← LEADERSHIP TERMINAL

PARLIAMENT OF SINGAPORE · FORMER

Josephine Teo

Singapore

IN THEIR OWN WORDS

The Government's risk-calibrated approach to data security in artificial intelligence (AI) systems was explained in a written reply, given on 9 January 2024, to related questions asked by Dr Tan Wu Meng and Mr Gerald Giam.

STRENGTHEN RULES GOVERNING USE OF CLASSIFIED AND UNCLASSIFIED GOVERNMENT DATA GIVEN RAPID DEVELOPMENT OF AI TECHNOLOGIES - 2026-07-07 · READ THE OFFICIAL RECORD

Access to frontier models is helpful for specific use cases, such as advanced research and cybersecurity. However, these form a small proportion of artificial intelligence (AI) demand. For most industry, Government and research uses, capable models are already available.

CONTINUED FRONTIER AI ACCESS FOR SINGAPORE GIVEN US ORDER TO BAR FOREIGN ACCESS TO ANTHROPIC'S FABLE AND MYTHOS MODELS - 2026-07-07 · READ THE OFFICIAL RECORD

The Government tracks the development of technical standards for identifying artificial intelligence (AI)-generated content, including watermarking and digital provenance approaches, as part of broader efforts to manage AI-related risks.

WATERMARKING AND DIGITAL PROVENANCE STANDARDS FOR AI-GENERATED MEDIA, METADATA PRESERVATION AND DISCLOSURE OF ORIGINAL UPLOADERS AND CROSS-PLATFORM COORDINATION MEASURES - 2026-07-07 · READ THE OFFICIAL RECORD

Upon receiving a valid report of intimate image abuse, the Commissioner of Online Safety is empowered by law to direct Online Service Providers (OSPs) to disable access by Singapore users to the specified harmful online material. This direction may be extended to cover identical copies found on the platform.

IMPLEMENTATION OF STAY-DOWN MEASURES FOR NON-CONSENSUAL INTIMATE IMAGES AND SEXUALISED DEEPFAKES UNDER ONLINE SAFETY COMMISSION AND PREVENTING GLOBAL ACCESSIBILITY - 2026-07-07 · READ THE OFFICIAL RECORD

The Government is committed to keeping children safe online. We have announced plans to extend age assurance requirements to designated social media services, including requiring platforms to keep users under 13 off their services.

ADDRESSING BROADER ISSUE OF UNDER-16S' SOCIAL MEDIA ADDICTION - 2026-07-07 · READ THE OFFICIAL RECORD

Under the Online Safety (Relief and Accountability) Act 2025, the Commissioner of Online Safety is empowered to issue directions to platforms to remove specified harmful content, including intimate image abuse.

COMPLIANCE TIMEFRAMES FOR PLATFORMS TO REMOVE NON-CONSENSUAL INTIMATE IMAGES UNDER DIRECTION OF ONLINE SAFETY COMMISSION - 2026-07-07 · READ THE OFFICIAL RECORD

The complete record

Every one of 2,900 lines we hold for Josephine Teo, in date order, each linked to its source. Free to read, in full, without an account. Page 10 of 58.

  1. Artificial intelligence can be exploited for malicious purposes, including scams and fraud. Agencies, such as the Ministry of Communications and Information, the Ministry of Home Affairs, the Singapore Police Force (SPF), the Infocomm Media Development Authority, and the Cybersecurity Agency of Singapore (CSA), are working closely to ensure that Singaporeans can go online safely and safeguard themselves against such online harms and threats. Social media platforms are expected to take down scam content as soon as it is detected and to take pre-emptive measures to detect and block possible scams, including deepfake-enabled content. The Online Criminal Harms Act (OCHA), which was passed in July 2023, allows the Government to issue directions to online platforms to prevent potential scam related accounts or content to reach Singapore users. Under OCHA, designated online service providers may also be required to implement measures – if not already taken – to proactively disrupt online scams, including those facilitated by deepfakes. The Government is working with industry partners to strengthen our capabilities to deal with these threats. Some of these initiatives were recently addressed in the Parliamentary Motion on Building an Inclusive and Safe Digital Society. [Please refer to "Building an Inclusive and Safe Digital Society", Official Report, 10 January 2024, Vol 95, Issue 119, Motions section.] For example, the Centre for Advanced Technologies in Online Safety, which will be launched in the first half of this year, aims to enhance industry collaboration and knowledge exchanges in deepfakes detection.

    MEASURES TO ENHANCE PUBLIC TECHNOLOGICAL UNDERSTANDING TO COMBAT CYBERCRIME AND DEEPFAKE CONTENT - 2024-02-05 · READ THE OFFICIAL RECORD

  2. The SPF is also working with the Home Team Science and Technology Agency to develop and enhance technologies to detect AI-generated audio and videos and respond to the malicious use of deepfake technology. To complement the Government's efforts to build a safe and inclusive digital society, we have rolled out public education programmes on digital media and information literacy, cybersecurity and scams. For example, the National Library Board's signature S.U.R.E. (Source. Understand. Research. Evaluate.) campaign, the CSA's national cybersecurity campaign "Unseen Enemy"; and the SPF/National Crime Prevention Council's "I can ACT against scams". The Scam Public Education Office was also set up in 2023 to drive anti-scam public education efforts and expand outreach. The Government will closely monitor and continue to adjust our strategies and tools to keep pace with the rapidly evolving technological landscape.

    REGULATIONS TO TACKLE DEEPFAKE SOFTWARE BEING USED IN SCAM AND FRAUD CASES - 2024-02-05 · READ THE OFFICIAL RECORD

  3. Artificial intelligence can be exploited for malicious purposes, including scams and fraud. Agencies, such as the Ministry of Communications and Information, the Ministry of Home Affairs, the Singapore Police Force (SPF), the Infocomm Media Development Authority and the Cybersecurity Agency of Singapore (CSA), are working closely to ensure that Singaporeans can go online safely and safeguard themselves against such online harms and threats. Social media platforms are expected to take down scam content as soon as it is detected and to take pre-emptive measures to detect and block possible scams, including deepfake-enabled content. The Online Criminal Harms Act (OCHA), which was passed in July 2023, allows the Government to issue directions to online platforms to prevent potential scam related accounts or content to reach Singapore users. Under OCHA, designated online service providers may also be required to implement measures – if not already taken – to proactively disrupt online scams, including those facilitated by deepfakes. The Government is working with industry partners to strengthen our capabilities to deal with these threats. Some of these initiatives were recently addressed in the Parliamentary Motion on Building an Inclusive and Safe Digital Society. [Please refer to "Building an Inclusive and Safe Digital Society", Official Report, 10 January 2024, Vol 95, Issue 119, Motions section.] For example, the Centre for Advanced Technologies in Online Safety, which will be launched in the first half of this year, aims to enhance industry collaboration and knowledge exchanges in deepfakes detection.

    REGULATIONS TO TACKLE DEEPFAKE SOFTWARE BEING USED IN SCAM AND FRAUD CASES - 2024-02-05 · READ THE OFFICIAL RECORD

  4. Films classified NC16 and above – that is, NC16, M18 or R21 – are age-restricted films, which typically contain stronger or more explicit content that would not be appropriate for younger audiences. The Infocomm Media Development Authority (IMDA) has medium-specific requirements to ensure that such films are accessed by appropriate audiences. For the public exhibition of age-restricted films, IMDA requires exhibitors, such as cinemas, to undertake age checks to prevent access by underaged persons. The exhibition of NC16 and M18 films must be held indoors, or in enclosed spaces if outdoors; R21 films can only be exhibited indoors and at cinemas which are outside of the Housing and Development Board (HDB) heartlands to further prevent inadvertent exposure to underaged persons. There are currently no plans to review these requirements. Similarly, online streaming services, including over-the-top services that offer age-restricted content, have measures in place to prevent underaged persons from accessing such content. These include parental locks for age-restricted content and the requirement for all R21 content to be locked by default and accessible only by a personal identification number (PIN). These requirements enable parents to use the parental locks and PIN to ensure that their children access only age-appropriate content.

