AI agents can plan, call tools and act across connected systems. That makes governance an operating design problem, not a policy exercise.

IMDA introduced Singapore's Model AI Governance Framework for Agentic AI in January 2026 and published an updated version in May. The update reflects feedback from more than 60 organisations and includes over 10 case studies. Its four dimensions provide a useful structure for organisations adopting agents in customer service, operations, software delivery and other business workflows.

Assess and bound the risk

Define the agent's task, the systems and data it can access, the actions it can take and the consequences of failure. Higher-impact use cases need tighter boundaries. An agent that drafts a response presents a different risk from one that sends it, changes a customer record or triggers a payment.

Make human accountability specific

Name an owner for the use case, an owner for the technical system and a decision-maker for exceptions. Human oversight needs a real intervention point. Approval gates should sit before consequential actions, not after the outcome has already reached a customer or production system.

Build technical controls into the workflow

Use least-privilege identities, allowlisted tools, protected secrets, input and output controls, complete logging and tested rollback. Treat prompts, orchestration logic, retrieval sources and connected tools as change-controlled components. Test for prompt injection, unintended data disclosure, excessive agency and misuse of tool permissions.

Give every agent a verifiable identity

An agent should not inherit a developer's account or operate through a shared service credential. Give each deployed agent a distinct workload identity, authenticate it before every connection and authorise only the tools, data and actions required for its current task. Use short-lived credentials where possible, record delegated authority and make the human or system that initiated the work traceable.

This is becoming a concrete implementation concern. On 29 September 2026, the US National Institute of Standards and Technology said its National Cybersecurity Center of Excellence will demonstrate how AI agents can be identified, authenticated and authorised in a software-development lifecycle. The announcement followed feedback from more than 600 participants across government, industry and academia. For enterprise teams, the practical lesson is clear: agent identity belongs in the access-control architecture, not only in the AI policy.

Give users the information to intervene

People should know when they are dealing with an agent, what the agent can do, where its output may be unreliable and how to escalate or stop it. Clear user guidance reduces unsafe reliance and helps surface unexpected behaviour earlier.

Govern the lifecycle, not only the launch

Agent behaviour can change as models, prompts, data sources and tools change. Keep an inventory of approved use cases, reassess material changes, monitor behaviour and incidents, and retire agents cleanly when they are no longer required.

Questions for an approval gate

What can the agent access? What can it change? Which actions require a person? What evidence will be retained? How will the team contain and reverse an unsafe action?

Sources and further reading