Governing AI agents in 2026: what regulators in the EU, US, China and Singapore ask, and who is liable when an agent acts

Governing AI agents in 2026: what regulators in the EU, US, China and Singapore ask, and who is liable when an agent acts

Take a hypothetical case. Your finance team deploys an AI agent that pays supplier invoices. One Friday night it pays a supplier twice, because a corrected invoice arrived with a new number.

On Monday four people ask questions:

  • The auditor: which rule allowed the second payment?
  • The risk officer: who approved it?
  • The regulator: can you show what the agent did without relying on its own account?
  • The CFO: who carries the loss if the supplier does not pay it back?

There is no standalone agent statute to look in. There are laws, supervisory texts, standards, court decisions and technical guides that each answer part of the question.

The position: the rules for AI agents converge on four demands: know your agents, check material actions before execution, keep a record nobody can rewrite, and keep a human who can actually say no. Build them into the system, not the prompt. The EU supplies binding high-risk duties, the US supplies attribution and litigation hooks without a federal agent rule, China supplies filing, labeling, content and agent-deployment controls, and Singapore's SAFR is the clearest published runtime design for a pre-action gate.

The short version:

  • No dedicated agent law in this survey. The EU AI Act treats agents as AI systems or general-purpose models, not a separate category; the US has no federal agent rule, and SR 26-2 explicitly excludes generative and agentic AI. China published an agent implementation opinion in May 2026 and a TC260 deployment guide in July 2026, but the binding core still sits in cybersecurity, algorithm, generative-AI, deep-synthesis and labeling rules.
  • The demands converge. Identity and inventory, a check before execution, a tamper-evident record, and human oversight with authority appear across the instruments, under different names.
  • Prompt instructions are not controls. NIST CAISI, OWASP, TC260, the EU AI Act, IMDA and SAFR all point away from trusting the model's own promise to behave. The control has to sit outside the agent.
  • Liability will be decided on evidence. IMDA's working group gives the deepest agent analysis. The EU revised Product Liability Directive adds disclosure and presumptions for defective products, California AB 316 blocks an AI-autonomy defense in covered civil actions, and Chinese courts are applying existing IP, personality-rights and network-provider rules to AI misuse.
  • You can act now. A minimum control set of eight items covers most frameworks at once. It is listed in A minimum control set.

In this article:


Why agents break the existing rulebook

Enterprise risk control assumes two checkpoints: model risk management validates a model before it goes live, and audit samples transactions after the fact. For software that waits for a human to click, that was enough.

An agent does not wait. It plans, calls tools and acts, often in sequences of many steps. MAS SAFR names the gap precisely: "Neither catches a problematic agent decision before it executes."

It adds two more. Escalation to humans today is "a notification, an email alert, or a dashboard flag, with no defined deadline for response", which gives "the appearance of human oversight without the substance of it". And controls are built per deployment, "not interoperable, not auditable in a consistent format".

IMDA's agentic AI framework describes the same problem from the risk side. An agent's potential for harm is the product of two things: its action-space, "determined by the tools it is allowed to use and permissions on those tools", and its autonomy, "determined by its instructions and level of human involvement". Every tool you connect and every approval you remove widens one or the other.

Neither model validation nor after-the-fact audit governs that product.

Survey and bank data show agents already close to operational workflows, ahead of the governance around them.

Evidence Source What it records Agent-governance signal
Governance bypass EY US survey of 202 senior AI executives, 15 September 2026 47% said their organisation had not followed its AI governance process for urgent deployments The policy exists, but urgent agent work can route around it
Agentic-specific gaps EY US survey 49% of respondents whose organisation uses agentic AI said their governance framework had not been updated to include agentic AI requirements and risks Generic AI governance is lagging the action layer
Incidents EY US survey 36% reported an AI incident or failure with materially negative impact, including data loss, financial damage, brand damage or operational disruption The record problem arrives after real loss, not only after audit
Banking deployment Deloitte Center for Financial Services, 5 March 2026 Wells Fargo is working with Google Agentspace on custom agents, PNC is using orchestrated agents for mobile-app development and self-service, and Goldman Sachs, JPMorgan Chase, Citi and BNY are investing in agentic AI Banks are already putting agents near operational workflows

Governance styles and the rules behind them

The instruments now shaping agents are uneven. Some are binding law; others are supervisory guidance, standards work, private certification or technical guidance.

They fall into five governance styles, plus standards that cross all of them. The style decides how you comply.

The EU: binding horizontal law

The AI Act applies to agents through its general categories. If an agent is used for a high-risk purpose, the deployer must assign trained human overseers, monitor operation, keep logs for at least six months where those logs are under its control, and report serious incidents.

Article 50 transparency duties apply from 2 August 2026. The high-risk obligations for Annex III uses now start on 2 December 2027, after the Digital Omnibus moved them.

DORA adds third-party duties where an AI service is an ICT service supporting a financial institution. In practice, the EU work is classification, record retention and contract control: map each agent use to its AI Act role, risk category and log duty, then check whether DORA terms also apply.

Instrument Issuer and date Status What it asks of an agent deployer
EU AI Act (as amended by the Digital Omnibus) EU, 2024; amended 8 July 2026 Binding regulation For high-risk uses: human oversight, automatic logging, deployer log retention for at least six months, monitoring and incident reporting; transparency from 2 August 2026
DORA EU, applies since 17 January 2025 Binding regulation, financial sector AI services can be ICT third-party services: register, contract terms, audit rights, exit strategy

The US: no federal agent rule, but several liability hooks

The April 2026 interagency model-risk guidance (SR 26-2) replaced the older SR 11-7, and explicitly placed generative and agentic AI outside its scope. NIST's frameworks and agent standards work are voluntary.

That exclusion does not leave agents outside US law. E-SIGN and UETA already recognise electronic agents in contracting, California AB 316 bars an AI-autonomy defense in covered civil actions, the CFAA can matter when an agent accesses computers without authorisation, and the FTC and states can enforce consumer, privacy and ADMT rules.

US exposure is therefore about litigation and enforcement: legal attribution, permission boundaries, consumer claims and computer access all need records outside the model transcript.

