
How computer-issued directions could help the authorities act on scam content faster and at greater scale
Singapore is proposing to allow certain directions under the Online Criminal Harms Act to be issued by a computer program. The change is part of the Scams (Countermeasures) and Other Matters Bill, introduced in Parliament on 4 August 2026.
The aim is speed. Scam syndicates can create huge numbers of adverts, websites, profiles, and messages faster than officers can review them one by one. A computer-assisted legal process could spot high-confidence activity and issue directions at a much larger scale.
But the proposal is not simply a free pass for an unaccountable bot. The Bill names responsible officers and keeps the legal conditions for issuing a direction. The Ministry of Home Affairs also said safeguards would be put in place so the program runs accurately, fairly, and within the law.
As at 13 August 2026, the Bill was at the First Reading stage. Automated directions were a proposal and had not yet started under the new amendments.
What an OCHA direction is
The Online Criminal Harms Act, or OCHA, lets designated officers issue directions dealing with online activity connected to certain offences, scams, and malicious cyber activity.
Depending on the legal power used, a direction may require action on online content, accounts, services, or access. In practice, this may mean removing or disabling harmful material, or another step allowed by the Act.
People often call these “takedown orders”, because removing scam content is the most visible use. But OCHA contains different types of direction, so the exact duty depends on the direction issued.
What the Bill would change
The Bill would allow a Part 2 direction to be given by a computer program, when the program makes the required assessment.
The proposed assessment covers two broad situations:
- A specified offence has been, or is likely to have been, committed, and online activity is, or is likely to be, helping to carry out that offence.
- Online activity is, or is likely to be, preparing for or helping to carry out a scam or malicious cyber activity offence.
A direction produced this way would be treated as a direction given by a designated officer. This keeps its status as an official legal direction, rather than ordinary platform moderation.
Why automation is being considered
Scam content has a copy-and-repeat advantage. Once a fake advert works, operators can copy its image, wording, and landing page. They can change one character in a web address, use another hacked profile, and launch the same campaign again.
Manual review struggles with this volume. Even a well-trained team has limited hours and must look at each case. A program can compare many signals quickly and run non-stop.
Automation may be especially useful for repeated patterns, such as identical scam pages, known malicious destinations, clusters of accounts run from the same infrastructure, or adverts copying an official organisation’s identity.
Is the proposal limited to artificial intelligence?
No. The Bill uses the broader term “computer program”. A program could use fixed rules, statistical models, machine learning, artificial intelligence, or a mix of these.
That wording avoids tying the law to one technology. A simple rule that matches a known malicious web address may be very accurate and needs no advanced AI. A more complex system may combine content, account, and network signals.
What matters legally is not the marketing label on the technology. The program must work within the conditions set by law, and a responsible officer must be accountable for its authorised use.
Who would be responsible
The Bill defines a “responsible officer” in relation to the computer program. Depending on who uses the program, this may include:
- A Permanent Secretary who authorised its use by designated public officers in a Ministry or government department
- The chief executive of a public authority who authorised its use by designated officers there
- The Commissioner of Police who authorised its use by police officers, Commercial Affairs Officers, or civilian specialist officers
- Another public officer appointed by a Minister as a responsible officer
This structure answers a basic accountability question. If a machine produces the operational decision, the legal system still identifies a senior person responsible for authorising that program’s use.
What safeguards are likely to matter
The Ministry of Home Affairs said safeguards would ensure accuracy, fairness, and legal compliance. The First Reading announcement did not list every operational safeguard, so it is important not to invent details that have not been published.
Even so, several safeguards are important for any system like this:
- Clear legal and technical criteria for identifying relevant activity
- Testing before launch and after major changes
- Monitoring of false alarms and missed scams
- Secure logs showing what information led to a direction
- Controls over who can change the rules or models
- Human escalation for uncertain or high-impact cases
- A process for correcting mistakes and restoring genuine material
- Regular review by the responsible authority
These are practical expectations, not a claim that every item is already required by the Bill.
Automation does not remove the legal threshold
A computer-generated direction would still rest on an assessment described by OCHA. Automation changes how the assessment and direction are produced, not the underlying purpose of the power.
That distinction is important. A platform’s private content rules may ban material that is legal but unwanted on the service. An OCHA direction is a government action based on legal criteria. It should be traceable back to the relevant legal authority.
The Bill also says the computer-issued direction is treated as given by a designated officer. This links the automated process to the existing legal framework, rather than creating a separate category of machine command.
