Asked in Parliament whether SAFR becomes binding, MAS said in its written reply to a Parliamentary Question that it is taking a principles-based approach and will finalise its AI Guidelines soon.
Singapore will not convert its industry framework for AI agent runtime safeguards into mandatory supervisory requirements, according to a written reply to a Parliamentary Question from the Monetary Authority of Singapore (MAS), answered by Deputy Prime Minister and MAS Chairman Gan Kim Yong.
- The question: Ms Mariam Jaafar asked whether MAS intends to move from the industry-led Safeguards for Agentic Finance at Runtime (SAFR) framework to mandatory requirements, and on what timeline.
- The answer: MAS said it is taking a principles-based approach, and described SAFR as setting out a potential approach to authorising agent actions, activating human oversight and recording consequential decisions.
- The gap: the draft Guidelines on AI Risk Management apply to all AI use cases including agentic AI, but their hooks are board oversight, risk materiality assessment and life cycle controls.
- The clock: consultation comments closed on 31 January 2026. The only timing MAS has given since is "soon".
MAS said the proposed guidelines set out supervisory expectations for robust board and senior management oversight, sound risk management frameworks and processes, and sound AI life cycle controls.
Those expectations apply to all AI use cases by financial institutions, including agentic AI, MAS said in the reply. It added that the Guidelines will be finalised soon.
What the reply does not contain is a rule about what an agent may execute.
The three-tier chain
Only the top tier is supervisory. The consultation paper MAS issued on 13 November 2025 covers oversight of AI risk management, key systems, policies and procedures, life cycle controls, and the capabilities needed for AI use.
Its definition of AI includes machine learning, deep learning, and reinforcement learning techniques, Generative AI, AI agents, and newer developments. MAS states it will update or augment the Guidelines when necessary.

Agentic coverage, in other words, comes from definitional breadth plus a promise of revision. It does not come from agent-specific controls in the draft text.

Tier two is where the runtime moment actually lives. MAS, financial institutions and FinTechs published SAFR on 3 July 2026 as an industry white paper under the BuildFin.ai initiative.
SAFR defines how agent actions are authorised, how human oversight is activated and what is recorded at the point of every decision. It is an industry white paper, not a MAS requirement. |
Tier three is tooling. MAS concluded phase two of Project MindForge with an AI Risk Management Toolkit, comprising an AI Risk Management Operationalisation Handbook and a supplement of case studies from financial institutions.
In that same media release, MAS said it was reviewing responses to the consultation. It also said it plans to set up an AI risk management workgroup under BuildFin.ai for newer AI technologies such as agentic AI.
What supervisors will test
If an agent executes an unauthorised payment, MAS' hook is governance, not SAFR. The chief compliance officer's file will need to show the agent was inventoried, its risk materiality assessed, and an accountable owner named.

The draft guidelines set a floor even for firms barely using AI. All financial institutions should minimally institute basic policies for AI use commensurate with their level of adoption, and those policies should address who is responsible for overseeing AI.
That makes "we only run a vendor's agent" an incomplete answer at the vendor-risk lead's desk.
Foreign-owned entities face an evidence problem rather than a build. The draft permits branches and subsidiaries of parents in other jurisdictions to leverage their parents' AI risk management frameworks, provided those frameworks meet the expectations in the Guidelines.

Local compliance therefore has to map a group framework, possibly written under a different regime, to each MAS expectation. Agentic gaps in that mapping surface at inspection, not at drafting.
MAS also states the Guidelines complement its FEAT principles on Fairness, Ethics, Accountability and Transparency, alongside national initiatives including the Infocomm Media Development Authority (IMDA) Model AI Governance Framework and work under the AI Verify Foundation.
The practical benchmark for firms deploying agents now is the SAFR triad: a written authorisation scope per agent, thresholds that force human approval before execution, and immutable logging at each consequential decision.
Implementation detail, meanwhile, is migrating to industry fora. The planned BuildFin.ai workgroup on newer AI technologies is where agentic expectations will be assembled, and MAS has attached no publication date to the final Guidelines.
Read the full parliamentary reply here.
