Most governance documents are written after the technology settles. Singapore keeps writing them while it is still moving, which is why one city-state's voluntary framework has quietly become the reference point that regulators elsewhere read before drafting their own. If you deploy AI anywhere in Asia, and increasingly anywhere at all, the Model AI Governance Framework is the document your counterparties have read, whether or not you have.
This piece covers the whole family: the original 2019 framework, the May 2024 generative AI edition and its nine dimensions, and the January 2026 agentic AI framework, which is the first governance document any jurisdiction has written specifically for AI agents. I have covered the agentic framework in detail in a separate piece; this one is the map of how the parts fit.
What is the Model AI Governance Framework?
The Model AI Governance Framework is Singapore's voluntary guidance for deploying AI responsibly, published by the Infocomm Media Development Authority (IMDA). First released in January 2019 and revised in January 2020, it has since been extended twice: for generative AI in May 2024 and for agentic AI in January 2026.
The word to take seriously in that answer is "model." It is not a statute and carries no penalties. It is a template: a statement of what responsible deployment looks like, written so that organisations can adopt it directly and other governments can borrow from it. Both things have happened. The 2019 edition was launched at Davos as a deliberate export, and its vocabulary shows up in corporate AI policies across the region.
The publisher matters too. IMDA sits under Singapore's Ministry of Communications, and since 2023 it has worked through the AI Verify Foundation, its wholly owned not-for-profit subsidiary, which also maintains open-source testing tooling. The framework family is therefore unusual among governance documents in having an implementation arm: the people who write the expectations also ship software for checking against some of them.
Is the Model AI Governance Framework mandatory?
No. Every edition is voluntary, and Singapore has deliberately avoided an omnibus AI statute. But voluntary is not the same as optional in practice: the framework shapes procurement questionnaires, board expectations and sectoral regulator guidance in Singapore, so organisations deploying AI there encounter its vocabulary as a de facto requirement.
This is the part foreign teams misread. Singapore regulates AI the way it often regulates: through expectation-setting backed by sectoral supervisors, rather than through a single enforcement statute. The Monetary Authority of Singapore asks financial institutions questions that sound remarkably like the framework. Enterprise buyers lift its language into due diligence. A document with no penalties attached can still decide whether your deal closes, and this one regularly does.
For an agent builder, the practical reading is that "voluntary" describes the legal status, not the commercial one.
What are the nine dimensions of the generative AI framework?
The Model AI Governance Framework for Generative AI, published 30 May 2024, sets out nine dimensions: accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for public good.
Reading the nine as a list undersells the design. They sort into three groups that correspond to who has to act. Accountability, data and trusted development sit with whoever builds and deploys: who answers for the system, what it was trained and operates on, and whether development followed practices anyone can inspect. Incident reporting, testing and assurance, and security are the operational spine: what happens when something goes wrong, how claims get verified before and after deployment, and how the system resists misuse. Content provenance, safety research and public good look outward, at the information ecosystem and at whether the technology's benefits land beyond its operators.
The dimension that aged best is incident reporting. In 2024 it read as borrowed from aviation and cybersecurity; by 2026, with agents acting at machine speed, the idea that AI systems need the equivalent of a flight recorder and a reporting discipline has become the consensus position across jurisdictions. Singapore wrote it down first, calmly, two years early.
How does the 2026 agentic AI framework build on it?
On 22 January 2026 IMDA published the Model AI Governance Framework for Agentic AI, the first governance framework anywhere written specifically for AI agents. It extends the GenAI edition to systems that act: taking the nine dimensions as given and asking what changes when AI executes multi-step tasks with real-world consequences rather than generating content.
Its answers are concrete, and they are the reason the document matters beyond Singapore. Agents should have bounded tool access rather than open-ended capability. Actions should be reversible where possible, and irreversibility should be a design decision someone made consciously. Each agent should have a unique identity tied to an accountable human, so that "which agent did this, on whose authority" has an answer. Human checkpoints should sit before consequential actions, and there should be offline mechanisms for when an agent malfunctions, a way to stop the thing that does not depend on the thing.
Notice what kind of requirements these are. None of them is about model quality. Every one is about conduct and evidence: what the agent was allowed to touch, what it did, who could have stopped it, and whether any of that can be shown afterwards. The full analysis is in the companion piece, but the one-line version is that the world's first agent governance framework is, in substance, a specification for agent records.
Why does Singapore's framework matter outside Singapore?
Because it exports. The framework family is written to be borrowed, and it is: its concepts appear in regional regulators' guidance, in enterprise procurement language, and in the vocabulary global teams use to discuss agent governance. Reading it is the cheapest preview available of what other jurisdictions will eventually ask.
There is a structural reason for this beyond good drafting. Singapore publishes early, before positions harden, so its frameworks become the neutral text everyone can cite while their own rules are still in committee. The EU AI Act is law and therefore argued about; the Model AI Governance Framework is guidance and therefore quoted. For a team shipping agents into several markets, the practical consequence is that Singapore's expectations are the leading indicator: bounded tool access, agent identity, reversibility and human checkpoints will not stay voluntary everywhere, and the teams that can already evidence them will treat later mandates as paperwork rather than engineering.
That is also the honest limit of the claim. The framework predicts the direction of travel, not the detail of any particular statute. Use it as a compass, not a compliance checklist for other jurisdictions.
What should an agent deployer actually do with it?
Treat the agentic framework's expectations as a test your records should pass today. For each production agent, ask: can you show its tool access was bounded, its identity tied to an accountable person, its consequential actions checkpointed, and its actions' reversibility assessed? If the evidence does not exist, the gap is yours to close before anyone makes it mandatory.
The sequence matters: evidence first, attestation second. A policy stating that agents have bounded tool access is an intention; a run-level record showing the boundary holding is a fact. The framework's own trajectory, from principles in 2019 to a near-specification for agent records in 2026, says which of the two regulators are converging on.
Truveil scores individual agent runs against the frameworks that apply to them, including Singapore's, and produces the per-run evidence this family of documents describes. The methodology is at truveil.app/methodology.