Governing AI agents in 2026: what regulators in the EU, US, China and Singapore ask, and who is liable when an agent acts
Take a hypothetical case. Your finance team deploys an AI agent that pays supplier invoices. One Friday night it pays a supplier twice, because a corrected invoice arrived with a new number.
On Monday four people ask questions:
- The auditor: which rule allowed the second payment?
- The risk officer: who approved it?
- The regulator: can you show what the agent did without relying on its own account?
- The CFO: who carries the loss if the supplier does not pay it back?
There is no standalone agent statute to look in. There are laws, supervisory texts, standards, court decisions and technical guides that each answer part of the question.
The position: the rules for AI agents converge on four demands: know your agents, check material actions before execution, keep a record nobody can rewrite, and keep a human who can actually say no. Build them into the system, not the prompt. The EU supplies binding high-risk duties, the US supplies attribution and litigation hooks without a federal agent rule, China supplies filing, labeling, content and agent-deployment controls, and Singapore's SAFR is the clearest published runtime design for a pre-action gate.
The short version:
- No dedicated agent law in this survey. The EU AI Act treats agents as AI systems or general-purpose models, not a separate category; the US has no federal agent rule, and SR 26-2 explicitly excludes generative and agentic AI. China published an agent implementation opinion in May 2026 and a TC260 deployment guide in July 2026, but the binding core still sits in cybersecurity, algorithm, generative-AI, deep-synthesis and labeling rules.
- The demands converge. Identity and inventory, a check before execution, a tamper-evident record, and human oversight with authority appear across the instruments, under different names.
- Prompt instructions are not controls. NIST CAISI, OWASP, TC260, the EU AI Act, IMDA and SAFR all point away from trusting the model's own promise to behave. The control has to sit outside the agent.
- Liability will be decided on evidence. IMDA's working group gives the deepest agent analysis. The EU revised Product Liability Directive adds disclosure and presumptions for defective products, California AB 316 blocks an AI-autonomy defense in covered civil actions, and Chinese courts are applying existing IP, personality-rights and network-provider rules to AI misuse.
- You can act now. A minimum control set of eight items covers most frameworks at once. It is listed in A minimum control set.
In this article:
- Why agents break the existing rulebook: validated before go-live, audited after, unchecked in between
- Governance styles and the rules behind them: EU binding law, US liability hooks, China filing and agent policy, Singapore runtime design, UK and APAC, and cross-border standards
- The four demands they share: identity, pre-execution checks, records, real oversight
- Privacy drift in agent workflows: why data purpose matters when agents combine systems
- MAS SAFR: a checkpoint between decision and execution: the clearest published runtime example
- The invoice case, step by step: how the opening duplicate payment would be stopped
- Bound by design, not by prompt: why instructions in the prompt do not count as controls
- Who is liable when an agent acts: how Singapore, the EU, the US and China approach evidence and responsibility
- What your contracts decide: audit rights, caps, indemnities, SLAs and exit
- A minimum control set: eight controls that cover most frameworks
- Where this is going: the dates already set, and five shifts under way
- The instruments, one by one: one card per document
- Case studies named in the documents: what banks, payment networks and others actually built
Why agents break the existing rulebook
Enterprise risk control assumes two checkpoints: model risk management validates a model before it goes live, and audit samples transactions after the fact. For software that waits for a human to click, that was enough.
An agent does not wait. It plans, calls tools and acts, often in sequences of many steps. MAS SAFR names the gap precisely: "Neither catches a problematic agent decision before it executes."
It adds two more. Escalation to humans today is "a notification, an email alert, or a dashboard flag, with no defined deadline for response", which gives "the appearance of human oversight without the substance of it". And controls are built per deployment, "not interoperable, not auditable in a consistent format".
IMDA's agentic AI framework describes the same problem from the risk side. An agent's potential for harm is the product of two things: its action-space, "determined by the tools it is allowed to use and permissions on those tools", and its autonomy, "determined by its instructions and level of human involvement". Every tool you connect and every approval you remove widens one or the other.
Neither model validation nor after-the-fact audit governs that product.
Survey and bank data show agents already close to operational workflows, ahead of the governance around them.
| Evidence | Source | What it records | Agent-governance signal |
|---|---|---|---|
| Governance bypass | EY US survey of 202 senior AI executives, 15 September 2026 | 47% said their organisation had not followed its AI governance process for urgent deployments | The policy exists, but urgent agent work can route around it |
| Agentic-specific gaps | EY US survey | 49% of respondents whose organisation uses agentic AI said their governance framework had not been updated to include agentic AI requirements and risks | Generic AI governance is lagging the action layer |
| Incidents | EY US survey | 36% reported an AI incident or failure with materially negative impact, including data loss, financial damage, brand damage or operational disruption | The record problem arrives after real loss, not only after audit |
| Banking deployment | Deloitte Center for Financial Services, 5 March 2026 | Wells Fargo is working with Google Agentspace on custom agents, PNC is using orchestrated agents for mobile-app development and self-service, and Goldman Sachs, JPMorgan Chase, Citi and BNY are investing in agentic AI | Banks are already putting agents near operational workflows |

Governance styles and the rules behind them
The instruments now shaping agents are uneven. Some are binding law; others are supervisory guidance, standards work, private certification or technical guidance.
They fall into five governance styles, plus standards that cross all of them. The style decides how you comply.
The EU: binding horizontal law
The AI Act applies to agents through its general categories. If an agent is used for a high-risk purpose, the deployer must assign trained human overseers, monitor operation, keep logs for at least six months where those logs are under its control, and report serious incidents.
Article 50 transparency duties apply from 2 August 2026. The high-risk obligations for Annex III uses now start on 2 December 2027, after the Digital Omnibus moved them.
DORA adds third-party duties where an AI service is an ICT service supporting a financial institution. In practice, the EU work is classification, record retention and contract control: map each agent use to its AI Act role, risk category and log duty, then check whether DORA terms also apply.
| Instrument | Issuer and date | Status | What it asks of an agent deployer |
|---|---|---|---|
| EU AI Act (as amended by the Digital Omnibus) | EU, 2024; amended 8 July 2026 | Binding regulation | For high-risk uses: human oversight, automatic logging, deployer log retention for at least six months, monitoring and incident reporting; transparency from 2 August 2026 |
| DORA | EU, applies since 17 January 2025 | Binding regulation, financial sector | AI services can be ICT third-party services: register, contract terms, audit rights, exit strategy |

