Josephine Teo
Singapore
“The Government's risk-calibrated approach to data security in artificial intelligence (AI) systems was explained in a written reply, given on 9 January 2024, to related questions asked by Dr Tan Wu Meng and Mr Gerald Giam.”
“Access to frontier models is helpful for specific use cases, such as advanced research and cybersecurity. However, these form a small proportion of artificial intelligence (AI) demand. For most industry, Government and research uses, capable models are already available.”
“The Government tracks the development of technical standards for identifying artificial intelligence (AI)-generated content, including watermarking and digital provenance approaches, as part of broader efforts to manage AI-related risks.”
“Upon receiving a valid report of intimate image abuse, the Commissioner of Online Safety is empowered by law to direct Online Service Providers (OSPs) to disable access by Singapore users to the specified harmful online material. This direction may be extended to cover identical copies found on the platform.”
“The Government is committed to keeping children safe online. We have announced plans to extend age assurance requirements to designated social media services, including requiring platforms to keep users under 13 off their services.”
“Under the Online Safety (Relief and Accountability) Act 2025, the Commissioner of Online Safety is empowered to issue directions to platforms to remove specified harmful content, including intimate image abuse.”
The complete record
Every one of 2,900 lines we hold for Josephine Teo, in date order, each linked to its source. Free to read, in full, without an account. Page 5 of 58.
“Singapore is indeed a target for cyberattacks by advanced persistent threat (APT). From 2021 to 2024, suspected APT attacks on Singapore increased more than fourfold. Such attacks happen across the private and public sectors, and various industries. Most recently, agencies detected UNC3886 attacking our critical information infrastructure (CII). Such attacks seriously threaten our national security. They can disrupt the delivery of essential services like electricity and water. Our sensitive data may also be stolen. The Cyber Security Agency of Singapore (CSA) works closely with both domestic and international partners and stakeholders to protect our nation's cyberspace against such threats. Within Singapore, CII owners play a critical role in safeguarding the critical systems under their charge. Under the Cybersecurity Act and Cybersecurity Code of Practice, CII owners must meet certain baseline requirements to help protect them from known vulnerabilities. These requirements are generally aligned to international best practices, such as the International Electrotechnical Commission (IEC) 62443 series of standards for automation and control systems, and the MITRE ATT&CK framework for Industrial Control Systems. CII owners must also conduct regular cybersecurity testing and audits to verify the robustness of their defences. To raise awareness and prepare organisations for cyber threats, CSA conducts Exercise Cyber Star each year. This nationwide exercise tests critical sectors on their readiness to respond during a cyber crisis. International collaboration is also key to countering cyber threats, given the borderless nature of cyberspace.”
“As Members are aware, the digital world is borderless. Malicious cyber actors can launch their attacks from anywhere and often design their attack pathways to mask their true origins. That is why it is important to investigate to establish the origin of attack. To date, the Government does not have any evidence of attacks originating from Singapore against the Ninth Asian Winter Games in Harbin. Singapore does not allow the use of our digital infrastructure for malicious cyber activities and will act on evidence of such activities. To this end, the Singapore Cyber Emergency Response Team, under the Cyber Security Agency of Singapore, has reached out to its counterpart in the People's Republic of China (PRC) to render its assistance. Should the PRC authorities share any information with us on this issue, we will follow up to investigate.”
“MDDI will continue to invest in core digital infrastructure to ensure robust connectivity, and study areas such as 6G, non-terrestrial networks and frontier technologies like quantum to futureproof our networks. MDDI will lead whole-of-Government efforts to transform our digital systems and deliver more user-centric, secure and resilient digital services. This will be supported by plans to systematically improve the Public Service’s digital capabilities, including through scaling up training for public officers. MDDI is committed to building an inclusive, trusted and forward-looking Smart Nation, in close partnership with our people, enterprises and partners.”
“We will set up the Online Safety Commission to support victims of online harms in seeking timely relief from perpetrators and platforms. To promote healthier digital interactions for children and youth, we will study interventions in other countries, build on existing measures for age-appropriate access and encourage positive norms for digital well-being. Public Service Media (PSM) and Government platforms remain essential for informed discourse that upholds public trust and social cohesion. MDDI will continue to support PSM entities by ensuring their financial sustainability, strengthening their verification capabilities, improving the prominence and discoverability of their products, and enhancing their ability to share Singapore’s perspectives internationally. MDDI will strengthen government communications across online and offline channels, ensuring their content remains timely, trusted and relevant to citizens. Through Reaching Everyone for Active Citizenry @ Home (REACH), we will deepen engagement and foster trust by bringing together people with diverse viewpoints. MDDI will raise our baseline cybersecurity standards nationally, including by promoting stronger cyber hygiene practices, particularly in entities that handle sensitive data or critical systems. We have strengthened incident reporting requirements for Critical Information Infrastructure owners to detect malicious cyber activities early, enabling timely responses. To meet growing demand for cybersecurity expertise, we will develop talent, innovation and the local research and development ecosystem. Resilient and future-ready infrastructure is essential for Singapore to thrive in a complex digital environment.”
“The Ministry of Digital Development and Information (MDDI) will refine our Smart Nation 2.0 strategies to navigate rising geopolitical and economic uncertainties and build a thriving digital future for all Singaporeans. Digital technologies such as artificial intelligence (AI) are rapidly reshaping jobs and industries. To seize growth opportunities, MDDI will build capabilities, boost innovation and accelerate AI adoption in our enterprises and workforce. As AI tools become more accessible, MDDI will help enterprises, including small and medium-sized enterprises, deploy them to improve efficiency. We will support enterprises ready to go further in embedding AI into their core business processes to generate greater value. We will also anchor more AI Centres of Excellence to deepen their capabilities here. We will engage the Labour Movement, professional bodies, trade associations and chambers to develop suitable programmes to equip our workers with AI-related skills, and grow a core of AI-fluent workers who can be pacesetters in their fields. We will also work across the Government, with industry and the community to achieve scale in outreach. MDDI will continue to support individuals and households in accessing digital tools and services, and work with partners to promote inclusivity of digital services by design. We will also transform our libraries and archives to encourage reading, learning and discovery through offering physical and digital resources for all. MDDI will help Singaporeans stay safe online amid rising scams, cyberbullying and increasingly sophisticated cyberattacks. The Government will continue to tackle scams on multiple fronts, including by deploying technical solutions for detection and prevention.”
