GAGE (Global Academy of Generative-AI Education) credential verification
★
Sample credential: this is what you will see
On a real credential, this banner is a live signature check: issued by GAGE, never altered. Everything below shows the exact layout with example scores.
Verified Completion Record
Agentic AI Governance: Applied Mastery
Issued to Sample Learner
The day every mastery assessment is passed
GovernanceSample
The GAGE seal. On a real credential it opens that learner’s living record; only GAGE can mint a code whose signature validates.
✓Scenario responses evaluated for applied judgment
Mastery Score
Example numbers, real formula
Continuous assessment (50%)
93%
Average of every topic exam best score
Mastery Exam (50%)
91%
Timed, open book, scenario based final exam
Mastery Score92%
Half earned topic by topic, half earned at the summit: a timed open book exam of applied judgment, or a rubric-graded capstone build. A real credential shows the learner’s true numbers, live; until the summit is passed, it says so plainly.
Competency map
Real topics, example scores
Taking the Controls
Welcome to Applied Conformance
You are building one document, not completing a course · The instrument is real, dated, and specific · Friction is a feature, not a defect
92%
What an Agent Actually Is
Three categories exist, not one blurry cloud of "AI." · The line that matters is talk versus act · The eight components are a diagnostic, not a checklist to satisfy
100%
Why Agentic Breaks Generative Governance
Outputs and actions are not degrees of the same thing; they are different categories of risk · Generative governance was built around a human checkpoint that agentic AI removes by default · The five negative outcomes in MGF v1.5 are all action-shaped, not content-shaped
83%
The Instrument
You now have a name, a date, and a page count for the thing this whole program answers to · It is guidance, not law · It is the first comprehensive national governance framework for agentic AI, not the only agentic instrument on earth
92%
Your AI Briefcase
An unfindable decision is functionally an undefended one · The AI Briefcase is one Claude project, not a metaphor · Three bins, one rule
100%
Choose Your Deployment
A deployment is one agent, one job, one population, one organization · The four-part fitness test exists to catch weak choices before they become expensive · Real and simulated deployments carry identical weight
92%
Reading Like a Practitioner
A regulatory claim without a status label is not yet a governance claim · An as-of date is what makes a claim checkable · Binding and voluntary are different axes from true and false, and both matter
83%
The Agent, Deconstructed
The Eight Components I
An agent is eight named components, not one black box · Model, instructions, and memory are the parts a simple LLM app already has · The model is the reasoning engine, not the agent
100%
The Parts That Make an Agent Act
Three components turn a brain into a body · A prediction and a tool call are different governance objects, even from the same reasoning · Tool risk lives in the permission, not the name
92%
The Safety Components
Controls is one component with three distinct jobs · Logging and Monitoring exists for three stated purposes, not one · These are v1.5 additions for a specific reason
100%
The Five Negative Outcomes
The framework names five negative outcomes, in this exact order and wording (MGF p.11): erroneous actions, unauthorised actions, biased or unfair actions, data breaches, and disruption to connected systems · Erroneous and unauthorised are opposite mistakes, not synonyms · Bias is visible only in aggregate
83%
Systemic Risk
Systemic risk is a multiplier, not a sixth outcome · Speed and volume are two separate hazards that usually travel together · Cascading effects are a chain; compounding effects are a loop
92%
The Instrument Landscape
The instrument landscape has four different kinds of authority on it, not one · Only one instrument on this shelf has teeth right now · IMDA's accurate claim is "first comprehensive national," not "only."
