Josephine Teo
Singapore
“The Government's risk-calibrated approach to data security in artificial intelligence (AI) systems was explained in a written reply, given on 9 January 2024, to related questions asked by Dr Tan Wu Meng and Mr Gerald Giam.”
“Access to frontier models is helpful for specific use cases, such as advanced research and cybersecurity. However, these form a small proportion of artificial intelligence (AI) demand. For most industry, Government and research uses, capable models are already available.”
“The Government tracks the development of technical standards for identifying artificial intelligence (AI)-generated content, including watermarking and digital provenance approaches, as part of broader efforts to manage AI-related risks.”
“Upon receiving a valid report of intimate image abuse, the Commissioner of Online Safety is empowered by law to direct Online Service Providers (OSPs) to disable access by Singapore users to the specified harmful online material. This direction may be extended to cover identical copies found on the platform.”
“The Government is committed to keeping children safe online. We have announced plans to extend age assurance requirements to designated social media services, including requiring platforms to keep users under 13 off their services.”
“Under the Online Safety (Relief and Accountability) Act 2025, the Commissioner of Online Safety is empowered to issue directions to platforms to remove specified harmful content, including intimate image abuse.”
The complete record
Every one of 2,900 lines we hold for Josephine Teo, in date order, each linked to its source. Free to read, in full, without an account. Page 7 of 58.
“Dialect content is allowed to a limited extent on free-to-air (FTA) television to support the prevailing language policy of Mandarin as one of the four official languages. This includes a dedicated two-hour belt of full dialect programmes every Friday late morning on Mediacorp’s Channel 8, which comprises over 90 hours, or 1% of Channel 8’s total transmission hours per year. This has remained constant over the years. The breakdown of dialects used is not tracked as, in most instances, a mix of dialects may be used during a programme.”
“Ministers are empowered to issue Correction Directions under the Protection from Online Falsehoods and Manipulation Act 2019 (POFMA). Two conditions must be satisfied before a Correction Direction can be issued; first, a false statement of fact must be communicated in Singapore, and second, the Minister in question is of the opinion that it is in the public interest to issue the Correction Direction. Whether a Correction Direction should be issued for a false statement of fact is a fact-specific assessment made by the Minister within whose domain the falsehood falls. The relevant Minister, supported by his or her staff with the requisite domain expertise, will carefully evaluate each case. This includes the nature of the falsehood, its context and the harm to the public, before deciding whether a Correction Direction should be issued.”
“Mr Speaker, the short answer is, yes. The video that I played earlier was completely generated by AI, notwithstanding the fact that the script was approved by me and it could have been penned by me, that image itself is problematic. I did not actually stand in front a camera and articulate those words. So, the way the Bill is designed is to not offer any room for misunderstanding. If you did not, in fact, read out a speech, even if you had written it, you used AI to generate that speech, that is prohibited. 7.16 pm”
“Mr Speaker, I thank Ms He for her clarification. I think it is helpful.”
“We introduced this Bill after careful study of global trends and a realistic assessment of what could happen in Singapore's elections if this threat was left unchecked. I urge all Members to support this Bill. Together, we can ensure that deepfakes and other digitally generated and manipulated content do not prejudice the fair and free elections that Singaporeans should be able to experience. Mr Speaker, I beg to move.”
“This will mean requiring social media companies to play a larger role in the complex issue of tackling deepfakes, given their extensive influence in shaping our online experiences. MDDI and the IMDA are in the process of engaging the major social media services in Singapore. The companies have been receptive to our proposals and recognise the need to do more against digitally manipulated content. We aim to introduce the code in 2025. Mr Yip, Ms He and Ms Soh have asked about our public education efforts to alert our citizens to the dangers of AI-generated misinformation. We agree that a digitally-aware public is the strongest defence we have against misleading and deceptive manipulated online content. Public education plays a critical role in empowering Singaporeans to safeguard themselves against risks in the digital space and be resilient to such threats. To this end, the Government has put in place public education programmes to equip the public to be discerning producers and consumers of information and protect themselves against online falsehoods. For example, the National Library's S.U.R.E. programme, which stands for source, understand, research and evaluate, has developed resources and organised activities to educate Singaporeans about the dangers of misinformation. In fact, the National Library Board is currently rolling out its community outreach initiative, Be S.U.R.E. Together: Gen AI and Deepfakes Edition, which provides opportunities for the public to learn about the uses and threats of generative AI. Mr Speaker, the Bill before us seeks to further protect Singapore's future elections from misinformation caused by deceptive deepfakes.”
“Some Members like Dr Wan Rizal and Ms He have asked if the Returning Officer or election officials can proactively monitor the Internet to identify prohibited content and how they will be supported in enforcing provisions under the Bill. During the election, there are processes in place to monitor for and minimise the risk of election interference that can arise from the spread of prohibited OEA. There will be dedicated teams stood up during the election period for this purpose and they will work closely with the social media services to act swiftly on prohibited content. As candidates will be best placed to determine if there is false OEA being circulated, we will rely primarily on their requests to review problematic content. However, the Returning Officer may still assess and act on problematic content without a candidate's request and declaration if the content is surfaced and deemed likely to threaten electoral integrity. Mr Speaker, I have discussed how this Bill, along with other legislative levers, deal with various types of harmful deepfakes. The Bill focuses on a specific category of deepfakes during elections while other legislation such as POFMA, OCHA and the Broadcasting Act may be used to tackle other forms of harmful deepfakes. However, beyond outrightly harmful consequences, the proliferation of deepfake content is also concerning. When users can no longer differentiate what is real and what is fake, there is a wider threat to trust in online media. As I said in my opening speech, the IMDA will introduce a Code of Practice to deal with digitally manipulated content at all times, beyond the election periods.”
“If we are aware of hostile information campaigns or foreign interference, we will address them under the Foreign Interference (Countermeasures) Act, or FICA. Ms He asked if the penalties for non-compliance by the social media services are too low to have sufficient impact or deterrence. Dr Wan Rizal asked if the penalties should be scaled according to the platform's reach and impact. Sir, the financial penalty quantum is comparable with other local legislation that covers social media services, such as POFMA and the Broadcasting Act. Non-compliance with the corrective directions is an offence punishable by a fine of up to $1 million and it will be for the Courts to decide the appropriate level for each offence. Beyond the exact quantum involved, the imposition of financial penalties on the services for not doing enough to preserve free and fair elections would have reputational implications for the respective platforms, whether from the perspective of Singapore users or globally. Some Members including Ms Pereira asked about tools that the Government will use to detect deepfakes. The Government will use a mix of commercially available and in-house tools such as AlchemiX, a tool developed by the Home Team Science and Technology Agency which can compare recordings of a suspected deepfake video with a recording of a speaker's actual voice. Deepfake technology is constantly improving and our capabilities must evolve accordingly. I seek Members' understanding that we will err on the side of caution and not reveal the full extent and capabilities of our detection tools. This is to guard against malicious actors who may seek to exploit this information and use it to game or circumvent our systems.”