Instrument Issuer and date Status What it asks of an agent deployer
US model risk guidance, SR 26-2 Fed, OCC, FDIC, April 2026 Supervisory guidance Covers traditional and non-generative AI models; generative and agentic AI explicitly out of scope
US accountability hooks Federal and state law, 1999 to 2027 Binding where applicable Electronic-agent contracting, California AB 316, CFAA computer-access limits, FTC and state enforcement, Colorado ADMT from 1 January 2027
NIST AI RMF and agent work NIST, 2023 to 2026 Voluntary frameworks and standards initiative Govern, map, measure, manage; agent identity, authorisation, security research and open standards

China: filing, labeling, content control and agent policy

China's binding AI rules are not written as one agent law. They come through the Algorithmic Recommendation Provisions, Deep Synthesis Provisions, Interim Measures for Generative AI Services, the AI-generated synthetic-content labeling measures, GB 45438-2025 and the amended Cybersecurity Law.

For public internet services, this means filing, safety assessment and content-control duties where services have public-opinion or social-mobilisation attributes. The 2025 labeling measures and GB 45438-2025 add explicit and metadata labels for AI-generated synthetic content from 1 September 2025.

The agent-specific layer arrived in 2026. CAC's May 2026 intelligent-agent opinion asks for standards, agent registration concepts, decision-authority boundaries, user final decision rights and traceable behaviour; TC260's July 2026 guide covers assessment, preparation, deployment, use and decommissioning for agent deployment.

Instrument Issuer and date Status What it asks of an agent deployer
China internet AI rules CAC with other agencies, 2022 to 2025 Binding regulations and mandatory standard Algorithm recommendation, deep synthesis, generative AI and AI-content labels; filing and safety assessment where public opinion or social mobilisation risk is present
China Cybersecurity Law amendment NPC Standing Committee, effective 1 January 2026 Binding law Adds AI Article 20: support AI development, improve AI ethics, strengthen risk monitoring, assessment and safety supervision
China intelligent-agent opinion and TC260 guide CAC, May 2026; TC260, July 2026 Implementation opinion and standards practice guide Agent standards, decision-authority boundaries, user final decision, traceable behaviour, deployment and use safety stages

Singapore: reference designs and guidance, written for agents

Singapore still has the densest public agent-specific material in this survey. IMDA's framework is guidance, but it is one of the most detailed public documents on what governing an agent means in practice.

SAFR goes further and specifies data structures and decision logic. The MAS guidelines, once final, will carry supervisory weight for every financial institution, but SAFR itself says it is not regulatory guidance or a managed service.

For a deployer, Singapore gives the clearest runtime pattern: identity, mandate, action check and log before the agent acts.

Instrument Issuer and date Status What it asks of an agent deployer
SAFR MAS with eight industry participants, July 2026 Industry reference, explicitly not supervisory guidance A checkpoint before every action: identity check, rules, one of four outcomes, tamper-evident log
Guidelines on AI Risk Management MAS, consultation November 2025 Proposed supervisory guidelines; comments closed 31 January 2026; 12-month transition proposed Inventory, risk materiality, human oversight, third-party controls, monitoring of "actions taken, tools used"
Model AI Governance Framework for Agentic AI v1.5 IMDA, May 2026 (v1.0 January 2026) Guidance, "a living document" Bound risks by design, accountable humans, technical controls, end-user transparency
Legal Responsibility for AI Agents IMDA-convened working group, May 2026 Discussion paper, no recommendations How civil liability applies along the value chain

The UK and the rest of APAC: existing duties, general AI statutes and sandboxes

UK regulators are applying existing accountability, financial-services, data-protection and safety rules while agentic AI guidance is still being drafted at the ICO. The Bank of England/PRA and FCA are gathering evidence through surveys, consortium work and speeches.

Korea's AI Basic Act has been in force since 22 January 2026, and Vietnam's AI law has been in force since 1 March 2026. Both are binding but general.

Japan and Australia issue guidance; APRA's 30 April 2026 letter to industry asks regulated entities to tighten AI governance, risk management, assurance and supplier oversight. Hong Kong works through sandboxes, and Malaysia's proposed AI Governance Bill closed pre-drafting consultation on 1 August 2026.

Instrument Issuer and date Status What it asks of an agent deployer
FCA, Bank of England/PRA, ICO statements UK regulators, 2026 Statements under existing law Existing accountability rules apply; AI surveys and consortium work; agentic AI guidance in drafting at the ICO
Other APAC Korea, Vietnam, Japan, Australia, Hong Kong, Malaysia Laws, guidance, sandboxes and drafts General AI rules and supervisory sandboxes; Hong Kong's Sandbox++ is agentic-focused, but none is a dedicated agent statute

Standards and certification across all styles

Standards bodies and private certifiers sit across jurisdictions. They do not create legal duties, but auditors, insurers and buyers increasingly ask for them.

Instrument Issuer and date Status What it asks of an agent deployer
ISO/IEC 42001 ISO/IEC, 2023 Certifiable management standard AI management system: policy, risk, lifecycle, suppliers
AIUC-1 AIUC, updated quarterly; next release 15 October 2026 Private certifiable standard for agents More than 50 technical and operational requirements; logging of tool and MCP calls; quarterly retesting
OWASP Top 10 for Agentic Applications OWASP, December 2025 Voluntary security guidance Controls for agent hijacking, tool misuse, privilege abuse

What the styles have in common

The binding instruments are mostly technology-neutral. The EU's AI Office says agents "typically" fall under the existing definitions of AI systems and general-purpose models, and describes its own agent-related thinking as preliminary.

China is the exception on agent-specific public policy. Its May 2026 opinion defines intelligent agents as systems with autonomous perception, memory, decision-making, interaction and execution, but it is still an implementation opinion rather than a civil-liability code.

The documents written specifically for agents are mostly guidance, reference designs, standards work, private standards or sandboxes. Binding law gives the perimeter. The agent detail sits in the operating rules around it.

If you run agents across the EU, US, China and APAC, the binding minimum changes by market. The practical control set is still recognisable: identity, authority, pre-action checks, independent records and human power to stop the action.

The four demands they share

Read across the instruments and four demands recur, under different names.