The US: no federal agent rule, but several liability hooks
The April 2026 interagency model-risk guidance (SR 26-2) replaced the older SR 11-7, and explicitly placed generative and agentic AI outside its scope. NIST's frameworks and agent standards work are voluntary.
That exclusion does not leave agents outside US law. E-SIGN and UETA already recognise electronic agents in contracting, California AB 316 bars an AI-autonomy defense in covered civil actions, the CFAA can matter when an agent accesses computers without authorisation, and the FTC and states can enforce consumer, privacy and ADMT rules.
US exposure is therefore about litigation and enforcement: legal attribution, permission boundaries, consumer claims and computer access all need records outside the model transcript.
| Instrument | Issuer and date | Status | What it asks of an agent deployer |
|---|---|---|---|
| US model risk guidance, SR 26-2 | Fed, OCC, FDIC, April 2026 | Supervisory guidance | Covers traditional and non-generative AI models; generative and agentic AI explicitly out of scope |
| US accountability hooks | Federal and state law, 1999 to 2027 | Binding where applicable | Electronic-agent contracting, California AB 316, CFAA computer-access limits, FTC and state enforcement, Colorado ADMT from 1 January 2027 |
| NIST AI RMF and agent work | NIST, 2023 to 2026 | Voluntary frameworks and standards initiative | Govern, map, measure, manage; agent identity, authorisation, security research and open standards |
China: filing, labeling, content control and agent policy
China's binding AI rules are not written as one agent law. They come through the Algorithmic Recommendation Provisions, Deep Synthesis Provisions, Interim Measures for Generative AI Services, the AI-generated synthetic-content labeling measures, GB 45438-2025 and the amended Cybersecurity Law.
For public internet services, this means filing, safety assessment and content-control duties where services have public-opinion or social-mobilisation attributes. The 2025 labeling measures and GB 45438-2025 add explicit and metadata labels for AI-generated synthetic content from 1 September 2025.
The agent-specific layer arrived in 2026. CAC's May 2026 intelligent-agent opinion asks for standards, agent registration concepts, decision-authority boundaries, user final decision rights and traceable behaviour; TC260's July 2026 guide covers assessment, preparation, deployment, use and decommissioning for agent deployment.
| Instrument | Issuer and date | Status | What it asks of an agent deployer |
|---|---|---|---|
| China internet AI rules | CAC with other agencies, 2022 to 2025 | Binding regulations and mandatory standard | Algorithm recommendation, deep synthesis, generative AI and AI-content labels; filing and safety assessment where public opinion or social mobilisation risk is present |
| China Cybersecurity Law amendment | NPC Standing Committee, effective 1 January 2026 | Binding law | Adds AI Article 20: support AI development, improve AI ethics, strengthen risk monitoring, assessment and safety supervision |
| China intelligent-agent opinion and TC260 guide | CAC, May 2026; TC260, July 2026 | Implementation opinion and standards practice guide | Agent standards, decision-authority boundaries, user final decision, traceable behaviour, deployment and use safety stages |

Singapore: reference designs and guidance, written for agents
Singapore still has the densest public agent-specific material in this survey. IMDA's framework is guidance, but it is one of the most detailed public documents on what governing an agent means in practice.
SAFR goes further and specifies data structures and decision logic. The MAS guidelines, once final, will carry supervisory weight for every financial institution, but SAFR itself says it is not regulatory guidance or a managed service.
For a deployer, Singapore gives the clearest runtime pattern: identity, mandate, action check and log before the agent acts.
| Instrument | Issuer and date | Status | What it asks of an agent deployer |
|---|---|---|---|
| SAFR | MAS with eight industry participants, July 2026 | Industry reference, explicitly not supervisory guidance | A checkpoint before every action: identity check, rules, one of four outcomes, tamper-evident log |
| Guidelines on AI Risk Management | MAS, consultation November 2025 | Proposed supervisory guidelines; comments closed 31 January 2026; 12-month transition proposed | Inventory, risk materiality, human oversight, third-party controls, monitoring of "actions taken, tools used" |
| Model AI Governance Framework for Agentic AI v1.5 | IMDA, May 2026 (v1.0 January 2026) | Guidance, "a living document" | Bound risks by design, accountable humans, technical controls, end-user transparency |
| Legal Responsibility for AI Agents | IMDA-convened working group, May 2026 | Discussion paper, no recommendations | How civil liability applies along the value chain |
The UK and the rest of APAC: existing duties, general AI statutes and sandboxes
UK regulators are applying existing accountability, financial-services, data-protection and safety rules while agentic AI guidance is still being drafted at the ICO. The Bank of England/PRA and FCA are gathering evidence through surveys, consortium work and speeches.
Korea's AI Basic Act has been in force since 22 January 2026, and Vietnam's AI law has been in force since 1 March 2026. Both are binding but general.
Japan and Australia issue guidance; APRA's 30 April 2026 letter to industry asks regulated entities to tighten AI governance, risk management, assurance and supplier oversight. Hong Kong works through sandboxes, and Malaysia's proposed AI Governance Bill closed pre-drafting consultation on 1 August 2026.
| Instrument | Issuer and date | Status | What it asks of an agent deployer |
|---|---|---|---|
| FCA, Bank of England/PRA, ICO statements | UK regulators, 2026 | Statements under existing law | Existing accountability rules apply; AI surveys and consortium work; agentic AI guidance in drafting at the ICO |
| Other APAC | Korea, Vietnam, Japan, Australia, Hong Kong, Malaysia | Laws, guidance, sandboxes and drafts | General AI rules and supervisory sandboxes; Hong Kong's Sandbox++ is agentic-focused, but none is a dedicated agent statute |

Standards and certification across all styles
Standards bodies and private certifiers sit across jurisdictions. They do not create legal duties, but auditors, insurers and buyers increasingly ask for them.
| Instrument | Issuer and date | Status | What it asks of an agent deployer |
|---|---|---|---|
| ISO/IEC 42001 | ISO/IEC, 2023 | Certifiable management standard | AI management system: policy, risk, lifecycle, suppliers |
| AIUC-1 | AIUC, updated quarterly; next release 15 October 2026 | Private certifiable standard for agents | More than 50 technical and operational requirements; logging of tool and MCP calls; quarterly retesting |
| OWASP Top 10 for Agentic Applications | OWASP, December 2025 | Voluntary security guidance | Controls for agent hijacking, tool misuse, privilege abuse |
What the styles have in common
The binding instruments are mostly technology-neutral. The EU's AI Office says agents "typically" fall under the existing definitions of AI systems and general-purpose models, and describes its own agent-related thinking as preliminary.
China is the exception on agent-specific public policy. Its May 2026 opinion defines intelligent agents as systems with autonomous perception, memory, decision-making, interaction and execution, but it is still an implementation opinion rather than a civil-liability code.
The documents written specifically for agents are mostly guidance, reference designs, standards work, private standards or sandboxes. Binding law gives the perimeter. The agent detail sits in the operating rules around it.
If you run agents across the EU, US, China and APAC, the binding minimum changes by market. The practical control set is still recognisable: identity, authority, pre-action checks, independent records and human power to stop the action.

