This week the Monetary Authority of Singapore confirmed that agentic AI sits inside its supervisory Guidelines on Artificial Intelligence Risk Management. The Guidelines apply to all AI use cases a financial institution runs, autonomous agents included, and they set the Authority's expectations for board and senior management oversight and for sound controls across the AI lifecycle.
It is the first major financial supervisor to say the agent is in scope rather than carve it out. That posture is the news. What the posture asks for, and what discharges the ask at the moment an agent acts, is the part worth reading closely.
Three supervisors, one object.
The object is the same everywhere. An autonomous agent takes an action a regulated institution has to answer for. What differs is where each supervisor stands relative to it.
In the United States, SR 26-2 replaced SR 11-7 in April and carved agentic AI out of model-risk scope pending an interagency request for information. The agent action is acknowledged and set aside. In the European Union, the enforcement powers that became applicable on August 2 reach the general-purpose model provider, on inspection, after the effect has landed. The Monetary Authority took a third position. The agent is in scope now, under a principles-based framework that expects the institution to oversee it across its lifecycle.
Carved out, reached after the fact, or brought in scope. Three postures toward one action. The Singapore posture puts the obligation closest to the run, which makes it the one that most needs a runtime answer.
A principle names the duty.
Principles-based supervision states what has to hold. Board oversight of the AI an institution deploys. Risk management proportionate to the consequence of the decision. Controls that span the model's life from development through use. It deliberately does not prescribe the mechanism, because a supervisor sets an expectation rather than ship an implementation.
That leaves the how to the institution, and the how is where an autonomous agent parts from a scored model. A model returns one output and stops. An agent composes inputs the certification never saw, calls tools, and acts on their results thousands of times inside a single run. Oversight of a model is a review. Oversight of an agent is a control that has to operate at the speed the agent operates.
A duty named at the level of the institution is discharged at the level of the action. The principle sets the bound. Something in the path of each action has to hold it.
Oversight is exercised on the action.
Human oversight of an agent cannot mean a person watching every step. The run is too fast and too long for that, and the supervisor knows it. Oversight that keeps its meaning at agent speed is a control that stands in the path of the action and sets how much authority the action may carry, against a safety envelope declared before the run.
That control reads one quantity. How far realized behavior has diverged from the trajectory the agent was assured to hold. It sets the authority of the next step on where the step is heading, not on how clean the current step looks. It can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence before the outcome landed. When the forward look has not resolved before the action's deadline, it grants less, not more.
This is what oversight becomes when the thing overseen acts on its own. Not a review after the run and not a policy above it. A grant set on each action before the action reaches the actuator.
Lifecycle control includes the moment the model changes.
The Guidelines ask for control across the AI lifecycle. For an agent that adapts inside the run, the lifecycle has a moment most control frameworks skip. The moment the model is permitted to change.
A learning event is not a decision. It is the agent rewriting the function that produces decisions, and it resets the disposition behind every decision that follows. A lifecycle control that spans development and deployment but treats the run as static misses it. The control that admits or refuses a learning event against a declared bound, and records which change committed, is the lifecycle control at the one point the lifecycle actually moves. Oversight across the lifecycle has to reach the update, not only the decision.
What principles-based supervision will ask to see.
A principles-based regime places the burden of proof on the institution. The supervisor does not hand over a checklist that ends the inquiry once it is ticked. It asks the institution to show how it met the expectation for the decision in front of it.
An institution that ran a governor in the path can answer with the authority the governor set on that action, the envelope it measured against, and the divergence that moved the grant. An institution that governed with a policy document and a log beside the execution path can restate the principle. It cannot show the action being held to it. The supervisor that brought the agent in scope this week is, by the shape of its own framework, going to ask which of those two an institution has.
What we are building.
Velma is a runtime governor. It sits in the execution path, before the actuator, and sets how much authority each action carries against a declared safety envelope. It modulates that authority as the run proceeds, narrowing the grant when realized behavior diverges from the assured trajectory, and it enforces the grant in the path, so the agent acts only inside what the governor allows and cannot reach the effect by another route. It governs the learning event as well as the decision, admitting or refusing a change against the bound. Every action it governs is sealed to a tamper-evident record as it happens, which is the evidence a principles-based supervisor is about to ask for. The governor is the product. The record is what it emits.
Thirty minutes. Architecture, not sales.
A conversation about where in your agent stack the governor has to sit so oversight is exercised on the action rather than declared above the run, and what the record it produces has to contain to answer a supervisor that reads principles rather than checklists.
JonathanLuethke@WayfinderSystemsGroup.com