100%
Why Singapore's Framework in Ohio
There are two distinct reasons to adopt a governance framework: authority-based (a regulator with jurisdiction over you requires it) and convergence-based (independent institutions, working separately, converge on the same structural primitives) · A "reference implementation" is the most complete, most corroborated worked example of solving a problem, not the only legally correct one · The WEF "AI Agents in Action" white paper (November 2025) and the IMDA MGF v1.5 (May/June 2026), produced independently roughly two months apart, converge on autonomy as a first-class axis, scoped access as a precondition, graded human oversight, and multi-agent risk as its own category, while diverging on classification schemes and the provider/adopter split
92%
The Whole Framework, Worked
IMDA published a worked example, not a policy for you to copy · OpenClaw's five named concerns are a template for how to name your own · Dimension 1 bounds by environment, architecture, and access scope, before testing anything
83%
Dossier Workshop A: System Description
§A is the foundation, not the throat clearing · Joining is where drift surfaces · A derivation trail names four things, not two
100%
Capability and Autonomy
Action-Space
Action-space is the range of actions an agent can take, including the transactions it can execute, determined by its tools and their permissions · Instructions are a request. Tools and permissions are the actual boundary · Enumerate the widest case, not the typical case
92%
Who Decides the Next Step
Autonomy and action-space are two separate questions · Autonomy has exactly two named drivers · A small action-space can hide a large autonomy gap
100%
The Four Levels of Human Involvement
The framework names four levels, not a dial · Level 4 is not ungoverned · The trigger is the level
83%
Reversibility Analysis
Reversibility, not raw capability, decides where a checkpoint belongs · The three-tier scale is reversible, costly-reversible, and irreversible, and the middle tier is where organizations round down · Rate the real-world undo cost, not the ledger mechanics
92%
Risk Tiering in Practice
Three questions, scored per task type, produce the tier · Reversibility is the swing factor · A tier sets two things, not one
100%
Levels of Agency
Seven dimensions, scored together, produce the level · L0 is a zero baseline, not a sixth level · Governance depth is calibrated to level, not uniform
92%
The New Risk Factors
v1.5 added exactly two new risk factors, and both are about origin and structure, not capability · Third-party is a visibility problem, quoted exactly · System complexity is explicitly compounding, not additive
83%
Dossier Workshop B: Classification
§B answers a different question than §A · A tool is not an action · A justification and a counterfactual are different arguments
100%
Bounding by Design
Least Privilege for Agents
The framework's own instruction is nine words with three separate design decisions inside it · Read versus write is the sharpest cut you can make · Prefer a wall over a request
92%
Agent Identity
Identity comes before permission · A well-formed agent identity has four required properties · Authorisation adds two more properties on top
100%
SOP-Wrapped Workflows
The framework names two instruction styles, not one · A well-built SOP reduces both likelihood and impact · "Constrained to follow" means enforced, not requested
83%
The Off Switch
The off switch is mechanisms and procedures, plural, decided in advance · There are at least three offline states, not one · Graceful degradation keeps an agent useful while it sheds risky authority
92%
Bounding a Bank's Agent
Three limits, named precisely, not one general posture of caution · "Decision support only" is a precise design claim, not a soft phrase · This topic composes Topics 3.1 to 3.4 into one real deployment
100%
Containing Third-Party Agents
"Enterprise AI invariably includes multiple third-party SaaS agentic platforms." · Vendor validation is real but bounded · MSD's default is restriction, not permission
92%
When Not to Deploy
Exclusion is the sixth bounding lever, and the only one that says no instead of narrower · The framework itself reaches this conclusion, in exact, unhedged language, for a real case · No single risk factor excludes a task type; the combination does
83%
Dossier Workshop C: Bounding Measures
§C is where description becomes enforcement · A ceiling is not the same as a permission level · The deterministic-bounding preference is a design choice, not a formality
100%
Meaningful Human Accountability
The Agentic Value Chain
The value chain has five stages, and your organization may occupy more than one of them · Platform provider and system provider are different roles with different duties, on purpose · "We licensed the technology" answers one question, not every question
