Article summaryEmployees at most small businesses are already using AI tools at work, often without anyone signing off on it. Singapore has built a growing stack of AI guidance, from IMDA’s governance frameworks to new PDPA rules on personal data in generative AI, and none of it assumes a business is too small to follow. A short, practical AI governance policy is what turns that guidance into something your team can actually follow.  There is a good chance that employees in your organisation are already using tools like ChatGPT, Gemini, or other AI assistants as part of their daily work, whether those tools have been formally approved or not. For many businesses, AI has quickly become part of everyday workflows. An AI governance policy may sound like something reserved for large enterprises, but it is just as valuable for small and medium-sized businesses. In reality, it is a practical extension of your existing IT policies, setting out which AI tools employees may use, what information can be shared with them, and the safeguards everyone is expected to follow.

Why “We’ll Figure It Out Later” No Longer Works

Employees are not waiting for permission. They are pasting client emails into chatbots, uploading spreadsheets for a quick summary, and drafting proposals with tools nobody in the office ever approved. According to Microsoft’s 2024 Work Trend Index, 75% of knowledge workers globally now use generative AI at work, while 78% of AI users are bringing their own AI tools into the workplace rather than relying solely on employer-provided solutions. This is called shadow AI: AI tool use happening outside any policy, review, or approval process. It is the AI-era version of shadow IT, and it creates the same blind spots. The risk is not the AI tool itself. It is not knowing what has already left the business, through which tool, and where it ended up.

What Singapore Expects from Businesses Using AI

Singapore does not have a single, comprehensive law governing artificial intelligence. Instead, the Infocomm Media Development Authority (IMDA) has adopted a principles-based approach built around a series of voluntary governance frameworks. This began with the Model AI Governance Framework for traditional AI and has since expanded to include dedicated guidance for generative AI and, more recently, agentic AI. Each framework builds on the foundations of the previous one, allowing organisations to strengthen their AI governance without starting from scratch.

IMDA’s guidance on responsible AI use

IMDA’s most recent framework focuses on agentic AI systems that can plan and take actions on an organisation’s behalf. It encourages organisations to define clear boundaries for what AI agents are allowed to do, establish meaningful human oversight and approval for significant actions, and ensure that accountability always remains with people rather than the technology itself. Although the framework is voluntary rather than legally binding, it reflects emerging best practices for responsible AI governance. Organisations that align with its recommendations will be better positioned to meet evolving regulatory expectations, demonstrate good governance to customers and partners, and manage AI-related risks more effectively.

PDPA and personal data in AI tools

If your organisation uses AI tools to process personal data, whether that includes customer names, contact details, transaction records, or employee information, the Personal Data Protection Act (PDPA) continues to apply. Using AI does not reduce or replace your existing data protection obligations. In 2026, the Personal Data Protection Commission (PDPC) launched a public consultation on proposed advisory guidelines clarifying how the PDPA applies to the use of personal data throughout the generative AI lifecycle, including development, deployment, and procurement. The guidance explains how existing data protection obligations apply when organisations build, purchase or use generative AI systems. An AI governance policy is where those regulatory expectations become practical day-to-day guidance. It gives employees clear rules on which AI tools they may use, what information they can share, and how to use AI responsibly while complying with your organisation’s data protection obligations.

What to Put in Your AI Governance Policy

An effective AI governance policy does not need to be lengthy or filled with legal jargon. For most SMEs, a single page is enough to cover the essentials, provided it is written in clear, straightforward language that employees can easily understand and follow from day one. At minimum, include:

  •     Which AI tools are approved for company use, and who approved them
  •     What information staff must never paste into an AI tool, including client data, passwords, and financial records
  •     Who to ask before trying a new AI tool for work
  •     How AI-generated output gets checked before it reaches a client
  •     What happens if someone breaches the policy

Use clear, straightforward language. A policy that employees cannot easily understand is unlikely to be followed in practice. New employees are another common oversight. Include your AI governance policy as part of your onboarding process so expectations are clear from day one, rather than leaving staff to discover the rules months later through trial and error.

Getting the Balance Right

Singapore is actively encouraging SMEs to adopt AI responsibly rather than discouraging its use.  Businesses that implemented AI-enabled solutions through the Productivity Solutions Grant (PSG) reported average cost savings of 52% in 2024, reflecting the government’s broader commitment to helping smaller businesses adopt AI with greater confidence and lower implementation costs. Many SMEs already have generative AI built into tools they use daily. If your team relies on Microsoft 365, reviewing those built-in AI features is often the fastest and cheapest place to start, since the tool is already licensed and the risk is mostly a matter of configuration. Good AI governance is not about slowing innovation or limiting adoption. It gives your organisation the confidence to use AI responsibly, with clear expectations and appropriate safeguards, rather than relying on guesswork.

Is Your AI Governance Policy Ready?

An AI governance policy gives your organisation a clear framework for adopting AI safely and responsibly. It sets expectations for employees, helps protect sensitive information, and ensures AI tools are used in a way that supports your business objectives. If you’re ready to put a practical AI governance policy in place, Managed IT Asia can help. We will work with you to identify the AI tools already in use, develop a clear, plain-language policy tailored to your organisation, and align it with IMDA guidance and the PDPA, helping you strengthen both your security and compliance as AI adoption continues to grow. Call Managed IT Asia at +65 6814 0818 or reach us on our contact page to get started.

Article FAQs

What is an AI governance policy?

An AI governance policy is a short internal document setting out which AI tools a business allows, what information staff can put into them, and how the output gets checked before use. It turns AI use from a free-for-all into something the business can manage.

Do small businesses in Singapore need to follow IMDA’s AI frameworks?

IMDA’s Model AI Governance Framework and related guidance are voluntary, not law. They still set the standard that regulators, clients, and insurers increasingly expect, so following them is good practice even for a small business.

What is shadow AI, and why does it matter?

Shadow AI refers to employees using AI tools at work without approval or oversight, similar to shadow IT. It matters because sensitive business or customer data can end up inside a tool the business never assessed.

    Name (Required)

    Email (Required)

    Phone

    Are You a Robot?

    Request for a call-back

     

    MANAGED IT ASIA, we are an IT Support, IT Solutioning and Managed IT Service Provider specializing in serving Small Businesses across Asia. Call us at +65 6748 8776 and let us manage your Small Business IT today!