Malaysia Malaysia digital economy MyDigital

Malaysia's Draft AI Governance Bill Gets the Risk Tiers Right, But Leaves the State and Foreign Developers Undefined

NAIO's consultation sketches a proportionate risk-tiered AI law, but exempts unclear state use and skipped input from the developers it targets most.

Malaysia's Draft AI Governance Bill People of Internet Research · Malaysia 21 days Consultation window NAIO's Public Consultation Paper r… 3 tiers AI risk classification tiers From Tier 1 unacceptable-risk syst… 2 roles Regulated actor categories Developers who shape system capabi… 25.5% Digital economy GDP share Malaysia's digital economy share o… peopleofinternet.com
Malaysia's Draft AI Governance Bill People of Internet Research · Malaysia 21 days Consultation window 3 tiers AI risk classification t… 2 roles Regulated actor categories 25.5% Digital economy GDP share peopleofinternet.com

Key Takeaways

Malaysia's National AI Office (NAIO) closed public consultation on 31 July 2026 on a draft AI Governance Bill that would give the country its first horizontal AI law — a single statute covering how AI systems are built and used across every sector, rather than leaving the job to scattered rules on data, cybersecurity, and consumer protection. The Public Consultation Paper was released 10 July 2026, and the Bill is targeted for completion by the end of the year.

The Case for Getting Ahead of It

The strongest argument for NAIO's approach is timing. Malaysia has no dedicated AI statute today, only a patchwork of data-protection, cybersecurity, and sectoral rules that were never written with foundation models or agentic systems in mind. AI-related harms — deepfakes, algorithmic discrimination, opaque high-stakes decisions — don't wait for legislatures, and regulators who move only after a harm has already made headlines end up writing worse law under public pressure. A framework built now, with structured industry and civil-society input, is more likely to be calibrated than one drafted in crisis mode later. NAIO's own mandate, as AI Malaysia Berhad describes it, is to "lead, coordinate, and accelerate the nation's AI ecosystem" toward an AI Nation 2030 vision — which means the office has an institutional incentive to avoid overshooting into a framework that chills the investment it's also trying to attract.

What's Actually in the Draft

The Bill's architecture is, on the whole, proportionate. It sorts AI systems into three risk tiers, per Rahmat Lim & Partners' summary of the consultation paper: Tier 1 covers systems intentionally designed to cause harm, which are prohibited outright; Tier 2 covers systems with foreseeable unintended harm, subject to documentation and controls; Tier 3 covers systems with no material foreseeable risk, which carry only baseline obligations. That's a meaningfully lighter touch than a blanket compliance regime — most everyday AI deployment (chatbots, recommendation engines, internal analytics tools) should land in Tier 3 and face minimal friction.

Oversight runs through a new Central AI Authority with three functions, as Baker McKenzie's analysis lays out: AI Safety (risk frameworks and incident oversight), Investigation and Enforcement, and AI Enablement — the last of which includes running the AI Sandbox, a controlled testing environment explicitly aimed at letting SMEs experiment with AI applications without absorbing the full weight of Tier 2 documentation obligations up front. Two roles carry the actual duties: Developers, who "materially shape" what a system can do, and Deployers, who put it into real-world use. Both must show "due regard" to five principles — human dignity, transparency, accountability, safety, and data governance — a formulation that leaves room for proportionate compliance rather than prescriptive checklists, closer to the EU AI Act's risk-based spirit than its rulebook density.

"One vocabulary for the actors, one assessment per system, one filing per incident" is how Edwin Lee & Partners framed the goal that should guide the Bill's integration with Malaysia's existing Personal Data Protection Act, Cyber Security Act, and Online Safety Act — avoiding duplicate compliance regimes for the same conduct.

Where the Draft Falls Short of Its Own Logic

The gaps are less about the framework's shape than about who it actually binds. Edwin Lee & Partners' submission to the consultation flags that the Bill doesn't clarify whether it applies to government entities at all — a serious omission given that public agencies are increasingly the ones deploying AI in welfare screening, policing, and service delivery, precisely the high-stakes contexts the risk tiers exist to catch. An AI law that quietly exempts the state while binding private Developers and Deployers inverts the accountability logic it's built on.

The second gap cuts against the Bill's extraterritorial reach. It applies to AI systems developed or deployed anywhere and used in Malaysia — yet, per the same submission, the definitions were drafted "without evidence of how its central definitions land" on foreign developers, who are likely to be the primary regulated party for any Malaysian business building on a US or Chinese foundation model. A Bill that regulates overseas AI labs without their meaningful input at the definitional stage risks vague compliance triggers that Malaysian Deployers — often the SMEs the sandbox is meant to help — inherit by default when their upstream vendor doesn't bother to adapt.

There's also an unresolved legal question sitting underneath the whole framework: whether scraping public web data for model training is lawful under the PDPA in the first place. NAIO can build as elegant a risk-tier system as it likes, but if the underlying data-lawfulness question stays "genuinely arguable and undecided," as the submission puts it, Developers face compliance uncertainty no incident-reporting duty can fix.

The Stakes for AI Nation 2030

Malaysia's digital economy contributed 25.5% of GDP in 2025, against a government target of 30% by 2030, and Digital Minister Gobind Singh Deo has tied that growth explicitly to the National AI Action Plan. A risk-tiered, sandbox-enabled framework is a defensible way to pursue that target without regulatory whiplash. But proportionality has to apply symmetrically — to the state as much as to startups, and to the foreign labs the law claims jurisdiction over as much as to the Malaysian SMEs it's designed to protect. NAIO should resolve the government-use and PDPA-training-data questions, and run a second consultation round aimed squarely at foreign Developers, before the Bill is tabled.

Sources & Citations

  1. Ministry of Digital: AI Governance Bill consultation announcement
  2. AI Malaysia Berhad (National AI Office)
  3. Rahmat Lim & Partners: NAIO consultation paper summary
  4. Baker McKenzie: Malaysia AI Governance Bill consultation
  5. The Star: Digital economy on track for 30% of GDP by 2030
  6. Edwin Lee & Partners: AI Governance Bill consultation submission