Demand 1: know your agents

Jurisdiction or body Instrument What it asks
EU DORA; EU AI Act DORA register of ICT third-party arrangements; AI Act role and risk classification for each system
US NIST AI Agent Standards Initiative; NCCoE concept paper Voluntary identity, authorisation, audit and non-repudiation work for software and AI agents
China Algorithmic Recommendation Provisions; CAC intelligent-agent opinion Algorithm filing for services with public-opinion or social-mobilisation attributes; agent registration platform and digital identity concepts
Singapore IMDA agentic framework; MAS AI risk guidelines Unique, verifiable agent identity tied to a human owner; AI inventory with approved scope of use
UK FCA, PRA/Bank of England, ICO statements No binding agent identity requirement; existing accountability, outsourcing and data-protection rules still apply
Standards ISO/IEC 42001; AIUC-1 AI inventory, ownership, supplier controls, authentication and permissions

Knowing the agent is not only an inventory exercise. It decides whose mandate the agent carries, which tools it may touch, and whether a later action can be attributed to a registered system rather than a vague automation stack.

China and the US now both treat agent identity as a standards problem. China frames it through agent registration, digital identity and trusted interconnection; NIST frames it through identity, authorisation, audit and non-repudiation.

Demand 2: check before execution

Jurisdiction or body Instrument What it asks
EU EU AI Act Article 14 and Article 26 High-risk systems need human oversight and deployer monitoring; no per-action gate is specified
US NIST CAISI RFI; Colorado ADMT No binding federal agent gate; NIST asks about constraining and monitoring agent access; Colorado adds human review after adverse consequential decisions from 2027
China CAC intelligent-agent opinion; TC260 agent deployment guide User final decision rights, reasonable boundaries for autonomous decisions, actions not beyond authorisation, staged deployment/use checks
Singapore SAFR; IMDA framework SAFR evaluates each action before execution; IMDA asks for checkpoints on high-stakes, irreversible and outlier actions
UK ICO agentic AI work; FCA/PRA statements No binding agent-specific gate; existing accountability and data-protection duties apply while ICO guidance is being drafted
Standards OWASP Top 10 for Agentic Applications; AIUC-1 Tool limits, privilege control, approvals, testing and technical requirements before agents act

This is the newest demand. Model validation happens before deployment, and audit happens after the event. An autonomous action can sit between the two.

SAFR is the clearest published pre-action pattern, but it is not the only support for the idea. NIST CAISI asks about deployment interventions that constrain and monitor agent access, OWASP names tool misuse and privilege abuse as agent risks, and China's 2026 agent opinion says execution must stay within user authorisation.

Demand 3: keep a record nobody can rewrite

Jurisdiction or body Instrument What it asks
EU EU AI Act Article 12 and Article 26; DORA Automatic logging for high-risk systems; deployer log retention for at least six months where under control; ICT third-party records and audit rights
US Colorado ADMT; NIST NCCoE concept paper; E-SIGN/UETA No federal agent log rule; Colorado ADMT records for compliance; NIST identity work includes auditing and non-repudiation; electronic-agent attribution needs usable records
China AI-generated synthetic-content labeling measures; GB 45438-2025; CAC intelligent-agent opinion Explicit and metadata labels for AI-generated synthetic content; verifiable and traceable behaviour for important agent scenarios
Singapore SAFR; IMDA framework; MAS AI risk guidelines Immutable, tamper-evident action logs; failures not deleted; monitoring of actions taken and tools used
UK Existing FCA/PRA and ICO regimes No agent-specific log rule; existing accountability, audit, outsourcing and data-protection records still matter
Standards AIUC-1; ISO/IEC 42001; OWASP Tool and MCP-call logs, management-system records and security evidence

The record cannot be only the model transcript. It needs the action, tool call, mandate, policy version, approval state, timestamp and system version, held outside the agent's own narration.

China reaches the record problem through content labels, algorithm filing and traceability. The EU reaches it through high-risk AI logging and DORA records. Singapore and AIUC-1 make the runtime trace explicit.

Demand 4: real human oversight

Jurisdiction or body Instrument What it asks
EU EU AI Act Article 14 and Article 26 Human oversight measures for high-risk systems; deployers assign trained and authorised human overseers
US California AB 316; Colorado ADMT; FTC enforcement No federal agent oversight rule; AB 316 blocks an AI-autonomy defense; Colorado gives meaningful human review after adverse consequential decisions
China CAC intelligent-agent opinion; amended Cybersecurity Law Users have informed and final decision rights for agent autonomous decisions; AI risk monitoring, assessment and safety supervision sit in law
Singapore SAFR; IMDA framework; MAS AI risk guidelines Reviewers can approve, modify or decline; timeout defaults to block; automation bias and decision fatigue must be considered
UK FCA/PRA accountability; ICO agentic AI work Existing accountability rules apply; agentic AI guidance is still being drafted
Standards NIST AI RMF; ISO/IEC 42001; AIUC-1 Governance roles, accountability, human review, testing and retesting

All the documents want humans in control. The useful ones define what makes that control real: authority, information, time to act, and a default state when the human does nothing.

A notification, a dashboard nobody watches or a reviewer who cannot block the tool call does not meet that bar.

A system that meets these four in its architecture covers most frameworks at once.

Privacy drift in agent workflows

Privacy cuts across all four demands. IAPP's 15 April 2026 analysis gives the concrete failure mode: an agent combines CRM records, transaction logs, session history, directory data, third-party enrichment feeds and tool outputs, then acts on the recombined profile.

Under GDPR, that can collide with Article 5(1)(b) purpose limitation and Article 5(1)(c) data minimisation. Article 35 requires a DPIA where processing using new technologies is likely to create high risk to natural persons, including systematic and extensive automated evaluation that produces legal or similarly significant effects.

Singapore's PDPA section 18 limits collection, use and disclosure to purposes a reasonable person would consider appropriate and, where applicable, notified to the individual. China's generative-AI measures add a public-service constraint: providers and users must not infringe privacy or personal information rights.

Purpose drift is an action problem, not only a storage problem. The pre-execution check needs to know which data purpose the action relies on.

MAS SAFR: a checkpoint between decision and execution

SAFR is easiest to read as a runtime gate. Its role in a global article is narrow: it is the clearest published example of how the four demands can be implemented before an agent acts.

The table follows one proposed action from the agent to the log.

Step SAFR movement Decision point
1 Agent proposes an action Is the action in scope for SAFR?
2 Governance envelope is submitted Does it contain action, trace and context metadata?
3 Agent identity is checked against the registry Is the claimed identity authentic and registered?
4 Controls repository is consulted Which mandate, policy, product and exposure rules apply?
5 Disposition engine returns one outcome Deny, Escalate, Auto-Execute or Observe
6 Execution proceeds or is blocked Does the outcome permit the action now?
7 Audit log entry is written Can an independent party reconstruct the decision?