    RATIONALE FOR RESTRICTIONS ON SCREENING LOCATIONS FOR MOVIES RATED NC16 AND ABOVE - 2024-02-05 · READ THE OFFICIAL RECORD

  5. Each NLB library is designed to cater to the demographics of the patrons who visit each library, the unique characteristics of the surrounding area, feedback received as well as patron surveys and interviews. Hence, the space allocation, which is also affected by the size and layout of each library, differs across the public libraries.

    SPACE USAGE IN NLB LIBRARIES - 2024-01-10 · READ THE OFFICIAL RECORD

  6. Over the one-year period from December 2022 to November 2023, 524,000 National Library Board (NLB) members borrowed at least one physical book from NLB's libraries. They made a total of 20.9 million physical loans and renewals of books, of which 141,000 were reservations.

    PHYSICAL NATIONAL LIBRARY BOARD BOOKS BORROWED, RESERVED AND COLLECTED IN 2023 - 2024-01-10 · READ THE OFFICIAL RECORD

  7. The National Multimodal Large Language Model Programme aims to develop Large Language Models (LLMs) that are more suited for our context. The Southeast Asian Languages in One Network (SEA-LION) model that was recently released was trained on a dataset that has more than 10 languages, including colloquial English (or Singlish), Chinese, Malay and Tamil. In the next phase, the programme will look at techniques to incorporate speech data containing non-verbal cues such as tone and pitch, to augment SEA-LION. For this, they will first evaluate the model performance when non-textual data in standard and colloquial English are added, before moving on to other languages. As we build our local expertise in developing and training regional LLMs through this effort, we will closely monitor ongoing developments and will adapt our plans as the technologies in the field evolve.

    USE OF NON-TEXTUAL TRAINING DATA FOR SINGAPORE'S COMMON LANGUAGES IN NATIONAL MULTIMODAL LARGE LANGUAGE MODEL PROGRAMME - 2024-01-10 · READ THE OFFICIAL RECORD

  8. In today’s cyber threat environment, a strong cybersecurity posture is essential. Even with best efforts, not all attacks will be prevented. There must therefore be resilience built into our systems. They must be robust and have the ability to resume normal operations without prolonged disruption. For critical information infrastructure (CII), all entities, government and non-government, are regulated in the same way under the Cybersecurity Act. The Cyber Security Agency of Singapore provides cybersecurity support in the design of networks and systems, and issues advisories on the latest threats and the precautionary measures to be taken. Sector regulators, such as for financial services, water and healthcare, may also have additional specific cybersecurity requirements for organisations operating within their sectors. All companies and organisations, and not just those owning CIIs, should practise strong cybersecurity hygiene. They should make use of the resources available, to put in place the necessary cyber defences and be prepared to respond to cyber attacks swiftly and effectively.

    EXTENSION OF GOVERNMENT CYBERSECURITY AGENCIES' ADVISORY SUPPORT TO NON-GOVERNMENT ENTITIES - 2024-01-10 · READ THE OFFICIAL RECORD

  9. We expect artificial intelligence (AI) to be deployed in a responsible and ethical way, so that its benefits can be enjoyed safely by all. Singapore’s practical and risk-based approach to the governance of AI has been explained at previous Sittings, most recently on 22 November 20231. We launched (a) the Model AI Governance Framework in 2019; and (b) AI Verify in 2022, a toolkit that helps companies be more transparent about their AI systems, in areas such as fairness and explainability. We also engage widely with international partners on AI governance through multilateral platforms such as the Global Partnership on AI. Together, these efforts help ensure that all Singaporeans can interact with AI systems with confidence. Recent advancements in generative AI have raised copyright concerns – for example, around the use of copyrighted materials for model training and copyright for AI-generated content. This is an area that many jurisdictions, including Singapore, are studying. The Ministry of Law and the Intellectual Property Office of Singapore have been engaging stakeholders and will develop an appropriate response in due time. Given the fast-evolving developments in AI, we cannot adopt a one-size-fits-all approach to regulate it, nor can we anticipate every risk out there. We have been reviewing our regulations and governance frameworks to ensure that they remain fit-for-purpose and will continue to do so as we implement our refreshed AI Strategy.

