The Runtime Enforcement Gap in Agentic AI Governance Standards

A clause-level analysis of the 2026 Singapore agentic-AI governance corpus — five primaries read in full and sorted by a single test: can the control refuse an agent’s action at execution time? A working paper; the author’s declared interest is in §7.

Abstract

Across 2026 the governance of agentic artificial intelligence — systems that do not merely recommend but act, invoking tools and executing transactions with limited human intervention — acquired its first dedicated standards. This paper asks one question of that new corpus: does any instrument require a control that can refuse an agent’s action at the moment of execution, deterministically, in bounded time, and independently of the model whose behaviour it governs? We call this criterion the enforceability test, and we use it to read five Singapore primary instruments clause by clause — the IMDA Model AI Governance Framework for Agentic AI (v1.5), the MAS-convened Safeguards for Agentic Finance at Runtime (SAFR, v1.0), the MAS Consultation Paper on Guidelines on AI Risk Management (AIRG, P017-2025), the MAS-supported MindForge AI Risk Management: Operationalisation Handbook, and the Association of Banks in Singapore Handbook on Generative AI Guardrails in Banking — against the binding global comparators (EU AI Act; NIST AI RMF; ISO/IEC 42001) and the runtime-governance research frontier (CaMeL; Szpruch et al.).

We find a striking asymmetry. The control — an execution-time, deterministic, model-independent enforcement gate, distinct from the observation layer that records and detects — is described, preferred, and in one case fully specified and built, across four functions of a single coordinated regulatory ecosystem: a regulator’s framework, a central bank’s industry specification, an industry-association handbook, and a supervisory consultation. We are explicit that this is functional convergence within one coordinated jurisdiction, not the independent agreement of unrelated actors — Singapore’s instruments are convened, supported, or issued by the same authorities, and we retract in §5.1 any stronger reading. The control is required by none of them. We further find that the most advanced specimen, SAFR, admits probabilistic and semantic controls into its own binding path and showcases an LLM-as-a-Judge case study — so even the corpus’s best description of a deterministic kernel does not hold the determinism line absolutely, which forces us to specify the minimum determinism the argument actually needs (a model-independent decision rule and fail-closed default over authenticated inputs, not a fully model-free path). We conclude with the reduced claim that survives adversarial review: what a standard could commit to is not a frozen permitted-action set but the gate’s properties — existence, fail-closed default, bounded-time refusal, model-independent decision rule — plus a mandatory, published justification of the action-domain and time-bound over which those properties hold, together with an autonomy threshold past which they become binding. The author builds such a kernel commercially, and authored the enforceability test used here; both interests are declared in §7, and the argument is constructed so that its load-bearing evidence is the standards-bodies’ own words, not the author’s.


1. Introduction: the enforceability test

An agentic system is one that closes the loop from decision to action: it holds tools, and it uses them. The governance question it raises is therefore not the familiar one of model quality — accuracy, bias, explainability — but one of model authority: at the instant an agent attempts an action with a real-world effect (moving money, releasing a document, granting access), what stands between the intention and the effect, and can that thing say no?

Two families of control are routinely conflated in the 2026 literature, and separating them is the whole of this paper’s method.

  • The observation layer records, detects, evaluates, scores, and reports. Audit logs, monitoring dashboards, drift detectors, post-hoc model-validation, and LLM-based evaluators all live here. Everything in this layer acts after — or alongside — the action, and its output is evidence, not refusal.
  • The execution layer (what the author elsewhere terms Ring Zero, an execution kernel) sits inline, between the agent’s decision and the system it acts upon, and returns a binding verdict before the action proceeds. Its output is not a record but a disposition: permit, hold, or deny.

The distinction is operational, not rhetorical, and it can be made precise as a single test applied to any proposed control:

The enforceability test. Can this control refuse an action at execution time, deterministically, in bounded time, and independently of the model whose behaviour it governs?

Each conjunct does work. At execution time excludes pre-deployment conformity assessment and retrospective audit. Deterministically excludes probabilistic gates whose verdict is a sample, not a guarantee. In bounded time excludes controls that may stall indefinitely (an unbounded human review is not a gate). Independently of the model excludes any control implemented as, or decided by, the very model it is meant to constrain — most sharply, an LLM judging another LLM. A control that satisfies all four is an execution-kernel control; a control that fails any one is, for the purpose of refusing an action, an observation-layer or process control, however valuable it may be for other ends.

