
When AI Starts Taking Action, What MAS’s GFF 2026 Address Means for Fund Managers
As financial institutions explore increasingly capable AI systems, the governance question is expanding from how AI produces outputs to how AI enabled systems may take actions.
On 11 September 2026, Monetary Authority of Singapore Managing Director Chia Der Jiun delivered a special address titled Building the Financial System of the Future, Trusted, Connected and Resilient, at the Global FinTech Fest 2026 in Mumbai. The address considered three technologies expected to shape financial services over the coming decade, artificial intelligence, tokenisation, and quantum computing. Chia identified AI as advancing and being adopted more rapidly than the other two, noting that tokenisation could take another few years to scale, while estimates place quantum computing five to ten years away from becoming powerful enough to threaten current encryption standards, even as he stressed the need to begin preparing for quantum resilience now. For fund managers and administrators, AI presents the more immediate governance question.
AI Governance Is Becoming More Structured
AI is already being applied across financial services. In his address, Chia cited applications including fraud detection, credit underwriting, risk management, regulatory compliance, marketing, customer service, and document processing. MAS has also issued draft Guidelines for AI Risk Management for public consultation. The proposed Guidelines set out supervisory expectations covering governance and risk management, together with AI lifecycle controls and capabilities, and they complement the AI Risk Management Handbooks developed with industry in 2025.
Chia described the relationship between the two in practical terms, the Guidelines establish the what, while the Handbooks provide examples of the how. This creates a more structured reference point for financial institutions considering how AI should be governed across its lifecycle.
From AI Outputs to AI Actions
A further development is the emergence of agentic AI. In July 2026, the Safeguards for Agentic Finance at Runtime white paper, generally known as SAFR, was published under the BuildFin.ai initiative. SAFR is an industry developed reference framework rather than regulatory guidance. It addresses runtime safeguards for agentic AI, including how an AI agent establishes its identity and authority, how proposed actions can be evaluated against applicable controls before execution, and how records can be maintained to support accountability and review.
The distinction is significant. Traditional uses of AI may involve generating information, analysis, or recommendations for a person to consider. Agentic systems can potentially go further by interacting with systems and taking actions within the authority given to them. As that capability develops, governance increasingly needs to consider not only the output of an AI system, but also the authority under which it operates and the controls surrounding any action it may take.
What This Could Mean for Fund Operations
For fund managers and administrators, the practical implications will depend on how AI is used and the materiality of the process involved. As an operational matter, firms may increasingly need to understand the following.
- Where AI is used within a process.
- What information it can access.
- Whether it generates information, recommends an action, or can initiate one.
- What authority has been given to it.
- Where human review or approval remains.
- How exceptions are identified and escalated.
- What records are retained.
These are not new MAS requirements for fund administration. They are operational questions that become increasingly relevant as the principles of AI governance are applied to processes supporting funds and investment structures. Potential areas for consideration could include fund accounting, reconciliations, AML and transaction monitoring, investor onboarding and servicing, regulatory reporting, document processing, and data management, depending on how AI is deployed within those activities.
The Third Party Dimension
There is another consideration for managers operating through outsourced service models. A financial institution may govern the AI tools used internally while also relying on administrators, compliance providers, technology vendors, and other third parties whose own systems and workflows may increasingly incorporate AI.
The MAS address did not prescribe specific AI due diligence requirements for fund administrators or other outsourced providers. However, as a matter of operational governance, managers may wish to understand where material AI use sits within outsourced processes and what controls apply around access, authority, human oversight, and record keeping. This becomes particularly relevant if AI moves beyond supporting staff and begins to influence or initiate operational actions.
Cyber Risk Is Evolving Alongside AI
The address also highlighted the changing cyber threat environment. Chia noted that the number of high severity Common Vulnerabilities and Exposures, or CVEs, had risen to approximately 2,200 this year, about six times the average of the preceding three years. He also cited CrowdStrike research reporting an 89 percent increase in AI enabled cyber attacks. Reported successful breaches, however, had not risen to the same extent. Chia pointed to model guardrails as one reason, and well implemented multi layered cyber defences as another, including authentication, patching, network segmentation, and monitoring. AI is therefore developing against a backdrop in which financial institutions are considering both how the technology can be deployed and how the risks surrounding increasingly capable systems should be controlled.
Beyond AI, Tokenisation and Quantum
AI was the principal focus of the address, but Chia also placed it within a longer term technology transition. He said tokenisation may take another few years to scale. Quantum computing is further out, with estimates suggesting five to ten years before quantum computers become powerful enough to threaten current encryption standards. Preparation, however, needs to begin earlier. He highlighted the need for financial institutions to identify their cryptographic assets and dependencies, assess vulnerabilities, and plan migration towards quantum resistant encryption. For firms responsible for long lived financial infrastructure and sensitive data, the point is particularly relevant, resilience planning often needs to begin well before a risk becomes immediate.
What to Watch
The draft AI Risk Management Guidelines remain under consultation, and the final Guidelines may differ from the current proposals. MAS is also working with law enforcement and the banking industry to test AI models using cross bank and public private data to improve the detection of suspicious accounts and transactions in near real time, with findings from this work expected by the end of 2026. The development of agentic AI will be another area to watch as financial institutions consider how increasingly autonomous systems can operate within appropriate boundaries.
The Broader Direction for Fund Managers
For fund managers and administrators, the broader direction is becoming clearer. AI governance is not only a technology question. As AI becomes more deeply embedded in financial processes, it increasingly intersects with operating governance, authority, accountability, controls, escalation, and evidence. Those principles are not new. The technology to which they must now be applied is.
Governance Ready Fund Operations
Auvene Operating Partners supports fund managers with operational governance across fund administration and fund operations, helping clients stay ready as AI becomes more deeply embedded in processes supporting funds and investment structures.
Visit auvenegroup.comThis article provided for general information only and does not constitute legal, regulatory, or other professional advice. Draft guidelines, consultations, and industry initiatives referred to above remain subject to development and change.






Leave a Reply