The risk of false alarms
Scammers copy genuine brands, government messages, and news reports. So automated systems may run into the same words and images in both harmful and lawful material.
A bank warning customers about a scam may show a screenshot of the scam advert. A journalist may reproduce part of a fake message for a report. A security researcher may visit and document a malicious site. A simple keyword system could misread these situations.
Context, source, account history, and linked destinations can help tell them apart. High-confidence matching may be fine for immediate action, while unclear cases may need human review.
The cost of missing harmful content
Missing harmful content also has a serious cost. A scam advert left online for a few hours can reach thousands of people. A fake customer-service account can move victims into private chats and ask for payment before a report is even reviewed.
This creates a hard balance. If the program is too cautious, it may not deliver the speed the proposal is meant to provide. If it is too aggressive, genuine users may be wrongly affected.
Authorities and providers will need to measure both types of error. Accuracy should not be reported only as the share of directions later upheld. It should also count how much harmful content slipped through, and how quickly mistakes were fixed.
What platforms may need to do
Providers receiving computer-issued directions will need systems that can authenticate, process, and carry them out reliably. Manual email queues may be too slow if directions arrive at much greater scale.
Platforms may need secure technical channels, automated matching of account and content identifiers, status reporting, and escalation when a direction cannot be carried out as written. They should also stop spoofed instructions from entering the workflow.
Operational teams must understand that an official direction is different from an ordinary user report. At the same time, automation should not lead to careless over-removal. Providers should keep records and do only what the direction requires.
What legitimate users may experience
Most users may not notice the new process. The visible effect could be scam adverts, profiles, or websites disappearing faster.
Some genuine users may face restrictions if their content, account, or infrastructure is wrongly matched. A merchant’s advert may resemble a copied scam ad. A hacked account may be disabled even though its owner was also a victim.
Keep evidence of ownership, advertising approvals, business registration, and original content. If content is removed or an account is restricted, use the official review channel, secure the account, and explain any hack or misleading similarity.
How automation fits with the rest of the Bill
The computer-direction proposal is one part of a wider anti-scam package. The Bill also proposes Account Disabling Orders, Disclosure Orders, Service Limitation Orders, new online-account offences, and stronger penalties for platforms that do not meet OCHA requirements.
Together, these measures target different points in the scam chain. Automated directions act on harmful online activity at speed. Account orders can interrupt communication or payment facilities. Information-sharing can reveal links across providers. New offences target the people who supply the accounts.
The strength of the system will depend on coordination. A fast direction is only useful if the right provider receives it, can identify the target, and acts before the scam moves elsewhere.
The accountability question
Automation can make government action faster, but it can also make decisions harder to understand. That is why the responsible-officer structure is significant.
Senior authorisation should be backed by practical governance. Someone must approve the purpose, data sources, rules, testing, and launch of the program. Changes should be documented. Serious errors should trigger review and correction.
Public confidence will also depend on whether affected users can tell that an official action happened, and know how to challenge a mistake. Speed is valuable, but a system that cannot fix errors quickly will create avoidable harm.
The bottom line
Singapore’s proposal would let certain OCHA directions be issued by a computer program. The change is meant to help the authorities keep up with the speed and volume of scam websites, adverts, accounts, and other online activity.
The Bill keeps a legal assessment and names senior responsible officers. The Government has also promised safeguards for accuracy, fairness, and legal compliance, though the First Reading announcement leaves many operational details to be developed or explained later.
Used carefully, automation can shorten the time that scam content stays active. Its success should be judged not only by how many directions are issued, but by how accurately harmful activity is stopped and how quickly genuine users can recover from mistakes.
Frequently Asked Questions
1. Will the source code of the direction program be made public?
The First Reading materials do not promise to publish the source code. Transparency may instead come through policies, audits, statistics, or explanations that do not reveal security-sensitive detection methods.
2. Can a wrongly affected user claim compensation?
The Bill’s public summary does not announce a general compensation scheme for automated errors. Any remedy would depend on the final law, the action taken, and the facts.
3. How quickly must a platform restore material after an error is found?
No universal restoration deadline is stated in the cited announcement. Providers and authorities should set up fast correction routes, because delay can seriously affect a genuine business or user.
4. Could automated directions be sent to overseas platforms?
The wider Bill gives some scam-related orders cross-border reach. How a particular OCHA direction applies and is enforced should be checked under the final Act and the provider’s legal position.
5. Who will be allowed to audit the program’s operation?
The First Reading materials name responsible officers but do not publish a full audit-access framework. Further rules, governance arrangements, or parliamentary explanations may add detail.