“Further details of the prescribed modality will be shared in future. In cases of positive campaigning, where the impugned content actually portrays a candidate favourably, other candidates and even non-candidates can make a request for review. However, we will still ask the depicted candidate for a declaration as the Returning Officer and his team are unlikely to have the full facts. If the depicted candidate does not make a declaration for whatever reasons, the Government is still empowered to issue directions if we have other objective information that the content is in breach and should be prohibited. Members including Mr Yip and Ms Soh have asked about the timely issuance of corrective directions and safeguards against foreign-based entities who attempt to influence our elections. We recognise the need to quickly disable such false online content about candidates, but there is also the need to be rigorous and fair. The Returning Officer will have to strike a balance. Once a corrective direction is issued, the expectation is for individuals, social media services and Internet access service providers to respond within hours. This is to minimise the potential harm that such content could cause during our election period. The proposed ban covers the publication in Singapore of all digitally generated and manipulated OEA depicting candidates, regardless of the nationality of the user who created or published the content. This addresses the question by Ms He. In addition, we already have rules prohibiting foreigners or foreign entities from knowingly publishing or publicly displaying any election advertising. This is in line with the principle that Singapore's politics are for Singaporeans alone to decide.”
“Each of the requests and declarations made by candidates to the Returning Officer will be carefully assessed. The Returning Officer will only issue corrective directions for genuine cases that have met the requirements. Mr Zhulkarnain asked if a candidate should instead affirm a statutory declaration for this purpose. My colleagues and I have studied the options and weighed the trade-offs between the formal process of making a statutory declaration in front of a Commissioner of Oaths and submitting a declaration online. An online declaration is both efficient and effective. The consequence is direct and appropriate. The offence is an election offence and should be punished in accordance with elections legislation, which provides for the loss of seat for egregious offences. The general punishment of making false statutory declarations does not capture the seriousness and context of this offence. The digital mode of the declaration is also meant to facilitate a speedy and efficient declaration process for candidates during the election period. In the spirit of promoting fair elections, we want to encourage candidates to report content that misrepresents them by removing as many administrative barriers as possible. Members like Mr Ng have also asked if any candidate can request corrective directions to be issued, not just candidates who are depicted in the impugned content. As I mentioned in my opening speech, we will place significant weight on a depicted candidate's declaration to the Returning Officer as he or she is in the best position to clarify if the content is an accurate representation of himself or herself. Therefore, in most cases, we will rely on candidates making requests and declarations when they are depicted in the impugned content.”
“Recipients of a corrective direction who feel that their content has been wrongfully taken down can contact the Returning Officer to provide supporting evidence of their claims. If the Returning Officer does not accept their appeal, they may apply to the Courts for judicial review of the Returning Officer's decision. If content was found to have been mistakenly taken down due to a false declaration by a candidate, there will be serious consequences for the candidate, including the loss of his or her seat if elected. If the content does not otherwise meet the criteria for prohibition, it can be reposted. To Ms He's query, there are also current penalties in place for persons other than candidates who knowingly provide false information to Government agencies. During this debate and on previous occasions, Members including Ms Sylvia Lim and Ms He have acknowledged the difficulties in determining the authenticity of online media content. This is why candidates will have to make a declaration in addition to their request to Returning Officer to assess content under the ELIONA Bill. Members will agree that we cannot just take a candidate's word at face value. Ms Soh highlighted what has been described as "liar's dividend". This is why, in addition to the candidate's declaration to the Returning Officer, there is an independent technical assessment made by the Returning Officer and his team of public officers and we have instituted severe penalties for a false declaration. To the question by Mr Louis Ng, candidates will be asked to submit their declarations via an online form during the election period. This form will be available on ELD's candidate services portal. More details on the information requirements will be shared in due course.”
“Our belief is that news agencies can and should play a part in preserving the integrity of our elections. The prohibition does not apply to news published by authorised news agencies because of their duty to report on news fairly and accurately to inform and educate the public. In fact, this is not new. Today, media outlets report on online scams to educate the public about its dangers and to let citizens know how to identify and avoid scams. This often includes republishing images of online content to alert citizens to the scam. Mr Yip and other Members sought assurances that the issuance of corrective directions will be impartial and that measures will apply equally, regardless of the party the depicted candidate belongs to. Sir, the Bill itself is designed for impartiality. We apply the same criteria to determine who are considered candidates. They are all provided with the choice of when to inform the public of their candidacy. The defined election period is also known to all candidates at the same time. The duration and thresholds for content prohibitions are the same for all candidates. We do not even assess whether the prohibited content is favourable or unfavourable to a candidate. This would be highly subjective and open to dispute. Deceptive content will not be allowed, whichever party the candidate belongs to. To ensure transparency and accountability, the public will be notified about corrective directions that have been issued against offending content, so that they can vote in an informed manner. To Ms Hany Soh's question on how this will be done, ELD will make an assessment and provide an update in due course. Members including Mr Zhulkarnain and Ms He have also asked – what recourse is there if a piece of content was deemed to be wrongfully taken down?”
“If prohibited content is circulated in these open groups, the Returning Officer will assess if action should be taken. If the same prohibited content is posted online, on websites or social media platforms, we can issue corrective directions for it under the ELIONA Bill. Members, such as Mr Louis Ng and Dr Wan Rizal, asked how we will assess if a piece of content is realistic enough to be believed. Clearly, this is not an exact science. But there are some factors that can be considered and I had outlined them in my opening speech. The aim of the ELIONA Bill is to uphold the integrity of our elections. We have seen how disinformation, even if believed by a small segment of society, can lead to drastic and violent consequences. Consider how allegations of election fraud in the US played a role in the deadly Capitol Hill insurrection on 6 January 2021. So, I hope Members will agree that we should not accept any segment, no matter how small, voting based on a false representation. We have no way of knowing in advance the extent to which it will alter the course of our elections. But why should we subject our elections to such risk at all, if we can prevent it or, at least, minimise it? This is why the ELIONA Bill has been drafted in this manner, to allow for the prohibition of deepfake content as long as some voters reasonably find them believable. Ms He opposed the proposal to allow mainstream media platforms to reproduce content prohibited under the ELIONA Bill when reporting on news and current affairs during the election period. I am slightly puzzled because in her speech Ms He also advocated educating the public through short-form videos, which will likely have to reproduce such content in some form to show how realistic they are.”
