Discover
A continuous sweep across Azure AI services, Microsoft 365, Power Platform and the related cost signals surfaces AI systems — sanctioned, experimental or shadow. What is found is registered; nothing stays dark.
Enterprise AI governance · Singapore
Regulators have started asking — by name — how your organisation governs its AI, including autonomous agents. AI Pulse finds what's running across your Azure estate, including the ones nobody registered, and turns what it sees into evidence you can hand to a supervisor.
One product, one discipline — it observes and proves, and enforces where you authorise it.
01What it does
Four jobs, in order. Everything else on this page follows from getting these right.
A continuous sweep across Azure AI services, Microsoft 365, Power Platform and the related cost signals surfaces AI systems — sanctioned, experimental or shadow. What is found is registered; nothing stays dark.
Each system is tiered by what it touches: data sensitivity, autonomy, customer impact. High-tier systems get closer attention and stricter evidence expectations.
Controls map to 45 frameworks — MAS guidance and information papers, IMDA's governance frameworks, ISO/IEC 42001, NIST AI RMF, the EU AI Act and more. Map once, report many.
Audit-ready packs: what exists, who owns it, what tier it sits in, which controls apply, when it was last reviewed. Produced for the review you actually face.
02Why now
On 13 November 2025, the Monetary Authority of Singapore published a consultation on Guidelines on Artificial Intelligence Risk Management. The draft applies to all financial institutions, expressly covers generative AI and autonomous AI agents, and proposes a 12-month transition once the final guidelines are issued in 2026.
Once final, MAS will assess firms' AI risk management at inspections and supervisory reviews. This is not a distant horizon: MAS ran a thematic review of banks' AI and generative-AI model risk practices in mid-2024, and published its findings as an information paper in December 2024. Supervision of AI governance is already happening.
“Show me your AI controls.”
The practical question for your next supervisory review. Everything here exists to make that answerable with a record rather than a reconstruction — which is a different exercise, and a much longer one, once someone is already asking.
MAS thematic review of banks' AI model risk management practices.
MAS Information Paper, 5 Dec 2024
MAS Information Paper on AI Model Risk Management published.
Consultation on AI Risk Management Guidelines opens — all financial institutions, generative AI and autonomous agents in scope.
MAS Consultation Paper, 13 Nov 2025
Consultation closes.
Final guidelines expected, with a proposed 12-month transition period.
Sources: MAS, Information Paper on AI Model Risk Management, 5 December 2024. MAS, Consultation Paper on Guidelines on Artificial Intelligence Risk Management, 13 November 2025. Consultation closed 31 January 2026; guidelines expected in 2026, with a proposed 12-month transition period. Consulted on — not yet in force.
03The cost
1 in 5
breached organisations were compromised through shadow AI — AI running outside sanctioned, governed channels. Of those, 97% had no AI access controls.
Source: IBM Security, Cost of a Data Breach Report 2025 (July 2025).
+US$670K
the premium on a breach where shadow AI was widespread: US$5.11 million against a US$4.44 million global average.
Source: IBM Security, Cost of a Data Breach Report 2025 (July 2025).
€35M
or 7% of worldwide turnover, whichever is higher — the EU AI Act's maximum administrative fine for prohibited practices. Singapore's PDPA ceiling is 10% of local turnover.
Source: Regulation (EU) 2024/1689 (EU AI Act), Article 99.
You cannot govern what you cannot see. Discovery is the first control — and the exact positions and citations are set out in full.
04What only we do
Most governance tools report on what an agent did. These are components an agent's traffic physically passes through — and what each one refuses.
Each agent declares the tools it may call; anything else is refused at the gateway. An agent that declared no allowlist at all is a finding, not a free pass.
Capability discovery is answered from a human-approved baseline, so a server that quietly rewrites a tool description cannot put that text into the model's context.
A paused action resumes only against an approval bound to the exact recipient and amount, recorded under a separate operator credential. An agent cannot approve itself.
Every decision is sealed into a hash chain. Change a field, delete a row or reorder one and it is detected — by a checker separate from the service that wrote it.
05One product
AI Pulse is one product with one portal, one evidence model and one registry. What changes is how much of it you switch on — and enforcement is not a setting, it is a layer you deploy and authorise separately.
Available now · Azure Managed Application
Read-only governance for Microsoft AI estates. Discovers AI systems across your tenant — including shadow AI — risk-tiers it, maps it to 45 frameworks, and produces audit-ready evidence. Deployed as a managed application in your own tenant, with zero write permissions in the set.
Planned · Hybrid and sovereign-connected
The same portal, with an interception layer in front of it: inline guardrails, tool-intent checks before an agent acts, and an Action Gatekeeper that pauses a sensitive action for human approval. Set per agent and per action class — and it runs wherever your agents do, including sovereign and air-gapped estates.
Observing never becomes enforcing by accident. The enforcement components are separate services you choose to deploy; where they are not installed, there is nothing in the permission set that could write.
06Roadmap
The product labels every figure it shows you with where it came from. We hold our own roadmap to the same standard: what is shipping is fact, what is not is direction, and the two are marked differently on purpose.
| Stage | What it means | Level |
|---|---|---|
| Available | Read-only governance on Azure — discovery, risk tiering, 45-framework mapping and evidence packs — deployed as a managed application in your own tenant. | Shipping |
| Enforcement | Inline guardrails, tool-intent interception, the Action Gatekeeper and the tamper-evident ledger — staged through shadow mode before anything goes live. Runs wherever your agents do, including sovereign and air-gapped estates. | Planned |
| Next | Portable evidence and telemetry, wherever your agents run — the same registry and evidence model, extended beyond Azure-only sources. | Planned |
| After that | Hybrid, sovereign and fully disconnected deployment — for regulated and air-gapped estates. | Planned |
We mark a stage Shipping only once there is a running build behind it. Everything else is labelled as direction, because a roadmap you cannot rely on is worth less than no roadmap at all.