29 July 2026

On 10 July 2026, the National AI Office (“NAIO”) issued a public consultation paper on the proposed Artificial Intelligence (“AI”) Governance Bill (“Bill”) (“Paper”). Relevant stakeholders and members of the public are invited to submit written feedback on any aspect of the Paper by 31 July 2026.

Based on the Paper, there will be three core approaches in the Bill:

  • Central institutional oversight through a central AI authority, while leveraging existing sectoral institutions;
  • A principle-based framework setting out AI governance principles as a national baseline for responsible AI governance; and
  • A risk-based approach ensuring regulatory obligations are proportionate to the nature, context and level of risk posed by an AI system.

This article summarises the core approaches set out in the Paper.

Background

The Ministry of Science, Technology and Innovation (MOSTI) previously published the National Guidelines on AI Governance and Ethics in September 2024, which serve as non-binding guidelines encouraging AI developers and deployers to voluntarily adopt a set of AI principles (e.g. fairness, transparency, accountability, etc.) alongside existing laws.

However, in view of the rapid adoption of AI across multiple sectors in Malaysia, there is a need to shift AI regulation from voluntary guidelines to legally enforceable accountability across the entire AI lifecycle. Consequently, if passed, the AI Governance Act (“Act”) will become the first comprehensive national legislation governing artificial intelligence in Malaysia. The Bill represents a departure from Malaysia's current reliance on sector-specific frameworks, which the NAIO acknowledges create a risk of fragmented and inconsistent regulatory standards across sectors.

Scope of application

What is being regulated?

The Bill proposes to regulate the AI lifecycle of AI systems which are:

  • placed on the market or put into service within Malaysia;
  • designed, developed, or used in Malaysia; or
  • used by a deployer established in Malaysia, regardless of where the system is physically hosted.

For completeness, the Bill seeks to define the following terms:

  • AI”: A functional capability or a set of methods that enables a system to perform functions that resemble human cognitive functions. These may include learning, reasoning, inference, prediction, perception, language processing, recommendation, content generation or decision support.
  • AI systems”: The actual operative system, whether stand-alone, embedded, integrated, modular, remote, or service-based, through which AI functionality is manifested in practice. It is a system that incorporates, applies, or is enabled by AI capability.
  • AI lifecycle”: The overall journey of an AI system, from early development until the system is withdrawn.

Who is being regulated?

The Bill proposes to regulate the following categories of parties involved in the AI lifecycle:

  • Developer: Any person or organisation that materially shapes what the AI system is capable of doing, how it is intended to function, how well it performs, what limits are built into it, or what risks it may create. This includes parties that train the model, adapt it for a specific use case, integrate it into a wider system, or modify it after deployment; and
  • Deployer: Any person or organisation that causes the AI system to operate in the real world or domain of deployment. The deployer decides whether, where, how, and under what conditions the capability is used, and may control the system's availability, configuration, operational use, monitoring, suspension, or withdrawal.

Exemptions

The Bill proposes certain exemptions from the scope of application, namely personal use (by individuals for personal, family or household affairs), and systems used solely for national defence or security.

Establishment of the Central AI Authority

The Bill proposes three core functions for the Central AI Authority (“Authority”):

  • AI safety function: This includes maintaining a risk framework, supervising assessments, supporting testing, developing incident reporting mechanisms, and engaging in international technical cooperation.
  • Investigation and enforcement function: This includes coordinating technical fact-finding in the event of AI incidents and issuing directions to mitigate risk.
  • AI enablement functions: This includes operationalising baseline AI governance principles, undertaking capacity building initiatives (e.g. developing guidance, templates, training, etc.) and implementing AI sandboxes.

The Authority may appoint sectoral leads and delegate specific powers to them to support the implementation of the framework such as the creation of sector-specific guidelines and codes of practice.

AI governance principles

The Bill proposes five AI governance principles to serve as a national baseline for responsible AI development, deployment and use:

  • Protection of human dignity: AI systems must not undermine meaningful human agency or remove important decisions from human review. Governance must uphold human dignity, ensuring individuals are not treated as mere data points.
  • Transparency and explainability: AI systems with material effects should be developed or deployed with transparency and explainability proportionate to the context, risk, intended use, and affected stakeholders.
  • Clear accountability: Responsibility for AI must remain attributable to identifiable persons and cannot be displaced onto the AI system itself. This requires a clear and traceable chain of accountability.
  • Safety and security: AI systems should be developed and deployed with proactive measures to anticipate, assess, and address risks before they materialise. The level of precaution must be proportionate to the foreseeability and severity of potential harm.
  • Responsible data governance: Data used in relation to AI systems must be governed and managed responsibly, lawfully and securely. Recognising that the quality, integrity, provenance and security directly impact the reliability, fairness and trustworthiness of AI systems, developers and deployers must ensure data is fit for purpose, properly sourced, and protected against unauthorised access or misuse.

