Only 14% of leaders in Singapore report having a mature model for agentic AI governance (Deloitte SEA, 2026). Yet 72% of companies plan to deploy agentic AI across several operational areas within two years. The budgets have been approved. The deployments are coming. The accountability structures, in most boardrooms, don’t exist yet.
The problem is sequencing, not technology. Boards that govern AI tools wait for a human to review the output before action is taken. Boards that govern AI agents are working with a different model altogether: the agent acts first. The oversight comes after, if it comes at all.
Agentic AI governance is the set of policies, accountability structures, and technical controls around an autonomous AI system. It determines who authorises what an AI agent can do, who is responsible when it acts incorrectly, and how the organisation responds. Governing AI tools means reviewing outputs before anyone acts on them. Governing AI agents means pre-defining the scope of autonomous action before deployment begins.
Singapore’s IMDA launched the world’s first governance framework specifically designed for agentic AI in January 2026, then updated it substantially in May 2026. Its core message hasn’t changed: humans are ultimately accountable. This article uses the current framework, alongside PDPA obligations and MAS guidance, to map what board-level accountability actually requires in practice.
TL;DR: Singapore launched the world’s first governance framework for agentic AI in January 2026 and updated it in May 2026, and its central message is explicit: humans are ultimately accountable. Only 14% of Singapore business leaders report a mature agentic AI governance model (Deloitte SEA, 2026), yet 72% plan broad deployment within two years. This article maps what “accountable” means at board level, using Singapore’s four-dimension framework and PDPA obligations as the structure.
- Only 14% of Singapore leaders have mature agentic AI governance, vs. 72% planning broad deployment within two years
- Singapore’s MGF is the world’s first framework designed specifically for agentic AI, launched January 2026 and updated 20 May 2026 with multi-agent risk guidance (IMDA)
- Three in four boards have approved major AI investments but fewer than half have set governance expectations (Grant Thornton 2026)
- Organisations with fully integrated AI governance are nearly four times more likely to report revenue growth than those still piloting (Grant Thornton 2026)
- Governance built now is absorbed as operating cost; governance retrofitted after a public failure is absorbed as crisis cost
For more on AI governance frameworks, see the Leadership and Governance topic hub.
Why Do AI Agents Require a Different Governance Model?
An AI agent acts first and gets reviewed afterwards, if at all. That reverses the order existing governance frameworks assume. The scale of what’s coming makes this urgent. Forty percent of enterprise apps will feature task-specific AI agents by 2026 (Gartner, Aug 2025). That is up from fewer than 5% in 2025. My own APAC AI Adoption 2026 survey of founders across 16 Asia-Pacific markets says the same thing at the small-business end. There, 90% plan to scale AI use in the year ahead, and not one respondent plans to cut back. Regional adoption figures are less settled than any single chart suggests. I have set every major Southeast Asian survey side by side to show why.
Board oversight has not moved at anything like that pace. An analysis of 3,048 US large-caps found that just 8% disclose any board-level oversight of AI (ISS STOXX, March 2026). Only 4% have two or more directors with AI skills. That figure is drawn from disclosures rather than self-assessment, which is what makes it uncomfortable. It measures what boards have actually committed to in writing. Most existing governance frameworks weren’t built for this speed or this operating model.
What Is the Difference Between an AI Tool and an AI Agent?
An AI tool waits for a human to approve its output. An AI agent does not wait. The distinction that matters for boards isn’t technical. It is the consequence sequence.
With an AI tool, the sequence is: prompt, output, human review, then action. A human sits between the output and any real-world consequence. If the tool hallucinates, meaning it produces a confident but wrong answer, a reviewer catches it before a customer, supplier, or regulator is affected.
With an AI agent, the sequence is different: instruction, action, then maybe a log entry somewhere. When an agent renegotiates with a supplier based on stale inventory data, the communication has already been sent. When an agent misreads a competitor signal and adjusts pricing, the price is already live. A human reviewing a log after the fact is doing documentation, not governance.
Consider an agency building an ad recommendation engine for a client. The first governance question is not whether it works. It is: who is responsible if it serves the wrong ad to the wrong person, and how will you know? That question sits in no vendor contract and no implementation timeline. It lives in governance. If you don’t decide it before deployment, the agent decides it for you by acting.
