On 3 July 2026, the Monetary Authority of Singapore, together with leading financial institutions and FinTechs, published Safeguards for Agentic Finance at Runtime, an industry white paper on safeguards for AI agents1 in finance. SAFR is developed under MAS's BuildFin.ai2 initiative for responsible AI development in the financial sector. The premise is stated plainly: AI agents increasingly carry out tasks autonomously and at speed beyond practical human intervention. Institutions therefore need real-time safeguards keeping agent behaviour within predefined mandates, policies and risk boundaries. SAFR's answer is a set of governance checkpoints3 that verifies and records an AI agent's proposed actions before its tasks are executed. The framework builds on Project Mindforge's4 AI risk management toolkit, moving from risk taxonomy to operationalisation at the point of action. Four safeguard classes anchor the paper: policy-bound execution, real-time validation, auditability and interoperability,5 embedded into system operations.
The regulatory logic: control moves to runtime
SAFR's significance is architectural. Traditional supervision assumes a human in the approval chain; agentic systems remove that assumption, because the agent transacts faster than any human can intervene. The control point therefore migrates from human sign-off to machine-checkable policy enforced at runtime,6 with a verified, recorded checkpoint standing where an approver used to stand. The audit trail becomes the compliance artefact. MAS's pattern is worth reading: its AI frameworks begin as industry co-developed soft law and mature into supervisory expectation.7 Firms deploying agents in Singapore should assume SAFR alignment will be asked about in future inspections, whatever its formal status today.
Where industry has applied it
Industry members have applied SAFR across three use cases. Agent-assisted payments and treasury operations, where autonomous agents execute routine transactions within predefined mandates. Wealth management and advisory workflows, where agents review documents and generate structured assessments within narrowly scoped task boundaries. And client engagement, where agents draft materials within approved content boundaries. The first is the one digital asset firms should study: crypto-native treasuries are where autonomous agents already move value on-chain at machine speed, and a mandate-bounded, checkpoint-verified execution pattern is the emerging template for showing an agent-operated wallet or settlement flow remains under institutional control.
Participation and next steps
MAS invites interested industry partners to join the BuildFin.ai work group to shape subsequent SAFR iterations, with expressions of interest via MAS's form. The new Future of Finance Institute8 will support adoption through industry pilots and sandbox experimentation. Firms building agentic capability, including VASPs with Singapore operations, should join the work group now: frameworks are shaped by those in the room when the second iteration is drafted.
Notes
1. An AI agent is software that pursues a goal by planning and executing multi-step tasks with a degree of autonomy, typically by invoking tools, APIs and other systems. The defining property is action: unlike a generative chatbot, which answers, an agent transacts. “Agentic finance” denotes financial workflows in which such agents initiate or complete steps, from placing a payment instruction to rebalancing a portfolio, without a human touching each step.
2. BuildFin.ai is MAS's collaborative initiative bringing together financial institutions, technology providers and research institutes to co-develop AI solutions addressing real market needs. SAFR is its first major published framework.
3. A governance checkpoint is a pre-execution gate: the agent's proposed action is intercepted, validated against the institution's codified mandate, policies and risk boundaries, and recorded, before execution proceeds or is blocked. Functionally it is the machine-speed equivalent of four-eyes approval, with the approval logic expressed as code rather than exercised by a person.
4. Project Mindforge is the MAS-industry consortium examining generative AI risks and opportunities in financial services, which produced an AI risk management toolkit spanning governance, technology and deployment dimensions. SAFR takes Mindforge's risk taxonomy and asks the operational question the taxonomy leaves open: what actually stops a non-compliant action at the moment it is attempted.
5. The four safeguard classes, precisely: policy-bound execution confines the agent to actions within a codified mandate, so anything outside it is structurally unavailable rather than merely prohibited; real-time validation checks each proposed action at the moment of proposal against current policies, limits and risk state; auditability preserves a complete record of proposal, validation, decision and execution, making agent behaviour reconstructable after the fact; interoperability ensures the safeguards function across heterogeneous systems and vendors, so checkpoints are not locked to a single platform and mandates travel with the agent.
6. “Runtime” is the moment of execution. Runtime safeguards operate when an action is attempted, as distinct from design-time controls (model selection, training, testing and pre-deployment assessment) which operate before the system goes live. The distinction carries the paper's central insight: a perfectly assessed model can still take a non-compliant action in production, so assurance must attach to the action, not only to the model.
7. The lineage: the FEAT Principles (2018) set fairness, ethics, accountability and transparency expectations for AI in Singapore financial services; Veritas (from 2019) translated them into assessment methodologies with industry consortia; Mindforge extended the work to generative AI risk. Each began as voluntary co-developed guidance and each now frames MAS's supervisory conversations. SAFR should be expected to follow the same trajectory for agentic systems.
8. The Future of Finance Institute, announced by MAS in 2026, is designed to scale financial innovation, including through facilitation of industry pilots and sandbox experimentation; it will provide the supervised environment for testing SAFR-aligned deployments.