“The Government does not condone individuals who post about their criminal activities on social media and seek to glamourise them. Such acts demonstrate a lack of accountability for their actions and disregard for victims of crime. Under the Code of Practice for Online Safety – Social Media Services (SMSs), designated SMSs with significant reach or impact, such as Facebook, HardwareZone, Instagram, TikTok, X and YouTube, are required to put in place system-level measures to minimise Singapore users' access to harmful content, including content facilitating vice and organised crime. The designated SMSs' own community guidelines prohibit illegal and criminal content on their platforms, and we expect them to enforce these guidelines. The Government will continue to work with designated SMSs to ensure that their community guidelines remain fit-for-purpose and effectively address emerging challenges. The Police are aware of the "post-and-boast" culture on social media and would like to remind members of the public to abide by our laws and not to participate in acts or viral online trends that constitute a criminal offence. Those who break the law will be dealt with firmly.”
“The Government is committed to ensuring that digital Government services are easy to navigate and use for all citizens, including seniors and the less digitally savvy. When designing these services, we consider citizens' needs and habits. Citizens may access these services through searching online or via agency-provided links. Some may prefer to use their computers, while some prefer to use apps on their smartphones as they are frequently on the go. Providing different channels facilitates discoverability and ease of access. Where it makes sense, we will bring together different digital services to make it more convenient for citizens. Examples include LifeSG and HealthHub. However, having too many services on a single app or website can lead to clutter and make it harder to find the right service. We recognise that, despite our best efforts, there will be citizens who need in-person support and this is why we provide such assistance at Government agencies' physical touchpoints and ServiceSG Centres.”
“Mr Chairman, when we set out to provide funding to any useful activity, we have to consider in that moment what are useful and effective ways to track performance and we do so very diligently. When funding was discussed in support of SPH Media Trust at the time, reach was one of the important KPIs. Over time, we also considered that engagement is important, is actually one of them, but in addition to that, we now think that trust as well as public satisfaction are just as important, so we will look to including them as part of the KPIs that we track for SPH Media Trust. To the Member's question that he posed in his cut earlier, I should address it briefly too. He had asked about what goes into the Budget book. And I acknowledge his suggestions, which we will consider for the future, but just to say that, like all Ministries, it is not possible to list all of the KPIs. So, I seek Member's understanding for that. The important thing is that where SMT is concerned, they know very well that the KPIs are a very central feature of the conversations that we have, and they can feel it. So, that is something I want to say. The comparison between ST and CNA, well, the fact of the matter is that opinions will differ. If you ask 10 people their views, probably you will get 15 at least. So, I think we take that as a given. We track how the public views the trustworthiness of these titles and we will continue to do so. And as I shared in my speech, as well as on other occasions, they compare very favourably.”
“Mr Chairman, in the nature of such botnet disruption operations, speed is of the essence and you want to be as comprehensive as possible. So, with those important considerations in mind, it is not possible to attempt even to inform all of the owners of the devices. Instead, what we regularly advise people to do is that as long as you have a device that is connected to the Internet, there are some hygiene practices that should be practised: changing the default password, restarting or rebooting regularly and enabling automatic firmware updates. These are the general guidance that apply to everyone. And in cybersecurity there is also another term that we say and that is "assume breach". It is something that you just have to keep in mind. You have to be vigilant and assume that the device may well have been compromised, and you need to do something to clean it up regularly.”
“If I add GovTech's working with the Singapore Police Force (SPF) to disrupt 45,000 scam related websites and also IMDA working with SPF to disrupt more than 57,000 mobile lines assessed to be likely used for scams, these are very considerable efforts. But we are not stopping at the above measures. We are working with telcos and online platforms to address criminal misuse of their services.”
“Second, by developing technology to support MHA's detection and disruption of scam activities. So, those are the two main areas of support. Maybe to give the Member some sense of the usefulness of these efforts, in 2023, IMDA implemented the full SMS sender ID registry regime and non-registered SMSes are labelled as "likely scams". I am sure we have all gotten them. I certainly have gotten them. And this has been effective. Cases of scam SMSes fell by 70% in the first three months of the regime's introduction and thereafter, it has remained low. IMDA also partnered with telcos to strengthen in network detection and blocking of scam calls and SMSes. In 2024, 117 million potential scam calls from overseas were blocked. They were about 25% of all international calls. For SMSes, 50 million potential scam SMSes were successfully blocked. IMDA also worked with telcos to offer new features to block all incoming international calls and SMSes, meaning that from the subscriber standpoint, I do not want to be at risk at all, I do not want to just depend on your auto blocking, I do not wish to get any of these calls. And to date, more than 280,000 subscribers have activated the feature to block overseas calls and close to 220,000 subscribers have activated the feature to block overseas SMSes. I mentioned briefly in my earlier speech how we are working with Google for the enhanced fraud protection feature. This feature is turned on in Singapore by default and it has successfully blocked 1.6 million attempts to install potentially malicious apps across nearly 400,000 devices.”