“Would they also believe that the candidate did or said that thing in real life? Memes and satire are already part of our online space. Most of such content will show caricatures of individuals, and a reasonable person will be able to distinguish fact from fiction. This also applies to other online content, like online political campaign posters. Mr Zhulkarnain asked what our approach will be if the offending content was labelled, in other words, declared to have been digitally generated or manipulated. Sir, labelling does not automatically exempt content from being prohibited by the ELIONA Bill. A label may not be noticed by everyone. There are also ways to remove labels from content before recirculation. What matters are the four criteria I have shared previously: (a) the content constitutes OEA; (b) it is digitally generated or manipulated; (c) it is realistic; and (d) it shows the candidate doing what he did not do or saying what he did not say. If these criteria are met, the content will be prohibited, even if labelled. Some Members asked for confirmation if the proposed ban covers private or domestic communications, such as messages on WhatsApp and Telegram. The election rules are not intended to police private or domestic communications. When deciding whether a communication is of a private or domestic nature, the Returning Officer will consider various factors, such as the number of individuals in Singapore who can access the content, if the group is public or closed and the relationships between the individuals. As an example, chat groups on WhatsApp and Telegram with very large memberships that anyone can freely join should not be considered private or domestic communication.”
“Furthermore, traditional media editing software are now beginning to adopt AI technologies, such as Photoshop's introduction of GenAI capabilities to add and remove content, with photorealistic results. This further blurs the line between content that has been purely manipulated via AI technology and other traditional means. This is why ELIONA does not exempt from prohibitions content that has been partially edited by AI or other more traditional technology. For instance, if one manually wrote a speech, but uses AI-generation to produce a video of a candidate reading it, the video will be considered to be AI-manipulated and will be prohibited. This addresses the point raised by Mr Vikram Nair. Mr Vikram Nair also asked if the Bill covers content about a candidate that does not directly relate to the constituency which the candidate is contesting in. The answer is yes. A piece of content does not have to refer to the specific constituency which a candidate is contesting in for it to be considered OEA. We will make a holistic assessment of what constitutes OEA, and if the online content that misrepresents a candidate has the potential to unduly influence the behaviour of voters in the election. Members, including Mr Louis Ng, Mr Yip and Mr Zhulkarnain, have asked how we will treat OEA designed to entertain, such as satire or memes. As I mentioned in my opening speech, content that does not mislead and deceive people about a candidate’s actual speech or actions will not be banned. Besides the question of whether it is digitally generated or manipulated, the law requires us to consider these questions. If the public saw or heard the content, would they believe it is the candidate being depicted in the content?”
“Where do we draw the line and who decides? As the political contest develops, the dynamics may also change. How about persons who were previously not influential but suddenly gained prominence? Similarly, Ms Pereira asked why the new measures only apply to content that explicitly depicts candidates and not content that indirectly misrepresents them. One such example is an AI-generated podcast that discusses their past. This problem has existed even without AI or digital manipulation, for example, through coffee shop talk of people who claim to know something about the candidate. However, the difference is that deepfake content can be very realistic and, hence, persuasive. When they directly depict candidates doing or saying something, the audience is more likely to accept it as reality. In contrast, hearsay information or third-party accounts like coffee shop chatter tend to be discounted, or at least viewed with some scepticism. There are also practical difficulties in extending the coverage of the ELIONA Bill outside of content directly depicting candidates' words and actions. For example, how do we ascertain the degree of misrepresentation and whether it warrants prohibition? The better alternative is to encourage a culture of truthfulness, where persons of influence and candidates themselves step forward to clarify to the public if they have been misrepresented through deepfake content. Voters, too, must be vigilant and turn to trusted sources, such as our mainstream media. Sir, in our review of how manipulated content has affected elections globally, we have seen examples of content being edited using non-AI means to very realistically misrepresent electoral candidates.”
“Previously, Ms He Ting Ru asked about the recourse for political candidates affected by deepfakes during cooling-off or Polling Day in elections. The ELIONA Bill provides the recourse. But we know that purveyors of deepfakes will not constrain themselves to just the Cooling Off Day or Polling Day. If we are to effectively uphold the integrity of elections, the protections under the Bill must be available when election activities are the most intense and mischief makers most active. This is usually the election period, which is also defined in section 61S of the Parliamentary Elections Act and section 42R of the Presidential Elections Act. It starts from the issuance of the Writ of Election and ends after the close of Polling. Mr Yip Hon Weng and Ms He suggested that the proposed duration of the ban should be longer. I thank them for their suggestion and agree with both their concerns. Practically speaking, however, even if we wanted ELIONA to take effect x days before an election, we cannot do so until the Writ is issued and Polling Day revealed. This is why we will introduce a Code of Practice to require specified social media services to implement safeguards beyond the election period specified in the Bill. This allows for calibration of the speed of response and the resource requirements outside of election periods. Let me now deal with the types of content the Bill will and will not cover. Mr Zhulkarnain Abdul Rahim and Mr Vikram Nair have asked why the ban was not scoped wider to cover OEA that misrepresents persons other than candidates. For example, deepfakes that falsely show key influencers or artistes endorsing a candidate. We considered this carefully. The question is how influential must these other persons be for the prohibition to apply?”
“Mr Speaker, I thank Members for their unanimous support of the Bill. In fact, Members had expressed concerns about deepfakes even before the debate on this Bill. We have heard questions in this House about how we can better tackle impersonation scams. Earlier this year, Members Dr Tan Wu Meng and Ms Mariam Jaafar shared concerns about the impact of deepfakes on democratic processes and elections. Taken together with today's debate, there is clear consensus on the pressing need to deal with the threat of digitally-manipulated online content because of what is at stake – the integrity of our elections. Members have also sought clarifications on several issues. I will try my best to address them. Some Members have asked how the ELIONA Bill compares to other governments' attempts to tackle deepfakes. Sir, we do take reference from other countries, but it is more important to be fit-for-purpose. We have, therefore, scoped the law to be appropriate for Singapore's context. Earlier, I mentioned how South Korea bans all political campaign videos that used AI-generated content 90 days prior to an election. Brazil has also banned synthetic electoral propaganda. In response to Ms Joan Pereira’s question, we did consider a temporary ban on all deepfake content of a political nature during elections. After careful deliberations, we decided this was not necessary. There is nothing inherently wrong if AI is used, for example, to enhance the background of political communications materials. The key problem is with digitally generated and manipulated content that misrepresents a candidate’s words or actions. The Bill, therefore, targets such content. Members have also asked for the rationale behind the proposed duration of the ban.”
