VIII.5VIII · Govern itgovern
Jurisdictions - Singapore, the EU, the US & UK
Singapore’s secure-by-design, voluntary-but-accountable regime and the EU AI Act’s binding high-risk duties are the two instruments an accredited tester assesses against - this page maps both, and shows how to build once and label many.
Singapore runs a secure-by-design, risk-based, largely voluntary regime, deliberately interoperable with international norms and a reference for the forthcoming ASEAN framework. The operational machinery for testing against it lives in Project Moonshot and the engagement runbook (VI.5 · Running the engagement), the assurance dimensions (VI.6 · Capability & assurance evaluation), and the verification/maturity standards (VIII.4 · ISO/IEC 42001, verification & maturity).
flowchart TB
subgraph SG["SINGAPORE INSTRUMENTS"]
G["CSA Guidelines on Securing AI Systems<br/>Oct 2024, secure-by-design, lifecycle"]
CG["Companion Guide<br/>living; May 2025 added adversarial-robustness<br/>testing & secure retraining"]
AD["Securing Agentic AI Addendum<br/>Oct 2025; capability-based risk, workflow mapping"]
ADV["Advisory AD-2026-004<br/>Apr 2026; frontier-model risk"]
end
INTL["INTERNATIONAL ANCHORS<br/>MITRE ATLAS · OWASP · NIST AI RMF<br/>ISO/IEC 42001 · EU AI Act"]
G --> CG --> AD
G --> ADV
CG -.aligns to.-> INTL
classDef sg fill:#26200c,stroke:#e4a23f,color:#f3dca0;
classDef in fill:#0f1a18,stroke:#5bd1c5,color:#bdeee2;
class G,CG,AD,ADV sg; class INTL in;
CSA (Cyber Security Agency) owns the security instruments; IMDA (Infocomm Media Development Authority) / PDPC (Personal Data Protection Commission) own governance; MAS (Monetary Authority of Singapore) owns financial-sector expectations. All reference ATLAS, OWASP, NIST and ISO, so a control built once maps outward.
AD-2026-004 - the mitigations, organized
| Horizon | Measure | Why (vs AI-speed attacks) |
|---|---|---|
| Immediate | Patch critical/high vulns on internet-facing systems | Highest exposure to automated mass exploitation |
| Immediate | MFA on admin/gateway/cloud; IP allowlist where impossible | Blocks fast credential-driven access |
| Immediate | Secure or disconnect internet-facing dev/test | Common soft entry for automated recon |
| Immediate | Tighten cloud configs; fix exposed mgmt interfaces | AI rapidly finds misconfigurations |
| Immediate | Least privilege; revoke dormant accounts | Shrinks lateral-movement surface |
| Longer term | Network/micro-segmentation | Contains rapid AI-driven lateral movement |
| Longer term | Supply chain & dependency security | AI accelerates third-party exploitation |
| Longer term | Attack-path monitoring + behavioral anomaly detection | Catches multi-stage ops faster than human timelines |
| Longer term | Strong IAM; rapid credential response (minutes) | AI escalates/pivots at machine speed |
| Longer term | Shorten/automate patch cycles; use AI for vuln detection | AI weaponizes new CVEs within hours |
MGF for Agentic AI - the framework assessors work against
# Authorized assessment of a client system only. AI Verify is IMDA's open-source# testing toolkit (github.com/aiverify-foundation/aiverify) - it runs the# technical + process-checklist tests behind an 'AI Verify testable principle'.
# 1. Stand up the toolkit and register the model under testgit clone https://github.com/aiverify-foundation/aiverify && cd aiverifydocker compose up -d # portal + test-engine
# 2. Run the test plugins that back the 'human agency & oversight' principle# (robustness, fairness, and process checklists) against <model-endpoint>aiverify-test run \ --model <model-endpoint> \ --testdataset <held-out.csv> \ --groundtruth <labels.csv> \ --plugins robustness_toolbox,fairness_metrics_toolbox,process_checklist \ --report out/helpdeskgpt_report.json
# 3. Crosswalk the emitted result to the local instrument you must cite:# control 'Human-in-the-loop on consequential agent actions'# -> IMDA MGF for Agentic AI : Dimension 2 (meaningful human accountability)# -> CSA AD-2026-004 : monitor + constrain autonomous action# -> AI Verify principle : 'Human agency & oversight' (evidence: report above)IMDA launched the Model AI Governance Framework for Agentic AI (“MGF for Agentic AI”) at the World Economic Forum in Davos on 22 Jan 2026 - the world’s first governance framework purpose-built for AI agents that plan, reason, and act autonomously - and published an updated v1.5 on 20 May 2026 adding real-world case studies (e.g. the OpenClaw open-source agent platform) and new best practices for multi-agent systems, managing third-party-agent risk, and guarding against automation bias. It builds on the original 2020 MGF and the 2024 MGF for GenAI. Compliance is voluntary, but organizations remain legally accountable for their agents’ actions, and it applies to anyone deploying agentic AI in Singapore - in-house or third-party.
It is organized around four dimensions, which double as an assessment checklist for an agentic deployment:
- Assess & bound the risks upfront - define agent boundaries and limit the potential scope of impact at design time.
- Meaningful human accountability - keep humans ultimately responsible and guard against automation bias (over-trusting a system that has been reliable before).
