Toto-Rex . totorex.ai . Asia edition Get the newsletter
Toto-Rex, professional headshot TOTO‑REXTMAI Compliance & Governance · Asia edition Subscribe
Singapore . China (mainland) . China (Hong Kong SAR) . India . Japan . AI compliance . regulation . the foundations

Understand AI.
No technical background needed.

"I told the chatbot I'm 66 million years old. It still asked me to verify my age."

— Regional Chief-Dino, Asia

Introducing Toto-Rex

A dinosaur lost his job to an algorithm, so he set out to understand it: the rules, the regulations, and just enough of the technology to follow them. This edition follows Asia. Singapore, China, Hong Kong, India and Japan; in plain English, from credible sources. Serious about the learning. Less serious about himself.

The newsletter is coming soon.

Toto-Rex at a laptop showing the word REJECTED
How it started

The algorithm came for the job. So he decided to understand it.

No technical background. No shortcuts. Just one word, one rule, and one small victory at a time, written down so you can walk the same path without the late nights and cold coffee.

This is that path, tidied up and shared. Welcome in.

02
Latest News

Hot off the wire, worldwide

The archive Toto-Rex's Weekly Summary

AI news from verified outlets across the globe. Asia first: SG, CN, HK, IN, JP.

Toto-Rex's morning clippings . all the news that's fit to bite

The Cretaceous Courier

News of the day

China's rules for human-like AI have been in force since 15 July

The world's first dedicated rulebook for AI companions has been in force since 15 July 2026. China's Interim Measures on anthropomorphic interactive services require covered services to disclose that users are interacting with AI, watch for signs of dependency, intervene when a user signals self-harm, and apply strict safeguards for minors. Finalised in April by the CAC and four other ministries, the Measures apply to services offered to the public within mainland China that simulate human personality and communication through continuing emotional interaction. Ordinary non-emotional customer-service, knowledge-answering, work-assistant, education and research tools are expressly outside these Measures. Cross-border providers should obtain advice on the territorial facts. Separately, the AI-agent Implementation Opinions published on 8 May 2026 are a guiding policy instrument with no stated commencement date. Paragraph 11 directs regulators to use filing, testing and defective-product recall measures for regulator-defined sensitive and key-industry scenarios under applicable law; it is not a general 15 July duty for all agents.

Read it on cac.gov.cn →
CN
China publishes policy guidance for AI agents
CAC, NDRC & MIIT . July 2026

The Implementation Opinions, published on 8 May 2026, are a guiding policy instrument with no stated commencement date. Paragraph 11 directs regulators to determine open scenarios and, under applicable law, regulatory requirements and safety standards, use filing, testing and defective-product recall measures in sensitive sectors and key industries. It is not a general 15 July duty for all agents.

CN
WAIC returns to Shanghai this month
World AI Conference . July 2026

The region's biggest AI gathering brings labs, robots and ministers to the riverfront; with governance sharing the main stage again.

HK
Hong Kong's HK$1bn AI institute takes shape
Digital Policy Office . 2026

The AI Research & Development Institute funded in the 2025 Budget moves from announcement to build-out, anchoring the city's AI ambitions.

JP
Newspapers v Perplexity grinds on in Tokyo
Nikkei Asia . 2025–26

Nikkei, the Asahi and the Yomiuri press their copyright suits against the AI answer engine; the case testing Japan's famously training-friendly law.

Headlines link to their original outlets; the one-line gists are Toto-Rex's own. Curated 22 September 2026; check the source for the latest.

The shelf

Four folders, one tidy desk

Open a folder; the desk shows only what you need. Less scrolling, more finding.

The side rail and menus still reach everything; picking a link opens its folder for you.

01
The AI & Compliance Briefing

The reading that matters, in plain English

The archive Toto-Rex's Weekly Summary

Each item summarised by Toto-Rex, linked to its original source. Asia first: Singapore, China, Hong Kong, India, Japan.

Sort:

Region:
Region:
Region:

How this works: every summary is Toto-Rex's own plain-English take, and each card links out to its original source so you can read it yourself. Nothing is reproduced here. Educational only, not legal advice — for your own situation, ask a suitably qualified professional.

Sources, scope & limitations

Scope. This briefing covers AI compliance, regulation and policy for Singapore, mainland China, Hong Kong, India and Japan, plus the regional work (ASEAN, the Hiroshima Process) that binds them together. The events radar (section 05, below) covers those five jurisdictions and online events from recognised hosts. It does not try to cover the US or Europe; the UK & EU edition does that.