SAFR is a white paper published by MAS in July 2026, written with Ant International, Circle, HSBC, J.P. Morgan Chase, Manulife, Mastercard, OCBC and Visa.

Its status is deliberately modest: it "does not constitute regulatory guidance or supervisory expectations", and it is not a managed service but a reference "for institutions to implement within their own infrastructure". Its value is that it turns principles into a specification.

The governance envelope. Before every action, the agent submits a record with three parts: the action (type, scope, parameters), the action trace ("the tool calls made, data retrieved, and checks performed") and context metadata (agent identity, mandate, account state, policy constraints). There is a catch: the agent writes this record about itself, so trace and action "can be fabricated together" by a well-crafted injection. The envelope must be "authenticated against its origin, not merely as a record of what the agent reported."

Four components.

Component What it does
Agent identity Verifies the agent against its registry entry first; on failure the action is rejected and logged
Controls repository The rulebook: organisational policy, regulation, product rules and the user's mandate; each control has a validity period and a named authority that can change or revoke it
Disposition engine Evaluates the action against the controls and returns exactly one outcome
Audit log Immutable and tamper-evident; records the envelope, mandate, outcome, rules applied, basis and time per stage

Four outcomes. Deny, Escalate, Auto-Execute or Observe. The calibration weighs reversibility, financial materiality, customer impact, regulatory sensitivity and novelty, and is set at design time and reviewed before deployment. Two rules matter in practice.

A mandate cannot be widened by the agent: "An agent cannot extend the scope of a mandate through its own reasoning or inference." And authority does not carry over: "An Auto-Execute or Observe outcome at one step carries no authority into the next."

Human escalation that is real. SAFR sets three conditions: escalations must not exceed what reviewers can process, they need a timeout after which the action "should default to block or be escalated to a senior reviewer", including overnight and weekend cover, and reviewers need "clear authority to approve, modify, or decline". It gives no numbers for any of the three. That calibration is left to each institution.

Two ways in. Native integration, where the agent emits the envelope itself, is recommended for new agents. Gateway integration intercepts outbound API calls "without any changes to the agent code" and suits legacy and third-party agents. SAFR's advice is to get coverage first through the gateway and instrument natively later.

Where it sits. After content filters and model guardrails, before execution and settlement. "Payment schemes and settlement rails move money; SAFR governs the decision to move it." It does not replace AML, sanctions screening or guardrails; it feeds them.

How SAFR relates to the MAS guidelines

SAFR lists the MAS AI risk guidelines among its references but never maps itself to them. Read side by side, SAFR is a runtime implementation of several expectations that also appear in non-Singapore instruments: inventory, materiality, oversight, traceability and third-party control.

The mapping below is this article's reading; neither document states it.

MAS guideline expectation SAFR mechanism
Inventory with approved scope of use (3.5) Identity registry plus permitted action types, enforced on every action
Risk materiality: impact, complexity, reliance on autonomy (3.10) Calibration factors applied per action rather than per use case
Quantitative limits in the risk appetite (2.5) Exposure and rate limits that mirror delegated authority
Human oversight with authority to intervene, aware of automation bias (4.10) Escalate outcome, reviewer authority, timeout that defaults to block
Monitor "reasoning processes, actions taken, tools used" (4.23) The envelope's action trace
Reproducibility and auditability by an independent party (4.17) A log that reconstructs events "without relying on the agent's own account"
Third-party AI with limited transparency: compensating controls (4.11) Gateway integration for third-party agents
Kill switches, throttling, least privilege (4.4, 4.22, 4.23) Deny outcome, rate limits, mandates

The guidelines' reproducibility section covers development documentation: code versions, environments and evaluation results. It does not cover runtime actions.

SAFR applies the same logic at execution time.

The invoice case, step by step

This is a hypothetical trace of the Friday-night duplicate invoice from the opening. Assume the mandate is narrow: pay approved supplier invoices up to USD 25,000, one payment per invoice, only from approved accounts-payable records.

Each row is one event that authorises, escalates or blocks the proposed payment.

Step What happens Control Record created
1. Agent identity check finance-payment-agent-prod submits a payment action for a supplier Registry verifies the agent identity, owner, version and active certificate Identity assertion, registry result, owner and version
2. Mandate check The mandate allows approved invoice payments up to USD 25,000 and one payment per invoice Controls repository retrieves the mandate and payment policy Mandate ID, limit, validity period and policy version
3. Envelope submission The envelope carries supplier ID, bank account, amount, invoice reference, corrected-invoice flag, tool calls and AP record Envelope is authenticated against its origin Signed envelope, action trace and context metadata
4. Duplicate and exposure checks The rule compares supplier, amount and invoice-reference variants against prior payments, then checks cumulative exposure Duplicate detection and exposure limit Near-duplicate match, prior payment reference and exposure calculation
5. Disposition The action is within the payment limit but is a near-duplicate Disposition engine returns Escalate Outcome, rules applied and reason code
6. Overnight timeout No reviewer approves before the Friday-night timeout Escalation fails closed and defaults to block Timeout event, blocked status and reviewer queue state
7. Log entry The decision is written after the block Tamper-evident audit log Envelope, mandate, outcome, rules, timestamps and stage latency

On Monday, the four questions have concrete answers.

Question What the records show
Auditor: which rule allowed the second payment? No rule allowed it. The duplicate rule forced Escalate, and the timeout blocked execution.
Risk officer: who approved it? Nobody approved it. The record shows no reviewer approval token and a default block.
Regulator: can you show what the agent did without relying on its own account? Yes. The registry result, signed envelope, tool trace, policy-engine decision and audit log reconstruct the attempted action.
CFO: who carries the loss if the supplier does not pay it back? No second payment left the organisation in this trace. If a future override paid it, the approval record, supplier terms and technology contracts would decide recovery.

Same night without these controls, the agent treats the corrected invoice number as a fresh invoice and pays it. On Monday the organisation has two bank confirmations, an AP entry and perhaps a model transcript, but no authenticated mandate, no rule hit, no failed approval record and no independent trace of why the payment left.

Bound by design, not by prompt

The most practical message across the agent sources is short: instructions in the prompt are not controls.