“This new law aims to prohibit the online publication of fake content that distorts a candidate's speech or actions so that we can better protect our democratic process and the fairness of our elections. However, legislation is not a panacea. Enhancing the public's ability to discern the authenticity of content is the most effective preventive measure. Therefore, let us work together to be more vigilant about online content, and verify them against reliable sources when necessary. Everyone should do their part and be the first line of defence against fake content. (In English): Sir, the ELIONA Bill will add an additional layer of safeguards to our elections, but everyone – candidates, citizens, tech platforms – has a part to play in protecting our democracy. We must keep our elections fair and honest, conducted on the basis of fact, not fiction. By and large, Members of this House, regardless of party allegiance, have supported these ideals and I appeal to Members to stand behind this Bill so that we can continue to uphold the integrity of our elections. With that, Sir, I beg to move. [(proc text) Question proposed. (proc text)]”
“Beyond the expectations set out in the ELIONA Bill during the election period, social media services should also bear greater responsibility for digitally generated or manipulated content at all times. Most major social media services are also prescribed Internet intermediaries (PIIs) under POFMA. They will be required to prevent and counter the abuse of digitally generated or manipulated content at all times through an upcoming Code of Practice under POFMA. This includes an obligation to put in place adequate systems and processes to enhance the transparency of digitally generated or manipulated content, such as through labelling. Like the three other POFMA codes in effect today, the new Code is being formulated in consultation with the PIIs. We intend to finalise the Code for issuance in 2025. Mr Speaker, may I continue in Mandarin, please. (In Mandarin): [Please refer to Vernacular Speech.] Mr Speaker, I believe that many people have experienced friends or family members around us believing in deepfakes online. No matter how we try to explain to them, they still believe in the fake content. Sometimes, even we can be deceived, and the spread of fake content is very difficult to guard against. With the rapid development of Artificial Intelligence (AI), deepfakes will only become more prevalent and realistic, allowing individuals with ulterior motives to sow seeds of doubt in our society more easily and quickly. If such fake content is widely disseminated during a General Election, the consequences could be too dire to imagine. In fact, this concern is not unfounded. In recent elections held in several countries, we have already witnessed the harm caused by fake content.”
“Second, it applies only during the election period, from the issuance of the Writ to the end of polling on Polling Day, to safeguard the integrity of the electoral process and preserve space for fair and legitimate political discourse during the elections. Third, the safeguards apply to all candidates, regardless of political party and potential impact of the fake content. This recognises that fake content favourable to one candidate must be unfavourable to another and vice versa. Our voters must be able to make informed choices based on factual and truthful representation of our prospective political leaders. Candidates, too, have a responsibility to conduct themselves with integrity during the elections. The ELIONA Bill updates our suite of measures introduced over the years to address various forms of harmful online content. During and outside the election periods, existing content regulation tools will continue to apply to certain types of AI-generated misinformation and deepfakes. For example, under POFMA, a Minister, or an appointed Alternate Authority during the election periods, may issue a direction for a recipient to communicate a correction notice. The Minister or Alternate Authority may also direct the removal or disabling of access to deepfakes on the grounds that they contain false statements of fact and it is in the public interest to issue the direction. Under OCHA, directions may be given to deal with online activities that are criminal in nature, such as deepfake-related scams. Under the Protection from Harassment Act, individuals may seek recourse for certain content that have caused personal harassment, alarm or distress to the individual.”
“To better equip the public to make informed choices during the elections, the public will be notified about corrective directions that have been issued against offending content. Non-compliance with a corrective direction issued by the Returning Officer is an offence. Recognising the extensive reach and responsibility that social media services must uphold, we have raised the fine of up to $1 million for a provider of a social media service that fails to comply with a corrective direction. This is a reasonable adjustment. The revised penalty is on par with similar offences under other content regulation tools like the Protection from Online Falsehoods and Manipulation Act (POFMA), the Broadcasting Act (BA) and the Online Criminal Harms Act (OCHA). For all others, including individuals, there is no change to the financial and custodial penalties for non-compliance with a corrective direction and remains at a fine not exceeding $1,000, or to imprisonment for a term not exceeding 12 months or to both. We have engaged major social media services on the requirements under the ELIONA Bill and shared our expectation that such directions are to be promptly complied with to uphold the integrity of our elections. Mr Speaker, as noted by Dr Carol Soon of the Institute of Policy Studies, the ELIONA Bill is carefully calibrated in its scope of the "what", "when" and "whom" and is a continuation of our principled approach towards the conduct of elections in Singapore. First, the Bill addresses the most harmful digitally generated and manipulated content, including deepfakes, that can influence electoral outcomes, while recognising the value of novel content creation techniques and the desire of candidates to employ innovative methods to engage voters.”
“To deter abuse of the law, such as candidates requesting to take down unfavourable content that is, in fact, a factual representation of their speech or action, it will be made an illegal practice for candidates to knowingly make a false or misleading declaration in a request. The penalties for an illegal practice are set out in the elections Acts. If convicted of an illegal practice, one may face a fine not exceeding $2,000 and become ineligible to be elected as a Member of Parliament (MP) or the President. Further, if already elected, the election of a candidate as a MP or President may also be invalidated. Currently, the Returning Officer has powers to issue corrective directions to any relevant person, including social media services, to remove or disable access in Singapore to prohibited OEA, or to stop or reduce its electronic communication activity. The ELIONA Bill extends these powers for the Returning Officer to issue corrective directions against this new category of content and corrective actions must be taken within the specified period of time. As mentioned earlier, the Government will prioritise candidates' reports and declarations to the Returning Officer. If assessed to be a genuine case, the Returning Officer will issue corrective directions. Only in exceptional cases will directions be considered against false representations without a candidate's declaration. This may arise when the objective facts are widely known or if the Government has access to data that reliably confirms the candidate's actual speech or action. The public can also report potentially prohibited content of candidates to the authorities for review.”