Sources. Credible, verifiable sources only: the regulators themselves (IMDA, the PDPC, the CAC, the PCPD, MeitY, METI and the PPC), established international and Asian law firms, recognised legal press, and peer-reviewed academic journals. Every card links to its primary source.

Depth & timeline. Summaries are short by design; what a thing is and why it matters, then off you go to the original. Current as of 27 September 2026. China's binding human-like AI Measures have applied since 15 July 2026, and the CAC's "Qinglang" AI clean-up campaign reported its second-phase results on 2 September; its separate AI-agent Opinions remain policy guidance without a commencement date; India's DPDP Rules phase in through 2027; Singapore's advisory guidelines on generative AI and personal data sit alongside the PDPA rather than replacing it.

Limitations. Toto-Rex is a dinosaur, not your lawyer. Summaries are his interpretation, they simplify, and much of this law is written in Chinese or Japanese; where an English summary and the official text differ, the official text prevails. Check the live source before you act, and take advice for your own circumstances.

02
The jurisdiction desk

Five rulebooks, one desk.

Six numbered desks; one per jurisdiction, plus the cross-border play; each expandable when you want the detail.

What this is: the working map of how each jurisdiction actually governs AI, in the order a product usually meets them; based on the official sources linked in each desk, as at 7 July 2026. Rules and dates change; the links are the truth. Educational only, not legal advice — for your own launch, brief counsel in each market.

Comparative analysis · Toto-Rex's read

How the five compare

One region, five philosophies; not five drafts of the same law. Read straight down: each line is one question, answered across all five jurisdictions.

  1. Is there a dedicated AI law? Among these five, only Japan has one; the AI Promotion Act (2025), and it carries no penalties. China governs through a binding chain of application-specific rules rather than one statute; Singapore, Hong Kong and India have each chosen, on purpose, to rely on frameworks and existing law instead of an AI Act.
  2. Hard law or soft? China is the hard case; file, label, enforce. Japan is soft by design (promotion first, no penalties). Singapore, Hong Kong and India sit in between: voluntary AI frameworks resting on a binding privacy law.
  3. File before you launch? China usually requires a security assessment and algorithm filing before a public GenAI service goes live; and it reaches services offered from abroad. The other four generally do not, though sector approvals (finance, health) still apply.
  4. What must be labelled? Synthetic content is mandatory to label in China (since September 2025) and India (2026); elsewhere it is handled through transparency duties and guidance. Export to the EU and its labelling duties have applied since 2 August 2026, with machine-readable marking of output from systems already on the market due by 2 December 2026; so build labelling once, for everyone.
  5. The privacy floor is always there: PDPA (Singapore), PIPL (China), PDPO (Hong Kong), DPDP (India), APPI (Japan). Different names, same gravity; each one reaches AI training and deployment.
  6. Copyright cuts the other way: Japan is the most training-friendly (Article 30-4); India has no US-style fair use and is litigating it (ANI v OpenAI); the rest remain unsettled.

Toto-Rex's note: build one governance programme to the strictest common denominator. China's filings, the labels China and India now demand, and Singapore's insistence on a named accountable human; then trim it down per market. Never the other way around.

Beyond these five. South Korea's AI Basic Act (Asia's first comprehensive statute, in force January 2026), Taiwan and the wider ASEAN bloc are moving too. This edition holds to the five above by design.

  1. Know the desks: MDDI sets digital strategy, IMDA writes the frameworks and tools, the PDPC enforces the PDPA, MAS covers finance, CSA covers security, MOH covers health. No single AI Act; deliberately.
  2. The binding floor is the PDPA (2012): consent plus exceptions (including business improvement), breach notification, DNC rules; and fines up to 10% of Singapore turnover. The PDPC's AI advisory guidelines (2024) and its proposed GenAI guidelines (June 2026) explain how it reaches training data, scraping included.
  3. Read the Model AI Governance Frameworks — classic (2019/2020), generative (2024), and agentic (January 2026, updated May 2026, the world's first). Voluntary, but the region's buyers and regulators treat them as the reference answer.
  4. Test with the national toolkits: AI Verify for classic systems, Project Moonshot for LLM benchmarking and red-teaming; free, open source, and doubling as governance evidence.
  5. Add the sector layer: MAS FEAT principles and Veritas (finance, with formal AI-risk guidelines in consultation), CSA's Guidelines on Securing AI Systems, MOH's healthcare AI guidelines.

