Singapore’s newly introduced mandate for AI-specific notifications is pushing organisations beyond simple disclosure and toward a harder question: do they actually know where their data lives, moves and is governed? That is the argument from Everpure, the enterprise data intelligence company formerly known as Pure Storage, in response to the new requirements for firms operating in Singapore.
Matthew Oostveen, Chief Technology Officer and Vice-President for Asia Pacific and Japan at Everpure, said the notification rules reinforce a principle that has long underpinned data protection in Singapore: effective AI governance cannot exist without effective data governance. Transparency, he argued, depends on organisations understanding what data they hold, where it resides, how it moves across environments, and how it is governed throughout its lifecycle.
Beyond disclosure: knowing where data actually sits
For organisations using Singapore as a regional hub for AI and enterprise data, Oostveen said the requirements mean understanding what data remains within the country, what crosses borders, what contains regulated or sensitive information, and what safeguards apply as information moves between countries, cloud environments and AI applications.
“As AI applications and agents become a bigger part of daily business, protecting people requires a shift in mindset. Instead of relying on individual applications to enforce privacy, guardrails must be attached directly to the data layer, so that privacy policies and citizen protections travel with the data wherever it is on its journey,” said Oostveen.
Towards ‘data primacy’ over application silos
Oostveen framed this as a broader shift in how organisations should think about enterprise information. Rather than data being fragmented across application silos, he said it should become a shared, governed system of record that carries its own business context, lineage and policies — a concept he called ‘data primacy’. Under this model, AI applications and agents can securely access trusted enterprise data without becoming its owner or creating new copies that increase governance and compliance risk.
Singapore’s new notification requirements, he said, reinforce the need for this approach. By embedding safety, context and privacy into the foundation of their data, organisations can protect the public, meet regulatory standards, and roll out AI with confidence.