    GAINING SUPPORT FOR STRONGER FRAMEWORKS TO ENSURE ETHICAL USE OF AI TECHNOLOGY - 2024-01-10 · READ THE OFFICIAL RECORD

  10. Mr Speaker, I invite Mr Leong to file a Parliamentary Question on that. I think that will be more appropriate, so that a proper response can be given.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  11. Mr Speaker, I appreciate Ms Lim for her clarifications. I do not think there is a question that we are each entitled to our opinions. This was not a question of opinion at all. It is simply to say that following the debate, whatever goes on to social media for the benefit of the people who are not able to take part in this discussion, I hope that messages being put out by MPs do not simply use very sensational, glaring headlines. I would very much appreciate if we can keep our efforts focused on the actual things that will make a difference. That is all I am asking for. I appreciate that if there is alignment on this issue across the aisle. And I would also urge MPs – let us try to keep it that way. It is the only way we can win this war against the scammers.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  12. (In Mandarin): [Please refer to Vernacular Speech.] Mr Speaker, firstly, I would like to reiterate my support for the Motion put forward by Ms Tin Pei Ling. Singapore's digital journey has brought great benefits, such as new economic opportunities for our people and businesses. However, it has also introduced new risks, including digitally-enabled scams that many people are concerned about. Therefore, the Government must enable our people to ride the wave of opportunities arising from our digital transformation, whilst doing everything possible to strengthen safety and trust in our digital domain. To this end, the Government has prioritised efforts to deal with scams. Many measures have been implemented and proven to be effective. However, as the scammers evolve their tactics, we too must update our counter measures. The Government will introduce three new measures to further strengthen our defences against scams. They are: enhancing the security of mobile applications; advisory guidelines for telcos to protect vulnerable consumers; and efforts to develop advanced technologies to combat scams. There is no silver bullet in the fight against scams; neither can the Government do it alone. This is a long-term battle that requires everyone's cooperation. But I believe that with persistent efforts and contributions from everyone, the battle can eventually be won. Thank you.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  13. Second, we should educate ourselves on the latest scam trends and anti-scam measures such as those on ScamAlert.sg. We should use available tools to make more informed decisions when transacting online. These include the E-commerce Marketplace Transaction Safety Ratings (TSR), which provide information on how secure an e-commerce platform is against scams. Even as we continue our efforts to stop scams and recover losses, we must not forget about the trauma experienced by victims. We understand the panic and anxiety that victims go through. That is why the SPF has trained volunteer Victim Care Officers to provide emotional and practical support to victims. The Anti-Scam Resource Guide on SPF's website also sets out additional avenues of community support. Mr Sharael Taha suggested reviewing the process of freezing bank accounts for the entire duration of the investigation period. SPF only freezes bank accounts when there is reason to suspect that they are involved in criminal activities. The time taken for investigations can differ from case to case. Victims with frozen bank accounts may be offered new ones by banks, which may come with restricted access to certain facilities, or be subject to enhanced monitoring measures. But these will still meet basic banking needs such as receiving salaries and Government support. Victims can also make an application to the Courts to withdraw money for reasonable living or other legitimate expenses. Mr Speaker, please allow me to conclude in Mandarin.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  14. As a first step, MCI and the Agency for Science, Technology and Research (A*STAR) will officially launch the Centre for Advanced Technologies in Online Safety (CATOS). The Centre will be a platform to bring together our community of research partners, companies and practitioners in Singapore to build capabilities for a safer Internet. Such capabilities may include tools and measures to: (a) detect harmful content, such as deepfakes and non-factual claims; (b) inject watermarks or trace the origin of digital content; and (c) empower vulnerable groups with resources to verify information they encounter online. These research efforts will also help inform new legislation or regulations that we will need for issues, such as deepfakes, and which we are studying. As Ms Tan pointed out, even with extensive efforts by the Government and businesses, we must each do our part as individuals to remain vigilant online. First, we should adopt measures that can mitigate the risks of scams, even if they may seem inconvenient or unnecessarily strict. This could mean downloading and enabling the ScamShield app or turning on multi-factor authentication for online services. We should avoid downloading apps from unfamiliar sources and avoid responding to suspicious videos promising guaranteed returns on investments or giveaways. When accessing websites, individuals should also exercise vigilance by always checking the URL in the address bar of their web browser. We agree with Mr Ong that consumer banking and messaging service providers can do more to prompt users to adopt such habits. The Government will continue working with key industry players to further strengthen efforts to raise public awareness.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  15. The Standard will also recommend that developers build in malware detection capabilities on their apps, since this feature has proven to be effective in disrupting scammers' unauthorised transactions using compromised devices. CSA will incorporate more of such effective practices in the Standard as they emerge or as the technologies evolve. CSA will also consider how best to help end-users easily identify apps that meet these Standards. As the Standard is new, we will assess its usefulness in due course and whether to keep it voluntary or make it mandatory. Besides apps that people use, we must also better protect vulnerable segments. To strengthen safeguards against them being tricked into signing up and footing the bill for phone lines used for scams, IMDA has published the Advisory Guidelines for telcos to protect vulnerable consumers. It calls for measures to help frontline staff identify vulnerable consumers during service sign-up and handle cases of suspected exploitation. The Guidelines also encourage telcos to waive charges for vulnerable consumers who have fallen victim to scams. Arising from earlier cases encountered, MHA is also exploring ways to better protect the public, particularly those who continue to believe the scammers, despite being warned by the Police and even their own family members. As the landscape evolves, we will need to grow new capabilities to keep pace with scammers and online risks. Several Members mentioned the misuse of deepfakes to create compelling pitches, such as the recent ads featuring our leaders' likeness to promote crypto scams. We are most concerned about this.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  16. By all means recognise the fact that there are also private sector players involved. It is hard work. And I think one of the Members said it is quite thankless. I believe it was Ms Hany Soh who said so and I appreciate her for acknowledging that. So, let us cheer them on. It is not so easy. So, Sir, overall, I am still very glad that all parties support the Motion and have largely avoided grandstanding. I call on Members to please use your own networks and your social media influence not to spread this, you know, very easy labels, to tag onto something like this, but to spread awareness of the tools that can really help people. I think that is a far better use of your social media influence. Use it appropriately. And my humble appeal to all Members who have contributed your ideas and suggestions, please give our agencies time to consider the feedback and to prioritise what is most needle-moving, because, actually, it will not be a matter of doing more, but doing more of the right things continuously. At any one time, we will be introducing new measures while designing some more. In fact, I would like to announce three today. As apps are the most common way to transact online, we also need app developers to design for security. This is why Cyber Security Agency (CSA) is publishing a new recommended Safe App Standard (Standard) that app developers should adopt to ensure that high-risk monetary transactions performed on their apps are secure. The Standard will set out best practices that reduce the risk of malicious actors exploiting weaknesses in the app design. For example, apps could be designed to require additional authentication of a user before authorising high-risk transactions, such as those providing access to our assets or savings.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  17. Do not go around vilifying various groups and saying that you should have done this, you should have done that. We will need them at some point. It is better to preserve the relationship and find ways to work together. So, in this context, I was listening carefully to Members' contributions and I appreciate all of them a great deal. I could not help but notice that, amongst the Members who spoke from the Workers' Party, there was this term that was repeated quite a few times. This is what Mr Vikram Nair also responded to. He said that he disagreed with this idea that there is a crisis of confidence. I am not sure what the purpose of describing this problem this way is. We do have a situation that we are dealing with and we are taking it very seriously. But let me perhaps offer a viewpoint from the agencies and the officers who are looking at this problem and listening to this debate and share what it comes across like to them. This is a bit like, you know, firefighters on the frontline. You are trying all ways and means to, firstly, figure out what is the terrain that you are working with and trying to push back the fire, not let it spread. And there, we have a group of bystanders who are, you know, instead of praying for them, encouraging them, we are saying to them: you should be doing this, you should be doing that – pontificating. And then, when they do manage to put out some fires, with great effort and actually getting ready to fight the next fire because they know it is coming, the very same bystanders say, "Thank goodness, I said that." You know, see, how wonderful! I say to Members, have a care. This is a tough fight and I think our agencies and all the people involved they are not just public officers.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  18. I appreciate that it sometimes makes them quite anxious – because they keep hearing about it when they are at the bus stop, they see it when they are at the void deck and they see the digital display panels and then they go to a grassroots event and the Member of Parliament is also advising them to listen to the Police talk about anti-scam measures. So, I appreciate this. It gives a certain sense of anxiety. But it is an essential part of our overall scam defence which we cannot avoid and which we aim to fortify through a variety of means. And so, the question is: what more can we do? First, let us take a step back and acknowledge that all countries recognise that when it comes to dealing with scams, there is really no silver bullet. There is not a single measure that you can implement and be done with it. In the trade, they call this a wicked problem. In cyber as well as in scams, you solve one problem, the bad actors are driven somewhere else and you have to start again. Therefore, an agile approach is critical and a very good example is how we had to very quickly pivot to dealing with the malware-enabled scams which had not been conceived of before and had not been seen before. It is very easy to say that, "You should have anticipated it." Not so easy in reality. The last thing, in this context, is not for us to politicise the debate or to vilify any group because you do not know when the next scam variant comes around who you need to work with to try and solve the problem. So, vilifying any group is not a good idea and we should very consciously try to avoid this. This is a problem that has emerged and we have observed in other countries. This is one lesson that we are taking away.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  19. And these include widespread call blocking, the SMS Sender ID Registry (SSIR) and the kill switches that the banks now use; and also CPF Board. The fact that we have an Anti-Scam Command, which involves the co-location of banks and, soon, other entities that we are speaking with; the fact that we have ScamShield; and something that people in the trade are very interested about: the backend processes that none of us will get to talk about in this room – among the agencies and all the stakeholders to smoothen the process of following up on leads – that is something that they find very difficult to even bring about. Many measures have also reduced the losses – stemmed the losses – to a very significant extent. So, then that begs the question, "What about these rankings that you come across that named Singapore as one of these top places in terms of how much victims have lost?" Well, I can only say this. In many places, scam victims are not going to take the trouble to report the fact that they have been scammed, because they do not expect whichever authority they report to, to be able to do anything about it. And so, when these kinds of reports are a function of reporting, what this really tells us is that reporting levels in Singapore are very high. This is, of course, not to trivialise the amounts lost. But I think we have to recognise that fact. In this regard, I think we also have to recognise that our members of the public have been quite remarkable in terms of their openness and willingness to pay attention to public education efforts on scams.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  20. These complementary measures notwithstanding, the Government will consider how to enhance the accountability of key entities and strengthen protection for individuals within SRF or through other means that are available to us. We hear the specific calls to include social media platforms and closed-messaging services, in particular, for scam variants involving malware and phishing that result in unauthorised transactions. I appreciate Mr Vikram Nair and Ms Hazel Poa's acknowledgment that there are trade-offs and moral hazards to consider and that the Government cannot take a one-size-fits-all approach. With regard to physical tokens, these are available upon customer request. I should caution, however, that existing physical tokens may be resistant to malware, but they are still vulnerable to phishing tactics. Agencies are, therefore, studying longer-term solutions, such as the Fast IDentity Online (FIDO) passkeys that were mentioned by Ms Tin. Sir, I thank Members who have recognised the many steps we are taking and also the challenges our agencies face, such as those identified by Mr Vikram Nair. To Mr Yip Hon Weng's suggestion to learn from best practices abroad, we have been proactive. Our efforts include exchanging information on the latest scam variants and strategies to combat scams. However, all of these efforts notwithstanding, this may still beg the question, "Has Singapore been slack in fighting scams?" On the contrary, Singapore is widely regarded as a leader in thought and action when it comes to battling scams. When interacting with our international counterparts, I can only share with you how much they marvel at some of the initiatives that we have put in place, which they consider quite unthinkable in their own context and still quite cutting edge.