Singapore Agentic AI Governance Framework was released by Singapore’s Infocomm Media Development Authority at the World Economic Forum in Davos on 22 January 2026. An updated version followed on 20 May 2026.
It is the first framework anywhere to address agentic AI systematically, and it currently has no equivalent in binding law in any jurisdiction. The EU AI Act does not treat agentic AI as a distinct category. Neither does any US state law, the UK framework, or China’s rules.
That gap matters more than the framework’s non-binding status. An organisation deploying autonomous agents in the EU is subject to the AI Act, but the AI Act was drafted around systems that produce outputs for human use, not systems that take actions on their own account. The Singapore framework is currently the most developed guidance available on the risks that distinction creates.
This guide covers what the framework contains, how its four dimensions work in practice, where it fills gaps that binding regulation leaves open, and how to apply it alongside EU AI Act compliance.
Singapore Agentic AI Governance Framework: Key Definitions
| Term | Definition |
|---|---|
| Agentic AI | AI systems capable of autonomous reasoning, planning, and action, able to initiate tasks and execute actions rather than only generate outputs for human use |
| IMDA | Infocomm Media Development Authority. Singapore’s infocomm and media regulator and the issuing body for the framework |
| MGF for Agentic AI | Model AI Governance Framework for Agentic AI, released 22 January 2026, updated 20 May 2026 |
| Risk bounding | Constraining an agent’s operating envelope before deployment by reference to linkages, data sensitivity, autonomy, and cascading potential |
| Cascading effect | A consequence propagating across linked systems when an agent’s action triggers downstream actions |
| Approval checkpoint | A defined point at which an agent must obtain human authorisation before proceeding |
| Privilege limitation | Granting an agent the minimum system access required for its task |
| Sandboxing | Isolating an agent’s execution environment so that its actions cannot reach systems outside a defined boundary |
| AI Verify | IMDA’s voluntary AI governance testing framework and toolkit |
Why Agentic AI Needed Its Own Framework
Generative AI produces outputs. A human reads them, evaluates them, and decides what to do. The human is the point at which the system’s output becomes consequential.
Agentic AI removes that point. An agent can initiate tasks, update databases, execute actions, and adapt dynamically. It reaches into systems, changes state, and triggers consequences without a human necessarily present at the moment of action.
The governance assumptions built into most AI frameworks do not survive that shift. Human oversight, as conceived in the EU AI Act’s Article 14, assumes a person who can understand the system’s output, interpret it correctly, and override it. That assumption holds when the output is a recommendation on a screen. It does not hold when the system has already sent the email, moved the funds, or updated the record.
IMDA identified four risk categories specific to this shift.
Unauthorised actions. An agent taking steps outside its intended scope, either through misinterpretation of its task, adversarial manipulation, or emergent behaviour not anticipated at design.
Data leakage. An agent with access to multiple systems moving information between them in ways no single access grant contemplated.
Biased decision-making at machine speed. Where a generative system produces a biased recommendation a human might catch, an agentic system executes a biased decision across thousands of cases before anyone reviews one.
Cascading effects. An agent’s action triggering downstream actions in linked systems, propagating consequences beyond the boundary anyone assessed.
Singapore Agentic AI Governance Framework: The Four Dimensions
The framework is organised around four dimensions. They are sequential in application: bound the risk, allocate the accountability, implement the controls, then communicate to users.
Dimension 1: Risk Bounding
Risk bounding means constraining the agent’s operating envelope before deployment rather than monitoring it afterwards. The framework directs organisations to evaluate four properties.
| Property | Assessment question |
|---|---|
| System linkages | What systems can the agent reach, and what can those systems reach in turn? |
| Data sensitivity | What categories of data can the agent access, and what is the consequence of exposure? |
| Degree of autonomy | What decisions can the agent make without authorisation, and what is the ceiling on their consequence? |
| Cascading potential | If the agent acts, what happens downstream, and where does the chain stop? |
The cascading potential assessment is the one organisations most often skip and the one that distinguishes agentic risk assessment from conventional AI risk assessment. A recommendation system’s failure mode is a bad recommendation. An agent’s failure mode is a bad recommendation acted upon, triggering further actions in systems the assessor may not have mapped.
The practical output of risk bounding is a defined operating envelope: the set of systems, data, and actions within which the agent may operate autonomously, and the boundary beyond which it may not.
Dimension 2: Human Accountability
The framework requires human oversight to remain central, with clear allocation of responsibilities and defined approval checkpoints.
Two elements do the work here.
Clear allocation of responsibilities. A named human accountable for the agent’s actions. Not a committee, not a function, a person. The framework treats diffuse accountability as equivalent to no accountability.
Approval checkpoints. Defined points at which the agent must stop and obtain authorisation before proceeding. The design question is where to place them, and the framework’s implicit answer is at the point where an action becomes materially consequential or irreversible.
This is where the framework is most useful and most demanding. An approval checkpoint that a human clicks through without meaningful review is not oversight, it is a signature. The Uber decision by the Dutch DPA in August 2026, fining the company €825 million for automated driver deactivations where the company maintained that human review existed, turned on precisely this distinction. The regulator did not find that no human was involved. It found that the involvement was not meaningful.
