ENGINEERING · AI SECURITY

When AI exposure becomes notifiable

Singapore’s PDPA sets two thresholds and a three-day clock. What that means when the data left through an assistant nobody approved.

4 August 2026·7 min read·By Agile Labs

What does the law actually require?

Singapore’s Personal Data Protection Act makes notification mandatory when a data breach meets either of two thresholds. The first is harm: the breach results in, or is likely to result in, significant harm to the individuals affected. The second is scale: the breach involves the personal data of 500 or more individuals, regardless of harm.

Categories that count as significant harm are prescribed in regulation and include identification numbers, financial account details, medical information and biometric data, among others. Where a threshold is met, the organisation notifies the Commission as soon as practicable and in any case no later than three calendar days after completing its assessment. Weekends and public holidays are inside that count.

The rule is not complicated. The difficulty is upstream of it.

Why AI exposure is hard to assess against that rule

A conventional breach has an event. A record was accessed, a laptop was lost, a bucket was public. There is a log with a timestamp and a scope.

Exposure through an assistant often has none of that. An employee pasted part of a customer record into a tool on a personal account, on a personal device, over a home network. Nothing in the organisation’s systems recorded it. The organisation may learn of it months later, from the employee, or from a supplier questionnaire, or not at all.

That produces a question the law does not answer: how do you assess an incident you cannot see? The answer is that the assessment has to be built from the sources that do exist, and its confidence stated honestly.

“A conventional breach has an event. Exposure through an assistant often has none.”

— on why the assessment is the hard part

What has to be established before a decision can be made?

Four things, and each takes evidence rather than assertion.

Which tool, and on what account type. The same product on a personal free tier and on an enterprise agreement are different findings, because the contract posture — retention, training use, sub-processing — is set by the tier rather than the vendor.

What class of data moved. Source code is the most common category submitted to unapproved tools, and source code is usually not personal data. Customer records, employee records and identification numbers are, and they attract the harm threshold.

How many individuals. The 500-person threshold is a count, and a count needs a scope. One pasted spreadsheet can cross it in a single action.

What the contract permits. A tool that is contractually entitled to hold the data changes the analysis; a tool that trains on it changes it again.

QuestionWhere the evidence comes fromConfidence
Which tools are in useIdentity provider grants; network egress; endpoint inventoryGood for corporate accounts, poor for personal ones
What data went inAssistant audit logs where the licence tier captures them; DLP logs; interviewsVaries sharply by tier and by tool
How many individualsThe source records themselves, once the file or query is identifiedGood, once the first two are answered
What the vendor may do with itThe contract and the AI addendum for that tierDefinitive, and frequently unread
Fig. 01 — A notification decision depends on all four rows. The first two are where most organisations discover they cannot answer.

Getting the truth out of people

Where the telemetry stops, the interviews start, and interviews conducted under implied threat return a confidently wrong picture. Survey evidence repeatedly puts the share of staff who would not admit unapproved AI use to a security team at around half.

A time-bound, explicitly non-disciplinary self-report window works better. It only works if the sponsor commits in writing, before the first conversation, that nothing disclosed will be used for discipline. The order matters too: run the telemetry first, then the interviews, so the questions are specific rather than general.

What we produce, and what we do not

An AI Exposure Assessment establishes what is in use, what data reached it, and what the contracts permit, with the confidence bound stated plainly. That is the input a notification decision needs.

The decision itself is the organisation’s, taken with its own legal advice. We are engineers rather than counsel, and an assessment that pretends otherwise is worth less, not more, because it invites a decision to be taken on the wrong authority.

Article

Published 9 August 2026

By Agile Labs

Agile Labs is a Singapore enterprise software engineering company. We design, build and secure enterprise software and AI systems.

Sources

  1. Personal Data Protection Act 2012 (Singapore), data breach notification obligation.
  2. Personal Data Protection (Notification of Data Breaches) Regulations 2021.
  3. PDPC guidance on assessing and notifying data breaches.

Related articles

View all insights

Have something complex to build, fix or take over?

Build better software, with zero surprises