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  21. Some customers felt inconvenienced, but in fact, they may have been among those that were saved from at least $2 million in losses in the first month of roll-out. The MAS has since worked with other major banks to implement similar safeguards. Several MPs also spoke about the need for larger companies to take more responsibility to mitigate scams by unauthorised transactions. This year, the upcoming Shared Responsibility Framework (SRF) will further enhance the accountability of the banks and telcos in protecting their customers from the threat of phishing scams. During the public consultation on the SRF, many suggestions were received, which are similar to those raised today. They relate to the expansion of coverage to more scam types and more entities, besides banks and telcos. The SRF covers phishing scams because such scams were the main contributor to fraudulent transactions taking place without the consumer's knowledge and consent when SRF was first conceived. Compared to the payout frameworks in other jurisdictions, which only impose obligations on banks, the SRF already holds a wider scope of entities accountable by including telcos. Duties are also specified to clearly hold banks and telcos accountable to the victims. Even if there is no breach of duty and, hence, no payout under SRF, there are other avenues of recourse for victims. These include banks' goodwill frameworks, which can provide some comfort to victims of new scam tactics. As was shared in Parliament last year, MAS has leaned on the banks to be more accommodative in applying their goodwill frameworks.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  22. Also last year, we observed the emergence of scammers exploiting malware to bypass existing safeguards and make unauthorised fraudulent transactions on victims' accounts. Having identified this new scam variant, we worked with the banks to enhance their fraud and malware detection capabilities. Compromised devices were prevented from transacting with the banks. We cannot quantify it but millions more dollars could otherwise have been lost. Ultimately, our devices themselves must be better able to defend against malware attacks launched by scammers – Ms Tin spoke about this. We are therefore working with key industry players to enhance the security of mobile devices sold in Singapore. For instance, we are working with Google to design new features that can better detect and deter users from downloading malicious files onto Android devices. The third set of measures involve harsher consequences to deter money mules from misusing our key digital services, such as Singpass, to perpetrate scams. We have recently tightened our legislation to criminalise individuals who intentionally disclose their Singpass credentials in aid of scams. We are also reviewing how to extend these principles to those who sell SIM cards to scammers. Sir, fighting scams is a team effort and the Government cannot do it alone. Ms Tan spoke about the need for platform players, telcos and device manufacturers to do more to improve online safety for their users. We agree. As mentioned by Mr Ong and Mr Tan, we need companies to ensure that their customers can enjoy a safe and secure environment as they interact online. Last August, OCBC was among the first banks in Singapore to disallow account access, if the bank app detected the presence of potentially risky mobile apps on the customers' devices.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  23. To further protect the public, telcos have now introduced an option for subscribers to block their mobile phones from receiving international calls, which is a common source of scam calls. Sir, whilst we can introduce blocking measures, we must expect the scammers to keep starting fires in new ways. As mentioned by Mr Ong, scammers are increasingly abusing online platforms to deceive their potential victims. To deal with this more effectively, we introduced the Online Criminal Harms Act (OCHA), which will be progressively implemented from this year. Many Members supported the Bill and I thank them again. This Act will allow authorities to order the swift blocking of online accounts or content suspected to be used for crimes, including scams. For the protection of consumer on high-risk platforms, we will also impose ex-ante requirements such as stricter requirements for identity verification. The second set of preventive safeguards aim to disrupt fraudulent transactions, even after a victim has been tricked. This includes preventing Singpass accounts from being taken over. It is why last year, we introduced more friction into the authentication process for Singpass. When conducting high-risk transactions, users are required to perform facial verification. To protect against impersonation attempts, which Ms Hazel Poa asked about, facial verification includes liveness checks, which guards against attacks such as using a still photo. Facial verification was also introduced as an additional safeguard for high-risk CPF e-services. Since then, there have been no further losses to scams due to unauthorised CPF withdrawals.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  24. In November last year, several banks implemented a "Money Lock" feature, allowing customers to set aside an amount in their bank accounts that cannot be transferred digitally. Another recent example is the lower default daily limit for online CPF withdrawals, which cannot be increased without strong user authentication. Members can also disable online CPF withdrawals easily by activating the CPF Withdrawal Lock, which instantly reduces this limit to $0. Sir, these containment efforts are helpful but we really prefer to prevent the scams from happening in the first place. Preventive safeguards are easier said than done, as they require close coordination with industry. Several sets of measures have been or are being implemented. First, we will keep closing off known avenues for scammers to reach prospective victims. Members will recall that not too long ago, scammers were spoofing the SMS IDs of key organisations to trick victims into giving their banking credentials. To counter this, IMDA introduced a novel solution. From January last year, all organisations that want to send SMSes using alphanumeric sender IDs had to register with the Singapore SMS Sender ID Registry (SSIR). SMSes from unregistered senders are labelled "Likely-SCAM" to alert phone users. The SSIR has been effective. Cases of scam SMSes fell by 70% in the first three months that it was mandated and remain a minority – less than 5% – among new cases reported. Additionally, telcos have implemented firewalls within their networks to proactively block suspicious calls and calls that attempt to spoof local numbers. These efforts have also been helpful. The volume of suspicious international calls blocked in 2023 has nearly doubled compared to a year ago.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  25. Through variety, speed and scale, they have claimed more victims than before. Whenever I speak with a scam victim and hear their harrowing experience, I am reminded of a very similar panic I experienced as a child. Back in the 1970s, I lived with my grandmother in an old shophouse in Joo Chiat. On several occasions, we were awakened in the middle of the night to nearby shouts of "Fire! Fire!". We had very little clue as to how far and fast the fire might reach us, only that we must be ready to run for our lives. This kind of fear and helplessness, you never forget. Today, fire hazards have largely been brought under control and most fire incidents have moderate impact. This is because we have well-trained and well-equipped firefighters to contain fires that do break out. There are regulations, including the Fire Safety Code, to prevent potential fire incidents. We also have the support of organisations and citizens alike, who do their part to create and maintain an environment safe from fires. In many ways, we are fighting scams like how we successfully fought fires. We have invested resources to strengthen our capabilities to contain the impact of emerging scam campaigns. Two years ago, the Singapore Police Force (SPF) established the Anti-Scam Command (ASCom). This helps to facilitate the swift tracing of funds and freezing of scam-tainted bank accounts. In the first half of 2023, the ASCom froze over 9,000 bank accounts and recovered about $50.8 million of the victims' losses. We have also put in place tools to limit losses for victims, much like the use of retardants to slow the spread of fires. Banks have implemented an emergency "kill-switch", so customers can quickly suspend their accounts if they suspect compromise.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  26. In 2021, Singapore became one of the first in the world to develop a testing framework and software toolkit for safe and responsible AI, which we call AI Verify. More recently, we committed to develop Advisory Guidelines on the use of personal data in AI systems, including safeguards to protect personal data of vulnerable groups like children. Global conversations on AI governance are important. Singapore will continue to participate actively at international fora, such as the Global Partnership on AI and the United Nations' High Level Advisory Board on AI. As mentioned by Ms Tan and Ms Mariam, we have refreshed our AI strategies through NAIS 2.0. We will soon update our recommendations on dealing with AI risks. For example, we are very concerned about the mis-use of generative AI to spread misinformation and carry out targeted scams. Mitigating biasness and enhancing the explainability of AI models are also crucial to developing and deploying them responsibly. We aim to release MGF 2.0 for public consultation later this month. Of all the risks in the digital domain, one category is particularly concerning – and they are scams. This was an issue raised by almost all MPs. Recent concerns about scams may sound new, but are in fact very similar to past cases of fraud. Older Singaporeans may remember the sale of fake insurance policies in the 1970s. In 2006, Sunshine Empire, which disguised itself as a multi-level marketing company, operated a Ponzi Scheme that promised high returns on fake products and services. In the early 2010s, the SureWin4U Ponzi Scheme lured victims to invest in betting schemes against casinos. These days, scammers use technology to sell fake jobs, fake love and fake discounted items like eggs or holiday packages.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  27. Currently, online harassment and doxxing are dealt with under the Protection from Harassment Act 2014. Victims can seek redress through the Protection from Harassment Court, which has served thousands since it was set up in 2021. The Ministry of Law (MinLaw) is looking further into how victims can be better empowered to put a stop to such online harms, and to seek redress from those responsible. MinLaw's efforts will complement MCI's efforts to enhance the Government's regulatory tool kit, as well as the Ministry of Home Affairs (MHA)'s efforts to address online criminal harms, which I will say more about later. Sir, from what I have cited, Members will see that we have actively and progressively introduced new laws and regulations for digital governance. We have consciously avoided a big-bang approach, choosing instead an accretive approach to understand the issues deeply and to move quickly when we identify measures that are likely to be effective. Where solutions are untested, we have not held back completely. Instead, we have introduced model frameworks or advisory guidelines for voluntary adoption. We have also developed practical tools to help organisations meet their regulatory obligations, or raised governance standards. This will remain Singapore's approach to digital governance for the foreseeable future. It was, in fact, how we dealt with AI governance. I thank Dr Rizal, Mr Jamus Lim and Ms Mariam for emphasising the importance of responsible AI use and development. Members may recall that even before we launched our first National AI Strategy or NAIS in 2019, we had introduced a Model AI Governance Framework or MGF – the first of its kind in the region.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  28. As a small, multiracial, and multi-religious country, Singapore is particularly vulnerable to falsehoods that deepen fault lines and polarise society. POFMA is a calibrated tool to safeguard the infrastructure of fact. Its usefulness was especially evident during the COVID-19 pandemic, to defend against all kinds of falsehoods about vaccines and COVID-19 related deaths. In 2021, to counter potential hostile information campaigns launched by other states against us, we introduced the Foreign Interference (Countermeasures) Act (FICA). This helps to ensure that Singapore politics remains only for Singaporeans. Dr Wan Rizal, Ms Mariam Jaafar and Ms Nadia Samdin spoke about the risks of children being exposed to harmful content online. We have also introduced measures to tackle this. In July 2023, the Infocomm Media Development Authority (IMDA) launched the Code of Practice for Online Safety. It requires social media services with significant reach or impact in Singapore to put in place measures to minimise users' exposure to harmful content on their platforms. These include additional measures to protect children below-18 years old. Dr Rizal and Ms Nadia suggested that platforms implement age assurance measures. There is currently no foolproof measure to prevent false age declarations on social media platforms. But the technology has improved. Today, age assurance is achievable to a fairly high degree of accuracy without compromising privacy. MCI and IMDA are monitoring the developments and will study viable regulatory options to better protect children online through age assurance measures. I am aware that Mr Darryl David will speak about addressing online dangers such as cyber stalking and body shaming, and providing support for victims.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  29. The first is what we have we done so far to protect Singaporeans in the digital domain; and the second, what more we need to keep people safe. Sir, in most domains, Singapore could learn from the examples of many other countries when designing our own governance approach. Unfortunately, in the digital domain, there are few ready playbooks with proven solutions. In fact, Singapore is considered an early mover in digital governance and has been recognised as such. Mr Mark Lee spoke about the need for our businesses to protect and handle customer information ethically. We moved to address this issue more than a decade ago. In 2012, we introduced the Personal Data Protection Act (PDPA), before the EU's General Data Protection Regulation. By 2020, we had amended the Act to strengthen organisational accountability and consumer protection, while bolstering confidence for using personal data for innovation. In 2018, we enacted the Cybersecurity Act to address the threats in cyberspace, particularly those faced by our critical information infrastructure (CII). Beyond protecting our CII, we have also introduced initiatives to help businesses enhance their cybersecurity posture. Mr Lee recommended developing sector-specific resources. We agree. In the next phase of the SG Cyber Safe Programme for enterprises, CSA will introduce sector-specific cybersecurity initiatives, starting with healthcare and manufacturing. Also, I had previously announced that we expect to update the Cybersecurity Act so that it remains fit-for-purpose. Public consultations on the proposed amendments are ongoing. In 2019, recognising the harms of misinformation, we introduced the Prevention of Online Falsehoods and Manipulation Act (POFMA).