“Mr Chairman, I would, first, like to thank Ms Tin for her acknowledgement of our efforts and in particular, her recognition of the importance of preserving our vernacular media. If we think about the need to continue projecting Singapore's voice on the international stage, in fact, the role of the vernacular media becomes even more prominent. So, I wish to recognise her acknowledgement and affirm it. 2.30 pm The big chunk of the Public Service Media funding support is directed towards helping our Public Service Media entities become more relevant in the digital era, so the technology upgrades are essential to this. But we have always maintained that at the same time we want to support quality journalism and that cuts across all language medium. And in particular, recognising that the domestic market for our vernacular media is actually very small, they need extra support. So, the understanding with the public service media entities is that they must set aside adequate resources, and the KPIs do track the performance of the vernacular media. I think that how they do on the KPIs is not just a matter of looking at their performance, but it is also a matter of helping us understand how the landscape is changing and what more is required to support the continued viability of vernacular media. Let me also take Ms Tin's question on how MDDI is working to support the Ministry of Home Affairs (MHA), the lead agency in addressing scams. We do so broadly in two ways, first by disrupting and making it harder for scammers to reach Singaporeans, whether by calls, SMSes, or apps infected with malware, because that is really how the victims fall. This is what we, within the working group, call the "attack factor".”
“Of course, threats to social cohesion are not the only concern in the digital age. Therefore, some have asked me, given the dangers in the digital world, should Singapore slow down or pause its digitalisation efforts? Indeed, while Singapore is very safe in the physical world, the digital world has no clear borders and is full of risks. However, Singapore is a small country with limited resources. In an era of intense global competition, digitalisation is key to overcoming our limitations and enabling us to continue thriving. In the digital journey, not progressing is akin to falling behind. The Government must therefore adopt the wise strategy of helping citizens and businesses enhance their digital skills and strengthening their cybersecurity awareness. Only then can Singapore grasp new opportunities in the digital age and our workers can move forward and secure better employment opportunities.”
“They now require Connected TVs to be pre-loaded with public service media apps like BBC iPlayer, or ABC iview, and to display these apps prominently on their user interfaces. Given the important role of our PSM entities to inform, educate and connect Singaporeans, we must be very concerned about their visibility being obscured by the decisions of third-party platforms. Our PSM content must remain visible and easily accessible to our audiences. Therefore, MDDI is studying the regulatory moves in other countries to safeguard the prominence and discoverability of PSM. We will consult industry stakeholders, including device manufacturers, before deciding the next steps. Sir, please allow me to conclude in Mandarin. (In Mandarin): [Please refer to Vernacular Speech.] Mr Chairman, Singapore is a highly open and digitalised country. Singaporeans can access information from various platforms – whether it is Xiaohongshu (小红书), Facebook, Netflix, or iQiYi (爱奇艺), these are platforms that many Singaporeans are familiar with. However, with more information received, is our ability to discern information sharpened or weakened? Is the society becoming more united or increasingly divided? These are questions worth pondering. In fact, in an era of intensifying geopolitical competition, being limited in our ability to share our narratives is not beneficial for maintaining our national stance and sense of identity. In this aspect, Public Service Media, such as Mediacorp and Lianhe Zaobao, play crucial roles. Only they will report news and analyse international events and their impact on us from Singapore's perspective. Therefore, the Government is exploring ways to make Public Service Media content more accessible to Singaporeans in the new media environment.”
“I would like to address slightly, to some extent, the comment that was made by Mr Pritam Singh when he compared CNA and The Straits Times, I believe. I would suggest respectfully to Members that comparisons must avoid oversimplification. Because we have to remember that CNA is mainly our national broadcaster as well as digital news channel, whereas most of the titles in SPH Media Trust (SMT), most of the assets of SMT, are print still – even though they have digital versions – and they are meant to be national papers of record. So, they are different and complementary. And it is perhaps, again, my humble suggestion to Members to look at the performance of public service media holistically. Because, in truth, we need all of them to reach as many Singaporeans as we can. So, that is something to keep in mind. And as mentioned, both CNA and The Straits Times remained the top-frequented new channels. And Members who expressed concern about the sustainability of Public Services Media will agree with me that the KPIs, such as reach, are important but they are not the only ways for us to assess the performance and the effectiveness of PSM entities. Equally, we must look at the trust levels that they are able to harness from the population and we must also look at satisfaction levels. And so, those would be the additional KPIs that we are looking to introduce. Meanwhile, let me also point to the threat to broadcast television, with consumers shifting to platforms like YouTube or Netflix. Even when PSM entities go onto these platforms, the experiences abroad suggest that placements and algorithms in the digital environment disadvantaged them. Countries like the UK and Australia have, therefore, made new rules.”
“Many Singaporeans, including Ms Hany Soh and Mr Sharael Taha, appreciate the efforts of Mediacorp and SPH Media to adapt to changing audience preferences. Against a climate of stiff competition, news fatigue and opaque algorithms on social media platforms, both companies are committed to increase audience reach. However, falling revenues have forced their newsrooms to rationalise. SPH Media ceased publication of its Chinese entertainment magazine, U-Weekly. Last October, Mediacorp merged TODAY Online with CNA's Digital newsroom. Mr Pritam Singh expressed concerns about SPH Media's performance. Like news outlets worldwide, SPH Media's print subscriptions have declined as readers shift to consuming news online. However, less than 20% of consumers in advanced countries, including Singapore, now pay for digital news subscriptions. Essentially, they can get it for free and they will continue to enjoy such services for free. Without revealing commercially sensitive information, I can share that SPH Media's digital subscriptions have held steady and it is now 35% higher than print subscriptions. It was only 20% higher two years ago. So, you see the shift. SPH Media will have to continue its pivot to digital news and the Government must support this effort so that our PSM entities can meet audiences where they are. Despite not meeting all their KPIs last year, SPH Media did not ask to lower their targets. They are determined to maintain their reach and relevance with Singaporeans. In 2024, they maintained their strong overall reach at 70% of Singapore's resident population although youths and vernacular reach dipped. In line with the funding agreement, MDDI will pro-rate and award the Performance-Linked Incentives accordingly.”
