MAS includes agentic AI

- Singapore’s Monetary Authority said on August 5 that its forthcoming AI risk-management guidelines for financial institutions will apply to all AI uses, including agentic systems. - Gan Kim Yong said the rules require board and senior-management oversight, risk frameworks and AI life-cycle controls, while SAFR records each consequential decision. - MAS said the guidelines will be finalised soon, with Project MindForge and the Future of Finance Institute supporting implementation.

Singapore’s Monetary Authority has now said the quiet part out loud: if a bank uses an autonomous AI agent, MAS will treat it as falling inside bank supervision, not outside it. In a written parliamentary reply for the August 5, 2026 sitting, Deputy Prime Minister Gan Kim Yong, who chairs MAS, said the regulator’s proposed Guidelines on Artificial Intelligence Risk Management “apply to all AI use cases by FIs, including agentic AI.” That matters because MAS is not talking about a voluntary sandbox note. The reply ties agentic systems to supervisory expectations on board oversight, risk management processes and AI life-cycle controls for financial institutions. MAS also said the guidelines, first proposed in a November 2025 consultation, “will be finalised soon.” Here’s the practical thread. (mondovisione.com) ### What exactly did MAS confirm? MAS confirmed that its AI risk-management guidelines cover “all AI use cases by FIs, including agentic AI.” That language came in response to a parliamentary question from MP Mariam Jaafar asking whether MAS planned to move beyond the industry-led SAFR framework toward mandatory supervisory requirements. (mondovisione.com) In plain regulatory terms, that means a bank cannot argue that an autonomous software agent sits outside existing governance because it is “just tooling.” MAS is saying the opposite: if the system is used by a financial institution, it belongs inside the institution’s supervised AI controls. That reading is supported by MAS’s own description of the guidelines as setting “supervisory expectations” for financial institutions. (mondovisione.com) ### What are those supervisory expectations? Gan said the proposed guidelines require “robust board and senior management oversight, sound risk management frameworks and processes, and sound AI life cycle controls.” Those are the core control categories MAS named in the parliamentary reply. For banks, that points to named ownership, documented controls and operational accountability around AI systems already in production. (mondovisione.com) For vendors selling agentic systems into banks, it means the product will need to fit into a bank’s governance stack rather than operate as a black box. That is an inference from MAS’s stated requirements on oversight, frameworks and life-cycle controls. ### Where does SAFR fit if MAS says the rules are broader? MAS drew a line between supervisory guidance and implementation tools. The regulator said Project MindForge produced an AI Risk Management Toolkit to help firms implement the guidelines, while the Safeguards for Agentic Finance at Runtime, or SAFR, sets out a possible operating model for authorising agent actions, activating human oversight and recording what happens at each consequential decision point. (mondovisione.com) A July 3 industry write-up on SAFR said the framework covers agent identity, a controls repository, a disposition engine and an audit log. It described use cases such as payments, trading orders, credit approvals, regulatory filings and insurance claims, all places where an AI agent can do more than recommend. ### Why is this different from generic AI guidance? MAS’s answer is specific to financial institutions and explicit about agentic AI. (mondovisione.com) TechTimes described Singapore as the first major financial regulator to formally put agentic AI inside binding bank rules, while OpenGov Asia separately reported that MAS chose a principles-based approach rather than highly prescriptive rules at this stage. (fintechnews.sg) The important distinction is that MAS did not create a separate “agent law.” Instead, it pulled agents into the same supervisory perimeter as other AI used by banks, then pointed firms to runtime safeguards for higher-autonomy use cases. ### What happens next for banks and suppliers? MAS said the guidelines “will be finalised soon,” but it did not give a date for any additional mandatory requirements beyond the current framework. (techtimes.com) The next concrete milestones are the final AI risk-management guidelines and further implementation work through Project MindForge and the Future of Finance Institute, both named in the August 5 parliamentary reply. (mondovisione.com)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.