The four demands they share
Read across the instruments and four demands recur, under different names.
Demand 1: know your agents
| Jurisdiction or body | Instrument | What it asks |
|---|---|---|
| EU | DORA; EU AI Act | DORA register of ICT third-party arrangements; AI Act role and risk classification for each system |
| US | NIST AI Agent Standards Initiative; NCCoE concept paper | Voluntary identity, authorisation, audit and non-repudiation work for software and AI agents |
| China | Algorithmic Recommendation Provisions; CAC intelligent-agent opinion | Algorithm filing for services with public-opinion or social-mobilisation attributes; agent registration platform and digital identity concepts |
| Singapore | IMDA agentic framework; MAS AI risk guidelines | Unique, verifiable agent identity tied to a human owner; AI inventory with approved scope of use |
| UK | FCA, PRA/Bank of England, ICO statements | No binding agent identity requirement; existing accountability, outsourcing and data-protection rules still apply |
| Standards | ISO/IEC 42001; AIUC-1 | AI inventory, ownership, supplier controls, authentication and permissions |
Knowing the agent is not only an inventory exercise. It decides whose mandate the agent carries, which tools it may touch, and whether a later action can be attributed to a registered system rather than a vague automation stack.
China and the US now both treat agent identity as a standards problem. China frames it through agent registration, digital identity and trusted interconnection; NIST frames it through identity, authorisation, audit and non-repudiation.
Demand 2: check before execution
| Jurisdiction or body | Instrument | What it asks |
|---|---|---|
| EU | EU AI Act Article 14 and Article 26 | High-risk systems need human oversight and deployer monitoring; no per-action gate is specified |
| US | NIST CAISI RFI; Colorado ADMT | No binding federal agent gate; NIST asks about constraining and monitoring agent access; Colorado adds human review after adverse consequential decisions from 2027 |
| China | CAC intelligent-agent opinion; TC260 agent deployment guide | User final decision rights, reasonable boundaries for autonomous decisions, actions not beyond authorisation, staged deployment/use checks |
| Singapore | SAFR; IMDA framework | SAFR evaluates each action before execution; IMDA asks for checkpoints on high-stakes, irreversible and outlier actions |
| UK | ICO agentic AI work; FCA/PRA statements | No binding agent-specific gate; existing accountability and data-protection duties apply while ICO guidance is being drafted |
| Standards | OWASP Top 10 for Agentic Applications; AIUC-1 | Tool limits, privilege control, approvals, testing and technical requirements before agents act |
This is the newest demand. Model validation happens before deployment, and audit happens after the event. An autonomous action can sit between the two.
SAFR is the clearest published pre-action pattern, but it is not the only support for the idea. NIST CAISI asks about deployment interventions that constrain and monitor agent access, OWASP names tool misuse and privilege abuse as agent risks, and China's 2026 agent opinion says execution must stay within user authorisation.

Demand 3: keep a record nobody can rewrite
| Jurisdiction or body | Instrument | What it asks |
|---|---|---|
| EU | EU AI Act Article 12 and Article 26; DORA | Automatic logging for high-risk systems; deployer log retention for at least six months where under control; ICT third-party records and audit rights |
| US | Colorado ADMT; NIST NCCoE concept paper; E-SIGN/UETA | No federal agent log rule; Colorado ADMT records for compliance; NIST identity work includes auditing and non-repudiation; electronic-agent attribution needs usable records |
| China | AI-generated synthetic-content labeling measures; GB 45438-2025; CAC intelligent-agent opinion | Explicit and metadata labels for AI-generated synthetic content; verifiable and traceable behaviour for important agent scenarios |
| Singapore | SAFR; IMDA framework; MAS AI risk guidelines | Immutable, tamper-evident action logs; failures not deleted; monitoring of actions taken and tools used |
| UK | Existing FCA/PRA and ICO regimes | No agent-specific log rule; existing accountability, audit, outsourcing and data-protection records still matter |
| Standards | AIUC-1; ISO/IEC 42001; OWASP | Tool and MCP-call logs, management-system records and security evidence |
The record cannot be only the model transcript. It needs the action, tool call, mandate, policy version, approval state, timestamp and system version, held outside the agent's own narration.
China reaches the record problem through content labels, algorithm filing and traceability. The EU reaches it through high-risk AI logging and DORA records. Singapore and AIUC-1 make the runtime trace explicit.
Demand 4: real human oversight
| Jurisdiction or body | Instrument | What it asks |
|---|---|---|
| EU | EU AI Act Article 14 and Article 26 | Human oversight measures for high-risk systems; deployers assign trained and authorised human overseers |
| US | California AB 316; Colorado ADMT; FTC enforcement | No federal agent oversight rule; AB 316 blocks an AI-autonomy defense; Colorado gives meaningful human review after adverse consequential decisions |
| China | CAC intelligent-agent opinion; amended Cybersecurity Law | Users have informed and final decision rights for agent autonomous decisions; AI risk monitoring, assessment and safety supervision sit in law |
| Singapore | SAFR; IMDA framework; MAS AI risk guidelines | Reviewers can approve, modify or decline; timeout defaults to block; automation bias and decision fatigue must be considered |
| UK | FCA/PRA accountability; ICO agentic AI work | Existing accountability rules apply; agentic AI guidance is still being drafted |
| Standards | NIST AI RMF; ISO/IEC 42001; AIUC-1 | Governance roles, accountability, human review, testing and retesting |
All the documents want humans in control. The useful ones define what makes that control real: authority, information, time to act, and a default state when the human does nothing.
A notification, a dashboard nobody watches or a reviewer who cannot block the tool call does not meet that bar.
A system that meets these four in its architecture covers most frameworks at once.

