Singapore’s MAS has introduced the SAFR framework for agentic AI in finance, adding runtime governance, real-time checks, audit trails and kill-switch controls for autonomous AI agents used by regulated firms.
Event Overview: MAS Leads Development of Agentic AI Governance Standards
In early July 2026, the Monetary Authority of Singapore (MAS) jointly released an industry white paper with multiple financial institutions and fintech companies, proposing a governance framework for artificial intelligence agents in financial services —SAFR. The framework was developed under BuildFin.ai, theAIindustry initiative led by MAS. It introduces the concept of “runtime governance” into the compliance framework for autonomous AI systems for the first time, requiring real-time validation and audit logging before an AI agent executes each decision.
Publication Background and Regulatory Context of the SAFR Framework
A Paradigm Shift from Predictive Models to Autonomous Agents
Over the past decade, AI systems deployed in the financial sector have mainly consisted of predictive and generative models, with behavioural boundaries fixed by developers in the form of rules before deployment. Since 2025, as “agentic AI” combining large language models with tool-calling capabilities has accelerated into practical use, financial institutions have begun introducing autonomous decision-making capabilities into core functions such as liquidity management, claims processing, customer interaction and algorithmic trading. These agents no longer rely on fixed instructions, but instead receive an objective and independently plan the steps required to act, meaning that the traditional compliance model of “pre-deployment testing plus post-event audit” struggles to cover risks arising at the moment of decision execution.
Historical Context: Continuation of the FEAT Principles and AI Model Risk Management
SAFR is not MAS’s first move in AI governance. In 2018, MAS worked with the financial industry to publish theFEATprinciples, establishing the basic ethical baseline for the use of AI and data analytics by financial institutions. In 2024, MAS also issued the Artificial Intelligence Model Risk Management information paper, setting out specific guidance on model lifecycle, data lineage, third-party procurement and related areas. SAFR follows the responsibility allocation logic of these earlier documents and extends the governance focus from the “model itself” to the “moment of agent action”, creating a runtime control layer for autonomous AI.
(Source: MAS website,Safeguards for Agentic Finance at Runtimeindustry white paper, published: 2026-07; MAS,Artificial Intelligence (AI) Model Risk Managementinformation paper, published: 2024; Xinhua,Singapore unveils safeguards framework for AI agents in finance, published: 2026-07-03.)
Core Mechanism of the Runtime Governance Layer
Point of Intervention and Validation Logic
SAFR proposes the deployment of an independent “runtime governance layer” between AI agents and financial institutions’ execution systems. Whenever an agent generates a proposed action, the governance layer evaluates its compliance, risk exposure and authorisation scope before execution, and records the outcome in an audit log. This mechanism gives financial institutions a “kill switch” capability over agent actions, allowing abnormal decisions to be intercepted before they are implemented.
“SAFR ensures that AI agents can be checked, governed, validated and recorded before taking action.”
Four Types of Disposition Outcomes
The SAFR framework classifies the runtime governance layer’s handling of proposed agent actions into four categories, each corresponding to a different compliance status and monitoring intensity:
Approved: the action meets all control requirements and risk limits, is automatically executed by the system and is recorded in the audit log.
Rejected: the action breaches preset policies or exceeds risk limits, so the governance layer blocks execution and generates an interception record.
Escalated: the action involves high risk or a low-confidence judgement and must be reviewed by a human before a release decision is made.
Flagged: the action has been executed within the control perimeter, but is added to an enhanced monitoring list for ongoing post-event audit tracking.
Together, these four disposition outcomes create full-chain traceability across the pre-event, in-event and post-event stages, enabling regulators and internal compliance teams to reconstruct an agent’s decision path at any point.
