Singapore Agentic AI Governance Framework was released by Singapore’s Infocomm Media Development Authority at the World Economic Forum in Davos on 22 January 2026. An updated version followed on 20 May 2026.

It is the first framework anywhere to address agentic AI systematically, and it currently has no equivalent in binding law in any jurisdiction. The EU AI Act does not treat agentic AI as a distinct category. Neither does any US state law, the UK framework, or China’s rules.

That gap matters more than the framework’s non-binding status. An organisation deploying autonomous agents in the EU is subject to the AI Act, but the AI Act was drafted around systems that produce outputs for human use, not systems that take actions on their own account. The Singapore framework is currently the most developed guidance available on the risks that distinction creates.

This guide covers what the framework contains, how its four dimensions work in practice, where it fills gaps that binding regulation leaves open, and how to apply it alongside EU AI Act compliance.

Singapore Agentic AI Governance Framework: Key Definitions

TermDefinition
Agentic AIAI systems capable of autonomous reasoning, planning, and action, able to initiate tasks and execute actions rather than only generate outputs for human use
IMDAInfocomm Media Development Authority. Singapore’s infocomm and media regulator and the issuing body for the framework
MGF for Agentic AIModel AI Governance Framework for Agentic AI, released 22 January 2026, updated 20 May 2026
Risk boundingConstraining an agent’s operating envelope before deployment by reference to linkages, data sensitivity, autonomy, and cascading potential
Cascading effectA consequence propagating across linked systems when an agent’s action triggers downstream actions
Approval checkpointA defined point at which an agent must obtain human authorisation before proceeding
Privilege limitationGranting an agent the minimum system access required for its task
SandboxingIsolating an agent’s execution environment so that its actions cannot reach systems outside a defined boundary
AI VerifyIMDA’s voluntary AI governance testing framework and toolkit

Why Agentic AI Needed Its Own Framework

Generative AI produces outputs. A human reads them, evaluates them, and decides what to do. The human is the point at which the system’s output becomes consequential.

Agentic AI removes that point. An agent can initiate tasks, update databases, execute actions, and adapt dynamically. It reaches into systems, changes state, and triggers consequences without a human necessarily present at the moment of action.

The governance assumptions built into most AI frameworks do not survive that shift. Human oversight, as conceived in the EU AI Act’s Article 14, assumes a person who can understand the system’s output, interpret it correctly, and override it. That assumption holds when the output is a recommendation on a screen. It does not hold when the system has already sent the email, moved the funds, or updated the record.

IMDA identified four risk categories specific to this shift.

Unauthorised actions. An agent taking steps outside its intended scope, either through misinterpretation of its task, adversarial manipulation, or emergent behaviour not anticipated at design.

Data leakage. An agent with access to multiple systems moving information between them in ways no single access grant contemplated.

Biased decision-making at machine speed. Where a generative system produces a biased recommendation a human might catch, an agentic system executes a biased decision across thousands of cases before anyone reviews one.

Cascading effects. An agent’s action triggering downstream actions in linked systems, propagating consequences beyond the boundary anyone assessed.

Singapore Agentic AI Governance Framework: The Four Dimensions

The framework is organised around four dimensions. They are sequential in application: bound the risk, allocate the accountability, implement the controls, then communicate to users.

Dimension 1: Risk Bounding

Risk bounding means constraining the agent’s operating envelope before deployment rather than monitoring it afterwards. The framework directs organisations to evaluate four properties.

PropertyAssessment question
System linkagesWhat systems can the agent reach, and what can those systems reach in turn?
Data sensitivityWhat categories of data can the agent access, and what is the consequence of exposure?
Degree of autonomyWhat decisions can the agent make without authorisation, and what is the ceiling on their consequence?
Cascading potentialIf the agent acts, what happens downstream, and where does the chain stop?

The cascading potential assessment is the one organisations most often skip and the one that distinguishes agentic risk assessment from conventional AI risk assessment. A recommendation system’s failure mode is a bad recommendation. An agent’s failure mode is a bad recommendation acted upon, triggering further actions in systems the assessor may not have mapped.

The practical output of risk bounding is a defined operating envelope: the set of systems, data, and actions within which the agent may operate autonomously, and the boundary beyond which it may not.

Dimension 2: Human Accountability

The framework requires human oversight to remain central, with clear allocation of responsibilities and defined approval checkpoints.

Two elements do the work here.

Clear allocation of responsibilities. A named human accountable for the agent’s actions. Not a committee, not a function, a person. The framework treats diffuse accountability as equivalent to no accountability.

Approval checkpoints. Defined points at which the agent must stop and obtain authorisation before proceeding. The design question is where to place them, and the framework’s implicit answer is at the point where an action becomes materially consequential or irreversible.

This is where the framework is most useful and most demanding. An approval checkpoint that a human clicks through without meaningful review is not oversight, it is a signature. The Uber decision by the Dutch DPA in August 2026, fining the company €825 million for automated driver deactivations where the company maintained that human review existed, turned on precisely this distinction. The regulator did not find that no human was involved. It found that the involvement was not meaningful.