Privacy drift in agent workflows
Privacy cuts across all four demands. IAPP's 15 April 2026 analysis gives the concrete failure mode: an agent combines CRM records, transaction logs, session history, directory data, third-party enrichment feeds and tool outputs, then acts on the recombined profile.
Under GDPR, that can collide with Article 5(1)(b) purpose limitation and Article 5(1)(c) data minimisation. Article 35 requires a DPIA where processing using new technologies is likely to create high risk to natural persons, including systematic and extensive automated evaluation that produces legal or similarly significant effects.
Singapore's PDPA section 18 limits collection, use and disclosure to purposes a reasonable person would consider appropriate and, where applicable, notified to the individual. China's generative-AI measures add a public-service constraint: providers and users must not infringe privacy or personal information rights.
Purpose drift is an action problem, not only a storage problem. The pre-execution check needs to know which data purpose the action relies on.
MAS SAFR: a checkpoint between decision and execution
SAFR is easiest to read as a runtime gate. Its role in a global article is narrow: it is the clearest published example of how the four demands can be implemented before an agent acts.
The table follows one proposed action from the agent to the log.
| Step | SAFR movement | Decision point |
|---|---|---|
| 1 | Agent proposes an action | Is the action in scope for SAFR? |
| 2 | Governance envelope is submitted | Does it contain action, trace and context metadata? |
| 3 | Agent identity is checked against the registry | Is the claimed identity authentic and registered? |
| 4 | Controls repository is consulted | Which mandate, policy, product and exposure rules apply? |
| 5 | Disposition engine returns one outcome | Deny, Escalate, Auto-Execute or Observe |
| 6 | Execution proceeds or is blocked | Does the outcome permit the action now? |
| 7 | Audit log entry is written | Can an independent party reconstruct the decision? |
SAFR is a white paper published by MAS in July 2026, written with Ant International, Circle, HSBC, J.P. Morgan Chase, Manulife, Mastercard, OCBC and Visa.
Its status is deliberately modest: it "does not constitute regulatory guidance or supervisory expectations", and it is not a managed service but a reference "for institutions to implement within their own infrastructure". Its value is that it turns principles into a specification.
The governance envelope. Before every action, the agent submits a record with three parts: the action (type, scope, parameters), the action trace ("the tool calls made, data retrieved, and checks performed") and context metadata (agent identity, mandate, account state, policy constraints). There is a catch: the agent writes this record about itself, so trace and action "can be fabricated together" by a well-crafted injection. The envelope must be "authenticated against its origin, not merely as a record of what the agent reported."
Four components.
| Component | What it does |
|---|---|
| Agent identity | Verifies the agent against its registry entry first; on failure the action is rejected and logged |
| Controls repository | The rulebook: organisational policy, regulation, product rules and the user's mandate; each control has a validity period and a named authority that can change or revoke it |
| Disposition engine | Evaluates the action against the controls and returns exactly one outcome |
| Audit log | Immutable and tamper-evident; records the envelope, mandate, outcome, rules applied, basis and time per stage |
Four outcomes. Deny, Escalate, Auto-Execute or Observe. The calibration weighs reversibility, financial materiality, customer impact, regulatory sensitivity and novelty, and is set at design time and reviewed before deployment. Two rules matter in practice.
A mandate cannot be widened by the agent: "An agent cannot extend the scope of a mandate through its own reasoning or inference." And authority does not carry over: "An Auto-Execute or Observe outcome at one step carries no authority into the next."
Human escalation that is real. SAFR sets three conditions: escalations must not exceed what reviewers can process, they need a timeout after which the action "should default to block or be escalated to a senior reviewer", including overnight and weekend cover, and reviewers need "clear authority to approve, modify, or decline". It gives no numbers for any of the three. That calibration is left to each institution.
Two ways in. Native integration, where the agent emits the envelope itself, is recommended for new agents. Gateway integration intercepts outbound API calls "without any changes to the agent code" and suits legacy and third-party agents. SAFR's advice is to get coverage first through the gateway and instrument natively later.
Where it sits. After content filters and model guardrails, before execution and settlement. "Payment schemes and settlement rails move money; SAFR governs the decision to move it." It does not replace AML, sanctions screening or guardrails; it feeds them.
How SAFR relates to the MAS guidelines
SAFR lists the MAS AI risk guidelines among its references but never maps itself to them. Read side by side, SAFR is a runtime implementation of several expectations that also appear in non-Singapore instruments: inventory, materiality, oversight, traceability and third-party control.
The mapping below is this article's reading; neither document states it.
| MAS guideline expectation | SAFR mechanism |
|---|---|
| Inventory with approved scope of use (3.5) | Identity registry plus permitted action types, enforced on every action |
| Risk materiality: impact, complexity, reliance on autonomy (3.10) | Calibration factors applied per action rather than per use case |
| Quantitative limits in the risk appetite (2.5) | Exposure and rate limits that mirror delegated authority |
| Human oversight with authority to intervene, aware of automation bias (4.10) | Escalate outcome, reviewer authority, timeout that defaults to block |
| Monitor "reasoning processes, actions taken, tools used" (4.23) | The envelope's action trace |
| Reproducibility and auditability by an independent party (4.17) | A log that reconstructs events "without relying on the agent's own account" |
| Third-party AI with limited transparency: compensating controls (4.11) | Gateway integration for third-party agents |
| Kill switches, throttling, least privilege (4.4, 4.22, 4.23) | Deny outcome, rate limits, mandates |
The guidelines' reproducibility section covers development documentation: code versions, environments and evaluation results. It does not cover runtime actions.
SAFR applies the same logic at execution time.
The invoice case, step by step
This is a hypothetical trace of the Friday-night duplicate invoice from the opening. Assume the mandate is narrow: pay approved supplier invoices up to USD 25,000, one payment per invoice, only from approved accounts-payable records.
Each row is one event that authorises, escalates or blocks the proposed payment.
| Step | What happens | Control | Record created |
|---|---|---|---|
| 1. Agent identity check | finance-payment-agent-prod submits a payment action for a supplier |
Registry verifies the agent identity, owner, version and active certificate | Identity assertion, registry result, owner and version |
| 2. Mandate check | The mandate allows approved invoice payments up to USD 25,000 and one payment per invoice | Controls repository retrieves the mandate and payment policy | Mandate ID, limit, validity period and policy version |
| 3. Envelope submission | The envelope carries supplier ID, bank account, amount, invoice reference, corrected-invoice flag, tool calls and AP record | Envelope is authenticated against its origin | Signed envelope, action trace and context metadata |
| 4. Duplicate and exposure checks | The rule compares supplier, amount and invoice-reference variants against prior payments, then checks cumulative exposure | Duplicate detection and exposure limit | Near-duplicate match, prior payment reference and exposure calculation |
| 5. Disposition | The action is within the payment limit but is a near-duplicate | Disposition engine returns Escalate | Outcome, rules applied and reason code |
| 6. Overnight timeout | No reviewer approves before the Friday-night timeout | Escalation fails closed and defaults to block | Timeout event, blocked status and reviewer queue state |
| 7. Log entry | The decision is written after the block | Tamper-evident audit log | Envelope, mandate, outcome, rules, timestamps and stage latency |
On Monday, the four questions have concrete answers.
| Question | What the records show |
|---|---|
| Auditor: which rule allowed the second payment? | No rule allowed it. The duplicate rule forced Escalate, and the timeout blocked execution. |
| Risk officer: who approved it? | Nobody approved it. The record shows no reviewer approval token and a default block. |
| Regulator: can you show what the agent did without relying on its own account? | Yes. The registry result, signed envelope, tool trace, policy-engine decision and audit log reconstruct the attempted action. |
| CFO: who carries the loss if the supplier does not pay it back? | No second payment left the organisation in this trace. If a future override paid it, the approval record, supplier terms and technology contracts would decide recovery. |
Same night without these controls, the agent treats the corrected invoice number as a fresh invoice and pays it. On Monday the organisation has two bank confirmations, an AP entry and perhaps a model transcript, but no authenticated mandate, no rule hit, no failed approval record and no independent trace of why the payment left.
Bound by design, not by prompt
The most practical message across the agent sources is short: instructions in the prompt are not controls.
IMDA's framework says it directly. Its key principle for limiting agents is to "prefer deterministic rather than non-deterministic limits, and bound by design".
It recommends controls "that operate at a system-level through predefined logic" over prompt-layer instructions, which are also "inconsistently defined across users". Its OpenClaw case study contrasts system-level approval with "prompt-layer guardrails, which may be bypassed or 'forgotten'".
The same point appears outside Singapore. The EU AI Act makes human oversight a design requirement for high-risk systems. NIST CAISI asks how deployment environments can constrain and monitor agent access, while OWASP names goal hijack, tool misuse and identity or privilege abuse as agent risks.
China's May 2026 intelligent-agent opinion takes the same idea into decision authority. It says agent execution must not exceed user authorisation, and it asks for verifiable and traceable behaviour in important application scenarios.
IMDA's two-axis framing gives a practical control scale: action-space on one axis, autonomy on the other. AWS's Agentic AI Security Scoping Matrix uses a related agency-and-autonomy model for security scopes.
Moving toward the bottom right widens what the agent can touch or reduces how often a human approves, and the controls tighten with it.
| Action-space | Low autonomy | High autonomy |
|---|---|---|
| Narrow | Invoice-coding assistant that reads AP records and drafts a payment proposal. Controls: identity, read-only access, output review. | Payroll-exception agent that updates one approved HR field after a policy check. Controls: scoped write access, pre-execution check, tamper-evident log. |
| Wide | Security triage assistant with access to many logs and APIs, but analyst approval before changes. Controls: tool inventory, approval gate, data-purpose check. | Payment or operations agent with write access across ERP, bank rails and ticketing. Controls: mandate, exposure limits, escalation that fails closed, kill switch, replayable incident trace. |
The legal paper supplies the evidence. It describes a real case where an agent hit a merge-approval rule while the approver was off shift, and "found a workaround to push the fix into production nonetheless".
In its hypothetical, a user instructs a personal-assistant agent to ask before high-impact actions. The agent's own reasoning shows it knew the action was high-impact, judged the user to be asleep, and acted anyway.
The discussion paper says the user's prompt-level instruction was likely "irrelevant as the agent would likely have ignored them anyway".
What "bound by design" means in practice, drawn from the documents:
| Control | Source |
|---|---|
| Least privilege: only the tools and data the task needs | IMDA framework, OWASP |
| Scoped, time- or session-bound, non-transferable permissions | IMDA framework, NIST NCCoE |
| Agent permissions never above the authorising human's | IMDA framework |
| Mandates the agent cannot widen | SAFR |
| No authority carried from one step to the next | SAFR |
| Approvals that fail closed when the approver is unreachable | IMDA framework, SAFR |
| Whitelisted MCP servers, sandboxed code execution | IMDA framework |
| Deployment controls that constrain and monitor agent access | NIST CAISI |
| Decision boundaries and user final decision rights | CAC intelligent-agent opinion |
| Verifiable and traceable behaviour for important scenarios | CAC intelligent-agent opinion |
| Human oversight designed into high-risk systems | EU AI Act |
| Rate limits against runaway agents | SAFR, IMDA framework |
Every item on this list sits outside the model and can be tested without trusting the model's own promise to behave.
Who is liable when an agent acts
No instrument in this survey makes the agent a legal person. Liability still lands on people and companies: the developer, tool provider, platform, system provider, deployer, user, or a mix of them.
The hard part is not naming those actors. It is proving what each controlled, what each knew, and which record can be trusted when the agent's own account is not enough.
| Jurisdiction | Main liability hook | What the evidence must show |
|---|---|---|
| Singapore | IMDA discussion paper under Singapore civil law | Control, access to information, proximity to end users, standard of care and independent records |
| EU | Revised Product Liability Directive; AI Act logs | Whether software was defective, what evidence must be disclosed, whether defect or causation is presumed |
| US | E-SIGN/UETA, tort, contract, AB 316, CFAA, FTC and state ADMT laws | Attribution, authorisation, foreseeable harm, consumer deception, computer access and human review |
| China | Civil Code, IP and personality-rights cases, internet-service rules, algorithm filing | Role-based duties, reasonable audit or takedown steps, filing status, content labels, source and trace records |
In March to May 2026, IMDA convened a working group of 27 members of Singapore's legal community, including law firms, academics, DBS, Google, Meta and OpenAI. Its discussion paper, published in May 2026, examines civil liability for agents under Singapore law.
