
There is a common assumption that AI regulation arrives as a single statute, and that firms should wait for it before committing to an operating model. Across the UAE, Singapore and India, that is not what is happening.
Each has taken a different route to AI governance without passing a horizontal AI Act – extending existing law, supervisory machinery and institutional structures rather than waiting for a single rulebook. The result is more defined than firms may expect. Governance expectations are already emerging through data protection, financial services supervision, technology risk and institutional accountability frameworks that organisations already understand.

What differs between the three is where accountability has been placed, and that placement shapes the controls organisations need to build.
Three Markets. One Emerging Model.
None of these three has followed the European route of a single comprehensive AI statute. Each has instead extended existing law and supervisory machinery into AI, while building institutional capacity alongside it. The result is a layered picture rather than a single rulebook.
For a firm operating across all three, this can be an advantage. Layered regimes reward organisations that can demonstrate a coherent internal control environment, because supervisors are increasingly interested not simply in whether a policy exists, but in whether governance, accountability and controls operate in practice.
A firm with genuine governance can adapt one operating model to three regimes. A firm without one cannot compensate with more policies.
The UAE: Consolidating AI Governance
The UAE’s AI governance framework has been built through institutional design as much as through rulemaking – and 2026 has been a significant year for both.
On 14 June 2026, the UAE announced the establishment of the Artificial Intelligence and Data Authority – a new national body intended to unify public data, artificial intelligence and digital-government capabilities within a single national ecosystem. Its mandate includes developing national AI strategy, setting standards and guidelines for AI and data management, and ensuring compliance across federal entities. The establishment of a national body signals a move towards more coherent national oversight and gives firms a clearer institutional reference point for AI governance.

Alongside that sit several instruments already in force. The federal data protection law governs personal data in AI systems. In the DIFC, Regulation 10 addresses autonomous and semi-autonomous systems, with full enforcement from January 2026 – which matters because it applies within a separate common-law jurisdiction with its own regulator, as licensing does. The UAE Charter for the Development and Use of AI sets out the principles. Abu Dhabi maintains its own governance arrangements. Above all of it sits the National Strategy for Artificial Intelligence 2031.
There is also a distinctly UAE feature worth noting. From January 2026, the National AI System holds an advisory position within the Cabinet and the Ministerial Development Council, and on the boards of all federal entities and government-owned companies. The direction is clear – AI is being positioned within the architecture of institutional decision-making, not simply as a technology capability.
That institutional approach is complemented by a growing focus on AI infrastructure and sovereignty. The UAE Cyber Security Council, e& UAE and Open Innovation AI launched the UAE Sovereign AI Platform at ISNR 2026 in May – an initiative designed primarily for national security, classified government environments and mission-critical sectors. The platform enables deployment of AI within fully UAE-controlled infrastructure. For regulated firms in strategic industries, the practical question of where a model runs, what data it can access and under whose control is therefore beginning to have a tangible answer.
Singapore: AI Governance at the Point of Execution
Singapore has taken a different route – and for financial institutions it is the most operationally demanding of the three.
The Monetary Authority of Singapore (MAS) has stayed with a principles-based supervisory approach applied across all AI use cases. In November 2025 it published a consultation on Guidelines on Artificial Intelligence Risk Management, setting expectations for board and senior management oversight, risk management frameworks and controls across the AI lifecycle. In March 2026 it published an AI Risk Management Toolkit for the sector, developed with a consortium of financial institutions – a collaborative instrument rather than an imposed one.
A more significant development came in July 2026, when MAS published an information paper proposing SAFR – Safeguards for Agentic Finance at Runtime — as an approach to governing AI agents. The framing repays attention. SAFR organises itself around three questions: what the system is authorised to do, how a proposed action is assessed at runtime before it executes, and what records are retained so that outcomes which diverge from intent can be reviewed and remediated.
Those are control questions, not technology questions. Authorisation, pre-execution assessment and an audit trail sufficient to reconstruct a decision are precisely what a first line of defence is designed to provide. What has changed is the timescale. Supervision is moving from periodic review of a system to assessment of an action at the moment it occurs.
As of August 2026, MAS has confirmed that agentic AI falls within the scope of its broader AI risk-management expectations for financial institutions. SAFR provides a practical framework for translating those expectations into real-time controls for AI agents. Singapore is, on current evidence, among the first major financial regulators to bring agentic AI explicitly into the supervisory conversation.
The question is therefore no longer simply whether an organisation has an AI governance framework. It is whether the framework can operate at the point an AI system makes or initiates a decision.
India: The Framework Is Voluntary. The Obligations Are Not
India published its AI Governance Guidelines on 15 February 2026, immediately ahead of the India AI Impact Summit,following work begun in mid-2025 and a substantial public consultation process.
The guidelines are voluntary and principles-based, structured in four parts covering governing principles, institutional architecture, an action plan and sector-specific guidance. Seven principles run through them: Trust is the Foundation, People First, Innovation over Restraint, Fairness & Equity, Accountability, Understandable by Design, and Safety, Resilience & Sustainability. India has explicitly preferred to adapt existing law rather than legislate a dedicated horizontal AI act.
Institutional architecture accompanies the principles – an AI Governance Group, a Technology and Policy Expert Committee, and an AI Safety Institute. This is the same instinct visible in the UAE: build the body that can supervise, and let the detail develop through it. It would be a misstep to interpret ‘voluntary’ as ‘no obligations’. India’s Digital Personal Data Protection framework is also relevant to AI systems that process personal data, including the lawful basis and consent requirements that will govern such processing as the framework comes into force. The amended IT Rules, which came into force on 20 February 2026, introduced binding obligations relating to synthetically generated information, including requirements around identification and labelling of certain synthetic content.
For a firm operating in India, the practical picture is a voluntary framework setting direction, sitting on top of enforceable obligations in data protection and synthetic content. The guidelines tell you where supervision is heading. The statutes tell you what is already required.
Five Questions. One Operating Model.
Reading the three frameworks together, a common operating model begins to emerge. The questions are architectural rather than simply legal.

