MAS Finalises AI Risk Guidelines: What Actually Changed

Commentary | 7 October 2026 | Luke Soon

MAS AI Risk Guidelines, Final: Agents, Vendors, and a Two-Year Clock // AIRG Final: Singapore Moves from Principles to Evidence

Contents

  1. Introduction
  2. Timeline and Transition
  3. Areas of Continuity
  4. Principal Changes from the Consultation
  5. Treatment of Agentic AI
  6. Interaction with the Broader Singapore Framework
  7. Enforceability Assessment
  8. Cross-Reference: The Drafter’s Reading
  9. Stakeholder Perspectives
  10. Recommended Actions for Boards and Senior Management
  11. Concluding Observations

I. Introduction

1.1 On 7 October 2026, the Monetary Authority of Singapore (MAS) issued its final Guidelines on Artificial Intelligence Risk Management (the “Guidelines” or “AIRG”). The Guidelines follow the consultation paper published on 13 November 2025 (P017-2025), which closed on 31 January 2026.

1.2 This commentary compares the final text with the consultation, identifies areas of continuity and change, and assesses the implications for financial institutions (FIs). It also cross-references the reading published on the same day by Gary Ang, who led AI risk supervision at MAS and developed the AIRG.

1.3 In summary, the architecture of the consultation has been retained. The principal changes concern the implementation runway, the test that determines the scope of expectations, the treatment of third-party AI, the unit of risk materiality assessment, and the accountability of local senior management. The final text is also materially more specific in its treatment of AI agents.

1.4 A note on method. The final text has been reviewed in full. Statements about the consultation draw on MAS’s consultation notice and questions, contemporaneous practitioner summaries, and Mr Ang’s account of what changed. Where these sources do not settle the consultation’s exact wording, this commentary does not assert a change.

II. Timeline and Transition

2.1 The consultation proposed a single transition period of 12 months after the Guidelines were finalised. The final text replaces this with a two-stage implementation (paragraph 1.8).

DateMilestone
13 November 2025Consultation paper issued
31 January 2026Consultation closed
7 October 2026Final Guidelines issued
7 October 2027Sections 3 and 4 apply: oversight, identification, inventory and risk materiality assessment
7 October 2028Sections 5 and 6 apply: life cycle controls, capability and capacity
Table 1: Implementation timeline

2.2 The sequencing is deliberate. An FI is expected to demonstrate that it knows where its AI is, and how material each use is, before it is assessed on how well it controls that AI. Controls cannot be validated for AI that has not been identified and inventoried.

III. Areas of Continuity

3.1 The final Guidelines retain the structure on which MAS consulted. FIs that benchmarked their practices against the consultation over the past year have not wasted that effort. The following elements are substantively unchanged.

3.2 Four pillars. Board and senior management oversight; identification, inventory and risk materiality assessment; AI life cycle controls; and capability and capacity. The final text adds an Introduction and an Application section around these pillars.

3.3 Three dimensions of materiality. Impact, Complexity and Reliance remain the minimum dimensions (paragraph 4.12). Reliance continues to capture the autonomy granted to AI and the degree of human involvement.

3.4 Inherent and residual risk. Both are to be assessed. The final text makes the consequence explicit: residual risk materiality must sit within the FI’s risk appetite before deployment (paragraph 4.11).

3.5 Breadth of scope. Generative AI and AI agents remain in scope. Rule-based tools and robotic process automation that follow fixed instructions without learning remain outside it (paragraph 1.3, footnote 6).

3.6 Proportionality. The Guidelines remain supervisory expectations rather than legislation, scaled to the size, nature and risk profile of each FI. They are less prescriptive than the EU AI Act by design.

3.7 FEAT. The 2018 principles on Fairness, Ethics, Accountability and Transparency continue to apply (paragraph 1.2). The Guidelines supply the operating machinery; FEAT remains its purpose.

