In January and February 2026, Singapore and NIST launched initiatives specific to AI agents; the European Union already had the AI Act, a general regulation on AI that came into force in 2024. The initiatives have partially common objectives, but different statuses and mechanisms; no primary evidence suggests they are deliberately ignoring each other. According to the Cloud Security Alliance, 82% of surveyed organizations discovered at least one previously unknown AI agent in their environment during the previous year. Law arrives after the facts, as always with network technologies, but this time the gap is particularly wide, and agents are not passive tools.
The Essentials
- Singapore, NIST, and the EU launched three governance frameworks for AI agents simultaneously in January-February 2026, with no convergence mechanism planned.
- 82% of enterprises deployed autonomous agents without informing their security teams (Zylos Research, 2026): corporate practices become the de facto standard before any public norm.
- AI agents differ from previous systems on one decisive point: they act autonomously within an organization’s systems, make chained decisions, and can delegate to other agents, making traceability of responsibility extremely difficult.
- Differences between international frameworks may create a regulatory fragmentation risk.
- Gartner predicts that 40% of enterprise AI agent deployments will be abandoned or degraded by 2027 due to insufficient internal governance.
Agents Don’t Resemble the Tools They Replace
A classical AI system awaits a request, produces a response, stops. An autonomous agent receives an objective, plans steps to achieve it, executes actions in third-party systems—email, databases, payment interfaces, development tools—and can delegate sub-tasks to other agents. Some agents can chain actions with limited human supervision; the level of human validation depends, however, on design, permissions, and deployment controls.
Agents require complementary adaptations and controls of existing frameworks, rather than necessarily rendering these frameworks entirely unsuitable. Audit, traceability, and accountability rules were designed for deterministic systems: one input, one processing, one identifiable output. With agents, the causal chain between an initial human decision and a final action in a critical system may pass through multiple intermediate agents, each operating according to its own parameters. Responsibility in the event of error in the middle of the chain raises legal questions in the jurisdictions concerned.
According to the CSA, 82% of surveyed organizations discovered during the previous year at least one AI agent or workflow previously unknown to security or IT teams. In other technological domains, deployment of this magnitude without consulting IT security would be flagrant negligence. With AI agents, it has become commonplace, for a simple reason: these deployments are often made by business teams via SaaS platforms, without going through IT departments. Ease of access creates the asymmetry.
Three Rigorous Texts That Turn Away from Each Other
The IMDA framework, published on January 22, 2026, recommends governance practices, including technical controls and human supervision; it does not establish regulatory obligations. The framework recommends limiting agent powers, ensuring significant human accountability, and deploying technical controls; it does not create a universal obligation for logging, boundaries, and a kill switch for each agent. The framework invites organizations to assess the level of autonomy and agent access according to risks; it does not impose the binary classification described. This distinction is useful and absent from the other two texts.
The NIST initiative aims to promote industry standards, open protocols, and research on the security, identity, and interoperability of agents; it does not yet set the cited obligations. The NIST initiative follows the American tradition of voluntary standards, making it a best-practices guide rather than a binding framework. Its strength is its modularity: enterprises can adopt it partially, which favors rapid adoption, at the risk of cherry-picking that empties the text of substance.
The AI Act applies in stages: application of certain rules begins on August 2, 2026, while rules in Annex III relating to high-risk systems apply from December 2, 2027. For high-risk systems concerned, the AI Act notably imposes a conformity assessment procedure before market placing or putting into service, documentation, logs, and, in cases provided for, registration in the EU database. But the scope of the AI Act is principally defined by the roles, type, and intended use of systems, as well as their risk level; certain high-risk categories concern specific domains.
The texts and initiatives share certain governance themes, but their statuses, fields of application, and levels of detail differ strongly. An enterprise may simultaneously fall under several regimes depending on its activities, roles, and markets, but this must be determined case by case; the IMDA framework is voluntary. Regulatory fragmentation is already documented as a brake on growth in other domains; with AI agents, it arrives at a moment when practices have not yet hardened into habits impossible to correct.
Capture Before Governance: A Known Mechanism
Adam Becker, a researcher specializing in the relationship between technology and governance, documents a recurring mechanism in the history of network technologies: the optimism of technology promoters tends to systematically minimize systemic risks until practices are so entrenched that any substantial regulation encounters massive resistance. The promoters are not necessarily acting in bad faith; they sincerely believe in the technology they are deploying, but their evaluation horizon is that of the successful use case, not of cascading failure.
The figure published by the CSA illustrates this mechanism. The 82% of organizations surveyed that discovered at least one previously unknown AI agent in their environment does not establish regulatory circumvention. They experiment, find that it works for the intended use case, and scale up. Governance problems only appear later, when an agent acts unexpectedly in a critical system, when an audit reveals decisions impossible to trace, or when a security breach traces back to an agent no one remembers authorizing deployment of.
The competing reading of this diagnosis deserves to be taken seriously. For economists working on the effects of technological adoption—Philippe Aghion on Schumpeterian creative destruction, Carl Benedikt Frey on innovation cycles—governance that is too early and too constraining can slow a technological wave before it reaches its productive potential. Autonomous agents could represent exactly the productivity leap that developed economies have sought for two decades: constraining them in heavy compliance obligations before understanding their uses would be a symmetrical error to that of absent governance.