“At the same time, individuals themselves should also readily come forward to clarify and debunk content that they believe misrepresents them. The Government will use a range of detection tools to assess if the content has been generated or manipulated using digital means. We have at our disposal commercial tools and also those developed in-house or in partnership with researchers, such as those at the Centre of Advanced Technologies in Online Safety, or CATOS. These tools are constantly updated to keep up with technology. Continuing strong investment in research is one way to ensure we stay ahead. We have channelled $50 million in funding over five years to CATOS, which will develop new technological capabilities to detect online harms, including harmful digitally manipulated content. In reviewing reports of false content flagged under this new prohibition, the Government will prioritise candidates' reports to the Returning Officer. Besides the technical assessment on whether the content has been manipulated, the Returning Officer will also rely on candidates' declarations on whether the content falsely depicts their speech and actions. We have placed significant weight on candidates' declarations to the Returning Officer under this new prohibition, as the candidate is in the best position to speedily clarify if the content is a truthful and accurate representation of himself or herself. The Government is unlikely to have all the evidence of whether a candidate actually said or did something, especially if it was in a private setting. The declaration by candidates will be made to the Returning Officer, for candidates to attest to the veracity of his or her claim. This declaration form will be made available to candidates via the Candidates' Portal on ELD's website.”
“Third, we recognise that a layperson may carelessly reshare messages and links without realising that the content has been manipulated. The legislation provides for a defence if a person did not know and had no reason to believe that the candidate did not, in fact, say or do the thing and inadvertently commits the offence. Sir, the enhanced safeguards will apply during the election period, from the issuance of the Writ of Election to the close of polling on Polling Day. From the issuance of the Writ to Nomination Day, we will introduce a two-part requirement for individuals who would like to identify themselves as prospective candidates and have the safeguards of the ELIONA Bill apply to them. First, pay the election deposit; and second, consent for their names to be made public by the Elections Department (ELD). The consent form will be made available via the ELD website. The intent is for the website to be updated daily. Paying the election deposit is a prerequisite for standing in an election and an indicator of an individual's seriousness of intent to be a candidate. It is a step up from simply making a public declaration of one's potential candidacy. Publishing the names of those who placed the deposit will also make clear to the public which individuals are covered by the law. It is the candidate's choice entirely when to inform the public about his or her intention to stand for election before Nomination Day. Candidates can choose to put down the election deposit but withhold consent to make their names public until Nomination Day. After nomination proceedings are completed and up to the close of polling on Polling Day, the safeguards of the ELIONA Bill will apply to content depicting all successfully nominated candidates.”
“Memes will not be caught under the law as long as they are assessed to be unrealistic and do not mislead audiences about a candidate's speech or actions. Some Members may be concerned, will candidates' regular campaign posters, showing individuals against the backdrop of a group representation constituency (GRC) or a single member constituency (SMC), be prohibited if they are put online? Such posters are usually obvious composite images, such as candidates disproportionately superimposed in front of a landmark or backdrop. Members of the public would not reasonably believe such content to be realistic depictions of a candidate's action. Such campaign posters are unlikely to fall within the scope of prohibitions. Mr Speaker, I would like to make clear that the ban will not apply to certain types of content. First, the Bill does not extend to private or domestic communications. This refers to content shared between individuals or within a closed group, like group chats with family or a small group of friends, in view of user privacy. That said, we know that false content can circulate rapidly on open WhatsApp or Telegram channels. If it is reported that prohibited content is being communicated in big group chats that involve many users who are strangers to one another and are freely accessible by the public, such communications will be caught under the Bill and we will assess if action should be taken. The factors that determine whether communications are private or domestic are set out in the respective election Acts. Second, the prohibition does not apply to news published by authorised news agencies. This is to give space to fair reporting on prohibited content, such that the public can be alerted to the false content about candidates in a timely manner.”
“Sir, Members can also access this handout through the MP@SGPARL App. Examples of content that would be prohibited include: (a) realistic audiofakes featuring a candidate saying things he did not say; (b) realistic AI-generated images of a candidate participating at events that did not happen, meeting people that he or she did not meet; and (c) realistic manipulated images or videos taken out of context and misrepresenting a candidate's actions. It does not matter if the content is favourable or unfavourable to any candidate. The publication of such prohibited content during the election period, including by boosting, sharing and reposting existing content, will be an offence. As we propose this new measure to tackle realistic misrepresentations of candidates online, we are mindful not to disallow reasonable use of AI or technology in electoral campaigning. While each case will be assessed on a case-by-case basis, there are several scenarios that the prohibition will not extend to. The first is AI-generated or animated characters and cartoons. Most of these animations are not photorealistic replicas of real persons. Audiences will generally be able to tell that the speech or actions depicted are not real. The second is benign cosmetic alterations, such as the use of beauty filters or colour and lighting adjustments of images and videos. Such alterations typically involve modifications that do not materially affect truthfulness and do not result in a misrepresentation of a candidate's speech or actions. The third is entertainment content, such as memes. We recognise that such content can arise as part of online discourse during the election period.”
“That is, the content: (a) is or includes OEA; (b) is digitally generated or manipulated; and (c) depicts a candidate saying or doing something that he or she did not, in fact, say or do; (d) but is realistic enough that some members of the public who see or hear the content would reasonably believe that the candidate did, in fact, say or do that thing. Mr Speaker, with your permission, may I ask the Clerks to distribute a handout that will illustrate our thinking on what will be allowed or disallowed under the new provisions?”
“The condition of being realistic will be objectively assessed. There is no one-size-fits-all set of criteria but some general points can be made. First, such content should closely match the candidates' known features, expressions and mannerisms. Technically, we would expect a degree of sophistication resulting in minimal inconsistencies in aspects like lighting, body movements or audio distortions. Second, content may make use of actual persons, events and places so that the false representation appears more believable. For example, a fake rally speech touching on current affairs looks more real when placed against the backdrop of an actual and familiar rally site. We must also recognise that audiences perceive and process the same content through different lenses shaped by their individual experiences, beliefs and cognitive biases. For example, many of us find it incredible that the Prime Minister would be giving investment advice on social media. But as Members of Parliament, we have all met residents who have fallen prey to such AI-enabled scams. In this regard, the law will apply so long as there are some members of the public who would reasonably believe that the candidate did say or do what was depicted. Also, in assessing whether content matches a candidate's speech or actions, we will be relying primarily on declarations by the candidate if he or she had said or done that thing. I will elaborate on this later in my speech. All four legal limbs have to be met for the content to be prohibited.”