Two objections to the test itself must be met here rather than deferred, because a reader who rejects the instrument will reject everything downstream. First, the test is not neutral — it is the author’s construct, and §7 discloses that it is near-coextensive with the author’s product. The reader is therefore owed the argument for these four conjuncts, not merely their statement. Second, the conjunction excludes two reasonable rival notions of “enforcement,” and does so by choice. A liability-and-audit theory (the EU AI Act’s) holds that a control “enforces” if non-compliance carries credible, turnover-scaled penalty backed by tamper-evident logging; under that definition the gap this paper identifies largely closes, because binding law already exists. A human-oversight theory (implicit in AIRG §4.10 and EU AI Act Art. 14) holds that an overseer with “authority and ability to intervene” is sufficient refusal capacity. We do not claim these are illegitimate; we claim they are insufficient for the agentic case specifically, and the reason is scale and speed. Liability deters a provider over quarters; it cannot refuse this transaction in the milliseconds before settlement, and post-hoc penalty presupposes the harm has already occurred. Human oversight fails the same way once an agent acts at machine volume — SAFR states the point plainly, that “the volume and speed of agent decisions make traditional per-action oversight operationally impossible” (SAFR, p.5). The four-conjunct test is thus not the only possible definition of enforcement; it is the definition that survives when the governed entity is an autonomous, fast, tool-wielding agent rather than a static model. We concede that under the liability or oversight definitions the “mandate gap” narrows or disappears — and we rest the paper on the claim that neither definition answers the agentic case.

The question this paper puts to the 2026 corpus is deliberately narrow. It is not whether the field wants such a gate — we will show it plainly does. It is whether any instrument, binding or voluntary, requires one. The answer organises everything that follows.


2. Method and corpus

2.1 Corpus

The primary corpus is the set of five Singapore instruments that, as of August 2026, constitute the most developed body of dedicated agentic- and generative-AI governance text in any single jurisdiction. Each was read in full from its official PDF; page anchors below refer to those PDFs.

#InstrumentBodyDateStatusPages
P1Model AI Governance Framework for Agentic AI, v1.5IMDA / AI Verify Foundation20 May 2026Voluntary framework53
P2Safeguards for Agentic Finance at Runtime (SAFR), v1.0MAS (BuildFin) + 8 financial institutionsJul 2026Voluntary reference; disclaimed25
P3Consultation Paper on Guidelines on AI Risk Management (AIRG), P017-2025Monetary Authority of SingaporeNov 2025Draft supervisory expectations30
P4AI Risk Management: Operationalisation HandbookMindForge Consortium (MAS-supported)Jan 2026Voluntary industry handbook173
P5Handbook on Generative AI Guardrails in BankingAssociation of Banks in SingaporeMay 2025Voluntary industry self-help47

The comparators — invoked in §5 but not clause-coded here — are the binding or widely-adopted global instruments the Singapore corpus sits inside: Regulation (EU) 2024/1689 (the AI Act); the NIST AI Risk Management Framework (AI 100-1, 2023); and ISO/IEC 42001:2023. The research frontier is represented by CaMeL (Debenedetti, Tramèr et al., 2025) and Scalable Runtime Governance for Agentic AI in Financial Services (Szpruch, Sudjianto, Bhatti & Ang, 2026).

2.2 Coding procedure

Every load-bearing clause was extracted with its page anchor and coded on three axes: Layer — execution-kernel (can refuse inline), observation-layer (records/detects/evaluates), or process-governance (governs how the organisation deliberates, documents, or is structured); Binding strength — read off the modal verb (mandatory “must/shall”; recommended/expected “should/expects/consider”; voluntary; or disclaimed); and the Enforceability verdict — whether the clause, as written, satisfies the four conjuncts. The full coded register (52 clauses) is the working-paper appendix; in the body we quote only the clauses that carry the argument.

2.3 Provenance discipline and limitations of method

Quotations are verbatim from the primary PDFs, page-anchored, and normalised only for optical-character-recognition spacing artefacts (for example the extractor’s “tamper -evident” is rendered “tamper-evident”); no wording is changed. Page anchors for P4 (MindForge) refer to the PDF sequence position, which runs approximately seven pages ahead of the document’s printed folio. Three limitations bear on interpretation and are carried into §6. First, P3 (AIRG) is a draft consultation, not an issued rule; its register (“should”, “expects”) is standard MAS soft-law and must be represented as proposed supervisory expectation, not statute. Second, the corpus is Singapore-centric — chosen because it is the frontier, but not globally representative. Third, clause coding involves judgement at the margin; the rule adopted throughout is conservative — a control is credited as execution-kernel only if all four conjuncts are satisfied on the face of the text.