This tension is real. It does not, however, apply equally depending on the type of agent. An agent that automates inventory management in a warehouse presents very different risks from one that makes credit decisions or manages access to critical systems. The IMDA and AI Act provide for risk-sensitive approaches, but according to different mechanisms; the NIST initiative does not yet set a common formal classification of agents by type and risk level.
Governing an Actor That Acts Before Being Observed
The concentration of power on a single interface is already documented as a risk for large digital platforms. With agents, the concentration shifts: the interface remains visible, but decisions are made upstream, in layers of automation that neither the end user nor often the deploying organization sees in real time. Governing this layer requires adapted instruments.
The central technical problem is that of traceability of agent chains. Multi-agent architectures can increase the complexity of attribution of responsibility and require strengthened mechanisms for identity, authorization, and logging. The three frameworks recognize this problem. The AI Act imposes, for high-risk systems concerned, technical capacity for automatic recording of events; the IMDA and NIST frameworks propose or develop technical controls and voluntary standards. This technical gap is precisely what standardization work like that of NIST could fill if resources and timeline followed.
A second problem, less discussed, is that of cross-validation between agents. When an agent delegates a sub-task to another agent, the frameworks do not all specify the procedures for verifying authorizations between agents. This is a design flaw that transforms agent chains into potential vectors for privilege escalation; a malicious or misconfigured agent can instruct an agent with a wider scope to execute actions that the first would not have the right to initiate directly.
The Points That 2028 Will Settle or Leave Open
The 2027-2028 horizon is structuring for two converging reasons. First, from August 2, 2026, certain rules and certain application mechanisms will apply; complete deployment of main deadlines continues until August 2, 2028. Second, Gartner predicts that by 2027, 40% of enterprises will downgrade or disable autonomous AI agents due to governance gaps identified after production incidents.
Two trajectories are plausible at this horizon. In the first, regulatory fragmentation persists but major technology companies, which operate in all three jurisdictions, develop internal standards that de facto converge toward a minimum international norm. This is the GDPR scenario applied to agents: a demanding standard in a major jurisdiction creates a global floor level through capillarity. This trajectory has solid precedents, but it assumes that American companies accept being subject to obligations defined partly in Brussels and Singapore, which is far from assured.
In the second trajectory, the three frameworks remain parallel texts, each applying in its territory without coordination. Enterprises develop compliance practices compartmentalized according to jurisdiction of operation, with the costs and inconsistencies that implies. In this scenario, the actors who benefit most from the absence of convergence are large platforms that can absorb the cost of multiple compliance, to the detriment of smaller actors who cannot. Fragmented governance becomes a competitive advantage for incumbents.
A third scenario, less probable but not negligible, would be a convergence initiative led by an international organization—the OECD, which already produced principles on AI in 2019, or the G20 whose presidency regularly rotates toward countries whose technological interests diverge. For this convergence to occur, a triggering event would be needed: a cascading agent failure in a critical system, a major judicial decision in one of the three jurisdictions, or a diplomatic initiative led by an actor with an interest in harmonization. Singapore, whose framework is the most precise of the three and whose economic strategy relies on its capacity to be a reference jurisdiction for global technology companies, is potentially this actor.
What is certain: decisions made in 2026-2027 on the governance of autonomous agents will have lasting effects on societies’ capacity to exercise democratic control over systems that make increasingly consequential decisions. The question of who controls open standards was raised for information; it arises today for agents that act in information systems. The answers are not identical, but the lessons on capture of standards by dominant actors apply directly.
The Signals That Would Allow Resolution
Three indicators will show, by end of 2027, which trajectory we find ourselves on. The first is the existence or absence of a joint working group between Singapore’s IMDA, NIST, and the European Commission: formal technical meetings on standards compatibility would signal political will toward convergence; their absence would confirm assumed fragmentation. The second is the content of the first enforcement decisions of the AI Act: if European regulators adopt a strict interpretation of obligations for agents deployed by non-European enterprises operating in the EU, upward convergence pressure will be strong. The third is the behavior of major agent deployment platforms—Microsoft Copilot Studio, Google Agentspace, Salesforce Agentforce—each with their own internal standards: if they adopt the Singapore framework as reference, it means that the most precise and operational text prevails regardless of jurisdiction size.
The governance of autonomous agents requires coordination among actors whose interests, timelines, and instruments differ: engineers cannot solve it alone, nor can lawyers. At least two publicly-led initiatives explicitly devoted to AI agents existed in 2026: IMDA’s agential framework and NIST’s standards initiative. The issue now is whether these institutions will coordinate before corporate practices make convergence difficult.
Sources
- Singapore IMDA, Model AI Governance Framework for Generative AI, January 2026, https://www.imda.gov.sg
- NIST, AI Agent Standards Initiative, February 2026, https://www.nist.gov/artificial-intelligence
- European Regulation on Artificial Intelligence (AI Act), progressive application until August 2026, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- Zylos Research, AI Agent Governance & Compliance 2026, May 2026, https://zylos.ai/research/2026-05-01-ai-agent-governance-compliance-2026/
- Gartner, Enterprise AI Risk Survey 2026, Gartner Inc., 2026
- Adam Becker, work on technology and governance, https://www.adamkbecker.com
- OECD, Council Recommendation on Artificial Intelligence, 2019, https://oecd.ai/en/ai-principles