A narrow, dated note on Singapore instruments relevant to AI-agent oversight. Each entry names the instrument's exact status. Published frameworks and proposals are not the same thing, and this note keeps them apart.
These pages describe the product and cite public instruments. They are not legal advice, not a certification, and not a statement that any instrument applies to your organisation. The official source is authoritative; applicability questions belong to your advisers.
Instruments, by status
| Instrument | Status | What it addresses |
|---|---|---|
| Model AI Governance Framework for Agentic AI · IMDA | Published, voluntary. Version 1.0 launched 22 January 2026; version 1.5 issued 20 May 2026. Not legislation; creates no legal duty. | Any organisation deploying AI agents. Four dimensions: assess and bound risk upfront, meaningful human accountability, technical controls and processes, end-user responsibility. |
| Proposed Guidelines on AI Risk Management · MAS (P017-2025) | Proposal, not final. Consultation ran 13 November 2025 to 31 January 2026. No final guidelines had been published when this note was reviewed; treat any "in force" claim as unverified. | All financial institutions. Draft expectations cover board and senior-management oversight, AI inventories and materiality assessment, lifecycle controls including human oversight and third-party risk. The draft covers AI agents among other AI applications. |
| Personal Data Protection Act 2012 · PDPC | Binding law. | Personal data in AI systems, including agentic ones. Using AAES does not discharge the organisation's accountability obligation; data intermediaries can carry their own duties. |
| FEAT Principles · MAS (2018) | Non-binding principles, referenced in MAS supervisory dialogue with financial institutions. | Fairness, ethics, accountability and transparency in AI-driven decisions; accountability and transparency are the prongs action-layer records speak to. |
What AAES records may contribute
| Expectation | AAES contribution | Capability status |
|---|---|---|
| Bounded agent authority (IMDA dimension 1) | Registered capabilities with risk tiers, scoped short-lived grants, and refusals recorded before execution, on actions routed through AAES. | Implemented; demonstrated in the evaluation package. Enforcement depends on control of the agent's credential path. |
| Human accountability (IMDA dimension 2; MAS draft oversight expectations) | Every registered agent has a named accountable manager, a configured association rather than a statutory appointment; actions the operator registers as irreversible (a registration classification, not an independent assessment of effects) require approval by an authorized person; agent identities cannot act as approvers through the supported AAES approval path. An approval record does not by itself show the approver had adequate information, time or practical power to intervene. | Implemented. |
| Technical controls and evidence (IMDA dimension 3; MAS draft lifecycle controls) | Sealed, hash-chained decision records with offline integrity verification by the client's own reviewer. | Implemented. An independently controlled witness can be configured separately; that is not an external assessment, and the default deployment has none. |
AAES decision records may support review of access and approval controls. They do not establish lawful processing, model fairness, suitability, or compliance with any instrument as a whole.
Within the configured trust model, integrity verification checks the exported records; it does not establish that every action was recorded, that an external action succeeded, or that recorded assertions are true. Approval records do not by themselves establish meaningful human oversight. Enforcement depends on control of the credential path, and actions bypassing AAES are not recorded.
Residual responsibility and explicit gaps
- The client remains the regulated entity. Whether the MAS proposal, once final, applies to you (and how) is your adviser's question, not this page's.
- Work outside AAES is invisible to AAES. Records cover actions routed through AAES; they say nothing about actions on bypass paths.
- No independent certification or assessment of AAES exists. No SOC 2 report, no penetration test.
- Status changes. MAS may publish final guidelines or a consultation response after this note's review date. Re-check the primary source before relying on the status shown here.
Bring the instruments your risk team cites to a scoped evaluation.
Related pages:
This note: https://aaes.ai/library/jurisdictions/singapore.html
Hong Kong note: https://aaes.ai/library/jurisdictions/hong-kong.html
Trust model: https://aaes.ai/library/trust-model.html
Scope an evaluation: https://aaes.ai/contact.html?ref=library-evaluation
