On 5 August 2026, the MP Mariam Jaafar tabled a question in Singapore’s parliament that is rarely asked so plainly. She wanted to know whether the Monetary Authority of Singapore (MAS) intends to move from an industry-led framework to mandatory supervisory requirements, and if so, on what timeline. Gan Kim Yong, Deputy Prime Minister and Chairman of MAS, replied in writing the same day. The reply contains no commitment and no date. That is not an omission. It is the position.

Anyone who reads that as Singapore lagging behind Europe has not looked at the European rules. The AI Act does not mention agentic AI once, and the Digital Omnibus Regulation of 8 July 2026 brings the term into European law exactly once: as the residual code for everything that fits no other box. Two regulators reach the same conclusion by different routes: there will be no dedicated regime for agents. That is not a regulatory gap but a shift in who has to justify the answer, and that burden comes to rest wherever the agent runs.

In brief

What: written reply from the Monetary Authority of Singapore to a parliamentary question on autonomous AI agents in financial services, published on 5 August 2026

The question: whether the regulator will move to mandatory supervisory requirements, and on what timeline

The answer: a principles-based approach, supervisory expectations, and finalisation of the Guidelines “soon” with no date attached

Status of the Guidelines: consulted on from 13 November 2025 to 31 January 2026; the final version is still outstanding

What is absent: a dedicated regime for agents. None exists, and none has been announced

The refusal sits in the first sentence of the reply

A written parliamentary question is a useful device for pinning down a regulator, because the answer has to be given in writing. Mariam Jaafar took the opportunity to ask in three parts: about the near-term risks of increasingly autonomous agents, about any intention “to move from the current industry-led Safeguards for Agentic Finance at Runtime (SAFR) framework towards mandatory supervisory requirements”, and about the timeline. Parts two and three elicited neither a commitment nor a date. Instead, Gan Kim Yong opens with a statement of principle: “Given AI’s fast-evolving nature, MAS is taking a principles-based approach to guide safe and responsible AI adoption.” That is the refusal, politely phrased and placed exactly where a commitment would have stood.

The reply describes SAFR itself as a possible industry-led approach to “how agent actions are authorised, how human oversight is activated, and what is recorded at the point of every consequential decision”. Behind that sits a white paper MAS published on 3 July 2026 together with financial institutions and technology firms. Page one of that paper carries the sentence that sums up the whole arrangement: its contents, it states, “do not constitute regulatory, financial, legal or any other professional advice”. The only document in Singapore that treats agentic AI in any detail expressly denies that it is regulation. It is useful all the same: it describes a checkpoint between decision and execution at which every agent action takes one of four routes. One of them, “Escalate”, holds the action for human review.

The decisive sentence comes in the second paragraph of the reply. The Guidelines under consultation, MAS says, “apply to all AI use cases by FIs, including agentic AI, and will be finalised soon”. Agentic AI is therefore covered, though not separately.

The sharpest document on agentic AI in Singapore denies, on page one, that it is regulation. Christian Schablitzki, the agentic banker

An expectation is not a statute, and the difference is the penalty regime

The distinction matters, and it is easily lost in translation. The consultation paper of 13 November 2025 describes its own subject matter as a supervisory expectation rather than as law: “The Guidelines on Artificial Intelligence (AI) Risk Management (AIRG) set out MAS’ supervisory expectations relating to AI risk management in financial institutions”. An expectation of that kind is far from toothless. It is the yardstick the regulator applies in day-to-day supervision, so departures need to be explained. But it is not a statute with a penalty regime attached. Anyone placing the MAS Guidelines alongside the AI Act in a board paper is comparing two different legal instruments and should say so.

On implementation, MAS proposes a transition period: “MAS proposes to provide a transition period of 12 months after the Guidelines are issued, for FIs to assess and implement the Guidelines as appropriate.” Two details are routinely got wrong. The period is a proposal put out for comment, appearing as Question 10 of the consultation paper. And it runs from the date the Guidelines are issued, not from today. Since no issue date has been fixed, the end of the transition period is unknown too. An implementation plan pegged to a 2027 deadline is pegged to a date nobody has given.

The word is missing, the failure mode is described

The text itself says more than any summary of it. Count through the thirty-page consultation paper and this is what you get: the word “agentic” does not appear at all, while “AI agents” appears thirteen times, and does so substantively. Those counts are our own reading of the published full text, not figures supplied by the regulator.

The description of the risks is specific. The paper describes agents as technologies “that leverage Generative AI, but with greater autonomy and the ability to access tools”, and identifies two distinct failure modes: “compromised AI agents could exfiltrate sensitive data or execute malicious commands”, and a “divergence between human goals and how the AI agent translated such goals into actions”. The first is a security problem, the second a control problem. Both are cleanly stated, and they are independent of one another: an agent whose access is watertight can still pursue the wrong objective.

That reflects a deliberate design decision. For MAS, agents amplify existing risks rather than forming a category of their own. Search the paper for the fashionable term, fail to find it, and you may well conclude that the topic has been left out. In fact it sits inside a framework that applies to all AI.

Europe reached the same conclusion, more quietly

The comparison runs against the usual story of a Europe that regulates everything. The AI Act, formally Regulation (EU) 2024/1689, uses the terms “agentic” and “AI agent” not once in a text running to well over a hundred pages. The amendment barely changes that: the Digital Omnibus Regulation on AI, Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026, mentions agentic AI exactly once. These two counts are likewise our own reading of the Official Journal texts.

