FL Fredrik Lindstrom


A national AI regulator built a four-pillar framework and split it, without naming it, into stages you pass through and properties that hold the whole way down.

IMDA’s Model AI Governance Framework for Agentic AI organises technical controls by lifecycle stage: design, development, pre-deployment, deployment. Those are horizontal layers. But two of its four pillars — make humans meaningfully accountable, and enable end-user responsibility — are not stages. They run across every stage at once.

That is the reason it earns a toolkit slot rather than a footnote. When a director pushes back that human oversight is a deployment-stage gate, the answer is no longer an argument about framework design. A regulator structured its own framework the other way.

A four-row table of the Singapore MGF pillars, what each requires, and whether it behaves as a lifecycle layer or as a column running across every stage.
Download the crosswalk PDF, text selectable, prints for board packs. No email required.

Four pillars, two shapes

  1. Layer

    Assess and bound the risks

    Likelihood × impact, judged before deployment. v1.5 adds systemic and multi-agent risk: agent sprawl, collaborative failure, emergent behaviour, third-party-agent visibility.

  2. Column

    Make humans meaningfully accountable

    Responsibility allocated inside and outside the org. Mandatory human approval for irreversible, high-stakes or atypical actions. Oversight complemented by real-time monitoring.

  3. Layer

    Implement technical controls

    Prefer structural, rule-based controls — block the tool at system level — over prompt-layer instruction not to use it. Runtime controls layered on top.

  4. Column

    Enable end-user responsibility

    Inform users of agent capabilities and limits. Train them to oversee agents. Tailor the information to different user needs.

The MGF is voluntary and non-binding, and organisations remain legally accountable for their agents’ actions regardless of whether they adopt it. Its value to a director is conceptual rather than compliance-driven: it names the agentic risks the binding regimes have not yet caught up to, including agent sprawl, collaborative failure between agents, and the visibility you do not have into third-party agents.


What it covers that the binding regimes have not caught up to

  1. 01

    Agent sprawl — how many are running, and who counted.

  2. 02

    Collaborative failure — miscoordination, conflict, collusion between agents.

  3. 03

    Structural over prompt-layer control — block the tool, do not ask the agent nicely.

Every framework that takes agents seriously ends up separating the stages from the properties.

Source: Model AI Governance Framework for Agentic AI, Infocomm Media Development Authority, Singapore. Launched 22 January 2026 at Davos; v1.5 published 20 May 2026 incorporating feedback from 60+ organisations. Builds on IMDA’s 2019 Model AI Governance Framework and the 2024 generative-AI edition. Voluntary and non-binding. Described here as the first national framework written specifically for agentic AI — IMDA’s own characterisation — not as an absolute first. Layer/column assignments are this sheet’s reading, not IMDA’s framing.


Related

The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.

What each AI tier actually decides — regulatory exposure tracked against the consequence of the decision, with the reversibility column most charts leave off.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.