“The ELIONA Bill will amend our election laws to prohibit the publication of content that: (a) is or includes Online Election Advertising (OEA); (b) is digitally generated or manipulated; and (c) depicts a candidate saying or doing something that he or she did not, in fact, say or do; (d) but is realistic enough that some members of the public who see or hear the content would reasonably believe that the candidate did, in fact, say or do that thing. I will go through each of these criteria in detail. First, OEA under our existing elections laws refers to any information or material published online that can reasonably be regarded as intended to promote or procure or prejudice the electoral success or prospects of a candidate or political party. The existing OEA provisions guide the transparent and responsible use of the Internet during elections, including for campaigning; and ensure that the elections are contested fairly. The ELIONA Bill strengthens OEA regime by targeting the substantive content of OEA. Second, the ELIONA Bill is scoped to address content that is digitally generated or manipulated. This includes content generated or manipulated using AI techniques, such as generative AI. It also includes non-AI techniques, such as Photoshop, dubbing and splicing. These are now seen as more traditional editing methods, but they can still be used to manipulate content depicting candidates, making them as harmful and misleading as AI-generated deepfakes. Third, the ELIONA Bill is scoped to address the most harmful types of content in the context of elections, which is content that misleads or deceives the public about a candidate through a false representation of his speech or actions that is realistic enough to be reasonably believed by some members of the public.”
“The technology industry has also recognised the dangers of electoral deepfakes and the importance of ensuring voters can exercise their choice, free from AI-based manipulation. Twenty leading tech companies, including Meta, Microsoft, OpenAI and TikTok, signed the Tech Accord at the Munich Security Conference in February, committing to combat the deceptive use of AI in elections this year. In the face of these developments, Singaporeans are rightly concerned. One study shows that more than six in 10 Singaporeans are worried about the potential impact of deepfakes on the next election. In a 2021 ruling on a case related to misinformation and online falsehoods, our apex Court had said, "It is simply incompatible with the core principles of democracy to procure the outcome of an election to public office or a referendum by trading in disinformation and falsehoods." Mr Speaker, I hope Members will agree that AI-generated misinformation can seriously threaten our democratic foundations and demands an equally serious response. The Elections (Integrity of Online Advertising) (Amendment) Bill, or ELIONA Bill, is our carefully calibrated response to augment our election laws under the Parliamentary Elections Act and the Presidential Elections Act, ensuring that the truthfulness of candidate representation and the integrity of our elections continue to be upheld. Sir, I will now bring Members through the key aspects of the Bill.”
“Thank you. [A video was shown to hon Members.] Sir, Members will appreciate that artificial intelligence (AI) technology is improving quickly. If the deepfake video you just watched did not convince you of its impersonation of me, more advanced versions soon will. Around the world, countries have recognised the need to mitigate the harms of deepfakes to their elections. For example, South Korea revised its Public Official Election Act to ban political campaign videos that use AI-generated content 90 days prior to an election. Violations of the revised law, which took effect in January this year, can lead to jail time of up to seven years or a fine of up to 50 million won, which is almost $50,000. To date, 388 deepfakes have been taken down by the National Election Commission of South Korea during its elections. Another example is Brazil, which has banned synthetic electoral propaganda that will harm or favour any candidate during an election. The sanctions include the revocation of the candidate's registration or their mandate if they had been elected. Last month, the state of California passed into law the "Defending Democracy from Deepfake Deception Act of 2024", which requires social media platforms to block materially deceptive deepfakes of candidates from 120 days before the election to the day of the election. The Australian government is also considering the advice of its Electoral Commission to regulate the use of AI in elections, given the Commission's recent warning that it has limited scope to protect voters from deepfake videos and phone calls imitating politicians in Australia's upcoming elections. It is not just governments which are concerned.”
“Why have deepfake content proliferated? The short answer is that they have become very easy and cheap to produce. With your permission, Mr Speaker, may I play a video on the LED screens?”
“Mdm Deputy Speaker, I beg to move, "That the Bill be now read a Second time." Madam, 2024 is a bumper year for elections around the world. Almost half of the world's population have gone or will go to the polls this year. Unfortunately, there has been a noticeable increase of deepfake incidents in countries where elections have taken place or are planned. Research conducted by London-based technology company, SumSub, suggests that the numbers are alarming. In India, compared to a year ago, there are three times as many deepfake incidents. In Indonesia, more than 15 times; and in South Korea, more than 16 times. [Mr Speaker in the Chair] Earlier in January this year, a fake version of the United States (US) President Joe Biden's voice was featured in robocalls that sought to discourage Democrats from participating in the New Hampshire primary. The robocalls reached thousands of people. The US Federal Communications Commission has since declared artificial intelligence (AI)-generated robocalls illegal, noting that they have the potential to confuse consumers with misinformation. The telecommunications company, which transmitted the fake robocalls, has been fined US$1 million and the individual behind it has been fined US$6 million and criminal charges. During the Slovakian parliamentary elections last year, a deepfake audio of a politician discussing electoral rigging was posted online. Unsurprisingly, the audio went viral. Its impact was amplified by its timing, right before Slovakia's electoral "silence period", which is like our cooling-off day. The candidate lost the elections, despite having earlier led in the polls. Did the deepfake audio contribute to his loss? No one can say with certainty, but surely we prefer not to have elections subject to such incidents.”
“Mobile operators are required by the Infocomm Media Development Authority to provide coverage of at least 85% within buildings, including first-level basement carparks. If mobile operators’ overall coverage for a building falls below 85%, they are required to take action to improve. Within a building, mobile operators can decide whether to provide coverage in specific areas like lifts, equipment rooms and car parks located at second-level basements or below. Footfall in these areas tends to be transient and it is up to building owners to assess if they require mobile service coverage. They may engage mobile operators to do so on a commercial basis.”
“They can draw on the expertise of CSA and the Government Technology Agency (GovTech), if needed, to investigate vulnerabilities and compromises that have been discovered. A device management solution such as that provided by Mobile Guardian is not a CII. While the Ministry of Education has overall responsibility for its cybersecurity and resilience, CSA and GovTech provided various types of support such as forensic investigations when incidents happened. The Minister of Education has already covered the details in his earlier reply. My Ministry has set up a task force to draw lessons from the CrowdStrike incident as the incident had the potential to cause disruptions to a wider set of systems. This is part of the effort to strengthen the overall security and resilience of our digital infrastructure.”