92%
Accountability Inside the Org
Accountability is allocated, not assumed · Four different jobs: appropriateness, risk advice, build, and review · Ownership sits above the build
100%
Checkpoint Design
A checkpoint is a pre-execution gate, not a post-execution log · Four triggers, memorized, are your placement test · Stakes and reversibility are independent axes, not one score
83%
Automation Bias
A human occupying a checkpoint is not the same as a human exercising judgment at it · Automation bias is precisely defined: "the tendency to over-trust an automated system, especially when it has performed reliably in the past" (MGF p.25) · The framework names two specific, measurable metrics: human override rate and human response time (MGF p.30)
92%
Approvals in a Coding Agent
Five actions, five different rules, not one blanket policy · "No approval required" is a governance decision, not a governance gap · A checkpoint a human cannot genuinely evaluate is not a functioning checkpoint
100%
Approvals in High-Stakes Hiring
Two checkpoints, not one, and neither at the wrong end · "Approve, modify, or reject" beats a binary yes or no · Explainable outputs are what make a checkpoint functional, not just legally defensible
92%
Oversight at Agent Speed
Continuous human review does not scale to agent speed, and the framework says so directly · Graduated oversight has an exact source and an exact definition · The four levels of human involvement are dials, not one setting
83%
Dossier Workshop D: Accountability Map
§D is where accountability stops being a name and starts being a structure · "Meaningfully" is the operative word in the framework's own dimension name · The value chain has five stages, and one organization can hold several of them
100%
Technical Controls and Threat Modeling
The Control Typology
A control is either enforced by the system or requested of the model, and those are two different kinds of thing · The MGF's own wording is the standard to cite · Structural is preferred for higher-risk actions, but it is not universally correct
92%
Three Layers of Threat
A cumulation is an addition, not a swap · Layer 1 predates AI and does not care that you added a model · Layer 2 belongs to the model, not the agent
100%
Rogue Actions and Data Disclosure
Two named concerns, not fifteen unrelated threats · Rogue actions have two named pathways · Impact directly correlates with capability
83%
The OWASP Threat Map I: Eight Ways an Agent Turns Against You
The taxonomy exists so your threat model is complete, not so you can recite fifteen names · T1, memory poisoning, treats memory as an input channel · T2, tool misuse, happens inside authorized permission
92%
The OWASP Threat Map II
T9 through T15 attack the seams where an agent has company · The taxonomy belongs to OWASP, adopted by the CSA · T9, identity spoofing and impersonation, defeats systems that trust a presented identity without robust verification
100%
Protocol-Layer Threats
The confused deputy is the root cause underneath most MCP threats · MCP's six named threats are specific, not synonyms for prompt injection · Dynamic tool discovery is MCP's power and its exposure in the same feature
92%
Taint Tracing
Taint tracing follows data, not intentions · Untrusted in equals tainted from that point forward · Isolation, not deletion, is the prescribed response
83%
Controls in the Wild
"We have guardrails" is not a classification · Structural controls hold when the model is wrong; model based controls hold in proportion to how reliably a judgment is made correctly · The right control type depends on whether the underlying risk can be fully specified in advance
100%
Dossier Workshop E, Control Architecture and Threat Model
A control with no derivation trail is decoration · An untested control is a claim, not a control · The primary names three control types, not one
92%
Testing and Red-Teaming
What to Test
Old testing practices are a foundation, not a substitute · Four things to test for new agentic risk, exact primary wording: overall task execution, policy compliance, tool calling, robustness · Test the workflow, not just the final answer
100%
Build the Test Environment Before You Trust a Single Score
Realism has two independent levers: data and environment · "Beyond the final output" is the instruction that creates step-level logging as a discipline · One symptom can hide multiple causes
83%
Red Teaming an Agent Starts With Its Use Case, Not a Generic Checklist
Attack design starts from the use case, not a generic checklist · Indirect prompt injection is the workhorse attack because it is a delivery mechanism, not a single threat · The three-step method is repeatable for any agent
92%
Probing Data Boundaries
A direct refusal is not proof a boundary holds · Test the whole matrix, not the cells that feel risky · Helpfulness is the mechanism, not a side effect