- Technical controls & processes - “agentic guardrails,” traceability, and oversight mechanisms.
- End-user responsibility - equip and train users to oversee agents.
The throughline (“define boundaries → bound impact → keep a human accountable → make it traceable”) maps directly onto this playbook’s spine: the lethal-trifecta triage (II.2 · Prompt injection & the LLM attack surface), least-privilege agent identity (IV.6 · Agent identity & access (NHI)), approval gates and the mitigation matrix (II.5 · Guardrails - what holds, and how to prove it), and detection/traceability (VII.3 · Detection, IR & forensics for AI).
EU AI Act - the structure, not just the timeline
The Act stacks two independent axes: who you are in the value chain (which decides what you owe) and which risk tier your system sits in (which decides how much).
Roles - who owes what
Obligations attach to your role under Article 3, not to the technology in the abstract. The heaviest duties fall on the provider; a deployer owes a lighter set (human oversight, use per instructions, some transparency and FRIA duties). The trap is Article 25: a distributor, importer, deployer, or third party who puts their name on a high-risk system, substantially modifies it, or repurposes it to a high-risk use is deemed a provider and inherits the full provider obligations.
| Role (Art. 3) | Who they are | Core obligation weight |
|---|---|---|
| Provider | Develops / has developed an AI system or GPAI model and places it on the market or into service under its own name | Heaviest - conformity assessment, technical docs, QMS, registration, post-market monitoring |
| Deployer | Uses an AI system under its authority in a professional capacity | Lighter - human oversight, use per instructions, input-data relevance, transparency, FRIA where required |
| Importer | EU-established party placing a third-country system on the EU market | Verify provider conformity before placing; keep documentation |
| Distributor | Any other supply-chain party making a system available on the EU market | Verify markings; act on non-conformity |
Four risk tiers
- Unacceptable (Article 5, prohibited since 2 Feb 2025) - eight banned practices: manipulative/deceptive subliminal techniques causing harm; exploiting age/disability/socio-economic vulnerability; social scoring; purely profiling-based criminal-risk prediction; untargeted facial-image scraping; emotion recognition in workplace/education; biometric categorization inferring sensitive traits; and real-time remote biometric identification in public spaces for law enforcement (narrow carve-outs). No conformity path - these are simply off-limits.
- High-risk (Annex III + Article 6) - the tier that carries the binding lifecycle duties (risk management, data governance, logging, human oversight, robustness and cybersecurity). See the classification test below.
- Limited / transparency (Article 50) - disclose AI interaction, machine-mark synthetic media, label deepfakes. Applies 2 Aug 2026.
- Minimal - everything else; no mandatory obligations.
The high-risk classification test
An Annex III use-case (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) is the entry gate - but Article 6(3) filters out systems that do not pose a significant risk. A system escapes high-risk if it meets any one of four exhaustive conditions: (a) it performs a narrow procedural task; (b) it improves the result of a completed human activity; (c) it detects decision-making patterns without replacing or influencing the human assessment; or (d) it performs a preparatory task to a relevant assessment. Two hard limits: a system that profiles natural persons is always high-risk regardless, and a provider claiming the derogation must document the assessment and still register under Article 49(2).
GPAI - a parallel track
General-purpose AI models (the foundation-model layer) sit on their own track, in force since 2 Aug 2025 with Commission enforcement from 2 Aug 2026:
- Baseline GPAI provider - technical documentation, information for downstream integrators, a copyright policy, and a public training-content summary.
- GPAI with systemic risk - presumed when training compute exceeds 10^25 FLOP (a handful of frontier providers). Adds model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and cybersecurity protection for the model and its weights.
The GPAI Code of Practice (final version published 2025, its Safety and Security chapter aimed at the systemic-risk cohort) is the voluntary compliance vehicle - signing it is the presumption-of-conformity route the AI Office steers providers toward.
EU cross-map: the EU AI Act is binding and risk-tiered. GPAI (general-purpose AI) obligations have applied since 2 Aug 2025. The Digital Omnibus on AI simplification package - which the Council gave its final green light on 29 June 2026 - re-cuts the high-risk timeline: the stand-alone (Annex III) high-risk duties (risk management, data governance, logging, human oversight, robustness & cybersecurity) move to 2 Dec 2027, and product-embedded (Annex I) high-risk to 2 Aug 2028, with the deferral tied to the availability of harmonized standards.
Crucially, 2 August 2026 does not disappear. It remains the application date for the parts that switch on then regardless of the deferral: Article 50 transparency (disclose AI interaction, machine-mark synthetic audio/image/video/text, label deepfakes), the Article 49 registration database, the governance and notified-body provisions, and the penalty framework (fines up to €35M / 7% of turnover for prohibited practices, €15M / 3% for other breaches). One transition: generative systems already on the market before 2 Aug 2026 get until 2 Dec 2026 to meet the Article 50(2) machine-readable marking of synthetic output. Only the high-risk Annex III obligations lift off that date. The amending regulation enters into force on the third day after its Official Journal publication, expected shortly after the 29 June adoption - anchor to the published regulation number once it lands. The architecture - four risk tiers, conformity assessment, the GPAI track, the AI Office - is unchanged. SG orgs touching EU markets: build to the stricter EU high-risk bar where it applies; CSA/NIST/ISO cover the rest. Build once, label many.