Artificial intelligence is now part of everyday business operations in Singapore. Marketing teams use AI to draft copy and create images. Research and development teams use AI coding tools. Management teams use AI to organise market information and internal reports.
The question many businesses have not yet considered is this: if a copyright dispute, commercial disagreement, investor review, audit or customer due diligence exercise arises, can the company explain how the content was created? Can it identify the input materials, the tools used, the people who modified and reviewed the output, and the person who approved its commercial use?
On 26 August 2026, Singapore’s Ministry of Law and IPOS launched a public consultation on “Artificial Intelligence and Singapore’s Intellectual Property Regime”. The consultation runs until 22 October 2026. The consultation does not itself create new law. It does, however, send a significant signal to businesses: AI compliance should address not only the final output, but also the process that produced it.
What the Singapore consultation is examining
The Ministry of Law and IPOS are seeking views on whether Singapore’s intellectual property laws and frameworks remain fit for purpose, trusted and capable of supporting innovation as AI develops.
Copyright: training, deployment and human contribution
The copyright consultation focuses on three broad areas.
First, it considers how to provide greater certainty and accountability in AI training while supporting innovation and protecting copyright owners. The issues include the scope of the computational data analysis exception, lawful access to materials and safeguards for rights owners.
Second, it examines how existing legal principles should apply when AI-generated output infringes copyright. It also asks how responsibility should be assessed among AI developers, deployers and end users. A business should not assume that any liability automatically belongs to the tool provider simply because the content was generated by AI.
Third, it considers the nature of human creativity in AI-assisted works. The consultation asks how human contribution should be understood, recognised and evidenced when generative AI is used as a tool in creative and business workflows.
Patents: inventorship and technical disclosures
The patents consultation focuses on how existing inventorship principles should apply across different forms of human-AI interaction, including problem formulation, selection from AI-generated outputs and human modification of technical solutions. It also examines how the large-scale publication of AI-generated technical disclosures may affect prior-art searches, examination, patentability assessments and incentives for innovation.
This is therefore not only a technology-sector issue. Any business using AI to process content, code, data or technical solutions may need to revisit its intellectual property and governance processes.
Why keeping only the final file is no longer enough
Many businesses assume that they face no IP risk as long as they did not deliberately copy someone else’s work. AI workflows are more complicated. A final file may look acceptable while leaving unanswered questions about the source and licence of the inputs, whether the output contains protected third-party elements, and the extent of the human contribution.
Consider a company that uses AI to create a promotional poster for a client. Management knows that an AI tool generated the image, but the company did not record where the input materials came from or check whether the output contained protected third-party elements. Months later, when the client receives a copyright complaint, the company may have nothing more than the final image to explain the process.
Or consider a technology company that uses an AI coding assistant without setting rules for whether employees may submit client materials, source code or trade secrets to the tool. Even if no dispute arises, the company may be asked during a financing, audit, merger, acquisition or customer due diligence exercise to explain the origin, licence scope and ownership of the code.
The practical distinction is important: the final deliverable is evidence of the result; the process record is evidence of governance.
Four categories of records businesses should retain
1. AI tools and use cases
Record which AI tools are used and whether they support marketing, design, coding, customer service, research or management analysis. The record does not need to be complex. It should identify the tool or service, the relevant team and the main business purpose.
2. Sources and permissions for input materials
Retain the source, permitted use and contractual basis for client-provided images, text, code, database content and other materials. For material obtained from the public internet or third-party platforms, record how it was obtained and what licence conditions apply.
3. Human modification, review and approval
Record who defined the task or prompt, who selected the output, who made substantive changes, who reviewed copyright and commercial risks, and who approved the final version for external use. This helps the company explain whether AI was an assisting tool or performed most of the substantive work.
4. The basis for commercial-use approval
For material projects, use management meeting minutes, board resolutions or internal approval records to document the purpose, permitted scope, risk assessment, responsible persons and follow-up arrangements. Projects involving core code, client data or trade secrets deserve particular attention.
What a company secretary can and cannot do
A company secretary normally cannot determine whether a specific AI-generated work infringes copyright. Nor can a company secretary replace an IP lawyer when the issue concerns ownership, inventorship, licensing or infringement.
A company secretary can, however, help establish a basic governance loop. When a company formally introduces AI into marketing, research and development or customer service, the company secretary can help ensure that the company identifies the project owner, approved tools, prohibited inputs, human-review requirements and approval authority. The secretary can also help centralise supplier terms, permissions, project descriptions, revision records, review records and meeting documents.
These records can help the company respond more quickly to questions during financing, audit, mergers, acquisitions or customer due diligence. They also reduce the risk that important decisions exist only in an employee’s private chat history, email account or personal computer.
A minimum internal policy to adopt now
A business does not need to build a sophisticated AI management system on day one. It should at least define:
•which teams may use AI and which tools are approved;
•which client data, personal data, source code and trade secrets may not be entered into AI tools;
•which external materials require source and licensing checks;
•which AI outputs require human modification and review;
•which projects require management or board approval; and
•how long the records must be retained and who is responsible for keeping them searchable.
If AI is used only to organise public information, the risk may be relatively limited. If it is used to create external marketing materials, develop core code, process client data or support major commercial decisions, the decision should not rest solely with an individual employee.
Building the record now is better than reconstructing it after a dispute
It remains to be seen what institutional arrangements will ultimately emerge from Singapore’s consultation on AI and IP. Businesses should not treat the consultation proposals as enacted law. They also should not wait for a legal dispute before designing their internal process.
A practical starting point is a simple, continuous and searchable record that answers three questions: What was used? Who reviewed it? Why did the company approve this use?
As AI, cross-border operations and investor due diligence become routine parts of business, clear governance records will serve more than copyright and patent risk management. They will also demonstrate the company’s professionalism, internal control and overall risk-management maturity.