Developers and deployers of AI systems are required to have “due regard” for these principles throughout the AI system's lifecycle. “Due regard" entails actively applying these principles in a manner proportionate to the system's nature, context, and potential impact.

AI risk framework

Types of risks

The risks an AI system may pose across its lifecycle are categorised into the following non-exhaustive types of harm, serving as a baseline:

  • death;
  • bodily injury;
  • unlawful deprivation of fundamental liberty anchored to the Federal Constitution; and
  • contravention of any written law.

Evaluation of risks

The Bill proposes that the following factors be considered when evaluating the potential risks posed by an AI system:

  • Likelihood: The probability of a harm pathway occurring;
  • Severity and scale: The intensity of the impact and the number of individuals affected; and
  • Duration and reversibility: The persistence of the harm and whether it can be remediated.

Risks are classified based on the following tiers:

  • Tier 1 (Unacceptable risk): An AI system developed or deployed with an intent to cause harm.
  • Tier 2 (High risk): An AI system developed or deployed without intent to cause harm, but which creates a risk of harm occurring.
  • Tier 3 (Low risk): An AI system that does not present foreseeable material AI harm.

Depending on the risk tier, the Authority may impose mandatory or voluntary compliance requirements under the Bill. Such obligations will specify requisite mitigation measures, tailored by class of AI system, sector, or domain of deployment.

AI incident reporting

Scope of reporting

A reporting requirement applies to all AI incidents. For purposes of this framework, an “AI incident” includes any failure, weakness, misuse, unexpected effect, or near-miss event arising from an AI system that causes, or has the potential to cause, AI-related harm.

Notification should contain details such as the nature of the incident, any foreseeable harm, containment measures taken, the root cause (if applicable) and remediation actions taken.

Reporting channels

AI incidents may be reported by:

  • the developer or deployer via prescribed channels; and/or
  • public complaints via channels implemented by the Authority.

Post-reporting process

The reporting framework aims to establish a repository of reliable technical records from incident reports. The Authority will oversee investigations, and may issue formal findings and recommend mitigation measures.

To the extent that sectoral leads have established comparable incident reporting mechanisms, the Bill intends to integrate with such existing measures rather than displace them.

AI sandbox

The Bill proposes to establish an AI sandbox regime to facilitate the testing of AI systems within a controlled environment that reflects their intended operational context. The AI sandbox may be implemented either by way of a centralised AI sandbox administered directly by the Authority, or by decentralised AI sandboxes utilising existing infrastructure, particularly where sectoral leads possess specialised technical expertise.

Questions requiring feedback

The NAIO is seeking feedback on the following points:

  • Scope of application and defined terms: The alignment of proposed definitions for AI, AI systems, AI lifecycle, developers, and deployers with industry understanding, the need for common definitions across sectors, potential exemptions based on sector or use-case, additional considerations or definitions to incorporate, and relevant local or international standards to guide the development of these definitions.
  • Authority and sectoral leads: Current regulatory engagement and multi-sector compliance practices, potential additional functions or safeguards for the Authority, anticipated implementation challenges, necessary guidance or tools for compliance, the specific powers and functions of sectoral leads, and relevant local or international best practices that should be considered.
  • AI governance principles: Current alignment of organisational practices with the proposed principles, existing governance frameworks, anticipated implementation challenges, potential additional principles, and the specific guidance or tools required to effectively operationalise the framework.
  • AI risk framework: Current organisational practices for identifying, assessing and managing AI-related risks, existing risk management frameworks and standards, potential risks or unintended consequences arising from the proposed AI risk framework and their mitigation, additional risk categories or safeguards to incorporate, and implementation challenges associated with applying the framework.
  • AI incident reporting: Current internal processes for identifying and managing AI incidents, the structure for coordination between the Authority and sectoral leads, challenges in establishing cross-sector reporting mechanisms, information to be collected for assessment and policy development, and additional reporting mechanisms or governance arrangements to incorporate.
  • AI sandbox: Current industry participation in AI sandboxes, preferred sandbox environments, operationalisation of AI sandbox and incentives, potential challenges in AI sandbox participation, additional safeguards or considerations to incorporate, and relevant local or international best practices that should be considered.

Conclusion

All relevant stakeholders are encouraged to review the Paper and provide feedback and comments in electronic form via the link provided here by 5:00pm on Friday, 31 July 2026. The Bill is expected to be tabled this year.

Entities developing or deploying AI systems should assess the potential impact of these proposals on their operations, particularly in relation to the governance principles, risk framework and incident reporting obligation.

Further information

This article has been prepared with the assistance of Senior Associate Ng Hong Syuen and Associate Muhammad Izzad Danial Bin Yusri Izzudin.

More

Knowledge Highlights 9 July 2026

House of Representatives passes statutory amendments to Competition Act 2010: Key changes under Competition (Amendment) ...

Read more