For agentic systems the problem compounds. Where the agent generates the case summary the reviewer reads, the risk assessment the reviewer weighs, and the recommendation the reviewer approves, the human is present and the oversight is theatre. Three agents agreeing is not three opinions. It is one opinion with a quorum.
The framework’s requirement for clear allocation and defined checkpoints is the counter to this, but only if the checkpoint gives the human something independent to look at.
Dimension 3: Technical Controls
The framework identifies sandboxing, safety testing, monitoring, privilege limitation, and logging.
| Control | What it addresses |
|---|---|
| Sandboxing | Isolates the execution environment so agent actions cannot reach beyond a defined boundary |
| Privilege limitation | Restricts agent access to the minimum required for the task |
| Safety testing | Tests agent behaviour against adversarial inputs and edge cases before deployment |
| Monitoring | Observes agent behaviour in operation, including deviation from expected patterns |
| Logging | Records what the agent actually did, in a form independent of the agent’s own reporting |
The logging point carries more weight than it appears to. An agent-generated summary of its own actions is not an audit trail. It is a narrative about an audit trail, produced by the entity being audited. The distinction holds until a regulator asks for the underlying system state and finds nobody kept it.
Privilege limitation is the control most often under-implemented, because agents are typically granted broad access during development for convenience and the grant is never narrowed before production.
Dimension 4: End-User Responsibility
The fourth dimension addresses communication to the people the agent interacts with or acts upon.
Users should understand what the agent can do, what it has done, and how to intervene. This is not a disclosure obligation in the transparency sense. It is an operational requirement: a user who does not know an agent has taken an action cannot correct it, and a user who does not know how to stop the agent cannot exercise the intervention right the framework assumes they have.
What Singapore Agentic AI Governance Framework Does Not Do
It is non-binding. IMDA has described it as a living document and invites feedback and case studies. No penalty attaches to departing from it.
Its practical effect operates through three channels. Enterprise procurement in Singapore increasingly references it. Sectoral regulators, particularly the Monetary Authority of Singapore for financial institutions, treat it as a reference point for reasonable AI governance. And it shapes international norms, complementing AI Verify and ASEAN governance initiatives.
Organisations deploying agentic AI in Singapore should treat the framework as the standard against which they will be measured, notwithstanding its voluntary status.
The Gap in Binding Regulation
The EU AI Act does not address agentic AI as a distinct category. This is a genuine gap rather than a deliberate omission: the Act was negotiated between 2021 and 2024, when agentic systems were not commercially significant.
The consequences are visible in several places.
Article 14 human oversight assumes a human who can understand outputs, detect anomalies, interpret results, and override decisions. Applied to an agent that acts before a human sees anything, the provision requires interpretation the text does not supply.
Article 6 classification turns on intended purpose and use case. An agent that operates across multiple functions may touch several Annex III domains simultaneously, and the framework for classifying a system with a variable operating scope is not well developed.
Article 12 logging requires automatic recording of events over the system’s lifetime. For an agent, the question of what constitutes an event, and whether the agent’s own account of its actions satisfies the requirement, is unresolved.
Article 9 risk management requires identification of risks from intended use and reasonably foreseeable misuse. Cascading effects across linked systems are not obviously either.
None of this means the AI Act does not apply to agentic systems. It applies fully. It means the operational guidance for applying it is thin, and the Singapore framework is currently the best available filler.
| Question | EU AI Act | Singapore MGF for Agentic AI |
|---|---|---|
| Agentic AI as a distinct category | Not addressed | Central subject |
| Cascading effects | Not addressed | Risk bounding dimension |
| Privilege limitation | Not addressed | Technical controls dimension |
| Approval checkpoints | Not specified | Human accountability dimension |
| Independent action logging | Article 12, not agent-specific | Technical controls dimension |
| Binding force | Yes, with penalties to €35m or 7% | No |
| Enforcement | AI Office and national authorities | None |
Applying Singapore’s Agentic AI Governance Framework Alongside EU AI Act Compliance
For organisations deploying agentic AI in both jurisdictions, the sequence is straightforward.
Build to the EU AI Act. Classification under Article 6, risk management under Article 9, data governance under Article 10, technical documentation under Annex IV, human oversight design under Article 14, and conformity assessment under Article 43 where applicable. This is the binding constraint and it is more demanding than anything Singapore requires.
Use the Singapore framework to fill the agentic gaps. Where the AI Act’s provisions do not tell you how to apply them to an autonomous agent, the four dimensions provide the operational answer. Risk bounding gives structure to the Article 9 risk assessment. Approval checkpoints give substance to Article 14 human oversight. Independent logging gives content to Article 12.
