Consultation Information

Ministry/Agency Ministry of Digital - Not Applicable
Consultation Period 10/07/2026 - 01/08/2026 Closed
Consultation Stage Pre-drafting
Classification Digital technology and innovation

Purpose

As part of a series of public consultations, the National AI Office (NAIO) invites stakeholders to provide feedback on the proposed AI Governance Bill, which aims to establish a comprehensive, coherent, and future-ready AI governance framework for Malaysia. The proposed framework is intended to support the responsible development, deployment, and use of Artificial Intelligence (AI) while keeping pace with rapid technological advancements and increasing AI adoption across all sectors.

The proposed Bill seeks to establish central institutional oversight, introduce principle-based national governance requirements, and implement a risk-based regulatory framework to ensure proportionate regulation. By clearly defining the roles and responsibilities of AI actors, the framework aims to promote a safe, responsible, and trustworthy AI ecosystem that balances innovation with the protection of individuals, society, and national interests.

Your feedback is essential in ensuring that the proposed framework is practical, effective, and responsive to the needs of industry, developers, deployers, researchers, civil society, government, and the wider public.

Please fill in the google form attached to share your thoughts.

Affected Stakeholder

  1. Members of the public
  2. Private sector organisations (SMEs and large enterprises)
  3. Academia and research institutions
  4. Professional bodies and Industry associations
  5. Civil society organisations (CSOs) & Non-governmental organisations (NGOs)
  6. Government ministries and agencies
  7. Statutory bodies and regulators
  8. Other interested organisations or individuals.

Documents

Main Consultation Document
Public Consultation Paper of the Proposed Artificial Intelligence (AI) Governance Bill_ 10 JULY 2026_.docx.pdf
Main Consultation Document â€ĸ 0.34 MB
Download
Questionnaire Document_Proposed Artificial Intelligence (AI) Governance Bill_Public Consultation_ 10 JULY 2026_.docx.pdf
Main Consultation Document â€ĸ 0.35 MB
Download
Summary of the Proposed Artificial Intelligence (AI) Governance Bill_Public Consultation_ 10 JULY 2026_.pdf
Main Consultation Document â€ĸ 2.89 MB
Download

Have Your Say

Share your thoughts and feedback

Engage with stakeholders and provide administrative oversight on feedback.

Top 5 Comments

Most liked comments from this consultation

Showing 5 of 66 comments
AN
Anonymous
July 31, 2026

I write as an ordinary Malaysian citizen, with a particular interest in Sabah, in response to the National AI Office's public consultation on the proposed AI Governance Bill. I welcome the government's effort to regulate artificial intelligence responsibly, and I support the Bill's stated goals of protecting human dignity, ensuring transparency, and enabling innovation. However, I am compelled to raise concerns about a significant and, in my view, unaddressed gap: the Bill's silence on Sabah's distinct constitutional position within the Federation of Malaysia.

Sabah did not join Malaysia as an ordinary state. It entered the Federation in 1963 under the Malaysia Agreement 1963 (MA63), a founding compact that secured specific safeguards not extended to the Peninsular states — safeguards touching native law and custom, native courts, land administration, immigration control, and religious and educational arrangements. These are not historical footnotes; they are live, constitutionally recognised protections that shape how federal policy must engage with Sabah.

Having reviewed the three consultation documents released to date — the Bill summary, the consultation paper, and the questionnaire — I find no reference whatsoever to Sabah, Sarawak, MA63, native customary rights, native courts, or any mechanism for state-federal consultation. This silence matters because AI systems, once deployed, will inevitably touch domains that Sabah's institutions constitutionally administer: land classification and Native Customary Rights determinations, native court processes, indigenous languages and cultural data, and delivery of public services in rural and interior communities. A national framework built around a single federal Central AI Authority, with "Sectoral Leads" defined only as unspecified "public bodies," offers no visible guarantee that Sabah's state government or state agencies will have a formal voice before instruments affecting these domains are issued.

I am not asserting that the Bill is unconstitutional, nor am I qualified to make that determination. My concern is narrower and, I believe, more urgent given the consultation's closing date of 31 July 2026: that Sabah's special position be explicitly acknowledged, and that concrete safeguards — consultation requirements, an expanded definition of harm that captures loss of customary rights, and protection for indigenous data and languages — be built into the Bill before it is finalised, rather than assumed or left to be read in afterward. Malaysia's history since 1963 shows that such assumptions are not always honoured in practice.

The recommendations that follow are offered in that spirit: not to obstruct a bill I broadly support in principle, but to ensure that as Malaysia regulates a powerful new technology, it does so in a way that respects the terms on which Sabah joined the Federation, and protects the rights of its citizens and indigenous communities as fully as those of any other Malaysian.

CH
Chai Fei Fong
July 31, 2026

Dear AI Policy Team,

On behalf of Randy labs, we appreciate the opportunity to provide comments on the public consultation paper for the draft AI Governance Bill. Please find attached Randy labs' written submission in response to the public consultation on the proposed AI Governance Bill.

