Model AI Governance Framework

· About Model AI Governance Framework

Key Takeaways

  • The Model AI Governance Framework is voluntary guidance, not a law, so it does not itself create fines or criminal penalties for noncompliance.[2][10][11]
  • The original framework was released by Singapore’s Infocomm Media Development Authority (IMDA) on 23 January 2019 and remains the foundation for later AI governance guidance.[1][7]
  • IMDA and the AI Verify Foundation issued a dedicated Model AI Governance Framework for Agentic AI on 20 May 2026, updated on 5 June 2026, to address autonomous AI systems.[2][5][10][11]
  • The framework is aimed at organisations deploying AI solutions, including teams that build AI in-house or use third-party AI systems, and it is especially relevant where AI can materially affect users or operations.[1][5][10]
  • Because the framework is not binding law, the practical “penalty” for ignoring it is usually heightened regulatory, contractual, and reputational risk rather than statutory fines.[10][11]
  • In Singapore, the framework is best treated as a benchmark for responsible AI governance that can support broader compliance with privacy, cyber, and sectoral rules.[1][2][10]

What It Is

The Model AI Governance Framework is Singapore’s voluntary governance guidance for organisations deploying AI, first issued by IMDA in 2019 and later expanded through versions covering generative and agentic AI.[1][7][9] It sets out practical controls for internal governance, decision-making, operations management, and stakeholder communication rather than imposing legally enforceable duties.[1][10][11]

The framework is enforced by IMDA as a policy and guidance instrument, not as a statutory regime with a dedicated inspection or penalty system.[1][10][11] The original framework was released on 23 January 2019; a second edition followed on 21 January 2020; a Model AI Governance Framework for Generative AI was published in June 2024; and the Model AI Governance Framework for Agentic AI was published on 20 May 2026 and updated on 5 June 2026.[1][2][7][9][11]

There are no 2025 amendments or delays identified in the official materials surfaced here; the major 2026 development is the release and rapid update of the agentic AI framework.[2][5][10][11]

Who Must Comply

The framework applies in practice to organisations deploying AI solutions, including those building AI systems internally and those procuring third-party AI capabilities.[1][5][10] The 2026 agentic AI version is targeted at organisations deploying agentic AI, described as systems capable of autonomous planning, reasoning, and action.[2][5][10]

There are no statutory thresholds such as employee count, annual turnover, or processing volume in the framework itself.[1][10][11] There is also no formal extraterritorial trigger written into the framework; however, non-Singapore organisations can still use it as a governance benchmark if they deploy systems in Singapore or seek alignment with Singapore’s AI policy expectations.[1][10][11]

Because the framework is voluntary, it does not create legal exemptions in the usual sense.[10][11] Instead, it functions as a recommended baseline for any organisation that wants a credible AI governance program, including regulated firms that must also comply with sector-specific rules, privacy laws, and contractual assurance requirements.[1][2][10]

Core Requirements

  1. Establish internal governance structures. Organisations should define clear accountability, roles, and oversight for AI lifecycle decisions so that responsibility is not left ambiguous across business, legal, technical, and risk teams.[1][2][10]
  1. Determine the AI decision-making model. The framework expects organisations to decide where humans remain in the loop, where humans supervise, and where automation is permitted, with a particular emphasis on meaningful human accountability in agentic systems.[2][5][10]
  1. Manage AI operations across the lifecycle. Organisations should put controls in place for design, testing, deployment, monitoring, incident handling, and changes to the model or use case, rather than treating AI governance as a one-time review.[1][2][10]
  1. Assess and bound risks upfront. The agentic AI framework specifically calls for upfront risk assessment and boundary-setting to limit unsafe autonomy, misuse, and cascading downstream effects.[2][5][10]
  1. Implement technical controls and processes. The framework emphasises safeguards such as access controls, logging, testing, monitoring, fallback procedures, and other operational controls suitable to the system’s risk level.[2][5][10]
  1. Enable stakeholder communication and responsibility. Organisations should communicate clearly with users and affected stakeholders about the system’s capabilities, limitations, and the responsibilities of users and operators.[1][2][5][10]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | First edition released | 23 January 2019 | Voluntary baseline AI governance guidance for organisations deploying AI.[1][7] | | Second edition released | 21 January 2020 | Updated voluntary framework with broader implementation guidance.[1] | | Generative AI framework published | June 2024 | Supplementary governance guidance for generative AI use cases.[9][14] | | Agentic AI framework published | 20 May 2026 | New voluntary guidance for autonomous AI systems.[2][5][10] | | Agentic AI framework updated | 5 June 2026 | Revised version 1.5 reflecting additional feedback and examples.[2][3][10][11] |

