Singapore's Online Safety Commission (OSC), which began operations on June 29, 2026 under the Online Safety (Relief and Accountability) Act 2025 (OSRAA), received more than 500 reports of online harm in its first two months, resolving over 90% of eligible cases, according to figures the commission released covering June 29 to August 31, 2026. Doxxing accounted for 44% of reports and online harassment 38%, with intimate image abuse (8%), online stalking (7%), and image-based child abuse (3%) making up the rest. Victims ranged from age 7 to 68, and those 18 and under were involved in 17% of eligible reports.
A narrowly scoped mechanism, not a speech code
OSRAA was passed in Parliament on November 5, 2025, and jointly stood up by the Ministry of Digital Development and Information and the Ministry of Law, with the Infocomm Media Development Authority (IMDA) providing administrative support. Commissioner Francis Ng, appointed June 1, 2026, can issue directions to three distinct parties: communicators (Stop Communication and Restraining Directions), administrators of groups or pages (which add Labelling and Account Restriction Directions), and platforms themselves (Access Disabling and Account Restriction Directions). Non-compliance is a criminal offense, and OSRAA also created a statutory tort with minimum damages of $5,000 per image or recording for image-based harms.
The design deserves credit on its own terms. Rather than legislating broad categories of "harmful content" that platforms must police at scale — the approach the EU has taken with its recently unveiled Kids Act, which EFF has criticized for pushing intrusive age verification onto all users to address risks to a subset of them — OSRAA's first phase targets five well-defined harms: doxxing, harassment, stalking, intimate image abuse, and child sexual abuse material. Each requires an individual, victim-initiated report and produces a fact-specific direction, not a standing content filter. That is a meaningfully different regulatory posture than an ex ante mandate, and it is the strongest case for this model: victims of doxxing or non-consensual intimate imagery genuinely have had no fast civil remedy in most jurisdictions, and a specialized commission that can order an Access Disabling Direction in days, rather than pursuing a defamation suit that takes years, closes a real gap.
The AI-imagery case is the hard test
The commission's first Access Disabling Direction, per Singaporean reporting, involved a victim subjected to online sexual harassment since 2022, escalating to AI-generated deepfake imagery and video distributed across more than 1,000 posts; the direction succeeded in getting that content removed across multiple platforms. This is precisely the scenario where a rapid, non-judicial takedown mechanism outperforms both criminal prosecution (slow, requires proving intent) and platform self-policing (inconsistent, especially for content mirrored across many small forums). Given that generative AI has made synthetic intimate imagery cheap to produce and hard to fully contain once distributed, a mechanism built to chase content across platforms — rather than relying on any single platform's terms of service — is a genuine capability gap that OSRAA fills.
But the same speed and breadth that make the mechanism effective against genuine abuse are also what should make observers watch it carefully as it scales. A commission empowered to order takedowns based on its own factual findings, with no court in the loop before the direction issues, is efficient precisely because it skips the due-process steps that protect against error and overreach. Two months and 500 cases is too small a sample to assess false-positive rates, appeal outcomes, or whether the six-member appeal panel (appointed for three-year terms) has yet had to reverse a wrongly issued direction. Singapore's track record on speech regulation — including IMDA's broader content-classification powers and its history of directions against publishers under separate statutes — is not one of restraint, which is the specific reason this narrower, victim-report-triggered model matters: it is a materially better design than a broad discretionary content-removal power, but it is still a power that a government agency exercises without pre-clearance from a court.
What comes next matters more than the launch numbers
OSRAA's first phase covers five of thirteen planned harm categories, with the remaining eight — which Singapore has signaled will include broader categories of harmful content — to be phased in progressively. The pattern to watch is whether later phases retain the same tight scoping (specific, identifiable harm to a specific victim, triggered by that victim's report) or drift toward the kind of broad, platform-facing content mandates that invite politically sensitive judgment calls about what counts as "harmful." The doxxing and harassment numbers so far suggest real demand for a fast redress channel that courts and platform trust-and-safety teams were not meeting. The right response from other jurisdictions, including the EU as it finalizes its Kids Act, is to copy the narrow, victim-initiated design — not to treat this as license for the more sweeping, all-user content-gating approaches currently being debated elsewhere.