Toto-Rex's note: the agentic framework launched at Davos in January 2026 with a companion paper asking the question of the decade; who is legally responsible when an AI agent acts? Singapore publishes its homework; everyone else copies it.

  1. Learn the chain: algorithm recommendation rules (2022), deep synthesis rules (2023), generative AI Interim Measures (2023), labelling Measures (September 2025); and from 15 July 2026, the binding anthropomorphic-AI Measures. The separate AI-agent Implementation Opinions were published on 8 May 2026 with no stated commencement date. Paragraph 11 directs regulators to use filing, testing and defective-product recall measures for defined sensitive and key-industry scenarios under applicable law; it is not a general 15 July duty for all agents. Each application may also engage the earlier CAC-led filing, assessment and labelling regimes.
  2. File before you launch: public-facing GenAI needs a security assessment and algorithm filing before going live; app stores check for filing numbers. The scope is extraterritorial; serving the Chinese public from abroad counts.
  3. Label everything synthetic: since September 2025, AI-generated content needs a visible label users can see and implicit metadata machines can read. The 2025–26 "Clear and Bright" campaigns removed thousands of non-compliant AI products.
  4. Mind the foundations: the PIPL (2021) for personal data and automated decisions, the Data Security Law for what may train and leave China, and the Cybersecurity Law; amended with AI provisions from 1 January 2026.
  5. Translations are your friend: the rules are law in Chinese; China Law Translate and the firm trackers keep reliable English versions.

Toto-Rex's note: a unified AI Law keeps being proposed and keeps being postponed; the spring 2026 line from state media was that conditions are "not yet ripe". The application-by-application chain is the system. Plan for it, not around it.

  1. The legal floor is the PDPO (Cap. 486): six data protection principles from 1996 that the PCPD applies to AI with modern energy; no AI statute, none currently planned.
  2. Adopt the PCPD's playbook: the AI Model Personal Data Protection Framework (June 2024) for buying, building and running AI; the employee GenAI checklist (March 2025) for the office policy. The regulator runs compliance-check rounds; "no policy" is the worst answer.
  3. In finance the bar is explicit: the FSTB policy statement (October 2024), HKMA GenAI circulars plus the Cyberport sandbox, and the SFC's November 2024 circular making senior management accountable for AI language models.
  4. Learn the Arup lesson: HK$200 million left on one deepfake video call in 2024. Out-of-band verification for payments is now standard Hong Kong hygiene; see Note no. 01 above.
  5. Watch the copyright file: the government consulted on an AI training exception in 2024 and reform is in progress; track it before you train on Hong Kong content.

Toto-Rex's note: Hong Kong regulates AI the way it regulates most things; existing law, sector regulators, and the strong suggestion that you would rather not be the example. The HK$1bn AI R&D Institute says the ambition is real.

  1. Start with the Governance Guidelines (MeitY, November 2025): seven principles, "Do No Harm", a techno-legal approach; and a clear decision not to write a standalone AI Act for now. New machinery: an AI Governance Group, expert committee and AI Safety Institute.
  2. Respect the SGI regime: the IT Amendment Rules 2026 make "synthetically generated information" a legal category; prominent labels or provenance metadata, platform traceability, and takedown of unlawful deepfakes within hours. Safe harbour depends on it.
  3. Diary the DPDP dates: the Act passed in 2023, the Rules were notified 13 November 2025, and obligations phase in through roughly 2027; consent-first, with a Data Protection Board to answer to.
  4. In finance, follow the RBI: the FREE-AI framework (2025) and the 2026 draft guidelines on AI model governance for banks and regulated entities.
  5. Copyright is live: India has no US-style fair use — ANI v OpenAI in the Delhi High Court and the DPIIT working paper will decide what training means here. Price in licensing.

Toto-Rex's note: the India–AI Impact Summit in New Delhi (February 2026) put a Global-South stamp on the agenda; adoption and impact first, with the New Delhi Declaration to show for it. India writes rules with teeth where it hurts: impersonation, elections, money.