Key Governance Elements of the SAFR Framework
| Governance Element | Core Function | Point of Intervention | Responsible Party |
|---|---|---|---|
| Policy-bound execution | Validates whether the agent’s action is within the authorised policy scope | At the moment an agent action is generated | Regulated financial institution |
| Real-time validation | Verifies decision inputs, risk exposure and compliance boundaries | Millisecond-level window before execution | Runtime governance layer operator |
| Auditability | Fully preserves the decision path, input data and disposition outcome | Full traceability throughout execution | Compliance and internal audit departments |
| Kill switch | Immediately terminates an agent’s execution authority in abnormal circumstances | When unacceptable risk is detected | Risk management and operations teams |
Impact on Retail Brokers and Regulated Entities
Principle of Accountability: No Transfer of Responsibility to Third Parties
The SAFR white paper makes clear that financial institutions bear full responsibility for the behaviour of the AI agents they deploy, regardless of whether the underlying model comes from a third-party provider. This principle directly constrains retail brokers, wealth management platforms and insurance brokers: when agents are used in areas such as customer onboarding, order routing, risk warnings or anti-money laundering screening, regulated entities cannot reduce their own compliance obligations by arguing that the algorithm was provided by an external technology vendor.
For retail brokers, given the large volume of automated customer activity handled in day-to-day operations, the practical impact of the SAFR framework mainly includes:
The need to add an independent runtime governance component between the order management system and the agent decision layer, so that every AI-generated customer instruction is subject to compliance validation.
The need to establish abnormality monitoring dashboards for AI agents, displaying in real time the frequency of the four disposition outcomes: approved, rejected, escalated and flagged.
The need to revise contractual terms with third-party AI vendors, clearly defining obligations relating to data use, model change notifications and audit cooperation.
The need to appoint AI governance owners at board and senior management level, with regular reporting to regulators on agent operations.
Industry Adoption Path and Open Participation Mechanism
SAFR has been published as a white paper and does not itself have binding legal force. However, its contents are regarded as a “directional document” for MAS’s subsequent formal regulatory rules. Through the BuildFin.ai initiative, MAS has also opened participation channels to more financial institutions and fintech companies. Relevant institutions can submit pilot findings through the expression of interest (EOI) process and take part in the iteration of the next version of the framework.
Industry organisations generally believe that SAFR’s approach of introducing real-time governance at the point of execution will gradually influence regulatory attitudes towards autonomous AI in Asia-Pacific financial centres such as Hong Kong, Tokyo and Sydney, while providing a reference minimum standard for cross-border regulatory coordination in scenarios including algorithmic trading, automated wealth management and robo-advisory services.
(Source: FinTech Global,MAS moves to rein in autonomous AI agents in finance, published: 2026-07-06; Retail Banker International,Singaporean regulator outlines safety guardrails for financial AI agents, published: 2026-07; RegTech Analyst,Can banks trust AI agents? MAS unveils SAFR framework, published: 2026-07.)
Questions About the SAFR Framework and AI Agent Governance
What is the full name of the SAFR framework and who published it?
SAFR stands for Safeguards for Agentic Finance at Runtime. The framework was led by the Monetary Authority of Singapore under the BuildFin.ai industry initiative and was released in early July 2026 as an industry white paper in collaboration with multiple financial institutions and fintech companies.
How does the SAFR framework differ from traditional AI compliance guidance?
Traditional AI compliance guidance mainly covers pre-deployment testing and post-event audit. SAFR introduces a runtime governance layer between AI agents and execution systems, carrying out pre-execution validation and audit logging for every proposed action generated by an agent, while allowing a kill switch to be triggered in abnormal circumstances.
Is SAFR binding on financial institutions?
SAFR is currently published as an industry white paper and does not itself have binding legal force. However, as a directional document led by MAS, its core principles are expected to be gradually incorporated into Singapore’s financial regulatory rules and adopted by industry self-regulatory mechanisms as a minimum standard.
How do the four disposition outcomes defined by SAFR operate?
The four disposition outcomes are approved, rejected, escalated and flagged. Approved means the action meets control requirements and is automatically executed; rejected means the action is blocked by the governance layer; escalated requires human review; and flagged means the action has been executed under controlled conditions but has been added to an enhanced monitoring list.
Are financial institutions responsible when problems arise with third-party AI vendors?
Under the accountability principle set out in the SAFR white paper, financial institutions bear full responsibility for the behaviour of the AI agents they deploy and cannot transfer responsibility to third-party AI vendors. Regulated entities must assume compliance obligations for the behaviour of external models and algorithms through contractual terms, technical validation and the runtime governance layer.