3. Clause analysis I — the two poles

The corpus has two instruments that define its analytical poles: SAFR, which builds the gate, and AIRG, which binds the process around the gate. We treat these in depth (§3.1–3.2), then read the surrounding chorus (§4).

3.1 SAFR — the kernel, described and disclaimed

SAFR is the corpus’s high-water mark: an engineered specification of a runtime governance layer, authored by a central bank’s industry programme together with eight financial institutions. Read against the enforceability test, its core functions as an execution kernel. Its own account of its position is unambiguous (p.5): it “sits between the agent and the systems it acts on, evaluating proposed actions before execution”. It operates, in its own words, “after content filtering and before execution” (p.14) — that is, after the model’s own guardrails and independent of them, which is precisely the architectural independence the enforceability test demands. SAFR states the test’s core premise itself: model-level guardrails “are typically probabilistic and may not, on their own, enforce the precise structural, numerical, or policy constraints that many financial actions require” (p.6), and therefore “Guardrails on model output are … not a substitute for runtime governance of financial action” (p.14).

The mechanism. Four runtime components interact through a Governance Envelope (p.8): Agent Identity (“Binds each proposed action to a recognised, registered agent, verified against that agent’s registry entry before any other evaluation proceeds”); a Controls Repository (the institution’s “configurable rulebook”); a Disposition Engine; and a tamper-evident, append-only Audit Log. The load-bearing claim is the Disposition Engine’s, and it is a determinism claim in plain text (p.11):

“The Disposition Engine evaluates the proposed action deterministically against the controls retrieved from the institution’s Controls Repository.” (SAFR, p.11)

It returns one of four dispositions (pp.11–12), of which two are refusals and two are permits: Deny — “the proposed action violates a hard regulatory or policy constraint … The action is rejected before execution, with a specific reason recorded”; Escalate — “above the threshold for autonomous execution. The action is held pending human review before proceeding”; Auto-Execute — “within scope, below hard constraints, and within defined risk thresholds. The action proceeds without requiring human intervention”; and Observe — “permitted to proceed but … flagged for monitoring; the action executes while a structured observation is logged for subsequent review.”

The system is fail-closed at the level of complete mediation (p.8): “Together, these ensure that no agentic action reaches execution without having been declared, authorised, and assessed.” Authority is capability-based, not model-inferred (p.11): “An agent cannot extend the scope of a mandate through its own reasoning or inference … Authority is explicit, structured, and defined by the mandate.” Escalations are bounded in time and fail closed on timeout (p.17): reviewer non-response should cause the action to “default to block or be escalated to a senior reviewer.” On the four conjuncts of the enforceability test, the core of SAFR — identity resolution, generic controls that “evaluate against fixed thresholds or categorical rules” (p.10), capability-bounded authority, the four-outcome disposition, fail-closed defaults — passes cleanly. This is the clearest execution-kernel description in the corpus.

And yet it is required of no one. SAFR is expressly disclaimed (p.5):

“It does not constitute regulatory guidance or supervisory expectations, nor does it prescribe or anticipate future directions for such guidance or expectations.” (SAFR, p.5)

Its bindingness is delegated entirely to the deploying institution (p.8): SAFR “is an industry reference model where each mechanism defines a condition that should hold for every proposed agentic action, leaving the form of implementation to the deployment context.” The determinism, in other words, is a property of the reference design, not an obligation on any adopter. The kernel is drawn in full and handed over as an option.

The honest complication. A paper that stopped there would overstate SAFR’s determinism, and the enforceability test cuts both ways. SAFR itself admits non-deterministic controls into the very control set the Disposition Engine evaluates (p.10): “AI-specific controls (e.g., evidence quality, envelope integrity checks) … may involve probabilistic or semantic assessment” (SAFR, p.10). If such a control contributes to a Deny or Escalate, then a probabilistic assessment sits on the binding path — and the “deterministic” engine is deterministic only in its comparison step, over inputs that need not be. Three further seams point the same way: the disposition may be realised “as a fixed threshold lookup or a multi-factor risk assessment” (p.11, the latter undefined and potentially an ML scorer); an evidence-quality route keys off “the agent’s stated confidence” (p.17), a model-produced number; and SAFR’s insurance case study (Manulife) validates outputs through “LLM-as-a-Judge evaluation” whose low-confidence results are “blocked or escalated” (p.21) — an LLM on the binding path, mitigated only by the fact that “the system provides no autonomous execution pathway” to financial systems (p.21). Finally, SAFR concedes the integrity of its own inputs is not guaranteed: the envelope’s contents are agent-declared and “can be fabricated together by a sophisticated adversarial injection” (p.9), so the envelope must be “authenticated against its origin” (p.9) — a requirement SAFR names but does not mechanise.

The accurate reading, then, is sharper than “SAFR is a deterministic kernel.” SAFR is a described kernel with a deterministic core and explicit probabilistic escape hatches, disclaimed as non-binding. It both vindicates the execution-kernel thesis and demonstrates how hard the determinism line is to hold even for those who draw it best.

3.2 MAS AIRG — the process is bound; the gate is not

If SAFR is the corpus’s engineering, AIRG is its nearest approach to law. As a MAS Guideline (in draft) it carries supervisory force: it sets out “supervisory expectations relating to AI risk management in the financial sector” (p.3), and “establish[es] a set of high-level expectations that all FIs should adhere to” (p.13). Crucially for our question, it puts agentic systems explicitly in scope (p.3):

“The Guidelines should be generally applicable to different AI applications and technologies, including Generative AI, as well as newer developments such as AI agents.” (AIRG, p.3)

And it names the runtime threat model with precision (p.15): “an AI agent with access to tools could autonomously execute actions that are not aligned with an FI’s business objectives or a customer’s best interests,” while “compromised AI agents with access to internal systems and external tools could be used to exfiltrate sensitive data or execute malicious commands at scale” (p.15). AIRG sees exactly the harm an execution kernel exists to prevent.

What it requires in response, however, is process, not the gate. Every runtime-adjacent control is framed as an expectation to establish a capability or run a process, never as a bound obligation that a deterministic refusal be present at the point of action. Human oversight requires that overseers have “the necessary authority and ability to intervene” (§4.10) — an oversight capability, not an automated gate. Most tellingly, the one control that would come closest to an execution-time containment is optional (p.26):

“For high risk materiality AI, consider implementing ‘kill switches’ or override mechanisms to rapidly deactivate the AI system if it exceeds risk tolerances.” (AIRG, p.26)

Two features of that sentence decide the matter. The modal verb is “consider” — the weakest in the supervisory register. And a kill switch, as AIRG itself defines it, deactivates AI “expeditiously if they exceed risk tolerances” — it stops the system, it does not deterministically refuse a single action at execution time. The register throughout is “should” and “expects”; the only operative “must” in the document (p.16) requires that firms “continue to comply with all existing regulatory requirements … even when AI is adopted” — a mandate pointing at existing rules, not at any new runtime gate. The nearest thing to a deterministic control AIRG contemplates is role-based access with multi-factor authentication and least privilege (p.24) — genuinely deterministic, but gating access to components, not the agent’s per-action governance decision.

The finding for P3 is therefore clean, and it corroborates the thesis by omission: AIRG mandates the observation layer and the process/governance layer comprehensively — inventory, materiality tiering, lifecycle controls, monitoring of “actions taken, tools used” (p.26), independent validation, contingency planning — and mandates the deterministic execution-time gate nowhere. The control the enforceability test isolates is precisely the one AIRG describes the need for and declines to require.


4. Clause analysis II — the surrounding chorus

Two poles do not make a convergence, and a caveat must precede this section rather than follow it. The five primary instruments are not independent voices: the Monetary Authority of Singapore convenes SAFR, supports the MindForge consortium, issues the AIRG consultation, and forewords the ABS handbook, while IMDA is an arm of the same government’s whole-of-nation AI strategy. What follows is therefore not a claim that uncoordinated actors reached the same answer — §5 retracts that reading explicitly — but the weaker and more careful observation that instruments serving different functions reach for the same control shape even though nothing compels them to.

4.1 IMDA Model AI Governance Framework for Agentic AI (P1)

The IMDA framework is the regulator’s own hand, and it draws the enforceability line explicitly. On enforcing human approval it states the preference at the heart of this paper (verbatim from the 53-page primary, printed p.15): approval should be enforced through ‘system-level controls where possible, vs prompt-layer guardrails, which may be bypassed or “forgotten”‘. That single clause distinguishes a gate in the infrastructure (which refuses whatever the model does) from an instruction to the model (which a probabilistic system honours at whatever rate it honours instructions) — and prefers the former. The framework goes further, reporting a government case in which “a programmatic runtime policy enforcement layer is being implemented at the AI gateway before higher levels of autonomy are enabled” — an actual kernel, in production, described approvingly, with enforcement strength tied to the level of agent autonomy. And then the instrument, by its own framing, recommends: it is voluntary best practice throughout. The regulator names the deterministic gate, shows one running, prefers it out loud — and requires none of it.

4.2 MindForge Operationalisation Handbook (P4)

The 173-page MindForge handbook shows the full runtime vocabulary assembled in one place — and bound nowhere. It is a consortium document (24 primary members endorsed its scope), explicitly a support text for the still-proposed MAS Guidelines: it is “intended to accompany and support the implementation of the proposed MAS Guidelines on Artificial Intelligence Risk Management” (PDF p.10), offered as “industry leading practices that FIs around the world can consider” (PDF p.19). Its operative register, without exception, is “FIs can consider” and “FIs may”; “must” and “shall” are never used to bind a firm.

Within that voluntary frame, MindForge names nearly every control the enforceability test looks for. It elevates system-level restriction above all other guardrails (PDF p.128): “Restricting the privileges, tool and data access, and capabilities of an agentic system is one of the most important guardrails in preventing unwanted behaviours,” recommending “the lowest possible level of privilege” per component. It reaches the purest form of a deterministic control — a structural capability prohibition (PDF p.128): “some actions may be too risky to delegate to AI under any circumstances, such as authorising financial transactions.” It names automated inline blocking (PDF p.129): interruption “could also be automated to ensure that harmful actions are promptly identified and blocked.” And in its guardrail library it states the deterministic-policy claim almost verbatim (PDF p.163): rule-based frameworks “support the codification of compliance requirements as transparent, enforceable rules with clear logic.”

Two features convert this catalogue into evidence for the mandate gap rather than against it. First, every one of these controls is softened by “can consider” and is triggered by a monitoring-and-incident loop rather than by inline mediation: the kill switch exists “to deactivate the use case … while an issue is investigated” (PDF p.100), i.e. after detection, not at the point of action. Second — and this is the tell — the handbook addresses the same risk by a deterministic and a model-level route and prefers neither. The risk of an agent spending money is met structurally, by withholding the capability (PDF p.128), and by prompting: FIs may “ground” the agent to “avoid certain types of action (such as spending money) unless specifically prompted” (PDF p.129). The pattern recurs at the output boundary, where the handbook concedes the deterministic option exists but reports the probabilistic one as the norm (PDF p.161): a content-moderation check “can take the form of deterministic rules, but is typically implemented using an LLM.” Across 173 pages, not one clause requires that a runtime control act deterministically, in bounded time, independently of the model, on the binding path. The handbook names the vocabulary and never binds it.

4.3 ABS Handbook on Generative AI Guardrails in Banking (P5)

The ABS handbook is the corpus’s most explicit demonstration that the word “guardrail” does most of its work at the process layer, not the execution layer. Its own foundational definition frames the term away from runtime enforcement (p.6): guardrails are “pre-established guidelines and processes that act as a safety net”. Of its nine guardrail approaches, four are explicitly process guardrails, one is enterprise governance, and only the “Filtering and Control” family plausibly constrains a model at runtime. Even there, the handbook offers three filtering styles as co-equal options and prefers none (p.24):

“Rules-based, which search for specific phrases or content and respond to it in a deterministic way.” … “Model-based, which detect targeted content … through a scoring approach”. … “Agentic, in which case an AI model – often a second LLM – checks inputs and outputs according to set criteria.” (ABS, p.24)

The handbook thus pairs a deterministic control against a model-based and an LLM-judge control and treats them as interchangeable, even endorsing an output verifier whose “role can be filled by the principal LLM in question” (p.25), collapsing the model-independence the enforceability test requires. ABS also concedes the structural reason a deployer-side kernel is needed and does not draw the conclusion: model-level controls “are less applicable to ‘buy’ deployment models, where hyperparameters may be unavailable” (p.24) — and “most code generation in banks will be conducted by Software-As-A-Service … coding assistants” (p.42), so the buy case dominates and model-level guardrails largely evaporate. The handbook is, in MAS’s own foreword, an “industry self-help effort” (p.3) — voluntary throughout.


5. Functional convergence and the mandate gap

Sorted by the enforceability test and by binding strength, the 2026 Singapore corpus — together with its allied research strand — falls into a consistent pattern. We state at the outset what this pattern is not: it is not the convergence of independent actors (see §5.1), and it is not evidence about “the field” globally, since the comparator jurisdictions embody a rival enforcement theory (§5.2).

Instrument / workCan refuse at execution time?Deterministic & model-independent?Binding strength
SAFR (P2)Yes — core; probabilistic escape hatches at the edgeCore yes; edges noDisclaimed (voluntary reference)
IMDA MGF (P1)Prefers system-level enforcement; shows one runningYes, where implementedVoluntary (“should”)
MindForge (P4)Names kill switch, timeout, least privilege, non-delegable actionsYes for several, but each an unranked optionVoluntary (consortium handbook)
ABS (P5)Only via optional rules-based filteringOne option of three; not preferredVoluntary (self-help)
MAS AIRG (P3)No — mandates process/oversight, not the gateAccess-control only, off the action pathDraft supervisory expectation
EU AI ActNo — conformity + post-hoc enforcementn/a (post-hoc)Binding, but not at runtime; high-risk deferred to Dec 2027
NIST AI RMF / ISO 42001No — govern the process/management systemn/aVoluntary process / certifiable standard
CaMeL; Szpruch et al.Yes — deterministic refusal at the tool-call boundaryYesNone — research, not mandate

The pattern is an asymmetry between reach and requirement. Where an instrument can refuse at runtime (SAFR, IMDA’s preferred pattern, the research frontier), it is voluntary or disclaimed. Where an instrument binds (the EU AI Act’s turnover-scaled fines; AIRG’s supervisory expectations), its teeth land either post-hoc or on the process — never as a deterministic refusal at the point of action. Regulation has teeth without runtime reach; the runtime work has reach without teeth.

5.1 What the convergence is, and is not

An earlier draft of this paper claimed that “four uncoordinated constituencies” arrived at the same control “independently” and “without conferring,” and inferred that the gate had therefore become a finding rather than a proposal. That inference does not survive, and we retract it. The corpus table of §2.1 refutes the premise: MAS convenes SAFR, supports MindForge, issues AIRG, and forewords ABS, and IMDA is the same government — four of the five instruments are one coordinated national programme describing itself in four functional registers, not four independent observers. The firewall does not even hold at the edge: SAFR’s acknowledgements name Gary Ang, and the “research frontier” corroborator (Szpruch et al.) shares that author — the outside voice is partly personnel-linked to the exhibit it corroborates. Convergence of independent actors is not a claim this evidence can support.

What the evidence does support is weaker but not nothing: a functional convergence. Within one coordinated ecosystem, instruments written for different purposes — a technical reference specification (SAFR), an operations handbook (MindForge), a guardrail catalogue (ABS), a regulator’s framework (IMDA), and a supervisory consultation (AIRG) — independently reach for the same control shape: a deterministic, model-independent refusal at the boundary where the agent acts. Different functions converging on one specification is evidence that the specification is the natural answer to a shared problem. It is not evidence that the answer is settled science. The honest status of the gate is therefore: a control that a coordinated regulatory ecosystem, across four functions, treats as the right answer — and requires in none of them.

5.2 The comparators embody a rival theory, not a shared one

The global comparators do not extend the convergence; they contest it. The EU AI Act enforces through ex ante conformity assessment and ex post penalty — a liability-and-audit theory of enforcement in which deterrence, not inline refusal, is the mechanism. NIST’s framework and ISO/IEC 42001 govern the organisation’s process and management system. These are not weaker versions of the runtime gate; they are a different answer to the same question, one that locates enforcement before deployment and after harm rather than at the moment of action. That a second, binding theory of enforcement exists is itself a limit on this paper’s claim: the runtime gate is the answer one tradition converged on, not the answer.

5.3 The gap

With those two retractions made, the residual finding is precise and it holds. Across the Singapore corpus, every instrument that can express a deterministic runtime refusal (SAFR’s core, IMDA’s preferred pattern, MindForge’s named controls, ABS’s rules-based filter) leaves it voluntary; the one instrument approaching binding force (AIRG) mandates the surrounding process and the oversight capability, and mandates the gate’s existence nowhere. The control is described across four functions and required by none. What it has not become — in this corpus, whatever its status elsewhere — is a requirement.


6. Discussion

6.1 The reduced claim

The strong claim — “mandate the kernel” — does not survive adversarial review, and this paper does not make it. Two objections reduce it. The sequencing objection holds that standards must mature before they bind, and that freezing an immature control into law could be worse than leaving it voluntary; this is granted, and it is the strongest defence of the present arrangement. The regress objection holds that a mandated gate still requires a human to enumerate what it may refuse, and a law that freezes that enumeration freezes a fallible judgement; this too is conceded.

What survives both is a narrower requirement — but it is narrower than an earlier draft claimed. That draft asserted a clean separation: “require the shape, leave the contents revisable.” That separation leaks, and the leak must be conceded. The properties are not content-free. “Fails closed on unknown” presupposes a defined domain over which “unknown” is evaluated — and that domain is a content choice. “Refuses in bounded time” is satisfiable vacuously by a deployer who sets the bound at thirty seconds and runs what is effectively human review, or who defines the known-good set so expansively that the gate permits almost everything while technically “failing closed.” A properties-only mandate hands the deployer the very gaming this paper accuses the corpus of enabling.

So the honest reduced claim is not “properties, not contents.” It is properties plus forced transparency about the contents. A standard could commit to requiring that, above an autonomy threshold, a deployed agent’s action path include an enforcement point that (1) exists on the action path and is architecturally distinct from the model; (2) fails closed on unknown, missing, or timeout; (3) refuses in bounded time; and (4) reaches its verdict by a model-independent decision rule — and that the deployer publish and justify the action-domain over which the gate operates, the time-bound it enforces, and the allowlist semantics of “fails closed,” so that a supervisor can test whether the properties are met substantively rather than nominally. Require the properties and the disclosure that stops them being satisfied vacuously; leave the specific permitted-action contents revisable. The failure of the 2026 corpus is not that the gate is voluntary this year — it may be too early to bind the contents — but that no instrument has committed even to requiring the gate’s existence, properties, and justification on any timeline.

6.2 Limitations and threats to the argument

  • The whole binding path cannot be model-independent — so define the minimum that must be. Even SAFR, the best-resourced specimen, admits “probabilistic or semantic” controls (p.10) and an LLM-as-a-Judge case (p.21) onto its binding path; for many financial actions this is unavoidable. Conjunct 4 is therefore too strong if read to mean the entire path is model-free. The claim must be reduced to a minimum determinism: what must be model-independent is the decision rule and the fail-closed default, not the evidence those inputs may summarise. A deterministic comparator applied to a probabilistic score satisfies the minimum; an LLM that itself issues the binding verdict does not.
  • The kernel’s inputs may be forgeable. SAFR concedes its envelope is agent-declared and adversarially fabricable (p.9). Model-independence at the decision step does not confer integrity at the input step — a real limit understated in the advocacy literature (including the author’s own).
  • Definitional flattening. The convergence aggregates a management handbook, a research capability system, a supervisor’s reference specification, and a regulator’s framework under one word — kernel. The defensible claim is that they converge on a requirement shape, not on a shared implementation.
  • AIRG is a draft. Its treatment here is as supervisory expectation, to be revisited against the final Guidelines.
  • Corpus selection. Singapore because it is the frontier, not because it is representative; a full cross-jurisdictional clause analysis remains future work.

6.3 Falsification condition

The central claim is falsifiable: it is wrong if any 2026 standard is shown to mandate a deterministic, model-independent control that refuses an agent’s action at execution time. To show the falsifier bites in practice, here is a concrete instrument the author would accept as a genuine refutation: an EU AI Act implementing act, or an issued MAS Guideline, that required — above a stated autonomy threshold — every tool call by a covered agent to pass through an enforcement point that denies non-conforming calls by a model-independent decision rule, fails closed on timeout, and whose action-domain and time-bound the deployer must publish. Such a rule need not name a vendor, freeze a permitted-action set, or exclude probabilistic evidence. If any jurisdiction enacts it (or is shown already to have), the “mandate gap” claim is refuted. On the corpus read here, no instrument approaches this; the nearest candidate, AIRG’s kill switch, is optional (“consider”) and operates on the system, not the action.


