How to govern AI agents under Singapore's framework
Singapore IMDA Model AI Governance Framework for Agentic AI
- Status
- Voluntary
- Binding
- No
- Object analysed
- AI system
- Requirements
- 9
- Next milestone
- 2027
In short
First governance framework dedicated to AI agents, published by IMDA at WEF 2026. Four dimensions: assess and bound the risks of each use case, keep meaningful human accountability, implement technical controls, enable end-user responsibility. It builds on the IMDA baseline: Model AI Governance Framework (2020), Generative AI framework (2024), AI Verify.
Steps to compliance
- Qualify each AI systemAxes to decide: Agent risk level (autonomy × access) and Agent origin.
- Determine your roleDuties vary by role: Deploying organisation and Agent developer.
- Apply the 9 requirementsThey focus on: Human oversight, Inventory & categorisation, Logging & traceability and Literacy & competence.
- Prove it with checks19 checks to document, 16 of which also serve NIST AI RMF, MAS AI Guidelines and AI Act.
- Track the deadlinesNext milestone: 2027, Follow-up to the discussion paper on agents' legal responsibility (potential).
Scope and penalties
- Kind
- Voluntary framework
- Scope
- Any organisation deploying AI agents in Singapore, built in-house or supplied by a third party.
- Territorial reach
- Singapore; an international reference for agent governance.
- Penalties
- None (voluntary). The organisation remains legally accountable for its agents' actions under existing law (PDPA, contract, tort).
- Jurisdiction
- Singapore
Timeline
Qualifying a system
Classification axes and possible verdicts
Agent risk level (autonomy × access)
Agent origin
Requirements
9 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| SGA-1.1 | Dimension 1 | Assess each use case's risk: autonomy, access to sensitive data, breadth of actions | ||
| SGA-1.2 | Dimension 1 | Bound risk by design: limited tools, permissions, environments and scope of action | ||
| SGA-1.3 | Dimension 1 | Give each agent an identity to trace its behaviour and know who answers for it | ||
| SGA-2.1 | Dimension 2 | Split responsibilities clearly and place human approvals before high-impact actions | ||
| SGA-2.2 | Dimension 2 | Prevent automation bias among the people overseeing agents | ||
| SGA-3.1 | Dimension 3 | Test before deployment and roll out gradually | ||
| SGA-3.2 | Dimension 3 | Monitor continuously, log actions and be able to stop the agent | ||
| SGA-3.3 | Dimension 3 | Control third-party agents and multi-agent systems: assessment, contracts, responsibilities | ||
| SGA-4.1 | Dimension 4 | Tell end users they are dealing with an agent, and what it can and cannot do |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-RISK-TOLERANCE | Risk tolerances are defined and AI systems are assigned to risk levels | Organisation | ||
| CHK-CATEGORIZATION | AI system tasks and methods are categorized (classifier, generative, recommender) | System | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| NEW-SG-AGENTIC-01 | Agent permissions and tools limited to need (least privilege) proposed | System | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | Organisation | ||
| VER-006-02 | Automatic logging operational and compliant | System | ||
| NEW-SG-AGENTIC-02 | Each agent has its own identity and a named owner proposed | System | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | Organisation | ||
| VER-008-03 | Competent overseers assigned to the system | System | ||
| NEW-SG-AGENTIC-03 | Human approval required before any irreversible or high-impact action proposed | System | ||
| VER-001-D-02 | System users trained in its use | System | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | System | ||
| VER-009-02 | Accuracy and robustness verified and documented | System | ||
| VER-021-D-03 | Operation monitoring | System | ||
| VER-008-01 | Documented escalation and emergency stop procedure | Organisation | ||
| VER-AUTO-01 | Suspension procedure in the event of risk | Organisation | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | Provider | ||
| VER-018-D-01 | Persons informed of the interaction with an AI system | System |
Themes covered
Frequently asked questions
Who is in scope of SG Agentic AI?
Any organisation deploying AI agents in Singapore, built in-house or supplied by a third party. Singapore; an international reference for agent governance.
What penalties does SG Agentic AI carry?
None (voluntary). The organisation remains legally accountable for its agents' actions under existing law (PDPA, contract, tort).
When do the SG Agentic AI obligations apply?
Jan 22, 2026: Agentic AI framework published (WEF); May 20, 2026: Update: multi-agent systems, third-party agents, automation bias; discussion paper on legal responsibility for agents; 2027: Follow-up to the discussion paper on agents' legal responsibility.
Is SG Agentic AI binding?
No. Kind: voluntary framework. Status: voluntary.
How does SG Agentic AI relate to other regulations?
The same checks serve several texts. Shared checks: NIST AI RMF (10), MAS AI Guidelines (10) and AI Act (10).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.