AI Regulation Is No Longer Just a Debate — These New Rules Could Change How AI Works

Singapore

AI Regulation Is No Longer Just a Debate — These New Rules Could Change How AI Works

SINGAPORE — Artificial intelligence is advancing faster than many governments can legislate, but regulators around the world are increasingly moving from voluntary guidelines to enforceable rules designed to address deepfakes, discrimination, privacy risks, autonomous AI agents and other potential harms.

The regulatory landscape is becoming increasingly fragmented.

The European Union is enforcing a comprehensive AI law. China is combining binding regulations with technical standards and state oversight. The United States remains more decentralised, with federal authorities relying heavily on existing laws while individual states develop their own requirements. Singapore, meanwhile, continues to emphasise governance frameworks, sector-specific safeguards and existing legislation rather than a single overarching AI law.

The result is a global experiment in how governments can control AI risks without unnecessarily restricting the technology’s development.

Europe has moved furthest toward comprehensive AI regulation

The European Union’s AI Act remains one of the world’s most comprehensive attempts to regulate artificial intelligence.

Rather than treating every AI application identically, the law uses a risk-based system. Certain low-risk applications face limited requirements, while systems considered high-risk are subject to stricter obligations. Some practices regarded as posing unacceptable risks are prohibited.

The EU’s rules entered another major enforcement phase on Aug 2, 2026. Among the requirements now being enforced are transparency obligations covering certain AI interactions and AI-generated or manipulated content. Chatbots must generally disclose that users are interacting with AI, while deepfakes and certain synthetic content must be appropriately identified.

The European Commission’s AI Office and national authorities are responsible for enforcement, with the AI Office overseeing general-purpose AI models and certain other systems within its remit.

The timetable does not end there.

Rules for certain high-risk AI systems are scheduled to apply from December 2027, while high-risk systems embedded in regulated products have a later August 2028 deadline under the EU’s updated timetable.

The EU framework also contains restrictions involving AI-generated non-consensual intimate material and child sexual abuse material, with those particular prohibitions scheduled to apply from December 2026.

That makes the European model significant not simply because it regulates AI, but because it attempts to establish different obligations according to the potential consequences of a system.

The US is taking a very different regulatory path

The United States does not currently have one comprehensive federal AI law comparable to the EU AI Act.

Instead, federal agencies can apply existing laws to AI-related conduct, while states have pursued their own measures.

The regulatory debate has also become intertwined with a broader argument over whether new federal requirements could slow technological development and investment.

President Donald Trump has recently reiterated opposition to additional AI regulation, arguing that existing laws provide tools for addressing harmful conduct. On Sept 15, US Attorney General Todd Blanche said the Justice Department would investigate AI-related violations of criminal law but said the department’s role was not to regulate AI.

That does not mean AI operates outside government oversight in the US. Rather, the current approach relies on a combination of existing federal law, executive policy, federal agencies and state-level legislation.

Meanwhile, proposals for stronger controls continue to emerge, including ideas involving mechanisms to shut down particularly dangerous AI systems.

This creates a regulatory patchwork in which companies may face different obligations depending on where they operate.

China is building a more state-directed AI framework

China has also developed an extensive AI governance system, although it does not rely on a single comprehensive AI law.

Its framework combines regulations, administrative measures, technical standards and government oversight.

Chinese rules cover areas including generative AI, algorithmic recommendation systems, data security and AI-generated content. AI services considered capable of influencing public opinion or mobilising society can face registration and security requirements.

AI-generated content is also subject to labelling requirements.

More recently, China’s regulatory attention has increasingly expanded toward autonomous or “agentic” AI — systems capable of planning and carrying out multiple tasks with less direct human intervention.

Reuters reported in September that Chinese policymakers have been developing measures addressing risks such as loss of operational control, data poisoning, algorithm manipulation and vulnerabilities in AI-agent systems. China is also working toward a mandatory national standard for AI-agent safety.

The approach illustrates another emerging regulatory question: What happens when AI stops merely generating information and starts taking actions in the real world?