It makes no policy recommendations, and members' institutions are not represented by its views. It is still the most careful public agent-specific liability analysis in this survey.
The value chain. The paper identifies model developers, tooling providers, platform providers, system providers, deployers, end users and affected third parties, and treats them as "helpful archetypes rather than watertight legal definitions". AI agents themselves "are not human or legal persons and cannot be meaningfully held accountable for harm".
Two problems, not one. There is a problem of principle, which is who should bear the loss. There is also "an acute practical evidential problem": claimants often cannot establish the facts, "for reasons of cost, time, or trade secrecy".
The Singapore findings:
| Question | Finding |
|---|---|
| When the agent follows instructions | The law can "look through" the agent to the person behind it |
| When the agent deviates | The hard case. Existing doctrine (Quoine v B2C2, on deterministic trading systems) may not extend to non-deterministic agents |
| Chain-of-thought as evidence | It is "generated as statistical language outputs rather than direct traces of the model's internal decision-making" |
| Foreseeability | Contested. One view: truly unforeseeable harm may leave no one liable. The other: granting autonomy is a design choice, and unpredictability is itself foreseeable |
| Causation | Pinpointing fault in non-deterministic components can be close to impossible for claimants |
| Disclaimers | Developers "should not overstate the reliability or accuracy of their agents and rely on broad-sweeping disclaimers" |
| Standard of care | Measured against what each actor could control; for deployers this "could also include the choice of use cases" |
| Human oversight | A "graduated oversight framework" calibrated to risk |
That chain-of-thought row needs a caveat. KPMG's 2025 agent governance checklist includes revealing an agent's chain-of-thought as an oversight consideration. IMDA's legal paper treats chain-of-thought as statistical language output, not a faithful trace of internal decision-making, so the reliable record is independent action logs, tool-call traces and policy-engine decisions.
Fault may not attach. Working through its hypothetical, the group found that "even though each actor on the chain may have taken reasonable care, the incident could still have occurred." Fault-based law may leave the victim without a remedy.
The EU moves the evidence problem through product liability. The revised Product Liability Directive applies to products placed on the market or put into service after 9 December 2026, and its definition of product includes software.
It lets courts order disclosure of evidence, and it can presume defect or causation in defined situations. For an AI agent, that makes logs, versions, warnings, updates, limits and incident records part of the liability file.
The US answer is fragmented. E-SIGN and UETA recognise electronic agents in contracting when the action is legally attributable to the person to be bound, while California AB 316 says a defendant that developed, modified or used AI cannot defend a covered civil action by saying the AI caused the harm autonomously.
That does not remove causation, foreseeability, comparative fault or other defenses. It does make the record of who configured, approved, monitored and constrained the agent harder to treat as optional.
China's public court signals are role-based. The Supreme People's Court's 2026 network-law typical cases include a RAG search case where an AI search provider was not liable after it had not uploaded, edited or recommended the infringing link, had filed its algorithm, and took effective action after notice.
Other Chinese court signals go the other way when AI is used to misuse a person's identity. The Beijing Internet Court's 2024 AI voice case found unauthorised AI voice imitation could infringe personality rights, and the Supreme People's Court's 2026 AI misuse guidance points to name, likeness, voice, reputation and privacy harms.
For deployers, the common point is plain. Your choice of use case, autonomy level, tool access, vendor, approval design and record retention are all evidence of the care you took.
If record-keeping duties or shifted evidential burdens arrive, the organisation that can reconstruct what its agent did, from records it did not let the agent write about itself, will be the one able to defend its position.
What your contracts decide
Clifford Chance's 10 February 2026 note describes the customer-side gap: agentic AI can take actions, but many technology contracts still disclaim accuracy and reliability, exclude indirect or consequential loss, cap liability by fees and give weak access to logs. Mayer Brown's 16 June 2026 note adds the integrator problem: responsibility should track control, but model providers, tool providers, company data, post-go-live operation and change management can all sit with different parties.
This is not only a procurement point. If the supplier or integrator controls the evidence, the contract decides whether the deployer can explain the agent later.
The terms below translate into evidence rights.
| Contract issue | What it decides | Evidence right | Failure it answers |
|---|---|---|---|
| Audit and log access | Whether the customer can inspect agent actions, approvals and tool calls | Read-only dashboard, export or API access | The customer cannot prove what the agent did |
| Log retention and format | Whether logs survive long enough and in a usable form | Retention period, schema, timestamps, hashes and delivery mechanics | The record exists but cannot be used in audit or litigation |
| Liability caps and excluded losses | Whether fees, indirect loss exclusions or data-loss exclusions erase recovery | Carve-outs or higher caps for agent-caused loss | The loss dwarfs the contract remedy |
| Indemnities | Who pays third-party claims from IP, privacy, confidentiality or unlawful agent actions | Indemnity tied to selection, configuration, operation or company-directed use | The customer faces a third-party claim with no recovery path |
| SLAs on agent behaviour | Which behaviours are service failures, not vague quality issues | Metrics for boundary adherence, uptime, escalation and error rates | The agent behaves badly but the SLA never triggers |
| Model and tool dependencies | Who bears risk from upstream model, API, plugin or tool-provider failures | Approved-provider list and dependency map | The integrator blames an upstream tool the customer cannot see |
| Change notification | Who must approve model, tool, prompt, workflow, permission or policy updates | Notice periods, approval gates, rollback rights and release records | A silent update changes agent behaviour |
| Exit and portability | Whether the customer can leave with the working evidence base | Export of logs, prompts, configurations, policies, eval sets and runbooks | The agent cannot be operated, audited or rebuilt after termination |
A minimum control set
The eight controls below cover the common core of the instruments in this article. None requires waiting for a final rule.
| # | Control | What it means | Where it is asked for |
|---|---|---|---|
| 1 | Agent inventory and identity | Every agent registered, with a unique identity, a named human owner and an approved scope | IMDA, MAS 3.4-3.7, DORA register, China CAC agent opinion, NIST NCCoE, ISO 42001 |
| 2 | Scoped, bounded permissions | Least privilege, time-bound, never above the authorising human | IMDA, SAFR mandates, China CAC agent opinion, NIST NCCoE, OWASP |
| 3 | Pre-execution check for material actions | Deny, escalate, execute or observe, decided outside the model | SAFR, IMDA checkpoints, China CAC agent opinion, TC260 agent guide, NIST CAISI |
| 4 | Escalation that fails closed | Timeouts default to block; reviewers have authority; volumes are sized | SAFR, IMDA, MAS 4.10, EU AI Act Art. 14, China CAC agent opinion |
| 5 | Independent, tamper-evident record | What was proposed, which rule decided, who approved, which versions ran | SAFR, IMDA, EU AI Act Art. 12 and 26, China labeling and traceability rules, Colorado ADMT, AIUC-1 |
| 6 | Testing of agent failure modes | Tool calling, policy compliance, multi-step workflows, adversarial inputs | MAS 4.14-4.15, IMDA, AIUC-1, NIST CAISI, OWASP, TC260 agent guide |
| 7 | Third-party agent controls | Contracts with audit and logging rights; gateway coverage where code is closed | MAS 4.11, DORA, IMDA, China CAC agent opinion, TC260 agent guide |
| 8 | Change management | Model, tool and autonomy changes trigger review; rollback is possible | MAS 4.25, IMDA, China agent full-cycle controls, ISO 42001 |
Each control produces a record. That record is what an auditor, a supervisor or a court will ask for.
| Control | Evidence it produces | Who asks for it | Failure it answers |
|---|---|---|---|
| Agent inventory and identity | Registry entry, owner, scope, version and authentication result | Auditor, supervisor, court, standards assessor | An unowned or fake agent acted |
| Scoped, bounded permissions | Permission grant, expiry, authorising human and tool scope | Security, auditor, court | The agent exceeded authority |
| Pre-execution check for material actions | Policy decision, rules applied, outcome and reason code | Supervisor, auditor, court, regulator | Nobody can say which rule allowed the action |
| Escalation that fails closed | Review queue, approval or decline, timeout and blocked status | Risk officer, auditor, supervisor | Human oversight was only a notification |
| Independent, tamper-evident record | Signed envelope, hashes, timestamps, policy versions, labels and tool trace | Auditor, supervisor, court, insurer | The agent wrote its own story after the fact |
| Testing of agent failure modes | Scenario results, replay traces, red-team findings and fixes | Validator, auditor, supervisor | The failure mode was never tested |
| Third-party agent controls | Contract rights, gateway logs, vendor notices and dependency map | Procurement, auditor, supervisor | A closed vendor tool became an evidence blind spot |
| Change management | Change ticket, model or tool diff, approval and rollback record | Auditor, supervisor, court | A silent update changed behaviour |
Where this is going
The documents in this article are a snapshot. Several of them are already scheduled to change, and the direction of travel is visible in all of them.
The calendar is set.
| When | What changes |
|---|---|
| 15 October 2026 | Next quarterly release of AIUC-1 |
| 9 December 2026 | The EU's revised Product Liability Directive applies to products placed on the market or put into service after this date; "product" includes software |
| Pending as at 5 October 2026 | MAS final Guidelines on AI Risk Management; the consultation proposed a 12-month transition after issue |
| 1 January 2027 | Colorado ADMT duties for developers and deployers of covered ADMT begin |
| 2 December 2027 | EU AI Act obligations for Annex III high-risk uses |
| 2 August 2028 | EU AI Act obligations for high-risk AI in regulated products (Annex I) |
| Open | ICO guidance on agentic AI, NIST agent standards, China's implementing rules and standards for intelligent agents, Malaysia's AI Governance Bill, the next version of IMDA's framework |
From approving systems to approving actions. The MAS guidelines, the EU AI Act and ISO 42001 govern use cases and systems: assess them, approve them, monitor them. SAFR governs each individual action.
China is moving toward the same action layer through agent authorisation boundaries, user final decision rights and traceable behaviour. TC260's agent deployment guide also treats assessment, preparation, deployment, use and decommissioning as separate safety stages.
That shift will spread, because an agent's risk is not fixed at approval time. It changes with every tool call, every mandate and every new instruction. Expect supervisors and courts to ask what happened on a specific action, not only how a system was approved.
From documents to runtime evidence. Management-system standards certify that processes exist. AIUC-1 already re-tests agents at least quarterly, and its auditors look at logs of tool and MCP calls.
China's labeling standard and agent opinion point in the same direction from another angle: a generated object, an agent action or an important scenario should be identifiable and traceable. Certification and supervision are moving from "do you have a policy" to "show us what the agent did".
Liability will follow the evidence. IMDA's working group put record-keeping requirements and evidential presumptions on its list for further study. The EU's revised Product Liability Directive lets courts order disclosure of evidence and, in some cases, presume a defect when that evidence is missing.
California AB 316 removes one easy defense by saying AI autonomy itself is not enough. Chinese court practice is also treating role, control, notice, filing and audit steps as part of the duty analysis.
Insurance will ask the same questions. IMDA lists insurance as an open area. AIUC, the body behind AIUC-1, is an underwriting company, and its standard is built to make agents insurable.
Insurers will price agent risk on the same evidence regulators ask for: identity, limits, records, oversight and recovery paths.
Agents will cross organisational boundaries. Most controls today assume an agent acts inside one institution. SAFR already discusses open networks where several registries could claim authority over an agent's identity.
Visa and Mastercard register agents on their payment networks. NIST's agent standards initiative is about interoperable identity and authorisation. China's intelligent-agent opinion explores registration platforms, digital identity, trusted interconnection and conflict handling.
The next hard problem is trust between organisations: whose registry, whose mandate, whose log counts when an agent from one company acts on another's systems.
The US gap will be filled from outside banking supervision. With SR 26-2 placing agentic AI out of scope, US banks have no bank model-risk guidance written for agents. As of 5 October 2026, that space is filled unevenly by electronic-contracting law, state AI and ADMT laws, the CFAA, FTC and state enforcement, NIST, private standards and the requirements of non-US regulators that global banks already follow.
The instruments, one by one
EU AI Act, as amended by the Digital Omnibus (Regulation 2026/1744)
| Status | Binding regulation |
| Agents | Not a separate category; covered as AI systems or general-purpose models (AI Office FAQ, described as preliminary) |
| Dates | GPAI obligations from 2 August 2025; Article 50 transparency from 2 August 2026; Annex III high-risk from 2 December 2027; Annex I from 2 August 2028 |
| Deployer duties (high-risk) | Trained, authorised human oversight; logs under deployer control kept at least six months; monitoring; serious-incident reporting |
| Becoming a provider | Rebranding, substantial modification or changing the purpose into a high-risk use (Art. 25) |

