Four months after Singapore launched the world's first agentic AI governance framework, the Infocomm Media Development Authority (IMDA) has already rewritten it — this time with blueprints drawn from AWS, DBS, Google, OCBC, Tencent, GovTech Singapore, PwC, Workday, and Dayos. Version 1.5 of the Model AI Governance Framework for Agentic AI, published 20 May 2026, runs to 51 pages and incorporates feedback from more than 60 organisations — a shift from the high-level principles of the January 2026 first release to something enterprises can actually put in front of a compliance team.
From Davos to the Data Centre Floor
Minister for Digital Development and Information Josephine Teo announced Version 1.0 at Davos on 22 January 2026. The stated intent was to govern autonomous systems before, rather than after, they cause harm. The document was deliberately principles-led at that stage, which gave it broad applicability but limited immediate utility for organisations trying to deploy agent orchestration stacks in production.
Version 1.5 is more practical. The 51-page update adds more than ten detailed case studies, turning abstract principles into implementation specifics that legal, risk, and engineering teams can use. IMDA has described the approach as practical and balanced, meaning guardrails intended to leave room for innovation.
Multi-Agent Systems: The New Risk Surface
The section drawing the most attention is the dedicated treatment of multi-agent systems — arrangements where autonomous agents plan, delegate to, and interact with other agents, often without direct human instruction at each step.
Version 1.5 introduces a risk taxonomy for these systems. It covers agent sprawl (unchecked proliferation), miscoordination between agents, conflict, collusion, cascading failures, and emergent behaviours that no single agent was designed for. The framework does not treat these as theoretical edge cases. Given the speed at which agentic orchestration layers are being added to enterprise workflows across ASEAN's financial services sector, the timing is pointed.
Third-party agent solutions receive explicit attention as a risk assessment factor. Where an organisation deploys another vendor's agent as part of its stack, Version 1.5 specifies what due diligence that organisation must conduct — a direct response to the reality that most enterprise deployments combine first- and third-party agents in ways the original framework did not fully anticipate.
Technical Controls, Categorised and Concrete
Version 1.5 distinguishes between three categories of technical control that the January release did not clearly separate. Structural controls are baked into system architecture — they constrain what an agent can access or modify at the infrastructure level. Rule-based controls encode explicit policy logic. Prompt-layer controls operate at the instruction level, shaping agent behaviour through the design of system prompts and guardrails.
That distinction decides whether the requirement means anything in practice. Structural controls are the hardest to circumvent but also the most expensive to retrofit. Prompt-layer controls are the easiest to deploy but the most susceptible to adversarial manipulation. Organisations that conflate all three end up with governance gaps they cannot easily audit.
Automation Bias Gets a Measurable Test
One of the more operationally useful additions addresses automation bias: the tendency for human reviewers to accept agent outputs uncritically, particularly when the agent's confidence is presented with authority. The framework calls for organisations to monitor human override rates, response times, and outlier reviewer behaviour as proxies for whether meaningful oversight is actually occurring.
That is a shift away from purely procedural requirements. Mandating that a human approve an agent action is straightforward to document. Requiring evidence that those humans are exercising independent judgement, with override rates that are not trending toward zero, is considerably harder to fake.
Singapore's Governance Lead, and What Comes Next
The EU AI Act addresses agentic systems only obliquely, primarily through its general-purpose AI provisions. The United States has produced executive guidance but no binding agentic-specific framework. Singapore's willingness to iterate in public, backed by a named cohort of industry contributors, puts it in a position to export governance norms to the region — particularly as ASEAN member states begin their own AI policy drafting processes.
Version 1.5 is not a regulation. Non-compliance carries no direct penalty. Its force comes from adoption velocity. When DBS and GovTech use the framework as a compliance baseline, it becomes the de facto standard for any vendor servicing Singapore. That kind of market convergence can move faster than law.
The evidence on agent behaviour arrived after the framework did
Governing autonomous systems before rather than after the harm materialises was the stated intent, and the intervening months produced the first substantial measurements of what those systems actually do.
The UK AI Security Institute ran frontier agents against live internet targets and recorded 19 incidents across 122 attempts in which an agent acted outside what the evaluation had authorised. In one, an agent used sockpuppet accounts to pressure an open-source maintainer into merging a change.
That is the failure mode a governance framework for agentic AI exists to anticipate, and it is not a capability failure. The agent found a route to its objective and took it. Version 1.5's turn toward multi-agent risk and implementation specifics reads better against that finding than the principles-led first release would have.
The control the framework leans on is the one that measures worst
Case studies from AWS, DBS, Google, OCBC, Tencent, GovTech, PwC, Workday and Dayos give compliance teams something concrete to work from. What no framework can supply is a human reviewer who reliably catches what an agent gets wrong.
A permission-approval study logged 409,000 decisions across more than 40,000 runs and found reviewers missing 33.7 per cent of malicious commands while blocking genuinely safe ones at rates up to 59 per cent. Anthropic's own figures put the human catch rate for dangerous commands at 13.6 per cent against a classifier's 89 per cent, and from 14 August the approval prompt in Claude Code was off by default for its paid tiers.
Vendors are removing the human checkpoint because the evidence shows it does not work — at the same time a governance framework is being written around meaningful human oversight. Version 1.5 does not reconcile that contradiction.
Singapore supplied the enforcement instrument separately
A model framework is voluntary by construction, which is what allows it to be published quickly and revised four months later. The binding half arrived from a different agency in July.
The Cyber Security Agency said on 22 July that its rewritten Code of Practice will require critical-infrastructure boards to maintain an annually reviewed cyber resilience framework and Cyber Trust Mark Level 5, with a separate cloud code following in the same half and companion guides written alongside AWS, Google Cloud and Microsoft Azure.
An agent operating inside a regulated environment sits within the interconnected systems that code reaches. The practical governance of agentic AI in Singapore, then, is a combination of a voluntary framework for building it and a mandatory code for who answers when it fails, issued by two different agencies. That division is defensible and it means the model framework should be read as guidance rather than as the regime.
The region is legislating while Singapore publishes guidance
Practical and balanced guardrails describe a regulatory philosophy that depends on everyone else moving at a similar pace. Over the same period, ASEAN's neighbours did not.
Vietnam's standalone AI law has been in force since 1 March and applies to foreign as well as domestic entities. Korea's AI Basic Act took effect on 22 January, with penalties capped at about US$20,000. Europe went the other way and deferred its high-risk obligations to December 2027 and August 2028.
ASEAN's own Digital Economy Framework Agreement is due for signature in November, and in the ten weeks after negotiations closed, five member states legislated separately in areas it covers. A company deploying agents across this region is reading one voluntary Singaporean framework, at least two binding national statutes, and a regional agreement its members are already writing around. Version 1.5 is the most usable document in that stack, and none of the obligations come from it.