7. Declared interest

There are two interests to declare here, and honesty requires naming the second, which is the more serious. The conclusion-interest is obvious: the author builds the control this paper argues should be required. The architecture referenced as Ring Zero / the execution kernel corresponds to the author’s own governance work (TrustOS, implemented through the author’s professional practice), so an argument whose conclusion is “require the gate” is an argument for the author’s own product category. The instrument-interest is subtler and a hostile reader is right to press it: the enforceability test that structures this entire paper — the four conjuncts that sort every instrument into “kernel” or “not” — is not drawn from any of the five sources. It is the author’s own construct, and its four properties are close to a specification of what the author’s product uniquely provides. The regulators supplied the quotations; the author supplied the ruler that makes those quotations resolve into a “gap.” Disclosing that one sells the kernel does not disclose that one also authored the measuring instrument, and the reader should scrutinise the choice of conjuncts.

The argument is constructed to make both discounts survivable, but only the first is fully answerable. Its load-bearing evidence is not the author’s assertion but the standards-bodies’ own text — the preference for system-level over prompt-layer control is IMDA’s; the deterministic Disposition Engine and its disclaimer are MAS’s and the industry’s; the “process, not gate” finding is read from MAS’s own consultation; the rival liability theory is the European Union’s. The framing — which control counts, which conjuncts matter — is the author’s, and no disclosure fully neutralises that. The reader is therefore directed to the reduced claim of §6.1 — require the properties, the trigger, and the justification, not the contents — which is the only form of the argument the author regards as defensible, and asked to weigh it in full knowledge both of who makes it and of who built the ruler.


Appendix A — Clause register

The full clause register — 52 page-anchored clauses across all five primaries, each coded by layer (execution-kernel / observation / process), binding strength, and enforceability verdict — is omitted here for length. It is reproduced in full, colour-coded, in the companion working-paper artefact and PDF. The two tables above (the corpus and the reach-vs-requirement matrix) carry the argument; the register is the underlying evidence.

References

  1. Infocomm Media Development Authority (IMDA) & AI Verify Foundation. Model AI Governance Framework for Agentic AI, v1.5. Singapore, 20 May 2026. (Primary; read.)
  2. Monetary Authority of Singapore (BuildFin) with Ant International, Circle, HSBC, J.P. Morgan, Manulife, Mastercard, OCBC, Visa. Safeguards for Agentic Finance at Runtime (SAFR), v1.0. July 2026. (Primary; read. Acknowledgements: Gary Ang, Quaintitative; Maxim Afanasyev, NUS.)
  3. Monetary Authority of Singapore. Consultation Paper on Guidelines on Artificial Intelligence Risk Management (AIRG), P017-2025. November 2025. (Primary; read.)
  4. MindForge Consortium (MAS-supported). AI Risk Management: Operationalisation Handbook. January 2026. (Primary; read.)
  5. Association of Banks in Singapore, Standing Committee on Data Management. Handbook on Generative AI Guardrails in Banking. May 2025. (Primary; read.)
  6. Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act). 2024. (Comparator.)
  7. National Institute of Standards and Technology. AI Risk Management Framework (AI 100-1). 2023. (Comparator.)
  8. ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system. 2023. (Comparator.)
  9. Debenedetti, E., Tramèr, F., et al. CaMeL: control/data-flow separation and capabilities at the tool-call boundary. arXiv:2503.18813, 2025. (Research frontier.)
  10. Szpruch, L., Sudjianto, A., Bhatti, T., & Ang, G. Scalable Runtime Governance for Agentic AI in Financial Services. SSRN 6567199, 13 April 2026. (Research frontier.)
  11. Dennis, J. B., & Van Horn, E. C. Programming semantics for multiprogrammed computations. Communications of the ACM, 9(3), 143–155, 1966. (Cited in SAFR for capability-based security.)

Working paper v1.0 — passed an evidence-verification pass (every quotation checked against the primary PDFs) and an adversarial red-team (one conceded objection and six claim reductions). Circulated for comment. © 2026 Dr Luke Soon.

Leave a comment