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  30. Mr Speaker, Sir, I rise in support of the Motion in the name of Ms Tin Pei Ling and thank her, together with Mr Sharael Taha, Ms Hany Soh, Ms Jessica Tan and Mr Alex Yam, for drawing attention to this important topic. When the Smart Nation Initiative was launched in 2014, we envisioned Singapore as "a nation where people live meaningful and fulfilled lives, enabled seamlessly by technology, offering exciting opportunities for all." A decade on, this vision has certainly come alive. Technology has become a big part of our daily lives and 84% of Singaporeans say they have benefited in one way or another. Of every $100 value-added in our economy, at least $17 can now be attributed to digital-related activities. It amounted to $106 billion in 2022, more than financial services and insurance, and comparable with wholesale trade. There are, today, more than 200,000 tech jobs in Singapore, earning median wages that are higher than that of the resident workforce. Although they represent just over 5% of all jobs, there are thousands more across all other sectors that have been enhanced by digital technologies. Our aim must be for all Singaporeans to gain from these developments. Senior Minister of State Tan Kiat How has spoken about digital inclusion and the Government's efforts to ensure that benefits are felt by all segments of society. At the same time, our digital way of life has exposed us to new risks. Cyberattacks, scams and harmful content pose a growing threat to our safety and security. As many Members have noted, trust in society, so crucial for normal human interactions, could be undermined. I will focus my speech on two topics specifically.

    BUILDING AN INCLUSIVE AND SAFE DIGITAL SOCIETY - 2024-01-10 · READ THE OFFICIAL RECORD

  31. Our regulatory regime to combat unsolicited communications consists of the Do Not Call (DNC) Provisions within the Personal Data Protection Act 2012 (PDPA) and Spam Control Act 2007 (SCA). They cover different areas. The PDPA's DNC Provisions cover the sending of unsolicited marketing messages communicated via voice, text and fax messages to Singapore telephone numbers. There has been a significant reduction in the number of DNC complaints received by the Personal Data Protection Commission (PDPC) over the past five years, as reflected in Table 1 below. SCA complements the DNC Provisions by setting out requirements in relation to the sending of unsolicited marketing emails. SCA adopts a civil-based regime for the enforcement of its requirements, where aggrieved parties can take direct legal action against senders. Given the civil-based regime, there is no specific enforcement authority. Consequently, PDPC does not track individual cases.

