Written and maintained by CASRAI Editorial Board
Last updated
Verified directly against the primary PDF — IMDA and AI Verify Foundation, “Model AI Governance Framework for Generative AI,” 19 June 2024 — and against CASRAI’s own NIKOLAI element pages; last checked September 2026. Singapore does not have a generative-AI statute. What it has instead is a voluntary best-practices framework, jointly issued by the Infocomm Media Development Authority (IMDA) and the AI Verify Foundation, that organizes the entire generative-AI governance problem into nine named dimensions. There is no penalty track, no enforcement body, and no compliance deadline attached to it — which is itself the point worth understanding, especially next to binding regimes like California’s SB 53 or the EU AI Act’s high-risk compliance track.
What the Framework Is
The Model AI Governance Framework for Generative AI carries the copyright line “© Copyright IMDA and AI Verify Foundation 2024. All rights reserved,” exactly as printed on its final page, and its own file metadata records a creation date of 19 June 2024 — consistent with the framework’s own publication filename. It builds directly on IMDA and AI Verify Foundation’s June 2023 Discussion Paper on Generative AI: Implications for Trust and Governance, which the framework’s executive summary credits as the source of “discussions and feedback” that shaped it.
Critically, this is not Singapore’s first Model AI Governance Framework. Singapore released the original version in 2019 and updated it in 2020, aimed at what this newer document calls “traditional AI” — the framework’s own term for predictive models like logistic regression and decision trees, as distinct from generative AI. Rather than retiring that earlier framework, the 2024 document explicitly folds it in: per the framework’s own footnote, “the focus of the [2020] Model AI Governance Framework is to set out best practices for the development and deployment of traditional AI solutions. This has been incorporated into and expanded under the Trusted Development and Deployment dimension of the Model AI Governance Framework for Generative AI.” The 2019/2020 framework’s principles are described as continuing to be relevant, extended rather than replaced. There is no separate Singapore framework for traditional AI still operating on its own track; the current, single reference point for Singapore’s AI governance approach is the 2024 document.
Nowhere in the framework’s 36 pages does the text use the language of legal obligation. There is no occurrence of “penalty” or “shall,” and the framework’s own vocabulary throughout is “recommend,” “consider,” “encourage industry to adopt,” and “best practice” — guidance language, not statutory language. That is a deliberate, structural choice, consistent with how IMDA and the AI Verify Foundation describe the document publicly: a set of practical suggestions industry can start applying now, not a licensing regime or a compliance deadline.
The Nine Dimensions
The framework organizes the entire generative-AI governance problem into nine dimensions, meant to be read together rather than picked from individually:
- Accountability — putting the right incentive structure in place across the AI development chain (model developers, application deployers, and everyone between) so responsibility to end-users doesn’t get lost in a multi-layer tech stack.
- Data — data quality and provenance as the core input to model behavior, including how to handle contentious training data such as personal data and copyrighted material “in a pragmatic way.”
- Trusted Development and Deployment — baseline safety and hygiene practices across the model lifecycle, plus “food label”-style disclosure (training data sources, training infrastructure, evaluation results, known risks, intended use, user-data handling) so downstream users can make informed decisions. This is the dimension that now carries the 2019/2020 framework’s traditional-AI best practices.
- Incident Reporting — structures for timely notification and remediation when something goes wrong, calibrated to be proportionate rather than maximal, with the EU AI Act’s serious-incident reporting regime cited in the document as one existing reference point.
- Testing and Assurance — growing a third-party AI testing ecosystem, split into two design questions the framework poses directly: how to test (standardizing methodology and benchmarks, potentially through bodies like ISO/IEC and IEEE) and who tests (building a pool of independent, eventually accredited testers, the way audit firms work in finance today).
- Security — addressing the “novel threat vectors” generative AI introduces beyond ordinary software security. The framework calls for adapting “security-by-design” principles to generative AI’s system development life cycle, and names two concrete tool categories still needing to be built: input filters (moderation tools to catch unsafe prompts) and digital forensics tools purpose-built for generative AI incident investigation. It points to MITRE’s ATLAS knowledge base as an existing resource for adversary tactics and case studies. The framework is candid that this is “a nascent space” where new concepts, not just adapted old ones, are still being developed.
- Content Provenance — transparency about how and where AI-generated content originates, via technical mechanisms like digital watermarking and cryptographic provenance, as a signal end-users can use to gauge what they’re consuming.
- Safety and Alignment R&D — accelerated research investment, coordinated globally across AI safety institutes, to close the gap between current alignment techniques and the full range of model risks.
