Singapore Wrote Rules For AI Agents In January. Your Team Is Already Running Them.
By Gabriel Tan | June 2026
A consultant sets an AI agent running overnight. It runs the daily media monitoring: it pulls the day's exchange filings, drafts a client brief, formats it, and queues an email for the morning. Nobody watches it work. This is not a future scenario. It is probably happening in your firm this week, on a tool someone installed without telling you.
Singapore has already named the rules for it. On 22 January 2026, the Infocomm Media Development Authority launched the Model AI Governance Framework for Agentic AI, the first framework of its kind anywhere, building on its earlier frameworks for traditional and generative AI. The Infocomm Media Development Authority, IMDA, is Singapore's lead agency on this. The framework is voluntary. That word does less for you than it sounds.
The framework carries no penalties on its own, but your organisation stays legally accountable for everything its agents do under existing data protection, financial, and sectoral law. Voluntary describes the framework. It does not describe your liability.
Why an agent is a different animal from the AI you know
Traditional AI predicts. Generative AI produces a draft you then read. An agent acts. It plans across steps, opens tools, reads and writes to live systems, and finishes a task without a human touching a key.
That is the value. It is also the exposure. A draft sits there until you approve it. An agent has already sent the email, updated the record, or filed the document by the time you look. The mistake is not waiting for your review. It already happened.
Four checks, read as a comms-team checklist
The framework sets out four dimensions. Read plainly, they are a checklist you can run on any agent in your agency workflow.
One, bound the risk before you switch it on. Decide what the agent is allowed to touch and what is off limits. An agent that can draft is lower risk than one that can send.
Two, keep a human meaningfully accountable. Not a name on a form. A person who sees the work and can stop it, with the time and standing to do so.
Three, put technical controls and logs in place. If the agent acted last night, you need a record of what it did, so that when something is wrong you can see where and undo it.
Four, make the end user's responsibility clear. The consultant running the agent has to know what they own and what they cannot push onto the machine.
Map these onto the way you already work. Human sets the task, AI does the production, human checks and signs off. The four checks are that architecture with the gates written down and the logs switched on.
What to do this week
Find the agents first. You cannot govern what you have not located.
Write down every task your team currently hands to an agent that runs without a human gate. Twenty minutes, and ask the team, do not guess.
Take the riskiest one, the one that sends, files, or changes something live, and add a single approval step before anything leaves the building. Thirty minutes.
If that surfaces an agent you did not know was running, the exercise has already paid for itself.
An agent that acts for you carries your name when it is wrong, and it will be wrong eventually. The four checks turn that exposure into something you can describe to a client with a straight face. Singapore has handed communications firms the structure for free. The only cost is the twenty minutes it takes to find out what your own team has already switched on.
Gabriel Tan is the founder of Mekong Bridge Advisory. He builds structured execution systems for PR and communications firms.