Enterprise AI governance · Singapore

Govern the AI you run in Azure. Prove it.

Regulators have started asking — by name — how your organisation governs its AI, including autonomous agents. AI Pulse finds what's running across your Azure estate, including the ones nobody registered, and turns what it sees into evidence you can hand to a supervisor.

One product, one discipline — it observes and proves, and enforces where you authorise it.

AI Pulse board view: AI maturity, evidence and governance readiness, AI estate, posture score and attestation coverage, each labelled with its data provenance.
AI Governance Posture The board view: estate, posture and evidence readiness, every figure labelled with where it came from.

01What it does

Discovery, tiering, mapping, evidence

Four jobs, in order. Everything else on this page follows from getting these right.

Discover

A continuous sweep across Azure AI services, Microsoft 365, Power Platform and the related cost signals surfaces AI systems — sanctioned, experimental or shadow. What is found is registered; nothing stays dark.

Risk-tier

Each system is tiered by what it touches: data sensitivity, autonomy, customer impact. High-tier systems get closer attention and stricter evidence expectations.

Map

Controls map to 45 frameworks — MAS guidance and information papers, IMDA's governance frameworks, ISO/IEC 42001, NIST AI RMF, the EU AI Act and more. Map once, report many.

Evidence

Audit-ready packs: what exists, who owns it, what tier it sits in, which controls apply, when it was last reviewed. Produced for the review you actually face.

See the platform in full →

02Why now

Your regulator is already asking

On 13 November 2025, the Monetary Authority of Singapore published a consultation on Guidelines on Artificial Intelligence Risk Management. The draft applies to all financial institutions, expressly covers generative AI and autonomous AI agents, and proposes a 12-month transition once the final guidelines are issued in 2026.

Once final, MAS will assess firms' AI risk management at inspections and supervisory reviews. This is not a distant horizon: MAS ran a thematic review of banks' AI and generative-AI model risk practices in mid-2024, and published its findings as an information paper in December 2024. Supervision of AI governance is already happening.

“Show me your AI controls.”

The practical question for your next supervisory review. Everything here exists to make that answerable with a record rather than a reconstruction — which is a different exercise, and a much longer one, once someone is already asking.

Mid-2024

MAS thematic review of banks' AI model risk management practices.

MAS Information Paper, 5 Dec 2024

5 Dec 2024

MAS Information Paper on AI Model Risk Management published.

13 Nov 2025

Consultation on AI Risk Management Guidelines opens — all financial institutions, generative AI and autonomous agents in scope.

MAS Consultation Paper, 13 Nov 2025

31 Jan 2026

Consultation closes.

Expected 2026

Final guidelines expected, with a proposed 12-month transition period.

Sources: MAS, Information Paper on AI Model Risk Management, 5 December 2024. MAS, Consultation Paper on Guidelines on Artificial Intelligence Risk Management, 13 November 2025. Consultation closed 31 January 2026; guidelines expected in 2026, with a proposed 12-month transition period. Consulted on — not yet in force.

03The cost

Ungoverned AI is the expensive kind

1 in 5

breached organisations were compromised through shadow AI — AI running outside sanctioned, governed channels. Of those, 97% had no AI access controls.

Source: IBM Security, Cost of a Data Breach Report 2025 (July 2025).

+US$670K

the premium on a breach where shadow AI was widespread: US$5.11 million against a US$4.44 million global average.

Source: IBM Security, Cost of a Data Breach Report 2025 (July 2025).

€35M

or 7% of worldwide turnover, whichever is higher — the EU AI Act's maximum administrative fine for prohibited practices. Singapore's PDPA ceiling is 10% of local turnover.

Source: Regulation (EU) 2024/1689 (EU AI Act), Article 99.

You cannot govern what you cannot see. Discovery is the first control — and the exact positions and citations are set out in full.

04What only we do

Four controls that sit between an agent and the world

Most governance tools report on what an agent did. These are components an agent's traffic physically passes through — and what each one refuses.

Tools it was never given

Each agent declares the tools it may call; anything else is refused at the gateway. An agent that declared no allowlist at all is a finding, not a free pass.

MCP servers that change

Capability discovery is answered from a human-approved baseline, so a server that quietly rewrites a tool description cannot put that text into the model's context.

Self-granted approvals

A paused action resumes only against an approval bound to the exact recipient and amount, recorded under a separate operator credential. An agent cannot approve itself.

Records edited later

Every decision is sealed into a hash chain. Change a field, delete a row or reorder one and it is detected — by a checker separate from the service that wrote it.

How enforcement works →

05One product

Start read-only. Add enforcement when you need it.

AI Pulse is one product with one portal, one evidence model and one registry. What changes is how much of it you switch on — and enforcement is not a setting, it is a layer you deploy and authorise separately.

Available now · Azure Managed Application

Start by observing

Read-only governance for Microsoft AI estates. Discovers AI systems across your tenant — including shadow AI — risk-tiers it, maps it to 45 frameworks, and produces audit-ready evidence. Deployed as a managed application in your own tenant, with zero write permissions in the set.

  • Full-estate discovery, incl. unregistered systems
  • Evidence packs mapped to MAS expectations
  • Your data never leaves your tenant
See the platform

Planned · Hybrid and sovereign-connected

Add enforcement when you need it

The same portal, with an interception layer in front of it: inline guardrails, tool-intent checks before an agent acts, and an Action Gatekeeper that pauses a sensitive action for human approval. Set per agent and per action class — and it runs wherever your agents do, including sovereign and air-gapped estates.

  • Stop an action before it happens, not after
  • Runs where your agents run — even air-gapped
  • Tamper-evident decision ledger
See enforcement

Observing never becomes enforcing by accident. The enforcement components are separate services you choose to deploy; where they are not installed, there is nothing in the permission set that could write.

06Roadmap

Shipped is fact. Everything after it is direction.

The product labels every figure it shows you with where it came from. We hold our own roadmap to the same standard: what is shipping is fact, what is not is direction, and the two are marked differently on purpose.

StageWhat it meansLevel
Available Read-only governance on Azure — discovery, risk tiering, 45-framework mapping and evidence packs — deployed as a managed application in your own tenant. Shipping
Enforcement Inline guardrails, tool-intent interception, the Action Gatekeeper and the tamper-evident ledger — staged through shadow mode before anything goes live. Runs wherever your agents do, including sovereign and air-gapped estates. Planned
Next Portable evidence and telemetry, wherever your agents run — the same registry and evidence model, extended beyond Azure-only sources. Planned
After that Hybrid, sovereign and fully disconnected deployment — for regulated and air-gapped estates. Planned

We mark a stage Shipping only once there is a running build behind it. Everything else is labelled as direction, because a roadmap you cannot rely on is worth less than no roadmap at all.