SGSingaporeVoluntarySG Agentic AI

How to govern AI agents under Singapore's framework

Singapore IMDA Model AI Governance Framework for Agentic AI

Status
Voluntary
Binding
No
Object analysed
AI system
Requirements
9
Next milestone
2027

In short

First governance framework dedicated to AI agents, published by IMDA at WEF 2026. Four dimensions: assess and bound the risks of each use case, keep meaningful human accountability, implement technical controls, enable end-user responsibility. It builds on the IMDA baseline: Model AI Governance Framework (2020), Generative AI framework (2024), AI Verify.

Steps to compliance

  1. Qualify each AI systemAxes to decide: Agent risk level (autonomy × access) and Agent origin.
  2. Determine your roleDuties vary by role: Deploying organisation and Agent developer.
  3. Apply the 9 requirementsThey focus on: Human oversight, Inventory & categorisation, Logging & traceability and Literacy & competence.
  4. Prove it with checks19 checks to document, 16 of which also serve NIST AI RMF, MAS AI Guidelines and AI Act.
  5. Track the deadlinesNext milestone: 2027, Follow-up to the discussion paper on agents' legal responsibility (potential).

Scope and penalties

Kind
Voluntary framework
Scope
Any organisation deploying AI agents in Singapore, built in-house or supplied by a third party.
Territorial reach
Singapore; an international reference for agent governance.
Penalties
None (voluntary). The organisation remains legally accountable for its agents' actions under existing law (PDPA, contract, tort).
Jurisdiction
Singapore

Timeline

Jan 23, 2019Model AI Governance Framework, 1st edition
Jan 21, 2020Model AI Governance Framework, 2nd edition
May 25, 2022AI Verify launched (governance testing)
May 30, 2024Model AI Governance Framework for Generative AI
Jan 22, 2026Agentic AI framework published (WEF)
May 20, 2026Update: multi-agent systems, third-party agents, automation bias; discussion paper on legal responsibility for agents
Release
2027Follow-up to the discussion paper on agents' legal responsibilityPotential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Agent risk level (autonomy × access)

High: strong autonomy, sensitive data or actionsModerateLow: bounded, reversible actions

Agent origin

Built in-houseThird-party agent

Requirements

9 requirements

CodeArticleRequirementApplies toChecks
SGA-1.1Dimension 1Assess each use case's risk: autonomy, access to sensitive data, breadth of actions
Deploying organisation
SGA-1.2Dimension 1Bound risk by design: limited tools, permissions, environments and scope of action
Deploying organisationAgent developer
SGA-1.3Dimension 1Give each agent an identity to trace its behaviour and know who answers for it
Deploying organisation
SGA-2.1Dimension 2Split responsibilities clearly and place human approvals before high-impact actions
Deploying organisationHigh: strong autonomy, sensitive data or actions
SGA-2.2Dimension 2Prevent automation bias among the people overseeing agents
Deploying organisation
SGA-3.1Dimension 3Test before deployment and roll out gradually
Deploying organisationAgent developer
SGA-3.2Dimension 3Monitor continuously, log actions and be able to stop the agent
Deploying organisation
SGA-3.3Dimension 3Control third-party agents and multi-agent systems: assessment, contracts, responsibilities
Deploying organisation
SGA-4.1Dimension 4Tell end users they are dealing with an agent, and what it can and cannot do
Deploying organisation

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-RISK-TOLERANCERisk tolerances are defined and AI systems are assigned to risk levelsOrganisation
CHK-CATEGORIZATIONAI system tasks and methods are categorized (classifier, generative, recommender)System
VER-008-02System designed to allow human oversight (stop button, override)System
NEW-SG-AGENTIC-01Agent permissions and tools limited to need (least privilege) proposedSystem
—
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourcedOrganisation
VER-006-02Automatic logging operational and compliantSystem
NEW-SG-AGENTIC-02Each agent has its own identity and a named owner proposedSystem
—
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholdersOrganisation
VER-008-03Competent overseers assigned to the systemSystem
NEW-SG-AGENTIC-03Human approval required before any irreversible or high-impact action proposedSystem
—
VER-001-D-02System users trained in its useSystem
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documentedSystem
VER-009-02Accuracy and robustness verified and documentedSystem
VER-021-D-03Operation monitoringSystem
VER-008-01Documented escalation and emergency stop procedureOrganisation
VER-AUTO-01Suspension procedure in the event of riskOrganisation
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
VER-026-F-01Contractual responsibilities documented between provider and third partiesProvider
VER-018-D-01Persons informed of the interaction with an AI systemSystem

Themes covered

Frequently asked questions

Who is in scope of SG Agentic AI?

Any organisation deploying AI agents in Singapore, built in-house or supplied by a third party. Singapore; an international reference for agent governance.

What penalties does SG Agentic AI carry?

None (voluntary). The organisation remains legally accountable for its agents' actions under existing law (PDPA, contract, tort).

When do the SG Agentic AI obligations apply?

Jan 22, 2026: Agentic AI framework published (WEF); May 20, 2026: Update: multi-agent systems, third-party agents, automation bias; discussion paper on legal responsibility for agents; 2027: Follow-up to the discussion paper on agents' legal responsibility.

Is SG Agentic AI binding?

No. Kind: voluntary framework. Status: voluntary.

How does SG Agentic AI relate to other regulations?

The same checks serve several texts. Shared checks: NIST AI RMF (10), MAS AI Guidelines (10) and AI Act (10).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo