Since our prior post on Singapore’s Model AI Governance Framework for Agentic AI, Singapore’s Infocomm Media Development Authority (“IMDA”) has published an updated version (Version 1.5) (the “Updated Framework”), incorporating feedback from over 60 organizations.
The Updated Framework, published on May 20, 2026, retains the same four-pillar structure—(1) assess and bound the risks upfront, (2) make humans meaningfully accountable, (3) implement technical controls and processes, and (4) enable end-user responsibility—but expands the guidance in several notable respects. These include a new discussion of multi-agent systemic risks, more granular guidance on technical controls, and real-world case studies illustrating how the Framework can be applied across sectors. We summarize some of the key updates below.
A. Expanded Risk Taxonomy, Including Systemic and Multi-Agent Risks
The Updated Framework adds additional information on the risks arising from systemic and multi-agent systems. Among the newly identified potential risks, the Framework highlights:
- Agent sprawl, where the uncontrolled proliferation of agents within an organization without centralized management leads to difficulties with provenance and compatibility.
- Collaborative failures, including miscoordination (agents interpreting the same user intent differently), conflict (agents optimizing competing objectives), and collusion (agents converging on behaviors that appear coordinated without explicit instruction—an issue the Framework notes has been studied in the context of pricing algorithms).
- Unpredictability and emergent behaviors, where the combination of multiple non-deterministic agents produces outcomes that cannot be predicted from testing each agent individually.
The Framework also adds new risk assessment factors, including system complexity (e.g., multiple interacting agents with feedback loops) and the use of third-party solutions, noting that organizations should consider the extent to which their visibility and control over an externally provided agent may be limited.
B. Refined Guidance on Human Review
The Updated Framework provides a more detailed discussion of how organizations can enable both meaningful human accountability and enable end-user responsibility. It suggests several practical human review measures organizations could take to guard against automation bias (i.e., the tendency for human overseers to over-trust agents as they become more capable). Such practices might include tracking human override rates and response times during review of agent actions, training human reviewers to identify common agentic AI failure modes and limitations, and ensuring that human reviewers have sufficient expertise to evaluate agent actions.
The Framework also discusses the risk that as agents take over entry-level tasks, basic operational knowledge could erode. The Framework frames this as a potential business continuity risk: if users no longer know how to perform critical processes manually when agents malfunction or become unavailable, organizations may face service disruptions. The Framework recommends that organizations identify core capabilities and provide sufficient training and work exposure to ensure that employees retain foundational skills.
The IMDA stresses the importance of designing agentic systems for effective human supervision, including defining significant checkpoints or action boundaries that require human approval, complemented with automated monitoring and pre-defined alert thresholds.
C. More Granular Guidance on Technical Controls
The Updated Framework provides an overview of controls for agentic systems and how to select them. At the outset, the Framework encourages organizations to consider the advantages of structural, rule-based controls as opposed to model-based or prompt-layer controls. Rule-based controls operate at the system level through pre-defined logic, which the Framework considers to be more robust overall (e.g., access controls preventing an agent from calling certain tools in the first place, rather than relying on prompt-based instructions not to use them). The Updated Framework acknowledges that certain risks may be harder to define through fixed rules, in which case model-based safeguards can be most effective (e.g., detecting harmful content, which can manifest in different ways). The Updated Framework also notes that static safeguards configured during the design phase may not be sufficient to catch every risk, so organizations should consider implementing certain runtime controls that monitor and intervene during execution, as well (e.g., rate limits to prevent excessive tool use or input validation to catch harmful responses before they are acted upon).
Overall, the Framework recommends that organizations prefer deterministic, structurally-enforced limits for higher-risk actions, and layer on additional monitoring or human-in-the-loop review where controls are less reliable. The Updated Framework also introduces new guidance on change management, noting that small modifications in complex agentic systems can cascade into larger impacts, and recommending that organizations define triggers for change review processes and categorize changes by risk level.
D. Real-World Case Studies
One of the most significant additions to the Framework is the inclusion of more than ten detailed case studies from organizations that have implemented the Framework’s principles in practice. The case studies span a range of sectors and use cases, illustrating how the Framework’s four dimensions can be operationalized in concrete deployments. Examples include:
- responsibly deploying an open-source AI agent platform following the IMDA’s Framework;
- bounding agent autonomy in financial services workflows such as source-of-wealth analysis and risk-tiered IT ticket resolution;
- designing meaningful human oversight checkpoints for agentic coding assistants and AI-powered recruitment platforms;
- implementing structural and hardware-level controls for payroll automation and compliance questionnaire completion; phased rollouts of coding assistants in the public sector; and
- transparency measures for end users interacting with HR and finance agents.
* * *
The Updated Framework reflects the rapid maturation of the agentic AI governance landscape. Its emphasis on structural (as opposed to prompt-layer) controls, automation bias, and multi-agent systemic risk aligns with themes emerging in other jurisdictions—including in CISA’s recent guidance on the careful adoption of agentic AI services, the ICO’s early views on agentic AI and data protection, and the AEPD’s guidance on agentic AI and GDPR compliance. The Framework remains a living, non-binding document, and IMDA continues to invite feedback and case studies.