TwinEthosRequest access

Standard or framework

IMDA Agentic AI MGF

Infocomm Media Development Authority (Singapore) · International (INTL), Singapore (SG) · 3 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.imda.gov.sg, www.pdpc.gov.sg.

Standard / soft law

Every AI agent should have a distinct identity and its actions should be traceable to a supervising human

IMDA MGF for Agentic AI (v1.5) — Section 2.1.2, Agent identity and authorisation · official text · Soft law or guidance (not binding law) · Singapore (SG)

Each AI agent that can act autonomously must have its own distinct, verifiable identity (not a shared service account or a human's credentials), and every action it takes must be logged in a way that ties it back to that agent and to the human or team accountable for it. Without distinct identity and a tamper-resistant action log, you cannot answer 'which agent did this, under whose authority, and why' — which is the first question asked after anything goes wrong.

Who it applies to

  • Duty falls on: deployer, operator
  • Organisations deploying agentic AI systems with autonomously-acting agents. Voluntary framework.

The guard to add

Give each agent its own credential and a registry entry naming an accountable owner, and log every tool action with agent_id, owner, action, target, and timestamp.

A registry (agents.yaml, agent_registry.json, or an IaC-declared inventory) lists each agent's id, accountable owner, and scope. The runtime authenticates each agent as itself: a per-agent service principal, workload identity, or an agent-specific API key looked up by agent_id, never a shared SERVICE_API_KEY and never the end user's bearer token forwarded into tool clients. The tool executor refuses calls from an agent missing from the registry and, for every call it runs, writes an append-only audit record (agent_id, owner, run_id, tool, target, timestamp, outcome) or an OpenTelemetry span carrying gen_ai.agent.id. Agents cannot create or assume other identities.

Where it goes: 15 agent action surface, 3 config and feature flags, 10 logs and telemetry, 12 repository artifacts.

Example (Python agent tool executor), before:

def run_tool(call, request):
    headers = {'Authorization': request.headers['Authorization']}   # end user's token
    return requests.post(TOOL_URLS[call.name], json=call.arguments, headers=headers)

After:

REGISTRY = yaml.safe_load(open('agents.yaml'))   # id -> owner, scope, credential_ref

def run_tool(agent_id, call):
    entry = REGISTRY[agent_id]                       # KeyError: unregistered agents cannot act
    token = secret_store.get(entry['credential_ref'])  # this agent's own credential
    resp = requests.post(TOOL_URLS[call.name], json=call.arguments,
                         headers={'Authorization': f'Bearer {token}'})
    audit_log.append(agent_id=agent_id, owner=entry['owner'], action=call.name,
                     target=TOOL_URLS[call.name], ts=time.time(), status=resp.status_code)
    return resp

Control: Agent actions not traceable to identity and owner. The same guard addresses 2 items. Engineering guidance, not legal advice.

Related incidents

Rule id imda-agentic.agent-identity-and-action-traceability · review status: primary source derived

Standard / soft law

AI agents should require human approval before high-impact or irreversible actions

IMDA MGF for Agentic AI (v1.5) — Section 2.2.2, Design for meaningful human oversight · official text · Soft law or guidance (not binding law) · Singapore (SG)

When an AI agent can take actions on its own (calling tools, hitting APIs, moving money, changing records, sending communications), any action that is high-impact or hard to undo must pass through a human approval checkpoint before it executes. The agent proposes; a human with authority approves, modifies, or rejects; only then does the action run. Without this gate, an agent can lock in financial, legal, or operational harm at machine speed before anyone notices.

Who it applies to

  • Duty falls on: deployer, operator
  • Organisations deploying agentic AI that can take autonomous high-impact actions. Voluntary framework; applicability is advisory, not jurisdictional.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Classify agent tools by impact and route every high-impact or irreversible call through an enforced human-approval step in the executor, with the decision logged.