IV. Principal Changes from the Consultation

4.1 The changes are largely refinements, but several will reshape implementation plans. They are set out in Table 2.

AreaNovember 2025 consultationOctober 2026 finalImplication
RunwaySingle 12-month transitionSections 3 and 4 from 7 October 2027; Sections 5 and 6 by 7 October 2028 (1.8)Governance first, controls second
Scope testFuller expectations keyed to whether AI formed an integrated part of business processesKeyed to impact: basic governance only where failure is unlikely to cause material adverse impact (2.3), with six worked examples (2.4)A deeply embedded but low-impact tool may remain on the basic track; a rarely used but consequential model may not
Third-party AIOne life cycle control area among othersPrimary accountability retained by the FI; limit, suspend or replace a provider where residual risk exceeds appetite; independent assessments rather than self-attestations (5.11)Procurement and contracts become frontline AI controls
Embedded and shadow AIInventory of AI usageIdentification extends to AI embedded in material providers’ services and to shadow AI, with residual risk kept within appetite (4.2, 4.4)AI never procured as AI falls within scope
Unit of materialityAI use case, system or modelMethodology evaluates the use case, with dependencies on supporting systems and models taken into account (4.10, footnote 26)One model may carry different ratings in different use cases
Committee structureDedicated cross-functional committee proposed where overall AI exposure is materialNo mandatory committee; cross-functional structures given as an example (footnote 16); oversight may sit at regional or global level (footnote 17)Flexibility for groups, with the burden shifting to demonstrating effective coordination
Group frameworksBranches and subsidiaries may leverage parent frameworksStill permitted (1.5), but local senior management remains accountable and must be able to demonstrate oversight to MAS (3.6)Reliance on the group is not, by itself, sufficient
Control functionsRoles for identification, inventory and assessmentA designated control function is the final arbiter of what constitutes AI and approves materiality ratings (4.3, 4.13)Classification disputes have a clear owner
Risk appetiteAI risk appetite and thresholdsQualitative statements and quantitative measures, including counts of material use cases dependent on a single provider (3.4(b), footnote 18)Concentration risk becomes a board-level metric
Eased expectationsFuller expectations on model selection and review of basic policiesLighter model selection expectations (5.12) and review cadence for basic policies (2.5(f))Consultation feedback was reflected where cost exceeded benefit
Table 2: Comparison of the consultation and the final Guidelines

4.2 The consultation column reflects the public record of MAS’s intent, as described in Paragraph 1.4. The final column is the text against which FIs will be supervised.

V. Treatment of Agentic AI

5.1 The consultation brought AI agents within scope. The final Guidelines specify how they are to be governed. This marks the transition from acknowledging a technology to supervising it.

5.2 Paragraph 1.11 identifies the core agentic failure mode with precision: a divergence between the goals an agent is given and the actions it takes to pursue them. It also identifies the security corollary, namely a compromised agent exfiltrating data or executing malicious commands at scale.

5.3 The relevant controls are distributed across the life cycle:

  • Inventory: agent-specific identifiers, the tools and systems an agent can access, its components and its guardrails (footnote 25).
  • Materiality: the Reliance dimension explicitly captures the autonomy granted (4.12(c)).
  • Evaluation and testing: coverage of key failure modes and the effectiveness of guardrails (5.15), with red teaming and adversarial testing before deployment (5.22(b)).
  • Monitoring: information flows, reasoning processes, actions taken and tools used, where relevant (5.23(a)); logging of prompts, responses, model versions and reasoning (5.23(d)).
  • Containment: kill switches for high-materiality AI, with activation protocols that are tested regularly (5.3, 5.23(b)).
  • Third parties: more detailed evaluation and cybersecurity checks where an FI has limited experience of vendor-supplied agents (footnote 40).

5.4 Supervision designed for prompts asks whether an output was correct. Supervision designed for agentic loops asks whether a sequence of actions remained within its mandate. The Guidelines now pose the second question, and cross-reference IMDA’s Model AI Governance Framework for Agentic AI in answering it (footnote 11). In the author’s framing, this is the progression from prompts, to loops, to loop governance.

VI. Interaction with the Broader Singapore Framework

6.1 The consultation and the final text are best read as a single argument made twice: the consultation set out what MAS expects; the final text sets out how it will look for evidence. FIs that built against the consultation may treat the final text as a specification for work already in progress.

6.2 AI inventories built in 2026 against the consultation form the baseline for 2027. The final text extends rather than replaces them: inventories should link to data asset and vendor registers (4.6, footnote 23), capture agent attributes (footnote 25), and record a materiality rating for each use case.

