What is the New Model AI Governance Framework for Agentic AI?
On 22 January 2026, at the World Economic Forum in Davos, Singapore launched the Model AI Governance Framework for Agentic AI (the Framework), developed by the Infocomm Media Development Authority (IMDA). It is described as the world’s first comprehensive governance framework specifically for “agentic AI” – systems that do not just generate content but can plan, reason, and act autonomously on a user’s behalf.
The Framework is a set of guidelines that builds on Singapore’s earlier AI governance initiatives (such as the 2020 Model AI Governance Framework and sectoral guidelines). It aims to provide practical, risk‑based guidance to organisations deploying AI agents in real‑world settings. The Framework emphasises that humans must remain meaningfully accountable for AI‑driven actions, even when those actions are taken autonomously by software agents. For end‑users in Singapore (e.g., businesses using AI tools or everyday consumers), this means clearer expectations on transparency, safety, recourse and data protection when interacting with increasingly autonomous AI services.
This article will cover the following topics:
- What is Agentic AI?
- What are the main objectives of the Framework for Agentic AI?
- Who is impacted by the Framework for Agentic AI and how?
- What does the Framework entail in terms of safeguards on the use of AI?
- What are the practical implications of the Framework for end-users?
- What are the legal/regulatory implications of the Framework?
What is Agentic AI?
Artificial Intelligence (AI) broadly refers to the study and use of intelligent machine learning to mimic human action and thought. Agentic AI represents the latest frontier of AI systems, coming after traditional AI and generative AI. The key characteristics of the three forms of AI systems are as follows:
- Traditional AI: Traditional AI, also known as rule-based or deterministic AI, is an AI system that relies on pre-programmed rules and algorithms to perform specific tasks. Traditional AI generally works by processing and analysing data, identifying patterns and then providing predictions or insights. Examples of traditional AI include virtual assistants such as Siri or Alexa, or even recommendation systems on Netflix and YouTube.
- Generative AI: Generative AI are AI systems that can generate original content (e.g. text, images, videos, software code) based on the data that they are trained on. Generative AI works by identifying patterns in huge amounts of data and then using that information to understand users’ requests or prompts. Based on this, original content is then generated. Examples of generative AI include ChatGPT, Google Gemini, Claude or Grok.
- Agentic AI: Agentic AI refers to self-managing AI systems that can plan, execute, critique, and iterate across multiple steps to achieve specified objectives. An example of agentic AI is LinkedIn’s Hiring Assistant, which is a multi-agent system designed to automate and support recruiters’ hiring workflows. Various AI agents perform tasks such as drafting outreach messages, generating screening questions, and sourcing candidates using LinkedIn’s recruitment data ecosystem.
Unlike traditional and generative AI, AI agents can reason and take action to complete tasks on behalf of users. This allows organisations to automate repetitive tasks, such as those related to customer service and enterprise productivity, and drive sectoral transformation by freeing up employees’ time to undertake higher-value activities. The following are some examples of how agentic AI can be used in everyday work or life:
- Banking: In the banking sector, agentic AI can be used to autonomously flag suspicious transactions and temporarily freeze accounts. This could help in scam or fraud prevention, or to contain the effects of a scam or fraud.
- Healthcare: In the healthcare sector, agentic AI systems can be designed to rank and prioritise patient cases based on reported symptoms, to ensure that urgent care is delivered promptly where necessary. Agentic AI can also be used to autonomously schedule follow-ups with patients.
- Workplaces: In most workplaces, agentic AI can be used to automatically filter and approve expense claims by employees or trigger procurement workflows. These are workstreams that would typically have to be done manually by human employees.
- Consumer Technology: In the realm of consumer technology, new technologies (e.g. latest mobile phone models) can also incorporate agentic AI, such as personal AI assistants that help with identifying and negotiating subscriptions or managing the user’s calendars.
The Framework is a set of guidelines introduced by the Singapore Government that specifically addresses agentic AI.
What are the Main Objectives of the Framework for Agentic AI?
The main objective of the Framework is to enable the safe and reliable deployment of autonomous AI agents, by providing organisations with practical guidance on how to manage the unique risks of agentic AI through both technical and non-technical measures. Ultimately, this would strengthen public trust in the development, deployment and use of AI, so that the benefits of AI can be widely and responsibly realised in line with Singapore’s broader, balanced approach to AI governance.
Who is Impacted by the Framework for Agentic AI and How?