We commend the Government of Malaysia for its commitment to establishing a robust AI governance framework that supports innovation while fostering trust, accountability, and responsible AI development. We believe that a clear and forward-looking regulatory framework will be instrumental in advancing the aspirations of Malaysia's AI Nation 2030 agenda by enabling the responsible adoption of AI, strengthening public confidence, and enhancing the nation's global competitiveness.

To that end, our single most important recommendation is that the Bill be drafted for international interoperability, so that compliance in Malaysia builds on the international frameworks that companies operating across the EU and ASEAN have already implemented, rather than requiring a separate, Malaysia-specific compliance regime. As the first binding omnibus AI law in ASEAN, the Bill can set the regional standard — and an interoperable, investment-friendly law is precisely what will attract the AI developers, cloud providers, and enterprise adopters whose presence drives Malaysia toward the top tier of global AI nations. A Bill that mirrors the EU AI Act and the ASEAN Guides turns compliance from a barrier into a signal that Malaysia is open for responsible AI business.

Yukino Chai, APAC Ops Lead
Randy labs

KE
Kennedy John Michael Anbumani
July 31, 2026

The single biggest concern are the constitutional safeguards that should be embedded as foundational in the bill. This bill represents the first step in a seachange on how human civilizations and nation states will engage with technology in multilateral and multidimensional ways that we cannot yet meaningfully imagine. We are as a species sorely outpaced by technology and innovation even at present. We are still finding ways to clean up the messes we created since the industrial revolution. This is a warning that if we are to transition safely to a new way of being in a world and life dominated by technology, one that can mimic us in all but autonomy and agency, we must learn from the past that Human Cognitive Sovereignty must be supreme in this bill. As it is we have lived experience of continuous abuse by government and corporations on a constant basis which we cannot even remedy. Hence it is necessary to place the oversight of this bill on an Ombudsman and Parliamentary oversight with a rollback feature that allows us to escape the limitations of abrogation by law that too often it not expedient or sufficient to instantly stop harms. The folly of rushing this bill without a thorough review of the bill before it is even presented for first reading will be evident the same way the URA, CCUS, FoI and NCC demonstrated. It is strongly advised that the same is not done with this bill.

WA
WAN ZURAINI MAHRAWI
July 31, 2026

FATAL SILENCES - The Proposed AI Governance Bill gets the ARCHITECTURE RIGHT and the ACCOUNTABILITY WRONG — it builds a Central AI Authority, a five-principle baseline, and a three-tier risk framework, but leaves five critical mechanisms unspecified: no independent check on the Authority itself, no personal remedy behind its promise of "redress," an "unacceptable risk" tier that only catches AI built to harm rather than AI that does harm, no requirement that high-risk systems be validated before they go live, and no answer for foundation models whose failures a Malaysian Deployer will be left holding alone. A governance bill that regulates everyone except the regulator, and remedies the system before it remedies the citizen, is a framework built to detect harm — not to prevent it.

AN
Anonymous
July 31, 2026

AI innovation must be allowed uninterrupted. It is not merely a tool or even technology, it's the future of mankind. What the country needs is a society that goes back to upholding the basics like core values and beliefs. These are the only guardrails moving forward in an AI-era. Sociologists need to be urged to focus on reconstructing ways how values can (re)learnt, cultured and ingrained into the nation-building efforts. Technocrats and policymakers then device a framework based on data and insights how best to live, work and thrive in an AI-era. Governing AI is too superficial moving forward because just as we fail to govern ethics, we will come to the same fate with AI. The only optimal strategy forward is to adapt to AI evolution and pathway. It is only by adapting vs mitigating AI human race will always be at least one step ahead of the many AI-driven technologies.

GR
GREENPEACE MALAYSIA
July 31, 2026

To Whom It May Concern,

Please find attached GREENPEACE MALAYSIA's consultation response regarding it.
As a campaigning organization for environmental justice for a thriving planet. We aim to protect what matters most: people, planet, and our shared future. Our Key demands are to ensure the use of Artificial Intelligence (AI) remains within the Justice, Equity, Diversity, Inclusion, and Safety (JEDIS) principles. Push for better policies, and collaborate with communities to build people-powered solutions. Every action is a step toward a greener, fairer future.

We appreciate the opportunity to share our consultation feedback on the proposed National AI Bills, and welcome further discussions and clarifications if required.

AN
Anonymous
July 31, 2026

Appreciate the opportunity given to provide feedback on the AI Governing Bill. Please find attached Duopharma comment from angle of local Pharmaceutical industry.

AN
Anonymous
July 31, 2026

I welcome the opportunity to comment on the proposed AI Governance Bill, and support its direction — particularly the Central AI Authority / Sectoral Lead architecture and the inclusion of near misses in incident reporting.

