
Building trustworthy AI is no longer a soft compliance exercise but the primary engineering bottleneck of the agentic AI era. As systems evolve from static LLM prompts to autonomous, multi-agent workflows executing real-time API calls, Data Protection Officers (DPOs), Chief Data Officers (CDOs), and privacy engineers are taking on a critical new role: architects of the AI control plane.
At a recent panel on AI governance at the inaugural Singapore Data Festival titled, Built to Last: Building the Foundations of Responsible AI, moderator J. Trevor Hughes, CEO of International Association of Privacy Professionals (IAPP) and industry leaders on the panel converged on a clear theme: if you cannot govern dynamic data flows, you cannot safely deploy agentic AI.
Here is how data and privacy professionals can operationalise trust and turn governance into a competitive advantage.
Trust as a Hard Market Metric
Risk mitigation is no longer just about dodging regulatory fines; it is about defending market share. Professor Simon Chesterman, Vice Provost at the National University of Singapore and AI Governance Lead at the NUS AI Institute, highlighted that eroding public confidence carries an immediate "bounty consequence" in the open market.
Nimish Panchmatia, Chief Data and Transformation Officer at DBS Bank, reinforced this operational reality, highlighting that if enterprise governance structures and control planes fail, the cost isn't just bad PR—it’s the immediate, irreversible loss of customer trust and business.
The End of Static Consent: Governing Flows, Not Files
Legacy compliance relies on curated, static datasets and "I Agree" checkboxes built for the web 2.0 era. Agentic systems, however, ingest live, streaming data environments in real time.
Chesterman noted that static consent forms that users skim and sign are useless for continuous, relational AI systems. Instead, enterprises need an ongoing framework—a digital "prenup"—to manage dynamic interactions and handle system failures gracefully. For technical teams, the takeaway is clear: We are no longer just governing static datasets; we must govern real-time data flows.
Governance as Code: Moving Trust into the Pipeline
How do teams operationalise this shift? Governance cannot remain trapped inside legal PDFs or post-hoc compliance audits. Panchmatia emphasised that control planes must be built directly into the organisation’s code pipelines.
True accountability spans the entire enterprise—from HR data policies to third-party API procurement. Crucially, managing risk at scale requires using AI to govern AI. This means deploying programmatic guardrails, real-time evaluation layers, and automated intervention tools to stop autonomous agents from outputting toxic, biased, or hallucinated payloads before they hit production.
Agentic AI Demands Intentional Friction
Agentic AI doesn't just output text. It executes multi-step actions across external databases and applications autonomously. Markham Cho Erickson, VP of Government Affairs & Public Policy at Google, pointed out that while users want seamless AI assistants, engineers must deliberately introduce "friction" at high-stakes checkpoints to guarantee user safety and explicit consent.
Finding the optimal trade-off between autonomous execution and human oversight—knowing when to trigger a human-in-the-loop approval versus letting the agent execute—is becoming a foundational system design challenge.
Bounding Agentic Risk With Practical AI Frameworks
Regulators are stepping up to translate high-level governance into concrete engineering guidance. Lee Wan Sie, Cluster Director of AI Safety & Governance at IMDA, outlined Singapore's Model AI Governance Framework for Agentic AI—the world's first comprehensive governance guide targeted specifically at autonomous agents.
As she emphasised, governing agentic AI requires moving beyond passive guidelines into active design boundaries and controlled testing. The framework establishes four key operational focus areas:
Assess & Bound Risks Upfront: Define clear agent privilege boundaries based on data sensitivity, agent autonomy, and action reversibility before deployment.
Meaningful Human Oversight: Enforce human approval checkpoints for high-stakes actions, ensuring alerts are contextual rather than standard "rubber-stamp" popups.
Technical Controls & Auditing: Implement tool-call logging, scoped API and identity tokens for individual agents, and continuous runtime monitoring.
Regulatory Sandboxes: IMDA actively champions safe, collaborative sandbox environments where developers and regulators can red-team agents and stress-test safety boundaries before public release.
Governance and compliance should never be viewed as innovation speed bumps. As Professor Chesterman analogised, compliance isn't a "stop sign"—it is a "seatbelt." Just as seatbelts allow drivers to push high-performance cars to higher speeds safely, robust data governance and real-time control planes are precisely what empower organizations to deploy agentic AI faster, bolder, and with complete trust.