Skip to main content

Paths

Learn the stack in the order it makes sense.

12 GUIDED PATHS · 2 JURISDICTIONS

The short answer

The map shows everything at once, which is exactly wrong for learning. These paths are five or six stops each, in a deliberate order, and each one ends somewhere useful: knowing who issues what, knowing what can be enforced against you, or knowing how the preemption fight actually works.

Singapore

Path M1 · 6 stops

Four-Agency Map

Orient yourself: who issues what in Singapore AI governance, and what each instrument's legal weight is.

  1. 1

    IMDA: frameworks and testing ecosystem

    Guidance

    IMDA writes the Model AI Governance Framework family, know it as the framework agency, not a lawmaker.

  2. 2

    PDPC: binding data protection

    Binding

    PDPC administers the only binding economy-wide law in this stack, the PDPA.

  3. 3

    MAS: financial-sector regulation

    Binding, sectoral

    MAS issues binding notices and supervisory expectations for financial institutions.

  4. 4

    CSA: AI security guidance

    Guidance

    CSA owns the security layer, guidelines, companion guide, and the agentic addendum.

  5. 5

    Anchor instrument: MGF 2.0

    Guidance

    Nearly every later instrument builds on or references this 2020 framework.

  6. 6

    AI Verify: the assurance layer

    Guidance

    Government-built testing tooling connects the frameworks to evidence.

Path M4 · 8 stops

Agentic AI Governance (MGF for Agentic AI)

Deep-dive the world's first agentic AI governance framework, from agent anatomy to organisational accountability.

  1. 1

    Read the framework overview

    Guidance

    Start with what the framework is for: structured overview of agentic risks and best practices for deployers.

  2. 2

    Agent anatomy: the model

    Guidance

    The LLM/SLM/MLLM "brain", governance starts by knowing what you are governing.

  3. 3

    Agent anatomy: memory

    Guidance

    Memory makes agents stateful, and makes data governance materially harder.

  4. 4

    Multi-agent patterns

    Guidance

    Sequential, supervisor, swarm, the pattern determines where accountability can attach.

  5. 5

    Five risk types

    Guidance

    Erroneous, unauthorised, biased actions, data breaches, disruption, your risk-register skeleton.

  6. 6

    Dimension 1: assess and bound risks upfront

    Guidance

    Risk assessment plus design-time limits is the framework's first line of defence.

  7. 7

    Dimension 2: human accountability

    Guidance

    Approval checkpoints and audited oversight, adapted human-in-the-loop for the agentic era.

  8. 8

    Track v1.5

    Guidance

    The May 2026 update added case studies and multi-agent risk guidance, a living document to watch.

Path M5 · 8 stops

PDPA and Personal Data in AI

From statute to advisory guidelines: how personal data law applies across the AI and GenAI lifecycle.

  1. 1

    PDPA baseline

    Binding

    The binding Act, obligations apply to AI exactly as to any other processing.

  2. 2

    Consent

    Binding

    The default gateway for collection, use and disclosure.

  3. 3

    Exceptions without consent

    Binding

    First and Second Schedules, where training data can lawfully come from without consent.

  4. 4

    2024 AI advisory

    Guidance

    PDPC's interpretation for ML systems, business improvement and research exceptions operationalised.

  5. 5

    Anonymisation guidance

    Guidance

    Anonymised data is outside the PDPA but carries re-identification risk, the guidance sets the test.

  6. 6

    2026 GenAI finals

    Guidance

    The July 2026 guidelines cover development, deployment and post-deployment for GenAI.

  7. 7

    General notices are insufficient

    Consultation

    AI-specific notification is the new bar for training consent.

  8. 8

    Access and correction for GenAI

    Consultation

    Best practices for honouring individual requests against trained models, a hard problem with official expectations.

Path M6 · 8 stops

MAS and Financial-Sector AI

The financial-sector stack: binding TRM notices, FEAT expectations, Veritas methodology, and the pending AI risk guidelines.