The three main groups of stakeholders affected by the Framework are businesses using AI tools, developers and technology providers, and everyday users. They are affected in different ways, a summary of which is set out below:
- Businesses using AI tools: Businesses of all sizes that deploy AI systems – from banks and law firms to e‑commerce platforms, logistics companies and start‑ups – are key users of the Framework. For example, a law firm using an AI agent to draft and send routine engagement letters, or an online retailer using AI agents to handle returns and refunds, would be expected to consider the Framework’s safeguards when designing and monitoring those systems.
- Developers and technology providers: Companies that build or provide AI models, APIs and platforms are another primary audience. They are encouraged to design agentic capabilities with built‑in risk controls, provide configuration options for customers (such as limiting tool access), and support transparency about how the agent behaves and what data it uses.
- Everyday users: Everyday users – whether consumers using banking apps, patients using telehealth services, or investors using robo‑advisory platforms – stand to benefit from clearer standards on safety, transparency and recourse. While the Framework is primarily addressed to organisations, it reinforces the idea that users should be told when AI is involved, what it can do, and that a human organisation remains ultimately responsible for its actions.
What Does the Framework Entail in Terms of Safeguards on the Use of AI?
The Framework seeks to provide guidance across four key dimensions that organisations should consider when deploying agentic AI systems. Broadly speaking, the Framework recommends that organisations should consider the following points across the four key dimensions:
- Assessing and bounding the risks upfront: Organisations should adjust their internal structures and workflows to address the emerging risks introduced by AI agents. A crucial first step is to understand the risks arising from an AI agent’s actions, which are influenced by factors such as the breadth of actions it can perform, whether those actions are reversible, and the degree of autonomy the AI agent has. To mitigate these risks upfront, organisations can narrow the potential impact of their AI agents by defining clear boundaries during the design phase, for example, by restricting the AI agent’s access to certain tools and external systems. They should also make sure that AI agents’ actions remain traceable and controllable by putting in place strong identity management practices and access controls for AI agents. For example, access to AI agent systems can be tiered by seniority and function, with only designated administrators authorised to adjust operational parameters. Another example could be that each AI agent should have a verifiable digital identity, enabling a clear audit trail of which AI agent acted, under whose authorisation, and when.
- Making humans meaningfully accountable: Once approval is granted for agentic AI deployment, organisations should establish clear human accountability frameworks, i.e. to define when a human will be held accountable for the acts of the agents, and who that will be. Given the autonomy of AI agents and the involvement of multiple stakeholders across their lifecycle, responsibility can become diffused. Roles and obligations, both within the organisation and with external vendors, should therefore be explicitly defined and supported by adaptive governance to respond to evolving risks and technologies. To illustrate how this could work in practice, a bank deploys an agentic AI system to conduct customer due diligence checks, screening customers against sanctions lists and flagging high-risk profiles. Despite the AI agent’s autonomy, the bank’s compliance team remains accountable for the adequacy of the overall process. If the agent incorrectly clears a high-risk customer due to a miscalibrated risk threshold, the compliance team would face regulatory scrutiny from the Monetary Authority of Singapore (MAS) for any resulting breach of anti-money laundering obligations. This underscores that deploying an AI agent does not transfer accountability away from the organisation. Human oversight must be genuine and ongoing, and humans must be held meaningfully accountable.
- Implementing technical controls and processes: Organisations should ensure agentic AI systems operate safely and reliably by embedding technical safeguards across their lifecycle. Development should include controls for new agentic features such as planning, tool use, and evolving protocols. Before deployment, baseline testing should assess safety, reliability, policy adherence, and tool performance, supported by updated evaluation methods for agentic behaviour. Given their dynamic nature, AI agents should be deployed gradually with continuous post-deployment monitoring to manage emerging risks.
- Enabling end-user responsibility: Trustworthy deployment of agentic AI depends not only on developers but also on users who engage with these systems responsibly. As a baseline, users should be made aware of the agent’s functions, data access, and their own accountability in its use. Organisations should complement this with training that builds employee capability to manage human-agent interactions, provide effective oversight, and maintain critical thinking and domain expertise.
What are the Practical Implications of the Framework for End-Users?
The Framework aims to strengthen public confidence and ensure safe, accountable, and transparent use of agentic AI in Singapore. For end-users, this translates into several tangible benefits:
- Better safety and trust: By encouraging organisations to bound agent behaviour, test systems thoroughly, and keep humans accountable, the Framework aims to reduce risky or harmful AI decisions. For instance, an AI investment assistant may be restricted from executing high‑risk trades without your explicit confirmation, reducing the chance of unexpected losses due to a misinterpretation of your risk appetite. Over time, consistent application of these safeguards can help build public confidence that AI‑powered services are designed with user safety in mind.