This is why existing AI governance frameworks, written for a world of outputs and approvals, aren’t adequate for agents. The oversight sequence has been inverted. Boards that don’t adjust their governance model accordingly are approving deployments they won’t be able to supervise.
For a practical overview of deploying AI agents in business operations, see the 2026 guide.
What Does Singapore’s Model AI Governance Framework for Agentic AI Require?
It asks four things of any organisation deploying an agent. Bound the risks upfront. Put named humans in the accountability chain. Apply technical controls across the agent’s lifecycle. Be transparent with the people who interact with it.
Singapore’s IMDA announced the framework in January 2026. International coverage described it as “the world’s first governance framework specifically designed for agentic AI.” Minister Josephine Teo launched it at the World Economic Forum in Davos (IMDA, January 22, 2026). Its central message carries a board-level implication most announcements glossed over: “Humans are ultimately accountable.” The framework assigns liability to the organisation deploying the agent, not to the agent itself. By implication, that reaches the board that approved the deployment.
What Changed in the May 2026 Update?
Two additions matter most at board level: multi-agent risk, and a clearer split of responsibility along the value chain. On 20 May 2026, IMDA published a substantially expanded version of the framework. It drew on input from more than 50 organisations. It added real-world case studies from the likes of AWS, DBS, OCBC, Google and Workday (IMDA, May 2026). If your AI policy still cites only the Davos launch, it is describing a framework that has moved on.
The first addition is multi-agent risk. The January version largely addressed a single agent doing a single job. The update confronts what happens when agents multiply and interact: agent sprawl, miscoordination, and emergent behaviour. Emergent behaviour is what a group of agents does together that no individual agent was designed to produce. Most boards approving “an AI agent” are in fact approving the first of many. The risk compounds at the seams between them.
The second is who is responsible along the value chain. The update draws a clearer line between the platform provider supplying the model and the organisation deploying it into a business process. This matters because it closes the most common boardroom escape hatch: the assumption that responsibility sits with the vendor.
Alongside the update, IMDA published something boards have paid less attention to and should read: a discussion paper on how legal responsibility should be allocated when an AI agent causes harm (IMDA, May 2026). It was written with a working group drawn from more than 20 members of Singapore’s legal community, and it covers civil liability across the whole chain: model developers, tooling providers, platform providers, system providers, deployers, end users and the third parties who get hurt.
What makes it worth a board’s time is that it does not land anywhere. It sets out the difficulty with fault-based liability, which is that breach and causation are hard to pin on any single party when an agent acts on its own. It sets out the case for strict liability, which would move apportionment disputes away from victims, and the objection to it, which is unbounded exposure and moral hazard. Then it stops, explicitly flagging the questions still open. A regulator thinking aloud about where liability should sit is a regulator that has not yet decided, and the period before it decides is the cheapest time to be able to show what your organisation did and why. The paper’s own practical advice is unglamorous and immediate: keep clear records, disclosures, logs and safeguards while the liability position develops.
Watch the direction of travel too. IMDA has an AI Tester Accreditation Programme expected in Q3 2026, and agentic testing coming to AI Verify in H2 2026. The assurance layer is arriving. Independent testing of material agent deployments is moving from something you could do to something you may be asked whether you did.
What Are the Framework’s Four Dimensions?
The four dimensions are risk bounding, human accountability, technical controls, and end-user responsibility, unchanged since January. For a board, the useful reading is a set of connected obligations rather than a checklist.
1. Assess and bound risks upfront
What the agent can and cannot do is a governance decision, not an implementation detail. Defining the scope of permissible actions before deployment, and documenting it, is where board accountability starts.
2. Human accountability across the full chain
The framework requires accountability to be defined across developers, deployers, operators, and end-users. For a board, this means a named accountable person must exist at each consequence tier. The vendor level or the engineering team level alone is not enough.
3. Technical controls throughout the lifecycle
Baseline testing before deployment, whitelisted APIs, staged rollouts, and real-time monitoring after launch. Whitelisted APIs mean the agent can only call connections you approved in advance. The board’s role here is to demand evidence that these controls exist and are being reviewed, not to configure the monitoring stack.
4. End-user responsibility
Transparency that agents are involved, and training to prevent over-trust. Employees and customers interacting with agents need to know they’re interacting with agents.
Do MAS-Regulated Financial Institutions Face Stricter Requirements?