  1. Read the AI Promotion Act (May 2025) — Japan's first AI statute, built to accelerate adoption: an AI Strategy Headquarters chaired by the Prime Minister, a national Basic Plan, duties to cooperate; and no penalties. The Cabinet AI hub carries it.
  2. Work the voluntary layer: the METI/MIC AI Guidelines for Business (v1.0 2024, updated 2025); risk-based, agile, and what Japanese counterparties will expect you to have read.
  3. The hard edges: the APPI for personal data (the PPC's AI-era review is under way; watch for amendment), the FSA's paper for finance, and the Information Distribution Platform Act (2025) for takedowns.
  4. Copyright, carefully: Article 30-4 famously permits training where enjoyment isn't the purpose; but the Cultural Affairs guidance (2024) draws limits, and the Nikkei/Asahi/Yomiuri suits against Perplexity are testing exactly where outputs cross the line.
  5. Use the safety machinery: the Japan AI Safety Institute's evaluation and red-teaming guides, and the G7 Hiroshima Process code of conduct that Japan authored.

Toto-Rex's note: Tokyo's courts have settled one thing already. DABUS lost here too. An inventor must be human (Tokyo District Court 2024, upheld 2025). The machine does the work; a person signs the form.

  1. Does this market need a filing or assessment first? China: usually yes (security assessment + algorithm filing, extraterritorial). Everywhere else: generally no; but sector approvals (health, finance) still apply.
  2. What must be labelled? Synthetic content needs labels in China (since September 2025) and India (since 2026); the EU's transparency duties follow from 2 August 2026 if you export. Build labelling into the pipeline once.
  3. What is the lawful basis for the data; in and out? PDPA, PIPL, PDPO, DPDP and APPI all reach training and deployment; China and India add data-localisation and transfer rules. Document provenance now; every regulator eventually asks for the receipts.
  4. Who is the accountable human? Hong Kong finance wants a named senior owner; Singapore's frameworks demand human accountability for agents; China wants a filed responsible person. "The model did it" is nobody's defence.
  5. Which common ground can you reuse? The ASEAN Guide on AI Governance, the G7 Hiroshima code of conduct, the OECD principles and ISO/IEC 42001; one well-built governance programme maps onto all five regimes with local trim.

Toto-Rex's note: he keeps the five questions on one card above the desk. Asked before launch they are a checklist; asked after launch they are an incident report.

How this desk is sourced

Sources. Every rule and date above links to its official source. IMDA, the PDPC, the CAC (with established English translations), the PCPD, MeitY and IndiaAI, Japan's Cabinet Office and METI; last updated 7 July 2026.

Scope. General business use of AI across Singapore, mainland China, China (Hong Kong SAR), India and Japan. Not covered: tax, employment, sector licensing, export controls, and anything bespoke to your situation.

Limitations. Toto-Rex is a dinosaur, not your lawyer; and much of this law is written in Chinese or Japanese, so summaries simplify and translations can lag. Always check the linked source, and brief counsel in each market before you act.

One more time, because it matters: everything on this desk is education, not legal advice — laws change and your facts are yours alone. Consult your lawyers before you act. Toto-Rex will still be here when you get back.

03
The application desk

What the machines are doing this week

Fresh AI uses in the wild; and the rule that walks in behind each one.

Editor's note . featured focus
Agents at large: when the software starts doing
Toto-Rex . 22 September 2026 . the focus rotates with the front page

This week's front page belongs to the machines that feel like people; and the agents that act like staff. On 15 July China's binding Measures for anthropomorphic AI interactive services take effect: covered companion services must disclose the machine behind the voice and meet safeguards for dependency, minors and crisis signals. China's separate AI-agent Implementation Opinions were published on 8 May with no stated commencement date; they direct regulator-led filing, testing and defective-product recall measures for defined sensitive and key-industry scenarios under applicable law, not a general 15 July duty for all agents. Singapore answered the agent question months earlier with a voluntary framework. Toto-Rex's working rule travels across all five jurisdictions: give an agent the least access it needs, log every step it takes, and keep a human hand on anything that moves money or people. Autonomy transfers work. It never transfers responsibility.

— T.R., from the study corner

How this note works: each morning Toto-Rex picks one focus from the front page (finance, health, agents, hiring) and writes its compliance angle in plain English. The focus rotates; the discipline doesn't. Educational only, never legal advice.

