Built for the first agentic-AI governance framework.
Singapore's IMDA published the world's first governance framework written specifically for agents that act, not just answer. It reframes the risk from wrong answers to wrong actions, and it is voluntary but keeps organizations accountable for what their agents do. Here is how its four dimensions map, control by control, to what Agentomy already provides at runtime.
Assess and bound the risk
The framework asks
- Evaluate each agent's impact, likelihood, and reversibility before deployment.
- Apply least privilege: the minimum tools and data an agent needs.
- Give agents a scoped identity and permission model.
Agentomy provides
- A five-tier identity model with tier capping, so an agent operates at the least privilege its role requires.
- Pre-action authorization that ties an action to the agent's identity and eligibility, not just its request.
- Export-control eligibility checks for actions that need them.
Meaningful human accountability
The framework asks
- Allocate clear responsibility across product, security, and operations.
- Keep a human in the loop in a way that counters automation bias.
- Require approval checkpoints for high-stakes, irreversible, or outlier actions.
Agentomy provides
- An escalation path: a permitted-but-pending action is recorded as escalated, not silently allowed.
- Operator-validated control for sensitive actions, so the human decision is attributable.
- Every decision carries an explicit authority source and expiry, so accountability is on the record.
Technical controls across the lifecycle
The framework asks
- Test agents with agent-specific and workflow-level evaluations before deployment.
- Monitor for anomalies and log for verification of what the agent did.
- Provide an offline mechanism for malfunctions, and threat-model memory poisoning, tool misuse, and privilege compromise.
Agentomy provides
- Named, runnable benchmarks: GovernanceBench, VIGIL, WorkflowBench, and OWASP-agentic coverage, run against the running system.
- A behavioral monitor and a tamper-evident, hash-linked audit trail that a third party can verify.
- A sub-50ms kill switch and quarantine, a file-integrity scanner over agent memory, and tier capping against privilege compromise.
End-user responsibility
The framework asks
- Be transparent with the people an agent interacts with.
- Give users the ability to intervene in or deactivate an agent.
Agentomy provides
- An AI-disclosure marker on outbound agent messages.
- Operator-triggered halt and quarantine, so an agent can be stopped on command.
Where the framework flags multi-agent risk but says little about it, Agentomy goes further: a cross-fleet threat-intelligence graph and fleet-wide halt govern the layer between agents, not just each agent alone.
What is Singapore's Model AI Governance Framework for Agentic AI?
It is a governance framework published by Singapore's IMDA in 2026, and it is widely described as the world's first framework written specifically for agentic AI: systems that plan, act, and adapt rather than only answer. It reframes the risk from wrong answers to wrong actions, and organizes governance into four dimensions: assessing and bounding risk, meaningful human accountability, technical controls across the lifecycle, and end-user responsibility. It is voluntary, but organizations remain accountable for what their agents do, and it applies to both those who build agents and those who deploy them.
How does Agentomy map to the framework?
Agentomy provides a runtime capability for nearly every technical control the framework names: least-privilege identity and pre-action authorization for bounding risk, an escalation path and operator-validated control for human accountability, agent-specific and workflow-level benchmarks plus a tamper-evident audit trail and a sub-50ms kill switch for the technical-controls dimension, and an AI-disclosure marker plus operator halt for end-user responsibility. The mapping above lists each control against the capability that answers it.
Does Agentomy address the multi-agent risk the framework raises?
Yes, and this is where Agentomy goes further than the framework specifies. The framework acknowledges that agents interact with other agents but provides limited multi-agent-specific guidance. Agentomy adds a cross-fleet threat-intelligence graph and fleet-wide halt, so an attack seen on one agent can protect the rest and an operator can stop the fleet on one command.
Is Agentomy certified or compliant with the framework?
No, and we are careful about this wording. The framework is voluntary and there is no certification to hold. Agentomy is designed to support readiness against the framework's controls; it is not a certification, an audit, or a legal opinion. Organizations should engage qualified advisors for any formal compliance assessment. What Agentomy provides is the runtime evidence: the enforcement, the tamper-evident record, and the benchmarks that make a readiness case demonstrable rather than asserted.
This page is a readiness mapping, not a certification, an audit, or a legal opinion. The framework is voluntary; Agentomy is designed to support readiness against its controls. Organizations should engage qualified advisors for any formal compliance assessment.