There are no maximum fines, civil penalties, or criminal sanctions in the framework itself because it is not binding law.[10][11] The main sanctions risk comes indirectly: organisations that ignore the framework may face adverse findings under other laws, contractual disputes, audit issues, or reputational harm if AI governance failures cause harm.[10][11]

How to Comply

  1. Map the AI estate. Inventory all AI use cases, owners, vendors, and affected data flows, then classify them by impact and autonomy level.
  1. Assign governance ownership. Create a named AI governance lead, a cross-functional review committee, and escalation paths for legal, risk, security, and product decisions.
  1. Use a risk framework. Align controls to ISO 27001 for security management, NIST CSF 2.0 for enterprise risk governance, and ISO/IEC 42001 for AI management systems where the organisation wants an auditable management framework.
  1. Document decision-making. Record model purpose, limitations, assumptions, human oversight points, testing results, and sign-off decisions so the organisation can evidence responsible deployment.
  1. Test before release and after change. Run pre-deployment evaluations, red-teaming or abuse-case testing where appropriate, and periodic revalidation after model updates, vendor changes, or major drift.
  1. Implement operational controls. Add logging, access restriction, monitoring, incident response, fallback modes, and kill-switch or rollback procedures proportionate to the risk.
  1. Communicate transparently. Provide user-facing notices on AI use, limitations, and human support routes, and ensure procurement terms require vendors to support governance, audit, and incident obligations.
  1. Review against law and sector rules. Check the framework alongside Singapore privacy, cybersecurity, and sectoral obligations so that AI governance supports broader compliance rather than operating in a silo.

Related Regulations

Singapore PDPA: The Personal Data Protection Act overlaps where AI systems process personal data, so governance controls in the framework should be paired with lawful collection, use, disclosure, and protection obligations.

Singapore Cybersecurity Act: AI systems with security-sensitive infrastructure implications may trigger cybersecurity controls beyond the framework, especially for logging, resilience, and incident response.

EU AI Act: The EU AI Act is binding law with risk-based obligations and penalties, unlike Singapore’s voluntary framework, but the framework’s governance concepts map well to documentation and oversight expectations.

NIST AI RMF 1.0: NIST’s framework is also voluntary and can complement Singapore’s guidance by providing a structured risk-management vocabulary for AI controls.

ISO/IEC 42001: This management-system standard aligns closely with the framework’s governance themes and is useful where an organisation wants certifiable AI management processes.

FAQ

Does the Model AI Governance Framework apply to companies outside Singapore?

Yes, as a matter of practical governance, any organisation can use it if it deploys AI systems that affect Singapore operations or customers.[1][10][11] The framework itself is not drafted as a territorial statute with an extraterritorial enforcement mechanism.[10][11]

Is the Model AI Governance Framework legally binding?

No. The official materials describe it as voluntary guidance and a practical framework, not a law or regulation.[1][10][11] That means there are no direct statutory fines for violating the framework itself.[10][11]

Does the framework cover generative AI and agentic AI?

Yes. Singapore published separate guidance for generative AI in 2024 and a dedicated agentic AI framework in 2026.[2][9][14] The 2026 material is the most current guidance for autonomous systems.[2][5][10][11]

Are there penalties for ignoring the framework?

Not under the framework itself, because it does not create binding offences or penalties.[10][11] However, poor AI governance can still lead to liability under other laws, contractual disputes, or regulatory scrutiny in sectors that already impose their own requirements.[10][11]

What changed in 2026?

The key 2026 development was the publication of a dedicated Model AI Governance Framework for Agentic AI on 20 May 2026, followed by an update on 5 June 2026.[2][3][10][11] That version focuses on risks from systems that plan and act with greater autonomy than traditional AI deployments.[2][5][10]

Sources

Put it into practice

More compliance guides