  1. 1

    Binding: TRM Notices

    Binding, sectoral

    Statutory technology risk requirements, the floor for any FI deploying AI.

  2. 2

    RTO of 4 hours

    Binding, sectoral

    Recovery objectives constrain how critical AI services must be architected.

  3. 3

    FEAT Principles

    Supervisory expectation

    Fourteen principles that define MAS's fairness/ethics/accountability/transparency expectations.

  4. 4

    FEAT 1: no systematic disadvantage

    Supervisory expectation

    The fairness principle your models will be tested against first.

  5. 5

    Veritas

    Guidance

    The methodology and open-source toolkit for assessing FEAT conformance.

  6. 6

    Proposed AI Risk Management Guidelines

    Consultation

    Consultation closed 31 Jan 2026, not yet final, plan against the proposal, label it as such.

  7. 7

    MindForge toolkit

    Guidance

    The industry handbook aligned to the proposal, your implementation bridge.

  8. 8

    ABS GenAI guardrails

    Guidance

    Banking-specific GenAI guardrails that fed the MAS toolkit.

Path M8 · 8 stops

Crosswalks and Assurance

Proving it: testing tooling, certification standards, and official crosswalks to NIST and ISO frameworks.

  1. 1

    AI Verify framework

    Guidance

    Eleven internationally accepted principles, technical tests plus process checks.

  2. 2

    AI Verify toolkit

    Guidance

    Run the open-source toolkit; the report is your primary assurance artefact.

  3. 3

    Moonshot

    Guidance

    LLM benchmarking and red teaming to operationalise the GenAI testing dimensions.

  4. 4

    Global AI Assurance Pilot

    Guidance

    Where Singapore codified testing norms with international testers and deployers.

  5. 5

    Crosswalk: NIST AI RMF

    Guidance

    The official October 2023 mapping, GOVERN/MAP/MEASURE/MANAGE to AI Verify.

  6. 6

    Crosswalk: ISO/IEC 42001

    Guidance

    The June 2024 mapping of Annex A controls to AI Verify.

  7. 7

    SS ISO/IEC 42001

    Standard

    The certifiable standard, Annex ZA expressly names AI Verify as a voluntary alignment tool.

  8. 8

    MGF-GenAI: testing and assurance dimension

    Guidance

    The framework-level case for why third-party testing and common standards matter.

Path M11 · 8 stops

Capstone: Build a Governance Dossier

Assemble a complete organisational AI governance dossier: governance structure, risk assessments, data controls, security, and assurance evidence.

  1. 1

    Governance charter

    Guidance

    Adapt internal governance structures and measures, the dossier's first chapter.

  2. 2

    Self-assess with ISAGO

    Guidance

    Run the official self-assessment to baseline your alignment with MGF 2.0.

  3. 3

    Risk-rating method

    Guidance

    Use the severity-probability matrix to justify human-involvement decisions per use case.

  4. 4

    Responsibility allocation

    Guidance

    Chains of accountability across the value chain, name owners for every system.

  5. 5

    Documented assessments

    Guidance

    DPIA-style written records for data-source decisions, the artefact regulators ask for.

  6. 6

    Threat modelling record

    Guidance

    Security threat modelling and taint tracing outputs belong in the dossier.

  7. 7

    AI inventory

    Guidance

    A maintained inventory of AI systems and capabilities, every regime expects one.

  8. 8

    Evidence: process checks

    Guidance

    Documentary evidence validating processes, the difference between claimed and demonstrated governance.

United States

Path US1 · 6 stops

Who governs AI in Washington

Orient yourself: the agencies that matter, and the fact that none of them is enforcing an AI statute.

  1. 1

    Start with what does not exist

    Binding

    No comprehensive federal AI law. Everything else follows from that.

  2. 2

    The White House sets policy by executive order

    Binding, sectoral

    Orders direct the executive branch. They are not statutes.

  3. 3

    OMB turns orders into agency requirements

    Binding, sectoral

    Numbered memoranda, binding on agencies.

