Search across all content
A government framework, described as the first of its kind, setting out how to manage the risks of AI that can take actions on its own.
Most AI systems that governments and businesses have adopted so far generate content. They draft text, summarise documents, answer questions, or produce recommendations, and a person reviews the output before deciding what to do with it.
Agentic AI, however, can plan a series of steps, draw on databases and other tools, and carry out actions without a person signing off on each one. An agent of this kind might amend a citizen's record, authorise a payment, issue a notification, or pass a task to another agent to finish a longer piece of work.
That difference matters most when something goes wrong. A poor recommendation can be spotted and set aside by the person reviewing it. When an agent makes the same kind of error, the action may already be done by the time anyone notices, and undoing a changed record, a released payment, or a sent message is not always possible.
The stakes rise with the extent of what an agent can reach. One who handles money or sensitive personal records, in a bank, a hospital, or a firm contracted to process such data, can cause more damage with a single misstep than one who summarises internal documents. Singapore's existing AI guidance was not written with this in mind. Its Model AI Governance Framework, introduced in 2020, set out broad principles for trustworthy AI, and its 2024 edition addressed the risks of generative AI. Neither anticipated AI that acts, where the worries run to actions taken without authorisation, errors that travel across connected systems, and behaviour that surfaces only when several agents interact.
On 22 January 2026, at the World Economic Forum in Davos, Singapore's Infocomm Media Development Authority (IMDA) published the Model AI Governance Framework for Agentic AI. The Minister for Digital Development and Information, Josephine Teo, presented the first-of-its-kind framework built specifically for AI that can reason, plan, and carry out actions without human approval.
The guidance is organised around four areas.
Weighing the risk before deployment. The framework starts by asking how likely an agent is to err and how much harm an error would do. Organisations are guided to judge both before they put an agent to work, weighing whether its actions can be undone, how involved the task is, how much latitude the agent has, and how far it reaches into sensitive data and outside systems. It then sets out how to contain that risk by design: capping what the agent is allowed to do, giving it only the data and tools the task calls for, and assigning it a managed identity so its actions can be traced. It can never hold more permissions than the person on whose behalf it acts.
Keeping people accountable. The framework asks organisations to mark the points in a workflow where a person has to check and clear what an agent is about to do, with those checks focused on the riskiest and hardest-to-reverse steps. It also asks them to pin down who is responsible for an agent's actions, from the leaders who set its goals and limits to the product and security teams who build and test it to the staff who rely on its output, and to write those obligations into contracts with any outside suppliers. The thread running through this is automation bias, the habit of trusting a system because it has done well before and missing the point at which it stops.
Building in technical safeguards. Throughout an agent's life, the framework recommends a set of controls: testing it thoroughly before it goes live, confining it to a list of cleared services, monitoring it continuously once it runs, and adding alerts for behaviour that looks out of pattern. It favours releasing agents in stages so that faults show up while their impact is still contained, with failsafes that can stop an agent and hand control back to a person. Where agents operate together, splitting work between them or coordinating towards one goal, it cautions that the group can behave in ways no single agent would, and that a fault in one can ripple through the rest.
Telling users what they are working with. Anyone dealing with an agent should be able to tell it apart from a human colleague, know its limits, understand how their data is used, and have someone to turn to when something goes wrong. The framework also asks for training, pitched differently for the public meeting an agent through a service and for staff folding agents into their own work, so that whoever is meant to oversee an agent is equipped to do it.
IMDA published the framework for organisations building their own agents and for those buying them in, calling it a living document and inviting feedback and working examples to sharpen it. It said it was preparing separate guidance on testing agentic applications, extending an earlier kit it had issued for testing tools built on large language models. That invitation has already prompted a revision: in May 2026, IMDA released Version 1.5, drawing on responses from more than 60 organisations and adding more than 10 real deployments across government and industry.
1. The first agentic AI governance framework anywhere
No government had published a governance framework aimed at AI that act until Singapore did. By naming the risks and setting out concrete measures, it has established a starting point to work from. Singapore is also taking an outward approach through its AI Safety Institute and playing a leading role in ASEAN's working group on AI governance.
2. Industry helped build it and backed it publicly
IMDA developed the framework with input from government agencies and industry. At launch, the AI assurance firm Resaro publicly supported it, with its Co-Chief Executive Officer April Chin saying it filled “a critical gap in policy guidance for agentic AI.” Major cloud and technology providers, including Amazon Web Services, Google, DBS and Salesforce, have since contributed feedback and deployments to the framework.
3. It slots into a wider body of Singapore AI governance work
The framework does not stand alone. It points to the Government Technology Agency's Agentic Risk and Capability Framework for sample controls. Set against the AI Verify Foundation's testing tools and the existing guidance from the data-protection and financial regulators, it gives organisations something to work with across governance, security, testing, and sector rules.
This case study was written with assistance from artificial intelligence.





Connect with 500,000+ public servants solving your hardest challenges.





Connect with 500,000+ public servants solving your hardest challenges.
Help public servants worldwide learn from your work, what worked, what flopped and what you'd do differently
Share your project
Log in or sign up to continue the conversation