How Singapore's AI governance framework evolved
Singapore's Model AI Governance Framework (MAIG) isn't new - IMDA and the PDPC first issued it in 2019, with a second edition in 2020, as voluntary cross-sector guidance on responsible AI use. In 2024, IMDA released a dedicated extension for generative AI, addressing risks that framework wasn't built for: hallucinations, bias, intellectual property, content provenance, cybersecurity, and systemic risk. In January 2026, it extended again - this time for agentic AI, addressing governance challenges posed by autonomous or semi-autonomous agents capable of independent decision-making.
What the agentic extension actually asks for
Human oversight, proportionate to risk
The framework asks organizations to define where human approval gates genuinely belong in an agent's decision chain, scaled to the consequences of getting it wrong - not blanket human review of every action.
Internal governance structure
A named accountability chain for an agent's decisions - who's responsible when an autonomous action produces an unexpected outcome, documented before deployment, not improvised after an incident.
Risk management scaled to autonomy
The more independently an agent can act - especially with tool access that has real-world effect, like sending payments or modifying records - the more rigorous the pre-deployment risk assessment the framework expects.
Stakeholder transparency
Communicating to affected users and stakeholders when they're interacting with, or being acted upon by, an autonomous system - the agentic-AI counterpart to the EU AI Act's chatbot disclosure requirement.
Building or buying an agentic system and want to know how it holds up against MAIG's expectations? Talk to us about an agentic AI governance review.
The related PDPA guidance worth tracking alongside it
A related but separate thread: the PDPC published Proposed Advisory Guidelines on Use of Personal Data in Generative AI on June 2, 2026, with public consultation closing July 14, 2026. That guidance addresses data protection specifically - how personal data can be used in training, fine-tuning, and inference - while MAIG's agentic extension addresses the broader governance question of an autonomous system's decisions and actions. A production agentic system touching personal data typically needs to satisfy both threads, not just one.
Why "voluntary" doesn't mean "optional" in practice
Two forces make MAIG alignment a practical requirement even without legal force. First, Singapore's approach to AI regulation has consistently been framework-first, legislation-later - which means today's voluntary guidance is a credible preview of where future binding requirements land, and building to it now avoids a retrofit later. Second, enterprise and government procurement in Singapore increasingly asks vendors directly whether their AI systems are designed against MAIG's principles - a "no" is a genuine competitive disadvantage in an RFP, framework or not.
| MAIG milestone | Date | Focus |
|---|---|---|
| Original framework | 2019 (2nd edition 2020) | General responsible AI use, cross-sector |
| Generative AI extension | 2024 | Hallucinations, bias, IP, content provenance, systemic risk |
| Agentic AI extension | Jan 2026 | Autonomous/semi-autonomous decision-making systems |
| PDPA generative AI guidance (proposed) | Jun-Jul 2026 | Personal data use in training and inference |
Key takeaways
- IMDA's January 2026 agentic AI extension to the Model AI Governance Framework addresses autonomous decision-making risks the earlier editions didn't cover.
- It's voluntary guidance, not legislation - but it's the clearest signal of where Singapore's future binding AI rules are likely headed.
- Core asks: proportionate human oversight, named accountability, risk assessment scaled to autonomy, and stakeholder transparency.
- Enterprise and government procurement increasingly treats MAIG alignment as a real vendor-evaluation criterion, making it a practical requirement despite lacking legal force.
Zetrixweb