Ungoverned | Singapore Agentic AI Framework IMDA — Infocomm Media Development Authority, Singapore
By Dr. Freddie Seba © 2026 Freddie Seba. All rights reserved.
Singapore: a city-state with no frontier AI lab just governed what most institutions have not: what happens when the agent acts, and no human authorized it.
What the world’s first agentic AI governance framework covers — and what it leaves to your institution. Applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI
Governance as Leadership: The organizations that govern AI intentionally will lead. The ones that don’t will follow the consequences.
This series is not about compliance. It is about leadership. Every framework examined here surfaces the same question: not whether your institution is following the rules — but whether your leaders are governing the most consequential technological transformation of our time. Ungoverned: Applied Frameworks Under the Lens exists for leaders who understand the difference.
Previous analysis in this miniseries: Anthropic, OpenAI, Google Gemini, NIST-CAISI, EU AI Act, China. This week: Singapore. Coming next: South Korea, Canada, UK.
Constructive analysis — three questions, every installment, without exception.
Why this series — and why these frameworks
This series does not examine every AI governance framework. It examines the frameworks that together reveal the full shape of the governance challenge — and the full scope of what institutional leadership must build in response.
The selection logic is deliberate. It begins with the AI labs — Anthropic, OpenAI, Google — because that is where most institutions first encountered the governance gap: in the terms of service of tools already embedded in their workflows. It moves to U.S. federal bodies — NIST-CAISI — because understanding the voluntary, underfunded, and pending-authorization nature of federal AI standards is essential context for every institution that assumed federal governance was someone else’s responsibility.
It then moves outward — to the EU AI Act, China, Singapore, South Korea, and beyond — because AI governance is not a Western conversation, and leaders who govern only within the frameworks they already know will be ungoverned by the ones they do not. Singapore is in this series not because it is large, but because it is first. The world’s first agentic AI governance framework came from a city-state of six million people with no frontier AI laboratory — and that tells us something important about where governance innovation actually lives.
The frameworks explored in this series are not the only ones that matter. They are the ones that, examined together, reveal the pattern. The framework governs the platform, the standard, the model, or the market. Only the institution governs the consequences. That pattern is what this series is for.
This is a living series. Frameworks are added as the global AI governance landscape evolves — and it is evolving faster than any publication schedule can fully anticipate.
Series roadmap — a living intellectual agenda
This roadmap reflects the series as currently envisioned. New frameworks will be added as countries, standards bodies, and sector organizations publish governance guidance. The sequence may evolve. The three questions never will.
Tier 1 — AI Labs: The governance gap begins here — in the terms of service, privacy policies, and platform decisions of the tools already embedded in institutional workflows.
- Anthropic — United States
- OpenAI — United States
- Google Gemini — United States
Tier 2 — Government & Standards Bodies: Federal and national frameworks that shape institutional expectations — and the gaps those frameworks deliberately or structurally leave ungoverned. 4. U.S. NIST-CAISI — United States 5. Canada AI Governance — North America 6. UK AI Governance — United Kingdom
Tier 3 — Binding Regulatory Frameworks: The binding laws and regulations that define legal compliance floors — and the institutional governance required to meet them. 7. EU AI Act — Europe 8. China AI Safety Governance Framework 2.0 — China 9. Singapore Agentic AI Framework — Asia-Pacific 10. South Korea AI Basic Act — Asia-Pacific 11.
Tier 4 — International Standards & Multilateral Bodies: The frameworks that aspire to global consensus — and the institutional gaps that consensus cannot close.
Tier 5 — Sector & Vertical Frameworks: Where global frameworks meet institutional reality — in education, financial services, and emerging economies.
Tier 6 — Series Synthesis: What the frameworks — examined together — leave ungoverned. And what leadership must build in the space they leave behind. Series Synthesis: What the Frameworks Don’t Say
An ongoing series. Full roadmap and all published editions at freddieseba.com. New frameworks added as the global AI governance landscape evolves.
Question One — What was the framework designed to govern?
Singapore’s Model AI Governance Framework for Agentic AI — launched on January 22, 2026, at the World Economic Forum in Davos by IMDA, the Infocomm Media Development Authority — is the world’s first governance framework specifically designed for AI agents capable of autonomous planning, reasoning, and action. It was updated to Version 1.5 on May 20, 2026, incorporating feedback from more than 60 organizations and introducing new best practices, real-world case studies, and expanded guidance on multi-agent systems.
The framework was announced by Singapore’s Minister for Digital Development and Information Josephine Teo and builds on Singapore’s earlier governance instruments for traditional and generative AI. It applies to all organizations deploying agentic AI in Singapore, whether using in-house or third-party agents.