Yes. For financial institutions, the proposed MAS Guidelines on AI Risk Management add a layer that is already treated as de facto mandatory. MAS issued them for consultation in November 2025. The consultation closed on 31 January 2026. In a written parliamentary reply on 5 August 2026, MAS Chairman and Deputy Prime Minister Gan Kim Yong said the guidelines apply to all AI use cases by financial institutions, including agentic AI, and “will be finalised soon”. They had not been issued as of early September 2026, and a 12-month transition follows once they land. That pending status is not a reprieve. Boards of regulated entities are expected to set AI risk appetite, formally approve the AI governance framework, and integrate AI risk into the three-lines-of-defence model. Supervisors will ask about all three before the ink is dry. The MGF remains voluntary for non-financial institutions. PDPA, though, creates binding obligations that sit underneath it regardless.
Citation capsule
Singapore’s IMDA launched the world’s first governance framework specifically designed for agentic AI on January 22, 2026, at the World Economic Forum in Davos, and published a substantially expanded version on 20 May 2026 that adds multi-agent systemic risk and a clearer split of responsibility between platform providers and deploying organisations. The framework’s central message is unchanged: “Humans are ultimately accountable.” It assigns responsibility not to the agent but to the organisation deploying it, across four dimensions: upfront risk bounding, human accountability chains, technical lifecycle controls, and end-user transparency. (IMDA, May 2026)
The Leadership and Governance topic hub has further reading on the full Singapore regulatory stack.
The Accountability Chain: Who Is “Ultimately Accountable”?
The organisation that deploys the agent is accountable, and so is the board that approved the deployment. Most boards have not built the chain that makes this workable. Three in four boards have approved major AI investments (Grant Thornton 2026 AI Impact Survey). Fewer than half have set governance expectations, and fewer than half have made AI risk a standing agenda item. The money is flowing, but the accountability chain hasn’t been built.
Eugene Teo of the Singapore Institute of Directors’ Finance Committee made a point about AI and cyber resilience in the Business Times in July 2026. It lands just as hard here. More capable AI, he argued, is surfacing weaknesses that were already present. Boards are discovering that “AI only removed the excuse for not seeing them.” The purpose of a sharper lens, he wrote, “is not to alarm boards, but to hold them accountable for what is now known” (Business Times, 10 July 2026).
Agentic AI asks a harder version of that question. Teo’s subject is visibility: AI revealing risk that already existed. Agents introduce something else. The question is no longer only what your board can now see, but what your systems can now do, without anyone seeing it. Visibility problems are solved by looking. Agency problems are not.
Which is why Teo’s other line travels so well: these are “governance questions, not technical details.” Singapore’s framework says humans are accountable. What it doesn’t do is name which humans. That gap is where most governance fails in practice.
How Do You Trace Who Authorised an Agent’s Action?
Map every action an agent can take to a consequence tier, and put a named owner on each tier. IMDA’s framework doesn’t give you a practical traceability tool like this. A traceability tool is something a board can point to after an incident. It answers who authorised this action, at what tier, and with which named accountable person. The template below fills that gap.
It is not drawn from the MGF. It’s a classification structure I developed to turn IMDA’s accountability principles into something boards can actually adopt. The idea is simple. Map every type of action your agents can take to a consequence level. Define the required oversight at that level. Assign a named owner. The board approves the framework. Everyone else works within it.
Here’s an example built for a digital agency running AI agents across client campaigns:
| Agent action type | Agency example | Human oversight required | Who holds accountability? |
|---|---|---|---|
| Read-only analysis | Pull client campaign performance data | Passive audit log | Account manager |
| Soft recommendation | Suggest revised media budget allocation | Account manager reviews before sharing | Account manager |
| Reversible action | Publish a social post on client's behalf | Human-in-the-loop approval or post-action audit | Account director |
| Semi-reversible action | Send a client-facing email, update CRM records | Pre-authorised within defined parameters | Client services head |
| Irreversible/high-stakes action | Commit ad spend above agreed threshold, submit a contract | Human approval required before execution | Managing director and client sign-off |
What Should the Board Approve, and What Can It Delegate?
The board approves the classification framework itself, not every agent action. Most agent actions are routine and low-consequence. The board’s role is narrower and more specific. Approve the framework. Confirm a named accountable person exists at each tier. Receive reports on any incidents at the semi-reversible or high-stakes tiers.
