Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Generative AI

The Generative AI System Security Plan template includes Level 0 and Level 1 baseline controls that are recommended as the default controls for systems that utilise generative AI models. Agencies may customise this template to create their own system-specific System Security Plan or use it as a default System Security Plan for generic Generative AI systems.

Last updated 24 March 2026

System Characteristics

DP: Data Protection (1)

DP-8: Data Classification Disclosure

Control Statement

Control Recommendations

Risk Statement

GA: Generative AI (8)

GA-1: Overseas-hosted GenAI API services

Control Statement

Control Recommendations

Risk Statement

GA-2: Singapore-hosted GenAI API services

Control Statement

Control Recommendations

Risk Statement

GA-3: Non-logging and non-training Agreement

Control Statement

Control Recommendations

Risk Statement

GA-4: Data classification for self-hosted GenAI models

Control Statement

Control Recommendations

Risk Statement

GA-5: GenAI model formats and loaders

Control Statement

Control Recommendations

Risk Statement

Parameters

GA-6: File upload safeguards

Control Statement

Control Recommendations

Risk Statement

GA-7: Evaluation of GenAI accuracy, safety, and output quality

Control Statement

Control Recommendations

Risk Statement

GA-8: Inform users about GenAI risks and limitations

Control Statement

Control Recommendations

Risk Statement