Is the deployment approved, and under which boundaries?
Layer 02 — access
What can the model and its vendors touch?
Layer 03 — action
Who can stop it before the consequential action?
Radar
EU AI Act enforcement — live since 2 Aug 2026·PDPA GenAI guidelines — 20 Jul 2026·IMDA Agentic AI Framework v1.5 — Jun 2026·NRIC-as-authentication phase-out — 31 Dec 2026·NIST AI Agent standards — Aug 2026·
EU AI Act enforcement — live since 2 Aug 2026·PDPA GenAI guidelines — 20 Jul 2026·IMDA Agentic AI Framework v1.5 — Jun 2026·NRIC-as-authentication phase-out — 31 Dec 2026·NIST AI Agent standards — Aug 2026·
Four questions decide whether an AI system is safe to operate — not whether it is approved.
01
“Should we deploy — and under which boundaries?”
the impact × autonomy × access assessment
02
“How does personal data move through the model and its vendors?”
the data-flow map and AI-specific notification checklist
03
“What evidence proves a control actually works?”
the evidence register, control test and exception log
04
“How much autonomy is safe — and who can stop it?”
the tool-permission matrix and pre-deployment eval set
02 — The seat you sit in
Tell us which seat you sit in.
“Should we deploy, and under which boundaries?”
impact × autonomy × access assessment
The first working session ends with the boundaries written down and a named owner for each.
Five seats, one question each. Governance is not a paper, it's an answer to the question in your seat.
03 · The one principle
“
Approval is not control.
A committee can approve a system and still have no visibility into what it does tomorrow. For an agent that can update records, the real control point is not the launch meeting. It is the moment before a consequential action. We separate every approval into three layers: use-case, access, action. The question is never “is the AI approved?” It is: which action can it take, with which permission, and who can stop it?
Use-caseAccessAction
04 · Field notes
The moment data gets asked for is where governance begins.
Scene 01// desk
Front desk. The form asks for your NRIC. No reason given. The joint PDPC/CSA advisory says organisations must stop using NRIC as authentication by 31 Dec 2026.
Field note 01 — NRIC at the desk
Scene 02// clinic
The clinic's consent form is two pages. The AI-training consent is a checkbox at the bottom, already ticked.
Field note 02 — The checkbox at the bottom
Scene 03// food
The QR menu wants your phone number before it shows you the food.
Field note 03 — The menu that wants a phone number
When the control failed, and what proves it didn't.
06 · Closing
Start with the post you are not sure about.
We opened with a promise: governance is a set of daily decisions. Send us one — the deployment, the policy, the comment thread. We'll tell you the first decision to make.