The most common governance failure right now is lag, not ignorance. Boards are approving AI deployments without having set the classification framework first. The result is agents taking semi-reversible and high-stakes actions with no defined approval threshold and no named accountable person. When something goes wrong, no one can say who authorised the scope of action.
Want the table above as a register you can actually fill in? Download the Board AI Agent Oversight Kit. Take one agent, tier every action it can take, and put a name against each one. Whatever you can't fill in is your governance gap.
The governance gap is about lag time and structural mismatch more than knowledge. Boards understand AI agents in the abstract; most directors can describe what an agent does. The problem is that governance structures were written for a world where outputs come before consequences. Agents invert that. The consequence arrives first, and the oversight, if any exists, arrives second. Singapore’s MGF addresses this structural problem explicitly. But the solution requires boards to act before deployment, not after it.
Citation capsule
Three in four boards have approved major AI investments, but fewer than half have set governance expectations for those investments, and fewer than half have made AI risk a standing agenda item. Only 20% of organisations have a tested AI incident response plan, and 78% of business executives lack strong confidence they could pass an independent AI governance audit within 90 days. (Grant Thornton 2026 AI Impact Survey)
Can Boards Outsource Accountability Under Singapore’s PDPA?
No. The organisation deploying the agent is accountable for how personal data is used, regardless of whether a third-party AI vendor processes it. Many boards assume accountability for AI outcomes can be transferred to the vendor. Under Singapore’s PDPA, it can’t.
The confidence numbers show how exposed that assumption leaves boards. Just 14% of CEOs believe their AI systems operate in adherence to regulations (EY Responsible AI Pulse Survey, March-April 2025, 975 C-suite leaders across 21 countries). Among their other C-suite peers, the figure is 29%. That gap is a visibility problem, not a knowledge problem. Domain C-suite leaders such as CTOs, CDOs, and CISOs feel confident about the AI systems within their lane. CEOs see the full picture but depend on what gets reported up to them. A 14% confidence rate at CEO level suggests most chief executives cannot see enough of their organisation’s AI footprint. They cannot call it compliant with any certainty. The CEO sits closer to day-to-day operations than the board does. If even the CEO is that uncertain, boards have their work cut out gaining confidence that AI is being deployed responsibly.
When Does the PDPA Apply to an AI Agent?
Whenever the agent uses personal data to make recommendations or decisions affecting individuals. The PDPC’s advisory guidelines make this concrete. The obligations cover consent for training data, explainability on request, purpose limitation, and accountability. Purpose limitation means personal data collected for one purpose cannot simply be reused for another. These obligations apply whether the agent is built in-house or assembled from third-party APIs.
This is also where the regulator is actively moving, not just where it has been. In June 2026 the PDPC opened a public consultation on proposed advisory guidelines for the use of personal data in generative AI (PDPC, June 2026). The consultation closed on 1 July 2026, with finalisation pending. One of its central themes is accountability across the AI supply chain. That is precisely the assumption a board makes when it treats the model vendor as the party carrying the risk. A board reading only the 2024 guidance is reading two-year-old signals about a regulator that has since moved.
The practical translation: your organisation is the accountable party whether the agentic workflow runs on Claude, OpenAI, or any other vendor’s model. That holds whenever the workflow processes customer or employee personal data. Signing a vendor data processing agreement shifts some operational risk. It does not shift PDPA accountability.
What Does PDPA Accountability Look Like in Practice?
Three things: an AI use register, vendor contracts with explicit data handling terms, and a defined process for access requests.
Running 2Stallions across Singapore, Malaysia, Indonesia, and India means client data flows through AI tools under several data protection regimes at once. For us, accountability is a client contract question, a staff training question, and a board-level governance question at the same time. One client conversation about how their campaign data was being processed through our AI tools led to a two-hour review of our vendor contracts. That’s the PDPA reality for any agency or service provider using agentic tools at scale.
Every board should be able to confirm all three exist in their organisation. First, an AI use register documenting every deployed agent, its purpose, and what data it touches. Second, vendor contracts with explicit data handling terms, not just the standard DPA. When I built out MCP integrations for ad platform reporting, we held off on extending the setup to any client account. First we reviewed each platform’s API Terms of Service and updated our own client-facing Terms of Service to disclose AI tool usage. The technical build took two weeks; the legal review took just as long. That sequencing is the right order of operations, and most organisations skip it (the MCP ad platform build walkthrough has the detail). Third, a defined process for handling PDPA access requests related to AI decisions, because regulators and affected individuals can and do ask.
