AITraining2U

Programs

Resources

Case Studies

Quick Links

Enquire Now
AI Governance

Malaysia's AI Governance Bill: What Is Proposed and What to Do Now

On 10 July 2026 the National AI Office published its Public Consultation Paper. If you deploy AI in Malaysia — or your system is used here from anywhere — this will reach you.

By AITraining2U Editorial Team 2026-09-09 11 min read
Legal and regulatory framework for artificial intelligence

Malaysia has been governing AI through voluntary guidelines — the National Guidelines on AI Governance and Ethics, sectoral rules from Bank Negara, and general law. That is about to change.

On 10 July 2026, the National AI Office (NAIO), established in December 2024 under the Ministry of Digital, published a Public Consultation Paper setting out the proposed AI Governance Bill. Written feedback was invited until 31 July 2026, with a potential enactment target in the second half of 2026.

The shift is from voluntary to mandatory. Here is what is proposed, in plain language.

The scope is broader than most people assume

This is the first thing to understand, because a lot of organisations will assume it does not apply to them.

The proposed scope reaches AI systems that are placed on the market or put into service in Malaysia, designed, developed or used in Malaysia, or used by a Deployer established in Malaysia regardless of where the system is hosted.

That last limb is the significant one. Running a US-hosted SaaS AI tool from a Malaysian entity does not put you outside the Bill. If you are established here and you deploy the system, you are in scope wherever the servers sit.

The proposed three-tier risk framework

TIER 1 — Unacceptable TIER 2 — High Risk TIER 3 — Low Risk Expected to be prohibited outright — uses judged to pose unacceptable harm to rights or safety. Permitted with obligations: risk assessment, human oversight, documentation, incident reporting. Baseline governance principles only — transparency and basic accountability. do not build this most enterprise AI lands here light touch Obligations are allocated by role — Developer, Deployer, and others in the chain carry different duties.
Based on the Public Consultation Paper published 10 July 2026. Final tiering may change before enactment.

Obligations follow your role, not just the tier

The proposed framework allocates governance responsibilities according to the role a party plays and the level of control it exercises. A Developer building a model carries different duties from a Deployer putting it into service.

For most Malaysian businesses the relevant identity is Deployer — you did not train the model, you are using it in a real process affecting real people. Deployer obligations typically centre on how the system is used, what oversight exists, and what happens when it goes wrong, rather than on how the model was built.

The four mechanisms worth understanding

Baseline governance principles. A floor applying across tiers — transparency, accountability, human oversight in some form.

Risk-based tiering. The three tiers above, with obligations scaling to risk.

Incident reporting. A mechanism requiring notification when an AI system causes or risks causing harm. Practically, this means you need to be able to detect an incident and reconstruct what happened — which is an observability requirement dressed as a legal one. If you cannot answer "what did the system do and why" after the fact, you cannot report on it. See LLM observability.

Regulatory sandbox. A supervised environment for testing higher-risk systems. Genuinely useful for organisations doing novel work, and worth watching.

Oversight sits with a proposed Central AI Authority working alongside existing sectoral regulators — so Bank Negara does not stop mattering for financial institutions. Expect layered rather than replaced supervision.

What is not yet public

Being straight about the gaps matters more than filling them with speculation.

The consultation paper sets out architecture rather than final text. Penalty levels are not detailed in publicly available summaries. The precise contents of each tier — which specific uses count as unacceptable or high-risk — remain to be settled. Enactment timing is a target, not a commitment, and consultation feedback can move all of it.

Anyone telling you exactly what the compliance obligations will be is guessing. What is reasonably certain is the direction: risk-based tiering, role-based obligations, mandatory incident reporting, extraterritorial reach.

What to do now

None of this requires waiting for enactment. All of it is worth doing regardless.

  1. Inventory your AI systems. Most organisations cannot currently answer "which AI systems do we run, who owns each, and what can they affect?" You cannot classify by risk tier without this, and it is the longest-lead item.
  2. Provisionally classify by risk. Anything touching employment decisions, credit, healthcare, or vulnerable people should be assumed high-risk. Internal drafting assistants almost certainly are not.
  3. Identify your role per system. Developer or Deployer — and note it, because your obligations differ.
  4. Build incident detection now. You cannot report what you cannot see. Tracing, logging and alerting are prerequisites, and retrofitting them is far harder than starting with them.
  5. Document human oversight. For every consequential AI decision, who reviews it, on what basis, with what authority to override.
  6. Align with what you already have. If you are complying with PDPA obligations and, in financial services, BNM RMiT, a great deal of the groundwork overlaps. See our PDPA and AI guide.

The proportionate view

Two failure modes are worth naming. The first is treating this as an existential compliance event and freezing AI adoption — the Bill is explicitly designed to enable adoption within guardrails, not to prevent it. The second is assuming voluntary guidelines will simply continue and doing nothing, which leaves you retrofitting governance onto systems already in production.

The organisations that will find this straightforward are those that already know what they run, can explain what it did, and have a human accountable for each consequential decision. That is defensible engineering practice with or without a statute.

Our AI Security programme and AI Awareness programme cover AI governance, risk classification and incident readiness for Malaysian organisations — HRD Corp SBL-KHAS claimable.

Frequently Asked Questions

The National AI Office published the Public Consultation Paper on 10 July 2026, with written feedback invited until 31 July 2026. Potential enactment has been signalled for the second half of 2026. The consultation paper sets out architecture rather than final statutory text, so details can change — enactment timing is a target rather than a commitment.

Very likely yes. The proposed scope reaches AI systems used by a Deployer established in Malaysia regardless of where the system is hosted, as well as systems placed on the market or put into service in Malaysia and systems designed, developed or used here. Running a US-hosted SaaS AI tool from a Malaysian entity does not put you outside the Bill — the extraterritorial limb is the one most organisations underestimate.

Tier 1 (Unacceptable Risk) covers uses expected to be prohibited outright. Tier 2 (High Risk) is permitted with substantive obligations — risk assessment, human oversight, documentation and incident reporting. Tier 3 (Low Risk) attracts baseline governance principles only. Most enterprise AI deployment is expected to fall into Tier 2. Obligations are also allocated by role, so a Developer and a Deployer carry different duties even for the same system.

Inventory your AI systems and note who owns each and what it can affect — most organisations cannot currently answer this, and it is the longest-lead item. Provisionally classify by risk, identify whether you are Developer or Deployer per system, build incident detection (you cannot report what you cannot see), and document human oversight for every consequential decision. All of it is defensible practice regardless of the statute.

No. Oversight is proposed to sit with a Central AI Authority working alongside existing sectoral regulators, so expect layered rather than replaced supervision. Financial institutions should assume BNM RMiT expectations continue to apply in addition to the new framework, and that the practical work of complying with both overlaps substantially.

Build AI systems that hold up in production

Evaluation, observability and guardrails are what separate a demo from a system your business can depend on. AITraining2U runs hands-on, HRD Corp SBL-KHAS claimable AI training for Malaysian organisations — tool-agnostic and mapped to your actual stack.