“The Cyber Security Agency (CSA) focuses on the higher risk systems that could affect our national security and delivery of essential services because of the widespread or systemic impact if disrupted. These are designated as Critical Information Infrastructure (CII) under the Cybersecurity Act and held to high standards of cybersecurity and resilience. CSA also requires CII owners to conduct regular audits and testing on their CIIs so that vulnerabilities can be quickly identified and remediated. If they encounter cyber-attacks, CSA’s incident response teams will support CII owners to investigate, contain and remediate the attack. But not all Government information technology (IT) systems are designated as CIIs, nor should they be. Disruptions to non-CII IT systems cause varying degrees of impact. It is therefore only practical to take a risk-based approach in managing their cybersecurity and resilience. Their disruption may cause inconvenience and loss which should certainly be avoided. But the consequences are generally localised or do not pose widespread or systemic disruptions compared to disruption to a CII. The owners of these non-CII systems are in the best position to decide the resources to be put in to protect such systems against disruption, which should in general, be proportionate to their risks and impact. All systems must, however, maintain a baseline of cybersecurity and resilience measures that are appropriately stepped up according to their risk assessments. Defensive measures must also be complemented by business continuity plans that mitigate the impact of disruptions when they occur. Agencies that own IT systems are responsible for their cybersecurity and resilience.”
“To support the adoption of good data protection practices, the PDPC conducts educational and outreach activities through events such as the annual Personal Data Protection Week and Privacy Awareness Week. The PDPC has also worked with the Ministry of Manpower to disseminate notices to migrant workers to raise awareness about the importance of keeping their personal data safe. Ultimately, everyone must exercise judgement and ensure they fully understand how their personal data will be used by whom before giving consent for it to be collected.”
“The Personal Data Protection Act (PDPA) governs the collection, use, disclosure and care of personal data by organisations in Singapore, including Worldcoin. Biometric data – which relate to the physiological, biological or behavioral characteristics of an individual – can form part of the personal data of an individual. The Personal Data Protection Commission (PDPC) has also issued a Guide on Responsible Use of Biometric Data in Security Applications, to advise on risks unique to biometric recognition technology and measures to govern and protect biometric data. As biometric data are generally unique, they cannot be changed once compromised, unlike passwords or other tokens. Stolen biometric data can therefore be misused by malicious actors to spoof an individual’s identity – in order to access information or systems or conduct scams or other fraudulent activity. Such misuse is harder to defuse because biometric data cannot be changed. Organisations that handle such data must ensure they put in place the necessary data protection and security arrangements to address these risks, when designing and operating their systems and processes. They must also obtain consent from consumers before collecting their data by giving all necessary information in a manner that is understandable to the consumer. The PDPC has been engaging Worldcoin on their obligations under the PDPA and will continue to monitor their collection, use and disclosure of personal data, including biometric data. The PDPC may take enforcement action against organisations in Singapore that are found to have breached their obligations under the PDPA. The PDPC also monitors developments in other jurisdictions and is ready to work with international counterparts as necessary.”
“Ministries and Government agencies procure creative services in various ways, and many do so via the whole-of-Government Period Contracts and Framework Agreements (PCFAs). Vendors under the Creative Services, and Video and Animation Services PCFA are required to adopt Tripartite Standards, which covers fair recruitment practices and the procurement of services from media freelancers. Creative agencies must however be allowed to hire talents that best meet the needs of their clients in the most cost-effective way. The Government is committed to supporting our local artistes and the development of the creative industry. Government agencies have programmes and grants to uplift the capabilities of local talent and companies in the industry such as the National Arts Council’s Presentation and Participation Grant and the Infocomm Media Development Authority’s Media Talent Progression Programme.”
“PDPC has been engaging Worldcoin on their obligations under PDPA and will continue to monitor their collection, use and disclosure of personal data, including biometric data. PDPC may take enforcement action against organisations in Singapore that are found to have breached their obligations under PDPA. PDPC also monitors developments in other jurisdictions and is ready to work with international counterparts as necessary. To support the adoption of good data protection practices, PDPC conducts educational and outreach activities through events, such as the annual Personal Data Protection Week and Privacy Awareness Week. PDPC has also worked with the Ministry of Manpower to disseminate notices to migrant workers to raise awareness about the importance of keeping their personal data safe. Ultimately, everyone must exercise judgement and ensure they fully understand how their personal data will be used by whom before giving consent for it to be collected.”
“My response will also cover the matter raised in the question for oral answer by Mr Zhulkarnain Abdul Rahim which is scheduled for a subsequent Sitting. I invite the Member to seek clarifications, if need be. If the question has been addressed, it may not be necessary for him to proceed with the question for future Sittings. The Personal Data Protection Act (PDPA) governs the collection, use, disclosure and care of personal data by organisations in Singapore, including Worldcoin. Biometric data – which relate to the physiological, biological or behavioral characteristics of an individual – can form part of the personal data of an individual. The Personal Data Protection Commission (PDPC) has also issued a Guide on Responsible Use of Biometric Data in Security Applications to advise on risks unique to biometric recognition technology and measures to govern and protect biometric data. As biometric data are generally unique, they cannot be changed once compromised, unlike passwords or other tokens. Stolen biometric data can, therefore, be misused by malicious actors to spoof an individual’s identity in order to access information or systems or conduct scams or other fraudulent activity. Such misuse is harder to defuse because biometric data cannot be changed. Organisations that handle such data must ensure they put in place the necessary data protection and security arrangements to address these risks when designing and operating their systems and processes. They must also obtain consent from consumers before collecting their data by giving all necessary information in a manner that is understandable to the consumer.”
“There are a variety of tools and techniques available to the Government to detect, identify and assess manipulated content, including artificial intelligence (AI)-generated content such as deepfakes. These may be sourced commercially, developed in-house or in partnership with researchers such as those at the Centre for Advanced Technologies in Online Safety. We do not publish their accuracy levels as our tools are constantly being updated to keep up with technology. It is also not in the public interest to reveal the full extent of capabilities as malicious actors may exploit it. The Government can take action against online falsehoods when certain thresholds are met, including falsehoods generated with the help of AI. Action may be taken under the Protection from Online Falsehoods and Manipulation Act (POFMA) if such content is false and against the public interest. Satire or parody do not by themselves meet the criteria for POFMA action, unless they contain falsehoods that harm public interest. Individuals who disagree with POFMA directions issued to them, including those for deepfake content, can file an appeal in court. Many countries have recognised the need to mitigate the harms and risks from AI use and application, including the malicious use of deepfakes. Some countries have already put in place safeguards, especially during elections, in order to protect the integrity of the electoral process. We are studying if further safeguards are required and will provide an update when ready.”