Citation capsule
Just 14% of CEOs believe their AI systems operate in adherence to regulations, compared to 29% of other C-suite peers. Under Singapore’s PDPA, organisations deploying agentic AI cannot transfer accountability to the vendor. If an agent processes personal data through a third-party API, the deploying organisation remains responsible for consent, explainability, purpose limitation, and accountability. (EY Responsible AI Pulse Survey, Aug 2025)
For the underlying board AI fluency foundation, that article covers what directors need to understand before they can govern effectively.
What Boards That Get This Right Are Doing Differently
They treat governance as what lets them move faster, not what slows them down. Organisations with comprehensive AI policies are nearly twice as likely to be early agentic AI adopters (CSA and Google Cloud, Dec 2025). In that study, 46% qualified as early adopters, against 25% for those with only partial guidelines. Governance maturity, not technical readiness, is the strongest predictor of successful AI adoption. That finding inverts the common assumption that governance is friction slowing down deployment.
The audit challenge is real: 84% of organisations doubt their current ability to properly audit AI agents (KPMG Singapore and IIA Singapore, “The Agentic Opportunity”, May 2026). The revenue case for fixing this is equally clear. Organisations with fully integrated AI are nearly four times more likely to report revenue growth than those still piloting (Grant Thornton 2026 AI Impact Survey). The split is 58% versus 15%. The boards getting this right treat governance not as a compliance cost but as the infrastructure that lets them scale with confidence.
Three concrete differences separate boards that have done this from those that haven’t.
1. A named Chief AI Risk Officer or equivalent
Someone whose explicit job is bringing AI risk directly to the board, not filtering it through layers of management first. Most boards don’t have this role defined, which means they receive AI risk information that has been sanitised before they see it.
2. Tested AI incident response drills
Only 20% of organisations have a tested AI incident response plan (Grant Thornton 2026). Getting to 20% is the first practical move, not a stretch goal. An untested plan isn’t a plan. It’s a document.
3. AI risk as a standing board agenda item
With a named owner presenting at each meeting, not buried in operational updates and not surfaced only when a problem occurs.
Two practical tools worth knowing about. Singapore’s AI Verify toolkit from IMDA is free and open-source. Using it for material agent deployments creates a verifiable record that governance was applied. MAS Project MindForge’s publicly available Executive Handbook and Operationalisation Handbook give any board a practical starting structure, even if your organisation isn’t MAS-regulated.
For the business case context, the AI agents for business hub covers deployment patterns, ROI models, and use cases across industries.
How Long Does Singapore’s Voluntary AI Governance Window Remain Open?
Not long. Binding law is already in force elsewhere in the region, and the mandatory layer is arriving in Singapore too. IDC projects that by 2030, 15% of A1000 organisations will have faced lawsuits, substantial fines, and CIO dismissals (IDC Asia/Pacific CIO Agenda 2026). The cause: high-profile disruptions stemming from inadequate controls and governance of AI agents. Singapore’s agentic AI framework is voluntary for non-financial institutions right now. That window has a clock on it, and the clock is already running.
The clearest signal yet came from the top. At the National Day Rally on 23 August 2026, Prime Minister Lawrence Wong devoted part of his address to AI agents, citing the July 2026 incident in which an OpenAI agent left its test environment and broke into another company’s systems. “Developments like this are unsettling,” he said, before committing that Singapore would “anticipate the risks, and put appropriate safeguards in place” (PMO, 23 August 2026). Read the speech carefully, though. He announced binding requirements for social media platforms, and MDDI followed on 31 August with legislative amendments due in early 2027. For AI he announced no law, no bill and no timeline. That distinction matters for board planning: what changed in August is the political salience of agentic AI risk, not its legal status. The frameworks a board is governed by today are the same ones it was governed by in July.
MAS AIRG is already de facto mandatory for financial institutions, with MAS telling Parliament in August 2026 that finalisation is close, followed by a 12-month transition period. Boards of regulated entities cannot treat this as optional reading. The governance framework must be board-approved. AI risk appetite must be formally set. Integration into the three-lines-of-defence model must be documented.
Which Binding AI Laws Are Already in Force Nearby?
