In brief

On 28 July 2026, the Cyber Security Agency of Singapore (CSA) and the Infocomm Media Development Authority (IMDA) issued a joint advisory titled Safe & Secure Use of Generative AI for Individuals. The advisory provides practical guidance for individuals on managing privacy, security and digital well-being risks associated with the growing use of generative AI ("Gen AI") tools, including chatbots, virtual assistants and image generators.

The advisory identifies three key areas of focus: safeguarding personal information, verifying AI-generated content before relying on or sharing it, and maintaining healthy boundaries when interacting with AI systems.

Although directed primarily at individual users, the guidance is relevant to organisations deploying AI technologies in the workplace, as it provides guidance as to how employees can responsibly use AI both in the workplace and at home.

In more detail

Safeguarding personal information when using AI

The advisory warns that users may inadvertently disclose significant amounts of personal information through interactions with Gen AI tools, which could be misused if the platform is compromised or the information is accessed by unauthorised parties.

To mitigate these risks, the advisory recommends that users:

  • Avoid sharing personal information that would ordinarily be kept private, including identification numbers, residential addresses, financial information, medical records and other sensitive data
  • Refrain from uploading confidential workplace information or sensitive business data without appropriate authorisation
  • Use reputable AI services with clear privacy policies and terms of service, paying particular attention to how user data is collected, processed, stored and potentially used for AI model training.

The advisory also highlights risks arising from accessing Gen AI through third-party applications, such as unofficial mobile applications or browser extensions. It cautions users to watch out for indicators of potentially malicious applications, such as excessive permission requests that do not match the app's intended function (e.g., requesting camera access or location data), or apps from unknown developers.

Verifying AI-generated content before use or distribution

The advisory notes that while many AI providers implement safeguards to reduce harmful or inaccurate outputs, Gen AI systems can still produce "hallucinations" which appear convincing and authoritative despite being inaccurate. Hence, users should:

  • Cross-check AI-generated information against official and trusted sources
  • Seek professional advice for high-impact matters such as medical or legal issues
  • Treat AI-generated outputs as a starting point rather than a definitive source of information
  • Exercise caution before acting on, distributing or relying upon AI-generated content.

Users are also encouraged to report harmful, misleading or manipulative content to relevant authorities or platform providers where appropriate.

Maintaining healthy boundaries with AI

The advisory further addresses the increasing tendency of users to engage with AI through conversational interfaces, and emphasises that AI systems do not form genuine emotional relationships and merely generate responses based on patterns in data. The advisory recommends using AI as a tool to support learning, productivity and exploration rather than as a substitute for human relationships, ensuring that important decisions remain subject to human judgment and critical thinking.

Key takeaways

While the guidance is directed at individuals, its underlying principles are equally relevant to organisations seeking to foster safe AI practices among employees and users. Organisations should consider whether their internal policies, training programmes and AI governance frameworks adequately address the risks highlighted in the advisory, including the disclosure of sensitive information to AI systems, overreliance on AI-generated outputs and ensuring human verification of AI-assisted work products. Organisations should also consider regularly reviewing and updating their internal policies, training programmes and AI governance frameworks to keep pace with rapidly developing AI technologies and evolving regulatory expectations.

* * * * *

© 2026 Baker & McKenzie. Wong & Leow. All rights reserved. Baker & McKenzie. Wong & Leow is incorporated with limited liability and is a member firm of Baker & McKenzie International, a global law firm with member law firms around the world. In accordance with the common terminology used in professional service organizations, reference to a "principal" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as "Attorney Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.

Explore More Insight