100%
Rigor Metadata
"It passed" is a conclusion with its evidence removed · N answers "how much," not "how good." · A clean run proves less than it feels like it proves
92%
Testing What You Did Not Build
Module 5's internals-based tools have a wall · Red-teaming shifts from exploratory to targeted at the vendor boundary · The Shared Responsibility Model names who owns which failure
83%
Pass, Fail, or Accept
There are three outcomes, not two · A threshold set after the result is known is not a threshold · Residual risk is specific, not vague
100%
Dossier Workshop F, Test Plan and Results
A number with no threshold derivation is a decoration, not evidence · Rigor metadata is what makes a result checkable · The three required metrics have exact primary wording
92%
Rollout, Monitoring, and Incident Response
Ship the Agent in Stages, Never All at Once
Gradual rollout has three named levers, not one · A real phase one is structurally incapable of certain actions, not just smaller · Phase one is working time, not waiting time
100%
Watching an Agent Work
Watching is a named, first-class component of an agent, not an afterthought · A monitoring pipeline has to serve three different purposes · Log actions, decisions and reasoning, and cross-component interactions, not just outputs
83%
Change Management
Small changes cascade in agentic systems more than they do in ordinary software · There are exactly four named trigger categories: technical, environmental, performance, and regulatory · Review depth should match risk, not the size of the code diff
92%
Incident Severity
An agent's most dangerous failures often leave the service perfectly available · The five negative outcomes name the shape of harm, not its size · Occurred versus contained is the first fork, and it matters most
100%
The Binding Clocks
Two numbers, not two philosophies · The PDPA clock does not start at the breach · The MAS clock does not wait for understanding
92%
Pre-Drafted Notifications
Draft the notice before you need it, not during · A notification matrix has exactly four required columns · The clock's trigger event is not the breach itself
83%
The Enterprise Control Plane
At enterprise scale, "the agent" stops being a governable unit unless it has its own identity · The CSA Addendum names five elements of the enterprise control plane, and they build on each other in order · A scoped, short-lived token limits damage even after a successful attack
100%
After the Incident
Three evidence sources, three different questions · A usable log is comprehensive, tamper-evident, attributable, and available · The memory snapshot is a deliberately dual-purpose control
92%
Dossier Workshop G, Operations
Section G is an operations plan, not a philosophy statement · Rollout gates need matching rollback criteria, and every rollback criterion needs a named control-plane mechanism · Monitoring should reuse section F's own metrics
100%
Multi-Agent Governance
The Three Patterns
Three names, exact primary wording, memorize them · "Multi-agent" alone is not a governance-ready description · Sequential concentrates compounding, silent error
83%
Agent Sprawl
You cannot govern an agent you do not know exists · The primary names three specific consequences, not a vague warning · Agent sprawl grows faster than earlier software sprawl did
92%
When Agents Work Together and Everything Goes Wrong Anyway
"Collaborative failures" is one heading covering three distinct mechanisms · Every agent can be individually correct and the system can still fail · Miscoordination is an information gap between agents that want the same thing
100%
Emergent Behaviour
The primary's exact wording, memorize it · Emergent behaviour belongs to no single agent · Multi-agent emergent behaviour is not the same phenomenon as single-model emergent capability
92%
Multi-Agent Controls
Individually bounded agents are not a bounded system · The MGF gives you two worked examples, not a menu · A schema turns ambiguous text into unambiguous data
83%
Attacks on the Collective
The collective has its own attack surface, separate from any single agent's · T13 is a state; T14 is a mechanism · Cross-Agent Privilege Escalation (Rehberger, September 2025) is real, documented, and already happened in production tooling
100%
Patterns in Production
The framework has no Module 8 case study, and saying it does is a defect, not a shortcut · A sequential chain's risk concentrates at its seams; a supervisor pattern's risk concentrates in one coordinating judgment · List only the controls the evidence actually documents, never the controls a well-run version of the system probably has
92%
Dossier Workshop H, Multi-Agent Addendum
