Everyone now agrees, in principle, that an autonomous agent needs a control that can actually stop it — something that refuses a dangerous action at the moment it is attempted, not a report written afterwards. The interesting question is no longer whether we want that gate. Every serious standard of 2026 has drawn it. The question is why not one of them requires it.
I. The Regulator That Named the Gate
On 20 May 2026, Singapore’s IMDA published version one-point-five of its Model AI Governance Framework for Agentic AI. Fifty-three pages, careful, current. Buried in its guidance on human oversight is a sentence that says more than the authors may have intended. Enforce approval, it tells organisations, through ‘system-level controls where possible, vs prompt-layer guardrails, which may be bypassed or forgotten’.
Read that twice, because a regulator has just drawn the exact line this publication spends its life drawing. A system-level control is a gate in the infrastructure: it refuses an action deterministically, whatever the model does. A prompt-layer guardrail is an instruction to the model, honoured at whatever rate a probabilistic system honours instructions – which is to say, bypassable, or, in IMDA’s own dry word, forgotten. The framework prefers the first to the second. It even reports, in a government case study, a programmatic runtime policy-enforcement layer installed at an AI gateway before higher levels of autonomy were allowed – an actual kernel, in production, described approvingly.
And then the whole document says should. It recommends. It is, in its own framing, voluntary best practice. Singapore’s regulator named the deterministic gate, showed you one running, preferred it out loud – and required none of it.
A regulator drew the enforceability line in its own hand, then filed the drawing under guidance.
II. What SAFR Actually Built
Change register, from a framework to an engineered specification, and the same shape sharpens. In July 2026 the Monetary Authority of Singapore, through its BuildFin programme and eight financial institutions, published SAFR — Safeguards for Agentic Finance at Runtime. Strip the branding and SAFR is a kernel. Four components sit between an agent’s decision and its execution; a disposition engine evaluates every proposed action against the institution’s encoded controls and returns one binding outcome — deny, escalate, auto-execute, observe — before anything happens. It is fail-closed: no action reaches execution without having been declared, authorised, and assessed.
Note what the disposition engine is, and what it is not. It evaluates deterministically against retrieved rules – identity checks, mandate authorisations, exposure and rate limits. It does not put a language model in the judge’s chair to score another model’s behaviour; the probabilistic pieces it carries are advisory inputs, not the binding gate. That distinction matters, and it is worth correcting a loose reading — including one I had reached for myself — that filed SAFR under the anti-pattern of AI-monitoring-AI. It is the opposite. A supervisor’s programme built the deterministic kernel, in the open, with the industry in the room.
And in the same document, SAFR states that it does not constitute regulatory guidance or supervisory expectations. A central bank helped specify the execution gate and, in the same breath, declared that it requires nothing. The kernel arrives as a reference other people may choose to implement.
A supervisor specified the gate and disclaimed the mandate on the same page.
III. The Sort
Apply the test this publication applies to everything, and apply it to the whole field at once. Can each instrument refuse an action at execution time, deterministically, in bounded time, independently of the model whose behaviour it governs? Sort by the answer.
The European Union’s AI Act has real teeth — fines to a share of global turnover — but they bite post-hoc, at pre-market conformity and after the fact. It can punish a provider; it cannot refuse an agent’s action at the moment it acts. Teeth without runtime reach. The NIST AI Risk Management Framework and ISO/IEC 42001 are, respectively, a voluntary risk process and a management-system standard: they govern how an organisation deliberates, documents, and certifies — the organisation, not the action. Process, not gate.
Singapore’s MAS is the leading edge, and honesty requires saying so. Its forthcoming Guidelines on AI Risk Management will bind financial institutions to supervisory expectations that explicitly cover agentic AI — further than the EU, which has deferred its high-risk regime to December 2027, and further than the United States, whose revised model-risk guidance put generative and agentic AI out of scope. But read what AIRG binds: the risk-management process, the lifecycle controls, the board’s oversight duty. It requires the discipline around the gate. It does not require the gate.
And the research that has actually built the gate — CaMeL, enforcing capabilities at the tool-call boundary so that a compromised model still cannot act; the trajectory-level architecture of Szpruch, Sudjianto, Bhatti and Ang; the conformance engines of the MI-nine line — has reach without mandate. It can refuse. It is not required to. It is a set of papers and defences, not a rule.
Regulation has teeth without runtime reach; the runtime research has reach without teeth.
IV. Everyone Draws It
Now put them in one room, and watch the convergence that no single body announced. IMDA prefers system-level enforcement to bypassable prompts. MAS’s MindForge handbook names kill switches, timeouts, least-privilege tool access. SAFR builds the fail-closed disposition engine. A large platform vendor ships an agent-governance toolkit whose entire pitch is runtime policy enforcement for agents. An academic security lab proves you can enforce provenance and capability at the tool-call boundary, deterministically, whatever the model does.
A regulator, a central bank’s industry programme, a hyperscaler, and a university lab — four constituencies with nothing in common and no coordination — arrived independently at the same object: a deterministic control, sitting at the boundary where an agent acts, that can refuse in bounded time without asking the model’s permission. When groups this different, working from this far apart, converge on one piece of infrastructure, that infrastructure has stopped being a bet and become a finding. The field knows what the answer is. It has drawn the same picture, in five hands, on five surfaces.
When a regulator, a bank, a hyperscaler and a lab draw the same gate without conferring, it is no longer a proposal. It is a fact awaiting a mandate.
V. Nobody Requires It
Here is the whole of it, and it is stark. Every instrument above either draws the kernel, endorses it, or builds it — and every one of them leaves it optional. The gate is universally described and nowhere required. The most important control in agentic AI is the one thing on which the entire field agrees and to which not one authority will commit a must.