Map the outputs into both vocabularies. Singapore stakeholders expect MGF language. EU regulators expect Annex IV structure. The underlying facts are the same. Maintaining them once and rendering them into two formats is considerably cheaper than running two assessments.
| Singapore dimension | Maps to EU AI Act |
|---|---|
| Risk bounding | Article 9 risk management system, Article 6 classification scope |
| Human accountability | Article 14 human oversight design, Article 26 deployer oversight obligations |
| Technical controls | Article 15 accuracy, robustness, cybersecurity; Article 12 logging |
| End-user responsibility | Article 50 transparency; Article 26(8) individual notification |
Singapore Agentic AI Governance Framework: A Practical Checklist
| Step | Action |
|---|---|
| 1 | Inventory every agentic system in deployment or development, distinguishing agents from generative systems by whether they take actions |
| 2 | For each agent, map system linkages: what it can reach, and what those systems can reach in turn |
| 3 | Classify data sensitivity across everything the agent can access |
| 4 | Define the degree of autonomy: what the agent may decide without authorisation |
| 5 | Trace cascading potential: what happens downstream when the agent acts, and where the chain terminates |
| 6 | Define the operating envelope and constrain the agent to it |
| 7 | Name an accountable individual for each agent |
| 8 | Place approval checkpoints at consequential and irreversible actions |
| 9 | Verify that each checkpoint gives the human something independent to evaluate, not an agent-generated summary |
| 10 | Narrow privileges to the minimum required for the task |
| 11 | Implement sandboxing where the agent’s action boundary can be technically enforced |
| 12 | Log agent actions independently of the agent’s own reporting |
| 13 | Conduct adversarial safety testing before deployment |
| 14 | Communicate agent capabilities, actions taken, and intervention routes to affected users |
| 15 | Reconcile the resulting documentation with EU AI Act Annex IV and Article 9 requirements |
FAQ
What is Singapore’s Agentic AI Governance Framework?
The Model AI Governance Framework for Agentic AI, released by IMDA at the World Economic Forum on 22 January 2026 and updated on 20 May 2026. It is the first framework anywhere to address agentic AI systematically, organised around risk bounding, human accountability, technical controls, and end-user responsibility.
Is the framework legally binding?
No. It is a voluntary framework issued by IMDA and described as a living document. No penalty attaches to departing from it. Its practical force comes from enterprise procurement expectations, sectoral regulator reference, and its influence on international norms.
What is agentic AI?
AI systems capable of autonomous reasoning, planning, and action. Unlike generative systems that produce outputs for human use, agentic systems initiate tasks, update databases, execute actions, and adapt dynamically without a human necessarily present at the moment of action.
What are the four dimensions?
Risk bounding, which constrains the agent’s operating envelope by reference to system linkages, data sensitivity, autonomy, and cascading effects.
Human accountability, which requires clear allocation of responsibility and defined approval checkpoints.
Technical controls, covering sandboxing, privilege limitation, safety testing, monitoring, and logging.
End-user responsibility, covering communication of what the agent can do, has done, and how to intervene.
Does the EU AI Act cover agentic AI?
The AI Act applies to agentic AI systems in full, but it does not address agentic AI as a distinct category. It was negotiated before agentic systems became commercially significant. Provisions including Article 14 human oversight and Article 12 logging require interpretation when applied to systems that act rather than recommend, and the operational guidance for that interpretation is thin.
Why does the framework matter outside Singapore?
Because no binding regulation anywhere addresses agentic AI as a distinct category, and the Singapore framework is currently the most developed guidance available on the specific risks agentic systems create. Organisations deploying agents in the EU face AI Act obligations without AI Act guidance on how to meet them for this class of system.
What is a cascading effect?
A consequence that propagates across linked systems when an agent’s action triggers downstream actions. It distinguishes agentic risk from conventional AI risk: a recommendation system’s failure produces a bad recommendation, whereas an agent’s failure produces a bad action that may trigger further actions in systems the risk assessment did not map.
Is an agent-generated log sufficient for audit purposes?
No. An agent’s account of its own actions is a narrative produced by the entity being audited. The framework’s technical controls dimension calls for logging that records what the agent actually did, independent of the agent’s own reporting. The same logic applies to approval checkpoints: a human reviewing an agent-generated summary is reviewing the agent’s account, not the underlying facts.
How should we apply this alongside EU AI Act compliance?
Build to the EU AI Act, which is the binding constraint and more demanding overall. Use the Singapore framework to fill the operational gaps where the AI Act does not tell you how to apply its provisions to autonomous agents. Maintain the underlying documentation once and render it into both the MGF and Annex IV vocabularies.
Does Singapore have an AI Act?
No. Singapore has not enacted cross-sectoral AI legislation and has said it does not intend to in the near term. AI governance operates through voluntary IMDA frameworks, sectoral guidance, and existing statutes including the Personal Data Protection Act.
Will other jurisdictions adopt similar frameworks?
The framework has been positioned as contributing to regional and international convergence, complementing AI Verify and ASEAN governance initiatives. Whether it is adopted formally elsewhere is unresolved, but its four dimensions have already begun appearing in practitioner guidance internationally, which is how soft law instruments typically travel.
Disclaimer
This guide reflects the Model AI Governance Framework for Agentic AI released by IMDA on 22 January 2026 and updated on 20 May 2026. The framework is voluntary and IMDA describes it as a living document subject to revision. This guide is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations deploying agentic AI should obtain advice specific to their systems, sectors, and the jurisdictions in which they operate.