Centre For Cybersecurity Institute Centre For Cybersecurity Institute
Menu
cybersecurity

How to Use AI Chatbots Safely in Singapore

What CSA and IMDA's 2026 advisory says about using AI chatbots safely in Singapore: what never to share, how to check the answers, and where to draw the line.

By James Lim, CEO and Academic Director · Published 29 July 2026 · Updated 29 July 2026 · 8 min read

You can use AI chatbots safely, as long as you treat them as public tools rather than private ones. On 28 July 2026 the Cyber Security Agency of Singapore (CSA) and the Infocomm Media Development Authority (IMDA) issued a joint advisory for individuals, setting out three practices: safeguard your information, verify what the tool gives you before using or sharing it, and maintain healthy boundaries when engaging with AI. This guide turns those three into everyday habits.

Most guidance about AI security is written for IT teams. This one is not. It is aimed at the person using a chatbot to draft an email, plan a trip, check a symptom or work through a difficult decision, which by now is most of us.

If the way these systems fail interests you as more than a safety habit, CFCI runs a free cybersecurity career info session for people curious about working in the field.

What Does Singapore’s 2026 Advisory on AI Actually Say?

The advisory names three best practices for individuals, in order: safeguard your information when using generative AI, verify content received from these tools before using or sharing it further, and maintain healthy boundaries when engaging with AI. It is deliberately short, and none of it requires technical knowledge.

What makes it worth reading is the framing. CSA and IMDA are not warning people off generative AI. The advisory opens by acknowledging that these tools boost productivity, spark creativity and help with learning, then points at the three places where ordinary use creates risk: personal privacy, information accuracy, and digital well-being.

You can read the original at csa.gov.sg. It is a three-page PDF and takes about five minutes.

What Should You Never Share With an AI Chatbot?

Avoid giving a generative AI tool any personal detail you would ordinarily keep private. That means your full name, home address and NRIC number, and sensitive records such as financial or medical information. The reason is simple: once you share something, you lose control over how it is stored, processed or accessed, and if the tool is ever compromised that information can be used for fraud or scams.

The trap is that oversharing feels helpful. Asking for travel recommendations “for someone my age with my interests” gets you a better answer, so you volunteer a little more each time. Over months, even casual conversations can reveal a great deal about you.

Unless you have checked the terms of service and know otherwise, assume everything you type can be seen by the platform provider and may be used to train the model.

Keep it outUsually fineWhy the line sits here
Full name, home address, NRIC or passport numberA first name, a general neighbourhood, an age rangeIdentifiers are what make impersonation and account takeover possible
Bank details, income, insurance and medical recordsA general question about how something worksThese are the records fraudsters need, and you cannot recall them once sent
Client names, contracts, unreleased plans, HR recordsA rewritten paragraph with the specifics stripped outWorkplace data needs proper authorisation before it leaves the organisation
Passwords, one-time codes, recovery answersNothing. There is no safe version of thisNo legitimate tool needs them, and a chatbot cannot use them on your behalf
Photos of documents, screenshots with data still visibleA cropped image with identifiers removedPeople forget images carry text, faces and metadata
Conceptual illustration of small teal and peach fragments of light drifting out through an opening, passing a frosted glass pane and dispersing beyond it, rendered in deep navy
Sharing is a one-way door. Once something has been typed into the tool, you no longer control how it is stored, processed or accessed.

The habit worth building is small: before you paste, read what you are about to send and take out anything that identifies a real person. It costs a few seconds and removes most of the risk.

How Can You Tell If an AI Answer Is Made Up?

You often cannot tell from the answer alone, which is exactly the problem. Legitimate AI tools are built with guardrails intended to limit harmful output, but those guardrails are not foolproof. The advisory uses the term confabulations, more commonly called hallucinations: fictional or partly correct information delivered in a convincing and authoritative manner, and often arriving as fabricated references, quotes or statistics that look entirely credible.

A made-up citation does not look made up. It has a plausible author, a plausible journal and a plausible year. That is why the check has to be a habit rather than a reaction to something feeling wrong.

Conceptual illustration of a polished frosted glass panel catching the light, with a thin peach line arcing from it back to a plainer anchored block behind, rendered in deep navy with teal accents
A confident answer is not a checked answer. Verification means tracing the claim back to the source that can actually settle it.
A two-minute check before you act on an AI answer
  1. 1

    Ask what happens if this is wrong 10 seconds

    If the answer only shapes a first draft or a brainstorm, use it. If it touches your money, your health, your legal position or someone else's, it needs checking before you act.

  2. 2

    Go to the primary source 60 seconds

    Verify against a legitimate source rather than another AI tool. For anything official in Singapore, that means the agency's own site: csa.gov.sg, pdpc.gov.sg, cpf.gov.sg, iras.gov.sg. If the tool cited a study or a figure, find the study.

  3. 3

    Escalate to a human where it matters As needed

    For health and legal questions, consult a qualified professional. CSA and IMDA are explicit that AI-generated content is a starting point, not the final word.

There is a second reason this matters beyond your own decisions. Content that seems harmful, misleading or manipulative is worth reporting to the platform and, where relevant, to the authorities, because that is part of how these tools get better for everyone else.

Are Third-Party AI Apps and Browser Extensions Safe?

Treat them with more caution than the official app. Plenty of generative AI is reached indirectly, through unofficial mobile apps, browser extensions and “AI assistant” wrappers, and those intermediaries can collect and use your data on their own terms rather than the model provider’s.