For agentic systems the problem compounds. Where the agent generates the case summary the reviewer reads, the risk assessment the reviewer weighs, and the recommendation the reviewer approves, the human is present and the oversight is theatre. Three agents agreeing is not three opinions. It is one opinion with a quorum.

The framework’s requirement for clear allocation and defined checkpoints is the counter to this, but only if the checkpoint gives the human something independent to look at.

Dimension 3: Technical Controls

The framework identifies sandboxing, safety testing, monitoring, privilege limitation, and logging.

ControlWhat it addresses
SandboxingIsolates the execution environment so agent actions cannot reach beyond a defined boundary
Privilege limitationRestricts agent access to the minimum required for the task
Safety testingTests agent behaviour against adversarial inputs and edge cases before deployment
MonitoringObserves agent behaviour in operation, including deviation from expected patterns
LoggingRecords what the agent actually did, in a form independent of the agent’s own reporting

The logging point carries more weight than it appears to. An agent-generated summary of its own actions is not an audit trail. It is a narrative about an audit trail, produced by the entity being audited. The distinction holds until a regulator asks for the underlying system state and finds nobody kept it.

Privilege limitation is the control most often under-implemented, because agents are typically granted broad access during development for convenience and the grant is never narrowed before production.

Dimension 4: End-User Responsibility

The fourth dimension addresses communication to the people the agent interacts with or acts upon.

Users should understand what the agent can do, what it has done, and how to intervene. This is not a disclosure obligation in the transparency sense. It is an operational requirement: a user who does not know an agent has taken an action cannot correct it, and a user who does not know how to stop the agent cannot exercise the intervention right the framework assumes they have.

What Singapore Agentic AI Governance Framework Does Not Do

It is non-binding. IMDA has described it as a living document and invites feedback and case studies. No penalty attaches to departing from it.

Its practical effect operates through three channels. Enterprise procurement in Singapore increasingly references it. Sectoral regulators, particularly the Monetary Authority of Singapore for financial institutions, treat it as a reference point for reasonable AI governance. And it shapes international norms, complementing AI Verify and ASEAN governance initiatives.

Organisations deploying agentic AI in Singapore should treat the framework as the standard against which they will be measured, notwithstanding its voluntary status.

The Gap in Binding Regulation

The EU AI Act does not address agentic AI as a distinct category. This is a genuine gap rather than a deliberate omission: the Act was negotiated between 2021 and 2024, when agentic systems were not commercially significant.

The consequences are visible in several places.

Article 14 human oversight assumes a human who can understand outputs, detect anomalies, interpret results, and override decisions. Applied to an agent that acts before a human sees anything, the provision requires interpretation the text does not supply.

Article 6 classification turns on intended purpose and use case. An agent that operates across multiple functions may touch several Annex III domains simultaneously, and the framework for classifying a system with a variable operating scope is not well developed.

Article 12 logging requires automatic recording of events over the system’s lifetime. For an agent, the question of what constitutes an event, and whether the agent’s own account of its actions satisfies the requirement, is unresolved.

Article 9 risk management requires identification of risks from intended use and reasonably foreseeable misuse. Cascading effects across linked systems are not obviously either.

None of this means the AI Act does not apply to agentic systems. It applies fully. It means the operational guidance for applying it is thin, and the Singapore framework is currently the best available filler.

QuestionEU AI ActSingapore MGF for Agentic AI
Agentic AI as a distinct categoryNot addressedCentral subject
Cascading effectsNot addressedRisk bounding dimension
Privilege limitationNot addressedTechnical controls dimension
Approval checkpointsNot specifiedHuman accountability dimension
Independent action loggingArticle 12, not agent-specificTechnical controls dimension
Binding forceYes, with penalties to €35m or 7%No
EnforcementAI Office and national authoritiesNone

Applying Singapore’s Agentic AI Governance Framework Alongside EU AI Act Compliance

For organisations deploying agentic AI in both jurisdictions, the sequence is straightforward.

Build to the EU AI Act. Classification under Article 6, risk management under Article 9, data governance under Article 10, technical documentation under Annex IV, human oversight design under Article 14, and conformity assessment under Article 43 where applicable. This is the binding constraint and it is more demanding than anything Singapore requires.

Use the Singapore framework to fill the agentic gaps. Where the AI Act’s provisions do not tell you how to apply them to an autonomous agent, the four dimensions provide the operational answer. Risk bounding gives structure to the Article 9 risk assessment. Approval checkpoints give substance to Article 14 human oversight. Independent logging gives content to Article 12.

Map the outputs into both vocabularies. Singapore stakeholders expect MGF language. EU regulators expect Annex IV structure. The underlying facts are the same. Maintaining them once and rendering them into two formats is considerably cheaper than running two assessments.

