Set clear approval rules for AI-generated tools: Forum
Source: Straits Times
Article Date: 07 Oct 2026
As AI enables more employees to develop automated tools, businesses should establish clear approval requirements before those tools enter operational use.
I refer to the article on Bee Cheng Hiang customers’ e-mail addresses being exposed after an employee used AI to generate a bulk e-mail program (Bee Cheng Hiang customers’ e-mail addresses exposed in first case of AI-related data breach in S’pore, Sept 30).
According to the Personal Data Protection Commission, testing of the e-mail distribution code had involved checking activity logs without inspecting the actual test e-mail.
As AI enables more employees to develop automated tools, businesses should establish clear approval requirements before those tools enter operational use. Permission to use an AI application should not automatically authorise deployment of its output in systems handling customer records, sending communications or executing transactions.
Controls should reflect the potential consequences. Tools that process personal data or perform actions at scale should be tested with dummy records and reviewed by someone with appropriate expertise. Testing must assess the actual outcome, including what information recipients can see. The approval record should identify the checks performed, any limitations and the person responsible for authorising deployment.
Smaller businesses may need external technical assistance for higher-risk applications. Industry bodies could support them with practical testing guides and access to qualified reviewers.
AI training should let employees recognise when a proposed tool requires further review. Management must provide the approval process, expertise and time needed to complete that review before customers are affected.
Calvin Zhang Song
Source: The Straits Times © SPH Media Limited. Permission required for reproduction.
1