Section H opens with a precise, checkable claim: exactly how many agents your deployment has, and the specific independent decision each one makes · The test for "is this a second agent" is independent decision authority over the next action, not the number of processing stages, not what your internal documentation happens to call a component · A single-agent N/A is a claim, not an absence of work
100%
End-User Responsibility
Telling Users the Truth
Human accountability extends to the user, not just the organisation · There are two archetypes of end user, and they need different things · Five elements make a complete transparency disclosure
83%
Content Provenance
Disclosure of an agent's presence and provenance of specific content are different obligations · The MGF already requires point-of-interaction disclosure, not a one-time notice · A complete provenance label answers four questions: origin, review status, data basis and date, and confidence
92%
Escalation and Recourse
The primary text names two distinct failure conditions in one sentence · Triage by lane before triage by queue · A human touchpoint is only meaningful if the reviewer has genuine authority, capacity, and information to actually change the outcome
100%
Tradecraft Preservation
Tradecraft and business continuity is the newest line in the primary framework, not an instructor's invention · Assistance and substitution are not the same intervention · Entry-level tasks are training grounds because the task and the learning are the same activity
92%
Users as Governors
The Ant International case study describes a third relationship between end users and agents · The primary text's three mechanisms each do a distinct job · Built-in verification checks execution, not intent
83%
Manipulating the Human
T10 and T15 are the two named threats in CSA's fifteen-threat taxonomy that target the human directly · T10 attacks the checkpoint mechanism · T15 attacks earned trust in the agent's output
100%
Disclosure That Holds Up
A regulator-convened working group of practicing lawyers, not a consumer advocate, wrote the caution this topic teaches · Disclosure and disclaimer are not synonyms · Overstated reliability plus a broad-sweeping disclaimer is the specific trap, not disclaimers in general
92%
Dossier Workshop I, Disclosure Package
Section I is written for a user who will never read the rest of this dossier; every fact they need has to live on the page they actually see, not only in a document written for a reviewer · The template names four required fields, identity and authority and data access, content provenance, user responsibilities and escalation paths, and a complaint channel with an SLA, plus a training and tradecraft plan; this topic assembles them from Topics 9.1 through 9.4 rather than re-deriving them · Two conditional rows belong in a complete section I for the deployments that need them: a Users as Governors addendum where end users can shape the agent's own instructions, and a manipulation-resistance check run against the finished draft rather than written into it as a field
100%
The Law and the Regulators
The Binding Spine
An instrument's tone tells you nothing about its legal force · PDPA 2012 Part 6A is the one row in this entire perimeter that every organisation touching personal data must treat as genuinely binding, regardless of sector · The MGF's "non binding, living document" self description is a design choice, not a weakness
83%
MAS and the Agent
MAS confirmed, in a written parliamentary reply for the 5 August 2026 sitting, that its proposed AI Risk Management Guidelines apply to all AI use cases by financial institutions, including agentic AI · The Guidelines were, on that same date, still proposed and not yet finalised · "Binding rules" is not the primary source's own characterisation
92%
The FS Toolkits
MAS's 5 August 2026 reply describes SAFR as "a potential approach to how agent actions are authorised, how human oversight is activated, and what is recorded at the point of every consequential decision." · SAFR is industry-led and voluntary as of that date, not a MAS mandate · Project MindForge produced an AI Risk Management Toolkit for financial institutions
100%
The Security Reference
CSA's own text states the Securing Agentic AI Addendum is issued "for informational purposes only and is not mandatory, prescriptive nor exhaustive" · Voluntary does not mean safe to ignore, but the reason differs from the AIRG's reason · The Addendum is designed to be read alongside, not instead of, CSA's October 2024 Guidelines and Companion Guide
92%
Who Pays When the Agent Errs I
