SecurityTechInsider AI security & governance
EN/ NL
Governance

Setting up separate governance for generative AI: what Singapore's approach demands of your workflows

Regulators treat generative AI as a distinct governance problem. What the Singaporean and IAPP guidelines demand of your AI workflows involving sensitive data.

4 September 2026 4 min
Illustration for this article: Setting up separate governance for generative AI. A ventilation grille in deep shadow, cold air distorting the light passing through it.
Organisations must now document generative AI use per workflow, including which data is processed and who holds accountability for outputs. Image: SecurityTechInsider — original editorial illustration

You must now document which generative AI model each workflow uses, which personal data it processes, how you verify outputs for hallucination and bias, and who holds human accountability for each decision. Generic AI governance will not satisfy regulators; you need controls built for the specific failure modes of generative systems.

The prompt is an analysis of 4 September 2026 of governance frameworks for generative AI, which argues that generative AI must be governed separately from other AI systems, with controls tailored to its distinct risks. Singapore's updated Model AI Governance Framework for Generative AI serves as the concrete case. In our assessment, this marks a shift from aspirational "responsible AI" principles towards demonstrable, workflow-specific controls that address what makes generative models different from traditional classification or prediction systems.

What makes generative AI a separate governance problem?

Generative models fail in ways that older AI systems do not. They can reproduce training data or infer it from outputs—a particular hazard when that training data includes personal information you never intended to process. They generate plausible-sounding but false information, a problem regulators now call hallucination. They embed and amplify biases present in training data, sometimes in ways that surface only after deployment. They operate as black boxes; you cannot easily trace why a particular output was generated. These failure modes sit outside the scope of controls designed for systems that classify or predict from structured inputs.

Regulators have begun to treat these risks as distinct. Singapore's framework and the draft guidelines from its privacy regulator, the PDPC, do not restate general AI principles. They specify what you must do across the entire lifecycle—development, testing, deployment, procurement—to manage generative-specific risks. This is not a statement of intent. It is a requirement to show your work per workflow.

Which failure modes now require explicit controls?

  • Data leakage and memorisation — personal data reproduced or inferred from model outputs during use or in training.
  • Hallucination and factual error — outputs that are plausible but false, particularly hazardous when used to inform decisions about individuals.
  • Bias amplification — systematic skew in outputs that reflects or magnifies biases in training data, affecting fairness of decisions.
  • Opacity of reasoning — inability to explain why a model produced a particular output, blocking accountability for decisions made on its basis.
  • Consent and lawful basis gaps — use of personal data in training or fine-tuning without establishing a legal ground or obtaining consent.
  • Transparency failure — end users or subjects of decisions unaware that generative AI was involved in the process.

What concrete controls must you be able to demonstrate?

  1. Record the model and its purpose — document which generative model each workflow uses, the lawful basis for any personal data it processes, and the business purpose it serves.
  2. Define and test for hallucination — establish what counts as a hallucination in your context, test the model against those criteria before deployment, and log corrections or disagreements between model output and source material.
  3. Assess and monitor bias — evaluate training data and outputs for systematic skew affecting protected characteristics, document findings, and establish monitoring during operation.
  4. Assign human accountability — name who reviews outputs before they inform a decision about an individual, what their review process is, and what records they keep.
  5. Control personal data flow — if the workflow touches personal data, document what data enters the model, what safeguards apply (such as synthetic substitution before processing), and what happens to outputs afterward.
  6. Maintain audit trails — keep records of which data was processed, which model version was used, which human reviews occurred, and what corrections were made.

How do you make controls inspectable?

Governance becomes actionable only when you can show, per workflow, which measures you have taken and where gaps remain. This is not a single policy document covering all generative AI use. It is a per-workflow record: for drafting tasks, for summarisation, for synthetic data generation, for agentic tools that act on your behalf. For each, you document the model, the data, the verification steps, the human review, and the logs. Regulators and auditors will ask to see this record. Your ability to produce it, workflow by workflow, determines whether you can demonstrate compliance.

Tooling can make verification visible—showing where a model output diverges from source material, where a correction was needed, where human disagreement was recorded. Such tools do not remove the need for governance; they make governance inspectable. The substance of compliance lies in the frameworks themselves and in your ability to show that you have applied them. The professional judgement about whether an output is fit for use always remains yours.

What stays your responsibility?

No framework and no tool can replace your own assessment of whether a generative AI workflow is appropriate for your context. Regulators have now made clear what you must document and control. They have not made the decision for you about which workflows should use generative AI at all, or how much human review is enough, or what threshold of hallucination or bias you can tolerate. Those judgements depend on your risk appetite, your data, your users, and your obligations to the people your decisions affect. Tooling can help you make those judgements visible and defensible. It cannot make them for you.

Sources: This article draws on reporting and guidance from IAPP and Wiley.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.