On August 2, 2026, the European Union’s AI Act becomes fully enforceable — the first binding, comprehensive AI regulation in history. But as the compliance clock runs out, a critical gap is already visible: the Act was drafted before autonomous AI agents became a commercial reality. As this comprehensive guide to global AI governance makes clear, the frameworks that will govern the next generation of AI systems are being written right now — and the EU is not leading.

The guide, published by Hung Yi Chen, maps over 1,000 AI policy initiatives across 69 countries tracked by the OECD AI Policy Observatory. The EU AI Act is the centerpiece, but it is no longer the only game in town. The United States relies on the voluntary NIST AI Risk Management Framework (AI RMF 1.0), published in January 2023, with sectoral regulators like the FDA (which has cleared over 950 AI-enabled medical devices) and the FTC enforcing specific rules. China requires algorithmic impact assessments, security reviews, and content reflecting “core socialist values” before deploying generative AI. Japan and South Korea have their own safety institutes and risk-based classification systems.

The most consequential development in 2026, however, is not in Brussels or Washington. It is in Singapore.

In January 2026, Singapore’s Infocomm Media Development Authority (IMDA) released the world’s first Model AI Governance Framework specifically for agentic AI. The framework introduces Agent Identity Cards — standardized disclosure formats specifying capabilities, limitations, and escalation protocols — and a five-tier taxonomy of graduated autonomy levels, from “tool-assisted” (Level 0) to “fully autonomous” (Level 4). Governance requirements increase at each level. Critically, the framework establishes a clear operator-deployer responsibility framework: the entity that builds an AI agent platform and the entity that deploys it in a specific context each bear defined liability.

Singapore’s framework addresses a governance gap that neither the EU AI Act nor the NIST AI RMF adequately covers. The EU AI Act was negotiated before the explosion of agentic systems. Its risk categories assume AI that assists human decision-making, not AI that makes and executes decisions independently. The NIST AI RMF, while influential, is voluntary and was designed for predictive and generative systems, not autonomous agents.

The gap is not theoretical. The guide notes that in February 2026, NIST launched a dedicated initiative to develop standards for autonomous AI agents — a direct response to governance challenges exposed by systems where AI agents operating autonomously created security vulnerabilities at a scale existing frameworks were not designed to address. The initiative focuses on three areas: agent identity and authentication, action logging and auditability, and containment boundaries for autonomous operation.

The EU AI Act does include provisions for General-Purpose AI (GPAI) models — foundation models like GPT-4, Claude, and Gemini — which took effect on August 2, 2025. GPAI providers must maintain technical documentation, comply with EU copyright law, and provide transparency summaries. Models assessed as posing “systemic risk” (based on cumulative compute exceeding 10^25 FLOPs, or Commission designation) face adversarial testing, incident reporting to the European AI Office, cybersecurity assessments, and energy consumption reporting. Penalties reach €35 million or 7% of global annual turnover for prohibited practices.

But these provisions assume a world where AI systems make predictions and generate content. They do not address what happens when an AI agent books a flight, signs a contract, or deploys code to production without human approval. The EU AI Act’s risk categories — unacceptable, high, limited, minimal — map poorly onto systems that operate on a spectrum of autonomy. A Level 2 agent that can execute transactions within defined parameters is categorically different from a Level 4 agent that can renegotiate those parameters.

The guide’s analysis of the “Brussels Effect” — the phenomenon, documented by Columbia Law professor Anu Bradford, by which EU standards become de facto global baselines — suggests that the EU AI Act will shape global compliance for conventional AI systems. Companies will find it more efficient to comply globally than to maintain separate systems for different jurisdictions. That logic holds for predictive AI and generative AI. It is less clear whether it holds for agentic AI, where the EU has no specific framework to export.

The international coordination mechanisms that do exist — the ISO/IEC 42001 AI management system standard, the OECD AI Principles, the G7 Hiroshima AI Process — provide common language and foundational principles but no binding rules for autonomous action. The G7 Code of Conduct emphasizes pre-deployment safety testing and incident information sharing, but it is non-binding. ISO/IEC 42001 offers a certifiable framework for AI governance but does not prescribe technical requirements for agent containment or audit trails.

The race to set the standard for agentic AI governance is now the most consequential regulatory contest in technology. Singapore has the first-mover advantage with a concrete, actionable framework. The U.S. has NIST working on standards but no legislative mandate. The EU has the enforcement machinery but a framework designed for a different era of AI.

For enterprises operating across jurisdictions, the compliance challenge is not just about meeting the EU AI Act’s August deadline. It is about building governance systems flexible enough to accommodate a regulatory landscape that is still being invented. The guide’s compliance roadmap emphasizes ISO/IEC 42001 certification as a foundation, precisely because it can be mapped to multiple regulatory frameworks. But no existing standard fully addresses the autonomy taxonomy Singapore has proposed.

The EU AI Act goes live in 13 days. It will be the most consequential AI regulation the world has seen. But the hardest questions about AI governance — who is liable when an autonomous agent makes a bad decision, how to audit a system that learns and adapts, what containment boundaries are sufficient — remain unanswered. Singapore has proposed answers. The rest of the world is still writing the questions.