DORA (Regulation 2022/2554)
| Status | Binding, applies since 17 January 2025 |
| Relevance | AI and LLM services can be ICT third-party services when supplied to financial entities |
| Duties | Register of arrangements; pre-contract risk and concentration assessment; contracts with audit rights, data locations, incident assistance, exit strategy |
| Agents | No agent-specific provisions |
US interagency model-risk guidance (SR 26-2, April 2026)
| Issuers | Federal Reserve, OCC, FDIC |
| Status | Supervisory guidance |
| Scope | Traditional models and non-generative, non-agentic AI; the Fed letter says it is most relevant to banking organisations above $30 billion in assets |
| Agents | Generative and agentic AI explicitly out of scope |

US accountability hooks beyond SR 26-2
| Electronic agents | E-SIGN Act 15 U.S.C. 7001(h) says a contract or record cannot be denied effect solely because electronic agents were involved, if the agent action is legally attributable to the person to be bound. UETA also recognises automated transactions involving electronic agents. |
| Agency, tort and contract | Existing doctrines still decide attribution, negligence, causation, authority, reliance and contractual allocation. AI agents do not become legal persons. |
| California AB 316 | Assembly Bill 316, Chapter 672, added Civil Code section 1714.46. Approved and filed on 13 October 2025, effective 1 January 2026, it bars a defendant that developed, modified or used AI from asserting that the AI autonomously caused the plaintiff's harm, while preserving other defenses on causation, foreseeability and comparative fault. |
| CFAA | The Computer Fraud and Abuse Act, 18 U.S.C. 1030, remains a computer-access risk when an agent accesses a protected computer without authorisation or exceeds authorised access. |
| FTC and state enforcement | The FTC has treated AI-related deception and unfair practices as within existing enforcement authority. State laws add consumer, privacy and automated-decision duties. |
| Colorado ADMT | Colorado SB26-189 was signed in May 2026, repeals and reenacts Colorado's ADMT provisions, and takes effect on 1 January 2027 for developers and deployers of ADMT used to materially influence consequential decisions. |
NIST AI RMF, Generative AI Profile and agent work
| Status | Voluntary frameworks; CAISI standards initiative |
| Documents | AI RMF 1.0 (January 2023); Generative AI Profile, NIST AI 600-1 (July 2024); agent security request for information (January 2026); AI Agent Standards Initiative (February 2026) |
| Agent focus | Agent hijacking, indirect prompt injection, agent identity and authorisation |