My submission addresses one structural gap.

Principle 5 governs the quality of data but not its structure. Quality, integrity, provenance and security are necessary but not sufficient. A dataset can satisfy all four and still fail to partition the inference space without gaps or overlaps. When it does, the system fails systematically rather than randomly — and no amount of testing, documentation, human oversight or incident reporting will detect it before the harm occurs. This is a data architecture problem, not a data quality problem, and it sits upstream of every other obligation in the Bill.

Four mechanisms inherit the gap:

1. Principle 3's "clear and traceable chain of accountability" has nothing to attach to at the handoff between chained AI systems.
2. The Developer/Deployer taxonomy is a single-system construct. It has no home for the party who deploys System A and thereby shapes System B's data source — which is where the risk is actually created.
3. Outcome-based risk tiering will classify structurally deficient cascades as Tier 3, because they perform acceptably until stressed.
4. Incident reporting presumes an observable event. The most dangerous agentic failure mode produces none.

The attached submission sets out six drafting-level amendments. The central one is five words: add "and structural completeness" to Principle 5, and make it certifiable. Annex A provides a computable, non-proprietary metric — cheap to run, and checkable by a supervisor who is not a machine learning specialist — so the requirement is auditable rather than aspirational.

Malaysia can lead here: neither Singapore's control-based agentic framework nor the EU AI Act specifies a computable structural precondition.

I am available to NAIO without fee for a technical session or drafting assistance.

Reto Gruenenfelder
ITAI Advisory
reto@itaiadvisory.com

TE
Ted Chan Kar Tat
July 31, 2026

From the AI Governance team of Puncak AI, we would like to thank AI Malaysia Berhad (formerly NAIO) the opportunity to provide our feedback. Please find attached our response.

TE
Teo Xiang Zheng
July 31, 2026

We appreciate the opportunity to share our consultation feedback and welcome further engagements for discussions and clarifications.
Please find attached our collective responses to your questionnaire.

AN
Anonymous
July 31, 2026

As an ordinary Malaysian who uses e-commerce, banking apps, and government portals daily, I know what it feels like when my data is harvested without real understanding, when algorithms profile me invisibly, and when "consent" is just a pre-ticked box. This Bill is our chance to stop Malaysia from becoming a playground for data farming; the mass extraction of personal data to train AI; without legal guardrails. We must learn from Europe's risk-based framework and go further where needed.

Malaysia has made progress. MOSTI's 2024 AI Governance & Ethics (AIGE) guidelines established seven principles, and the PDPA (Amendment) Act 2024 introduced mandatory Data Protection Officers and breach notifications. But AIGE remains voluntary; companies can ignore it. The PDPA was not designed for AI; it does not address how my photos, writing, or biometric data are scraped from the internet, fed into foundation models, or used to deny me loans or jobs. This Bill must make AI-specific data protections legally binding.

My first demand is meaningful consent. No company should use my personal data to train AI unless I give specific, informed, opt-in consent; not a blanket opt-out buried in fine print. The Bill must prohibit publicly scraped personal data for AI training without explicit consent, require training data provenance reports, and grant citizens a "right to be forgotten" for AI models; with technical standards to enforce deletion.

Second, ban or strictly regulate AI practices that threaten dignity. The EU AI Act prohibits social scoring, real-time biometric surveillance in public spaces, and emotion recognition in workplaces. I support the same for Malaysia: prohibit facial recognition tracking in malls and protests; ban employers from using AI to scan my emotions; outlaw AI-generated intimate imagery; and strictly regulate biometric categorization by race or gender. These practices reduce human beings to data points, violating the Bill's own Human Dignity principle.

Third, transparency. I have a right to know when AI is judging me. The Bill must mandate clear "This is AI" disclosures for chatbots and virtual assistants; machine-readable labels on all AI-generated content; and human-understandable explanations when AI denies my loan, rejects my job application, or flags my account.

Fourth, human oversight. For high-risk decisions affecting employment, credit, housing, healthcare, or migration, there must always be a meaningful right to human review; not an appeal to another algorithm. The proposed Central AI Authority must audit whether oversight is genuine or a rubber-stamp.

Fifth, cross-border data protection. The PDPA 2024 tightened data transfers, but many AI services still process Malaysian data overseas. The Bill must require AI training on Malaysian personal data to occur either domestically or in jurisdictions with equivalent protection (like the EU), with no loopholes for "legitimate business interests."

Please see document below for full feedback.

AN
Anonymous
July 31, 2026

Thank you for the opportunity to provide feedback. Please find attached UNICEF Malaysia's feedback.

JU
Jure Kralj
July 31, 2026

FAO: Malaysian National AI Office

We welcome the opportunity to provide feedback in relation to Malaysia's proposed AI Governance Framework.

Please find attached the consultation response submitted by The International Confederation of Music Publishers ('ICMP') and the Music Publishers Association of Malaysia ('MPA Malaysia').

