Singapore faces AI’s challenge early, and it’s about the data you can prove

Governance that lives only in policy documents fails in production; it must be embedded in how data is collected, shared and used

Summarise
    • The questions that stall AI roll-outs are practical, not philosophical: Where did this data come from? What rights apply? Can we trace an output back to its inputs when something goes wrong?
    • The questions that stall AI roll-outs are practical, not philosophical: Where did this data come from? What rights apply? Can we trace an output back to its inputs when something goes wrong? IMAGE: PIXABAY
    Published Thu, Apr 2, 2026 · 07:00 AM

    DATA trust is not a new issue – companies have been grappling with it for years. What’s new is the urgency: as generative artificial intelligence (AI) moves into production, knowing where your data came from, whether you are allowed to use it, and whether you can explain your AI’s outputs are no longer negotiable.

    President Tharman Shanmugaratnam recently said Singapore will face AI’s challenge sooner than many economies, and that the deeper test is ensuring AI’s productivity gains are distributed “up and down the workforce”.

    That urgency is reinforced by Budget 2026’s push to scale AI nationally, including a new National AI Council chaired by Prime Minister Lawrence Wong, with missions spanning manufacturing, connectivity, finance and healthcare.

    Within enterprises, that distribution hinges on one practical question: Can business users trust the data on which AI systems rely, and can the organisation prove it?

    Trust: the constraint

    Pilots are forgiving. Firms can curate data sets, limit scope and rely on informal checks. Production is not.

    Once AI moves into customer operations and decision-making, from credit and fraud to supply chain planning, it starts consuming messy, cross-border data. That is where deployment slows.

    The questions that stall roll-outs are practical, not philosophical: Where did this data come from? What rights apply? Can we trace an output back to its inputs when something goes wrong?

    I observed one such pause when a team attempted to deploy an AI assistant for trading and risk into production, using a mix of internal logs and third-party market data. The pilot worked.

    But when governance requested proof of usage rights and lineage across vendors and jurisdictions, the organisation could not demonstrate which data was licensed for AI use or how derived signals were built. The result: a forced scope cut and weeks of rework.

    “AI governance in practice” is an audit trail, not a framework deck

    Singapore has made significant progress in responsible AI. But governance that lives only in policy documents fails in production. It must be embedded in how data is collected, shared and used.

    For business leaders, this comes down to four practical controls:

    Data provenance, knowing exactly where your data originated and how it was transformed along the way, much like a chain of custody for evidence, is the foundation. Without it, you cannot explain what went into an AI output.

    Permissions determine what data can be used for what purpose, and under what terms.

    Integrity means being able to detect tampering or drift in the data pipeline.

    Auditability means that if something goes wrong, you can trace an output back to specific inputs, versions and access points.

    These are not compliance overhead. They are the conditions for scaling AI beyond pilots. When they are missing, roll-outs slow for a simple reason: No one can confidently sign off on what data the system is using, where it came from, or how to explain a bad output.

    Why Singapore’s advantage is shifting from model access to trusted data infrastructure

    As foundation models become easier to access, model choice alone is no longer a defensible advantage. The differentiator is increasingly the data layer: whether a firm’s data is usable, permissioned and trustworthy, and whether it can be audited in hours, not weeks, as it moves across vendors, business units and borders.

    Asean has published guidance on AI governance and ethics, including considerations for generative AI and a push for more consistent standards, even as data and systems flow across jurisdictions.

    For Singapore firms, this matters because regional operating models naturally generate cross-border data flows among vendors, business units and markets.

    In practice, a Singapore headquarters running shared Asean services might draw on customer interactions from local markets, transaction data from regional systems and vendor data supporting onboarding, KYC (Know Your Customer) and fraud detection, all under different usage rights, spanning multiple jurisdictions.

    Lineage gets lost when data is copied into shared pools; definitions drift between functions, until someone asks for proof and the project stalls.

    If Singapore firms can make provenance, permissions and auditability routine rather than ad hoc, they will deploy AI faster with fewer false starts, and be better positioned to scale AI across the workforce, not just within specialist teams.

    Making AI a “productivity plus” for the whole workforce

    President Tharman’s emphasis on distribution matters inside the enterprise too.

    If AI remains usable only by specialists, because everyone else fears data leakage, unverifiable outputs, or governance uncertainty, productivity gains will concentrate. Frontline functions will hesitate to act on outputs they cannot explain or verify.

    A trusted data infrastructure changes that. When business users can see what an output is based on – the data sources, permissions and confidence signals, they can apply judgment, spot stale inputs and escalate exceptions. That is how AI becomes a capability distributed across functions, not a black box confined to a technical few.

    What CEOs should do next

    Companies do not need to solve governance in one grand programme. They need momentum and measurable controls:

    • Start with high-value workflows and build trust controls into roll-out from day one. Require data provenance and auditability as part of implementation, not as an afterthought.
    • Treat data permissions like an enterprise asset. Track rights and allowed uses for key data sets. If leaders cannot explain what data can be used for training, fine-tuning, or retrieval, it will not scale safely.
    • Measure AI readiness beyond pilots. Ask for metrics that reflect real deployability: provenance coverage on critical datasets, time to audit an output back to its inputs, and clarity on cross-border data controls.

    Singapore will face AI’s challenge early, but early can also mean first to build the trust layer that makes enterprise AI deployable at scale.

    The biggest delays are rarely about models, they come when organisations cannot sign off on data quality, permissions and auditability across regional operations.

    Firms do not get stuck on model access; they get stuck on sign-off. The ones that move fastest can answer these questions in hours, not weeks, because they built a trust layer for data they can actually prove.

    The writer is co-founder of Pundi AI. He was formerly an executive at Opera China and chairperson of a W3C interest group