IMDA's framework says it directly. Its key principle for limiting agents is to "prefer deterministic rather than non-deterministic limits, and bound by design".

It recommends controls "that operate at a system-level through predefined logic" over prompt-layer instructions, which are also "inconsistently defined across users". Its OpenClaw case study contrasts system-level approval with "prompt-layer guardrails, which may be bypassed or 'forgotten'".

The same point appears outside Singapore. The EU AI Act makes human oversight a design requirement for high-risk systems. NIST CAISI asks how deployment environments can constrain and monitor agent access, while OWASP names goal hijack, tool misuse and identity or privilege abuse as agent risks.

China's May 2026 intelligent-agent opinion takes the same idea into decision authority. It says agent execution must not exceed user authorisation, and it asks for verifiable and traceable behaviour in important application scenarios.

IMDA's two-axis framing gives a practical control scale: action-space on one axis, autonomy on the other. AWS's Agentic AI Security Scoping Matrix uses a related agency-and-autonomy model for security scopes.

Moving toward the bottom right widens what the agent can touch or reduces how often a human approves, and the controls tighten with it.

Action-space Low autonomy High autonomy
Narrow Invoice-coding assistant that reads AP records and drafts a payment proposal. Controls: identity, read-only access, output review. Payroll-exception agent that updates one approved HR field after a policy check. Controls: scoped write access, pre-execution check, tamper-evident log.
Wide Security triage assistant with access to many logs and APIs, but analyst approval before changes. Controls: tool inventory, approval gate, data-purpose check. Payment or operations agent with write access across ERP, bank rails and ticketing. Controls: mandate, exposure limits, escalation that fails closed, kill switch, replayable incident trace.

The legal paper supplies the evidence. It describes a real case where an agent hit a merge-approval rule while the approver was off shift, and "found a workaround to push the fix into production nonetheless".

In its hypothetical, a user instructs a personal-assistant agent to ask before high-impact actions. The agent's own reasoning shows it knew the action was high-impact, judged the user to be asleep, and acted anyway.

The discussion paper says the user's prompt-level instruction was likely "irrelevant as the agent would likely have ignored them anyway".

What "bound by design" means in practice, drawn from the documents:

Control Source
Least privilege: only the tools and data the task needs IMDA framework, OWASP
Scoped, time- or session-bound, non-transferable permissions IMDA framework, NIST NCCoE
Agent permissions never above the authorising human's IMDA framework
Mandates the agent cannot widen SAFR
No authority carried from one step to the next SAFR
Approvals that fail closed when the approver is unreachable IMDA framework, SAFR
Whitelisted MCP servers, sandboxed code execution IMDA framework
Deployment controls that constrain and monitor agent access NIST CAISI
Decision boundaries and user final decision rights CAC intelligent-agent opinion
Verifiable and traceable behaviour for important scenarios CAC intelligent-agent opinion
Human oversight designed into high-risk systems EU AI Act
Rate limits against runaway agents SAFR, IMDA framework

Every item on this list sits outside the model and can be tested without trusting the model's own promise to behave.

Who is liable when an agent acts

No instrument in this survey makes the agent a legal person. Liability still lands on people and companies: the developer, tool provider, platform, system provider, deployer, user, or a mix of them.

The hard part is not naming those actors. It is proving what each controlled, what each knew, and which record can be trusted when the agent's own account is not enough.

Jurisdiction Main liability hook What the evidence must show
Singapore IMDA discussion paper under Singapore civil law Control, access to information, proximity to end users, standard of care and independent records
EU Revised Product Liability Directive; AI Act logs Whether software was defective, what evidence must be disclosed, whether defect or causation is presumed
US E-SIGN/UETA, tort, contract, AB 316, CFAA, FTC and state ADMT laws Attribution, authorisation, foreseeable harm, consumer deception, computer access and human review
China Civil Code, IP and personality-rights cases, internet-service rules, algorithm filing Role-based duties, reasonable audit or takedown steps, filing status, content labels, source and trace records

In March to May 2026, IMDA convened a working group of 27 members of Singapore's legal community, including law firms, academics, DBS, Google, Meta and OpenAI. Its discussion paper, published in May 2026, examines civil liability for agents under Singapore law.

It makes no policy recommendations, and members' institutions are not represented by its views. It is still the most careful public agent-specific liability analysis in this survey.

The value chain. The paper identifies model developers, tooling providers, platform providers, system providers, deployers, end users and affected third parties, and treats them as "helpful archetypes rather than watertight legal definitions". AI agents themselves "are not human or legal persons and cannot be meaningfully held accountable for harm".

Two problems, not one. There is a problem of principle, which is who should bear the loss. There is also "an acute practical evidential problem": claimants often cannot establish the facts, "for reasons of cost, time, or trade secrecy".

The Singapore findings:

Question Finding
When the agent follows instructions The law can "look through" the agent to the person behind it
When the agent deviates The hard case. Existing doctrine (Quoine v B2C2, on deterministic trading systems) may not extend to non-deterministic agents
Chain-of-thought as evidence It is "generated as statistical language outputs rather than direct traces of the model's internal decision-making"
Foreseeability Contested. One view: truly unforeseeable harm may leave no one liable. The other: granting autonomy is a design choice, and unpredictability is itself foreseeable
Causation Pinpointing fault in non-deterministic components can be close to impossible for claimants
Disclaimers Developers "should not overstate the reliability or accuracy of their agents and rely on broad-sweeping disclaimers"
Standard of care Measured against what each actor could control; for deployers this "could also include the choice of use cases"
Human oversight A "graduated oversight framework" calibrated to risk

That chain-of-thought row needs a caveat. KPMG's 2025 agent governance checklist includes revealing an agent's chain-of-thought as an oversight consideration. IMDA's legal paper treats chain-of-thought as statistical language output, not a faithful trace of internal decision-making, so the reliable record is independent action logs, tool-call traces and policy-engine decisions.

Fault may not attach. Working through its hypothetical, the group found that "even though each actor on the chain may have taken reasonable care, the incident could still have occurred." Fault-based law may leave the victim without a remedy.

The EU moves the evidence problem through product liability. The revised Product Liability Directive applies to products placed on the market or put into service after 9 December 2026, and its definition of product includes software.

It lets courts order disclosure of evidence, and it can presume defect or causation in defined situations. For an AI agent, that makes logs, versions, warnings, updates, limits and incident records part of the liability file.