    COMPLAINTS OF UNSOLICITED MARKETING COMMUNICATIONS RECEIVED AND EFFECTIVENESS OF SPAM CONTROL ACT - 2024-01-09 · READ THE OFFICIAL RECORD

  32. There were no cybersecurity breaches of the Singapore Personal Access (Singpass) system detected in the last five years. The Government Technology Agency (GovTech) continually strengthens the Singpass system against potential breaches. In addition to cybersecurity testing conducted by the Government, crowdsourced vulnerability discovery programmes are applied to Singpass. These include the Vulnerability Reward Programme, Vulnerability Disclosure Programme and the Government Bug Bounty Programme, which run at different time periods and draw on different pools of cybersecurity experts. Beyond technical cybersecurity breaches, the human user is often the weakest link. That is why we are taking measures to make it harder for scammers to use phishing and other social engineering methods to gain control of a user's Singpass account. For example, for transactions identified to be of higher risk, we require more than the standard two-factor authentication of a password and one-time password. The account is protected by additional factors, such as facial verification. Secure online transactions and a safe cyberspace need everyone to play their part. We are constantly improving and testing Singpass' defences to guard against cybersecurity and scam threats. We call upon banks and telcos to enhance their defences and strengthen the cybersecurity ecosystem. Users need to arm themselves with knowledge of scam tactics, social engineering and phishing to avoid being scammed. A vigilant and discerning public is our best defence against scams.

    BREACHES OF SINGPASS IN LAST FIVE YEARS AND STEPS TO ENHANCE ITS SECURITY - 2024-01-09 · READ THE OFFICIAL RECORD

  33. Artificial intelligence (AI) development is changing every day and its impact on the workforce is not fully predictable. As with other technologies, the Government's consistent approach has been to maximise the potential of our businesses and workers to harness AI as an opportunity, through supporting their efforts to adapt. This has helped our economy to expand and our workers to enjoy improved employment outcomes. In particular, Jobs Transformation Maps specific to sectors, will help employers and workers understand and prepare themselves for the future of work that is influenced by AI. Through SkillsFuture courses as well as Workforce Singapore's job redesign and career conversion programmes, workers can upskill and reskill to work in roles that may be transformed by AI. For those who wish to transit to AI tech roles, IMDA's TechSkills Accelerator supports fresh and mid-career workers to be equipped with relevant skills. Singapore's educated and skilled population is well-placed to take advantage of AI, as we have done so in previous waves of technological change. The Government will continue to work with our tripartite partners to support our workforce.

    WORKERS FACING HIGHEST RISK OF DISPLACEMENT FROM ARTIFICIAL INTELLIGENCE AND RESKILLING PROGRAMMES AVAILABLE - 2024-01-09 · READ THE OFFICIAL RECORD

  34. An important enabler of our National Artificial Intelligence Strategy (NAIS) 2.0 strategy is artificial intelligence (AI) compute power housed in data centres (DCs) in Singapore. The Government is committed to anchoring the necessary compute power and growing the DC sector in a sustainable manner, consistent with our international climate commitments. One key strategy is to improve the energy efficiency of DCs and facilitate the deployment of efficient cooling solutions. For example, AI compute infrastructure typically relies on liquid cooling, which is more energy-efficient than air cooling for such intensive workloads. Other measures include: (a) supporting DC operators to reduce greenhouse gas emissions through the Economic Development Board's Resource Efficiency Grant for Emissions; (b) developing sustainability standards, such as the Infocomm Media Development Authority's (IMDA)'s Tropical DC Standards that enable DCs to operate safely at higher temperatures and use less energy for cooling; and (c) reviewing Building and Construction Authority (BCA)-IMDA's Green Mark for DCs certification scheme to update the energy-efficiency criteria. Beyond sustainable AI compute infrastructure, it is important to invest in the development of green computing methods. These methods include (a) coding and algorithm optimisation, (b) software-hardware optimisation, and (c) developing standards for low-data, low-energy AI models. The Government will continue to deepen international and domestic partnerships with the research community and industry partners on this front.

    NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2.0 VS ENERGY AND ENVIRONMENTAL SUSTAINABILITY - 2024-01-09 · READ THE OFFICIAL RECORD

  35. The Infocomm Media Development Authority (IMDA) and Ministry of Education (MOE) introduced the Code for Fun (CFF) enrichment programme in 2014 to expose primary and secondary school students to coding and computational thinking. Since 2020, it has been mandatory for all upper primary school students to go through CFF or a comparable coding programme. While CFF remains an optional programme at the secondary school level, almost two-thirds of secondary schools offered the programme in 2023, up from 48% in 2021. More than 50,000 students are reached through these programmes every year. As technology continues to evolve quickly, IMDA and MOE review CFF regularly to ensure that the programme is relevant and up to date. As part of its programme design, CFF covers emerging technologies, such as artificial intelligence (AI). We are working towards introducing new content on AI and data literacy in the refreshed CFF for 2025. MOE provides opportunities for students to develop knowledge of digital and AI literacies, as well as emerging technologies through formal curriculum, STEM-related co-curricular activities and other enrichment programmes. More information is available in MOE's responses to the Parliamentary Questions on Incorporating Artificial Intelligence into the Curriculum on 3 July 2023; and Plans to Ensure Singaporeans' Readiness in Technology-driven Economy on 6 January 2020. [Please refer to (a) "Incorporating Artificial Intelligence into School Curriculum", Official Report, 3 July 2023, Vol 95, Issue 105, Written Answers to Questions for Oral Answer not Answered by End of Question Time section; and (b) "Plans to Ensure Singaporeans' Readiness in Technology-driven Economy", Official Report, 6 January 2020, Vol 94, Issue 115, Written Answers to Questions section.]

    PROPORTION OF STUDENTS WHO HAVE UNDERGONE CODE FOR FUN ENRICHMENT PROGRAMME - 2024-01-09 · READ THE OFFICIAL RECORD

  36. Should service disruptions occur, telecommunication service providers are expected to restore services quickly, undertake rectification measures to prevent recurrences and offer appropriate measures, such as fee waivers, to mitigate the impact on affected users. Financial penalties may also be imposed on telecommunication service providers found responsible for the service disruptions. That said, regulations and penalties cannot fully eliminate the possibility of service disruptions. Businesses and end users should plan and prepare for contingencies by leveraging upon the diversity of networks or service providers, based on their needs.

    RESILIENCY OF KEY TELECOMMUNICATION NETWORKS AND SERVICES AGAINST MASSIVE OUTAGES - 2024-01-09 · READ THE OFFICIAL RECORD

  37. Telecommunication networks and services are essential to the public and businesses, enabling communication and connectivity between people and businesses. Singapore's key fixed and mobile telecommunication networks are required to be designed for resilience with high availability, on par with international standards. Key telecommunication service providers are also required to uphold service quality standards, such as: (a) providing nationwide outdoor service coverage of at least 99% for mobile services; and (b) ensuring network availability of at least 99.9% for fibre broadband services. They have consistently met these requirements. These providers are also required to conduct continuous regular audits in areas like their infrastructure, processes and business continuity plans to ensure that the resilience of their networks is on par with industry standards and international best practices, for example, those set by global bodies, such as the International Telecommunication Union and International Organization for Standardization. They have consistently achieved a high level of compliance for past audits for both fixed and mobile networks. To achieve a high level of resilience, critical network components of each fixed and mobile network are built with failover capabilities and diversity, to minimise widespread service disruptions. At the system level, resilience is further achieved through a diversity of networks, with multiple service providers offering a variety of mobile, broadband and public wi-fi services.