- AI for Public Good — the framework’s affirmative half: democratizing AI access, growing public-sector AI adoption, upskilling workers, and developing AI systems sustainably, framed as inseparable from the risk-mitigation dimensions above it.
On Testing and Assurance specifically, the framework is explicit that near-term third-party testing will simply reuse the same benchmarks and evaluations developers already run on themselves — the value-add today is independence, not a different test suite — with standardization and eventual accreditation as the stated end state, not the starting point.
Voluntary Guidance, Not a Statute
It’s worth being precise about what kind of document this is, because CASRAI tracks frameworks across a wide range of legal force in this cluster. The Model AI Governance Framework for Generative AI sits at the non-binding end: no scope-threshold that triggers mandatory obligations, no designated regulator with enforcement powers over it, and no administrative or criminal penalty track. That’s a real structural difference from, for example, California’s SB 53, which ties disclosure obligations to a defined compute threshold, or the EU AI Act’s high-risk system track, which carries conformity-assessment and market-surveillance requirements with real penalties behind them. Singapore’s own framework acknowledges this positioning implicitly: it repeatedly frames itself as a starting point for industry consensus-building (common benchmarks, shared tooling, eventual accreditation) rather than a set of rules already in force. For the fuller jurisdiction-by-jurisdiction picture of where frameworks like this one sit on the voluntary-to-binding spectrum, see CASRAI’s AI regulations around the world guide.
The NIKOLAI angle: an open candidate, not yet a mapping
NIKOLAI is CASRAI’s own frontier-AI-safety dictionary — an independent, unendorsed reference work, not an official record of any regulator’s or lab’s terminology, and certainly not an official record of Singapore’s framework. Every NIKOLAI crosswalk row is a shadow mapping, CASRAI’s own interpretive reading of how a jurisdiction’s or organization’s language lines up with NIKOLAI’s elements, unless and until that organization files its own Mapping Declaration and the declaration clears editorial review.
Singapore’s framework has two dimensions with a structural resemblance to an existing NIKOLAI track: Security, and Testing and Assurance both sit conceptually inside Track N6, Mitigations and security, and its nine elements. We checked directly before writing this: as of publication, none of NIKOLAI’s Security level, Security control, Coverage scope threshold, or Evaluation validity threat element pages carry a crosswalk row for Singapore, IMDA, or the AI Verify Foundation — no shadow mapping exists today, on any element, for this framework.
We’re flagging Security specifically as the strongest open candidate for a future row, and naming which element rather than asserting a fit: NIKOLAI’s Security level element is defined as “a graded controlled-value statement of a developer’s model-weight and infrastructure security posture, indexed to a named external scale (e.g. RAND Security Levels) where the developer has adopted one.” Singapore’s Security dimension names the right problem — adapting security-by-design to generative AI’s threat surface, with input filters and generative-AI-specific digital forensics tools as its two concrete deliverables — but the framework text itself does not yet define or reference a graded security-level scale the way NIKOLAI’s element structure expects. That gap is exactly why we’re calling this a candidate, not a mapping: a future N6 crosswalk row for IMDA/AI Verify Foundation would need either the framework itself, or a later IMDA-published elaboration of it, to specify a concrete graded posture or named external scale before that row could honestly be filled in. Testing and Assurance points in a similar direction — toward Evaluation validity threat and NIKOLAI’s broader evidence-and-evaluations track — but the framework’s current text (reuse existing benchmarks, standardize later) is even less specific there, so we’re not naming a candidate element for that dimension at all rather than guessing one.
For how NIKOLAI’s shadow-mapping system works generally, see Comparing AI Safety Terms Across Frameworks: A NIKOLAI Crosswalk Guide.
Sources
- IMDA and AI Verify Foundation, “Model AI Governance Framework for Generative AI,” 19 June 2024 (primary PDF) — the nine dimensions, the 2019/2020 framework’s incorporation into the Trusted Development and Deployment dimension, and the Security and Testing and Assurance dimension text, all read directly from this document; file metadata confirms a 19 June 2024 creation date, and the final page carries the copyright line “© Copyright IMDA and AI Verify Foundation 2024. All rights reserved.”
- AI Verify Foundation, “MGF for GenAI” resource page — confirms the nine-dimension structure, the framework’s relationship to the 2019/2020 Model AI Governance Framework for Traditional AI, and its guidance-oriented framing (“a set of practical suggestions that apply as initial steps”).
- CASRAI’s own NIKOLAI element pages for Security level, Security control, Coverage scope threshold, and Evaluation validity threat, checked directly for existing crosswalk rows before publication.