  4. 4

    NIST writes the voluntary framework

    Guidance

    Influential, and not law.

  5. 5

    The FTC is the closest thing to a general AI regulator

    Binding

    Section 5, no AI statute required.

  6. 6

    And the states carry most of the binding law

    Binding

    Which is why there is a separate Atlas for them.

Path US2 · 5 stops

The binding floor

What can actually be enforced against a private company in the United States today.

  1. 1

    FTC Act Section 5

    Binding

    Unfair or deceptive practices, technology neutral for over a century.

  2. 2

    Title VII

    Binding

    Discriminatory selection procedures, whoever or whatever produced the score.

  3. 3

    The ADA

    Binding

    Screen out risk and reasonable accommodation.

  4. 4

    ECOA and Regulation B

    Binding

    Specific and accurate principal reasons for adverse action.

  5. 5

    The TAKE IT DOWN Act

    Binding

    The one federal statute written for AI generated content.

Path US3 · 6 stops

Reading the executive orders in order

The chain from the January 2025 reset to the current frontier model order.

  1. 1

    EO 14148 clears the board

    Binding, sectoral

    Revokes EO 14110.

  2. 2

    EO 14179 sets the replacement policy

    Binding, sectoral

    And directs the action plan and the OMB rewrite.

  3. 3

    The AI Action Plan lays out the programme

    Guidance

    Three pillars, many recommendations, zero obligations.

  4. 4

    EO 14319 reaches private vendors

    Binding, sectoral

    Through procurement, which is the only route an order has.

  5. 5

    EO 14365 turns on the states

    Binding, sectoral

    Litigation task force, funding conditions, preemptive standards.

  6. 6

    EO 14409 is the current frontier model order

    Binding, sectoral

    Security first, voluntary, and expressly not a licensing regime.

Path US4 · 5 stops

If you sell AI to the federal government

The acquisition path, end to end.

  1. 1

    M-25-22 governs the buy

    Binding, sectoral

    Read it before you write the proposal.

  2. 2

    M-25-21 governs the use

    Binding, sectoral

    Your buyer must be able to answer for your system.

  3. 3

    High impact AI carries minimum practices

    Binding, sectoral

    And a directive to stop if they cannot be met.

  4. 4

    LLMs carry two extra contract terms

    Binding, sectoral

    Truth seeking and ideological neutrality.

  5. 5

    Your deployment becomes public

    Binding, sectoral

    Annual inventory with risk determinations.

Path US5 · 6 stops

The federal versus state fight

How Washington is trying to displace state AI law, and what has actually happened so far.

  1. 1
  2. 2

    The litigation route

    Binding, sectoral

    DOJ task force, announced January 2026.

  3. 3

    The naming route

    Binding, sectoral

    A Commerce list of onerous state laws, due March 2026, not published as of this dataset's verification date.

  4. 4

    The money route

    Binding, sectoral

    Broadband funding conditioned on not enforcing conflicting AI laws.

  5. 5

    The deception route

    Binding, sectoral

    A state law requiring altered outputs could itself breach the FTC Act.

  6. 6

    And the legislative route

    Consultation

    The March 2026 framework, which Congress has not enacted.

Path US6 · 5 stops

Frontier models, agents and security

The fastest moving part of the US stack, and the part with the least binding force.

  1. 1

    CAISI evaluates frontier models

    Guidance

    Voluntary, agreement based.

  2. 2

    The AI Agent Standards Initiative

    Guidance

    Launched February 2026.

  3. 3

    Covered frontier models under EO 14409

    Binding, sectoral

    Classified benchmarking, voluntary access.

  4. 4

    The explicit bar on licensing

    Binding, sectoral

    Read it before assuming a regime exists.

  5. 5

    CISA guidance on securing AI systems

    Guidance

    The voluntary security baseline.

Want the graded version

These paths are free reading. GAGE's AI Governance programme is the same material taught, practised and assessed, with a credential at the end.

See the AI Governance programme