Skip to content
AIAC AI ASSURANCE COUNCIL

Singapore's AI assurance ecosystem, and what it means for practitioners

§ 1 — Guide

Singapore has produced more usable AI governance material per capita than any other jurisdiction, and it has done it without passing an AI act. For practitioners working in or with Asia this matters practically: the guidance is voluntary, specific, and — unlike most national AI strategy documents — written to be applied by someone on a Tuesday.

The three generations

Singapore’s approach has moved in deliberate steps, each arriving roughly when the technology made it necessary.

Traditional AI (2020). The Model AI Governance Framework, aimed at conventional machine learning: internal governance, human-in-the-loop decisions, operations management, stakeholder communication.

Generative AI (2024). An extension addressing foundation models — provenance, content assurance, security, and the accountability problem created when the model is somebody else’s.

Agentic AI (January 2026). The Model AI Governance Framework for Agentic AI, announced by Minister Josephine Teo at the World Economic Forum on 22 January 2026, and presented by MDDI as the first framework of its kind to include enterprise guidance on deploying agentic AI responsibly.

That third one is why this ecosystem deserves attention rather than politeness.

The agentic framework, in practice

Agents differ from models in one respect that breaks most existing governance: they act. They update records, call tools, move money. The framework, developed by the Infocomm Media Development Authority (IMDA), organises the response into four dimensions:

  1. Risk assessment — selecting appropriate use cases, and limiting agent autonomy and data access to what the task requires.
  2. Human accountability — establishing checkpoints where a human approves before an action proceeds.
  3. Technical controls — baseline testing and access management across the agent lifecycle.
  4. End-user responsibility — transparency and training for the people working alongside the agent.

The framing that carries the most weight is the plainest: humans are ultimately accountable. Anyone who has tried to reconstruct why an agent did something knows the temptation to treat autonomy as a defence. This forecloses it.

Note what dimensions 1 and 2 imply for practice. “Limiting autonomy and data access” is an authorisation-boundary problem. “Checkpoints requiring human approval” is a reversibility problem — decide which actions cannot be undone, and gate those. That is a design discipline, not a policy statement.

AI Verify

AI Verify is the testing framework and software toolkit, governed by the AI Verify Foundation — an open-source body IMDA established to develop it with industry rather than for it.

What makes it unusual is that it is a toolkit, not a document. It runs technical tests and process checks and produces a report. It does not certify anything, and the Foundation is explicit about that: the output is evidence, not a verdict.

For an assurance practitioner that is the right shape. A tool producing pass/fail would be making a judgement it has no standing to make. One producing structured evidence leaves the judgement where it belongs — with a qualified person who can defend it.

The LLM Starter Kit

The Starter Kit for Testing LLM-Based Applications for Safety and Reliability is the most immediately useful artefact in the set: a step-by-step guide to identifying which risks apply to an LLM application and how to test for them, written for teams with no red-teaming function. It follows a pattern worth noting: publish something concrete, consult on it, revise.

Why voluntary is not weaker

The reflex reading is that voluntary guidance is weaker than regulation. In assurance work the opposite is often true, for a specific reason: voluntary guidance can afford to be specific. A binding rule must survive legal challenge, so it is drafted abstractly. A voluntary framework can tell you to test a particular failure mode in a particular way, because nobody will be prosecuted under it.

That is why the Starter Kit is more operationally useful than most statutory instruments, and why practitioners in Europe read Singapore’s material even where it has no force.

The financial sector shows the same pattern: the Monetary Authority of Singapore’s FEAT principles — fairness, ethics, accountability, transparency — and the Veritas initiative that followed produced assessment methodology developed with the industry rather than imposed on it.

What a practitioner is expected to do with it

If you operate in Singapore or serve Singaporean clients, the expectation is not that you have memorised the frameworks. It is that you can:

  • Identify which generation applies. A retrieval chatbot, a scoring model, and a payments agent sit under different guidance.
  • Run the Starter Kit method on a live application and interpret what the results do and do not establish.
  • Apply the four agentic dimensions to a real deployment — specifically, state which actions are irreversible and what gates them.
  • Explain to a board why voluntary guidance still creates exposure. It creates no statutory penalty. It creates an expectation, and a demonstrable departure from published national guidance is hard to defend after an incident.

The gap it leaves

Singapore has produced frameworks, toolkits, and testing methodology. What no jurisdiction has produced is a way to tell whether the person applying them is competent to do so. Guidance assumes a capable practitioner; it does not create one.

That gap is what the Council exists to close, and it is why the Agentic AI Oversight Endorsement is built around authorisation boundaries, reversibility, and evidence rather than around any single jurisdiction’s document.


Sources: MDDI — Singapore Launches New Model AI Governance Framework for Agentic AI (22 January 2026) · AI Verify Foundation · IMDA — Starter Kit for Testing LLM-Based Applications

§ 2 — Certification

Related certification track

AIAC-09 · Advanced

Agentic AI Oversight Endorsement

For practitioners assuring systems that take actions rather than produce outputs. Authorisation boundaries, reversibility, and audit trails for software that acts.

§ 3 — Related guides

Continue reading