top of page

Singapore’s financial industry has named the runtime governance gap in agentic AI. Here is how we close it.

  • Writer: Midships
    Midships
  • Jul 10
  • 2 min read

On 3 July, the Monetary Authority of Singapore, together with a group of financial institutions and FinTechs, published Safeguards for Agentic Finance at Runtime, or SAFR. It was developed under MAS’s BuildFin.ai initiative, and it sets out how AI agents in financial services should be authorised, how human oversight is triggered, and what is recorded at the point of every action.


It is an industry white paper, not a regulation. That is the right way to read it. But it matters, because it names something we have built Midships around.

Authenticated is not the same as behaving within purpose.


An AI agent can be fully authenticated. It can hold valid permissions. It can call only approved APIs. And it can still take an action that is inconsistent with the business purpose it was delegated to achieve.

Traditional IAM answers two questions.

 

  • Who is acting?

  • What are they allowed to access?

 

Autonomous AI introduces a third.


Should the agent take this action, right now, for this purpose?


That single question is why a new category exists. Identity and permissions were never designed to answer it.


SAFR describes the answer as a governance checkpoint that sits at the point of action, evaluates a proposed action before it executes, and retains a record for review and accountability. That is exactly the layer we built Icebreaker to be.


Icebreaker does not replace your identity platform. It works alongside it. IAM authenticates the agent and authorises access. Icebreaker is the runtime governance layer for autonomous AI. It continuously verifies that an agent’s behaviour stays aligned with the approved business purpose it was authorised to fulfil. Before an action executes, it evaluates a short, bounded set of questions:

 

  • Is the agent operating under an approved business purpose?

  • Does the session objective align with that purpose?

  • Do the planned intents stay within that objective?

  • Does this specific action still support those intents and comply with policy?

 

Only then is the action allowed, blocked, modified or escalated. Static authorisation becomes continuous runtime verification.


For regulated institutions, the value is in what this leaves behind. Audit logs after the event are not enough. You have to be able to show that an autonomous agent stayed within approved boundaries while it was deciding. Icebreaker records a tamper evident chain that ties every action back to an authenticated agent, an approved persona, an accountable human, an approved purpose, an approved objective and an approved intent. That is a verifiable line of accountability from delegation through to execution.


We think autonomous AI is the next major shift in enterprise security architecture. Identity stays the foundation. Runtime governance is the layer that has been missing. It is encouraging that the industry, convened by a regulator, has now put that gap in writing. The next step is giving enterprises the technology to close it.


Icebreaker is that technology. It is patent pending, it works with any IAM platform, and it is in pilot with financial and telecommunications organisations today.


Autonomy. Trusted.

bottom of page