As AI adoption accelerates, many organisations are discovering that governance can no longer be treated as a compliance issue. While AI may be deployed by technology teams, its impact extends across customer service, marketing, HR, operations and decision-making processes throughout the business, making AI governance a whole-of-business responsibility rather than just a tech function.
Singaporeโs proposed advisory guidelines on the use of personal data in generative AI reflect this growing reality. Although the guidelines focus on responsible data practices, they also signal a broader shift in how organisations are expected to manage AI risk. Increasingly, accountability is moving beyond the IT department and into the executive team and boardroom.

We take a closer look at Southeast Asiaโs AI boom and why adoption alone is not enough
This shift recognises that AI is not simply another tech investment. If it has the potential to influence customer trust, organisational reputation and regulatory compliance, shouldnโt AI governance be viewed as a business issue just as much as a technology one?
AI risks are becoming business risksย
For many organisations, responsibility for managing technology risks has traditionally sat within IT, security or compliance teams. AI is changing that dynamic.
As AI becomes embedded into business-critical functions, the consequences of poor governance can extend well beyond system performance. Issues such as inaccurate outputs, biased recommendations, misuse of personal data or a lack of transparency can quickly become reputational and regulatory challenges.ย
Importantly, these risks can emerge even when AI systems are functioning exactly as designed. Unlike traditional software, AI systems generate outcomes based on data, prompts and model behaviour, making their outputs less predictable and often more difficult to explain.
Executive accountability is becoming increasingly importantย
Regulators around the world are placing greater emphasis on accountability, transparency and oversight in the use of AI. Singaporeโs proposed guidelines reinforce the expectation that organisations should understand how personal data is being collected, used and protected within AI systems.
Meeting those expectations requires more than technical controls. Organisations need clear ownership, defined governance frameworks and visibility into how AI is being used across the business.
This is driving a significant change in leadership responsibilities. Executives and boards are increasingly being asked to understand where AI is being deployed, what risks exist, who is accountable for outcomes and how those risks are being monitored over time.
AI literacy is becoming a leadership capability
As accountability shifts higher within organisations, executive leaders are being required to develop a stronger understanding of AI.
This does not mean every leader needs deep technical expertise. However, they do need enough knowledge to assess risk, ask informed questions and make effective governance decisions.
Understanding how AI systems use data, where potential risks can arise and what safeguards are in place is becoming an important part of executive decision-making. Leaders who lack visibility into how AI is being adopted across their organisations may find it increasingly difficult to manage both risk and opportunity.
Governance is becoming a source of competitive advantage
Many organisations still view governance primarily through the lens of compliance. While regulatory obligations remain important, governance is increasingly becoming a differentiator in its own right.
Customers, employees and regulators are paying closer attention to how organisations use AI and manage personal data. Trust is becoming a critical factor in determining whether AI initiatives are accepted and successfully scaled.
Organisations that can demonstrate transparency, accountability and responsible data practices will be better positioned to build confidence among stakeholders and accelerate AI adoption. In contrast, those that treat governance as an afterthought may face greater scrutiny and resistance as expectations continue to evolve.
Defining the next phase of responsible AI leadership
Singaporeโs proposed guidelines provide an early indication of where AI governance is heading globally. The conversation is shifting away from whether organisations should adopt AI and towards how they can do so responsibly.
The organisations that succeed in the next phase of AI adoption will be those that recognise governance as a leadership responsibility rather than a technical exercise. By building strong governance frameworks and investing in executive AI literacy, they will be better positioned to manage risk, earn trust and unlock the long-term value of AI.
The article titled “Singapore is moving AI governance from the IT department to the boardroom” was authored by Arran Mulvaney, Regional Director – South East Asia & India at OneTrust
About the author

Arran Mulvaney is Regional Director for ASEAN and India at OneTrust, based in Singapore. He leads regional go-to-market strategy across Southeast Asia and India, working with enterprises in highly regulated sectors to operationalise data privacy, AI governance, consent, and third-party risk programs.
Arran partners with senior business, legal, risk, and technology leaders to help organisations move from regulatory awareness to practical execution. His work focuses on building trust as a business enabler, helping companies manage regulatory complexity, adopt emerging technologies responsibly, and create scalable governance programs across fast-growing Asian markets.
He is a frequent speaker on privacy, AI governance, and trust, with a particular focus on how organisations can turn compliance obligations into stronger customer relationships, better risk management, and more resilient digital growth.