6.3 The Guidelines cite by name the instruments that surround them, as set out in Table 3.

InstrumentRoleReference in the Guidelines
MAS FEAT principles (2018)Ethical intent1.2, footnote 35
IMDA Model AI Governance Framework for Agentic AIAgent-specific governance practiceFootnote 11
IMDA Starter Kit for Testing LLM-Based ApplicationsGenerative AI evaluationFootnotes 43, 46
IMDA Transparency Guidelines for Generative AI ChatbotsCustomer disclosureFootnote 34
CSA Guidelines on Securing AI SystemsCybersecurity of AIFootnote 3
PDPC Advisory Guidelines on personal data in AIPersonal data useFootnote 30
MAS Technology Risk Management GuidelinesInfrastructure and resilience5.16, 6.3
NIST AI Risk Management FrameworkInternational referenceFootnotes 31, 51
Table 3: Instruments referenced in the Guidelines

6.4 The pattern is characteristic of Singapore’s approach: voluntary frameworks first, supervisory expectations second, and a common vocabulary between them. The author had the privilege of co-authoring the agentic AI governance framework with IMDA, and it is encouraging to see it now referenced in sectoral supervision.

6.5 For FIs operating across jurisdictions, the practical lesson is to implement once against a coherent control set mapped to several regimes, including MAS, IMDA, NIST, ISO/IEC 42001 and the EU AI Act. This is the design principle behind TrustOS.

VII. Enforceability Assessment

7.1 The test applied here is whether a supervisor examining an FI after 7 October 2027 would find evidence, or only intentions. By that test, the final Guidelines are materially stronger than the consultation, for the following reasons.

  • Decision rights are assigned. A designated control function arbitrates what constitutes AI and approves materiality ratings (4.3, 4.13).
  • Thresholds are measurable. Evaluation thresholds must be clear, measurable and agreed between business owners, developers and reviewers (5.14(a)); monitoring should use tiered early-warning levels (5.23(a)).
  • Vendor assurance has a minimum standard. Independent assessments are recognised; self-attestations are not (5.11(a)). Compensatory testing on the FI’s own data is expected where disclosure is limited (5.10).
  • Contingency is tested. Fallback plans for high-risk use cases and kill-switch protocols must be tested regularly (5.3).
  • Local accountability is demonstrable. Local senior management must be able to show MAS how it discharges oversight (3.6).

7.2 Qualifiers such as “relevant”, “appropriate” and “where possible” continue to carry weight, and much will depend on how proportionality is calibrated in supervisory practice. This is inherent in a principles-based regime. It follows that the evidence trail is itself the compliance: an FI unable to produce its inventory, materiality rationale and test results on request will find its policies of limited assistance.

VIII. Cross-Reference: The Drafter’s Reading

8.1 Gary Ang led AI risk supervision at MAS, developed the AIRG and now leads Quaintitative. His overview of the final AIRG, published on 7 October 2026, is the nearest available equivalent to an author’s note. He identifies five points: a phased clock; a scope test based on impact; third-party AI as the area most tightened; direct naming of generative AI and agents, with guardrails to be tested for effectiveness; and some expectations eased, including the removal of the mandatory committee.

8.2 Points of convergence. The phased runway, the agentic provisions and the removal of the committee are consistent with this commentary. So is Mr Ang’s underlying thesis that AI risk is largely an extension of risks FIs already manage. For an FI with functioning model, third-party and technology risk disciplines, this is the most reassuring observation in either reading.

8.3 Points of refinement. Mr Ang frames the basic-governance track as a change in the test itself, from how embedded AI is to how much harm it could cause. This is significant for large FIs with extensive copilot estates, not only for smaller firms. He also identifies third-party AI as the area most tightened; Table 2 reflects this.

8.4 Points for further emphasis. The author would emphasise three further matters:

  1. Testing guardrails is necessary but not sufficient. A guardrail that passes pre-deployment testing may still fail on a novel sequence of actions. Runtime monitoring of reasoning and tool use under paragraph 5.23(a) is likely to prove the most important agentic control.
  2. Local accountability. For groups headquartered outside Singapore, paragraph 3.6 may prove the most demanding change in practice.
  3. The use case as the unit of assessment. Anchoring materiality on the use case, with model dependencies feeding in, requires inventories structured as linked records rather than flat lists.