DI
Dineshwara Naidu
July 31, 2026

On behalf of the Malaysian Media Council (MMM), please find attached our submission to the public consultation on the proposed AI Governance Bill. We've focused our response on three components: the AI Governance Principles, the AI Risk Framework, and AI Incident Reporting, as these are where the media sector can offer the most grounded, sector-specific input.

Our central argument is this: the Bill's principle-based, risk-tiered approach is sound, but it needs sector-specific translation to work in practice and the media sector is a clear case study of why. Specifically, we raise a gap in the Bill's harm taxonomy: the four proposed harm categories (death, bodily injury, deprivation of liberty, contravention of written law) do not clearly capture harm to information integrity and public trust, even though this is a real and increasingly urgent risk as AI becomes embedded in how the public accesses and consumes information.

We also illustrate why clear, traceable accountability between developers and deployers matters, and why pre-deployment testing and impact assessment would meaningfully strengthen the Bill. We also recommend the Bill's own proposed AI Sandbox be explicitly widened to serve this pre-deployment assurance role.

Finally, we've noted that the Council, given its existing Code of Conduct and grievance mechanism, is well positioned to serve as a Sectoral Lead for the media and information domain, consistent with the Bill's own architecture.

We hope this is useful to the National AI Office's continued development of the Bill, and we remain available to discuss any of these points further.

AN
Anonymous
July 31, 2026

Workday is pleased to provide comments on the National AI Office’s (NAIO) Public Consultation Paper on the AI Governance Bill (Consultation Paper). Workday welcomes NAIO’s initiative to establish a coherent, principle-based and risk-based framework for AI governance in Malaysia. A national baseline, complemented by sectoral expertise and practical implementation support, can promote trustworthy AI while enabling organisations to innovate responsibly.

We support regulation that is technology-neutral, proportionate to demonstrable risk, internationally interoperable and practical for organisations that develop, provide, and deploy AI-enabled products and services across borders. We appreciate the Consultation Paper's recognition that accountability should follow a party's actual degree of control over decisions and actions throughout the AI lifecycle.

Our comments draw on the policy positions Workday has advanced in AI-governance engagement in other key markets: risk-based, use-context-sensitive requirements; clear allocation of obligations across the AI value chain; workable incident reporting; importance of interoperability, and meaningful stakeholder engagement.

MI
Michael East
July 30, 2026

Medical Protection Society welcomes the opportunity to provide feedback on the proposed Artificial Intelligence (AI) Governance Bill.

Overall, we support the proposed Bill and commend the Malaysia Government and the National AI Office (NAIO) for taking the steps to develop a comprehensive legal framework for AI systems throughout their entire lifecycle.

As an organisation representing over 350,000 healthcare professionals in Malaysia and across the world, our comments in the attached submission focus on ensuring that the proposed Bill and the framework appropriately reflect the unique risks associated with the use of AI in healthcare. AI has significant potential to improve healthcare by supporting clinical decision-making, improving administrative efficiency and enhancing patient outcomes.

A clear and proportionate governance framework is therefore essential to encourage innovation while maintaining public confidence and protecting patient safety. Our submission outlines a range of recommendations designed to achieve this.

SU
Suppiah & Partners Law Firm
July 30, 2026

Suppiah & Partners Law Firm welcomes the Ministry of Digital and the National AI Office’s initiative to develop the proposed Artificial Intelligence (AI) Governance Bill. The proposed Bill is a timely and important step towards establishing a clear national framework that supports responsible AI development and adoption, manages emerging risks and provides greater regulatory certainty to organisations and the public.

Suppiah & Partners Law Firm has submitted its detailed responses through the official Google Form under the name of Suppiah & Law. The firm has also attached a consolidated summary of its key recommendations for consideration through the Unified Public Consultation platform.

Across the six focus areas, our recommendations are guided by the need for the final framework to be clear, proportionate, practical and capable of being implemented consistently across sectors.

In particular, the Bill should provide clear legal definitions and practical guidance so that organisations can determine whether a technology falls within its scope, whether they are acting as a Developer or Deployer, how an AI System should be classified and what obligations apply. The respective roles of the Central AI Authority and Sectoral Leads should also be clearly defined, with a lead-regulator mechanism to prevent overlapping or duplicative assessments, reporting obligations, investigations and enforcement actions.

Regulatory requirements should reflect the seriousness and likelihood of potential harm. Minor administrative, procedural or technical breaches that do not cause significant harm should not automatically result in a high-risk classification or external incident reporting. At the same time, Developers and AI service providers should provide Deployers with sufficient information on intended use, known limitations, material risks and significant updates so that risks can be properly assessed and managed.

The framework should also include appropriate review and appeal mechanisms, protect legal professional privilege, client confidentiality, trade secrets and cybersecurity-sensitive information, and preserve accessible complaint and redress channels for affected persons.

