Chia Der Jiun, Managing Director of the Monetary Authority of Singapore (MAS), presented new supervisory expectations for artificial intelligence at the Global FinTech Fest 2026. The consultation guidelines aim to regulate the structural shift from purely analytical algorithms to autonomously acting agents in the financial sector. MAS justified this intervention with a sharp increase in operational risk: AI-driven cyber attacks surged by 89 percent recently, accompanied by a sixfold rise in critical vulnerabilities, with 2,200 CVEs recorded this year alone.
At the core of the supervisory framework lies the SAFR standard, short for Safeguards for Agentic Finance at Runtime. This architecture addresses software systems that no longer merely generate text or recommendations, but independently execute transactions and workflows at runtime. The framework mandates rigorous identity verification for every autonomous agent and strictly enforces authorization thresholds. Furthermore, financial institutions are required to maintain tamper-proof runtime audit trails to keep every automated decision fully explainable and reviewable.
The central bank systematically splits its regulatory package into high-level strategy and technical operationalization. The Guidelines for AI Risk Management define the binding requirements and governance duties expected of bank boards. Complementary Operationalisation Handbooks provide explicit engineering methodologies so that IT and risk divisions can integrate runtime guardrails directly into their software stacks. This structural separation is designed to provide clear regulatory boundaries without suffocating technical experimentation under inflexible legislation.
The urgency of actionable standards is highlighted by a global industry study released on September 22, 2026, by RegTech provider Regnology and consultancy Oliver Wyman. Titled 'The Agentic Gap', the report investigates the state of AI integration across regulatory reporting workflows. The findings reveal a stark disparity between early testing and production: while 87 percent of surveyed financial institutions run pilot projects with AI agents and large language models, 89 percent fail to bring these systems into live, productive use.
Regulatory reporting represents a substantial operational burden, accounting for one to three percent of overall expenditures at major banks. Up to 50 percent of these reporting costs stem from manual data checking, aggregation, and reconciliation workflows. According to the Regnology study, the barrier to deployment is not model capability or intelligence. Instead, the bottleneck is driven by missing governance boundaries, fragmented data architectures, and unresolved liability risks regarding erroneous data submissions to supervisory authorities.
The policy movement in Singapore and the findings from the reporting report signal a pivotal transition for the financial services industry. Isolated proof-of-concept projects are no longer sufficient to satisfy risk committees and regulators. Autonomous systems will only secure broader adoption once supervisory requirements like the SAFR framework are embedded directly into technical deployment pipelines, allowing institutions to delegate critical operations without compromising compliance.