- More transparency: The Framework promotes clear disclosure when users are interacting with AI systems and clarity about what the AI is doing or deciding. This helps individuals understand the system’s role and capabilities, reducing confusion or unintended deception in human-AI interactions.
- Accountability when things go wrong: The Framework reinforces the principle that organisations, not algorithms, are ultimately responsible for AI‑driven outcomes. If an agentic AI wrongly terminates your subscription, denies a refund you are entitled to, or mishandles your data, you should be able to hold the company accountable under existing legal and complaints processes. Courts and regulators may look at whether the organisation followed the Framework when deciding if it acted reasonably, which may in turn determine your prospects for redress.
- Privacy protection: The Framework supports Singapore’s broader regulatory ecosystem, including the PDPA, by ensuring that data used or accessed by agentic AI is handled responsibly and securely. Even as AI agents act autonomously, safeguards must be in place to protect personal and sensitive data from misuse.
What are the Legal/Regulatory Implications of the Framework?
Non-binding status and legal accountability
The Framework is not a piece of legislation and is currently only non-binding guidance. Therefore, organisations are not legally required to follow it. However, organisations are encouraged to adopt the Framework, as adherence to the Framework can influence findings of liability and the severity of any penalties imposed under existing laws that organisations must comply with.
Organisations that employ agentic AI must continue to comply with binding laws such as the Personal Data Protection Act 2012 (PDPA) and sector‑specific regulations and can face enforcement action if they fall short.
- The PDPA governs how organisations collect, use, disclose and protect personal data, including in AI systems, and requires reasonable security, limited purpose use, and breach notification in serious cases. The Personal Data Protection Commission also issued its Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (PDPC Guidelines), which explain how the PDPA applies when organisations use AI for profiling, automated decision‑making and personalisation across the AI lifecycle.
- As for sectorial-specific regulations, one such example would be the MAS guidelines and notices on risk management, outsourcing and model risk, which are relevant when financial institutions use AI for credit scoring, trading or fraud detection.
In practice, this means that if an AI agent causes harm – for example, by sending a sensitive medical report to the wrong person, or by approving a fraudulent transaction – the organisation may face regulatory investigations, fines, civil claims, under existing laws and regulations.
Therefore, while the Framework does not create new legal powers or binding legal obligations, the Framework still facilitates legal accountability by helping courts and regulators assess whether an organisation took reasonable steps (such as risk assessments, technical controls and clear accountability) in employing AI agents, which could influence how liability is determined or even the punishments that are meted out.
As an example of how the Framework can affect how an organisation’s liability is determined, take a robo-advisory platform in Singapore that uses an agentic AI system to rebalance portfolios automatically and answer customer queries. Assuming the AI agent mistakenly interprets instructions and liquidates the wrong holdings, causing losses, affected customers might argue that the platform was negligent in its design or monitoring of the system. A court could then consider whether the platform had set appropriate boundaries (e.g. limits on trade size), carried out testing, and provided ways for users to confirm or override actions, as suggested by the Framework, when deciding if it breached its duty of care.
Areas of legal risk
Agentic AI systems introduce heightened legal risks compared to traditional AI, precisely because they act autonomously and at scale. Thus, organisations using AI agents should be wary of the key areas of legal risk and thus comply with the Framework as far as possible. Potential sources of legal risk include:
- Data protection breaches: If an AI agent accesses or discloses personal data beyond what is authorised, the organisation could face PDPC enforcement, including directions and financial penalties.
- Negligence: Where an organisation fails to implement reasonable safeguards and an AI‑driven error causes loss (financial, reputational or physical), affected individuals may bring civil claims in tort.
- Contractual and consumer protection issues: Misleading statements about what an AI service can do, or unfair terms that attempt to disclaim responsibility for AI errors, may be challenged under contract or consumer protection law.
- Vicarious or organisational liability: Even if a particular employee was not directly at fault, the organisation may still be held liable for how its systems operate.
– –
In conclusion, Singapore’s Model AI Governance Framework for Agentic AI is a significant step towards overseeing AI systems that act with greater autonomy, while still anchoring responsibility in human hands. Though it does not have the force of law, it builds on existing statutes – in particular the PDPA and sector-specific regulations – and reflects regulators’ expectations of sound governance. For organisations and developers, it operates as a practical roadmap for designing, deploying and overseeing agentic AI in a way that controls risks and strengthens user confidence. For individuals, it points towards safer use of AI-powered services, clearer information about how these systems affect them, and better avenues for redress when autonomous tools move beyond simple automation and begin to plan and act on their own.
