What Bee Cheng Hiang’s AI Slip Teaches About Preventing Data Leaks

The Personal Data Protection Commission (PDPC) said the breach was caused by a human error in the prompt, not by a malfunction of the AI tool itself. The employee did not tell the AI to conceal the other recipients and did not check the actual test email, only the activity logs.
Bee Cheng Hiang acted quickly. It stopped the bulk‑email process, fixed the script, and announced a new rule that at least two staff members must verify every bulk email before it is sent.
PDPC accepted a voluntary undertaking from the company to improve its compliance with Singapore’s Personal Data Protection Act. The regulator also reminded organisations that before using AI, they should carry out data‑protection impact assessments, set clear policies, and put testing and review mechanisms in place.
The incident shows that a simple prompt mistake can expose personal data on a large scale. Companies using AI should ensure thorough testing of generated code and require dual‑staff checks to safeguard customer information.