That single passage sits in a list of classification codes and reads in full: “AIA Code AIH 0401 AI systems based on other emerging AI technologies not covered by other codes, including Agentic AI”. The category heading above it is “Emerging AI technologies”. The list is used by conformity assessment bodies when they apply for notification under Article 29. The entry imposes no substantive requirement; it is an administrative identifier. European legislation has taken the term on board and, in the very act of doing so, filed it under miscellaneous.

Supervisors have said little more, and where they mention AI agents at all, they do so in speeches rather than in binding text. Mark Branson, president of Germany’s Federal Financial Supervisory Authority (BaFin), told the BaFinTech conference in Berlin on 2 July 2025 that the next stage would be software systems that analyse data on their own, take decisions and carry those decisions out without human involvement. Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, asked whether the market needs a kill switch for AI trading agents, at the European Central Bank’s Sintra forum on 30 June 2026. Both are speeches, and a speech binds nobody. BaFin’s own risk outlook for 2026, which discusses AI in several places, does not use the term AI agent anywhere in the published print edition.

Both jurisdictions therefore arrive at the same place by different routes. Singapore states, when asked directly, that there is no dedicated agent regime. Europe never states it; the result follows from how the AI Act is built. A credit scoring agent is regulated in the European Union not because it is an agent, but because creditworthiness assessment is classed as high-risk under Annex III. The obligations attach to the use case, not to the architecture. When they bite has now shifted: sections 1 to 3 of Chapter III, with the exception of Article 6(5), apply to Annex III systems from 2 December 2027 and to Annex I systems from 2 August 2028. The original date of application was 2 August 2026.

The interpretation risk moves to the firm

The shared approach has a defensible rationale. Define a technology today and you will have defined it wrongly by tomorrow. A regime built around the word “agent” would need to draw a legally robust boundary around it, and nobody can currently do that. The price is equally clear. Principles-based expectations work through interpretation, and interpretation needs cases. Until supervisory practice on agents exists, every institution carries the interpretative risk. That is the uncomfortable side of flexibility: it moves the onus from the rule-maker to the regulated firm.

How a principles-based rule behaves in practice can be seen from a precedent the trading floor has known for two decades. The best execution obligation, the duty to execute client orders on terms most favourable to the client, has been EU law since MiFID I, and it sat there as a principle without saying which venue is the right one in any given case. It became testable only through supervisory practice and through supplementary reporting requirements, some of which were later repealed. In the years between, the interpretation risk sat entirely with the executing firm, and it could be neither delegated nor insured against. With agentic AI the same cycle is beginning again. The difference is that this time the subject matter changes faster than the practice meant to interpret it.

Anyone who reads that shift as a relief has misread who benefits from it. A binding requirement tells a firm what to do and, in doing so, also limits what can be demanded of it. An expectation does neither. It leaves open how much control is enough, and the answer comes in the end from the supervisor rather than from the paper. The closing sentence of the parliamentary reply matters for that reason. MAS says it will “continue to review our supervisory expectations and update them where necessary”. That is not a promise, nor is it a closed door. Anyone following the sector should put the question again in twelve months.

There is nothing to wait for

An institution that defers its agent governance until “the agent rules arrive” is waiting for an event that, on current evidence, will not occur. Neither MAS nor the EU legislator has announced such a regime, and in Singapore the absence of any announcement is now on the parliamentary record.

The converse also holds. Build your existing AI governance so that it can distinguish degrees of autonomy, and you satisfy both frameworks at once. In the consultation paper, MAS expects board and senior management oversight, sound frameworks and controls across the life cycle. For high-risk systems, the AI Act requires documentation, risk management and human oversight. These are not identical, but they are the same shape, and a firm that builds that shape once builds it for both jurisdictions. The rule being waited for is not coming. The supervisor is.

Recommendations

1. Add the degree of autonomy to the existing model inventory rather than building a second register

Now: both frameworks handle agents within general AI governance. A separate agent register creates maintenance work and a second version of the truth. What works is an additional attribute on the existing entry: what the system may trigger by itself, which tools and systems it can reach, and where its authority ends.

2. Adopt the two MAS failure modes as review questions

This month: the consultation paper names them precisely and independently of one another. First, the compromised agent that leaks data or executes commands, which is a security question. Second, the divergence between a human goal and the way the agent translated it into action, which is a control question. Test only the first and you have tested half.

3. Keep the legal status straight in your own communication

Ongoing: a supervisory expectation, a regulation and an industry standard are three different things. Put them side by side in a board paper without labelling them and you invite the question of whether the analysis holds. For Singapore the answer is expectation. For the AI Act it is directly applicable law with staggered dates of application.

4. Prioritise by use case, not by technology

In planning: whether an agent is caught by the high-risk obligations turns on what it is used for. Creditworthiness assessment falls under Annex III; an internal research assistant does not. Prioritising by degree of autonomy alone is misleading; what matters is the combination of use case and authority to act. The date to plan against for Annex III is 2 December 2027.

Glossary

SAFR: Safeguards for Agentic Finance at Runtime, an industry-led framework MAS published on 3 July 2026 with financial institutions and technology firms. It sets out how agent actions are authorised, overseen by a human and recorded, and it expressly denies that it is regulation.

Supervisory expectation: the yardstick a regulator applies to a firm in day-to-day supervision. Departure is permitted but must be explained. Unlike a regulation, it carries no penalty regime of its own.

Annex III: the AI Act’s list of high-risk use cases, including creditworthiness assessment of natural persons, but excluding systems used to detect financial fraud. Classification turns on the intended purpose, not on the technical shape of the system.

AIA Code AIH 0401: the identifier under which agentic AI first appears in European legal text. It belongs to a list that conformity assessment bodies use when applying for notification, and it creates no obligation of its own.