“CSA is, therefore, assessing if more measures are needed, particularly for vendors that may be given access to sensitive data or systems within the Government. Such vendors include cybersecurity penetration testing firms and cybersecurity auditors. Possible measures include requiring these vendors and their subcontractors to obtain their Cyber Essentials or Cyber Trust Marks before they can be licensed or bid for contracts offered by the Government. Government may also take the lead to incorporate cybersecurity considerations in our procurement decisions. As the impact of these measures may be non-trivial, CSA plans to engage the industry before deciding. Sir, let me turn now to my final theme. We share the same concern as Members that AI-enabled tools, like deepfakes, may be abused to cause harm. This is why we passed the Elections (Integrity of Online Advertising) (Amendment) Act to protect Singaporeans from the threat of AI-generated misinformation during elections. We are also developing a new Code of Practice to require social media companies to prevent and counter abuse of fake content. These measures, while important, are not enough. Against the tide of false information online, we must have trusted sources to turn to. Thankfully, our Public Service Media (PSM) entities remain many Singaporeans' first port of call for credible news. The Straits Times and CNA are amongst our most frequented online news platforms, with more than 40% of Singaporeans reading them weekly. More importantly, public trust in our mainstream media remains high, with CNA and The Straits Times being the most trusted by Singaporeans at 74% and 73% respectively. Meanwhile, public trust in mainstream news has fallen in other countries, hovering at 60% or below.”
“Botnets are just one of the many cyber threats we need to defend against. This is why we emphasise the need to safeguard our cybersecurity at multiple levels. For individuals, we will continue working with industry partners to offer better protection. One example is the Enhanced Fraud Protection feature under Google Play Protect. A common scam tactic is to entice victims to download apps from unofficial sources that can inject malware into our devices. With this feature, such download attempts on Android devices will be blocked. For organisations, the Government is improving the SG Cyber Safe Programme. Senior Minister of State Tan Kiat How will share more details later. We also agree with Mr Sharael Taha on the need to raise our national cybersecurity posture. Last year, CSA amended the Cybersecurity Act to require that CII owners report on a larger set of cyber incidents. We also expanded CSA's oversight beyond CIIs to other important systems and entities, such as cloud services and data centres. The amendments are expected to come into force later this year. More information can be found in the handout. Beyond cybersecurity, we aim to introduce a new Digital Infrastructure Act to enhance security and resilience of digital infrastructure. Senior Minister of State Janil Puthucheary will share more later. What I worry about are the organisations that are not covered by such legislation, that are not paying enough attention to cybersecurity. Thankfully, over 500 organisations believe in the importance of cybersecurity and have acted on it by getting their Cyber Essentials and Cyber Trust Marks. But we should raise baseline cybersecurity standards nationally and protect more organisations, especially those of higher risk.”
“Everyone has a part to play. Minister of State Rahayu will share what citizens can do to protect themselves online. Sir, in his Budget Statement, the Prime Minister talked about the global context being more uncertain and having more downside risks. This is reflected in the digital domain, where cyber threats have become more severe. Criminal groups are increasingly going online to look for illicit gains. Advanced Persistent Threat actors, linked to certain states, are actively seeking to advance their national agenda. We have seen both kinds of activities in our cyberspace. Last year, a global botnet, which included infected servers and devices around the world, was discovered. More details can be found in the handout. Until the Cyber Security Agency of Singapore (CSA) participated in an international operation to disrupt this botnet, about 2,700 devices in Singapore had been infected, unbeknownst to their owners. The malicious actors exploited poor cyber hygiene practices to infect devices, including baby monitors and Internet routers. Members may ask, so what if the botnet had remained? Well, it would have meant the devices were vulnerable and personal data belonging to device owners could have been stolen. More worryingly, the devices could be used as a standby army, much like our full-time National Servicemen, ready to be deployed into active duty. Except in this case, it would be foreign state-linked actors using the bots for malicious purposes, which can include targets directed within Singapore. 1.30 pm As Ms Tin Pei Ling highlighted, international partnerships are critical in combatting such complex threats. CSA could act only because it has recognised capabilities and was trusted by its partners to be involved in this international operation.”
“During this ordeal, she felt scared and embarrassed, even blaming herself for posting photos online in the first place. A full decade later, at 29 years old today, Jane continues to question who created that photo of her and if it is still found online. Victims like Jane need more support to find closure. During the Smart Nation 2.0 launch, the Prime Minister announced that the Government will introduce new legislation to support victims seeking relief from specified online harms. Ms Tin will be glad to know that the proposed law, the Online Safety (Relief and Accountability) Bill, will be introduced later this year. It will establish a new agency called the Online Safety Commission (OSC) so that victims can get timely help if they encounter online harms. The OSC will be set up by the first half of 2026. Victims will be able to request OSC to issue a direction to the platform to take down the offensive content. The platform must also remove existing identical copies on the platform – something they refused to do for Jane. The new law will also help victims hold their perpetrators accountable. If they want to sue the perpetrators, they can request OSC to direct the platform to provide information about the perpetrators. In drafting the new law, the Minister of Law and MDDI have engaged a wide range of stakeholders from industry, academia, community groups and international partners. We also invited the public to provide their feedback. The public consultation findings have been published on the website of Reaching Everyone for Active Citizenry @ Home (REACH). We are heartened by the strong support and useful feedback which will help refine our proposals. Given the complexity and vastness of the digital space, rules and regulations alone are insufficient.”
“This is why we passed the Online Safety (Miscellaneous Amendments) Act in 2022 to set out their basic obligations. Like Mr Eric Chua, we believe in adopting a holistic and balanced approach to online safety, particularly for young users. Where it is useful to do so, we will strengthen regulatory levers. For example, in January, we issued a new Code of Practice for Online Safety for App Distribution Services. For the first time, we are introducing measures to ensure that young users under 18 do not access age-inappropriate apps. Last month, we also published our first ever Online Safety Assessment Report. To questions raised by Mr Xie Yao Quan, the report showed that the designated social media services made good efforts to put in place baseline user safety measures. However, as he has also pointed out, there are areas for improvement. They should respond more quickly to user reports. Their measures to protect children from harmful content are also far from satisfactory. This is why MDDI is studying whether the age assurance obligations for app stores should also apply to social media services. We also want to do more to support the victims of online harms. IMDA's report found that, more often than not, platforms fail to take action to remove genuinely harmful content reported to them by victims. One such victim was Jane, and that is not her real name. At 18, she was horrified to find an image of her face superimposed onto another person's nude body, circulating on an image sharing platform. Strangers reposted the image and left comments, some of which sexualised or insulted her. When she reported this to the platform, they took down only the original post but not the reposts.”