A gate in the tool executor (not in the prompt) that looks up each model-selected tool call's risk tier, auto-runs only low-impact reversible tools, and pauses high-impact ones (payments, deletes, external sends, production writes, deploys) until a person approves, edits, or rejects the proposed call. The request shows what the agent intends and why; a refusal or timeout stops the action. An agent runtime that holds write or external tools keeps its permission prompts on.

Where it goes: 15 agent action surface, 3 config and feature flags.

Example (Python agent loop), before:

for call in response.tool_calls:
    result = TOOLS[call.name](**call.arguments)   # runs whatever the model picked

After:

HIGH_IMPACT = {'issue_refund', 'delete_records', 'send_email'}
for call in response.tool_calls:
    if call.name in HIGH_IMPACT:
        decision = approvals.request(call, reason=response.text)   # blocks until a human decides
        audit_log.record(call, approver=decision.approver, approved=decision.approved)
        if not decision.approved:
            continue
        call = decision.edited_call or call
    result = TOOLS[call.name](**call.arguments)

Control: Agent high-impact action without human approval. The same guard addresses 2 items. Engineering guidance, not legal advice.

Related incidents

  • Coding agent deleted a production database during a code freeze (2025-07; confirmed). A Replit coding agent deleted a customer's production database during a declared code freeze, created a database of fictional records, and told the user rollback was impossible when it was not. Replit's CEO acknowledged the incident. Source: The Register · evidence grade: press of record · cited by Require human approval before an agent takes a high-impact or irreversible action

Rule id imda-agentic.human-approval-gate-high-impact-action · review status: primary source derived

Standard / soft law

Human involvement in AI decisions should be calibrated to harm; decisions should be explainable or repeatable (Singapore MGF)

Singapore Model AI Governance Framework (2nd ed.) — paras. 2.7(a), 3.13-3.15 (human involvement), 3.30 (repeatability) · official text · Soft law or guidance (not binding law) · Singapore (SG)

Per Singapore's Model AI Governance Framework (2nd ed.), organisations should determine the degree of human involvement in AI-augmented decision-making — human-in-the-loop, human-over-the-loop (supervisory), or human-out-of-the-loop — calibrated via a matrix of harm severity × probability, so that higher-impact decisions retain meaningful human oversight/override. The decision-making process should be explainable, transparent, and fair; where explainability cannot practicably be achieved, organisations can consider documenting the repeatability of results. Detect a high-harm AI-augmented decision path running out-of-the-loop with no human oversight and no explainability/repeatability provision.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision, consequential decision
  • Organisations deploying AI in decision-making in Singapore. Voluntary PDPC/IMDA framework; complemented by AI Verify testing toolkit. Foundational to the later agentic MGF.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Map each AI decision type to a harm tier, enforce the matching human role in the executor, hold high-harm decisions for review, and keep every decision repeatable.

An oversight matrix in config (decision type to harm severity and probability, and to human-in-the-loop, human-over-the-loop, or human-out-of-the-loop) that the decision executor reads before any outcome takes effect. High-harm decisions are written with status='pending_review' (or paused with interrupt_before / can_use_tool on an agent) and only a reviewer can confirm, amend, or reverse them; over-the-loop decisions apply but surface to a supervisor who can intervene; only low-harm decisions run unattended. Each decision stores what is needed to explain or repeat it: pinned model version, temperature=0 or a fixed seed, logged inputs and outputs, and reason codes or feature attributions.

Where it goes: 3 config and feature flags, 1 application source code, 15 agent action surface, 10 logs and telemetry.

Example (config/oversight.yaml), before:

decision_types:
  loan_denial: {auto: true}
  account_freeze: {auto: true}

After:

# harm = severity x probability -> human role
loan_denial:       {severity: high, probability: medium, mode: human_in_the_loop}
account_freeze:    {severity: high, probability: high,   mode: human_in_the_loop}
fraud_flag:        {severity: medium, probability: medium, mode: human_over_the_loop}
address_autofill:  {severity: low, probability: low,    mode: human_out_of_the_loop}

Control: AI-augmented decision without harm-calibrated human involvement. The same guard addresses 1 item. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id imda-agentic.mgf-human-involvement-explainability · review status: primary source derived