Assistants now complete multi-step tasks (browsing, form-filling, booking) through "computer use" controls. Marvellous, and also a liability surface, because an agent's click is your click. The rule that follows: Singapore's Model AI Governance Framework for Agentic AI (the world's first) says bound the risk, keep humans accountable, control the tools. China's agent Opinions direct regulators to use filing, testing and defective-product recall measures for defined sensitive and key-industry scenarios under applicable law, but do not create a general 15 July duty for all agents.

IMDA · the agentic framework

From radiology triage to national screening programmes, clinical AI is deployed and scaling across Asia's hospitals. The rule that follows: health ministries treat it as regulated medical technology. Singapore's MOH publishes dedicated AI-in-healthcare guidelines, and each jurisdiction's device regulator stands behind them.

MOH Singapore

Wuhan runs one of the world's largest driverless-taxi fleets, and more cities license services every quarter. The rule that follows: city-by-city pilot permits, safety-driver phase-outs, and liability rules that keep the operator; not the passenger; answerable.

Baidu Apollo · official site

From 15 July, covered services must disclose that users are interacting with AI, build anti-addiction safeguards, intervene on self-harm signals, and apply strict protections for minors. The Measures are limited to public services within mainland China that provide continuing emotional interaction; ordinary non-emotional assistants are expressly excluded. The rule that follows: classify the service before assuming this specialist rulebook applies, then check the other CAC regimes separately.

CAC · the Measures

Applications change weekly; the desk keeps only what is verifiably deployed, linked to its official source. Educational only; not legal advice, and never a product endorsement.

04
AI & finance

Where the money meets the machine

Markets, funding and the rules that referee them; refreshed daily.

Money story of the day
The AI capex wave breaks over Asia
TechCrunch . June 2026 . datacentres & infrastructure

Meta has signed its first AI datacentre deal in India with Reliance, planting hyperscale AI infrastructure on the subcontinent; while Johor, Batam and Japan's regional grids fill with the same concrete. The models make headlines; the buildings make balance sheets. For the region's regulators the questions follow the money: power, water, data residency, and who answers when the workloads are sovereign.

Read it on TechCrunch

Singapore's central bank wrote Asia's first AI-in-finance principles (FEAT, 2018), built the Veritas assessment methodology with the industry, and is now consulting on formal guidelines for AI model risk management across banks, insurers and capital-markets firms. If you deploy AI in Singaporean finance, this is your rulebook's front door.

MAS · official site

The FREE-AI committee's 2025 report set the framework for responsible AI in Indian finance; the RBI's 2026 draft guidelines would harden it into supervisory expectations; model inventories, validation, human oversight and board accountability for banks and regulated lenders.

RBI · official site

Hong Kong's banking regulator pairs firm expectations; senior-management accountability, consumer-protection circulars, model risk management; with a generative-AI sandbox at Cyberport where banks trial use-cases under supervisory eyes. The SFC applies the same logic to licensed firms.

HKMA · official site

Asian exporters meet the EU AI Act the moment their systems or outputs reach European users: transparency duties since 2 August 2026, high-risk obligations from 2 December 2027 after the Omnibus deferral. The lesson for a Singapore fintech or an Indian SaaS firm is the same; the market decides which law applies.

EUR-Lex · the Act

Toto-Rex's standing reminder: this desk reports the money; it does not manage yours. Nothing here is investment, legal or tax advice — markets move faster than dinosaurs, so verify at the source and consult your own advisers.

05
Situations vacant

Hot AI jobs, pinned fresh daily

Where AI meets law, policy and product; straight from the boards that matter.

Region:
No. 1Policy & governanceAI policy & governance rolesSingapore public service · IMDA, PDPC & GovTech

The state that writes Asia's most-copied AI frameworks hires the people who write them; policy, standards, testing and the agentic-AI desk.

Singapore . hybridCareers@Gov
No. 2Privacy & data protectionDPO / Privacy Counsel, AsiaEvery multinational with a regional HQ

One desk, five regimes: PDPA, PIPL, PDPO, DPDP and the APPI. The IAPP's CIPP/A and AIGP are the badges recruiters search for.

SG / HK . hybridIAPP hub
No. 3FinanceAI risk & model governanceBanks, insurers & fintechs; and MAS itself

MAS, the HKMA and the RBI are all raising the bar on AI model risk; and every institution in scope is hiring the people to meet it.