Finally, implementation should be phased and supported by clear guidance, practical examples, templates, assessment tools, transition periods, regulatory enquiry channels and proportionate assistance for SMEs and organisations with limited technical resources.

Suppiah & Partners Law Firm appreciates the opportunity to contribute to this consultation and welcomes further engagement with the Ministry of Digital and NAIO in the continued development of Malaysia’s AI governance framework. Please refer to the attached submission for the firm’s detailed recommendations across all six focus areas.

AN
Anonymous
July 30, 2026

IFRAME NETWORK SDN. BHD. welcomes the National AI Office's initiative to introduce a comprehensive Artificial Intelligence Governance Bill and appreciates the opportunity to participate in this public consultation. We believe the proposed Bill represents an important milestone in establishing Malaysia as a trusted, innovative and globally competitive AI nation.

We support the proposed principles-based and risk-based approach to AI governance, as it provides the flexibility needed to accommodate rapidly evolving technologies while ensuring appropriate safeguards for individuals, organisations and society. The establishment of a Central AI Authority, together with Sectoral Leads, can strengthen coordination, improve regulatory consistency and provide greater certainty for organisations developing and deploying AI solutions.

To ensure successful implementation, the framework should remain technology-neutral, practical and proportionate to the level of AI risk. Regulatory obligations should encourage responsible innovation without creating unnecessary barriers, particularly for startups, SMEs and organisations adopting lower-risk AI systems. Clear implementation guidance, sector-specific best practices, model governance templates and capacity-building programmes will be essential to support compliance across different industries.

We also support the proposed AI Risk Framework, AI Incident Reporting Mechanism and AI Sandbox as important components of a modern AI governance ecosystem. These initiatives should encourage continuous learning, responsible experimentation and collaboration between government, industry, academia and civil society. Regulatory sandbox programmes, in particular, can accelerate innovation while allowing regulators to better understand emerging technologies and develop evidence-based policies.

Malaysia should continue aligning its AI governance framework with recognised international standards and best practices to facilitate cross-border collaboration, strengthen investor confidence and improve the global competitiveness of Malaysian businesses. The framework should also be reviewed periodically to remain responsive to technological developments and evolving societal expectations.

Finally, we encourage continued investment in AI talent development, digital infrastructure, research, public awareness and industry collaboration to ensure the benefits of AI are widely shared across society. IFRAME NETWORK SDN. BHD. looks forward to supporting the Government and the National AI Office in building a trusted, responsible and future-ready AI ecosystem that strengthens Malaysia's digital economy and positions the nation as a recognised leader in artificial intelligence within ASEAN and on the global stage.

AN
Anonymous
July 30, 2026

The proposed Bill establishes a coherent and internationally-aligned starting point for AI governance in Malaysia, combining institutional oversight, principle-based regulation, and a risk-tiered approach. This submission does not contest that overall architecture. Instead, it identifies specific areas of ambiguity, gaps, or design choices that could be exploited, create enforcement difficulty, or unintentionally under-protect the public if left unaddressed in the final Bill.
The key concerns raised in this submission are:
â€ĸ Definitional gaps ("material effects", "material AI harm") that leave core obligations without a workable trigger.
â€ĸ A Personal Use exemption that could be used to shield the creation of harmful AI outputs later distributed publicly.
â€ĸ No allocation rule for liability across multi-party AI supply chains, including open-weight/open-source models.
â€ĸ A harm taxonomy in the Risk Framework that omits significant categories of harm (economic, discriminatory, psychological, privacy, systemic/societal).
â€ĸ Absence of self-classification safeguards, reporting timelines, and whistleblower protections in the Incident Reporting mechanism.
â€ĸ No due process, appeal, or judicial review provisions attached to the Central AI Authority's enforcement powers.
â€ĸ A potential conflict of interest where the same Authority is responsible for both enabling innovation (sandbox) and enforcing compliance.
â€ĸ No sandbox exit/graduation criteria or cap on real-world exposure during testing.

AN
Anonymous
July 30, 2026

QDR Labs submits the following observations on the incident-definition, reporting-threshold, and evidentiary-duty provisions of the proposed Bill.

We recommend six measures:

R1. Define a minimum reconstructable PROPERTY SET for any reportable incident — eight properties: (a) actor, (b) authority, (c) action, (d) policy, (e) decision basis, (f) resource touch, (g) lifecycle context, (h) verification strength. This vocabulary is drawn from published, openly licensed work and is proprietary to no vendor.

R2. Allocate each property explicitly between Developer and Deployer so neither assumes the other holds the record. Developers must ensure systems can EMIT properties (c), (d), and (e). Deployers must CONFIGURE and RETAIN properties (a), (b), (g), and (h).

R3. Keep the property set UNIFORM across risk tiers. Scale retention period and attestation cadence instead. This is simpler to draft, simpler to supervise, and harder to arbitrage than tiered scope.

