Since our prior post on Singapore’s Model AI Governance Framework for Agentic AI, Singapore’s Infocomm Media Development Authority (“IMDA”) has published an updated version (Version 1.5) (the “Updated Framework”), incorporating feedback from over 60 organizations.

The Updated Framework, published on May 20, 2026, retains the same four-pillar structure—(1) assess and bound the risks upfront, (2) make humans meaningfully accountable, (3) implement technical controls and processes, and (4) enable end-user responsibility—but expands the guidance in several notable respects. These include a new discussion of multi-agent systemic risks, more granular guidance on technical controls, and real-world case studies illustrating how the Framework can be applied across sectors. We summarize some of the key updates below.

A. Expanded Risk Taxonomy, Including Systemic and Multi-Agent Risks

The Updated Framework adds additional information on the risks arising from systemic and multi-agent systems. Among the newly identified potential risks, the Framework highlights:

  • Agent sprawl, where the uncontrolled proliferation of agents within an organization without centralized management leads to difficulties with provenance and compatibility.
  • Collaborative failures, including miscoordination (agents interpreting the same user intent differently), conflict (agents optimizing competing objectives), and collusion (agents converging on behaviors that appear coordinated without explicit instruction—an issue the Framework notes has been studied in the context of pricing algorithms).
  • Unpredictability and emergent behaviors, where the combination of multiple non-deterministic agents produces outcomes that cannot be predicted from testing each agent individually.

The Framework also adds new risk assessment factors, including system complexity (e.g., multiple interacting agents with feedback loops) and the use of third-party solutions, noting that organizations should consider the extent to which their visibility and control over an externally provided agent may be limited.

B. Refined Guidance on Human Review

The Updated Framework provides a more detailed discussion of how organizations can enable both meaningful human accountability and enable end-user responsibility. It suggests several practical human review measures organizations could take to guard against automation bias (i.e., the tendency for human overseers to over-trust agents as they become more capable). Such practices might include tracking human override rates and response times during review of agent actions, training human reviewers to identify common agentic AI failure modes and limitations, and ensuring that human reviewers have sufficient expertise to evaluate agent actions.

The Framework also discusses the risk that as agents take over entry-level tasks, basic operational knowledge could erode. The Framework frames this as a potential business continuity risk: if users no longer know how to perform critical processes manually when agents malfunction or become unavailable, organizations may face service disruptions. The Framework recommends that organizations identify core capabilities and provide sufficient training and work exposure to ensure that employees retain foundational skills.

The IMDA stresses the importance of designing agentic systems for effective human supervision, including defining significant checkpoints or action boundaries that require human approval, complemented with automated monitoring and pre-defined alert thresholds.

C. More Granular Guidance on Technical Controls

The Updated Framework provides an overview of controls for agentic systems and how to select them. At the outset, the Framework encourages organizations to consider the advantages of structural, rule-based controls as opposed to model-based or prompt-layer controls. Rule-based controls operate at the system level through pre-defined logic, which the Framework considers to be more robust overall (e.g., access controls preventing an agent from calling certain tools in the first place, rather than relying on prompt-based instructions not to use them). The Updated Framework acknowledges that certain risks may be harder to define through fixed rules, in which case model-based safeguards can be most effective (e.g., detecting harmful content, which can manifest in different ways). The Updated Framework also notes that static safeguards configured during the design phase may not be sufficient to catch every risk, so organizations should consider implementing certain runtime controls that monitor and intervene during execution, as well (e.g., rate limits to prevent excessive tool use or input validation to catch harmful responses before they are acted upon).

Overall, the Framework recommends that organizations prefer deterministic, structurally-enforced limits for higher-risk actions, and layer on additional monitoring or human-in-the-loop review where controls are less reliable. The Updated Framework also introduces new guidance on change management, noting that small modifications in complex agentic systems can cascade into larger impacts, and recommending that organizations define triggers for change review processes and categorize changes by risk level.

D. Real-World Case Studies

One of the most significant additions to the Framework is the inclusion of more than ten detailed case studies from organizations that have implemented the Framework’s principles in practice. The case studies span a range of sectors and use cases, illustrating how the Framework’s four dimensions can be operationalized in concrete deployments. Examples include:

  • responsibly deploying an open-source AI agent platform following the IMDA’s Framework;
  • bounding agent autonomy in financial services workflows such as source-of-wealth analysis and risk-tiered IT ticket resolution;
  • designing meaningful human oversight checkpoints for agentic coding assistants and AI-powered recruitment platforms;
  • implementing structural and hardware-level controls for payroll automation and compliance questionnaire completion; phased rollouts of coding assistants in the public sector; and
  • transparency measures for end users interacting with HR and finance agents.

*  *  *

The Updated Framework reflects the rapid maturation of the agentic AI governance landscape. Its emphasis on structural (as opposed to prompt-layer) controls, automation bias, and multi-agent systemic risk aligns with themes emerging in other jurisdictions—including in CISA’s recent guidance on the careful adoption of agentic AI services, the ICO’s early views on agentic AI and data protection, and the AEPD’s guidance on agentic AI and GDPR compliance. The Framework remains a living, non-binding document, and IMDA continues to invite feedback and case studies.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Jadzia Pierce Jadzia Pierce

Jadzia Pierce advises clients developing and deploying technology on a range of regulatory matters, including the intersection of AI governance and data protection. Jadzia draws on her experience in senior in house leadership roles and extensive, hands on engagement with regulators worldwide. Prior…

Jadzia Pierce advises clients developing and deploying technology on a range of regulatory matters, including the intersection of AI governance and data protection. Jadzia draws on her experience in senior in house leadership roles and extensive, hands on engagement with regulators worldwide. Prior to rejoining Covington in 2026, Jadzia served as Global Data Protection Officer at Microsoft, where she oversaw and advised on the company’s GDPR/UK GDPR program and acted as a primary point of contact for supervisory authorities on matters including AI, children’s data, advertising, and data subject rights.

Jadzia previously was Director of Microsoft’s Global Privacy Policy function and served as Associate General Counsel for Cybersecurity at McKinsey & Company. She began her career at Covington, advising Fortune 100 companies on privacy, cybersecurity, incident preparedness and response, investigations, and data driven transactions.

At Covington, Jadzia helps clients operationalize defensible, scalable approaches to AI enabled products and services, aligning privacy and security obligations with rapidly evolving regulatory frameworks across jurisdictions—with a particular focus on anticipating enforcement trends and navigating inter regulator dynamics.

Photo of Sam Jungyun Choi Sam Jungyun Choi

Recognized by Law.com International as a Rising Star (2023), Sam Jungyun Choi is an associate in the technology regulatory group in Brussels. She advises leading multinationals on European and UK data protection law and new regulations and policy relating to innovative technologies, such…

Recognized by Law.com International as a Rising Star (2023), Sam Jungyun Choi is an associate in the technology regulatory group in Brussels. She advises leading multinationals on European and UK data protection law and new regulations and policy relating to innovative technologies, such as AI, digital health, and autonomous vehicles.

Sam is an expert on the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act, having advised on these laws since they started to apply. In recent years, her work has evolved to include advising companies on new data and digital laws in the EU, including the AI Act, Data Act and the Digital Services Act.

Sam’s practice includes advising on regulatory, compliance and policy issues that affect leading companies in the technology, life sciences and gaming companies on laws relating to privacy and data protection, digital services and AI. She advises clients on designing of new products and services, preparing privacy documentation, and developing data and AI governance programs. She also advises clients on matters relating to children’s privacy and policy initiatives relating to online safety.