“For example, Home Team Science and Technology Agency (HTX) is on track to hire and train a 300-person AI workforce by end-2025. To meet demand, we need to grow a strong pipeline of AI practitioners. To this end, we will expand our efforts under IMDA's TechSkills Accelerator (TeSA). We will provide more company-led training opportunities. We will also explore ways to expand the AI Apprenticeship Programme together with AI Singapore. Let me share an example of how these programmes benefit Singaporeans. Seow Yuxin studied business and started her career in Regional Operations for an e-commerce platform. She did not work on AI systems directly, but the role sparked her interest in the field. After seeing her husband and brother-in-law go through the AI Apprenticeship Programme, she took a leap of faith and enrolled in the programme. I spoke to Yuxin recently and was pleased to learn that she has pivoted to a new role in a new company delivering AI and data-driven solutions to other organisations. We are determined to keep AI opportunities open and inclusive. Yuxin shows that one can access AI opportunities even without a STEM background. We will aim to support more Singaporeans like her to fulfil their AI aspirations. As a Government, we will always put our people at the heart of all we do and that includes our AI plans. I hope these efforts reassure Members of our support for Singaporeans to make the most of AI. Besides succeeding with AI, we want Singaporeans to feel safe when they go online. But this is not something the Government alone can achieve. Social media platforms must do their part, no different from how all service providers bear some responsibilities towards their users.”
“This will help them to enhance their productivity at work, even if they have no background in technology. The second thing we must recognise is that AI will create new jobs even as it replaces some existing ones. As Members have highlighted, our next most important task is to deepen our AI capabilities and anchor more new jobs in Singapore. This means growing our pool of AI practitioners, which includes data scientists, machine learning engineers and more. Take, for example, the need for AI safety. As AI adoption grows, there will be greater demand for AI testing and assurance service providers, just as the widespread information technology (IT) adoption led to greater demand for IT auditors. Estimates of the market for such testing, inspection and certification services vary, but they would be in the billions in time to come. Singapore believes in the importance of good AI governance. We were one of the first in the world to introduce a testing framework and software toolkit, AI Verify. Just last month, I launched the Global AI Assurance Pilot of the AI Verify Foundation to promote best practices in the testing of models using Gen AI. These efforts can help to grow the AI testing industry here and create new jobs. In response to Mr Sharael Taha and Ms Tin Pei Ling, let me provide an update on efforts to expand our pool of AI practitioners. I previously shared our ambition to expand the pool from under 5,000 to 15,000 in about five years. In the last year or so, we estimate that the pool has grown by nearly 25%. The AI Centres of Excellence that MDDI and MTI worked closely together to set up will catalyse more demand for AI practitioners, by the hundreds if not thousands. The public sector itself has growing needs.”
“Thank you. Members may also access these materials through the MP@SGPARL app. Sir, in this year's Budget and COS debates, Members spoke often about AI. Ms Jessica Tan, Miss Rachel Ong and Mr Sharael Taha also raised concerns about its impact on workers. I understand these concerns. They are real and will be with us for some time, because we are only at the very early stages of AI adoption globally. People all over the world would like to know who will be impacted and how. While there is no perfect clarity, there are ways in which we can help. The first is to recognise that many jobs will still be around. The risk is not that these jobs will be lost to AI, but that they are lost to another country or city that is more competitive than us. Our most important task, therefore, is to help as many people and businesses as we can become more productive, with the use of AI. We want to become a nation of competent and confident AI users. In doing so, we can maintain Singapore's economic competitiveness and retain more good jobs here. Sir, I have compiled a list of comparisons by various organisations in the handout . Members will see that Singapore is well-regarded and well-placed to benefit from widespread AI adoption. We should capitalise on this opportunity. We have established strong partnerships with tech companies, like Amazon Web Services, Databricks, Google and Oracle. For example, Microsoft has partnered with NTUC Learning Hub to train up to 100,000 workers with AI skills. At the same time, IMDA is working with SkillsFuture Singapore to expand the curriculum in SkillsFuture for Digital Workplace 2.0 to include AI and Gen AI content. Under this expansion, workers in all sectors, be it manufacturing or retail, can learn how to use tools, such as ChatGPT and CoPilot.”
“Mr Chairman, I thank Members for their cuts. Last year, the Prime Minister launched Smart Nation 2.0 – a refresh of our vision for Singapore to use technology to uplift the lives of our people. Today, I will elaborate on our efforts in four areas: (a) how we support our workforce to succeed in the age of AI; (b) how we keep Singaporeans safe by fighting harmful online activities; (c) how we protect our cyberspace against malicious attacks; and (d) how we preserve trust in our information space (infospace) by strengthening public service media. Mr Chairman, may I ask the Clerks to distribute the package of handouts?”
“Our Mobile Network Operators (MNOs) that provide mobile broadband services have achieved over 99% nationwide outdoor mobile coverage for their 4G networks; and over 95% nationwide outdoor mobile coverage for their 5G networks. MNOs are also required to meet the Quality of Service standard for 4G coverage of over 85% per building, as well as over 99% coverage for nationwide outdoor areas and all roads or mass rapid transit tunnels. The Infocomm Media Development Authority regularly monitors the performance of these services and will require the service providers to improve their performance to meet the requirements if there are gaps.”
“Nonetheless, we will continue to monitor DSMSs' efforts to enhance online safety.”