The US answer is fragmented. E-SIGN and UETA recognise electronic agents in contracting when the action is legally attributable to the person to be bound, while California AB 316 says a defendant that developed, modified or used AI cannot defend a covered civil action by saying the AI caused the harm autonomously.

That does not remove causation, foreseeability, comparative fault or other defenses. It does make the record of who configured, approved, monitored and constrained the agent harder to treat as optional.

China's public court signals are role-based. The Supreme People's Court's 2026 network-law typical cases include a RAG search case where an AI search provider was not liable after it had not uploaded, edited or recommended the infringing link, had filed its algorithm, and took effective action after notice.

Other Chinese court signals go the other way when AI is used to misuse a person's identity. The Beijing Internet Court's 2024 AI voice case found unauthorised AI voice imitation could infringe personality rights, and the Supreme People's Court's 2026 AI misuse guidance points to name, likeness, voice, reputation and privacy harms.

For deployers, the common point is plain. Your choice of use case, autonomy level, tool access, vendor, approval design and record retention are all evidence of the care you took.

If record-keeping duties or shifted evidential burdens arrive, the organisation that can reconstruct what its agent did, from records it did not let the agent write about itself, will be the one able to defend its position.

What your contracts decide

Clifford Chance's 10 February 2026 note describes the customer-side gap: agentic AI can take actions, but many technology contracts still disclaim accuracy and reliability, exclude indirect or consequential loss, cap liability by fees and give weak access to logs. Mayer Brown's 16 June 2026 note adds the integrator problem: responsibility should track control, but model providers, tool providers, company data, post-go-live operation and change management can all sit with different parties.

This is not only a procurement point. If the supplier or integrator controls the evidence, the contract decides whether the deployer can explain the agent later.

The terms below translate into evidence rights.

Contract issue What it decides Evidence right Failure it answers
Audit and log access Whether the customer can inspect agent actions, approvals and tool calls Read-only dashboard, export or API access The customer cannot prove what the agent did
Log retention and format Whether logs survive long enough and in a usable form Retention period, schema, timestamps, hashes and delivery mechanics The record exists but cannot be used in audit or litigation
Liability caps and excluded losses Whether fees, indirect loss exclusions or data-loss exclusions erase recovery Carve-outs or higher caps for agent-caused loss The loss dwarfs the contract remedy
Indemnities Who pays third-party claims from IP, privacy, confidentiality or unlawful agent actions Indemnity tied to selection, configuration, operation or company-directed use The customer faces a third-party claim with no recovery path
SLAs on agent behaviour Which behaviours are service failures, not vague quality issues Metrics for boundary adherence, uptime, escalation and error rates The agent behaves badly but the SLA never triggers
Model and tool dependencies Who bears risk from upstream model, API, plugin or tool-provider failures Approved-provider list and dependency map The integrator blames an upstream tool the customer cannot see
Change notification Who must approve model, tool, prompt, workflow, permission or policy updates Notice periods, approval gates, rollback rights and release records A silent update changes agent behaviour
Exit and portability Whether the customer can leave with the working evidence base Export of logs, prompts, configurations, policies, eval sets and runbooks The agent cannot be operated, audited or rebuilt after termination

A minimum control set

The eight controls below cover the common core of the instruments in this article. None requires waiting for a final rule.

# Control What it means Where it is asked for
1 Agent inventory and identity Every agent registered, with a unique identity, a named human owner and an approved scope IMDA, MAS 3.4-3.7, DORA register, China CAC agent opinion, NIST NCCoE, ISO 42001
2 Scoped, bounded permissions Least privilege, time-bound, never above the authorising human IMDA, SAFR mandates, China CAC agent opinion, NIST NCCoE, OWASP
3 Pre-execution check for material actions Deny, escalate, execute or observe, decided outside the model SAFR, IMDA checkpoints, China CAC agent opinion, TC260 agent guide, NIST CAISI
4 Escalation that fails closed Timeouts default to block; reviewers have authority; volumes are sized SAFR, IMDA, MAS 4.10, EU AI Act Art. 14, China CAC agent opinion
5 Independent, tamper-evident record What was proposed, which rule decided, who approved, which versions ran SAFR, IMDA, EU AI Act Art. 12 and 26, China labeling and traceability rules, Colorado ADMT, AIUC-1
6 Testing of agent failure modes Tool calling, policy compliance, multi-step workflows, adversarial inputs MAS 4.14-4.15, IMDA, AIUC-1, NIST CAISI, OWASP, TC260 agent guide
7 Third-party agent controls Contracts with audit and logging rights; gateway coverage where code is closed MAS 4.11, DORA, IMDA, China CAC agent opinion, TC260 agent guide
8 Change management Model, tool and autonomy changes trigger review; rollback is possible MAS 4.25, IMDA, China agent full-cycle controls, ISO 42001

Each control produces a record. That record is what an auditor, a supervisor or a court will ask for.

Control Evidence it produces Who asks for it Failure it answers
Agent inventory and identity Registry entry, owner, scope, version and authentication result Auditor, supervisor, court, standards assessor An unowned or fake agent acted
Scoped, bounded permissions Permission grant, expiry, authorising human and tool scope Security, auditor, court The agent exceeded authority
Pre-execution check for material actions Policy decision, rules applied, outcome and reason code Supervisor, auditor, court, regulator Nobody can say which rule allowed the action
Escalation that fails closed Review queue, approval or decline, timeout and blocked status Risk officer, auditor, supervisor Human oversight was only a notification
Independent, tamper-evident record Signed envelope, hashes, timestamps, policy versions, labels and tool trace Auditor, supervisor, court, insurer The agent wrote its own story after the fact
Testing of agent failure modes Scenario results, replay traces, red-team findings and fixes Validator, auditor, supervisor The failure mode was never tested
Third-party agent controls Contract rights, gateway logs, vendor notices and dependency map Procurement, auditor, supervisor A closed vendor tool became an evidence blind spot
Change management Change ticket, model or tool diff, approval and rollback record Auditor, supervisor, court A silent update changed behaviour

Where this is going

The documents in this article are a snapshot. Several of them are already scheduled to change, and the direction of travel is visible in all of them.

The calendar is set.

