Back to AI Regulations Review
Draft Bill - Public Consultation Since July 2026 Malaysia

Malaysia's Draft AI Governance Bill

// Draft Bill - Voluntary Today, Statutory Tomorrow

Malaysia is sequencing its rulebook deliberately: voluntary guidelines first, national standards second, statute third. The AI Governance Bill in consultation since July 2026 will be Malaysia's first binding AI framework, and organizations that align during the voluntary window will absorb the transition cheapest.

AIGE Sep 2024NAIO Dec 2024Bill consultation Jul 10, 2026
// Key Highlights

Key Highlights

From AIGE principles to the consultation paper, plus the hard law already in force.

  1. 01

    The National Guidelines on AI Governance and Ethics (AIGE), published September 2024, set seven voluntary principles: fairness, transparency, privacy, security and safety, accountability, robustness, and benefit to humanity.

  2. 02

    The National AI Office (NAIO), launched December 2024 under the Ministry of Digital ecosystem, coordinates national strategy, standards harmonization, and a forthcoming high-risk AI register.

  3. 03

    The MY-AI national standards platform launched March 2026 with the Department of Standards Malaysia and SIRIM, consolidating technical and process standards covering risk management, model documentation, bias testing, data governance, and incident reporting.

  4. 04

    The draft AI Governance Bill entered public consultation on July 10, 2026. It proposes a risk-based model covering the entire AI lifecycle - stand-alone, embedded, integrated, or service-based systems alike.

  5. 05

    The bill adds provisions beyond risk tiering: deepfake controls, copyright questions around AI-generated works, and data sovereignty expectations.

  6. 06

    The framework is expected to draw on the EU AI Act's structure tempered by Singapore's Model AI Governance Framework and the ASEAN Guide - risk-tiered obligations without EU-scale penalties at launch.

  7. 07

    Hard law already applies today regardless of the bill: the Cyber Security Act 2024 imposes incident-reporting and audit duties on AI within National Critical Information Infrastructure, and the PDPA Amendment Act 2024 treats biometric data as sensitive and mandates Data Protection Officers for large-scale processing.

  8. 08

    Sectoral regulators moved first: Bank Negara Malaysia's RMiT and the Securities Commission's GTRM already demand rigorous technology-risk governance from financial institutions using AI.

// Governance & Compliance Playbook

Action Items for Governance and Compliance

Six moves that turn the voluntary phase into an advantage.

Adopt AIGE principles as internal policy now

A01
Governance

Publish an AI acceptable-use and ethics policy mapped explicitly to the seven AIGE principles, endorsed by leadership.

Compliance

Run self-assessments against MY-AI reference controls so alignment evidence exists before any mandate arrives.

Prepare your inventory for future registration

A02
Governance

Assign one accountable register owner with a documented classification methodology.

Compliance

Design the register schema so it ports cleanly into the national high-risk registry NAIO is expected to operate.

Close sectoral gaps immediately

A03
Governance

Align model governance to BNM RMiT and SC GTRM expectations where you touch Malaysian finance.

Compliance

Meet Cyber Security Act clocks for NCII-classified systems: incident reporting windows and periodic audits.

Harden PDPA alignment

A04
Governance

Appoint the Data Protection Officer and define a biometric-processing approval workflow.

Compliance

Maintain consent records, breach-notification runbooks, and processing registers that satisfy JPDP enforcement.

Build synthetic-content readiness

A05
Governance

Set a labeling policy for generated media across products and marketing before deepfake provisions take effect.

Compliance

Ship content-marking capability ahead of enactment rather than retrofitting under deadline.

Engage the consultation process

A06
Governance

Submit structured industry feedback through NAIO channels while the bill is still shapeable.

Compliance

Track bill milestones and sandbox opportunities to time governance investment correctly.

// From Rulebook to Build

Engineering Translation

High-level capabilities that make the eventual statutory leap painless.

[REGULATION_BUILD_PLAN] HIGH LEVEL

>_AIGE principles encoded as checklist gates inside delivery workflows instead of policy PDFs.

>_Register designed once, portable to the forthcoming national registry format.

>_Incident connectors aligned to critical-infrastructure reporting timelines.

>_Consent and biometric data flows isolated behind auditable request boundaries.

>_Synthetic-content labeling hooks shipped ahead of the mandate.

>_Deployment options preserved to honor sovereign-hosting expectations.

Delivered as capabilities, not paperwork

Each obligation above is translated into product-level engineering capabilities. The underlying stack and internal tooling are intentionally abstracted here; they are covered in technical briefings.

Educational summary only. This is not legal advice. Confirm obligations with qualified counsel for your jurisdiction.

Get Malaysia-Ready Before the Bill Becomes Law

Book a technical briefing to align your AI estate with AIGE principles and prepare registration-ready governance records.