HomeBlogDigital Infrastructure
Digital Infrastructure

What Should a Singapore SME's AI Usage Policy Cover?

What Should a Singapore SME's AI Usage Policy Cover?

A Singapore SME's AI usage policy needs to cover six things: which AI tools are approved, what data may never be entered into them, who is accountable for checking AI output before it reaches a customer, when AI involvement must be disclosed, how AI-assisted work is recorded, and how often the policy is reviewed. That is it. Two pages, written in plain English, signed by every staff member. Anything longer will not be read, and a policy nobody reads offers no protection under the Personal Data Protection Act if a complaint lands on your desk.

The urgency is not theoretical. Most SMEs we speak to discover, when they actually ask, that between a third and half their staff are already pasting customer enquiries, quotations, resumes and supplier contracts into free AI chatbots. Nobody told them not to. That gap between actual practice and written rules is the real exposure — and it widens every month you leave it alone.

Why does an SME need a written AI policy at all?

Because under PDPA, you remain the organisation responsible for personal data you collect, regardless of which tool your staff chose to process it in. If an employee uploads a spreadsheet of 400 customer names, mobile numbers and delivery addresses into a consumer AI service to "clean it up", you have disclosed personal data to a third party without consent, and quite possibly transferred it outside Singapore without the transfer safeguards the Act requires.

A written policy does three practical jobs. It gives staff a clear line they can follow without guessing. It demonstrates you took reasonable steps, which matters if the PDPC ever asks. And it sets the boundary you will need later — because the day you deploy an AI agent that actually touches orders, invoices or customer records, you will need governance already in place, not invented in a panic.

Which AI tools should you actually approve?

Name them explicitly. A policy that says "use approved AI tools" without listing them is not a policy. For a typical Singapore SME, the approved list looks something like: the paid business tier of one general assistant, whatever AI features are already built into your existing Microsoft 365 or Google Workspace subscription, and any purpose-built tool you have contracted with a proper data processing agreement.

The distinction that matters most is business tier versus free tier. Paid business and enterprise plans from the major providers contractually exclude your inputs from model training and give you an actual data processing agreement to point at. Free consumer accounts generally do not. That single upgrade — often under S$40 per user per month — removes the largest single source of AI-related data risk in most SMEs. It is the cheapest compliance spend available to you.

Everything not on the list is prohibited by default, with a named person who can approve additions. Keep that approval route open and fast, or staff will simply route around you.

What data should never go into an AI tool?

This is the section your staff will actually reference, so make it concrete rather than abstract. Categories that should be off-limits regardless of tool tier:

Then give the workaround, because prohibition without an alternative gets ignored. Staff can strip identifiers before pasting: replace names with "Customer A", remove phone numbers, delete the NRIC column. Most AI tasks — drafting a reply, summarising a complaint, rewriting a proposal — work perfectly well on de-identified text. Teach that habit once and it sticks.

Who checks AI output before a customer sees it?

Name a human for every category of AI-assisted output. The rule we recommend is simple: whoever sends it, owns it. If a coordinator uses AI to draft a quotation, the coordinator is responsible for the numbers being right — not the tool, not the person who approved the tool.

Set the review level by consequence. Internal notes and first drafts need no formal check. Customer-facing emails and marketing copy need the sender's own review. Anything with a number in it that binds you — quotations, delivery commitments, invoices, contract terms — needs a second pair of eyes before it leaves. Anything with legal or regulatory weight goes to a human specialist, full stop.

When should you tell customers AI was involved?

Singapore has no blanket disclosure requirement for AI-assisted work, and you do not need to caveat every email your team drafts with help from a chatbot. Disclosure matters in two situations: when a customer is interacting with an automated system and might reasonably think they are talking to a person, and when AI output materially affects a decision about that person — a credit assessment, a job application, a claim.

If you run an AI chatbot on your website or WhatsApp, label it. "You're chatting with our AI assistant — type 'human' to reach the team" costs you nothing and prevents the far worse outcome of a customer discovering it themselves mid-complaint. For recruitment screening, tell candidates AI is used and keep a human in the loop on rejections.

How do you keep the policy from going stale?

Set a review date every six months and put it in the calendar with an owner's name against it. AI tooling changes faster than any other category of business software; a list of approved tools written in early 2026 will be partly wrong by year end.

Three things to check at each review: has anyone requested a tool that should now be approved, has any approved vendor changed its data terms, and has anything gone wrong that the policy failed to prevent. That last question is the valuable one. Keep a short log of AI-related incidents and near misses, even trivial ones. It is the only honest evidence of whether your policy describes what actually happens in your business.

One further step worth taking now: run a quiet audit before you write anything. Ask each department which AI tools they currently use and what they put into them. You will find tools you did not know about. Write the policy around that reality rather than the one you assumed — a policy that bans what people are already doing, with no replacement offered, simply pushes the same behaviour out of sight.

Frequently asked questions

Does PDPA specifically regulate AI use in Singapore?
There is no separate AI statute. PDPA applies to personal data however it is processed, so entering customer data into an AI tool is a disclosure to a third party and must satisfy consent, purpose limitation and transfer requirements. The PDPC and IMDA have also published advisory guidelines on AI systems and the Model AI Governance Framework, which are voluntary but set the benchmark a regulator would measure you against.

Can a small company of ten staff skip a formal policy?
The obligations under PDPA do not scale with headcount, and a ten-person firm can leak a customer database just as easily as a hundred-person one. A two-page document and a thirty-minute team briefing is proportionate. What is not proportionate is a twenty-page framework copied from a multinational.

What should we do first if staff are already using AI without rules?
Audit before you legislate. Spend a week finding out what tools are in use and what data has gone into them, upgrade the one or two tools worth keeping to paid business tiers, then write the policy to match. Starting with the document produces a policy that describes a company you do not have.

Ready to Transform Your Business?

Let Digital Perpetual help you automate, streamline, and grow.

Get Started with Digital Perpetual →
pdpa ai-governance data-protection ai-policy sme-compliance