Where does the model run, and who controls the infrastructure?
Sovereignty initiatives across the three markets make this a governance question, not simply a procurement decision. Where models run, where data is processed and who controls the underlying infrastructure increasingly need to be considered when an AI system is designed.
What is the system authorised to do, and who decided?
Singapore’s emerging approach to agentic AI makes this particularly explicit, but the underlying principle is universal. An authorisation boundary that exists only in documentation is not a control.
Can a decision be reconstructed after the fact?
India’s emphasis on understandability by design, Singapore’s focus on records and accountability, and the UAE’s AI governance principles converge on the same practical question: can the organisation understand what happened, why it happened and who was accountable when it did?
Who is accountable – by name?
A model is not accountable. A committee is rarely accountable in practice. Someone needs the authority and standing to intervene.
Across all three markets, accountability ultimately has to translate from principle into people, roles and decision rights.
What data trained it, and on what lawful basis?
Data governance sits underneath AI governance. India’s data protection framework makes this particularly relevant, but the question applies across jurisdictions: what data was used, what rights attach to it, what permissions apply, and can the organisation demonstrate the basis on which it was used?
Firms that can answer these five questions have the foundations of a governance model that can travel across jurisdictions. Firms that cannot remain exposed however comprehensive their AI policy appears.
One Operating Model Across Three Regimes
When facing three regimes, the temptation is to build three separate programmes. In practice that approach is expensive, difficult to maintain and likely to create inconsistencies. The more sustainable approach is to build the control environment once, at group level, and then map local requirements onto it.
For AI, that means designing around the most demanding controls relevant to the organisation’s use cases – particularly around authorisation, accountability, monitoring, data governance and record retention, and then adding jurisdiction-specific requirements where necessary.
Two caveats matter.
First, data residency and cross-border transfer rules do not harmonise. A group-level control environment does not relieve a firm of local data obligations.
Second, accountability is genuinely local. A group-level AI owner may provide oversight, but it does not necessarily satisfy a regulator that expects an accountable individual within its jurisdiction or regulatory perimeter.
Beyond those differences, the convergence is useful. All three markets are moving towards governance that can be demonstrated, evidenced and challenged – rather than governance that exists only in policy.
Where to Begin
The practical starting point is an inventory: which AI systems are in use, what each is authorised to do, what data it uses, who owns it, what controls apply, and what record it leaves behind.
That exercise regularly surfaces more than organisations expect – shadow AI, unclear ownership, inconsistent approval processes and undocumented use cases. These are difficult to govern because they are difficult to see.
From there, the sequence is straightforward:
- Set authorisation boundaries deliberately.
- Establish the evidence trail before it is needed.
- Assign named accountability.
- Test the controls against the way the system actually operates.
- None of this requires waiting for further rulemaking.
The regulatory detail will continue to evolve. The technology will evolve faster. But the underlying governance disciplines are unlikely to change.
That is the value of governance done well. It does not simply respond to the next rule. It gives an organisation a structure capable of absorbing what comes next
Also Read: When An Ai Agent Pays, Who Owns The Risk?