The framework is organized around four core dimensions. The first is assessing and bounding risks upfront — organizations must conduct use-case-specific risk assessments, considering the level of autonomy, access to sensitive data, the reversibility of actions, and task complexity. The second is making humans meaningfully accountable — organizational structures must allocate clear responsibilities across the AI lifecycle, with significant checkpoints at which human approval is required. The third is implementing technical controls and processes — including agent identity management, audit trails, baseline testing, monitoring, and offline mechanisms for malfunctions. The fourth is enabling end-user responsibility — end users must have the information they need to hold the organization accountable and use agents appropriately.
Version 1.5 added three significant expansions. Multi-agent systemic risk guidance addresses the compounding risks that arise when agents interact with other agents across organizational boundaries. More granular technical controls provide sector-specific implementation guidance across financial services, healthcare, public sector, and HR functions. And Version 1.5 identified a business continuity risk few institutions have named. As agents take over tasks, employees may lose the foundational skills to perform them manually when agents malfunction or become unavailable. The framework recommends that organizations identify core capabilities and ensure employees retain foundational skills — framing this explicitly as a business continuity and organizational resilience issue.
Compliance is voluntary. Legal accountability for agent behavior is not — organizations remain legally accountable for their agents’ behaviors and actions regardless of the degree of autonomy involved. A companion discussion paper on legal responsibility for AI agents was published simultaneously with Version 1.5.
It governs agentic AI deployment. Practically. Operationally. With the precision that comes from being first.
Question Two — The Governance Gap: what falls outside the frame, and where leadership begins?
Institutional accountability assignment.
Singapore’s framework defines with precision what meaningful human accountability looks like for agentic AI systems. What it cannot do — and was not designed to do — is name the accountable human inside your institution, build the agent identity architecture your organization requires, or maintain the audit trail that demonstrates your agents acted within their authorized boundaries. That work belongs to the institution. That is where leadership begins.
The framework requires each agent to carry a verifiable digital identity and an audit trail of which agent acted under whose authorization. Your institution must build and maintain that identity architecture. The framework requires significant checkpoints at which human approval is required. Your institution must define where those checkpoints are in every workflow where agents operate. The framework requires organizations to design offline mechanisms for malfunctions. Your institution must build, test, and maintain those mechanisms before an agent malfunction requires them.
Consider the questions the framework cannot answer for your institution. Who authorized each agent’s scope of action in your operational workflows? Who is named as accountable when an agent acts outside its intended boundaries? Who monitors the audit trail? Who has the authority to suspend an agent’s operations if its behavior drifts outside acceptable parameters? Who owns the institutional response when an agent causes harm through an action no human directly authorized? And — the question Version 1.5 surfaced explicitly — who is responsible for ensuring your staff retains the skills to perform critical processes manually if your agents become unavailable?
Singapore’s framework governs what accountability must look like. Leadership governance names the accountable humans, builds the architecture, and assumes responsibility for the consequences.
Question Three — What does governance as leadership look like before deployment?
This is where AI Minimum Viable Governance (AI-MVG) begins. Not after an unauthorized agent action triggers a review — before deployment, when the institution still has the leverage to govern with intention. This is not a compliance checklist. It is a leadership architecture.
Agent inventory — document every AI agent deployed or under consideration, including third-party agents operating within your institutional workflows Agent identity management — assign each agent a unique identity tied to a named supervising human or role within your institution Delegation boundary definitions — define explicitly what each agent is authorized to do, what data it can access, and what actions it cannot take without human approval Human checkpoint assignment — name the human checkpoint at each significant decision point in every agentic workflow Audit trail maintenance — establish who maintains the audit trail of agent actions and how long that trail is retained Skill continuity planning — identify which employee capabilities must be preserved alongside agent deployment to maintain operational resilience when agents malfunction Malfunction protocols — design and test offline mechanisms for agent malfunction before deployment, not after Named executive accountability — assign a named leader responsible for agentic AI governance outcomes across the institution
This week’s 12 Ps lens: People
People — the fourth P — is the governance dimension Singapore’s framework addresses most directly and most urgently. The framework’s central insight is that human accountability does not disappear when an agent acts autonomously — it becomes more important, more difficult to maintain, and more consequential when it is not clearly assigned before deployment.
Problems — Who authorized each agent’s scope of action, and what decision problem is the agent actually solving? Your institution must define this before deployment, not after an agent acts outside its intended boundaries.
Profits — Who benefits from agentic AI deployment in your institution, and who bears the risk when an agent acts unexpectedly? That asymmetry must be named and governed before deployment.
People — This is the governance gap. The framework mandates meaningful human accountability across developers, deployers, operators, and end users. Your institution must name the accountable person at each stage — not just the category.