“The Cybersecurity Act and specific sectoral regulations hold CIIs and key ES operators accountable for meeting the baseline security and resilience requirements. This includes timely review of risks assessments and audits. For example, Government agencies using third-party software in their ICT systems have to do a thorough risk assessment and put in place necessary mitigation measures. CSA also established the CII Supply Chain Programme to better manage key vendor supply chain risks. Businesses must also play their part to improve their resilience when disruptions occur and recognise that it is in their own, and their customers’ interests to do so. When things are running smoothly, businesses may question why they should incur cost or prioritise efforts to assess and improve their resilience measures. Unfortunately, some may not take appropriate actions until it is too late. We therefore encourage businesses to conduct their own risk assessments and put in place the appropriate BCPs to help business continuity in the event of a disruption. SingCERT has recently published an advisory on building digital resiliency, which can be found on CSA’s website. As part of the support for enterprises’ digitalisation, my Ministry offers other practical resources and financial assistance to encourage robust IT practices. This includes CSA’s cybersecurity toolkits and the Infocomm Media Development Authority’s SMEs Go Digital Programme. While these efforts may not specifically address IT outages like the one related to CrowdStrike, they can help businesses prevent incidents and recover more quickly should disruptions occur. I also encourage all businesses to take advantage of the Government’s resource support to strengthen their digital resilience.”
“Prominent examples of these were the passenger check-in for some airlines at Changi Terminal 4 and gantry operations at some Housing and Development Board carparks. Customers of affected business met with delays and were inconvenienced. However, business continuity plans (BCPs) kicked in. These included switching over to manual processes, such as for flight ticketing and check-in. The Singapore Cyber Emergency Response Team (SingCERT) of the Cyber Security Agency of Singapore (CSA) also quickly issued an advisory to guide affected system administrators and users on how to manually recover their systems. Most of the affected IT systems had recovered within a day, and services returned to normal. As Members know, IT systems may experience outages and disruptions from time to time. In this particular instance, it is not yet fully understood what caused a relatively routine software update to have created such major disruptions around the world. My Ministry has set up an internal taskforce to engage relevant partners to gain insights into the incident and assess if further measures should be taken to improve Singapore’s resilience when such disruptions occur. In the meantime, one key lesson can already be reinforced. As we have said on previous occasions, even with best efforts, not all disruptions can be prevented. System owners should therefore have plans in place to help them to recover quickly from unexpected disturbances. On its part, the Government adopts a risk-based approach to ensure our critical systems and essential services are resilient. Critical Information Infrastructures (CIIs), Essential Services (ES) and Government services are all subject to stringent requirements and have to put in place robust BCPs, Disaster Recovery Plans and Incident Response Plans.”
“I will answer Parliamentary Question (PQ) No 5 to 10 on today’s Order Paper, Written Parliamentary Question Nos 27 and 28 on today's Order Paper, and PQ Nos 60, 64, 65, 66, 68, and 69 on yesterday's Order Paper together, as they are related to the outage of IT systems caused by CrowdStrike on 19 July 2024. My response will also cover the matters raised in the oral questions by Assoc Prof Razwana Begum Abdul Rahim which are scheduled for a subsequent Sitting. I would invite all interested Members to seek clarifications after I have given my reply today. If the questions have been addressed, it may not be necessary to proceed with the Parliamentary Questions for future Sittings. On 19 July 2024, a faulty software update by a cybersecurity service provider CrowdStrike disrupted major services around the world. Images of the now infamous Blue Screen of Death appeared in media news cycles and attracted significant public attention. According to public reports, outages were experienced by users of the Microsoft Windows operating system that adopted CrowdStrike’s Falcon Endpoint Detection and Response (EDR) solution. It is a security solution that requires frequent and timely updates to be effective. The Members’ questions fall broadly into two categories. First, what is the impact of the outage in Singapore, particularly in relation to services provided by Government. Second, what are the lessons learnt, particularly in relation to the resilience of our IT systems. Fortuitously, Government services and most essential services in Singapore were unaffected by the outages. However, some businesses that use CrowdStrike’s Falcon EDR were affected. In most cases, the impact was to internal staff. In a minority of the cases, customers were impacted due to service disruptions.”
“Government funding to SPH Media Trust (SMT) is intended to support its talent, technology and vernacular capabilities. As part of the funding requirements, SMT must also ensure the circulation and delivery of its Flagship Titles’ print copies, on all days except Print Holidays.1 This applies to the Straits Times, Lianhe Zaobao, Berita Harian, Tamil Murasu and the Business Times. SMT should also inform the Government, as well as the public, and deploy contingency arrangements if there are unexpected delays in circulation affecting a significant proportion of home deliveries. There are penalties if SMT reports more than an acceptable number of such unplanned incidents. Outside of these requirements, SMT has autonomy over its business operations, including how newspapers are delivered to subscribers. It is important that SMT has flexibility to decide on the optimal delivery approach as it relies on some 390 vendors which face different challenges, including manpower shortages.”
“Mr Speaker, I think the Member's question is very specific to gov.sg, nothing to do with CrowdStrike, actually. But briefly, nobody is outsourcing responsibility for gov.sg. It is entirely the Government's responsibility. Gov.sg is a sender ID that is also protected by the SMS sender ID registry that we set up some time ago. The whole reason for requiring all Government communications with citizens, with the public, on SMSes to go through gov.sg is so that we can secure this channel more robustly. And I can share very briefly that extensive testing was implemented before the roll-out and, indeed, the roll-out was also first to a smaller group and then to a bigger group. So, I hope that addresses the Member's question.”
“Mr Speaker, the response to the Member's question is very similar to the response to the first set of questions that were posed in supplementary. It is actually in the companies' and systems owners' own interests to assure their stakeholders that they regularly test their systems and their systems have resilience. Where appropriate, we would, of course, put out what are good practices – and the Supply Chain Programme that we introduced together with the toolkit is one example. Mandatory requirements, if and when they have proven to be essential, foundational to all services, we are not averse to putting them in place. But we are still very mindful that there is such a great diversity in the systems and digital products and services that are being delivered to citizens, that a one-size-fits-all set of requirements may not really do the job but may, in fact, add to resources being diverted to meeting these compliance requirements without achieving the necessary resilience and usability that system owners should be striving for.”
“And whether you are at the car park gantry not able to get out or whether you are at the check-in counter not able to get your boarding pass, you feel just as annoyed or you feel that something has failed you. We understand all of that. So, it requires all of the actors, all of the stakeholders in the system, to be able to work with a single-minded focus on ensuring resilience of their systems.”