The IMDA legal-responsibility paper names seven value-chain actor archetypes, model developers, tooling providers, platform providers, system providers, deployers, end users, third parties, described as "helpful archetypes rather than watertight legal definitions." · The Annex's nine-row "Working Document on Actors in the Agentic AI Value Chain" (pp.33 to 36) adds orchestration layer provider and orchestration layer operator, and maps each actor to what it controls, its plausible errors, and the laws that could apply · The tooling-provider row names MCP errors as a distinct new failure category, specifically authorisation errors violating the principle of least privilege, alongside more familiar API errors
83%
Who Pays When the Agent Errs II
The Spandeck test is the gate every negligence claim has to pass through first · Proximity, not mere technical involvement, decides who is close enough to owe a duty · Quoine v B2C2 gives Singapore its clearest doctrine on knowledge and intention for automated systems, and its clearest open question
100%
Who Pays When the Agent Errs III
Fault based liability can fail even when nobody was at fault · Strict liability is a different question, not a stricter version of the same question · Rylands v Fletcher is a contested analogy, not settled doctrine
92%
The World Beyond Singapore
IMDA's framework is your spine, not your ceiling · The EU AI Act's high-risk obligations, including Articles 14 and 15, have a real but moving deadline · Article 14 wants a real human checkpoint with a working stop mechanism
100%
Dossier Workshop J, Regulatory Exposure Statement
A regulatory exposure statement lists what applies to you, not everything that exists · BINDING and ESTABLISHED are different questions · The five question test from Topic 10.1 is your working tool, not a one time lesson
83%
The Capstone: Deploy and Defend
Assembling the Dossier
Assembling is integration and reconciliation, never stapling · Contradictions between honestly written sections are structurally guaranteed, not a personal failure · Cross-section contradictions cluster into four shapes
92%
Derivation Trails
A derivation trail has four working parts, not one · The counterfactual is the part most learners skip and the part that does the most work · The strictest-sounding control is not automatically the right one
100%
Currency Pass
A finished dossier is not a finished object · The ESTABLISHED / EMERGING / SPECULATIVE method from Topic 0.7 is not a Module 0 exercise you outgrow; it is the tool this entire topic asks you to apply exhaustively, one more time, to a document you already believe is finished · A claim goes stale for one of three reasons: the instrument itself changed, your deployment changed, or the claim was never dated in the first place, which makes it unfalsifiable from the day it was written
92%
Know Your Attacker
There is no single attacker · Every attack lands as one of five negative outcomes · The three-layer threat cumulation is where technical attacks originate
83%
The Defense Method
The defense method has exactly three moves, applied in order to every finding: respond with evidence, concede what is actually true, and state a disposition · An evidence response names a specific dossier section and artifact, following the dossier template's own worked derivation example · An honest concession states, in one sentence, exactly what is and is not true about a finding, avoiding both denial dressed as defense and over-conceding a finding your own evidence actually answers
100%
Mock Defense I
A findings report is raw material, not a verdict · Triage has three buckets and each has one hard rule · Restate before you judge
92%
Mock Defense II
A round-one triage into Fixed, Accepted, and Deferred is a set of promises · "Hardened" means evidence a fix closes the exact original gap, not a description of a change · An accepted-risk rationale that survived round one is not automatically strong enough for round two; it needs new evidence, a tighter residual-risk bound, or an honest reclassification, not a restatement
100%
The Defense and the Living Dossier
A passing score certifies a snapshot, not a permanent state · The instruments you cite move fast, and the pace is documented, not a feeling · Section K is the only forward-looking section in the entire dossier
83%
Ask about this credential
Try it right now. Answers come only from the real program topics a completed credential carries; this is the exact tool an employer gets.
On a real credential the answers narrow to the topics that specific learner passed, with their scores.
Certificate Hash (SHA-256)
sample-credential-no-real-record; a real hash is unique, signed, and verifiable
Free account, no card. The first 7 topics are open.
Demonstration record, shown so anyone can see and test what a finished GAGE credential looks like before earning one. The program, its modules and its topic titles are the real shipped course. The learner and the scores are illustrative and describe no actual person. A credential earned on GAGE carries a signed, permanent verification link that resolves to that learner’s own record. Verify a real credential.