Singapore just moved AI governance squarely into the financial control environment.
On October 7, the Monetary Authority of Singapore finalized AI Risk Management Guidelines covering every financial institution it supervises and all forms of AI. The rules require institutions to identify their AI use, maintain inventories, assess materiality, establish board and senior-management accountability, and apply controls across testing, data, cybersecurity, human oversight, monitoring, change management, and third-party AI. They take effect beginning October 7, 2027.
The most consequential principle is simple:
Financial institutions remain responsible for AI used in their services even when someone else builds or operates it.
If a bank cannot obtain sufficient assurance about a third-party AI provider, MAS expects compensating controls. If the remaining risk exceeds the institution's risk appetite, it should consider limiting, suspending, or replacing the AI service.
That turns AI from a software-vendor issue into an enterprise risk issue.
And it could matter considerably in the United States.
The U.S. Already Has the Regulatory Plumbing
U.S. banking regulators do not need Congress to create an entirely new AI regulatory system from scratch.
They already supervise:
- model risk
- operational risk
- cybersecurity
- third-party risk
- internal controls
- vendor concentration
- consumer protection
What's missing is a clear supervisory bridge from those disciplines into generative and agentic AI.
In April, the Federal Reserve, OCC, and FDIC revised their model-risk guidance but specifically left generative and agentic AI outside its formal scope. The agencies nevertheless said existing governance principles should inform how banks manage tools not covered by the guidance.
Then in September, state bank supervisors released an AI Supervisory Framework designed to help examiners assess banks' AI use. Federal banking agencies also proposed updated third-party risk guidance focused on tailoring controls to the risk posed by individual vendors.
Singapore has now connected those pieces.
What Could Migrate to the U.S.
I would watch five MAS concepts closely:
1. AI inventories.
Institutions need to know where AI is actually being used.
2. Materiality-based controls.
An AI writing internal notes should not be governed the same way as an agent touching payments, credit, customer decisions, or financial records.
3. Executive accountability.
AI risk moves into normal board and senior-management oversight.
4. Third-party accountability.
Using OpenAI, Anthropic, Google, Microsoft, or another provider does not transfer responsibility away from the financial institution.
5. Agentic AI as a separate risk class.
MAS explicitly recognizes systems that can autonomously make decisions or execute actions and plans additional agent-specific guidance in 2027.
None of that requires a sweeping U.S. AI Act.
Much of it could arrive through the supervisory system banks already live under.
The Bigger Shift
For finance, the most important AI question is becoming less:
Which model are we using?
And more:
What authority have we given it, what can it touch, who remains accountable, and can we prove what happened?
That is a familiar financial-control problem applied to a new kind of actor.
Singapore may simply be getting there first.
Primary sources
- Download the MAS AI Risk Management Guidelines — October 7, 2026 (PDF)
- MAS AI Risk Management Guidelines
- MAS announcement and implementation timetable
- Federal Reserve SR 26-2: Revised Guidance on Model Risk Management
- CSBS AI Supervisory Framework announcement
- OCC proposed third-party risk management guidance