SG / HK / MumbaiMAS careers
No. 4Research & frontier labsResearch, safety & policy at the labsAnthropic, OpenAI & peers. Tokyo & Singapore

The frontier labs now hire in Asia; alignment, policy and trust & safety alongside engineering, in Tokyo and Singapore offices.

Tokyo / SingaporeAnthropic careers
No. 5India's AI economyAI compliance in the GCCs & startupsIndiaAI Mission · global capability centres

India's IT majors and thousand-plus capability centres are standing up AI governance teams as the DPDP Act and deepfake rules land.

Bengaluru / Delhi / remoteIndiaAI Mission
No. 6The regulatorsThe referees are recruiting tooPCPD · IMDA · MeitY · and peers

Compliance checks, framework drafting, sandbox supervision; the region's regulators are staffing their AI desks. Public-service pay, front-row seat.

Hong Kong & regionPCPD · official site
No. 7China deskAlgorithm filing & platform AI compliancePlatform giants & top PRC firms

Every filing regime creates a profession: security assessments, algorithm registrations, labelling audits and content compliance for China's AI products.

Beijing / Shanghai / ShenzhenHan Kun · official site

Toto-Rex re-pins this board every morning from the official sources linked; postings, salaries and closing dates change daily, so always verify on the board itself. No placement fees, no affiliations; he just likes seeing dinosaurs employed.

06
Events radar

Get in the room where AI happens

AI summits, conferences and seminars from credible hosts. Singapore, China, Hong Kong, India, Japan and online.

Featured event
SWITCH. Singapore Week of Innovation & Technology
Marina Bay Sands & venues citywide . October 2026 . passes from free community tiers

If you leave the study corner for one thing this year, make it this. SWITCH is Singapore's flagship innovation festival and the front door to the whole Asian tech scene; tens of thousands of founders, investors, researchers and regulators, government-backed and thoroughly international. AI runs through every hall, IMDA and the national AI programme use its stages for the announcements that become next year's frameworks, and it lands in the same city and season as the Singapore FinTech Festival; one trip, two summits.

Why this one, and why you can trust it: Toto-Rex took no fee, no ticket and no commission to name it; this is simply the most useful, most popular and most prestigious innovation gathering on the Asian calendar. Read on for the full radar below.

Official site & registration
Region:
Sort:

Dates, venues and prices change; check them out yourselves before you go. Anything free is marked.

07
Toto-Rex's Notes . working drafts

Toto-Rex's notes, jurisdiction by jurisdiction

Real cases, real fines, one fictional lake; and your rights at every turn.

Pick a jurisdiction. Each opens with one featured overview — Toto-Rex's plain-English summary of how that place governs AI; then at least ten notes on the real cases, fines and rules beneath it: what actually happened, what the rules say, what a company should never do, and what you can do about it. Every piece states its scope and links its sources, and none of it is legal advice.

Jurisdiction:

How to read these: the cases, fines and dates are real and each note links its sources so you can verify them yourself; please do. The lake, Nessie and Colin are entirely fictional, and clearly labelled as such. None of this is legal advice, and it does not create any professional relationship; for your own situation, consult your lawyers. Based on the sources as at 7 July 2026; the law moves quickly.

The research library behind these notes

The library. These notes are the public face of Toto-Rex's AI Compliance Library; at version 6.1.1, 187 research documents (about 115,000 words): twelve deep jurisdiction packs (UK, EU, US, Singapore, Hong Kong, mainland China, India, Japan, South Korea, Brazil, Canada, Russia), an EU-27 implementation matrix, a US 50-state & D.C. index, a wider regional atlas, and the policy and evidence templates beneath them. Research cut-off: 13 July 2026.

How it is sourced. The English research edition records 431 unique official-source URLs across 1,160 citations and 2,610 internal links. The library is not re-cut every time this page changes: anything added after the cut-off carries its own last-updated date. Automated structural and citation checks are useful quality controls, but they are not legal or linguistic certification.

What it is not. The library's own label applies here too: general information and customisable templates — not legal advice or certification. English is the controlling edition; official legal texts and their authoritative language versions prevail.

08
Foundations, study paths & credentials

Learn enough to follow the rules

Just enough of the technology to understand the compliance. No coding required.

New . The Classroom . free e-learning

Proper courses now, taught the Toto-Rex way

Fifteen guided tracks from absolute beginner to specialist; including the five-jurisdiction Asia primer. Step-by-step lessons, graded quizzes, four-depth study notes, flashcards, and a printable certificate when you pass. Every claim carries its source.

