Singapore Is About to Put Data Centres and Big Cloud Providers on a Licence — But the Toughest Rules Haven’t Been Written Yet

Singapore Is About to Put Data Centres and Big Cloud Providers on a Licence — But the Toughest Rules Haven’t Been Written Yet

SINGAPORE, Sept. 8, 2026 — Singapore is preparing to tighten its grip on the physical infrastructure powering everything from artificial intelligence and digital banking to e-commerce and government services, with a new Bill that could place most of the city-state’s major data centres under a formal licensing regime.

The Digital Infrastructure Bill, introduced for First Reading in Parliament on Tuesday, would establish two regulatory tracks administered by the Infocomm Media Development Authority (IMDA): one targeting the security and operational resilience of major data centres and cloud providers, and another focused on the environmental sustainability of data-centre operations.

The move is significant because Singapore is no longer treating data-centre uptime, disaster recovery and energy efficiency simply as matters between technology companies and their customers.

They are increasingly being treated as issues with economy-wide consequences.

The 3MW Threshold: A Much Wider Net

Under the Bill, operators of Singapore data centres with a critical IT load of at least 3 megawatts would need a data-centre licence.

The licence would initially require operators to meet facility-level energy-efficiency standards, including requirements based on Power Usage Effectiveness, or PUE, one of the industry's principal measures of how efficiently a facility uses electricity.

The rules would apply to both existing and new data centres. Future requirements could also address water efficiency and the efficiency of IT equipment, although regulators have said mandatory IT-equipment efficiency standards will not be imposed at the outset.

That 3MW threshold potentially gives the legislation considerable reach.

Singapore has around 70 data centres, and MDDI estimates roughly two-thirds could fall within the two proposed licensing regimes. The Business Times reported that the country now has more than 1.6 gigawatts of data-centre capacity.

Then Comes the Heavier 10MW Regime

A second, more demanding licence would apply to infrastructure considered important enough that a major disruption could significantly affect Singapore's economy or society.

It would cover major co-location and cloud data centres with at least 10MW of critical IT load that provide services to unrelated third parties.

Major cloud providers would also fall within the regime when their Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) operations generate at least S$100 million in average annual revenue from Singapore users over the previous three years.

Software-as-a-Service providers are not captured simply because they exceed that revenue level; the threshold specifically targets IaaS and PaaS services under the proposed framework.

For businesses above those thresholds, the obligations go considerably beyond electricity consumption.

Licensees would have to implement security and risk-management measures, maintain business-continuity and disaster-recovery plans and report specified cybersecurity incidents and service disruptions to IMDA.

This Isn't Only About Hackers

Cybersecurity may attract the headlines, but Singapore's proposal is deliberately broader.

The country already expanded its Cybersecurity Act framework to cover foundational digital infrastructure such as cloud computing and data-centre facility services. The new legislation is intended to complement that regime by addressing operational failures that are not necessarily cyberattacks.

Those risks include power failures, cooling problems, fires, technical breakdowns and other physical or operational incidents capable of taking important online services offline.

That distinction matters.

A cloud platform does not need to be hacked to disrupt thousands of businesses. A cooling failure, electrical fault or badly handled recovery process can potentially produce the same result for customers who depend on the infrastructure.

Singapore is effectively arguing that once digital infrastructure becomes deeply embedded in payments, healthcare, communications, transport and business operations, its reliability becomes a broader economic concern rather than purely a commercial service-level issue.

The Other Battle Is Electricity

Security, however, is only half the story.

Singapore's position as a major Asian data-centre hub has created a difficult policy problem: computing demand is rising rapidly, particularly as artificial intelligence workloads expand, while the country has limited land, electricity and water.

IMDA's Green Data Centre Roadmap, launched in 2024, targeted at least 300MW of additional data-centre capacity in the near term, with potentially more capacity unlocked through green-energy deployment.

But expansion comes at an enormous resource cost.

IMDA previously estimated that data centres accounted for about 7 per cent of Singapore's electricity consumption, with that share potentially reaching 12 per cent by 2030.

That helps explain why the government is moving away from relying entirely on voluntary efficiency improvements.

Under the new framework, baseline energy efficiency would become something regulators can require rather than merely encourage.

Industry Didn't Reject the Bill — But It Asked for Breathing Room

The legislation was not drafted in isolation.

MDDI and IMDA held a public consultation from July 1 to July 22 and received submissions from 25 respondents, including data-centre operators, cloud providers, consultants and industry associations.

According to the government's consultation response, respondents broadly supported the Bill's objectives but raised practical concerns about licensing, reporting, compliance with overlapping regulations and how older facilities would meet new environmental requirements.

One particularly important issue involved the proposed six-month transitional period.

Some companies worried six months would not be enough to determine whether they needed a licence, prepare an application and make the contractual or operational changes necessary for compliance.

The government clarified that the six-month window is primarily a period for submitting the licence application. An operator that applies during that period would be allowed to continue operating while its application is being processed until the licence is granted, rejected or withdrawn.

Existing data centres will also be given additional transition time to meet energy-efficiency requirements, although regulators have not yet announced exactly how long that adjustment period will be.

Regulators Are Also Trying to Avoid Duplicate Compliance

Another concern for large operators is the possibility of complying with several overlapping frameworks.

MDDI and IMDA said they intend to streamline licensing and reporting processes, recognise existing industry standards and certifications where possible, and align requirements under the Digital Infrastructure framework with Singapore's existing Cybersecurity Act.

The regulators are even exploring measures such as consolidated application documentation for facilities and services covered by multiple requirements.

That could become an important test of the legislation.

Singapore wants tougher oversight without making its data-centre market unnecessarily cumbersome for the multinational operators whose investment it is simultaneously trying to attract.

The Toughest Numbers Still Haven't Been Set

For operators, there is another reason to keep watching the legislation closely.

While Parliament is now considering the statutory framework, many of the detailed technical requirements will come later through regulations and Codes of Practice.

That includes the specific PUE standards facilities must achieve, detailed incident-reporting thresholds, implementation timelines and potentially future water-efficiency or IT-equipment requirements. Regulators have promised further industry consultation before finalising several of those measures.

In other words, September's Bill establishes who can be regulated and broadly what Singapore expects from them.

The numbers determining exactly how difficult — and expensive — compliance becomes may arrive later.

Why This Matters for Singapore's AI Ambitions

That makes the Digital Infrastructure Bill much bigger than a data-centre regulation story.

Artificial intelligence requires enormous amounts of computing capacity. More computing capacity requires servers. Servers require data centres. And data centres require electricity, cooling, water, land and infrastructure capable of operating with extremely high reliability.

Singapore wants to remain a major regional digital hub without allowing the physical infrastructure behind that ambition to overwhelm its limited resources.

The government itself says the Bill is intended to strengthen the foundation on which Singapore's digital economy and AI ambitions will be built.

The strategic calculation is clear: Singapore is still inviting digital infrastructure investment — but increasingly on Singapore's terms.

And for data-centre and cloud operators, the biggest question may no longer be whether regulation is coming.

It is how demanding the rules become once IMDA finally fills in the details.

WWC ONE MEDIA M.J.E