Blog

Setting up separate governance for generative AI: what Singapore's approach demands of your workflows

Regulators treat generative AI as a distinct governance problem. What the Singaporean and IAPP guidelines demand of your AI workflows involving sensitive data.

· By

Wooden desk in daylight with a paper file on the left, a printed text with one highlighted line in the centre and a handwritten checklist on the right.
Governance for generative AI becomes useful only when controls are demonstrable per workflow, including review steps and data handling.Image: IamVera.ai — original editorial illustration

Treat generative AI as a distinct governance problem: record per workflow where the model is used, which personal data it touches, how you check for hallucinations and bias, and who provides human oversight. Generic AI policies are not enough; you need controls that match the failure modes of generative models.

The prompt is an IAPP analysis of 12 August 2026, "Taming generative AI: Why it must be governed first — and differently", which argues that generative AI must be governed first — and differently — from other AI. The piece uses Singapore's updated Model AI Governance Framework for Generative AI as a concrete example. In our assessment, for professionals handling confidential information this signals a shift: from general "responsible AI" principles towards controls tailored per workflow to what characterises generative models.

What changes now that Singapore wants to regulate generative AI separately?

According to the cited IAPP analysis, Singapore’s updated framework treats generative AI as something that should be governed first — and differently — with proportionate, practical risk management tailored to generative models. This fits a broader movement: in June 2026 the IAPP reported that Singapore's privacy regulator, the PDPC, had published draft guidelines on the use of personal data in generative AI, with a public consultation running until 1 July 2026.

According to the IAPP, those draft guidelines cover the whole lifecycle: development, testing, deployment and procurement. They emphasise consent and a basis for the use of personal data, accountability, limiting hallucination and bias risks, and transparency about where generative AI is used. This is more than a statement of intent — it is lifecycle-wide, generative-specific guidance.

Which risks make governance for generative AI different from that for ordinary AI?

In our assessment, the failure modes of generative models differ substantially from those of classic classification or prediction models. From the Singaporean and PDPC documents, as described by the IAPP, several recurring risks emerge that call for separate treatment:

  • Reuse of training data — personal data may end up in training sets without a clear basis.
  • Hallucinations — the model produces plausible-sounding but incorrect or fabricated output.
  • Bias in output — distortion that only becomes visible in the generated text itself.
  • Personal data during inference — sensitive input forwarded when querying the model.
  • Emergent agentic behaviour — models that independently carry out actions beyond a bounded task.
  • Transparency — the duty to make clear where and how generative AI sits in a product or process.

That these categories are now receiving explicit attention is also evident from the February 2026 supplement to the IAPP AIGP Body of Knowledge (version 2.1): it explicitly adds generative and agentic AI to the curriculum, within a lifecycle- and risk-based governance structure. So the professional canon itself is shifting too, something we also saw in the broader shift from governance principles to concrete control duties.

Which concrete controls do the new guidelines demand per workflow?

We read the guidelines as translating into controls you can assign per workflow. We read the Singaporean and PDPC documents, as described by the IAPP, as pointing toward controls you can assign per workflow, including among others:

  1. Basis for training data — an explicit legitimation for the use of personal data in training.
  2. Risk mitigation for output — measures against hallucinated or distorted results, including a layered approach to hallucination detection.
  3. Data minimisation — as little personal data as possible directed towards the model, which works out concretely as data minimisation in generative AI workflows.
  4. Transparency duty — making known where generative AI is deployed and what its limitations are.
  5. Human oversight and incident response — review steps and a plan for the case where output goes off the rails or sensitive information is shared unintentionally.

The IAPP column "A view from DC" of April 2026 places such controls in a layered model — core functions such as validity, privacy and transparency, above them system integrity and risk management, and governance and enforcement. Under the GDPR, the basis for personal data in particular touches directly on existing obligations. You will find more context in our topic hub on AI governance and control duties.

How do I make those controls visible and testable in my own processes?

We read the common thread across the cited sources as this: governance becomes useful only when controls are demonstrable per workflow — including which review steps were taken, which data handling applied, and which logs exist. In our assessment that is the heart of the work for teams handling sensitive or high-trust information: not a single policy document, but showing per workflow (drafting, summarising, synthetic data, agentic tools) which measures have been implemented and where gaps remain.

A verification layer such as Vera can help here by making verification steps, corrections, disagreement between models and sources visible for inspection. Vera is not a chatbot and not its own language model; it supports control and does not claim to establish correctness, and it makes control possible rather than removing hallucinations. The Semantic Privacy Shield can replace sensitive document values before AI processing with synthetic, session-only equivalents on Vera infrastructure in the EU, where the workflow is designed to forward only that synthesised content; if the privacy check fails, nothing is forwarded. The professional's final judgement always remains with the user. Such tooling adds no governance novelty — the substance lies in the emerging, generative-specific frameworks themselves and in the requirement to make their controls inspectable per workflow.

Sources and references

  1. Taming generative AI: Why it must be governed first — and differentlyIAPP · 2026-08-12
  2. Notes from the Asia-Pacific region: Singapore issues draft guidelines on personal data use in generative AIIAPP · 2026-06-12
  3. February 2026 Supplement to IAPP AIGP Study Guide (AIGP Body of Knowledge version 2.1)IAPP / Wiley · 2026-02-01
  4. A view from DC: Can AI governance catch up to innovation?IAPP · 2026-04-17

Sources: The article draws on IAPP analyses of Singapore's Model AI Governance Framework for Generative AI, the PDPC draft guidelines on personal data in generative AI, and the IAPP AIGP Body of Knowledge supplement.

← All articles in this topic ← All articles