AI Governance Library

Model AI Governance Framework for Agentic AI

The Model AI Governance Framework for Agentic AI gives organisations a structured overview of the risks of agentic AI and emerging best practices in managing these risks. If risks are properly managed, organisations can adopt agentic AI with greater confidence.
Model AI Governance Framework for Agentic AI

⚡ Quick Summary

Published by Singapore's Infocomm Media Development Authority (IMDA), the Model AI Governance Framework for Agentic AI provides structured guidance for safely deploying autonomous generative AI systems. Expanding upon traditional generative AI risk management, this framework addresses the unique vulnerabilities introduced when AI models are granted autonomy, multi-step planning, tool execution, and inter-agent communication capabilities.

The framework organizes actionable risk management across four core dimensions: assessing and bounding risks upfront, ensuring meaningful human accountability, implementing robust technical controls throughout the lifecycle, and fostering end-user responsibility. Grounded in real-world enterprise deployments across financial services, cybersecurity, and recruitment, it balances productivity advantages against emergent failure modes and automation bias.

🧩 What's Covered

The framework details actionable practices across four interconnected lifecycle dimensions, supported by concrete enterprise case studies:

  • Assess and Bound Risks Upfront: Methodologies for evaluating use cases by assessing domain error tolerance, reversibility of actions, system complexity, and tool access levels. It outlines core design boundaries, least-privilege tool access, and cryptographically verifiable, centrally catalogued agent identities tied directly to human supervisors or business units.
  • Make Humans Meaningfully Accountable: Structural division of responsibilities across key decision-makers, product teams, cybersecurity personnel, and end-users. It emphasizes safeguards against automation bias—such as tracking human override rates and response times—and establishing mandatory human checkpoints for irreversible, high-stakes, or out-of-scope actions.
  • Implement Technical Controls and Processes: Detailed safeguards across the development, pre-deployment, and operational stages. Recommendations highlight deterministic rule-based controls over prompt-layer instructions, protocol governance (such as Model Context Protocol and Agent2Agent standards), multi-agent communication schemas, sandbox execution, full-workflow testing, automated trajectory anomaly detection, and change management triggers.
  • Enable End-User Responsibility: Tailored strategies for users interacting with agents versus users embedding agents into workflows. Key topics include upfront UI transparency, disclosure of decision reasoning, user-defined risk thresholds, and mitigating tradecraft erosion and business continuity risks arising from automated entry-level tasks.
  • Practical Case Studies: Real-world implementations demonstrating tiered IT ticket automation (Dayos), source-of-wealth analysis boundaries (OCBC), confidential payroll processing via Trusted Execution Environments (Terminal 3), compliance questionnaire reflection loops (Cyber Sierra), phased developer tool rollouts (GovTech), open-source agent hardening (OpenClaw), and plain-language specification frameworks (Ant International).

💡 Why it matters?

As AI transitions from passive text generation to autonomous action-taking, traditional governance approaches focused purely on conversational safety become inadequate. Autonomous agents possess direct access to databases, APIs, and business execution tools, introducing compounding risks such as prompt injection via external tools, uncoordinated multi-agent conflicts, and systemic cascading errors. This framework bridges the gap between high-level ethical principles and granular technical architecture, enabling organizations to deploy agentic systems safely through structured scoping, hardware-enforced boundaries, and verified human oversight.

❓ What's Missing

While comprehensive in technical scoping and organizational oversight, the framework explicitly frames itself as an evolving living document. It does not establish binding regulatory thresholds, formal compliance certification schemes, or standardized cross-border liability apportionments for decentralized multi-agent commercial transactions. Detailed quantitative benchmarks for measuring safe autonomous drift across proprietary foundational models are also left to emerging industry evaluation toolkits.

👥 Best For

This framework is designed for Chief AI Officers, Enterprise Risk Managers, AI Engineers, Cybersecurity Leads, and Compliance Officers evaluating, building, or operationalizing agentic workflows and multi-agent platforms.

📄 Source Details

  • Title: Model AI Governance Framework for Agentic AI
  • Version: Version 1.5
  • Publication Date: 20 May 2026
  • Publishing Entity: Infocomm Media Development Authority (IMDA), Singapore
  • Document Type: Governance Framework

📝 Thanks to

Developed with contributions from Singapore government agencies including the Cyber Security Agency of Singapore (CSA) and GovTech, alongside feedback from over 60 industry organizations including Ant International, Google, Microsoft, OCBC, PwC, Tencent, Terminal 3, and Workday.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.