There is an honest reason and a quieter one. The honest reason is that standards mature before they bind: mandate a moving target too early and you ossify last year’s answer into next year’s law, and a prematurely frozen kernel could be worse than none. Grant it; it is real, and it is the strongest thing that can be said for the present arrangement. The quieter reason is that a voluntary gate is a gift to everyone it governs: it confers the appearance of safety — we drew the control, we endorsed it — while leaving each party free to implement exactly as much of it as is cheap, and no more. Optionality does not merely permit the gap between description and enforcement. It rewards it.
Be precise about what ‘require it’ can honestly mean, because the case against this essay will make me shrink the ask and I would rather shrink it now. Not a frozen ruleset written into statute — that would ossify a fallible judgement, and a badly-specified mandatory gate is a worse assurance than a well-built voluntary one. What a regulator could commit to is narrower and harder to dodge: the gate’s properties — that it exists, fails closed, refuses in bounded time, and is independent of the model — together with a stated threshold of autonomy past which those properties become mandatory. Require the shape and the trigger; leave the contents revisable. No authority has committed even to that.
I have to declare an interest here, in the body, at the point it becomes convenient, because that is the rule this publication holds others to. I build this kernel. The architecture I have spent two years on — TrustOS, implemented through my firm’s agent-governance practice — is the execution layer this essay argues should be required. An argument whose conclusion is ‘mandate the kernel’ is an argument for the thing I sell, and you should discount it exactly that far. Then weigh the discount against a fact it cannot reach: the words carrying this argument are not mine. The preference for system-level over prompt-layer control is IMDA’s. The fail-closed disposition engine is MAS’s and the industry’s. The teeth-without-reach is the European Union’s. I did not write the sentences that convict the field of knowing better than it requires. The regulators did.
I sell the gate, so discount me — then notice that the case against optionality is written in the regulators’ own hand, not mine.
VI. The Case Against This Essay
The essay’s conclusion — require the thing the author sells — is the most commercially convenient sentence I could write, so the case against it deserves more room than usual. Four objections, and the second reduces the claim.
The sequencing objection. Standards mature before they bind. Mandate a moving target too early and you freeze this year’s answer into next year’s law; a prematurely required kernel could be worse than a voluntary one that keeps improving. The essay treats optionality as a scandal when it may be prudence. Answer, partial. Granted, and it is the strongest thing said for the status quo. What survives is narrower: prudence would still commit to a threshold — a level of autonomy, a class of action — past which the gate becomes required, and to a timeline. No authority has committed to either. The failure is not that the gate is voluntary this year; it is that nobody has said what would make it mandatory in any year.
The regress objection. A mandated gate still needs a human to enumerate what it may refuse, and a law that freezes that enumeration freezes a fallible judgement — a badly-specified mandatory gate is a false assurance, arguably worse than none. Conceded. This is correct, and it shrinks the claim, which I now state in its reduced form: what should be required is the gate’s properties — that it exists, fails closed, refuses in bounded time, and is independent of the model — not its contents, which must stay revisable. Mandate the shape of the kernel, never its frozen ruleset. Anyone, including me, who argues for requiring a specific permitted set is selling the very rigidity this reduction rejects.
The definitional objection. The essay flattens a management toolkit, a research capability system, a supervisor’s reference spec and a regulator’s framework into one word — kernel — to manufacture a convergence. They are not the same mechanism, and their maturity and rigour differ sharply. Answer, partial. True of the implementations; what converges is not the code but the requirement shape — a deterministic, model-independent refusal at the boundary where the agent acts. I should have said the field agrees on the specification, not on the build.
The interest objection. The author sells the kernel and argues it should be compelled by law. Answer, and declared in section five. Discount accordingly; then weigh it against the fact that every load-bearing sentence is a regulator’s, not mine. But grant the reader the sharper version too: no disclosure fully neutralises a man arguing that the state should require his product. Read the reduced claim, not the strong one, precisely because of who is making it.
The strongest case against this essay is the name on its byline — which is why the argument is built from the regulators’ words and not the author’s.
VII. Coda: The Drawing and the Law
Return to the sentence in the IMDA framework — the regulator preferring the control that cannot be forgotten, and then, in the same document, making it optional. Hold the two halves together, because the distance between them is the whole subject. To describe a control is to know what safety looks like. To require it is to decide to have it. Every serious standard of this year has done the first. Not one has done the second, and the gap between them is not a technical gap — the kernel is buildable; people have built it — but a gap of will. We have written the gate into our prose and left it out of our law, and we are calling the drawing a safeguard. It is not a safeguard. It is a sketch of one, initialled by everyone, signed by no one.
We have written the kernel into our prose and left it out of our law — and called the drawing a safeguard.
Sources
- IMDA, Model AI Governance Framework for Agentic AI, v1.5, 20 May 2026 (primary, read).
- MAS BuildFin & industry partners, Safeguards for Agentic Finance at Runtime (SAFR), v1.0, July 2026.
- MAS, Consultation on Guidelines on AI Risk Management (AIRG), 13 November 2025.
- Szpruch, Sudjianto, Bhatti & Ang, Scalable Runtime Governance for Agentic AI in Financial Services, SSRN, 13 April 2026.
- Debenedetti & Tramèr et al., CaMeL: capabilities at the tool-call boundary, arXiv 2503.18813, 2025.
- Regulation (EU) 2024/1689 (AI Act).
Provenance note: only the IMDA framework is quoted verbatim, from the 53-page primary. SAFR and the MAS AIRG guidelines are paraphrased, not quoted — their official PDFs were returning server errors at the time of writing, so their content here rests on the framework’s own listing and on corroborating coverage, and no sentence in this essay depends on a direct quotation from either until the primaries can be read.


Leave a comment