Approaches to Agentic AI Governance in Singapore and the UK
Singapore and the United Kingdom (“UK”) have both positioned themselves as pro-innovation hubs for artificial intelligence (“AI”) without horizontal AI-specific statutes. Singapore’s approach to agentic AI centres on building governance tools to support responsible deployment, including guidance, testing resources and data-protection obligations. The UK organises AI governance through a principles-based, sector-led model in which regulators apply existing rules, including data protection, consumer protection and financial services, to AI use cases.
Singapore and the UK share the same objective of enabling responsible adoption of agentic AI, but take different institutional pathways. The following provides a high-level overview.
Governance Challenges of Agentic AI
Agentic AI differs from generative AI because it can pursue goals, plan steps, retrieve real-time data, use tools, interact across systems and, in some cases, take actions such as making payments on a user’s behalf.
This shifts the risk from inaccurate outputs to erroneous or unauthorised actions, biased or unfair decisions, data breaches and disruption to connected systems. The governance question is therefore not only whether the agent is accurate, but what it is allowed to do, what it may access, when a human must approve its actions and who remains responsible if something goes wrong.
Singapore’s Deployment Playbook
Governance Framework
Singapore’s agentic AI governance is led by the Infocomm Media Development Authority (“IMDA”) and centred on its Model AI Governance Framework for Agentic AI (“Agentic AI Framework”), which provides guidance on managing the risks associated with deploying agentic AI systems.
The Agentic AI Framework is structured around four core dimensions: (1) assessing and bounding risk, (2) ensuring meaningful human accountability, (3) implementing technical controls and processes, and (4) enabling end-user responsibility.
First published by IMDA in January 2026, the Agentic AI Framework was further updated in May 2026. The updates reinforce its iterative character, reflect industry feedback and add new best practices and practical case studies to address issues such as multi-agent systems, third-party agents and automation bias.
Supporting Rules and Tools
The Agentic AI Framework overlays a combination of data-protection law, voluntary guidance, testing and assurance tools. The Personal Data Protection Act 2012 (“PDPA”) is binding law and applies where organisations deploy agents that collect, use or disclose personal data. The PDPA is administered and enforced by Singapore’s Personal Data Protection Commission (“PDPC”), whose Advisory Guidelines on Use of Personal Data in Generative AI (“GenAI Guidelines”), published on 20 July 2026, provide guidance on how the PDPA applies to the use of personal data in generative AI models and systems, but do not create binding legal obligations beyond the requirements of the PDPA.
IMDA and the AI Verify Foundation have also developed voluntary guidance and testing resources. These include the Model AI Governance Framework for Generative AI, applicable where agents are built on generative AI models, and AI Verify and the Starter Kit for Testing LLM-based Applications, which support testing and assurance for AI and generative AI applications. In addition, IMDA’s Transparency Guidelines for Generative AI Chatbots are aimed at generative AI chatbots and can serve as a reference point for other user-facing applications, demonstrating how organisations can provide clear and accessible information about an AI system’s capabilities, reliability, safety, data handling and reporting channels.
From Framework to Practice
Where the PDPA applies, if the agent collects, uses or discloses personal data, organisations need to consider consent or other authorisation, purpose limitation, data accuracy, protection, retention and data breach notification risks. Where generative AI is involved, the GenAI Guidelines add practical points on AI-specific notifications, allocation of responsibilities between model providers, system providers and deployers, publicly available data, access and correction requests.
IMDA has also published a case study on OpenClaw, showing how the Agentic AI Framework applies in practice. OpenClaw is an open-source AI agent that can act as an autonomous personal assistant through common chat interfaces. IMDA notes that safe deployment requires careful setup because OpenClaw has limited built-in security controls. The case study recommends least-privilege access, human oversight, secure integrations and continuous monitoring.
In addition, IMDA published a discussion paper on the legal responsibility for AI agents (May 2026), examining how existing private law frameworks may allocate responsibility where AI agents act autonomously, interact with third parties or cause harm. The paper focuses on civil liability and is expressly not a settled statement of the law.