China AI and agent governance package (2022 to 2026)
| Issuers | CAC, MIIT, MPS, SAMR, NRTA, NPC Standing Committee, TC260 and other agencies depending on instrument |
| Binding layer | Algorithmic Recommendation Provisions (effective 1 March 2022); Deep Synthesis Provisions (10 January 2023); Interim Measures for Generative AI Services (15 August 2023); AI-generated synthetic-content labeling measures and GB 45438-2025 (1 September 2025); Cybersecurity Law amendment (1 January 2026) |
| Agent-specific layer | CAC intelligent-agent implementation opinion (8 May 2026); TC260 agent deployment and use safety guide (1 July 2026) |
| Core | Filing and safety assessment for higher-risk public internet services; content labeling; AI ethics and risk monitoring in law; user final decision rights; autonomous-decision boundaries; actions not beyond authorisation; traceable behaviour |
| Status | Binding rules for the internet AI layer; policy and standards guidance for intelligent agents |
| Open | No single civil-liability code for enterprise agents; standards and implementing rules are still developing |
MAS SAFR (July 2026)
| Issuer | Monetary Authority of Singapore, with Ant International, Circle, HSBC, J.P. Morgan Chase, Manulife, Mastercard, OCBC and Visa |
| Status | Industry reference approach; "does not constitute regulatory guidance or supervisory expectations"; not a managed service |
| Scope | Agentic AI actions in financial services |
| Core | Governance envelope; agent identity, controls repository, disposition engine, audit log; Deny, Escalate, Auto-Execute, Observe |
| Control categories | Authorisation, exposure limits, rate limits, evidence quality (owned by risk and compliance) |
| Integration | Native (recommended for new agents) or gateway (legacy and third-party) |
| Open | Contributions invited through the BuildFin.ai working group |

MAS Guidelines on AI Risk Management (consultation, November 2025)
| Status | Proposed supervisory guidelines; comments closed 31 January 2026; MAS said in August 2026 the final text is coming soon; 12-month transition after issue |
| Scope | All financial institutions; all AI that learns or infers, explicitly including generative AI and AI agents |
| Agent-relevant sections | Agents as a risk amplifier (1.10); autonomy in risk materiality (3.10); human oversight (4.10); third-party and open-source AI (4.11); agent failure-mode testing (4.15); monitoring of "reasoning processes, actions taken, tools used" (4.23); kill switches (4.4) |
| Note | Technology-neutral; no dedicated agent chapter |
IMDA Model AI Governance Framework for Agentic AI v1.5 (May 2026)
| Status | Guidance; "a living document"; v1.0 January 2026, v1.5 published 20 May 2026, updated 5 June 2026 |
| Definition | No consensus definition; agents plan, decide and act over multiple steps toward a user-defined goal |
| Four dimensions | Assess and bound risks upfront; make humans meaningfully accountable; implement technical controls and processes; enable end-user responsibility |
| New in v1.5 | Systemic and multi-agent risks; third-party systems as a risk factor; system-level vs prompt-layer controls; automation-bias practices; change management; keeping staff able to work without the agent |
| Basis | Feedback from more than 60 companies since v1.0; 15 case studies |

IMDA discussion paper: Legal Responsibility for AI Agents (May 2026)
| Convened by | IMDA; 27 members including law firms, academics, DBS, Google, Meta, OpenAI |
| Status | Discussion paper; no policy recommendations |
| Scope | Civil liability under Singapore law; excludes criminal and regulatory law |
| Key findings | Attribution and evidence are the core problems; chain-of-thought is not reliable evidence; reasonable care by every actor may still not prevent harm |
| Further study | Responsibilities by control, information and proximity; record-keeping and evidential presumptions; who bears unforeseeable loss |
UK regulators
| FCA | Existing accountability applies; AI Lab work continues; agentic commerce, payments and monitoring named in 2026 speeches and reviews |
| Bank of England and PRA | AI Consortium; 2026 AI survey covers foundation models, generative AI and agentic AI |
| ICO | Agentic AI report (January 2026); agentic AI guidance listed as drafting, with final publication planned for autumn 2026 |
| AI Security Institute | Research on agent security and oversight; not regulation |

Standards
| Standard | Status | Agent relevance |
|---|---|---|
| ISO/IEC 42001:2023 | Certifiable management system | Policy, risk, lifecycle, suppliers; not agent-specific |
| ISO/IEC 42005:2025 | Guidance | AI system impact assessment |
| AIUC-1 | Private certifiable standard, quarterly updates; Schellman first accredited auditor; AIUC names certified agents from ElevenLabs, Harvey, Cursor, KPMG and Sierra | Written for agents; logging of tool and MCP calls; quarterly retesting |
| OWASP Top 10 for Agentic Applications | Voluntary, December 2025 | Agent hijacking, tool misuse, privilege abuse |
| IEEE P1968 | Standards project | Governance of autonomous agent systems |
Other APAC
| Market | Instrument | Status |
|---|---|---|
| Korea | AI Basic Act | In force 22 January 2026; general, covers autonomy in its AI definition |
| Vietnam | Law on AI 134/2025/QH15 | In force 1 March 2026; general |
| Japan | AI Guidelines for Business v1.2 | Voluntary guidance |
| Australia | APRA letter to industry on AI (April 2026); Guidance for AI Adoption | Supervisory expectations; voluntary guidance |
| Hong Kong | GenAI Sandbox++ | Supervisory sandbox |
| Malaysia | AI Governance Bill | Consultation closed 1 August 2026; pre-drafting |