“The Government seeks to protect vulnerable users, especially children, from harmful and age-inappropriate content on social media services. The Infocomm Media Development Authority's (IMDA's) Code of Practice for Online Safety requires social media services with significant reach or impact to put in place online safety measures, including differentiated measures for young users. Six Designated Social Media Services (DSMSs) were assessed recently for the comprehensiveness and effectiveness of these measures. X and HardwareZone were found to have shortcomings in user safety measures for children. For example, the services' own community guidelines for children were frequently breached, resulting in children being more exposed to age-inappropriate content than was desirable. Even for DSMSs that did better in this area, such as Facebook and YouTube, children could still access some age-inappropriate content. Other than user safety features, DSMSs should improve on the effectiveness and timeliness of their response to user reports. More often than not, content that violated the services' community guidelines were not removed even after users reported their presence. Most DSMSs also took an average of five days or more to act on these user reports. These findings show that DSMSs need to step up efforts to protect users on their platforms. IMDA has engaged DSMSs to do so and will review their responses when their next annual online safety reports are due in June 2025. In addition, IMDA is studying how social media services should use age assurance technology to better protect children and youth from age-inappropriate content. As to the impact of prolonged exposure, the Ministry of Digital Development and Information does not have authoritative findings to share.”
“Now, let me assure Members of the training requirements that the foreign hires must meet. For example, they have to go through bridging and onboarding courses, and they will, even before they are deployed, be put on on-the-job ambulance attachments with local senior paramedics to ensure that they are well-assimilated and equipped to operate in line with SCDF's professional standards and protocols. The foreign hires will all be required to pass English language requirements to ensure that they can communicate clearly and effectively with patients and their families. All paramedics will also need to pass the paramedic specialist certification test and the ambulance proficiency test while emergency medical technicians will need to pass the SCDF Emergency Medical Technician (EMT) certification test before they are deployed. Upon deployment, the foreign hires will undergo certification tests annually, and continuous education as well as training will also be provided to them so that they can continue to fulfil the same requirements as the local hires. So, these are the suite of measures that we have put in place.”
“We will continue to do so and find every possible opportunity to introduce the kinds of technologies that are being deployed in support of law enforcement. Perhaps, turning to the Member's two questions that are related to how SCDF seeks to strengthen its local core, as well as to ensure that its foreign hires are able to carry out its mission, first, let me deal with the strategies that we have put in place to ensure that SCDF careers remain attractive. The first is that the progression pathways have to be well laid out and they have to be attractive. So, one example is the new programme that we are working on with the Lee Kong Chian School of Medicine to develop graduate certificates in advanced pre-hospital care. Of course, we have also regularly reviewed our salaries and these efforts are to ensure that SCDF careers remain attractive to locals. To the Member's second question, let me, first, say that we will always try and open up recruitment pathways and be willing to consider people of more varied backgrounds, as well as train them. One example is the diploma in paramedicine programme, which we are working with the PSB Academy on. This will double the annual intake at the diploma level. Our preference, of course, is always to recruit and train locals but, as Mr Zhulkarnain has alluded to, we must also balance this against the growing needs, because if we are not able to bring relief to the pressures that are faced by our officers, then, clearly, it could also compromise our ability to retain them. So, being able to supplement this with some foreign hires and to make sure that we are able to meet all of Singapore's needs, that is an avenue of support that we have gone towards as well.”
“Mr Chairman, I thank Mr Zhulkarnain for his very important questions. Perhaps, I will take the third one first, in which he correctly pointed out that even as we are using technology more to support our operations, we need to help the public understand how these technologies are deployed in support of our efforts. I think we have been fortunate in the sense that when we rolled out the network of closed-circuit television (CCTVs), or what is referred to as PolCams in general, we saw a very positive response in our neighbourhoods. Today, if we were to ask people whether they see the usefulness of this CCTV network in detecting and solving crimes, the response level will be very positive. In fact, in our latest public perception survey, nine in 10 Singaporeans said that they see the value of these PolCams. I would say that if we take the question further and ask people what contributes to them feeling safe when they go out at night, for example, the top reason cited is often, again, the CCTVs. So, we have a situation where Singaporeans became sensitised to the usefulness of technology, and they saw it being deployed in a very tangible way and helping them. So, building on that sort of foundation, what Home Team agencies have done consistently is that whenever they have opportunities, they have events where there are public touchpoints, they will introduce the technologies that are being used. I have attended the workplan presentations of SCDF, as well as ICA, for example, where these technologies are exhibited. Media is invited to cover the events and, through the media, we get the word out on what is being used to carry out the Home Team's missions.”
“Since the POFMA Office's online form for reporting potential falsehoods was introduced in 2021, the Online Falsehoods and Manipulation Act (POFMA) Office has received a total of 1,276 pieces of public feedback about potential online falsehoods, as of 31 January 2025. In the same period, there were nine POFMA Directions issued regarding falsehoods that had been reported by a total of 37 pieces of public feedback to the POFMA Office.”
“Buy-now-pay-later plans are offered by telecommunication companies (telcos) to consumers wishing to pay for mobile devices in instalments. Such plans are common for many other sectors and retail merchants. To safeguard consumer interest, the Infocomm Media Development Authority (IMDA) requires telcos to ensure that consumers acknowledge the terms and conditions, instalment charges, billing arrangements and penalties prior to consumers entering into purchase/service agreements. Over the last two years, IMDA received 14 feedback from members of the public on such instalment schemes. To date, telcos have assisted customers in resolving their issues for all cases.”
“The Ministry of Digital Development and Information has provided $260.6 million to SPH Media Trust in FY2024, in line with the current funding agreement. In addition, we have budgeted for $28.9 million of Performance Linked Incentives, which can be disbursed to SPH Media Trust, subject to them meeting the key performance indicators under the current funding agreement.”
