The landscape of business technology is rapidly evolving, with Artificial Intelligence (AI) moving beyond analytical tasks to actively executing operations. For small and medium-sized enterprises (SMEs) in Malaysia and Singapore, this shift presents both immense opportunities and significant challenges, particularly concerning trust. As AI agents begin to book appointments, answer complex queries, and even facilitate transactions, the question of how to ensure their actions are reliable, accountable, and secure becomes paramount. This is where robust governance frameworks become indispensable, transforming AI agents from mere tools into trustworthy partners.
The Rise of Agentic AI and the Imperative for Trust
For years, AI has been a powerful assistant, crunching data and offering insights. Now, we are witnessing the emergence of 'agentic AI' – systems capable of understanding context, making decisions, and taking autonomous actions. From automating customer service to managing inventory, these agents promise unprecedented efficiency for SMEs. However, with this increased autonomy comes a critical need for trust. How can a business confidently delegate tasks to an AI agent if there isn't a clear understanding of its decision-making process, its boundaries, or its accountability? This growing imperative for governance has been recognised at the highest levels of finance.
SAFR: A Blueprint for Governed AI Actions
On 3 July 2026, the Monetary Authority of Singapore (MAS) published a landmark industry white paper, "Safeguards for Agentic Finance at Runtime" (SAFR), version 1.0. Developed jointly under MAS' BuildFin.ai initiative with leading financial institutions including Ant International, Circle, HSBC, J.P. Morgan Chase, Manulife, Mastercard, OCBC, and Visa, SAFR provides a critical industry reference for governing AI agents. While explicitly stating it does not constitute regulatory guidance or supervisory expectations, SAFR defines essential governance checkpoints designed to verify and record an AI agent's proposed actions before execution. Its core principles include policy-bound execution, real-time validation, auditability, and interoperability – all crucial for building a trustworthy AI ecosystem.
Deconstructing SAFR's Governance Framework for SMEs
SAFR introduces a comprehensive framework with four runtime components that evaluate every proposed action by an AI agent, resolving it to one of four clear dispositions. Understanding these components and dispositions is vital for any SME looking to integrate agentic AI responsibly:
- Agent Identity: This component establishes who the AI agent is and confirms its authorised role. Just as an employee has an ID and job description, an AI agent needs a verified identity to ensure it's operating within its designated capacity and permissions.
- Controls Repository: Think of this as the rulebook for the AI agent. It contains all the policies, rules, and constraints that dictate what the agent can and cannot do. This ensures the AI operates within predefined ethical, legal, and operational boundaries.
- Disposition Engine: This is the decision-making core. It takes the proposed action, checks the Agent Identity and Controls Repository, and then determines the appropriate course of action based on the defined rules and context.
- Audit Log: Every action, every decision, and every interaction by the AI agent is meticulously recorded here. This provides an immutable record, essential for transparency, accountability, and post-event analysis – much like a flight recorder for an aircraft.
The Disposition Engine then resolves each proposed action into one of four clear outcomes:
- Deny: The agent's proposed action is outright rejected because it violates a rule, exceeds its authority, or is deemed unsafe. For an SME, this could mean an AI automatically denying an unauthorised transaction attempt.
- Escalate: The proposed action is complex, unusual, or requires human judgment or approval. The AI agent flags it for a human operator to review and decide. This is crucial for handling nuanced customer queries or high-stakes financial decisions.
- Auto-Execute: The proposed action is routine, fully compliant with all rules, and within the agent's authority. The AI agent proceeds with the action automatically, such as processing a standard booking or retrieving common information.
- Observe: The action is allowed to proceed, but it is flagged for monitoring. This might be used for new types of interactions, actions with potential learning value, or to track performance and compliance over time without immediate intervention.
Translating SAFR Principles to SME AI Adoption
While SAFR's initial use cases cited include agent-assisted payments/treasury, wealth-management/advisory review, and client engagement within finance, its underlying principles are universally applicable to any SME adopting AI. Policy-bound execution ensures AI actions align with business objectives and ethical standards. Real-time validation means decisions are checked against current rules, not outdated ones. Auditability provides a transparent trail for every AI interaction, fostering trust and enabling easy troubleshooting. Finally, interoperability ensures AI agents can seamlessly interact with existing systems like CRM or API-driven services, creating a cohesive operational environment.
Building Trust with AI in Everyday Business Operations
For SMEs, the lesson from SAFR is clear: trust in AI is not inherent; it is engineered through robust governance. When integrating AI into operations, businesses must prioritise systems that offer transparent decision-making, clear operational boundaries, and comprehensive accountability. For instance, an AI call-answering service like ErzyCall, when designed with SAFR-like principles, doesn't just provide answers; it ensures every interaction is logged, complex issues are escalated to a human agent, and its actions are always within predefined boundaries, fostering deep customer trust. This approach moves beyond simply automating tasks to building a reliable, ethical AI workforce that complements human efforts.
Frequently Asked Questions
What is SAFR and why is it important for SMEs?
SAFR, or "Safeguards for Agentic Finance at Runtime," is an industry white paper published by the Monetary Authority of Singapore (MAS) on 3 July 2026. It provides a framework for governing AI agents by defining checkpoints that verify and record their proposed actions. For SMEs, it's important because it offers a blueprint for how to adopt AI agents responsibly, ensuring they are trustworthy, accountable, and operate within defined rules, even if not directly in the financial sector.
How do SAFR's dispositions apply to my business's AI tools?
SAFR's four dispositions – Deny, Escalate, Auto-Execute, and Observe – are practical guidelines for managing AI agent actions. For your business, this means designing AI tools that can automatically block unauthorised requests (Deny), flag unusual customer queries for human review (Escalate), handle routine tasks without intervention (Auto-Execute), and monitor new types of interactions for learning and compliance (Observe). This ensures controlled and transparent AI operations.
Does SAFR mean AI agents can't be trusted?
Quite the opposite. SAFR's framework is specifically designed to build and enhance trust in AI agents. By establishing clear identities, rules, decision-making processes, and audit trails, SAFR provides the necessary governance to make AI agents reliable and accountable. It acknowledges the increasing autonomy of AI and offers a structured approach to ensure their actions are verifiable, safe, and aligned with business policies, thereby fostering greater confidence in their deployment.