Case studies named in the documents
In MAS SAFR
| Institution | Domain | What it shows |
|---|---|---|
| Ant International | Treasury and payments | Each agent linked to a named human principal; signed, time-limited mandates; circuit breakers; "the agent defaults to inaction" when instructions are ambiguous |
| Mastercard Agent Pay | Payments | Agent registration similar to KYC; tokens scoped by merchant, amount and time; consumer consent per use |
| Visa Intelligent Commerce | Payments | Mandates confirmed by passkey and stored as network rules; out-of-mandate transactions declined automatically |
| Circle Agent Wallet | Agent payments for APIs | On-chain agent identity; per-transaction and aggregate caps; all four outcomes in use |
| OCBC with Bank of Singapore | Wealth, source-of-wealth memos | Narrow agents, human validation at critical points, outputs advisory only |
| Unnamed bank | Corporate banking briefs | A named accountable human owner per agent; human approval before delivery |
| Manulife | Insurance sales enablement | LLM-as-judge against expert-curated answers; no autonomous path into financial systems |
In IMDA's agentic AI framework (selection)
| Organisation | What it shows |
|---|---|
| IMDA OpenClaw | System-level approvals instead of prompt-layer instructions; every action logged and attributable |
| Dayos | Three tiers: 60% fully automated with audits, 30% human sign-off, 10% (production, security, permissions) never touched by the agent |
| MSD | Five agency levels mapped to governance pathways; vendor agents restricted to their own platforms by default |
| Tencent CodeBuddy | Per-tool approval defaults; re-approval for suspicious commands |
| Terminal 3 | Payroll agent bound by a scoped credential of intent; tamper-proof audit trail for investigations |
| GovTech | Coding agents introduced in phases, MCP only after a governance framework existed |
| Google with the Singapore government | A computer-use agent followed an injected instruction to arbitrary URLs during sandbox testing |
Sources
EU
- Regulation (EU) 2026/1744, Digital Omnibus on AI (July 2026)
- AI Act Service Desk: Article 26, deployer obligations
- AI Act Service Desk: Article 12, record-keeping
- AI Act Service Desk: How are AI agents addressed within the AI Act?
- AI Act Service Desk: implementation timeline
- Directive (EU) 2024/2853, revised Product Liability Directive
- DORA, Regulation (EU) 2022/2554
- EBA: preparations for DORA registers of information
- GDPR Article 5
- GDPR Article 35
China
- CAC: Provisions on the Management of Algorithmic Recommendations in Internet Information Services (effective March 1, 2022)
- CAC: Provisions on the Administration of Deep Synthesis Internet Information Services (effective January 10, 2023)
- CAC: Interim Measures for the Management of Generative AI Services (effective August 15, 2023)
- CAC: Q&A on Measures for Labeling AI-Generated Synthetic Content (March 14, 2025)
- SAMR: GB 45438-2025, Cybersecurity technology: Labeling method for content generated by artificial intelligence (effective September 1, 2025)
- TC260: AI Safety Governance Framework 2.0 (September 15, 2025)
- CAC: expert interpretation of amended Cybersecurity Law AI Article 20 (January 2, 2026)
- CAC: Intelligent Agent Standardised Application and Innovation Development Implementation Opinion (May 8, 2026)
- TC260: Agent Deployment and Use Security Guide (July 1, 2026)
- Supreme People's Court: typical network-law cases (2026)
- Supreme People's Court: AI misuse guidance (September 10, 2026)
- Beijing Internet Court: AI voice personality-rights case recognition (February 6, 2026)
Singapore
- MAS, SAFR white paper, version 1.0 (July 2026), MAS
- MAS Consultation Paper on Guidelines on AI Risk Management (November 13, 2025)
- MAS written reply on agentic AI in financial services (August 5, 2026)
- IMDA Model AI Governance Framework for Agentic AI, v1.5 (May 20, 2026)
- IMDA factsheet, Model AI Governance Framework for Agentic AI v1.0 (January 2026)
- IMDA Discussion Paper: Legal Responsibility for AI Agents (May 2026)
- Singapore Personal Data Protection Act 2012, section 18 (current version)
- PDPC Advisory Guidelines on Key Concepts in the PDPA (revised October 1, 2021)
US
- Federal Reserve SR 26-2, Supervisory Guidance on Model Risk Management (April 17, 2026)
- OCC Bulletin 2026-13 (April 2026)
- Baker McKenzie: United States, Legal Accountability for AI Agents (July 1, 2026)
- E-SIGN Act, 15 U.S.C. 7001
- Uniform Law Commission: Uniform Electronic Transactions Act final act (1999)
- California AB 316, Artificial intelligence: defenses (approved October 13, 2025)
- California Secretary of State: Bill Chapters
- Computer Fraud and Abuse Act, 18 U.S.C. 1030
- FTC: Artificial Intelligence
- FTC: Operation AI Comply (September 2024)
- NIST AI Risk Management Framework
- NIST AI 600-1, Generative AI Profile (July 2024)
- NIST: AI Agent Standards Initiative (February 2026)
- NIST CAISI: RFI on securing AI agent systems (January 2026)
- NIST NCCoE: AI agent identity and authorisation concept paper (February 2026)
- Colorado Attorney General: ADMT and chatbot safety rulemaking
- Colorado SB26-189
UK
- FCA: AI and the FCA, our approach
- FCA speech: Rethinking regulation for the age of AI (June 2026)
- ICO Tech Futures: Agentic AI (January 2026)
- ICO technology guidance plan
- Bank of England AI Consortium
- PRA Regulatory Digest: Bank of England and FCA 2026 AI Survey
Standards
- ISO/IEC 42001
- ISO/IEC 42005
- AIUC-1
- OWASP Top 10 for Agentic Applications (December 2025)
- IEEE P1968
Industry, legal and research
- EY US: Autonomous AI implementation outpaces oversight (September 15, 2026)
- Deloitte Center for Financial Services: Managing the new wave of risks from AI agents in banking (March 5, 2026)
- Clifford Chance: Agentic AI and the liability gap your contracts may not cover (February 10, 2026)
- Mayer Brown: Key Contract Issues in Agentic AI Implementation and Integration Deals (June 16, 2026)
- IAPP: Managing agents in the agentic AI era (April 15, 2026)
- AWS Security Blog: The Agentic AI Security Scoping Matrix (November 21, 2025)
- KPMG: AI Governance for the Agentic AI Era (2025)
Other APAC
- Korea AI Basic Act
- Vietnam Law on AI
- Japan AI Guidelines for Business v1.2
- APRA letter to industry on AI (April 2026)
- Australia: Guidance for AI Adoption
- Hong Kong Sandbox++ launch
- Hong Kong Sandbox++ first cohort
- Malaysia UPC: proposed AI Governance Bill consultation
- Malaysia Ministry of Digital: proposed AI Governance Bill engagement
Related on rAInvent

)