Vietnam’s is, and the EU AI Act’s next enforcement date arrives in August 2026. Vietnam’s binding AI law (No. 134/2025) took effect March 2026 and is the first binding AI legislation in Southeast Asia (Pertama Partners). Grace periods run to March 2027 for existing providers, and to September 2027 in health, education and finance. The enforcement picture is phased rather than immediate. For any organisation with regional operations spanning ASEAN, this signals where the regulatory environment is heading. Singapore’s voluntary framework is the vanguard, not the outlier.
Two other dates belong on the board calendar. From 2 August 2026, the EU AI Act activates enforcement powers over general-purpose AI, along with high-risk obligations and transparency duties. Its systemic-risk provisions reach the autonomous capabilities that make agents agents. If you touch the EU, that is a hard date rather than a direction of travel. Closer to home, ASEAN concluded negotiations on its Digital Economy Framework Agreement in May 2026, with signing targeted for the November 2026 summit. DEFA is a digital-economy framework rather than an AI safety regime. It is, though, the vehicle through which a common regional approach to AI and cross-border data is most likely to arrive.
The pattern across all of them is the same. Voluntary in Singapore today, binding somewhere you operate tomorrow.
What Should Boards Do While the Framework Is Still Voluntary?
Use the window to build governance at operating cost, before a failure forces crisis cost. Here is the timing reality: 78% of business executives lack strong confidence they could pass an independent AI governance audit within 90 days (Grant Thornton 2026). The voluntary period is the window to close that gap. Governance built now is absorbed as operating cost. Governance retrofitted after a public failure, a regulatory enforcement action, or a client contract dispute is absorbed as crisis cost. The crisis cost includes the reputational dimension that doesn’t appear on a balance sheet.
Built this way, governance stops being friction. It becomes the infrastructure that lets you deploy agents at scale without stopping to manually review every action. Organisations building it now move faster and with more confidence. Organisations that skip it are borrowing time.
Citation capsule
IDC projects that by 2030, 15% of A1000 organisations will face lawsuits, substantial fines, and CIO dismissals from inadequate AI agent governance. Vietnam’s binding AI law (No. 134/2025), the first in Southeast Asia, took effect March 2026. Singapore’s agentic AI MGF remains voluntary for non-financial institutions, but MAS AIRG for regulated financial institutions is already de facto mandatory. (IDC Asia/Pacific CIO Agenda 2026; Pertama Partners)
Does your board need to get current on AI governance and agentic AI, quickly? I run customised board and C-suite sessions built around your actual deployments, your sector, and your regulatory exposure, rather than a stock deck. As an SID Accredited Director who builds and runs these agents day to day, I can brief your board from both sides of the table: what the technology actually does, and what you’re accountable for when it acts. Get in touch.
What Should Your Board Ask Before the Next AI Agent Deployment?
Six questions, each needing a documented answer before the deployment goes live. If your governance framework is working, those answers already exist.
- What actions can this agent take without human approval? This maps directly to the classification table above. If you can’t answer it precisely, the agent’s scope hasn’t been defined.
- Who is the named accountable person at each action tier? A tier without a named person is an unowned tier.
- What personal data does this agent access, and has PDPA compliance been confirmed in writing? Not assumed. Confirmed.
- What is the incident response plan if the agent acts incorrectly, and has it been tested? An untested plan isn’t a plan. It’s a document.
- How will the agent be monitored after deployment, and who receives those reports? Monitoring that no one reads isn’t monitoring.
- What is the shutdown procedure, and who has the authority to trigger it? How quickly can the agent be taken offline if something goes wrong?
If your board can’t answer all six before a deployment proceeds, the gap is in governance, not technology. Every one of these questions can be resolved with policy decisions, not engineering work.
The six questions above as a pre-approval gate, plus the five-tier action register, an AI use register for PDPA, a five-step incident drill, and a July 2026 regulatory checkpoint. Templates your board fills in, not another framework summary.
Get the Kit
Frequently Asked Questions
Is Singapore's agentic AI governance framework legally binding?
The Model AI Governance Framework for Agentic AI, launched January 2026 and updated May 2026, remains voluntary for non-financial institutions. The May update did not change that status. The PDPA, however, is binding and creates accountability obligations that sit underneath the MGF regardless of whether an organisation formally adopts it. For MAS-regulated entities, the proposed Guidelines on AI Risk Management are treated as de facto mandatory: MAS consulted on them in November 2025 and the consultation closed on 31 January 2026. On 5 August 2026 MAS told Parliament the guidelines cover all AI use cases by financial institutions, including agentic AI, and would be finalised soon; they had still not been issued as of early September 2026, with a 12-month transition to follow once they are.