R4. Attach the duty to the record a Deployer can OBTAIN, and treat contractual evidence-access rights as a condition of lawful deployment. Without this, extraterritorial scope is stated but not exercisable.

R5. Align the AUTHORITY property early with jurisdictions already converging on it — China (rules in force 15 July 2026), Singapore (IMDA framework), and the United States.

R6. Do not duplicate Bank Negara Malaysia's RMiT. Where an entity already reports an incident under an existing sectoral instrument, the same record should satisfy this Act provided the eight properties are present — one record, two supervisors.

These recommendations are grounded in peer-reviewed research: Agarwal, Agarwal & Nene, "The AI Regulatory Readiness Index (ARRI)", Computer Law & Security Review 61 (2026) 106340; and Solozobov, "DEMM-Bench", arXiv 2606.20634.

We would provide a reference incident-record structure to the Authority at no cost, and would participate in any technical working group the Authority convenes.

Full submission attached as file.

Muhammad Marzuqee bin Nasruddin
QDR Labs ¡ Damansara Utama ¡ Selangor
info@qdrlabs.co
31 July 2026

AN
Anonymous
July 30, 2026

Comments of The Center for AI and Digital Policy (CAIDP) to the National AI Office of Malaysia in response to AI Governance Bill The Center for AI and Digital Policy (CAIDP) welcomes the opportunity to provide comments from the National AI Office (NAIO) of Malaysia on the draft AI Governance Bill’s public consultation paper. CAIDP Recommendations 1. AI Governance Architecture: Build an independent, transparent, and accountable Central AI Authority. 2. AI Governance Principles: Align principles with international law and implement them fully and immediately. 3. AI Risk Framework: Create clear red lines and broaden the definition of harm. 4. AI Incident Reporting: Ensure transparency and accountability for AI failures. 5. AI Sandbox: Integrate mechanisms for public participation into the AI Sandbox. About CAIDP CAIDP is the largest independent, non-profit AI policy research and education organization with a global footprint across 130 countries and a network of more than 2,000 experts . CAIDP’s mission is to ensure that AI and digital policies promote a better society, more fair, more just, and more accountable – a world where technology promotes broad social inclusion based on fundamental rights, democratic institutions, and the rule of law. CAIDP provides expert guidance on AI policy to governments and international organizations, including UNESCO, OECD-GPAI, the Council of Europe, G7 and G20, and the European Parliament. CAIDP publishes the CAIDP AI Index, which is the most comprehensive global assessment of national AI policy and practice measured against democratic principles.4 The 2026 CAIDP Index recognizes Malaysia’s National AI Office (NAIO) 's efforts to establish a comprehensive and coherent governance framework that ensures the responsible and trustworthy use of AI in Malaysia through central institutional oversight, principle-based baselines, and risk-based, proportionate regulation. Nevertheless, the country's rapid digital transformation introduces critical challenges, particularly regarding mass surveillance, algorithmic transparency, and the safeguarding of individual digital rights. We thank you for considering our contributions. We welcome the opportunity to engage and discuss these recommendations in further detail.

AN
Anonymous
July 30, 2026

Comments of The Center for AI and Digital Policy (CAIDP) to the National AI Office of Malaysia in response to AI Governance Bill The Center for AI and Digital Policy (CAIDP) welcomes the opportunity to provide comments from the National AI Office (NAIO) of Malaysia on the draft AI Governance Bill’s public consultation paper. CAIDP Recommendations 1. AI Governance Architecture: Build an independent, transparent, and accountable Central AI Authority. 2. AI Governance Principles: Align principles with international law and implement them fully and immediately. 3. AI Risk Framework: Create clear red lines and broaden the definition of harm. 4. AI Incident Reporting: Ensure transparency and accountability for AI failures. 5. AI Sandbox: Integrate mechanisms for public participation into the AI Sandbox. About CAIDP CAIDP is the largest independent, non-profit AI policy research and education organization with a global footprint across 130 countries and a network of more than 2,000 experts . CAIDP’s mission is to ensure that AI and digital policies promote a better society, more fair, more just, and more accountable – a world where technology promotes broad social inclusion based on fundamental rights, democratic institutions, and the rule of law. CAIDP provides expert guidance on AI policy to governments and international organizations, including UNESCO, OECD-GPAI, the Council of Europe, G7 and G20, and the European Parliament. CAIDP publishes the CAIDP AI Index, which is the most comprehensive global assessment of national AI policy and practice measured against democratic principles.4 The 2026 CAIDP Index recognizes Malaysia’s National AI Office (NAIO) 's efforts to establish a comprehensive and coherent governance framework that ensures the responsible and trustworthy use of AI in Malaysia through central institutional oversight, principle-based baselines, and risk-based, proportionate regulation. Nevertheless, the country's rapid digital transformation introduces critical challenges, particularly regarding mass surveillance, algorithmic transparency, and the safeguarding of individual digital rights. We thank you for considering our contributions. We welcome the opportunity to engage and discuss these recommendations in further detail.

