← Back to memos

If the model is someone else’s, who answers for the outcome?

On 7 October 2026 the Monetary Authority of Singapore published AI risk management guidelines. Financial institutions stay accountable for AI they deliver, including models developed, operated or provided by third parties. On the same day, an open-weights agent company was valued at US$1.5 billion. Capability is becoming a commodity; accountability is not.

What MAS Actually Said

The guidelines took effect on 7 October 2027, and they keep the institution accountable for the models it buys.

On 7 October 2026 the Monetary Authority of Singapore issued its Guidelines on Artificial Intelligence Risk Management for Financial Institutions. They apply to all financial institutions and all forms of AI technologies, and they take effect on 7 October 2027, with sections 5 and 6 falling due by 7 October 2028.[1][2]

The sentence that matters to anyone buying AI sits in the third expectation. Financial institutions “remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties”.[1][3]

What follows from it is specific. Institutions should obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for its intended use, and apply compensating controls where assurance gaps or practical constraints arise. Where the risk cannot be brought inside the institution’s risk appetite, MAS expects it to consider limiting, suspending or replacing that service.[1]

Three other expectations complete the framework. First, clear board and senior management accountabilities, with a stated risk appetite. Second, an inventory of AI use, with risk materiality assessed use case by use case. Third, proportionate controls across the life cycle: data governance, testing, human oversight, cybersecurity, monitoring and change management.[1]

The proportionality is not decorative. Institutions may satisfy the expectations with basic policies and procedures where poor performance or unavailability of an AI service is unlikely to materially affect them, their customers or other stakeholders. They need not establish a dedicated AI committee if existing governance already provides adequate oversight.[1]

MAS also indicated what comes next: in 2027 it intends to consult the financial sector on what additional guidance on agentic AI would be useful.[1]

Two Clocks, Same Two Years

The subsidy window and the compliance deadline cover exactly the same two years.

Budget 2026 enhanced the Enterprise Innovation Scheme. Companies can claim 400% tax deductions on qualifying AI spend, capped at S$50,000 per year for YA2027 and YA2028.[4]

The same Budget expanded the Productivity Solutions Grant to lower the cost for local SMEs adopting digital and AI solutions, and set aside a dedicated AI cluster at one-north.[4]

Reskilling is funded on the same footing. SkillsFuture Singapore is developing a self-diagnostic AI readiness tool and a revamped portal, both targeted at 2026, so that workers can gauge their own readiness and find courses matched to it.[6]

Put the two together and the calendar is unusual. The state pays 400% on qualifying AI spend for YA2027 and YA2028, and it raises the governance bar on 7 October 2027 and October 2028. The incentive and the obligation land in the same window.[1][4]

The Arithmetic
S$50,000 qualifying AI spend × 400% = S$200,000 in deductions
S$200,000 × 17% corporate tax = about S$34,000 of tax saved

That is the shape of the deal being offered: adopt now, on the state’s money, and document what you adopted.

The Model Is Becoming a Commodity

On the same day, an open-weights agent company was valued at US$1.5 billion on distribution rather than a frontier model.

Also on 7 October 2026, Nous Research confirmed a US$90 million Series B at a US$1.5 billion valuation, and paired it with the launch of Hermes for Businesses, an enterprise push for its open-source agent.[5]

The round was led by Robot Ventures, with Nvidia, Union Square Ventures, Menlo Ventures, Samsung and 1789 Capital participating. Total funding now stands at US$158 million.[5]

The usage figures are the company’s own estimates: more than 24 million clones of the open-source agent, and roughly 2.5% of global AI token usage.[5]

Revenue is what makes it a business rather than a project. Nous was at roughly US$36 million in annualised revenue by mid-September 2026, and expects to pass US$100 million before the end of the year.[5]

Read the two announcements together and they describe one shift. Model capability is being priced like a commodity — open weights, tens of millions of clones, and a valuation resting on distribution rather than a proprietary frontier model. Accountability moves the other way. It cannot be downloaded, cloned or bought in, and the guidelines make that explicit.

What It Means for a Finance Team

If the model is a commodity and the accountability is yours, then the assurance is the product.