“The Ministry of Digital Development and Information had addressed related queries at the 7 January 2025 Parliament Sitting. [Please refer to "Probe in to Manual Manipulation of Delivery Status Codes for SingPost Parcels", Official Report, 7 January 2025, Vol 95, Issue 148, Oral Answers to Questions section.] Notwithstanding the changes in leadership, SingPost is expected to comply with its Quality of Service standards and Universal Service Obligations as a Public Postal Licensee. They have done so thus far. Nonetheless, the Infocomm Media Development Authority is closely monitoring developments at SingPost and will work with its management to ensure postal services are not affected.”
“This question has been addressed in the oral reply to Parliamentary Question Nos 13 to 17 at the 4 February Sitting. [Please refer to "Assistance for Victims of Incident Involving Address Changes Via ICA System, Punishment for Perpetrators and Remedial Actions to Correct System or Process", Official Report, 4 February 2025, Vol 95, Issue 150, Oral Answers to Questions section.]”
“The Productivity Solutions Grant (PSG) supports businesses' adoption of pre-approved solutions under the Infocomm Media Development Authority's (IMDA's) SMEs Go Digital programme, which aims to help businesses improve productivity and enhance their business processes. The PSG supports a diverse range of solutions and vendors, which businesses can choose from. This variety promotes price and quality competitiveness among vendors. Businesses are encouraged to choose solutions that best suits their needs and are value for money. If there are concerns with the quality or pricing of the solutions, businesses can submit their feedback to IMDA on the GoBusiness platform or on the Business Grants Portal.”
“The Infocomm Media Development Authority's (IMDA's) investigations into the disruptions which occurred in late-2024 are ongoing. Once investigations are complete, IMDA will publish on its website the findings of key incidents, including lessons that can be learnt to prevent recurrence. IMDA will also take firm enforcement action should the investigations reveal lapses on the part of the service providers. This can include the imposition of financial penalties and directions to remedy gaps. For more information on IMDA's preliminary findings and treatment of the late-2024 disruptions, Members may refer to the Ministry of Digital Development and Information's responses to similar Parliamentary Questions at the 11 and 12 November 2024 Parliament Sittings. [Please refer to "Root Causes for Singtel's Recent Outage, Impact of Disruption to Essential Services and Measures to Ensure Telecom Operational Continuity and Resilience", Official Report, 11 November 2024, Vol 95, Issue 145, Oral Answers to Questions section; and "Penalties for Service Outages that Affected Mobile Network, Broadband Internet and Subscription Television Services in 2024", Official Report, 12 November 2024, Vol 95, Issue 146, Written Answers to Questions for Oral Answer not Answered by End of Question Time section.]”
“Singapore's approach to online content regulations is outcome-based. We focus on ways to minimise exposure of harmful online content to Singapore users, regardless of how the content is generated or how the exposure comes about. We continue to monitor regulations elsewhere, including Europe and the United States, that seek to mandate transparency over the algorithms used by social media platforms. We note that these regulatory approaches are still in the early stages of development and there is no consensus on their effectiveness in ensuring online safety. Under the Code of Practice for Online Safety for social media services, designated social media services have to ensure that their users have access to tools on their platforms to manage their own safety, such as tools to restrict visibility of harmful content and unwanted interactions. The Code also requires platforms to ensure that children must not be targeted to receive content that is detrimental to their physical and mental well-being, and put in place more restrictive account settings. The Code does not prescribe how the designated social media services are to implement these measures. To enhance online safety, the Code also mandates that designated social media services submit annual accountability reports to the Infocomm Media Development Authority (IMDA). These reports must contain information about measures that they have put in place to combat harmful content and improve users' safety. IMDA is currently reviewing the first annual online safety reports and will subsequently publish the findings. We will continue to study the evolving online landscape and review if additional regulations for social media services are needed as part of our ongoing efforts to enhance online safety in Singapore.”
“My response will also cover the matters raised in the oral question by Dr Wan Rizal1, which is scheduled for a subsequent Sitting. If the question has been addressed, it may not be necessary for the Member to proceed with the question for future Sittings. Members have raised a range of questions. The Ministry of Home Affairs has already addressed the queries specific to the electronic Change of Address (eCOA) service and how the Government Technology Agency (GovTech) is supporting on that front. My reply will address more general questions on other Government digital services and Singpass, beyond what is relevant to the eCOA service. Since the unauthorised change of addresses via the Immigration and Checkpoints Authority's online system were publicly reported, Government agencies have been conducting checks on the possible impact to their e-services. So far, there have been no transactional services identified that can be completed in the same manner as unauthorised eCOA transactions using only the National Registration Identity Card (NRIC) number and date of issue of NRIC. More broadly, in managing their information technology systems, Government agencies are required to conduct regular risk assessments, including risks arising from dependencies on systems managed by other agencies. The systems must also be regularly assessed for vulnerabilities and subject to penetration testing. Once identified, vulnerabilities must be promptly remediated. As for Singpass, GovTech is constantly improving and testing the security of its design. This includes penetration testing, enhancing fraud analytics and requiring additional face verification if Singpass is used for higher-risk transactions.”
“I thank Mr Saktiandi for his question, which I have answered in the reply to the Parliamentary Questions filed by Ms Foo Mee Har and Mr Pritam Singh at the Sitting of 7 January 2025. [Please refer to "Examining Australia's Move on Social Media Ban for Those Aged 16 and Below", Official Report, 7 January 2025, Vol 95, Issue 148, Oral Answers to Questions section.] I invite him to seek clarification, if any, on my reply.”
“This Question was addressed through the Statement by the Minister for Digital Development and Information during the Parliament Sitting on 8 January. [Please refer to "Responsible Use of NRIC Numbers", Official Report, 8 January 2025, Vol 95, Issue 149, Ministerial Statements section.]”