AJ
Aja Rangaswamy
July 30, 2026

Dear AI Policy Team,
Please find attached Midships' written submission to the public consultation on the proposed AI Governance Bill.
I attended the stakeholder workshop in Kuala Lumpur earlier this month and contributed to the breakout session on definitions and scope. This submission develops points raised there and responds to all six focus areas in the consultation paper.
We support the three approaches the Bill proposes: central institutional oversight leveraging existing sectoral regulators, a principle-based instrument, and proportionate risk-based obligations. Our comments are about mechanism rather than direction, and are made from the perspective of a firm that builds AI-enabled systems which clients then operate.

Thanks
Aja

MI
Michelle Leblond
July 29, 2026

29 July 2026
TO: policy@ai.gov.my
SUBJECT: PBSA Response to Public Consultation Notice on the Proposed Malaysia AI Governance Bill
Thank you for your time and we appreciate the opportunity to introduce PBSA and provide feedback on the consultation related to AI Governance.
The Professional Background Screening Association (PBSA) appreciates the opportunity to provide feedback on the proposed Bill. As a global non-profit organisation representing over 750 member companies engaged in background screening across six continents, PBSA is committed to advancing ethical standards, compliance, and data protection. Our members conduct background vetting for employment, volunteer, residence/tenant, promotion, due diligence and other opportunities.
Organisations conduct background searches to ensure integrity in their operations, create a safe work environment and preserve public safety, manage their reputation, protect their assets, and meet regulatory requirements, among other reasons. Members of the PBSA can be verified here. A key role of our Association is also to communicate with and educate, our members on changes to data use protocols, and to advocate for efficient and effective processes for the organisations we serve. It is from this educational standpoint that we come to you in this correspondence.
We support the Ministry’s efforts to provide practical guidance on the use of AI. The document appropriately recognizes the need to balance innovation with privacy protection and acknowledges the technical realities of AI development and deployment. In particular, the guidance on stakeholder responsibilities, data retention, and the challenges associated with access and correction requests is helpful.
Below we provide answers to the specific questions posed in the Public Consultation document.
Respectfully submitted,
APAC Council, Government Relations Committee
c/o michelle.leblond@thepbsa.org
Michelle Leblond - Director of Operations, PBSA

AN
Anonymous
July 29, 2026

We commend the National AI Office (NAIO) and the Ministry of Digital for initiating this important public consultation on the proposed Artificial Intelligence (AI) Governance Bill.

People Decoder Pte. Ltd. fully supports the proposed Bill and believes it provides a strong foundation for responsible, trusted and innovation-enabling AI adoption in Malaysia.

Our attached submission presents an implementation perspective that is often under-represented in policy discussions—how organisations operationalise AI governance once legislation is in place. Drawing on practical experience supporting organisations in AI readiness, organisational transformation and AI implementation, we identify common organisational challenges and offer six recommendations to strengthen implementation across organisations of different sizes and levels of AI maturity.

Rather than commenting on legislative drafting, our submission focuses on practical organisational implementation. We hope the implementation observations and recommendations contained in the paper will contribute constructively to the development of an AI governance framework that is practical, proportionate and supports Malaysia's ambition to become a trusted regional AI leader.

We appreciate the opportunity to participate in this consultation and thank the National AI Office for inviting public feedback.

AN
Anonymous
July 29, 2026

To whom it may concern:

Xperientia has been at the forefront of conducting and creating AI Ethics and Risk Awareness training. This includes the identification of regulatory gaps. We have been working with compliance professional and recently published the book, The Full Stack AI Ethicist. Attached are some considerations for Malaysia's governance plans.

Regards

Adam Khan

AR
ARULNAGESWARAN ARULESWARAN
July 29, 2026

Thank you for the opportunity to contribute to the public consultation on Malaysia's proposed AI Governance Bill. Having reviewed the consultation paper, we believe the proposed governance architecture provides a strong foundation for responsible AI adoption. This position paper respectfully offers one additional perspective: that the human–AI interaction boundary, where judgement, authority and accountability are exercised, merits explicit consideration as a governance domain. We hope this submission contributes constructively to the ongoing development of Malaysia's AI governance framework.

CH
Chang Yin Jue
July 29, 2026

Written in my personal capacity as co-founder of Otti NeuroLearning Institute, founding member of the HumAIne Movement, and part of the AI @ Planetary Health Working Group, which has sent its own statement.

What I have paid attention to in this Bill is what happens to the person on the other end of a system, rather than the institutions that will run it.

Full detail is in the attached document. A summary of the main points:

1. Give people rights they can actually use. The right to be told, at the time, that they are dealing with an AI System. Where a high-risk system helps decide something about them, the right to a plain explanation of what the system did and what the main factors were. The right to have a human look at it again, someone who can change the answer. The right to argue back.