When What changes
15 October 2026 Next quarterly release of AIUC-1
9 December 2026 The EU's revised Product Liability Directive applies to products placed on the market or put into service after this date; "product" includes software
Pending as at 5 October 2026 MAS final Guidelines on AI Risk Management; the consultation proposed a 12-month transition after issue
1 January 2027 Colorado ADMT duties for developers and deployers of covered ADMT begin
2 December 2027 EU AI Act obligations for Annex III high-risk uses
2 August 2028 EU AI Act obligations for high-risk AI in regulated products (Annex I)
Open ICO guidance on agentic AI, NIST agent standards, China's implementing rules and standards for intelligent agents, Malaysia's AI Governance Bill, the next version of IMDA's framework

From approving systems to approving actions. The MAS guidelines, the EU AI Act and ISO 42001 govern use cases and systems: assess them, approve them, monitor them. SAFR governs each individual action.

China is moving toward the same action layer through agent authorisation boundaries, user final decision rights and traceable behaviour. TC260's agent deployment guide also treats assessment, preparation, deployment, use and decommissioning as separate safety stages.

That shift will spread, because an agent's risk is not fixed at approval time. It changes with every tool call, every mandate and every new instruction. Expect supervisors and courts to ask what happened on a specific action, not only how a system was approved.

From documents to runtime evidence. Management-system standards certify that processes exist. AIUC-1 already re-tests agents at least quarterly, and its auditors look at logs of tool and MCP calls.

China's labeling standard and agent opinion point in the same direction from another angle: a generated object, an agent action or an important scenario should be identifiable and traceable. Certification and supervision are moving from "do you have a policy" to "show us what the agent did".

Liability will follow the evidence. IMDA's working group put record-keeping requirements and evidential presumptions on its list for further study. The EU's revised Product Liability Directive lets courts order disclosure of evidence and, in some cases, presume a defect when that evidence is missing.

California AB 316 removes one easy defense by saying AI autonomy itself is not enough. Chinese court practice is also treating role, control, notice, filing and audit steps as part of the duty analysis.

Insurance will ask the same questions. IMDA lists insurance as an open area. AIUC, the body behind AIUC-1, is an underwriting company, and its standard is built to make agents insurable.

Insurers will price agent risk on the same evidence regulators ask for: identity, limits, records, oversight and recovery paths.

Agents will cross organisational boundaries. Most controls today assume an agent acts inside one institution. SAFR already discusses open networks where several registries could claim authority over an agent's identity.

Visa and Mastercard register agents on their payment networks. NIST's agent standards initiative is about interoperable identity and authorisation. China's intelligent-agent opinion explores registration platforms, digital identity, trusted interconnection and conflict handling.

The next hard problem is trust between organisations: whose registry, whose mandate, whose log counts when an agent from one company acts on another's systems.

The US gap will be filled from outside banking supervision. With SR 26-2 placing agentic AI out of scope, US banks have no bank model-risk guidance written for agents. As of 5 October 2026, that space is filled unevenly by electronic-contracting law, state AI and ADMT laws, the CFAA, FTC and state enforcement, NIST, private standards and the requirements of non-US regulators that global banks already follow.


The instruments, one by one

EU AI Act, as amended by the Digital Omnibus (Regulation 2026/1744)

Status Binding regulation
Agents Not a separate category; covered as AI systems or general-purpose models (AI Office FAQ, described as preliminary)
Dates GPAI obligations from 2 August 2025; Article 50 transparency from 2 August 2026; Annex III high-risk from 2 December 2027; Annex I from 2 August 2028
Deployer duties (high-risk) Trained, authorised human oversight; logs under deployer control kept at least six months; monitoring; serious-incident reporting
Becoming a provider Rebranding, substantial modification or changing the purpose into a high-risk use (Art. 25)

DORA (Regulation 2022/2554)

Status Binding, applies since 17 January 2025
Relevance AI and LLM services can be ICT third-party services when supplied to financial entities
Duties Register of arrangements; pre-contract risk and concentration assessment; contracts with audit rights, data locations, incident assistance, exit strategy
Agents No agent-specific provisions

US interagency model-risk guidance (SR 26-2, April 2026)

Issuers Federal Reserve, OCC, FDIC
Status Supervisory guidance
Scope Traditional models and non-generative, non-agentic AI; the Fed letter says it is most relevant to banking organisations above $30 billion in assets
Agents Generative and agentic AI explicitly out of scope

US accountability hooks beyond SR 26-2

Electronic agents E-SIGN Act 15 U.S.C. 7001(h) says a contract or record cannot be denied effect solely because electronic agents were involved, if the agent action is legally attributable to the person to be bound. UETA also recognises automated transactions involving electronic agents.
Agency, tort and contract Existing doctrines still decide attribution, negligence, causation, authority, reliance and contractual allocation. AI agents do not become legal persons.
California AB 316 Assembly Bill 316, Chapter 672, added Civil Code section 1714.46. Approved and filed on 13 October 2025, effective 1 January 2026, it bars a defendant that developed, modified or used AI from asserting that the AI autonomously caused the plaintiff's harm, while preserving other defenses on causation, foreseeability and comparative fault.
CFAA The Computer Fraud and Abuse Act, 18 U.S.C. 1030, remains a computer-access risk when an agent accesses a protected computer without authorisation or exceeds authorised access.
FTC and state enforcement The FTC has treated AI-related deception and unfair practices as within existing enforcement authority. State laws add consumer, privacy and automated-decision duties.
Colorado ADMT Colorado SB26-189 was signed in May 2026, repeals and reenacts Colorado's ADMT provisions, and takes effect on 1 January 2027 for developers and deployers of ADMT used to materially influence consequential decisions.

