ABCD Field manual — operational AI governance · 2026 · Singapore

Field manual — operational AI governance · 2026

AI governance is not a policy. It is a set of daily decisions.

ABCD works with teams across Singapore and Asia to deploy AI they can defend — from use-case approval to the moment before a consequential action.

No decks, no pitches. A working session.

Layer 01 — use-case
Is the deployment approved, and under which boundaries?
Layer 02 — access
What can the model and its vendors touch?
Layer 03 — action
Who can stop it before the consequential action?
Radar
EU AI Act enforcement — live since 2 Aug 2026· PDPA GenAI guidelines — 20 Jul 2026· IMDA Agentic AI Framework v1.5 — Jun 2026· NRIC-as-authentication phase-out — 31 Dec 2026· NIST AI Agent standards — Aug 2026·
Citations EU Commission PDPC IMDA NIST
01 — The questions we answer

Four questions decide whether an AI system is safe to operate — not whether it is approved.

01
“Should we deploy — and under which boundaries?”
the impact × autonomy × access assessment
02
“How does personal data move through the model and its vendors?”
the data-flow map and AI-specific notification checklist
03
“What evidence proves a control actually works?”
the evidence register, control test and exception log
04
“How much autonomy is safe — and who can stop it?”
the tool-permission matrix and pre-deployment eval set
02 — The seat you sit in

Tell us which seat you sit in.

“Should we deploy, and under which boundaries?”
impact × autonomy × access assessment
The first working session ends with the boundaries written down and a named owner for each.
Five seats, one question each. Governance is not a paper, it's an answer to the question in your seat.
03 · The one principle
Approval is not control.
A committee can approve a system and still have no visibility into what it does tomorrow. For an agent that can update records, the real control point is not the launch meeting. It is the moment before a consequential action. We separate every approval into three layers: use-case, access, action. The question is never “is the AI approved?” It is: which action can it take, with which permission, and who can stop it?
Use-case Access Action
04 · Field notes

The moment data gets asked for is where governance begins.

Scene 01// desk

Front desk. The form asks for your NRIC. No reason given. The joint PDPC/CSA advisory says organisations must stop using NRIC as authentication by 31 Dec 2026.

Field note 01 — NRIC at the desk
Scene 02// clinic

The clinic's consent form is two pages. The AI-training consent is a checkbox at the bottom, already ticked.

Field note 02 — The checkbox at the bottom
Scene 03// food

The QR menu wants your phone number before it shows you the food.

Field note 03 — The menu that wants a phone number

Sources: PDPC / CSA joint advisory, 2025 · PDPC GenAI advisory guidelines · PDPA, s.20 notification · EU AI Act, Regulation (EU) 2024/1689

We photograph the ask, never the data. One a week, on LinkedIn.

05 · What we operate

Five things, honestly scoped.

  1. AI readiness & governance
    Decisions, gates, ownership. For teams about to deploy.
  2. PDPA & AI compliance
    GenAI training, AI-specific notifications, retention, access & correction.
  3. Agentic AI governance
    Permissions, containment, stop switches, evidence registers.
  4. Boards & teams
    The workshop for leaders who must answer for AI.
  5. Incidents & assurance
    When the control failed, and what proves it didn't.
06 · Closing
Start with the post you are not sure about.

We opened with a promise: governance is a set of daily decisions. Send us one — the deployment, the policy, the comment thread. We'll tell you the first decision to make.

Replies within a working day.