Singapore has just provided one of the clearest regulatory signals yet for financial AI:
The model is not enough. The institution needs a governance layer around it.
On October 7, the Monetary Authority of Singapore finalized AI Risk Management Guidelines for financial institutions covering all forms of AI, including systems with increasing autonomy over decisions and execution. MAS plans additional guidance specifically addressing agentic AI in 2027.
The framework requires financial institutions to know where AI is deployed, assess the risk of each use, maintain human and cybersecurity controls, monitor systems as they change, and remain accountable for third-party AI.
If an outside model cannot be adequately controlled, MAS says the institution should consider limiting, suspending, or replacing it.
That has an important architectural implication:
The enterprise control layer needs to be independent of the model.
01 / Financial AI
Financial Agents Need Runtime Controls
Consider an agent connected to financial systems.
The model may supply intelligence.
But something else needs to determine:
Identity
Which agent is acting?
Authority
What can it do?
Financial limits
How much authority does it have?
Tools and data
What systems can it access?
Human oversight
What requires approval?
Runtime policy
What happens when behavior crosses a boundary?
Evidence
Can every consequential action be reconstructed?
Those controls cannot depend entirely on the AI policing itself.
02 / Financial AI
Why This Matters in the U.S.
U.S. regulators already have frameworks for model risk and third-party technology risk.
But federal banking regulators explicitly excluded generative and agentic AI from their revised 2026 model-risk guidance. Meanwhile, state supervisors have introduced an AI examination framework and federal agencies are revisiting third-party risk management.
That leaves a recognizable gap.
MAS is showing one way to fill it:
inventory → classify → authorize → monitor → oversee → replace if necessary.
The U.S. would not need a comprehensive AI law to adopt that logic. Banking supervisors could incorporate it into examinations, vendor-risk expectations, cybersecurity requirements, or sector-specific guidance.
03 / Financial AI
The Architecture That Follows
For agentic finance, we believe the stack increasingly needs to look like:
Financial Applications + Humans
↓
Agents + Workflows
↓
Identity + Authorization + Governance + Observability
↓
Models + Tools + Data + Financial Systems
The model can change.
The governance should not.
That makes model independence more than a technology preference. It becomes part of risk management.
As AI moves from answering financial questions to executing financial work, the critical question will not simply be:
“Which model are you running?”
It will be:
“What controls the agent when the model can act?”
That is the layer BlackBoxx is being built to address.
Primary sources
- Download the MAS AI Risk Management Guidelines — October 7, 2026 (PDF)
- MAS AI Risk Management Guidelines
- MAS announcement and implementation timetable
- Federal Reserve SR 26-2: Revised Guidance on Model Risk Management
- CSBS AI Supervisory Framework announcement
- OCC proposed third-party risk management guidance