An opinion column by Isabel Berwick in The Straits Times on 5 October 2026 opens on a split: most office workers are still primarily using this technology for basic tasks, while a few AI “superusers” have restructured their working lives around intensive use of new tools. If you are among the people quietly doing admin with it, the distance between those camps is a delegation question, not a motivation problem. [1]
The answer is a three-band split, applied weekly rather than in one heroic clean-up. Band one: the assistant drafts and sorts — thread summaries, first-draft replies built from information you supply, non-numeric filing. Band two: anything carrying a deadline, a figure, a contract term or a commitment, which the tool flags and you approve. Band three: decisions affecting a person, which stay with a human. Two written records make the habit defensible: a policy naming the surfaces the tool touches, and an inventory of the systems in use with training behind it. The bands are our suggested split; PDPC AI guidance supplies the data-protection conditions attached to them.
Draft, don't decide: where the handover line sits
PDPC's primer on the Model AI Governance Framework sets out a design framework for the degree of human involvement in an AI solution, mapping human-in-the-loop, human-over-the-loop and human-out-of-the-loop against the severity and probability of harm. Its worked example is telling: an online retail store wanting to fully automate food product recommendations is told that, given the low severity of harm and the fact that the customer can still decide whether to accept, the human-out-of-the-loop approach could be considered. A badly chosen snack is not the same kind of harm as a wrongly priced contract. [2]
The Implementation and Self-Assessment Guide, developed with IMDA and PDPC, adds the middle rung that suits inbox work: a human-over-the-loop approach that allows humans to intervene when the situation calls for it, for example by using confidence levels so staff review results below a set threshold. The Model Framework is voluntary, and the guide states it is not intended for organisations deploying updated commercial off-the-shelf software packages that happen to incorporate AI in their feature set; whether that note covers the assistant on your desk is worth confirming with your employer. Read it as reasoning behind a delegation line, not a compliance test. [3]
The ICT guide's own caution still applies: it lists adversarial attacks, data breaches, undesired model outcomes, AI bias and hallucinations among the significant risks of AI adoption, and notes that the field of AI security remains nascent. [4]
What actually goes in, and in what form
Before an item is checked against the bands, decide what data is allowed in at all. PDPC's Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, issued on 1 March 2024, say organisations should practise data minimisation as good practice, using only personal data containing attributes required to train and improve the system, and should limit the volume of personal data to relevant time periods and other relevant filters. Where possible, they add, organisations are encouraged to pseudonymise or de-identify the personal data used as a basic control. The guidelines state that they are advisory in nature, not legally binding, and that the PDPA prevails in any inconsistency. [5]
A practical filter follows from that guidance rather than from any product rule: replace identifiers with a reference code before the text goes in, cut the parts of a thread you do not need for the task, and keep the raw version on your own systems. The Self-Assessment Guide frames the same question as an organisational consideration — whether the model can be trained on pseudonymised or de-identified data, and which data an AI system should have access to and which sensitive data it should not. [3] [5]
On the employer side, the ICT guide lists implementing measures to prevent employees, third parties and contractors from disclosing or leaking personal data outside the organisation, with examples including clauses on unauthorised disclosure in employment and third-party contracts. For your own desk, the version is narrower: know what the system in front of you can see, and what your workplace says may be pasted into it, before you paste anything. [4]
The two written records
The first record is a written policy that names its surfaces. PDPC's Guide to Data Protection Practices for ICT Systems, issued on 14 September 2021 and revised on 20 July 2026, lists as a basic practice having clear written policies and documented processes for the safeguards for personal data collected and processed by AI systems — and it names them explicitly: end-user prompts, inputs and generated outputs, agent or tool activity data, and internal enterprise data. The same guide says organisations should educate users on the proper use of AI systems, including the security and data risks, for example by highlighting what specific types of data or documents should be input and how data flows through the system. [4]
The second is the inventory and the training behind it. The ICT guide recommends maintaining an inventory of AI systems in use across the organisation, capturing each system's purpose, data flow information and intended users, reviewed and updated regularly, which also helps mitigate the risks of “shadow AI”. It also recommends periodic, for example annual, ICT security awareness training, with processes to monitor employees' awareness level and the training's effectiveness, and to review the content periodically. Under the Accountability Obligation, organisations must ensure their policies on using personal data to develop AI systems are updated and practices established. [5] [4]
What to ask for this week
Test your own setup against three checks. Every drafted item is read by a human before it leaves. The data that entered was minimised and you can name it. Your workplace's written policy already covers end-user prompts, inputs and generated outputs, agent or tool activity data, and internal enterprise data. If any of the three fails, the first step is a policy line rather than a faster workflow.
What to raise is narrower than a complaint and cheaper than a migration: which AI systems are in use, what each one can see, which data types staff may paste in, and who reviews an output before it is sent. If those answers exist, your bands are just a habit to write down. If they do not, the missing record — not the slow morning — is what actually needs fixing first.
Sources
- We can learn a lot from the office's AI superusers | The Straits Times
- RESPONSIBLE AI MADE EASY
- Companion to the Model AI Governance Framework
- DATA PROTECTION PRACTICES FOR ICT SYSTEMS
- ADVISORY GUIDELINES ON USE OF PERSONAL DATA IN AI RECOMMENDATION AND DECISION SYSTEMS
BUTLER Magazine Editorial · AI-assisted research and writing, reviewed by our automated editorial team. Sources checked 2026-10-10. Featured image: AI-generated editorial illustration.