Sector-specific guidance is also beginning to develop. In financial services, the Monetary Authority of Singapore (“MAS”), together with financial institutions and fintech firms, has published Safeguards for Agentic Finance at Runtime (“SAFR Framework”), an industry white paper published on 3 July 2026 under the BuildFin.ai initiative. The paper expressly states that it does not constitute regulatory guidance or supervisory expectations, but shows how Singapore’s agentic AI governance can become more specific in higher-stakes contexts.
UK’s Sectoral Governance
Regulatory Model
Like the PDPA in Singapore, the United Kingdom General Data Protection Regulation (“UK GDPR”), as amended by the Data (Use and Access) Act 2025 (“DUAA”), is the main data-protection law applicable to UK deployments, including where an agent processes personal data or supports automated decision-making.
The UK has no single agentic AI playbook equivalent to Singapore’s Agentic AI Framework. The current approach therefore largely turns on what an AI agent does, rather than the technology itself.
The UK addresses agentic AI risks through existing sectors. The Digital Regulation Cooperation Forum (“DRCF”), which is comprised of key regulators including the Information Commissioner’s Office (“ICO”) for data protection, the Competition and Markets Authority (“CMA”) for competition and markets, the Financial Conduct Authority (“FCA”) for financial services, and Ofcom, has published work on the cross-regulatory implications of agentic AI, reflecting growing coordination across sectors.
Supporting Rules and Guidance
The ICO’s 2026 report, Tech Futures: Agentic AI, is not formal regulatory guidance, but identifies agent-specific data-protection issues including responsibility across supply chains, automated decision-making, broad processing purposes, transparency, special category data inference, cybersecurity and the concentration of personal information in personal-assistant agents. Following DUAA, the ICO is updating its guidance on automated decision-making and profiling and is developing dedicated guidance on agentic AI as part of its 2026/27 workplan.
The CMA, in its guidance Using AI Agents: Complying With Consumer Law, makes clear that businesses remain responsible for their AI agents, including those developed or supplied by third parties. The CMA has also identified broader consumer and competition risks associated with agentic AI, including manipulation, over-reliance and possible anti-competitive practices. The guidance confirms that existing consumer law applies in the same way whether a consumer is engaging with a human or an AI agent.
In contrast to Singapore’s SAFR Framework, there does not appear to be FCA guidance specifically directed at agentic AI in financial services. The UK financial-services position is currently addressed through the FCA’s broader AI and innovation work, including AI Live Testing and the Supercharged Sandbox, which support firms testing novel AI-driven services in real-world or controlled conditions.
From Regulation to Practice
For organisations operating in the UK, the analysis should consider whether the agent interacts with consumers, processes personal data, makes or supports significant decisions, affects pricing, ranking or recommendations, operates in financial services or accesses particular systems.
The UK’s approach offers continuity but presents new challenges for agent deployment. The underlying legal frameworks are familiar, but applying them to increasingly autonomous systems raises novel practical issues. Nevertheless, the ICO, CMA and FCA examples point in the same direction. Businesses need evidence that agent design, data access, testing, monitoring and human oversight are matched to the risks of the relevant use case.
Future Outlook
Rather than indicating that horizontal AI legislation is imminent, Singapore is continuing to build a pro-innovation, iterative and framework-led agentic AI governance model, using voluntary guidance, testing and assurance tools, data-protection law and sector-specific initiatives.
The UK has signalled that it will legislate where necessary, but the direction of AI policy under Prime Minister Burnham’s government remains to be seen. Agentic AI regulation will likely remain tied to existing sectoral regimes, with greater coordination between regulators rather than a single AI authority. Under DUAA, the ICO will transition into the Information Commission, and its core data-protection functions will transfer to the new body.
Key Takeaways
Singapore and the UK are converging on many of the same practical controls for agentic AI, including constrained autonomy, meaningful human oversight, transparency, testing, monitoring, auditability and secure deployment. Singapore offers a clearer central playbook, supported by PDPA obligations, guidance and assurance tools, while the UK addresses similar risks through existing regulators and legislation such as UK GDPR.
Organisations in both jurisdictions should determine what an agent may do, limit its access, test its behaviour, monitor its use and ensure human accountability.