Certificates will be a paid option, launching soon.

Guided lessonsGraded quizzesStudy notes · 4 depthsFlashcardsCertificates
Enter the Classroom

Toto-Rex is not paid to feature any of these, and there are no affiliate links on this site. Listings point to each provider's official page; details, prices and dates change, so check before you enrol. Anything free is marked.

09
The AI dictionary

Featured word

One term, in plain English. No maths. No jargon.

Why it matters
The first real skill is knowing what it gets wrong.

Toto-Rex's note: always check what an AI tells you against a proper source. Especially names, numbers, and anything you would put your own name to. It is the cheapest insurance you will ever buy.

Toto-Rex . puzzles desk

The Daily Crossword

8–12 terms from the full glossary, refreshed daily. Ignore spaces and hyphens; letters only. Toto-Rex is watching. Supportively.

Across

    Down

      10
      Watch & listen

      Voices from across the AI world

      The archive Toto-Rex's Weekly Summary

      Talks, interviews and podcasts; builders, regulators, researchers and critics, in their own words.

      Clip of the day
      Inside Asia's AI race
      CNA . YouTube, verified channel . documentaries & explainers

      Singapore's CNA covers the region's AI build-out better than anyone with a camera: the model labs of Hangzhou, the datacentres of Johor and Mumbai, the regulators writing the rulebooks; documentary-grade reporting, free on its verified channel, from the newsroom closest to the story.

      Watch on CNA's channel
      Conversations worth your time . podcasts & interviews with high-stakes AI players
      The two guests every AI panel somehow ends up booking: Somebody, and Nobody.

      These are external shows Toto-Rex rates. Links go to each show's official page; specific episodes come and go, so browse for the guest you want.

      11
      The toolbox

      Popular AI tools, by what they do

      Toto-Rex wants to try them all. Forgive him; he's a dinosaur, picking it up bone by bone.

      Grouped by job. Listings link to each tool's official site; none of it is paid placement, and most have a free tier.

      12
      Regional expert dossiers · English source edition

      Five Asia jurisdictions, in depth

      Rights, duties, penalties, dated agendas, operational practice and cross-border reach.

      Five expert dossiers most relevant to this edition are available here in compact English form. The interactive globe, all fourteen jurisdictions, treaties, comparative models and industry tracker remain in the Global edition.

      Open the full Global atlas

      13
      From the study corner to the shelf

      The book is coming

      Everything this site teaches, bound, sourced and indexed.

      Maqutt Publishing · London
      AI Compliance
      in the EU and UKAn Introduction
      EW
      Toto-Rex's neighbour
      IAPP AIGP · CIPM · CIPP/E · BCS PDP
      Microsoft Azure AI Engineer (AI-102) · AWS Machine Learning
      Google Cloud Generative AI · MIT Sloan, AI & Strategy

      AI has arrived faster than the law that governs it; and that gap is where careers, companies and rights are now won or lost. The book strips away the maths, the hype and the fear: the EU AI Act, the GDPR and UK data protection in plain English, built around a practical six-factor framework you can run on any AI system; five factors that follow its life, and a sixth you hold against them all. Written for founders, lawyers, educators, regulators and the professionally curious.

      • What AI actually is, and how it works, in plain English
      • The EU AI Act, the UK regime, and rulebooks from Brussels to Beijing
      • The GDPR, cybersecurity and the copyright fight
      • How the legal profession really uses AI today
      • The six-factor framework for assessing any AI system

      "A working machine asks: who answers for me?". Like everything in the study corner, the book is education, not legal advice. It sets out the law, cases, news and studies as at September 2026, reminds you to check them against the primary sources, and then tells you what the current situation is.

      The newsletter

      AI, explained for normal people.

      A monthly-ish letter; he aims for once a month, study schedule permitting, and would rather skip an issue than send you filler. Toto-Rex writes it himself, between study sessions and waiting on deliveries. The developments that matter, what the new rules mean, and one tool worth a look. Plain English, no jargon, no commitment.

      Sign-up opens soon.

      Toto-Rex in a bowler hat raising a glass

      Cheers. See you next month. Probably.

      14
      In your pocket

      Toto-Rex, going mobile

      The real thing is still in the workshop.