8.5 That a drafter and an implementer, reading the same text on the day of issuance, broadly agree on what has changed is itself informative. A text that can be read consistently is a precondition for one that is supervised consistently.

IX. Stakeholder Perspectives

9.1 Chief Risk Officers. The phased timeline is realistic, and the basic-governance track avoids imposing model-grade documentation on low-impact tools. The principal concern is resourcing: independent validation and periodic re-validation of high-materiality use cases will stretch second-line functions.

9.2 Engineering teams building agents. Logging of reasoning, tool calls and actions is consistent with existing engineering practice. The gap is semantic: logs record what an agent did, not whether it should have done so. Goal-to-action divergence (1.11) calls for runtime policy enforcement as well as telemetry.

9.3 Global and regional groups. Oversight committees may sit outside Singapore, but paragraph 3.6 requires local senior management to have visibility, escalation paths and the capacity to act.

9.4 Technology vendors. Paragraph 5.11(f) will prompt contractual changes: notification before AI is introduced, notification of updates, and rights to audit. AI embedded within software-as-a-service (footnote 21) is likely to surface use that FIs did not procure as AI.

9.5 Sceptics. The natural concern is that proportionality becomes a loophole. Paragraph 2.5(f) addresses this by requiring periodic and trigger-based review of eligibility for the basic track. Whether FIs detect the moment a low-impact tool begins to inform a consequential decision will test the quality of their identification processes.

X. Recommended Actions for Boards and Senior Management

10.1 Twelve months is sufficient to meet the expectations in Sections 3 and 4 if work begins this quarter. The following sequence is recommended:

  1. Assign accountability. Designate the senior manager accountable for AI oversight and the control function responsible for identification and materiality.
  2. Incorporate AI into risk appetite. Adopt qualitative statements and at least two quantitative measures, such as AI incident counts and single-provider dependencies.
  3. Conduct an identification exercise. Include AI embedded in material providers’ services and shadow AI, and record the residual risk of what cannot be identified.
  4. Restructure the inventory around use cases. Link each use case to its models, systems, data assets and providers, with agent identifiers, tool access and guardrails recorded.
  5. Assess every use case. Apply Impact, Complexity and Reliance before and after controls, and retain the rationale as evidence.
  6. Triage low-impact use. Place qualifying tools on the basic-governance track, with triggers for reassessment.
  7. Formalise the group interface. Document Singapore escalation paths and the reporting received by local management.
  8. Begin the 2028 workstreams. Independent validation capacity, contingency testing and contractual changes with providers carry the longest lead times and should be budgeted now.

XI. Concluding Observations

11.1 The 2025 consultation asked whether AI risk could be managed with the same discipline as credit or market risk. The final Guidelines answer in the affirmative, and specify how that discipline is to be evidenced: named owners, a defined timeline, and agents treated as actors whose actions are to be inventoried, monitored and, where necessary, halted.

11.2 Singapore has again chosen a course between laissez-faire and statute: supervisory expectations, proportionate by design and integrated with national frameworks. For FIs, the near term will bring a demanding programme of work. For the financial system and the customers it serves, the longer-term return is trust that can be demonstrated rather than asserted. Short-term turbulence, for long-term abundance.


References

  1. Monetary Authority of Singapore, Guidelines on Artificial Intelligence Risk Management, 7 October 2026.
  2. Monetary Authority of Singapore, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management (P017-2025), 13 November 2025.
  3. Gary Ang, Quaintitative, Singapore’s AI Risk Management Guidelines (AIRG) are final, 7 October 2026.
  4. BABL AI, MAS Unveils Draft AI Risk Management Guidelines for Financial Institutions.
  5. Mondaq, Navigating AI Risk Management in Financial Institutions in Singapore.
  6. Allen & Gledhill, MAS consults on proposed Guidelines for Artificial Intelligence Risk Management.

The views expressed are the author’s own. This commentary does not constitute legal or regulatory advice.

One response

Leave a comment