How Singapore Companies Can Safely Use ChatGPT at Work
Four steps that work, starting from the fact that your staff are almost certainly already using it.
Four things, in this order: decide which tools are approved, write one rule people can remember, train the habit, and keep a record of what is actually being used. Banning AI outright is the option that reliably fails, because it moves the usage onto personal accounts where you have no visibility and no control.
Start from what is already happening
In most Singapore teams we work with, staff are already using AI tools nobody approved and nobody counted. Free tiers, personal logins, on work documents. That is the actual starting position, and any plan that assumes a blank slate is solving a different company’s problem.
So the first move is not a policy. It is finding out what is in use. Ask, without making it a disciplinary matter, or you will get an inaccurate answer and lose the chance to fix anything.
1. Decide what is approved
Pick a small number of tools and say so explicitly. Two considerations that matter more than the brand:
- Consumer tier versus business tier. The difference in retention and training-use commitments is substantial. If staff are on free personal accounts, you are relying on terms you did not agree to and cannot enforce.
- Where the data goes. Any AI vendor processing personal data on your behalf is a disclosure and, for most, a cross-border transfer. That engages the Transfer Limitation Obligation and is worth checking before rollout rather than after.
Being permissive about a couple of properly-procured tools beats being restrictive about everything and enforcing none of it.
2. Write one rule, not a policy nobody reads
A fifteen-page policy does not survive contact with a deadline. What survives is a single line staff can recall while they are busy. Ours is: if you would not email it to a stranger, do not paste it into a chatbot.
Behind that, keep a short written policy for the record, covering approved tools, what must never be entered, when AI output must be checked, and who to tell when something goes wrong. The AI use policy template is a starting point. The detailed list of what must never go in is on what employees should never paste into ChatGPT.
3. Train the habit, not the rule
Knowing the rule and behaving differently under time pressure are separate things. The habit worth building is describe the problem instead of pasting the data: rather than pasting a customer list to be tidied, describe its structure and ask for the method. Same result, no disclosure.
That takes practice on real workflows, which is what our AI training does. A slide deck about risk produces awareness. Repetition on the tasks people actually do produces behaviour.
4. Check the output before it goes anywhere
The second failure mode has nothing to do with data. AI tools produce fluent, confident text that is sometimes wrong, and fluency is exactly what makes people skip the check. Two rules cover most of it:
- Anything factual gets verified before it reaches a customer, a regulator or a contract. Figures, dates, legal or regulatory claims, names.
- A person owns every output. Whoever sends it is accountable for it. “The AI wrote it” is not a defence anyone will accept.
Do you have to tell customers you use AI?
It depends what it touches. AI used internally to draft something a person then reviews sits differently from AI making or materially influencing a decision about someone, or interacting with customers directly as though it were a person. Where AI is customer-facing or decision-affecting, disclosure is the safer position, and it is increasingly what customers expect. IMDA’s Model AI Governance Framework is the reference point for Singapore organisations here, and our free AI governance guide covers where the line sits in practice.
Keep a record
An inventory of what is in use, what data it touches, and who approved it. Unglamorous, and it is the artefact that turns “we take AI seriously” into something you can show. It also makes the next question answerable: when a new tool appears, is it in or out?
The organisations that handle this well are not the ones with the strictest rules. They are the ones where staff know what is approved, know the single rule, and are not afraid to say they made a mistake. The last one matters most, because the incidents that get expensive are the ones nobody reported.
Where to start
If nothing is in place yet, start with the inventory and the one-line rule; both take an afternoon. AI training builds the habit on your team’s real workflows, and our free AI governance guide covers risk classification, vendor due diligence and the governance framework.
Common questions
How can Singapore companies use ChatGPT safely at work?
Decide which tools are approved and on which tier, write one rule staff can remember rather than a long policy, train the habit of describing a problem instead of pasting the data, require that factual output is verified before it leaves the organisation, and keep a record of what is actually in use.
Should we just ban ChatGPT at work?
Banning it reliably fails. Staff move onto personal accounts and free tiers, which means the usage continues with no visibility, no approved tooling and no record. Being permissive about a small number of properly-procured tools gives you far more control than a ban you cannot enforce.
Is using ChatGPT at work a PDPA issue?
It becomes one as soon as personal data is entered. That is a disclosure to a third party and usually a cross-border transfer, which engages the Consent, Purpose Limitation and Transfer Limitation obligations. Using AI on data that contains no personal information raises no PDPA question at all.
Do we need to tell customers we use AI?
It depends what the AI touches. Internal drafting that a person reviews sits differently from AI that makes or materially influences decisions about people, or that interacts with customers directly. Where it is customer-facing or decision-affecting, disclosure is the safer position and increasingly the expected one.
What is the difference between the free and business versions?
Principally the commitments on data retention and whether your inputs may be used to improve the service, along with administrative controls. The difference is significant enough that it should drive which tier staff are on, and in practice most staff do not know which one they are using.
Who should be responsible for AI use in a small company?
Usually whoever already holds the DPO role, since the risks overlap heavily with data protection. It needs to be a named person rather than a committee, with enough authority to say a tool is not approved.
Disclaimer: This page is general information, not legal advice. The Personal Data Protection Act and the PDPC’s advisory guidelines are the authoritative sources, and requirements change. For your own obligations, seek qualified advice.
Want your team using AI well and safely?
Our AI training is built around your actual workflows, not a generic slide deck about risk.
Schedule Consultation