and labelling of AI-generated content.
  8. Safety and Alignment R&D — global cooperation among AI Safety Institutes, together with evaluation, interpretability, and alignment research.
  9. AI for Public Good — democratised access, public-sector adoption, worker upskilling, and sustainability, covering both environmental and inclusion concerns.

International positioning

Singapore presents the framework as a "rule-taker and rule-bridge" designed to be interoperable with other governance instruments rather than to establish equivalence. It positions the framework alongside the OECD AI Principles, the G7 Hiroshima Code of Conduct, the NIST AI Risk Management Framework, the EU AI Act, and the GPAI Code of Practice.

Comparison with other approaches

Against the G7 Hiroshima Code and its 11 Actions, Singapore's nine dimensions map closely but are re-ordered for generative-AI salience and are explicit about the cloud-style shared-responsibility model.

Against the Seoul Commitments and their eight commitments, the Seoul text focuses on frontier-lab obligations with binding-looking language ("don't deploy"), whereas Singapore focuses on ecosystem-wide practice through non-prescriptive guidance.

Against the NIST AI RMF, which uses a four-function Govern/Map/Measure/Manage structure, Singapore uses nine domain dimensions; both are voluntary.

Against the EU AI Act, which is binding, Singapore is guidance and explicitly designs for interoperability rather than equivalence.

Against the China Interim Measures on Gen AI (2023), which use licensing and content-control requirements, Singapore uses shared-responsibility guidance, reflecting different regulatory philosophies.

Debates and limitations

Commentary on the framework has identified several points of tension. Because the framework creates no legal obligations, it relies on market signalling and reputation rather than enforcement. The accountability dimension's shared-responsibility allocation has been described as contested: cloud computing's Shared Responsibility Model works in part because cloud contracts are bilateral, while generative AI value chains are many-to-many and often indirect. The "rule-bridge" positioning depends on the bridged frameworks remaining compatible, and growing divergence among the EU (binding), the United States (state-by-state), and China (content-control) approaches has been cited as making such bridging harder over time. The content-provenance dimension has been noted to run ahead of current technical capability, as robust, tamper-resistant watermarking for generative AI remains an unsolved problem (see G7 Hiroshima Code of Conduct for Advanced AI (2023) Action 7).

Relationships