Framework
Agentic AI oversight
What actually governs an AI system that plans and acts on its own — which is far less than the volume of writing about it suggests. One non-binding framework, one unfinalised supervisory draft, and a body of general law written before agents existed.
§ 1 — Orientation
How Agentic AI oversight is put together
It is worth starting with a fact that can be checked in an afternoon. The word "agentic" appears exactly once in European Union AI legislation, and it is not a regulatory provision: the Digital Omnibus inserts a new Annex XIV into the AI Act listing the codes a notified body uses when applying for a scope of designation, and one of them covers emerging technologies "including Agentic AI". It creates no duty for anyone. There is no agentic chapter, no agentic tier, and no agentic threshold. An agent is regulated, where it is regulated at all, by provisions drafted for systems that did not act on their own.
What fills the gap is guidance. Singapore’s IMDA published a Model AI Governance Framework for Agentic AI, now at version 1.5, and it is the most detailed treatment any government has produced — but it recommends rather than requires, uses "should" throughout, and carries no enforcement of any kind. The Monetary Authority of Singapore has consulted on guidelines that reach agents through general provisions on autonomy and oversight, and that consultation closed without the guidelines being issued. Neither is law today, and pages that present either as binding are the most common error in this area.
That does not make the questions unanswerable, and it is why these pages are worth having. Where an agent is deployed inside a high-risk system the AI Act reaches it — through record-keeping, through human oversight, through the deployer duties — and where it is deployed by a financial institution the existing supervisory expectations already apply. The rest is assurance practice: what bounds an agent’s authority, what a trajectory must capture, which actions cannot be undone and must therefore be gated, and what an assessor asks to see. Each page states plainly what has force and what does not, because the difference is the whole of the advice.
§ 2 — By who it binds
Obligations by role
On the deployer
Whoever uses the system under their own authority, in the course of their activity.
- IMDA Agentic AI Framework v1.5 §2.1Assess and bound the risks upfront
No binding instrument requires an organisation to decide what an AI agent may and may not do.
§ 3 — By when it applies
Obligations by date
The date each obligation first bites, earliest first. Where a provision applies on more than one date, the earliest is shown.
§ 4 — Elsewhere
The same ground, cut differently
Certification
Assessed on the same standard of evidence
Every Council credential is examined on applied judgement against a published anchor, set out the way the obligations on this page are. The free AI Literacy Certificate is open to any adult today, and the register lists what is open for enrolment.