VISIONEER Book a walkthrough
How it worksTrust & standardsInsights
INSIGHTS · REGULATION

MAS SAFR, explained in plain English

Singapore just published a framework for governing AI agents at the moment they act. Here is what it actually says, who it applies to, and what to do about it.

Published July 2026·8 min read·Signal-Fire / Visioneer

The short answer: SAFR stands for Safeguards for Agentic Finance at Runtime. It is an industry white paper published by the Monetary Authority of Singapore on 3 July 2026, developed with financial institutions and FinTechs under the BuildFin.ai initiative. It is not a regulation and carries no penalties. What it does is describe how an AI agent's proposed action should be checked, approved or refused, and recorded — before it reaches live financial systems.

That last word is the whole point. Most AI governance to date has been retrospective: you review the logs after something has happened. SAFR moves the control to runtime — the instant before the agent acts. It is the difference between an inquest and a seatbelt.

Why this appeared now

Because AI stopped advising and started acting. A model that drafts a recommendation is a tool. An agent that can move money, open a position, or file a submission is something else — it is an actor inside your financial systems, operating at machine speed, and often several of them at once.

Gartner's numbers give the scale of the problem: the average large enterprise ran fewer than 15 AI agents in 2025 and is projected to run over 150,000 by 2028. Only about 13% of organisations believe they have the right governance in place for them. When agents multiply faster than oversight, you get what Gartner now calls agent sprawl — and in finance, sprawl is not a productivity issue. It is a systemic one.

What SAFR actually proposes

Strip away the framing and SAFR describes a checkpoint. An AI agent proposes an action. Before that action touches anything real, the checkpoint verifies who the agent is and what authority it holds, then evaluates the proposed action against the institution's controls — deterministically, meaning by fixed rules rather than by another model's judgment.

The checkpoint then returns one of four outcomes:

OUTCOME 01

Auto-execute

The action is within policy and authority. It proceeds without friction — which is what makes the rest workable.

OUTCOME 02

Observe

It proceeds, but is flagged and watched more closely. The middle setting most frameworks forget to include.

OUTCOME 03

Escalate

It stops and waits for a human decision. This is where accountability actually lives.

OUTCOME 04

Deny

It is refused outright and recorded. The agent does not get a second attempt at the same door.

Nothing reaches the financial rails unless it is approved. That is the architecture in one sentence.

The four pillars

SAFR organises this into four principles:

  • Policy-aligned execution — the agent can only do what your policy permits, enforced before the act, not judged after it.
  • Real-time validation — identity, authority and intent are checked at runtime, every time.
  • Auditability — every decision, approval and refusal is recorded in a form you can produce later.
  • Interoperability — the safeguards work across systems and providers, rather than being locked inside one vendor's stack.

That fourth pillar is the one most commentary skips, and it is quietly the most demanding. It means governance cannot be a proprietary island. If your controls only work on one vendor's agents, you have not governed your institution — you have governed a corner of it.

Does SAFR apply to me?

Directly, it is aimed at financial institutions and FinTechs deploying agents that can act on financial systems. If you are a licensed institution, this is your direction of travel and your board will ask about it.

If you are a law firm, a distributor, or a family office, SAFR does not bind you. But it would be a mistake to file it away. Regulators borrow from each other, and clients borrow faster. The four principles are already becoming the general vocabulary for "we have this under control" — and the first time a client, auditor or counterparty asks how you govern your AI, this is the shape of answer they will expect.

What SAFR does not do

Three honest clarifications, because the marketing around this will get loose very quickly.

There is no such thing as being "SAFR certified." It is a white paper, not a certification scheme. Any vendor claiming certification is telling you something about their integrity, not their product.

It does not move your obligation onto a vendor. MAS's guidance on AI risk is consistent on this point: third-party tools are in scope, and an institution cannot delegate its governance responsibility to a supplier. A platform can give you the controls and the evidence. It cannot absorb your accountability.

It does not slow you down, if implemented properly. The auto-execute path exists precisely so that routine work runs at full speed. Friction is reserved for the actions that deserve it.

What to actually do about it

The uncomfortable question first: could you stop one of your AI agents right now — in one second, permanently, with a record of who stopped it and why? For most firms the honest answer is no, and every other consideration is downstream of that.

You cannot govern an agent you do not run through something. If your agents execute on infrastructure you do not control, you are watching them, not governing them — and a dashboard is not a safeguard. The practical starting point is architectural: give every agent one door to walk through, and put the checkpoint in that door.

Concretely, that means four things: define what each agent is permitted to do before it runs; validate every proposed action against that at runtime; require human approval for anything material; and write all of it to a record you can produce on demand. If that sounds like the four pillars, it is — because the pillars are not a bar to clear so much as a description of how any competently governed agent already works.

The wider point

Singapore has done something genuinely useful here. While much of the world argues about the EU AI Act's scope, MAS has published something an engineer can build against and a board can understand. Firms that can show alignment will win regulated work. Firms that cannot will quietly be screened out of it — not by a regulator, but by counterparties who ask the question first.

That is the shift worth internalising. AI governance stopped being a compliance document this year and became an architectural decision. The organisations that treat it as the latter will still be moving fast in three years' time.

See what runtime governance looks like

Visioneer puts every AI agent behind a single controlled door — checked before it acts, escalated when it matters, stopped in under a second, and recorded permanently. Take a 30-minute walkthrough on one of your own workflows.

This article describes a published industry framework for general information. It is not legal or regulatory advice, and references to MAS and its publications do not imply endorsement or affiliation. Firms should confirm their own obligations with qualified advisers.