ZENTARA

AI Governance Framework for Agentic AI in Singapore

Learn how Singapore organisations can apply AI governance frameworks, MAS FEAT principles, and human oversight to manage risks from agentic AI.

Trimikha Valentius9 min read
AI Governance Framework for Agentic AI in Singapore

AI Governance Framework for Agentic AI in Singapore

Artificial intelligence is moving rapidly from systems that merely generate text or answer queries to autonomous agents designed to execute actions.  

Agentic AI can plan complex tasks, execute tool calls, access databases, interact with third-party software, and make operational decisions with minimal human intervention. While this capability unlocks immense productivity for financial institutions and enterprises, it fundamentally changes how AI risk management must be conducted.  

An AI model that produces an inaccurate text response is an informational issue. An AI agent that acts on that inaccurate response is an operational hazard. It could approve an unauthorized transaction, alter customer records, execute payments, access classified data, or trigger unexpected workflows across external systems. As autonomy expands, establishing a clear AI governance framework becomes essential to define strict operational boundaries.  

Singapore has established itself as a global benchmark for AI governance Singapore initiatives. The Monetary Authority of Singapore (MAS) introduced the foundational FEAT principles, covering Fairness, Ethics, Accountability, and Transparency, to guide financial services. Furthermore, recent updates to the MAS AI risk management toolkit and operational handbooks underscore that governance must evolve from abstract principles into active controls.  

What Are the MAS FEAT Principles?

The FEAT principles provide the baseline for responsible deployment across financial services, aligned with official MAS AI guidelines. They focus on four core pillars: 

While these principles were developed in the context of financial institutions, they offer a useful foundation for thinking about how AI should be governed as it becomes more capable and autonomous.

1. Fairness

AI systems should not produce unjustifiably discriminatory outcomes. For financial institutions, this can be particularly important when AI is used in areas such as credit assessment, customer segmentation, fraud detection, or insurance-related decisions.

Organisations should understand which data and variables influence outcomes, test for potential bias, and establish processes to investigate unexpected disparities.

2. Ethics

AI systems should be developed and used in ways that are consistent with ethical standards and organisational values. This requires organisations to consider not only whether an AI system can perform a task, but whether it should be allowed to perform it.

For agentic AI, this question becomes more important because an autonomous system may make decisions or take actions that were not explicitly anticipated when it was deployed.

3. Accountability

There should be clear responsibility for how AI systems are developed, deployed, and used. An AI agent cannot be the final owner of a business decision. Organisations need to define who is responsible for the system, who approves its use, who monitors its performance, and who takes action when something goes wrong.

4. Transparency

People should have sufficient information to understand how AI is being used and, where appropriate, how decisions are reached.

For agentic AI, transparency also means making the system's capabilities and boundaries clear. Users should know when they are interacting with an AI agent and understand what actions it can take on their behalf.

Why Agentic AI Changes the Governance Challenge

Traditional machine learning models perform single, defined tasks. In contrast, agentic AI systems plan across multiple steps, call external APIs, query databases, and execute tasks on behalf of users.

National guidelines addressing agentic AI governance highlight four key focus areas:

  • Assessing and bounding risks upfront.
  • Enforcing meaningful human accountability.
  • Implementing technical controls and process guardrails.
  • Enabling end-user responsibility and transparency.

Updated frameworks released in 2026 incorporate feedback on multi-agent architectures, third-party agent dependencies, and the risks of automation bias. Consequently, the core governance question shifts from "Can we trust this model?" to "How do we bound what this system is permitted to execute?"

Building an AI Governance Framework for Agentic AI

Implementing an operational AI governance framework for autonomous agents requires eight core capabilities: 

1. Establish clear board and executive accountability

AI governance should start at the top. Boards and senior leadership should understand where AI is being used, what risks it creates, and which systems could have material consequences for customers, employees, or the organisation.

Responsibility should then flow down through clearly defined roles. Business owners, AI developers, data teams, cybersecurity teams, risk functions, compliance, and internal audit should each understand their responsibilities across the AI lifecycle.

For agentic AI, accountability should extend to the actions taken by the system, not just the model that powers it.

2. Classify AI use cases by risk

Not all deployments require identical oversight. An internal assistant summarizing notes carries a vastly different risk profile than an agent authorized to modify customer accounts or execute fund transfers. Incorporating these criteria into your broader model risk management strategy ensures that oversight remains proportionate to risk materiality. 

3. Set boundaries around AI autonomy

Autonomous systems should not have unlimited freedom to act. Organisations should define what an AI agent can access, which tools it can use, what systems it can interact with, and which actions require approval.

High-impact or irreversible actions should generally have stronger controls than low-risk and reversible tasks.