Singapore dimensionMaps to EU AI Act
Risk boundingArticle 9 risk management system, Article 6 classification scope
Human accountabilityArticle 14 human oversight design, Article 26 deployer oversight obligations
Technical controlsArticle 15 accuracy, robustness, cybersecurity; Article 12 logging
End-user responsibilityArticle 50 transparency; Article 26(8) individual notification

Singapore Agentic AI Governance Framework: A Practical Checklist

StepAction
1Inventory every agentic system in deployment or development, distinguishing agents from generative systems by whether they take actions
2For each agent, map system linkages: what it can reach, and what those systems can reach in turn
3Classify data sensitivity across everything the agent can access
4Define the degree of autonomy: what the agent may decide without authorisation
5Trace cascading potential: what happens downstream when the agent acts, and where the chain terminates
6Define the operating envelope and constrain the agent to it
7Name an accountable individual for each agent
8Place approval checkpoints at consequential and irreversible actions
9Verify that each checkpoint gives the human something independent to evaluate, not an agent-generated summary
10Narrow privileges to the minimum required for the task
11Implement sandboxing where the agent’s action boundary can be technically enforced
12Log agent actions independently of the agent’s own reporting
13Conduct adversarial safety testing before deployment
14Communicate agent capabilities, actions taken, and intervention routes to affected users
15Reconcile the resulting documentation with EU AI Act Annex IV and Article 9 requirements

FAQ

What is Singapore’s Agentic AI Governance Framework?

The Model AI Governance Framework for Agentic AI, released by IMDA at the World Economic Forum on 22 January 2026 and updated on 20 May 2026. It is the first framework anywhere to address agentic AI systematically, organised around risk bounding, human accountability, technical controls, and end-user responsibility.

Is the framework legally binding?

No. It is a voluntary framework issued by IMDA and described as a living document. No penalty attaches to departing from it. Its practical force comes from enterprise procurement expectations, sectoral regulator reference, and its influence on international norms.

What is agentic AI?

AI systems capable of autonomous reasoning, planning, and action. Unlike generative systems that produce outputs for human use, agentic systems initiate tasks, update databases, execute actions, and adapt dynamically without a human necessarily present at the moment of action.

What are the four dimensions?

Risk bounding, which constrains the agent’s operating envelope by reference to system linkages, data sensitivity, autonomy, and cascading effects.

Human accountability, which requires clear allocation of responsibility and defined approval checkpoints.

Technical controls, covering sandboxing, privilege limitation, safety testing, monitoring, and logging.

End-user responsibility, covering communication of what the agent can do, has done, and how to intervene.

Does the EU AI Act cover agentic AI?

The AI Act applies to agentic AI systems in full, but it does not address agentic AI as a distinct category. It was negotiated before agentic systems became commercially significant. Provisions including Article 14 human oversight and Article 12 logging require interpretation when applied to systems that act rather than recommend, and the operational guidance for that interpretation is thin.

Why does the framework matter outside Singapore?

Because no binding regulation anywhere addresses agentic AI as a distinct category, and the Singapore framework is currently the most developed guidance available on the specific risks agentic systems create. Organisations deploying agents in the EU face AI Act obligations without AI Act guidance on how to meet them for this class of system.

What is a cascading effect?

A consequence that propagates across linked systems when an agent’s action triggers downstream actions. It distinguishes agentic risk from conventional AI risk: a recommendation system’s failure produces a bad recommendation, whereas an agent’s failure produces a bad action that may trigger further actions in systems the risk assessment did not map.

Is an agent-generated log sufficient for audit purposes?

No. An agent’s account of its own actions is a narrative produced by the entity being audited. The framework’s technical controls dimension calls for logging that records what the agent actually did, independent of the agent’s own reporting. The same logic applies to approval checkpoints: a human reviewing an agent-generated summary is reviewing the agent’s account, not the underlying facts.

How should we apply this alongside EU AI Act compliance?

Build to the EU AI Act, which is the binding constraint and more demanding overall. Use the Singapore framework to fill the operational gaps where the AI Act does not tell you how to apply its provisions to autonomous agents. Maintain the underlying documentation once and render it into both the MGF and Annex IV vocabularies.

Does Singapore have an AI Act?

No. Singapore has not enacted cross-sectoral AI legislation and has said it does not intend to in the near term. AI governance operates through voluntary IMDA frameworks, sectoral guidance, and existing statutes including the Personal Data Protection Act.

Will other jurisdictions adopt similar frameworks?

The framework has been positioned as contributing to regional and international convergence, complementing AI Verify and ASEAN governance initiatives. Whether it is adopted formally elsewhere is unresolved, but its four dimensions have already begun appearing in practitioner guidance internationally, which is how soft law instruments typically travel.

Disclaimer

This guide reflects the Model AI Governance Framework for Agentic AI released by IMDA on 22 January 2026 and updated on 20 May 2026. The framework is voluntary and IMDA describes it as a living document subject to revision. This guide is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations deploying agentic AI should obtain advice specific to their systems, sectors, and the jurisdictions in which they operate.

Back to Blog