    RESILIENCY OF KEY TELECOMMUNICATION NETWORKS AND SERVICES AGAINST MASSIVE OUTAGES - 2024-01-09 · READ THE OFFICIAL RECORD

  38. In the past, consumers and businesses relied on post offices as physical touch points to buy stamps and mail letters and parcels. Today, most post and parcel transactions are already served through automated means and do not need to be done over-the-counter at post offices. For example, postage labels can be purchased at self-service automated machines (SAMs) and parcels can be dropped off or picked up at POPStations. In addition, about 80% of transactions at post offices today are for non-postal services, such as passport collection and payment of bills, which can be completed through alternative means. Overall, the total number of transactions at post offices has also declined by 35%, from 10.3 million in FY2019 to 6.5 million in FY2022. These trends have been similarly observed at Yishun Central Post Office. As I shared in Parliament in October last year, with the evolving post and parcel landscape, and changing business and consumer needs, SingPost has been reviewing its costs and operations as part of its business transformation. This is so that it can better balance commercial sustainability while serving the public's postal needs. The closures of some of SingPost's post office network is part of this review and SingPost is required to ensure that the postal needs of the community will continue to be met through alternative means, such as the SingPost mobile app, SAM kiosks, POPStations and PO boxes. I understand Mr Derrick Goh's concerns about the impact of the closure of the Yishun Central Post Office on his residents. As with other post office closures, SingPost will notify the public at least one month ahead of closure. Customers will also continue to have access to a SAM kiosk and POPStation near to the original post office.

    ASSESSMENT CRITERIA FOR CLOSURE OF SINGPOST BRANCHES - 2024-01-09 · READ THE OFFICIAL RECORD

  39. The Government's longstanding policy is to promote the use of Mandarin, as one of our four official languages. Free-to-Air (FTA) TV and radio cater to a wide range of audiences and are, therefore, required to offer Chinese services in Mandarin. Nonetheless, dialect content remains available. Mediacorp's Channel 8 provides a dedicated belt of dialect programmes every Friday morning. Its radio station, Capital 95.8FM, offers daily news bulletins in various dialects. Dialect is also allowed for operatic performances or when the Mandarin terms are not commonly used. Dialect content is available on other platforms as well, such as Mediacorp's meWATCH, online platforms like YouTube, videos and music albums in retail stores, as well as through outdoor and theatrical performances. There are currently no plans to allow more dialect programmes on FTA TV and radio. A Ministry of Communications and Information study in 2023 found that almost seven in 10 respondents chose Mandarin as the language that they can read or listen in. A very small number chose dialect exclusively. In addition, more than half of the respondents across all age groups felt that the amount of dialect content on FTA TV and radio should remain at the current level. That said, we will continue to monitor Singaporeans' views and demand towards dialect content and are prepared to lift the restrictions when the need arises, such as during the COVID-19 pandemic to facilitate health-related information dissemination.

    DIALECT USAGE ON FREE-TO-AIR RADIO AND TELEVISION SERVICES - 2024-01-09 · READ THE OFFICIAL RECORD

  40. Large language models (LLMs), such as those powering ChatGPT, have the potential to enhance the delivery of public services and the productivity of public officers. We adopt a risk-managed approach for LLMs, consistent with the existing public sector framework for the handling of classified information when using technologies, such as Internet-based applications and the commercial cloud. Highly sensitive applications and data are not exposed to the Internet. Where use cases involve sensitive data, open-source models may be finetuned for use but must be deployed on Government servers and computers. For use cases involving less-sensitive data, the artificial intelligence models may be owned and managed by commercial and private companies. Our contracts with these companies are governed by service agreements, which include clauses on data handling and security, such as the non-retention of data, and limitations on the use of data to train other products or models. Beyond contractual safeguards, the Government has also implemented technical measures to screen sensitive data, visual cues to remind users on data security practices and governance measures to enforce compliance. We continuously reassess the adequacy of our measures as the technology evolves.

    REGULATIONS ON INPUT PROMPTS FOR LARGE LANGUAGE MODELS TO PREVENT DISCLOSURE OF CONFIDENTIAL DATA - 2024-01-09 · READ THE OFFICIAL RECORD

  41. We will build on these through our partnership in research and development with the UK AI Safety Institute and our bilateral AI Governance Group with the US respectively, in addition to supporting existing multilateral, multi-stakeholder efforts at the United Nations, World Economic Forum and Global Partnership on AI.

    GOVERNMENT'S APPROACH AND POLICY ON GOVERNING SAFE AND RESPONSIBLE ARTIFICIAL INTELLIGENCE DEVELOPMENT - 2023-11-22 · READ THE OFFICIAL RECORD

  42. Singapore's approach to the responsible development and deployment of artificial intelligence (AI) has been explained at the Sittings on: (a) 21 April 2023; [Please refer to "Regulatory Framework for Artificial Intelligence Governance in Singapore", Official Report, 21 April 2023, Vol 95, Issue 101, Oral Answers to Questions section.] (b) 9 May 2023; [Please refer to "Ensuring Development and Maintenance of Ethical Artificial Intelligence Standards", Official Report, 9 May 2023, Vol 95, Issue 103, Oral Answers to Questions section.] (c) 6 July 2023; [Please refer to "Feasibility of Establishing Body to Regulate Artificial Intelligence", Official Report, 6 July 2023, Vol 95, Issue 108, Oral Answers to Questions section.] (d) 6 November 2023. [Please refer to "Encouraging Companies to Enrol in IMDA's AI Verify Foundation to Uphold Responsible and Ethical Use of AI", Official Report, 6 November 2023, Vol 95, Issue 115, Written Answers to Questions for Oral Answer not Answered by End of Question Time section.] Singapore has been consistent in our support for international efforts that enhance alignment on AI governance. These provide greater certainty and clarity to businesses and citizens, as developers and deployers of AI. Recent initiatives include the Bletchley Declaration in November 2023 and the completion of a joint mapping exercise between IMDA's AI Verify and the US National Institute of Standards and Technology's AI Risk Management Framework in October 2023.

    GOVERNMENT'S APPROACH AND POLICY ON GOVERNING SAFE AND RESPONSIBLE ARTIFICIAL INTELLIGENCE DEVELOPMENT - 2023-11-22 · READ THE OFFICIAL RECORD

  43. The Government recognises that, as we digitalise more, we become more dependent on digital services and infrastructure. We can never rule out cyber incidents or service disruptions happening. The Government and system owners will mitigate and manage these risks, taking into account how critical a given system is. We allocate more resources to harden the most critical systems and ensure a baseline of measures for all systems. Cybersecurity defence has to be complemented by business continuity plans that mitigate the impact of e-service disruptions when they occur. The Cyber Security Agency (CSA) identifies and regulates Critical Information Infrastructure (CII) that are necessary for the provision of essential services in sectors, such as the Government, infocomm, banking and finance and others. For instance, in 2022, Government agencies maintained an availability uptime of at least 99.5% for most of our critical systems, which is equivalent to less than four hours of unscheduled downtime per system per month. Sector regulators also impose requirements on service providers in their respective sectors, such as requirements for service availability in the telecommunications, banking and healthcare sectors. While some disruption might be inevitable, prolonged disruptions should not be the norm. In addition to prevention, we must also focus on recovering quickly. The Ministry of Communications and Information (MCI) has been reviewing our measures to ensure they remain relevant and fit for purpose. For example, CSA is in the midst of reviewing the Cybersecurity Act to look beyond CII and consider other digital infrastructure and services that are important to the nation. MCI will provide more details when ready.