This approach reflects the practical direction of Singapore's agentic AI governance framework, which recommends placing limits on agent autonomy and access to tools and data.

4. Create meaningful human approval points

Human oversight only works when people can genuinely review and challenge an AI system's actions. If employees automatically approve every recommendation, human oversight becomes little more than a formality.

Organisations should identify significant decision points where human approval is required and provide enough context for the reviewer to make an informed decision. This is particularly important for addressing automation bias, where people may become overly reliant on AI outputs because the system has performed reliably in the past.

5. Build AI security into the architecture

AI governance and cybersecurity cannot operate separately. Agentic AI systems may have access to APIs, databases, cloud environments, internal applications, and third-party tools. Each connection introduces potential security risks.

Access should therefore follow least-privilege principles, with strong authentication, scoped permissions, secrets management, and controls over which tools and external services an agent can access.

The goal is to ensure that compromising an AI agent does not automatically give an attacker unrestricted access to the wider environment.

6. Monitor AI behaviour continuously

AI governance should not end when a system goes live. Organisations should continuously monitor how AI systems behave, including the actions they take, data they access, tools they use, and decisions they make.

Monitoring can help identify unusual activity, unexpected outputs, repeated policy violations, or changes in behaviour that may indicate a security or governance issue.

Singapore's updated agentic AI framework specifically highlights continuous monitoring and testing as part of responsible deployment, including phased rollouts that allow organisations to observe risks before expanding access.

7. Test AI systems before and after deployment

AI systems should be tested before they are given access to sensitive information or critical business processes.

Testing should examine both security and governance risks, including prompt injection, data leakage, excessive permissions, unsafe tool use, and attempts to bypass guardrails. Testing should continue after deployment because AI systems and their surrounding environments change over time.

New models, tools, integrations, and prompts can introduce risks that were not present during the initial assessment.

8. Maintain an AI inventory

Organisations cannot govern systems they do not know exist. An AI inventory should record approved AI applications, models, agents, data sources, owners, vendors, connected systems, and risk classifications. This should include both internally developed systems and third-party AI services.

Maintaining this visibility becomes increasingly important as employees begin adopting AI tools independently and organisations introduce multiple agents across different business functions.

Turning FEAT Principles Into Operational Controls

The FEAT principles provide a useful foundation, but principles alone do not create effective governance. Organisations need to translate them into measurable controls.

FEAT principle

Practical control

Fairness

Bias testing and outcome monitoring

Ethics

AI use-case approval and risk management

Accountability

Named AI owners and escalation processes

Transparency

User disclosure, explainability, and decision records

For agentic AI, these controls should also cover autonomy, tool access, human approval, monitoring, and incident response. The objective is to make governance part of everyday operations rather than something that exists only in policy documents.

Continuous Monitoring Is the Missing Layer

Many AI governance programmes focus heavily on approval before deployment. That is important, but it is only the beginning.

Deploying automated AI monitoring tools provides continuous visibility over active agents. Organizations must establish baselines for normal operational behavior and configure real-time alerts for anomalies, such as unusual tool calls, unexpected data access, or repeated guardrail failures. If an agent exhibits unpredictable behavior, automated controls should revoke its permissions or step down its autonomy until the root cause is resolved.  

Continuous monitoring ensures that your AI governance framework adapts dynamically as systems evolve in production.

From AI Principles to AI Governance in Practice

The true test of any AI governance framework is how effectively it functions in active production environments. 

For Singapore organisations, the MAS FEAT principles provide an important foundation for responsible AI use in financial services. As AI becomes more autonomous, the newer agentic AI guidance from IMDA provides additional practical direction around autonomy, human accountability, technical controls, and continuous monitoring.

The next step is turning those principles into operational controls. That means knowing where AI is used, classifying its risks, defining who is accountable, limiting what agents can do, monitoring their behaviour, and testing whether safeguards continue to work.

The goal is not to slow down AI adoption. It is to make sure innovation does not move faster than your ability to control it.

As AI becomes more autonomous, organisations need governance that connects strategy, risk, privacy, and cybersecurity.

Zentara helps organisations strengthen their security and governance programmes through cybersecurity consulting, VAPT, and Managed SOC services. These capabilities can help organisations assess technical risks, validate security controls, and maintain continuous visibility across evolving digital environments.

For organisations introducing AI agents, the focus should be simple: know what your AI can access, know what it can do, and know when it needs to be stopped.

Ready to turn AI governance from policy into practice?

Explore Zentara's cybersecurity services and build a stronger foundation for secure, responsible AI adoption.

More like this, monthly.

What our teams are seeing in Indonesian threat activity and regulatory movement — written by the people running the SOC.

We use your address to send what you asked for and nothing else. No list is sold or shared. Privacy policy.

Have a security question this raised?

Our engineers answer directly — no qualification call first.