Two red flags are worth memorising. The first is a permission request that does not match what the app is for: a writing assistant asking for camera access or location data has no business need for either. The second is an unknown developer, particularly on an app that mirrors a well-known product’s name and icon.

If this pattern feels familiar, it should. Fake apps and over-permissioned extensions are an old technique wearing new clothes, and they sit alongside the other common cyber threats in Singapore that reach people through ordinary channels.

Can You Use AI Chatbots at Work?

Only within the boundaries your employer has set. The advisory is unusually direct on this point: workplace information and confidential or sensitive business data should never be provided to generative AI tools without proper authorisation. That covers client names, draft contracts, HR records, unreleased plans and anything you would not send to an external party by email.

In the awareness sessions we run for Singapore organisations, this is the question that comes up most often, and it is almost never asked by somebody looking to bend a rule. It is asked by people who want to use the tool well and genuinely do not know where the line sits.

In practice, most leaks of this kind are not malicious. Someone pastes a customer complaint into a chatbot to get help writing a calmer reply, or drops a spreadsheet in to have it summarised, and the data leaves the organisation without anyone deciding that it should.

The fix is not a ban. Blanket bans push usage onto personal phones where nobody can see it. What works is a short written policy that names what may and may not be shared, paired with training so people recognise the moment they are about to cross the line. That is the ground CFCI’s AI safety at work sessions cover for organisations, and it complements the wider cybersecurity awareness training most Singapore teams already run.

Where Do Healthy Boundaries With AI Sit?

The third practice is the one people skip, and it is the one the advisory spends the most care on. Because you interact with these tools through conversation, a chatbot can start to feel like a friend who understands you. What is actually happening is pattern recognition in a model, not empathy.

CSA and IMDA raise two specific concerns. The first is emotional dependency, particularly among younger users who may find it harder to distinguish a genuine connection from a generated response, and who may invest less in real relationships as a result. Parents and caregivers are advised to help children understand that AI is a tool for support or learning rather than a replacement for human connection. IMDA and CSA point to the Digital for Life guidance on AI companions for more on this.

The second is over-reliance. AI can help you explore ideas and see new angles, but it cannot do your thinking for you, and leaning on it too heavily carries a real cost to skill development, especially in education where creativity, critical thinking and reasoning are the point of the exercise.

Reasonable to delegateKeep under your own control
Drafting a trip itinerary or a first outlineImportant life, financial and career decisions
Rewording something you have already writtenJudging whether a source is trustworthy
Explaining an unfamiliar concept in simpler termsHealth and legal conclusions, which need a professional
Generating options you will then evaluateThe final evaluation itself
Summarising a document you can still checkLearning a skill you actually want to have

The test is straightforward. Delegate the parts where being wrong is cheap and easy to spot. Keep the parts where being wrong is expensive, or where the doing is the point.

The Bottom Line: Three Habits That Cover Most of It

Safe use of generative AI comes down to three habits, and none of them requires you to understand how the models work. Share less than feels natural, because you cannot take it back. Verify anything that matters against a primary source, because a confident answer is not a checked one. And keep the tool in its place, as something that augments your thinking rather than replaces it.

If you want to go further on the everyday basics that sit underneath all of this, our guide to cyber hygiene in everyday life covers passwords, two-factor authentication and safe browsing, and AI in cybersecurity: friend or foe looks at how the same technology is reshaping attack and defence. For the fraud side specifically, deepfakes and social engineering explains how convincing synthetic media is now being used against people and organisations.

Curiosity about how any of this works is a genuinely good reason to look at the field. At CFCI, 75% of graduates who secured cyber roles had no prior IT background, and quite a few of them started exactly here, by wondering how a system they use every day could go wrong. If that sounds like you, the free cybersecurity career info session is a low-commitment way to find out what the work actually involves.

Frequently Asked Questions

Is it safe to use AI chatbots like ChatGPT?

Yes, generative AI tools can be used safely, provided you treat them as public tools rather than private ones. Singapore's Cyber Security Agency and IMDA set out three practices in their joint advisory of 28 July 2026: safeguard the information you share, verify content before you use or share it further, and maintain healthy boundaries with the tool. The risk is not the technology itself but the habits people build around it.

What should you never tell an AI chatbot?

Avoid disclosing personal details you would ordinarily keep private, including your full name, home address and NRIC number, along with sensitive information such as financial or medical records. Workplace information and confidential or sensitive business data should never be provided to a generative AI tool without proper authorisation. Once you share something you lose control over how it is stored, processed or accessed, and your conversations may be used to train the model.

Can you trust what an AI chatbot tells you?

Not without checking. Generative AI tools are known to produce confabulations, commonly called hallucinations, which are fictional or partially correct statements delivered in a convincing and authoritative tone, often as fabricated references, quotes or statistics. CSA and IMDA advise cross-checking AI output against legitimate sources such as government websites, and consulting a qualified professional for health or legal questions. Treat the answer as a starting point, not the final word.

Is it safe to use AI chatbots at work?

Only within the boundaries your employer has set. The CSA and IMDA advisory is explicit that workplace information and confidential or sensitive business data should never be provided to generative AI tools without proper authorisation, and that includes tools reached through unofficial apps or browser extensions. The practical answer for most organisations is a short written policy naming what may and may not be shared, rather than a blanket ban that nobody follows.

Ready to secure your future?

Join a free info session to meet the team, walk through the curriculum and find the right path for you. No IT background needed.

Chat with us