Singapore is focusing on governance, safeguards and existing laws

Singapore has not adopted a single AI statute equivalent to the EU AI Act.

Instead, its approach combines existing legislation, sector-specific regulation and voluntary governance frameworks.

The Personal Data Protection Act can apply when organisations use personal information in AI systems, while agencies including the Infocomm Media Development Authority and Monetary Authority of Singapore have developed guidance and frameworks for responsible AI use.

Singapore has also moved deeper into the governance of AI agents.

In January 2026, IMDA published its Model AI Governance Framework for Agentic AI, addressing issues including human accountability, transparency, oversight and risk management.

IMDA has separately examined a question that could become increasingly important as AI agents become more autonomous: who is legally responsible when an AI system takes an unexpected action that causes harm?

A 2026 IMDA discussion paper noted that AI agents are not legal persons and therefore cannot themselves meaningfully bear legal responsibility. It examined how existing civil-liability principles could apply and identified questions for policymakers as increasingly autonomous systems are deployed.

This points to a regulatory challenge that goes beyond whether AI should be permitted to perform a particular task.

Governments must increasingly determine who carries responsibility when the system makes the decision and something goes wrong.

The rules are increasingly targeting deception

One of the clearest areas of regulatory convergence is synthetic media.

Deepfakes can be used for entertainment and creative production, but they can also be used to impersonate people, manipulate information or create non-consensual sexual material.

The EU’s transparency rules require certain AI-generated or manipulated content to be identifiable, including machine-readable markings for applicable synthetic content.

China likewise requires AI-generated content to be labelled under its regulatory framework.

These measures reflect a growing regulatory emphasis on giving people information about whether the content they encounter was produced or altered by AI.

But labelling alone does not solve every problem.

A technically accurate label may do little to prevent harm if synthetic content spreads rapidly before users notice or understand it. That is why regulators are also examining platform responsibility, provenance technology, privacy, cybersecurity and enforcement.

AI safety is moving beyond chatbots

Another major shift is the growing focus on AI systems that can act, rather than simply respond.

Traditional chatbots generally generate text, images, audio or code in response to prompts.

AI agents can potentially interact with software, access information, execute tasks and make decisions across multiple steps.

That creates a different category of risk.

Singapore’s 2026 agentic-AI framework highlights the need for mechanisms such as human accountability and oversight.

China is similarly examining safeguards against agents losing operational control or bypassing safety boundaries.

The EU AI Act also contains provisions addressing systemic risks from advanced general-purpose AI models, including security and safety requirements.

The regulatory question is therefore changing from “What can this chatbot say?” to “What can this AI system actually do?”

Why the global rules matter to ordinary users

AI regulation may sound like an issue for governments and technology companies, but its effects could reach everyday users.

Rules governing AI transparency could affect whether consumers are told they are communicating with an AI system.

Content-labelling requirements could change how synthetic images, videos and audio appear online.

Data-protection rules could influence how companies use personal information to train or operate AI systems.

High-risk AI requirements could affect automated decisions involving areas such as employment and other consequential services.

And rules governing autonomous agents could eventually determine how much human approval is required before an AI system can take significant actions on a user’s behalf.

The global regulatory map is still being written

There is no single international model for AI regulation.

The EU is building a comprehensive risk-based legal framework. The US is relying more heavily on existing federal law alongside state-level measures and a continuing debate over the appropriate role of government. China combines binding regulations, standards and government oversight. Singapore is using existing laws and targeted governance frameworks while developing additional guidance for emerging technologies such as AI agents.

What these approaches have in common is that governments are increasingly confronting the same basic problem: AI can create benefits and risks faster than traditional regulatory systems can respond.

The next phase may therefore be less about whether AI should be regulated and more about exactly where responsibility should sit — with developers, platforms, deployers, users, governments, or some combination of all of them.

And as AI systems become increasingly capable of acting independently, that question could become much harder to answer.

More in Singapore

See all in Singapore