The Monetary Authority of Singapore, together with financial institutions and FinTechs, published an industry white paper on 3 July 2026 setting out how AI agents in financial services should be governed at the moment they act. The paper, "Safeguards for Agentic Finance at Runtime" — SAFR — proposes a framework of governance checkpoints that verify and record an agent's proposed actions before those actions are executed. It was developed under MAS's BuildFin.ai initiative and, in MAS's description, builds on the AI Risk Management toolkit from the regulator's earlier Project Mindforge programme. MAS says contributors included financial institutions and FinTechs; industry coverage named participants such as Ant International, Circle, HSBC and J.P. Morgan.

The framing matters before the mechanics: SAFR is a voluntary, industry-developed framework, not a regulation or a binding directive. It proposes a direction and a set of design principles, and leaves adoption to institutions.

What is actually new: governing the action, not the model

The most useful idea in the paper is a distinction it draws carefully. Controls built into an AI agent — content filtering, prompt defences and similar guardrails — screen the model's outputs for harmful, malformed or policy-violating content before they leave the model. Those controls are necessary, the paper argues, but they do not determine whether a proposed financial action is authorised or executable. An agent with clean outputs can still propose a payment above its authority, a trade outside its permitted instruments, or a filing it was never delegated to make.

The SAFR paper proposes placing a governance layer in that gap. As the paper describes it, SAFR sits between the agent and the execution environment, taking each proposed action and evaluating it deterministically against the mandates, policies and risk boundaries the institution has defined — deciding whether the action can be executed, must be escalated for a human decision, or must be rejected — before it reaches the systems that would carry it out. In the paper's own architecture, model-level guardrails govern what an agent may say; SAFR governs what it may do.

That reflects a structural change in how AI is being used in finance. Earlier deployments generally produced outputs for a human to review and then execute. Agentic systems can plan intermediate steps, select tools and initiate consequential actions directly in live environments, at a speed that may make continuous human oversight impractical. When the human is no longer reliably in the loop at the point of execution, a governance layer at that point becomes the control that matters.

The four principles

SAFR sets out four properties for institutions to embed into system operations: policy-bound execution, so an agent's actions are constrained to what it is explicitly permitted to do; real-time validation, so proposed actions are checked at the moment they are made rather than after the fact; auditability, so every proposed action and decision is recorded; and interoperability, so the safeguards can work across different systems and agent implementations rather than being locked to one vendor's stack.

Industry members have already applied the framework to concrete workflows. The paper cites agent-assisted payments and treasury operations, where agents execute routine transactions within predefined mandates; wealth-management and advisory work, where agents review documents and produce structured assessments inside narrowly scoped task boundaries; and client engagement, where agents draft materials and generate insights within approved content boundaries. In each, the common thread is a bounded mandate with a checkpoint enforcing it.

Why the regional lens is genuine here

This is a Singapore-specific move with a wider signal. Much of the global debate on AI governance sits at the model layer — how a model is trained, tested and disclosed — or at the disclosure layer, through transparency obligations. SAFR is an attempt to govern at the action layer, which is where financial risk actually crystallises. For a financial centre positioning itself as a place to deploy agentic systems in production, that is a deliberate emphasis: trust in agentic finance, on this view, is built less by constraining the model in the abstract and more by controlling what any agent is allowed to execute against real accounts and instruments.

It is also consistent with how MAS has tended to operate — convening industry to co-develop a practical framework under a named programme, rather than issuing prescriptive rules first. Similar ideas are surfacing elsewhere in the market, if less formally: transaction-approval policies in banking copilots, and tool-permission and human-in-the-loop approval systems in enterprise AI agents, all point at the same instinct to gate what an agent is allowed to execute. Whether MAS's convening approach produces faster, more workable safeguards or simply slower-binding ones is the open question that adoption will answer.

Key Takeaways

  • MAS and industry partners published the SAFR framework on 3 July 2026 to govern AI agents in finance at the point of action.

  • SAFR is a voluntary, industry-developed white paper under MAS's BuildFin.ai initiative — not a regulation — building on Project Mindforge's AI Risk Management toolkit.

  • It sits between the agent and the execution environment, checking and recording proposed actions against institutional mandates before they run.

  • Four principles: policy-bound execution, real-time validation, auditability and interoperability.

  • Its central insight: model-level guardrails govern an agent's outputs, but not whether a financial action is authorised — that requires runtime governance.