      Toto-Rex is coming to phones. The waitlist opens soon.

      15
      Toto-Rex originals

      Learning, the Toto-Rex way

      Short films, songs about AI and honest tool tests; serious learning, carried lightly.

      Meet Toto-Rex . two short films
      Swipe for more →
      Songs about AI . and more to come
      Swipe for more →
      For real

      What the Toto-Rex team has studied

      • AI Governance (AIGP, IAPP)2025
      • Privacy Programme Management (CIPM, IAPP)2025
      • Data Protection (CIPP/E, IAPP)2025
      • Data Protection, Asia (CIPP/A, IAPP)2025
      • BCS Practitioner Certificate in Data Protection2025
      • Microsoft Azure AI Engineer (AI-102)2025
      • Microsoft Azure AI Fundamentals (AI-900)2025
      • Microsoft Power BI Data Analyst (PL-300)2025
      • AWS AI Practitioner (AIF-C01)2025
      • AWS Machine Learning2025
      • Google Cloud Generative AI2025
      • MIT Sloan, AI & Strategy2025

      No technical degree here, and no rush; just one exam at a time. All the new AI can feel overwhelming, and a touch of FOMO is only natural, but once you know what you're aiming for, it's far easier to find your way through. Your pace, your path.

      “Who says a T-rex can't reach their toes?” — Toto-Rex, stretching

      Toto-Rex's Corner

      The bit that will not help your career

      Everything above is the serious stuff. This is the cherry on top: useless facts, small joys, and a dinosaur with opinions.

      He told everyone the "T" in T-Rex stands for Technology. We both know it stands for Tyrannosaurus.

      Swipe for more →
      Dino of the day
      Pachycephalosaurus

      A 25 cm dome of solid bone on its head, evolved for headbutting rivals. And, Toto-Rex suspects, recruitment software.

      Late Cretaceous . "thick-headed lizard"
      Useless fact
      200 million years

      Roughly how long his lineage survived. He still cannot get a CV past an automated screening filter.

      Evolution: undefeated. Recruitment: also undefeated.
      Quote of the day
      “I'm not behind. I'm pacing myself across 200 million years.”

      A healthy attitude to a backlog, or a coping mechanism. Possibly both.

      Toto-Rex, on his learning speed
      Celebrity crush
      Nessie's granddaughter

      Of the Scottish Highlands. Also named Nessie, she runs a flourishing marketing company on the shores of Loch Ness; and is entirely out of his league, which, he notes, has never stopped anyone on a dating app.

      Takes client calls from the loch. Her grandmother is very proud.
      Love–hate relationship
      The flying reptiles of South Kensington

      Distant relations, technically. They hang about a certain museum looking down on everyone, and they haven't kept up with a single development since the Cretaceous. He visits anyway. Family is family.

      They are not even dinosaurs. He has told them this. Repeatedly.
      His dating profile
      The way to my heartA tidy spreadsheet and properly cited sources.
      Looking forSomeone who thinks resitting an exam shows commitment, not a red flag.

      16
      Before you go

      AI may take the job. It cannot take you.

      The one thing on this site that is not negotiable.

      A machine can draft, sort, total and summarise. It cannot care, keep a promise, own a mistake, or read a room. That part of the work was never in the job description. It was always you.

      So learn the tools and mind the rules. Then bring what no model can produce: taste, judgement, kindness, and the nerve to ask the obvious question.

      “Whatever the algorithm decides, you've got me, buddy.”

      Toto-Rex

      “The difference between AI and a person is that a person can feel pain. Then again, what would I know? I’m just a dino boy who eats fish.”

      Toto-Rex holding his CV in a row of identical fish-headed candidates
      Seven identical CVs. One original. Be the original.
      17
      Rex for relax

      Fancy a game?

      Step away from the syllabus. The dinosaur plays a patient game.

      The Cretaceous Chess Club · established a very long time ago

      Fancy a Game?

      Your move.
      Tap to dismiss
      18
      Say hello

      Write to Toto-Rex

      He reads more than he lets on.

      Toto-Rex in his bowler hat and coat

      He may or may not read this. He is usually studying, or waiting on a delivery. But he reads more than he lets on, and he appreciates you stopping by.

      The postbox opens soon.

      Toto-Rex can make mistakes. Everything here is general information, not legal advice: check the primary source, and take advice from a qualified professional before you act.