Skip to main content
Talk to a human
AI Assistant

AI Policy Template for Singapore Companies

A copy-ready ten-clause policy, free and ungated, with the parts that actually decide whether it works.

Short answer

A workable AI use policy for a Singapore SME is about one page and ten clauses. The full text is below, free to copy, with square brackets marking what you need to fill in. Longer is not safer: a policy nobody reads is not a control, and the failure mode here is a staff member pasting a customer list at 6pm on a deadline.

Before you copy it

Three things decide whether this policy does anything.

  • Name the approved tools and the tier. Clause 2 is the one most often left vague. “Approved AI tools” means nothing; “ChatGPT Business” means something, and free personal accounts are a different risk from business tiers.
  • Give it an owner. Usually whoever already holds the DPO role, because the risks overlap almost entirely with data protection.
  • Train it. A policy that has never been practised is a document. The clause that matters most, number 3, is a behaviour under time pressure, not a rule people look up.

The policy

Copy this, replace everything in square brackets, and delete anything that does not apply to how you actually work.

1

Purpose and scope

This policy sets out how [Company] staff may use generative AI tools in the course of their work. It applies to all employees, contractors and interns, on any device, whether the tool is provided by [Company] or accessed personally for work purposes.

2

Approved tools

Staff may use the following tools for work: [list tools and the tier, e.g. ChatGPT Business, Microsoft 365 Copilot]. Any other AI tool must be approved by [role] before it is used on [Company] information. Personal free-tier accounts must not be used for work.

3

What must never be entered

Staff must not enter into any AI tool: personal data of customers, employees or any identifiable individual; information subject to a confidentiality or non-disclosure obligation; credentials, API keys or access tokens; unreleased commercial information including pricing, tenders and contract terms; or source code from private repositories. If in doubt, the test is: would you email this to a stranger?

4

Handling data safely

Where AI assistance is useful on sensitive work, describe the structure of the problem rather than supplying the underlying data. Anonymisation is only sufficient where an individual cannot be re-identified by combining the information with anything else.

5

Verifying output

AI output is a draft, not a fact. Any figure, date, name, legal or regulatory statement must be verified before it is sent to a customer, regulator or counterparty, or relied on in a decision.

6

Accountability

The member of staff who sends, publishes or acts on an output is accountable for it. Use of an AI tool does not transfer responsibility for accuracy or appropriateness.

7

Disclosure to customers

Where AI is used in a way that is customer-facing, or that makes or materially influences a decision about an individual, that use must be disclosed. Internal drafting that a person reviews before it leaves [Company] does not require disclosure.

8

Reporting problems

Staff must report to [role] any occasion where confidential information or personal data has been entered into an AI tool, any output that caused or nearly caused an error, and any suspected misuse. Reports made promptly and in good faith will not result in disciplinary action.

9

Record of AI use

[Role] maintains a register of AI tools in use, the categories of data each may process, and who approved them. Staff must not introduce a new tool into a workflow without it being added.

10

Review

This policy is reviewed at least annually and whenever a new tool is approved or a significant incident occurs. Effective date: [date]. Owner: [role].

The clause that does the work

Clause 3 is the whole policy in practice

Nobody sets out to leak anything. Someone is busy, has a messy customer list, and pastes it in to have it tidied. Under the PDPA that is a disclosure of personal data to a third party, with the consent and transfer obligations that follow. The detailed version of what belongs in that clause is on what employees should never paste into ChatGPT.

What this policy does not do

  • It is not legal advice, and it is not tailored to your sector. Financial services, healthcare and education carry obligations beyond this.
  • It does not make you compliant. It describes intended behaviour; it does not create it.
  • It does not substitute for governance where AI is doing something consequential. Making or materially influencing decisions about people needs risk classification and oversight, not a use policy. That is what our free AI governance guide covers.
  • Left inaccurate, it works against you, in the same way a privacy notice describing practices you do not follow is a written record of the gap.

Supporting templates

Three related documents, all free and ungated:

Making it real

The policy is the easy part. What changes behaviour is people having practised the habit on their own work, which is what our AI training does, and using ChatGPT safely at work covers the operating model the policy sits inside.

Common questions

Is this AI policy template free to use?

Yes. Copy it from this page, replace what is in square brackets, and delete anything that does not apply. There is no form and no email required.

How long should an AI use policy be?

About a page. Ten clauses covers what an SME needs. Length is not safety: the failure mode is a staff member pasting a customer list at the end of a long day, and no amount of additional wording prevents that. A short policy people remember beats a long one nobody has read.

Do we legally need an AI policy in Singapore?

There is no standalone legal requirement to have an AI use policy. What is required is compliance with the PDPA, and staff entering personal data into AI tools is a disclosure to a third party. A policy is one of the more practical ways to meet the Accountability Obligation, alongside training and a record of what is in use.

Who should own the AI policy?

Usually whoever already holds the DPO role, since the risks overlap almost entirely with data protection. It needs to be a named person with enough authority to say a tool is not approved, rather than a committee.

Should we ban AI tools instead?

Banning them reliably fails, because usage moves onto personal accounts and free tiers where you have no visibility. Naming a small number of approved tools and being clear about what must never be entered gives you far more control than a ban you cannot enforce.

Does having a policy make us compliant?

No. A policy describes intended behaviour; it does not create it, and it becomes a liability if it describes practices you do not follow. What makes it a control is training, an owner, and a record of what tools are actually in use.

Disclaimer: This page is general information, not legal advice. The Personal Data Protection Act and the PDPC’s advisory guidelines are the authoritative sources, and requirements change. For your own obligations, seek qualified advice.

Want the policy to change behaviour?

Training is what turns a document into a control. Ours runs on your team’s real workflows.

Schedule Consultation