Singapore Just Told Its Lawyers Exactly How to Use AI. Indian Legal Firms Are Still Guessing.
Key Takeaways:
- Singapore's Ministry of Law published a comprehensive Guide for Using Generative AI in the Legal Sector on March 6, 2026
- The guide covers three core obligations for legal professionals using AI: professional ethics, confidentiality, and transparency with clients
- It introduces a risk-based oversight framework, distinguishing between "human-in-the-loop" tasks that require active lawyer review before finalizing AI output and "human-on-the-loop" tasks that can run with supervisory monitoring
- Major Singapore firms including Rajah and Tann, WongPartnership, and Allen and Gledhill are cited as real-world examples of responsible AI adoption
- India has no equivalent sector-specific guidance yet, but the DPDP Act 2023 already creates obligations that every Indian law firm using AI tools must satisfy
- Indian advocates and in-house counsel can use Singapore's framework as a practical compliance reference right now
Most Indian law firms using AI are doing one of two things.
They are using free ChatGPT accounts to summarize documents and drafting client emails, with no policy, no data classification, no client disclosure, and no idea whether their confidential case details are sitting in a training dataset somewhere in California.
Or they have banned AI entirely, watched younger lawyers sneak it in anyway, and called it a policy.
Singapore's Ministry of Law just showed both groups what a grown-up answer looks like.
On March 6, 2026, MinLaw published a 50-page Guide for Using Generative AI in the Legal Sector, co-developed with major Singapore law firms, Google, Microsoft, the Infocomm Media Development Authority, the Cyber Security Agency, and the Singapore Courts. It is non-binding. It is also the most detailed, practically useful document any government has yet produced on exactly how legal professionals should and should not use generative AI in real client matters.
Here is what it says, why it matters, and what Indian legal professionals should be doing differently by Monday morning.
The Three Obligations the Guide Places on Every Legal Professional
The guide builds its framework around three core principles. None of them are optional for Indian lawyers either, regardless of whether India has equivalent published guidance yet.
Professional Ethics
The guide is direct about one thing that many advocates find uncomfortable to hear: using AI does not reduce your professional responsibility. It does not delegate it. It does not dilute it.
Under Singapore's Legal Profession Act, lawyers remain fully responsible for every work product, regardless of how much AI contributed to it. The guide states plainly that hallucination, the tendency of large language models to produce confident-sounding incorrect information, cannot be completely eliminated. It can be reduced through techniques like retrieval-augmented generation and careful prompting. But it cannot be switched off.
For Indian advocates, the parallel obligation sits in the Bar Council of India Rules, which require competence and diligence in all professional work. An advocate who submits an AI-generated research memo to a High Court without verifying the citations has not outsourced their professional responsibility. They have breached it, while using a tool they may not have disclosed at all.
Confidentiality
This is where most Indian law firms are currently exposed without knowing it.
The guide walks through a spectrum of risk. Free-to-use AI tools like the public version of ChatGPT may use your input data for model training. Enterprise versions with explicit contractual prohibitions on model training use are a different category. Proprietary systems built on private infrastructure are different again.
The question every Indian law firm should answer today: which category is the tool your staff is actually using for client matters? Not the tool your firm officially approved. The one being used.
Singapore's guide lists specific safeguards that law firms have implemented. WongPartnership requires contractual commitments from all AI vendors that prohibit use of input and output data for model training, and reinforces this with data minimization protocols requiring staff to strip or anonymize client identifiers before inputting anything into AI tools. Rajah and Tann limits AI access to enterprise versions of Microsoft Copilot and Harvey AI only, after securing explicit vendor commitments on data use.
For Indian firms, the DPDP Act 2023 already treats client personal data handled by a law firm as data that requires a lawful basis for processing and contractual safeguards when transferred to processors, including AI vendors. If your firm has not reviewed the terms of service of your AI tools against DPDP obligations, that review is overdue.
Transparency with Clients
The guide recommends disclosing AI use to clients in three specific situations: when AI is used substantially in producing work the client will rely on, when AI affects the cost of legal services, and when the AI tool's data handling could conflict with the client's own data residency requirements.
This last point is underappreciated in India. Major corporate clients, especially those in regulated sectors like banking, insurance, and healthcare, often have internal data governance policies that prohibit their confidential information from being processed on US or EU cloud infrastructure. A law firm that uploads a client's transaction documents to a US-based AI tool, without checking the client's data residency requirements, is not just violating the client's policy. It may also be breaching the confidentiality terms of the engagement.
The Risk Framework Indian Legal Teams Can Use Tomorrow
The most practically useful section of the Singapore guide is the risk-based oversight framework in Diagram 2.
The framework works on two axes: whether the output is for internal or external use, and whether the task carries legal, reputational, or financial consequences.
Tasks in the high-risk category, including court submissions, regulatory filings, commercial contracts, and legal advice, require what the guide calls "human-in-the-loop" oversight. This means a qualified lawyer reviews and approves every AI output before it is finalized or acted upon. The AI assists. The lawyer makes every final call.
Tasks in the medium-risk category, including routine client updates, document reviews, and customer queries, can operate with "human-on-the-loop" oversight. The AI runs more autonomously, with supervisory monitoring and structured sampling of outputs rather than line-by-line review.
Low-risk tasks, including administrative work, meeting notes, scheduling, and document formatting, sit at the other end. The AI operates independently, with the understanding that outputs are easily reversible if errors appear.
The guide adds one diagnostic question that cuts through all the framework complexity: can you explain how the AI output was verified, if asked? If the answer is no, the level of oversight is insufficient for the task, regardless of which risk category it falls into.
Indian law firms can implement this framework today without waiting for Indian-specific guidance. The three-tier structure maps directly onto the kind of work most advocates and in-house teams handle daily. The question is not whether to build a policy. It is whether to build it before a problem forces the issue.