    ENHANCING RESILIENCE FROM LESSONS OF EXTENDED LARGE-SCALE DISTRIBUTED DENIAL-OF-SERVICE ATTACK ON PUBLIC HEALTHCARE INSTITUTIONS ON 1 NOVEMBER 2023 - 2023-11-22 · READ THE OFFICIAL RECORD

  44. Funding for SPH Media Trust (SMT) is earmarked for three key focus areas, namely, Technology Development, Talent Development and the Preservation of Vernacular Media. To ensure prudent use of public funds, the Ministry of Communications and Information (MCI) has been closely monitoring SMT’s performance and its utilisation of funding in support of these areas. Earlier this year, SMT had informed MCI of its plans to acquire Tech in Asia (TIA) and to fund the acquisition through existing resources. As a commercial entity, SMT will have to undertake independent and sound decisions to carry out its mission, including how best to bring about its transformation. While the Government does not get involved in such decisions, we note that the acquisition supports SMT’s transformation and is aligned with the intent of Government funding. We also note that SMT and TIA will not be disclosing the financial terms of this transaction, in view of market sensitivities. On the Member’s concern about agglomeration risks, we should take a broader and more updated view of the media landscape. With the advent of social and digital media, the media industry has seen increasing fragmentation and intense competition both globally and locally, with diverse forms of content offered across a wide range of online and offline platforms. Nonetheless, as with other industries, the Government will continue to protect consumers and prevent anti-competitive practices and will take measures to promote fair and efficient market conduct where necessary.

    RESTRICTIONS ON USE OF $180 MILLION ANNUAL FUNDING TO SPH MEDIA TRUST - 2023-11-22 · READ THE OFFICIAL RECORD

  45. Our position today already states that a higher standard of personal data protection is required when organisations hold large quantities of different types of personal data or hold data that might be more sensitive, such as insurance, medical and financial data. In such cases, organisations are required to implement enhanced data protection practices as stipulated in the PDPC's guide to data protection practices for information and communications technology (ICT) systems. In addition, the PDPC has issued an advisory guideline on enforcement for data protection provisions that makes clear that failure to put in place adequate safeguards for large volumes of sensitive personal data can be taken as an aggravating factor in calculating the level of penalties to be imposed on an organisation. I hope that addresses the Member's questions.

    DATA SECURITY INCIDENT INVOLVING PERSONAL DATA OF MEMBERS OF SHOPPING LOYALTY PROGRAMME - 2023-11-22 · READ THE OFFICIAL RECORD

  46. Mr Speaker, I thank the Member for her supplementary questions. Let me try to address them in turn. The first is on whether the findings of its investigations will be made public – the answer is yes. As to how long that will take, it goes to the complexity of the investigations. And so, it is difficult to say in advance what the duration is likely to be. Her second question relates to whether there were any follow-ups from affected members of MBS. The PDPC received reports from two of those members who were affected. Essentially, they wanted to draw the PDPC's attention to this, in case it was not notified, or it was not yet aware of the breach. And the second is that they also asked that the PDPC take MBS to account for this breach which, of course, the PDPC intended to do in any case. As to how these affected members were being assisted by MBS, I think, in the first place, it is most important for the members to know what types of data have been accessed or revealed as a result of this breach. And so, when MBS notified the affected members, it did clarify that the types of personal data that were revealed, included the name, contact information, country of residence and membership number as well as tier. This was the extent of the breach that the MBS was able to ascertain. It further provided advice to the affected members on how they could safeguard their accounts with MBS, as well as other kinds of personal information. As a responsible measure, they provided a contact for follow-up enquiries, in case the affected members wanted to clarify on various other aspects. Ms Soh's third question had to do with the organisations that could be in possession of large volumes of data.

    DATA SECURITY INCIDENT INVOLVING PERSONAL DATA OF MEMBERS OF SHOPPING LOYALTY PROGRAMME - 2023-11-22 · READ THE OFFICIAL RECORD

  47. So, there are these four steps, and because the priority is on containment and assessment, PDPC does give the organisation a little bit of time before they make the notification report to the PDPC. With that as background, let me assure the Member that PDPC is conducting investigations into this incident. It will ascertain whether there was significant harm to affected individuals and correspondingly, whether affected individuals were notified in a timely manner. PDPC will provide their findings in due course.

    DATA SECURITY INCIDENT INVOLVING PERSONAL DATA OF MEMBERS OF SHOPPING LOYALTY PROGRAMME - 2023-11-22 · READ THE OFFICIAL RECORD

  48. Mr Speaker, on 7 November 2023, Marina Bay Sands (MBS) announced a breach of its customers' loyalty programme membership data that took place on 19 and 20 October 2023. MBS has since notified affected individuals. Singapore takes breaches of personal data seriously. The Personal Data Protection Act (PDPA) requires all organisations to put in place reasonable security measures to protect the personal data in their possession or control, to prevent unauthorised access, disclosure or modification. The Guide on Managing and Notifying Data Breaches under the PDPA sets out clear timelines and requirements that organisations must comply with. MBS discovered the data breach on 20 October 2023, and notified the Personal Data Protection Commission (PDPC) on 24 October 2023. This meets the timeframes for notification to PDPC as set out in the earlier mentioned guide. The Member may ask why notifications are not required to be made immediately. That is really because in the usual follow-up to the discovery of a data breach, there are usually four things that we would like the organisations to undertake. First is that they must immediately seek to contain the breach. So, that is the immediate priority. The second is that they must then make best efforts to assess the degree and the extent to which the data breach has resulted in loss of data. The third is then they must assess whether this falls within the requirements for notification, and if it does, then they must proceed to make the report. And the fourth is that they must then evaluate their containment efforts, whether they are secure.

    DATA SECURITY INCIDENT INVOLVING PERSONAL DATA OF MEMBERS OF SHOPPING LOYALTY PROGRAMME - 2023-11-22 · READ THE OFFICIAL RECORD

  49. Wireless@SG complements Singapore's fixed and mobile connectivity services. The key difference between Wireless@SG and other Wi-Fi services is that Wireless@SG provides a harmonised platform for the public to seamlessly access free Wi-Fi services across all participating Wireless@SG operators. It is typically deployed at public locations with higher footfall or where people tend to congregate for longer periods, for example, hawker centres, community centres, libraries and shopping malls, to support our increasing connectivity needs. From 2018 to 2022, there were an average of 1.8 million unique logins per month, 98% of which were by residents1. When the Wireless@SG programme was launched in 2006, IMDA had provided some initial funding support to Wireless@SG operators to defray one-time capital costs and encourage widespread deployment. Today, interested venue owners can contract with any of the four appointed Wireless@SG operators – Singtel, StarHub, M1 and SIMBA. Although IMDA may provide periodic funding to enhance the security and bandwidth of Wireless@SG, the main financial costs are carried by the operators and venue owners who pay for the deployment as well as ongoing maintenance and upgrades of the Wi-Fi hotspots. This arrangement is sustainable and can continue so long as venue owners see value in providing free Wi-Fi services for their customers through the convenient log-in access provided by Wireless@SG operators.

    USAGE AND COST OF MAINTAINING WIRELESS@SG SYSTEM - 2023-11-07 · READ THE OFFICIAL RECORD

  50. IMDA will also continue to encourage all SMEs that handle a large amount of personal data to adopt the DPE, including SMEs in the exercise sector. The data protection measures will aid SMEs in upholding confidence and trust among their customers as they digitalise their processes and services.

    MICRO-ENTERPRISES IN EXERCISE AND EDUCATION SECTORS SUPPORTED BY IMDA'S DATA PROTECTION ESSENTIALS PROGRAMME - 2023-11-07 · READ THE OFFICIAL RECORD