“The issues concerning the whistle-blowing report and subsequent dismissals by SingPost was addressed in the Ministry of Digital Development and Information's response to similar Parliamentary Questions filed by Mr Saktiandi Supaat and Mr Louis Chua, which was published in the Hansard for the 7 January 2025 Parliament Sitting. [Please refer to "Probe in to Manual Manipulation of Delivery Status Codes for SingPost Parcels", Official Report, 7 January 2025, Vol 95, Issue 148, Oral Answers to Questions section.] The Member was present in Chamber at the time of the response but did not ask a follow-up question.”
“The issue of recent telecommunication service disruptions and steps being taken to address them was addressed in the Ministry of Digital Development and Information's response to a similar Parliamentary Question filed by Mr Saktiandi Supaat, which was published in the Hansard for the 12 November 2024 Parliament Sitting. [Please refer to "Penalties for Service Outages that Affected Mobile Network, Broadband Internet and Subscription Television Services in 2024", Official Report, 12 November 2024, Vol 95, Issue 146, Written Answers to Questions for Oral Answer not Answered by End of Question Time section.]”
“Mr Speaker, two quick responses to Assoc Prof Jamus Lim. First, I believe that his opening sentence in his preamble is erroneous. We did not say that the NRIC number is not suitable for identification. It is an identifier. It is a unique identifier. So, it has to be used for identification. It is authentication that it should not be used for. You can use it to identify a person. You cannot use the NRIC number to prove that the person is who he claims to be. I do appreciate that there is a lot to take on board, so, I would refer Assoc Prof Jamus Lim to the specific statements on this topic of drawing a distinction between the NRIC number as an identifier and as an authenticator, so that we could have a proper understanding of what it is. The second response to his comments is that, I am not sure that it is useful to characterise what we are doing as desensitising. As I explained, we are not making a change to allow the full NRIC number to be widely disclosed. The only change that we are making is to stop the incorrect uses of NRIC numbers as authenticators and as passwords. Nowhere in this description is there a need to refer to desensitisation. I am not sure that that characterisation applies to what we are seeking to do and I would encourage Members not to use this characterisation. To reiterate, we are not making a change to allow full NRIC numbers to become widely disclosed. The only change we are making is to stop incorrect uses of NRIC numbers as authenticators and as passwords.”
“It comes back to the fundamental point, even if you cannot work out the full identifier from a partial identifier, as long as that identifier is used for the purposes of authentication or as password, you still have a problem. I hope that explains our position and our thinking.”
“As to the question of whether we will legally prohibit the use of NRIC numbers as authenticators, as I said, the practices for the private sector will have to be decided upon consultation. So, I do not want to say now, what the landing point is going to be. But even without a legal prohibition, I think if organisations care about their data security and they care about protecting the data that they have in their possession or the services being accessed by people who are not intended to enjoy the service, then they should really re-think the authentication methods. Their customers ought to be sensitised to this too – that when the NRIC number is being used by an organisation as an authenticator, it is actually not safe at all. It goes to the Member's point that there are algorithms online that will allow you to work backwards, using the masked numbers to uncover the full number. Which is why we are advising our own public agencies to move away from the use of the masked numbers and not to give themselves that false sense of security. The Member's question on, how about if you invented a new identifier that cannot be worked backwards from the partial identifier? I think my answer still stands. Whether you can work out or you cannot work out, the identifier is not meant to be a secret. It is not shared widely, but some people will know. For example, the persons whom you revealed it to at the clinic, the person that you revealed it to when making a mobile line application. If this person was determined to get hold of your identifier, the NRIC number in this case, or any other identifier that you use to access information and services that are not meant for them, they will do so.”
“Mr Speaker, I thank Mr Giam for his questions. As I said in my Ministerial Statement, the problem is relatively contained. So, we have observed instances of, for example, bank statements being sent to individuals and being accessed with most of the time, a partial NRIC number. Usually, in what people receive, you need a password to access a file that is attached to an email. Although the email is already encrypted, for whatever reasons, these organisations still believe that it is necessary to attach another layer of access security for the document that is carried as part of the email. So, this process then involves, very often, using a combination of some other identifier, some other information, could be date of birth, combined with part of the NRIC number to access. The question has to be, is there really a need for authentication to begin with? If you use the example that I have just raised, previously, before statements of this nature were sent by encrypted mail, it would have been mailed to our homes in a little envelope. That envelope does not need a special password for us to open up. So, the fact that some organisations have decided that they need a further layer of authentication in order to access that bank statement, firstly, we would invite the organisation to think through: do you really, really need it? So, that is one question. If they still choose, for whatever services that they make available digitally to their clients or to their stakeholders, to require authentication, then, our advice to them is that the NRIC number is not a very good authenticator, they should not use it at all. So, that remains our advice.”
“Mr Speaker, I thank Mr Yip for his question and for always having a heart for those that are less privileged. He is right to say that there will be certain hard-to-reach segments: seniors, perhaps persons with less privileged backgrounds. We do intend to use all channels available to the Government. They can certainly include people who are volunteers on the Seniors Go Digital programme. We would welcome the opportunity to partner with the Silver Generation Office or more broadly, the Agency for Integrated Care, which also supervises the active ageing centres. I should say that in terms of reaching out to, for example, small and medium enterprises, fortunately, we do have the trade associations and chambers who are forward leaning. In fact, they have approached us and initiated the process to better inform their members on what to do. So, we will use all channels available to the Government in order to strengthen the outreach. If Members have suggestions on any groups that we may have missed out, please feel free to let us know too.”
“Firstly, congratulations to Ms Sylvia Lim on her recent nuptials. You must have used your full NRIC number at the registry, right? Singpass too! Ms Lim asked a very relevant question. Does the digital NRIC card suffice as an authenticator? If you open up your Singpass app and you tap on your digital NRIC card, you will see your photograph. And therefore, containing this information allows the digital ID card to be matched against the person holding the device that shows this digital NRIC. In fact, we have said quite clearly that the production of this digital NRIC card is the same as producing the physical NRIC card. So, that part is quite clear. So, it would be acceptable as an authenticator. I could just put it across that way.”