Commentary

Singapore is leading AI governance while we fall behind

A version of this article was first published by IAPP on 23 July 2026.

In July, our partner Daimhin Warner attended the IAPP Asia Forum 2026 in Singapore, and shares his observations on the state of AI governance.

It has become clear that the conversation in the APAC region has moved well beyond whether organisations should be governing artificial intelligence. The focus is now on how to operationalise governance, demonstrate assurance and build public trust as AI systems become embedded in business and government. In her opening keynote, Singapore’s Personal Data Protection Commissioner Denise Wong commented that “clarity in rules equals confidence in use.” Singapore has become a regional leader in this space, developing not only high-level principles but also practical governance frameworks, AI testing methodologies and technical assurance tools.

The New Zealand government has publicly recognised Singapore as a global leader in AI, modelling its own national AI strategy on Singapore’s proactive frameworks, and actively partnering with them on joint technology and healthcare research initiatives. However, while New Zealand appears keen to adopt Singapore’s proactive AI adoption stance, it has not followed Singapore’s lead on AI governance.

New Zealand’s approach remains comparatively fragmented. There is no standalone AI law, no dedicated AI regulator and limited AI-relevant legislation. Instead, the government has produced a dispersed body of strategies and guidance, much of it voluntary. This leaves organisations with considerable discretion in determining what responsible AI governance looks like. To return to Commissioner Wong’s statement, we do not have “clarity in rules,” and so “confidence in use” is less likely to follow.

The government’s position is broadly to encourage AI adoption while managing risk through existing laws and practical guidance rather than new legislation. This differs markedly from many overseas approaches. While the New Zealand approach offers flexibility, it also places significant responsibility on organisations to interpret how existing legal obligations apply to rapidly evolving technologies.

The centerpiece is the Ministry of Business, Innovation and Employment’s 2025 New Zealand Strategy for AI: Investing with Confidence, supported by Responsible AI Guidance for Businesses (we’ve written an article about this here). The emphasis is on increasing AI adoption while encouraging organisations to establish governance, assess risk and operate transparently. However, the guidance creates no new legal obligations and offers limited clarity about what constitutes adequate governance in practice.

The Government Chief Digital Officer’s Public Service AI Framework and accompanying generative AI guidance encourage agencies to implement governance measures, retain meaningful human oversight and remain accountable for AI-assisted decisions (we’ve written an article about this here). They provide useful direction, but they have little practical detail, are non-binding and their effectiveness depends on consistent implementation across agencies.

The Ministry for Regulation has adopted a similar position in its Responsible AI in Action, encouraging regulators to use AI to support functions such as analysing large volumes of information while ensuring that responsibility for regulatory decisions remains with humans. Sensible though this is, retaining a human in the process will not necessarily prevent automation bias or over-reliance on AI-generated outputs.

The absence of AI-specific legislation should not be mistaken for a total absence of regulation. The Privacy Act 2020, Human Rights Act 1993, consumer protection law and sector-specific obligations all apply to the use of AI. However, these frameworks were not designed with modern AI systems in mind. While existing privacy law can address matters such as excessive data collection, inadequate transparency, poor security and inaccurate personal information, it does not adequately address broader concerns such as model opacity, inference, bias and accountability. And, of course, it only covers personal information.

New Zealand’s approach remains deliberately light touch. That may encourage innovation, but it also risks governance developing unevenly and largely in response to harm after it occurs. It is hard to say how long voluntary guidance and general legislation can provide credible protection as AI systems become more capable, pervasive and influential. For now, privacy professionals face the challenge of encouraging employers or clients to implement best practice responsible AI controls despite a lack of concrete legal obligations, or even agreement on what these controls are. For now, we will need to fall back on the old levers of trust and reputation and hope these can compete with the allure of new AI tools and the competitive pressure to embrace them.