
Singapore has published a plain template for telling customers what an AI chatbot does and does not do. On 20 July 2026 the Infocomm Media Development Authority (IMDA) released its Transparency Guidelines for Generative AI Chatbots, built around a one-stop "chatbot info card". On the same day the Personal Data Protection Commission (PDPC) issued Advisory Guidelines on Use of Personal Data in Generative AI. Neither document is a new law, but together they show what a regulator expects a business to be able to say about a chatbot it puts in front of the public. This article is general information, not legal advice.
What happened
IMDA's Transparency Guidelines for Generative AI Chatbots, published on 20 July 2026, are aimed at chatbot deployers: the organisations that make a chatbot available for use. They cover chatbots that face customers or the public. Tools used only inside an organisation, such as an internal knowledge assistant, are outside the scope.
The centre of the document is the chatbot info card, which IMDA compares to a medical label: a single place where a customer can find the essentials. IMDA is direct about the status of the guidelines: "These guidelines are voluntary and do not impose obligations." It also says it strongly encourages deployers to meet a stated minimum.
The PDPC announced its own document in a press release titled PDPC Issues Guidance for Organisations on Responsible Use of Personal Data in Generative AI. The Advisory Guidelines on Use of Personal Data in Generative AI explain how Singapore's Personal Data Protection Act (PDPA) applies across three stages: developing a model, deploying a system, and answering people's requests about their data afterwards. The guidelines describe themselves as advisory and not legally binding. The PDPA itself remains the law.
Key details
| Question | Chatbot transparency guidelines | Personal data guidelines |
|---|---|---|
| Who issued it | IMDA | PDPC |
| Date | 20 July 2026 | 20 July 2026 |
| Legal status | Voluntary | Advisory, not legally binding; the PDPA continues to apply |
| Who it is written for | Deployers of customer-facing or public-facing generative AI chatbots | Model providers, system providers and system deployers |
| Main ask | Publish a chatbot info card and link to it at first use | Be specific with people when their data trains AI, and know who is responsible for what |
IMDA organises the info card around three principles: relevance, accessibility and timeliness. The card should answer four questions users care about:
- What can the chatbot be used for? Its capabilities, its limits and anything prohibited, such as age restrictions or out-of-scope uses.
- How reliable and safe is it? The common risks, the safeguards in place, the risks that remain and the precautions a user should take.
- How will user data be used and protected? What is collected, who has access, whether it is used for model training and what controls the user has.
- How can users report issues? The channel, the kinds of issues that can be raised and what follow-up to expect.
The minimum IMDA encourages is a card covering all four areas "with at least one substantive disclosure in each", a short safety statement with a clear link to the card before a person starts chatting, and a way to reach the card from inside the chatbot afterwards. A substantive disclosure is a concrete statement a user can act on. IMDA's own example of a line that does not meet the bar is "we take safety seriously".
Cards should be published by the time a chatbot is available to outside users, including in beta or pilot form. They should be updated when the underlying model, the guardrails or the features change in a way that affects users, and IMDA suggests showing a "last updated" date and a version.
Why it matters
Most public discussion of AI transparency has been about the large models. IMDA has deliberately gone to the application layer, because that is where customers meet the technology, and it has placed the job with the business that runs the chatbot. In its words, "When something goes wrong, users expect answers from the deployers first". A business that builds on someone else's model is only expected to disclose what is reasonably available to it.
The PDPC document sharpens two points that any business should be able to answer for.
- Vague privacy wording is not enough for AI training. The PDPC says general notices, for example a line about "new product development", are an insufficient way to obtain consent to use customer data for large-scale model training or fine-tuning. It expects an explicit, AI-specific notice, and reminds organisations not to make consent to that use a condition of service beyond what is reasonable.
- The business that deploys a system carries the responsibility for choosing it. The guidelines say system deployers "bear primary responsibility" for making sure the generative AI systems they have chosen can meet their PDPA obligations, including when the system is bought as software as a service. Deployers must also safeguard the new kinds of data their systems collect, such as prompts, generated outputs and agent or tool activity data, and educate their users, inside or outside the organisation, on the types of personal data that should be entered.
Singapore has taken a voluntary route, but IMDA adds that sectoral regulators can build on the guidelines to develop more specific transparency guidelines for applications in their sectors.
What this means for businesses
Neither document creates a new obligation: IMDA's guidelines are voluntary and the PDPC's are advisory. If you handle the personal data of people in Singapore, ask an adviser whether and how the PDPA applies to you; the PDPC guidelines show how the regulator reads that Act for generative AI. For everyone else, the info card is a useful free template. Writing one is a small job, and it forces you to answer the questions a careful customer would ask.
A short checklist for a small or medium business with a chatbot on its website or in its app:
- List every chatbot a customer can reach: website widget, mobile app, messaging channels.
- Draft a one-page card that answers the four questions, with at least one specific statement under each.
- Show a one-line safety statement and a link to the card before the first message, and keep an information icon in the chat window.
- Ask your chatbot supplier in writing whether conversations are used to train models, where they are stored, how long they are kept and whether you can turn training off.
- Check that your privacy notice says so plainly if customer data is used to train or fine-tune a model.
- Tell staff what personal information may go into prompts, and restrict who can read chat logs.
- Give the card a date and version, and review it when the model, the guardrails or the features change.
If the chatbot is part of a product you sell, the card belongs in the product itself. That is a design task for whoever builds your custom software or mobile app. Access controls and log retention are covered in our cyber security work. If you would like help mapping what your systems collect and where it goes, ask us for a quote.
Key takeaways
- On 20 July 2026 Singapore's IMDA published voluntary transparency guidelines for customer-facing generative AI chatbots, and the PDPC issued advisory guidelines on personal data in generative AI.
- The chatbot info card answers four questions: what the chatbot is for, how reliable and safe it is, how data is handled and how to report a problem.
- Responsibility for transparency sits mainly with the business that deploys the chatbot, not the model maker.
- Where consent is needed, the PDPC expects an explicit AI-specific notice before customer data is used for large-scale training or fine-tuning of generative AI models.
- Neither document is legally binding, but the info card is a ready-made template for a chatbot disclosure.
Frequently asked questions
Are Singapore's chatbot transparency guidelines mandatory?
No. IMDA states that the guidelines are voluntary and do not impose obligations, and that they do not replace duties under other laws or sector rules.
What is a chatbot info card?
It is a single reference point, such as a web page or a pop-up, where users can find the essential facts about a chatbot: what it can and cannot do, how reliable and safe it is, how their data is used and protected, and how to report issues.
Do the guidelines cover chatbots used only by staff?
No. The IMDA guidelines target external-facing chatbots used by customers or the public. Chatbots deployed solely for internal use, such as employee productivity tools, are outside their scope.
Can a business use customer conversations to train an AI model?
Under the PDPC's reading of Singapore law, an organisation that needs consent for this must give an explicit AI-specific notice that explains which personal data is affected and how it will be used. A general statement about product development is not enough for large-scale training or fine-tuning.
Does this affect Australian businesses?
Neither document is binding: one is voluntary and the other advisory. If you handle the personal data of people in Singapore, ask an adviser whether and how the PDPA applies to you. For other businesses the guidelines are a practical model for a chatbot disclosure.