Planet — Agentic AI systems operating autonomously at scale carry infrastructure and energy implications your institution should assess before deployment, particularly for multi-agent systems running continuously.
Process — The framework requires standard operating procedures including checkpoint processes, monitoring cadences, and malfunction protocols. Those processes belong to the institution — build them before deployment, not after a malfunction requires them.
Policy — The framework is voluntary but legal accountability is not. Your institution must translate voluntary guidance into binding internal policy with named owners and review cadences.
Protections — The framework identifies harmful real-world impacts including erroneous actions, biased outcomes, data breaches, and service disruptions. Your institution must define red lines, identify vulnerable groups affected by agent decisions, and establish complaint pathways before deployment.
Privacy — Agents that access sensitive data require institutional governance that maps agent data access against privacy obligations in every applicable jurisdiction — including jurisdictions where agent outputs are used, not just where agents are deployed.
Provenance — The framework requires baseline testing and audit trails of agent actions. Your institution must build evidence-based benchmarks, maintain traceability of agent decisions, and produce that documentation on demand — for regulators, accreditors, or board members who ask.
Preparedness — Version 1.5 surfaced a governance risk few institutions have named: as agents take over tasks, employees may lose the foundational skills to perform them manually when agents malfunction. Leadership competence and governance cadence must include skill continuity planning — not just technology readiness.
Product Ownership — Organizations are legally accountable for agent behavior regardless of autonomy level. Who owns the outcomes when an agent shapes a consequential institutional decision? Answering that question before deployment is what governance as leadership looks like.
Singapore’s framework governs what agentic AI deployment governance should look like. Institutional leadership governance governs whether your organization has built it. One defines the standard. The other names the accountable human, builds the audit trail, and defines the boundaries before the agent acts. That is the foundation of AI Minimum Viable Governance.
For executive briefings, board workshops, and keynote presentations → freddieseba.com
About the Author
Dr. Freddie Seba helps boards, trustees, and executive leadership teams build practical AI governance before AI failures make governance unavoidable. Scholar-operator, Silicon Valley founder, and global executive — EdD, USF · MBA, Yale · MA, Stanford.
This analysis is part of Ungoverned: Applied Frameworks Under the Lens, a recurring miniseries applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI to organizations shaping AI governance globally — including AI labs, governments, standards bodies, and international actors across the United States, Europe, Asia-Pacific, the Gulf, Latin America, and beyond. Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
This analysis is for informational and educational purposes only. It does not constitute legal, regulatory, or compliance advice. Institutions should consult qualified legal counsel regarding their specific obligations under applicable frameworks.
© 2026 Freddie Seba. All rights reserved.
References
Infocomm Media Development Authority. (January 22, 2026). Model AI Governance Framework for Agentic AI, Version 1.0. Singapore Ministry of Digital Development and Information. https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2026/new-model-ai-governance-framework-for-agentic-ai
Infocomm Media Development Authority. (May 20, 2026). Updated Model AI Governance Framework for Agentic AI, Version 1.5. https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/factsheets/2026/updated-model-ai-governance-framework-for-agentic-ai
Baker McKenzie. (January 29, 2026). Singapore: Governance framework for agentic AI launched. https://www.bakermckenzie.com/en/insight/publications/2026/01/singapore-governance-framework-for-agentic-ai-launched
Baker McKenzie. (2026, June). Singapore: IMDA updates Model AI Governance Framework for Agentic AI. https://www.bakermckenzie.com/en/insight/publications/2026/06/singapore-imda-updates-model-ai-governance-framework-for-agentic-ai
Inside Global Tech. (June 18, 2026). Singapore updates Model AI Governance Framework for Agentic AI. https://www.insideglobaltech.com/2026/06/18/singapore-updates-model-ai-governance-framework-for-agentic-ai/
Global Policy Watch. (2026, June). Singapore updates Model AI Governance Framework for Agentic AI. https://www.globalpolicywatch.com/2026/06/singapore-updates-model-ai-governance-framework-for-agentic-ai/
Lexology. (June 4, 2026). Singapore: IMDA updates Model AI Governance Framework for Agentic AI and publishes discussion paper on legal responsibility for AI agents. https://www.lexology.com/library/detail.aspx?g=f865bfe4-4d81-4420-b7d7-4dfa07959670
Regulations.AI. (2026). Updated Model AI Governance Framework for Agentic AI — Singapore. https://regulations.ai/regulations/RAI-SG-NA-GOVERNA-2026
Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
#AIGovernance #AgenticAI #AIMVG #AILeadership #Ungoverned #BoardGovernance #AIPolicy #CIO #Singapore #AIAgents #TechGovernance