Three consequences follow for anyone operating under these guidelines.

1. An AI inventory becomes a governance artefact. You cannot assess the materiality of use cases you have not listed, and MAS expects the inventory maintained at an appropriate level of granularity.[1]

2. Vendor due diligence becomes a procurement gate. The guidelines expect sufficient assurance from third-party providers, and a service that cannot supply it becomes a candidate for replacement rather than a line item to renegotiate.[1]

3. Controls outlast model choice. Data governance, testing, human oversight, monitoring and change management survive a switch of provider. The model does not.[1]

For anyone selling automation into regulated institutions, the practical reading is sharper still. Assurance documentation stops being a differentiator and becomes a sales requirement. A vendor that cannot evidence its controls by the deadline will be replaced by one that can — and the guidelines give the buyer a stated basis for doing so.

The Counterargument

Four readings weaken the claim that much changes before 2027.

Nothing bites for a year. The guidelines take effect on 7 October 2027, and the remaining sections only by October 2028. Institutions have a transition period, and the first deadline is governance rather than behaviour.[1]

“Accountable” is not “liable for every output”. MAS asks for proportionate controls, testing and compensating measures. It does not ask an institution to guarantee that a model never errs.[1]

The proportionate route is generous. Where AI failure would not materially affect the institution, its customers or other stakeholders, basic policies and procedures may be enough — and existing committees may serve.[1]

The rules will move again. MAS intends to consult on agentic AI guidance in 2027, so the third-party expectations may sharpen, shift or split into separate requirements for systems that act rather than advise.[1]

And the subsidy is temporary. The 400% deduction applies to YA2027 and YA2028 only, so the economics of adoption worsen in 2029 regardless of what the guidelines require.[4]

What to Watch

Four signals will show whether third-party accountability changes buying behaviour.

1. The 2027 consultation on agentic AI. Whether MAS extends third-party expectations to systems that execute rather than advise is the single largest variable for anyone building agents for financial clients.[1]

2. Assurance requests arriving before signature. The guidelines give institutions a stated basis to demand control documentation from vendors. Watch whether procurement teams use it.[1]

3. The Financial Stability Board’s parallel work. It has consulted on sound practices for responsible AI adoption, which may standardise what vendor assurance is expected to contain across jurisdictions.[1]

4. The first supervisory reviews after October 2027. If third-party oversight appears in findings, the market will price assurance accordingly; if it does not, the guidelines were a floor rather than a filter.[1]

31 January 2026 Consultation closed 7 October 2026 Guidelines published 7 October 2027 In effect 7 October 2028 Sections 5–6 due
Fig. 1 The compliance clock: the consultation closed on 31 January 2026, the guidelines were published on 7 October 2026, they take effect on 7 October 2027, and the remaining sections fall due by 7 October 2028.

Source: MAS — “MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions” (7 Oct 2026). mas.gov.sg

MAS has said what most buyers suspected and few contracts admitted: buying the model does not buy the accountability. As capability commoditises, the assurance built around it is the part that carries a price.

The Bottom Line
Singapore is paying companies to adopt AI in the same two years it is making them answerable for it. Capability is becoming a commodity; accountability is not transferable.

Sources

This analysis is based on publicly available data as of 2026-10-07. For related coverage, see The AI Safety Crisis and Algorithmic Harm as Legal Liability.

  1. Monetary Authority of Singapore — “MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions” (7 Oct 2026). mas.gov.sg
  2. Monetary Authority of Singapore — “Guidelines on Artificial Intelligence Risk Management for Financial Institutions” (7 Oct 2026). mas.gov.sg
  3. CNA — “Financial institutions remain accountable for third-party AI under new MAS guidelines” (7 Oct 2026). channelnewsasia.com
  4. Singapore Economic Development Board — “Singapore’s next growth chapter: What international businesses should know from Budget 2026” (24 Mar 2026). edb.gov.sg
  5. TechCrunch — “Nous Research confirms it hit $1.5B Valuation, launches AI agents for business users” (7 Oct 2026). techcrunch.com
  6. SkillsFuture Singapore — “Budget Announcements” (2026). skillsfuture.gov.sg