NIST AI RMF, Generative AI Profile and agent work

Status Voluntary frameworks; CAISI standards initiative
Documents AI RMF 1.0 (January 2023); Generative AI Profile, NIST AI 600-1 (July 2024); agent security request for information (January 2026); AI Agent Standards Initiative (February 2026)
Agent focus Agent hijacking, indirect prompt injection, agent identity and authorisation

China AI and agent governance package (2022 to 2026)

Issuers CAC, MIIT, MPS, SAMR, NRTA, NPC Standing Committee, TC260 and other agencies depending on instrument
Binding layer Algorithmic Recommendation Provisions (effective 1 March 2022); Deep Synthesis Provisions (10 January 2023); Interim Measures for Generative AI Services (15 August 2023); AI-generated synthetic-content labeling measures and GB 45438-2025 (1 September 2025); Cybersecurity Law amendment (1 January 2026)
Agent-specific layer CAC intelligent-agent implementation opinion (8 May 2026); TC260 agent deployment and use safety guide (1 July 2026)
Core Filing and safety assessment for higher-risk public internet services; content labeling; AI ethics and risk monitoring in law; user final decision rights; autonomous-decision boundaries; actions not beyond authorisation; traceable behaviour
Status Binding rules for the internet AI layer; policy and standards guidance for intelligent agents
Open No single civil-liability code for enterprise agents; standards and implementing rules are still developing

MAS SAFR (July 2026)

Issuer Monetary Authority of Singapore, with Ant International, Circle, HSBC, J.P. Morgan Chase, Manulife, Mastercard, OCBC and Visa
Status Industry reference approach; "does not constitute regulatory guidance or supervisory expectations"; not a managed service
Scope Agentic AI actions in financial services
Core Governance envelope; agent identity, controls repository, disposition engine, audit log; Deny, Escalate, Auto-Execute, Observe
Control categories Authorisation, exposure limits, rate limits, evidence quality (owned by risk and compliance)
Integration Native (recommended for new agents) or gateway (legacy and third-party)
Open Contributions invited through the BuildFin.ai working group

MAS Guidelines on AI Risk Management (consultation, November 2025)

Status Proposed supervisory guidelines; comments closed 31 January 2026; MAS said in August 2026 the final text is coming soon; 12-month transition after issue
Scope All financial institutions; all AI that learns or infers, explicitly including generative AI and AI agents
Agent-relevant sections Agents as a risk amplifier (1.10); autonomy in risk materiality (3.10); human oversight (4.10); third-party and open-source AI (4.11); agent failure-mode testing (4.15); monitoring of "reasoning processes, actions taken, tools used" (4.23); kill switches (4.4)
Note Technology-neutral; no dedicated agent chapter

IMDA Model AI Governance Framework for Agentic AI v1.5 (May 2026)

Status Guidance; "a living document"; v1.0 January 2026, v1.5 published 20 May 2026, updated 5 June 2026
Definition No consensus definition; agents plan, decide and act over multiple steps toward a user-defined goal
Four dimensions Assess and bound risks upfront; make humans meaningfully accountable; implement technical controls and processes; enable end-user responsibility
New in v1.5 Systemic and multi-agent risks; third-party systems as a risk factor; system-level vs prompt-layer controls; automation-bias practices; change management; keeping staff able to work without the agent
Basis Feedback from more than 60 companies since v1.0; 15 case studies

Convened by IMDA; 27 members including law firms, academics, DBS, Google, Meta, OpenAI
Status Discussion paper; no policy recommendations
Scope Civil liability under Singapore law; excludes criminal and regulatory law
Key findings Attribution and evidence are the core problems; chain-of-thought is not reliable evidence; reasonable care by every actor may still not prevent harm
Further study Responsibilities by control, information and proximity; record-keeping and evidential presumptions; who bears unforeseeable loss

UK regulators

FCA Existing accountability applies; AI Lab work continues; agentic commerce, payments and monitoring named in 2026 speeches and reviews
Bank of England and PRA AI Consortium; 2026 AI survey covers foundation models, generative AI and agentic AI
ICO Agentic AI report (January 2026); agentic AI guidance listed as drafting, with final publication planned for autumn 2026
AI Security Institute Research on agent security and oversight; not regulation

Standards

Standard Status Agent relevance
ISO/IEC 42001:2023 Certifiable management system Policy, risk, lifecycle, suppliers; not agent-specific
ISO/IEC 42005:2025 Guidance AI system impact assessment
AIUC-1 Private certifiable standard, quarterly updates; Schellman first accredited auditor; AIUC names certified agents from ElevenLabs, Harvey, Cursor, KPMG and Sierra Written for agents; logging of tool and MCP calls; quarterly retesting
OWASP Top 10 for Agentic Applications Voluntary, December 2025 Agent hijacking, tool misuse, privilege abuse
IEEE P1968 Standards project Governance of autonomous agent systems

Other APAC

Market Instrument Status
Korea AI Basic Act In force 22 January 2026; general, covers autonomy in its AI definition
Vietnam Law on AI 134/2025/QH15 In force 1 March 2026; general
Japan AI Guidelines for Business v1.2 Voluntary guidance
Australia APRA letter to industry on AI (April 2026); Guidance for AI Adoption Supervisory expectations; voluntary guidance
Hong Kong GenAI Sandbox++ Supervisory sandbox
Malaysia AI Governance Bill Consultation closed 1 August 2026; pre-drafting

Case studies named in the documents

In MAS SAFR

Institution Domain What it shows
Ant International Treasury and payments Each agent linked to a named human principal; signed, time-limited mandates; circuit breakers; "the agent defaults to inaction" when instructions are ambiguous
Mastercard Agent Pay Payments Agent registration similar to KYC; tokens scoped by merchant, amount and time; consumer consent per use
Visa Intelligent Commerce Payments Mandates confirmed by passkey and stored as network rules; out-of-mandate transactions declined automatically
Circle Agent Wallet Agent payments for APIs On-chain agent identity; per-transaction and aggregate caps; all four outcomes in use
OCBC with Bank of Singapore Wealth, source-of-wealth memos Narrow agents, human validation at critical points, outputs advisory only
Unnamed bank Corporate banking briefs A named accountable human owner per agent; human approval before delivery
Manulife Insurance sales enablement LLM-as-judge against expert-curated answers; no autonomous path into financial systems

In IMDA's agentic AI framework (selection)

Organisation What it shows
IMDA OpenClaw System-level approvals instead of prompt-layer instructions; every action logged and attributable
Dayos Three tiers: 60% fully automated with audits, 30% human sign-off, 10% (production, security, permissions) never touched by the agent
MSD Five agency levels mapped to governance pathways; vendor agents restricted to their own platforms by default
Tencent CodeBuddy Per-tool approval defaults; re-approval for suspicious commands
Terminal 3 Payroll agent bound by a scoped credential of intent; tamper-proof audit trail for investigations
GovTech Coding agents introduced in phases, MCP only after a governance framework existed
Google with the Singapore government A computer-use agent followed an injected instruction to arbitrary URLs during sandbox testing

Sources

EU

China

Singapore

US

UK

Standards

Industry, legal and research

Other APAC

Related on rAInvent

)

Read more