What happens when multiple AI agents interact?
This is the biggest addition in IMDA’s May 2026 update, and the risk most boards have not considered. The January framework largely addressed one agent doing one job. The update covers multi-agent systemic risk: agent sprawl as deployments multiply, miscoordination between agents, and emergent behaviour that no single agent was designed to produce. The practical implication for a board is that approving “an AI agent” usually means approving the first of many, and the risk concentrates at the seams between them rather than inside any one agent. Scope limits and named accountability need to cover the interactions, not just the individual deployments.
Is the AI vendor or my company responsible when an agent fails?
Your company. IMDA’s May 2026 update draws a clearer line across the value chain, distinguishing the platform provider that supplies the model from the organisation that deploys it into a business process. The provider carries obligations for the model; the deploying organisation carries responsibility for what it is pointed at and permitted to do. Under the PDPA the position is firmer still: accountability for personal data cannot be contracted away to a vendor. A contract can allocate cost and liability between commercial parties. It does not move regulatory accountability off your board.
Who is liable for AI decisions made by an AI agent?
Under Singapore’s PDPA and the IMDA MGF, liability sits with the organisation that deployed the agent, not the AI system itself. AI cannot be held legally accountable. The named accountable person in your governance framework is liable for actions within their assigned tier. At board level, directors carry governance accountability for approving deployment without adequate oversight structures — the same standard applied to any other material operational risk.
What is the difference between governing AI tools and governing AI agents?
AI tools produce outputs that humans review before taking action. AI agents take actions as their primary function: they send emails, update records, process payments, and execute decisions without a human in the loop at each step. Governing tools means reviewing outputs after generation. Governing agents means pre-authorising the scope of permissible actions, assigning named accountability for outcomes at each consequence tier, and monitoring behaviour in real time after deployment.
What should a board ask before approving an agentic AI deployment?
Six questions: (1) What actions can this agent take without human approval? (2) Who is the named accountable person for each action tier? (3) What data does it access, and is PDPA compliance confirmed in writing? (4) What is the incident response plan if the agent acts incorrectly, and has it been tested? (5) How will it be monitored after deployment, and who receives those reports? (6) What is the shutdown procedure and who has authority to trigger it?
Who is responsible for AI governance in an organisation?
Singapore’s IMDA MGF assigns responsibility across developers, deployers, operators, and end-users. At board level, directors are responsible for approving the AI governance framework and setting AI risk appetite. The primary responsibility for day-to-day AI governance sits with a designated role, ideally a Chief AI Risk Officer or equivalent, whose job is bringing AI risk directly to the board without filtering. For MAS-regulated entities, this structure must be formally documented and integrated into the three-lines-of-defense model.
Does PDPA apply to AI agents that use third-party APIs?
Yes. If your AI agent processes personal data through a third-party API, whether Claude, ChatGPT, or any other vendor’s model, your organisation remains the accountable party under PDPA. You cannot transfer this accountability to the vendor through a data processing agreement. The organisation deploying the agent is responsible for consent, explainability on request, purpose limitation, and accountability. Vendor contracts should include explicit data handling terms, but those terms do not transfer PDPA accountability. The PDPC reinforced this direction in June 2026, opening a consultation on proposed advisory guidelines for personal data in generative AI, with accountability across the AI supply chain as a central theme.
The Governance Shift That Actually Matters
The companies that move well with agentic AI won’t be the fastest to deploy. They’ll be the ones that built pre-authorisation structures before deployment instead of reviewing consequences after the fact.
Singapore’s MGF gives you the governance structure. PDPA gives it legal force. MAS AIRG shows you where mandatory requirements are heading, even if your organisation isn’t currently regulated. The agent action classification framework in this article gives you a practical place to start the board conversation.
Agents invert the oversight sequence. Boards that don’t adjust their governance model will find themselves overseeing consequences they can’t reverse. The position they oversee from wasn’t designed for this operating model.
The organisations building governance now are moving faster, not slower. They’re deploying agents with defined scope, named accountability, and monitored behaviour, which means they’re deploying with confidence. That is a competitive advantage, not merely a compliance one.
For more on building board-ready AI governance frameworks, the Leadership and Governance hub has further resources.