What Indian Law Firms Are Missing That Singapore Firms Already Have
The Singapore guide includes real examples from named firms, which makes it considerably more useful than most regulatory publications.
Allen and Gledhill built an in-house large language model in partnership with Singapore AI startup Pand.ai, consolidated over 100 use cases across practice areas, and deployed the system specifically for the use cases with the greatest impact and likelihood of success. They did not deploy general-purpose AI and hope for the best.
Google's own legal department described building a custom AI Negotiations Assistant using Vertex AI, grounded on a curated dataset of agreement documents and negotiation guidance, to generate draft clauses and internal advice notes with citations to source documents. The citations are the key detail. Every output is traceable to a source document. Hallucination risk is managed structurally, not just by asking lawyers to check carefully.
Clifford Chance operates a three-tier adoption structure: general productivity tools at the base, specialized legal AI tools like contract review platforms at the middle tier, and custom-built solutions for complex firm-specific workflows at the top. They also maintain an Innovation Board that monitors AI usage firm-wide.
None of these are small firms operating with small budgets and minimal IT infrastructure. But the governance principles they apply, data classification, vendor due diligence, human oversight mapped to task risk, client disclosure, and incident response protocols, are available to any law firm of any size. The infrastructure cost scales down. The obligation does not.
The India Dimension: DPDP Act 2023 and AI Tools in Legal Practice
India does not yet have a MinLaw equivalent guide for the legal sector. The Data Protection Board has not been constituted. The DPDP rules remain pending notification. None of that means Indian law firms are operating in a compliance-free environment.
The DPDP Act 2023 applies to any organization, including a law firm, that processes personal data of individuals in India. Client data is personal data. Case files containing personal information about parties to litigation are personal data. Documents uploaded to AI tools for review are personal data if they contain information about identifiable individuals.
Section 8 of the DPDP Act requires Data Fiduciaries to implement reasonable security safeguards. Section 9 applies obligations around processing children's data. Section 16 gives individuals rights around their data. And Section 8(2) requires that personal data be processed only for the purpose for which consent was obtained or a legitimate purpose exists.
Uploading a client's matter documents to a US-based AI tool that uses inputs for model training is not the same purpose as providing legal advice to that client. A law firm that does this without explicit client consent, or without a vendor agreement that prohibits training use, has a DPDP exposure they have probably not measured.
The Singapore guide's vendor checklist in Annex E provides a direct template Indian firms can adapt. Questions about whether data inputs are used for model training, whether client data can be deleted at conclusion of engagement, and whether the vendor holds recognized security certifications are not Singapore-specific. They are the right questions to ask any AI vendor whose tool touches client data, in any jurisdiction.
Frequently Asked Questions
Q: Is the Singapore Ministry of Law GenAI guide legally binding on Indian advocates?
A: No. The guide is non-binding even in Singapore, where it was published as a reference document. For Indian advocates, it has no legal force whatsoever. Its value is as a practical framework. It consolidates input from major law firms, regulators, and technology providers into one document, which Indian firms can adapt to their own practice and compliance obligations.
Q: Which Indian law would apply if a law firm's AI tool causes a client data breach?
A: Multiple laws could apply depending on the specifics. The DPDP Act 2023 applies if personal data is involved. The Information Technology Act 2000 and its Information Technology (Reasonable Security Practices and Procedures) Rules 2011 also impose obligations on entities handling sensitive personal data. Bar Council rules on professional conduct would apply to any breach of client confidentiality. And the terms of the engagement letter may create independent contractual liability.
Q: What is "human-in-the-loop" AI oversight and when does an Indian advocate need it?
A: Human-in-the-loop means a qualified human reviews and approves every AI output before it is finalized or acted upon. It applies whenever the task involves legal consequences, reputational risk, or output that will be submitted to a court, regulator, or client as part of formal legal work. For Indian advocates, this means any court filing, legal opinion, contract, or regulatory submission where AI was used in drafting or research requires active lawyer review before it goes out.
Q: How should an Indian law firm disclose AI use to clients?
A: The Singapore guide recommends disclosure in the engagement letter, on the firm's website, and in direct client communication where relevant. A simple clause in the letter of engagement stating that the firm may use AI tools in delivering services, specifying the safeguards in place and the client's right to opt out, is a reasonable starting point. Clients in regulated sectors with data residency requirements should receive more specific disclosure about where their data is processed.
Q: Does the DPDP Act 2023 apply to a law firm using an AI tool whose servers are outside India?
A: The DPDP Act applies to the processing of personal data of Indian individuals, regardless of where the processing takes place. A law firm that uploads Indian client data to a US-based AI platform is processing that data and is subject to the DPDP Act's obligations. The cross-border transfer provisions of the Act will apply once the government notifies the applicable rules. In the meantime, the Act's general obligation to implement reasonable security safeguards still applies.
Q: What should an Indian law firm do first if it has no AI governance policy today?
A: Three immediate steps. First, audit which AI tools are actually being used by your staff for client work, not which tools you officially approved, what is actually running. Second, check the terms of service of each tool to determine whether input data is used for model training and whether client data can be deleted. Third, issue an internal usage protocol that classifies client matter data as confidential, restricts it to approved enterprise tools only, and requires anonymization of client identifiers when using any tool that cannot provide training-use opt-out guarantees.
Indian law firms adopting AI tools face a compliance landscape that includes the DPDP Act 2023, IT Act obligations, Bar Council professional conduct rules, and evolving client data governance requirements. The LLM Advocates team provides advisory services on AI governance, data privacy compliance, and cyber law for law firms and in-house legal teams across India. Contact us at contact@llmadvocates.com or call +91-8572022292.