2. Ban the worst design methods outright. Right now the top tier of risk only catches systems built with an intent to cause harm, which almost nothing is. It should also catch reasonably foreseeable effect, and it should name what is banned: systems that use hidden, manipulative or deceptive methods to wear down a person's ability to make an informed decision, and systems that take advantage of someone because of their age, a disability, or their financial situation.

3. Count psychological and cognitive harm as harm, including emotional dependence on AI. The four categories of harm in the paper are all things that happen fast and can be pointed at. Slow damage is missing entirely. That includes systems built to keep people talking to them, which should carry duties on how they are designed rather than waiting for proof of what they do to people over ten years.

Two shorter notes in the attachment: people need all of this in the languages they actually read, and the words "child" and "minor" do not appear anywhere in the paper.

The EU AI Act and China's new rules on AI anthropomorphic interactive services already do versions of all three. Article references are in the document.

Thanks for reading.

WO
Wong Wai San
July 28, 2026

Dear NAIO colleagues,

The Business Software Alliance (BSA) is pleased to submit the attached comments in response to the public consultation by the National AI Office (NAIO) on the public consultation paper regarding the AI Governance Bill.

Our submission is attached in PDF format, with the same submitted via email.

We thank the NAIO for the opportunity to provide feedback and would be pleased to discuss our comments in a follow-up meeting.

Best regards,
Wai San


Wai San Wong (she/her)
Director, Policy - APAC
Business Software Alliance
P +65 9729 1253
bsa.org

ES
Esther Ong
July 28, 2026

Please find attached herewith our letter which is self-explanatory, Thank you.

K
K V Soon
July 27, 2026

Thank you for this initiative. The way AI is going, we need good and strong governance strategies and we strongly support the Government's move to introduce a national AI governance framework.

We feel that the process needs to be careful and consultative and consider the fact that the technology is evolving and few truly can say for sure the shape of the future AGI or something else. A careful and phased thought process is more important than finalising the bill and setting up the AI Authority. We need to be able to run the marathon of AI governance and not just sprint to a short finish line.

I have shared a phased approach and some more items to be considered.

Thank you

AH
Ahmad Firdaus Bin Ahmad Azman
July 27, 2026

Thank you NAIO and relevant ministries for the engagement and public consultation. Please refer to the attached for my comments and suggestions.

AN
Anonymous
July 27, 2026

I checked all the comments. No one seems to have used AI (or admitted to doing so) to submit their response. So I asked Claude to have a look at the documents. These are the resulting views I was sent by Anthropic:

**What's right about it**

The risk-based, principle-based structure is sound. Trying to write rigid technical definitions into primary legislation at this stage would be a mistake; AI moves too fast for that. The Developer/Deployer split anchored to degree of control is also sensible in principle, and the sandbox mechanism is the right instinct: better to test uncertain applications in a controlled space than either ban outright or let them loose unchecked.

**Where it falls short**

Three things stand out to me as genuine weaknesses, not just quibbles.

First, the harm taxonomy is too narrow. Limiting "unacceptable risk" to death, bodily injury, unlawful activity and property damage misses most of how AI actually harms people day to day: discrimination in hiring or credit decisions, financial loss, psychological harm, erosion of democratic trust, misinformation at scale. Several submitters flagged this and they are right. A framework that only catches physical harm is built for the AI of ten years ago.

Second, there is no defined role for the person affected by an automated decision. The Bill regulates Developers and Deployers, but the individual whose loan gets refused or whose benefits get cut appears only as a source of complaint data after the fact. That is backwards. If Principle 1 says people should not be reduced to data points, the Bill needs to give them an actual right, not just a grievance channel.

Third, and this is the one I find most consequential: the environmental footprint of AI is entirely absent from the five governance principles. Data centres draw heavily on energy, water and land. A Bill that claims to future proof Malaysia's AI ecosystem but says nothing about the physical infrastructure underpinning it is missing half the picture. This is not a side issue. It goes to whether AI development in Malaysia is sustainable in the literal sense of the word.

**The bigger structural point**

The "due regard" compliance standard is self-assessed and point in time. Models drift, data ages, and real world use creeps past what was originally approved. A framework that checks compliance once at deployment and then trusts self-reporting thereafter is not proportionate to how these systems actually behave over time.

**My overall take**

The bones are good. The architecture, the risk tiers, the sandbox, the intent to coordinate centrally while allowing sectoral expertise, all of that is the right shape. But right now it reads as a framework built to manage risk to individuals and institutions, with planetary and environmental risk treated as an afterthought rather than a core principle. Given where this consultation is being hosted and who is reading it, that gap is worth naming plainly rather than softening.

AN
Anonymous
July 27, 2026

Dr. Salasiah Abbas, CEO of SOVA Intelligence (M) Sdn Bhd, a Malaysian AI company, welcomes this consultation and attach our position paper, "Building Malaysia's AI Future," for the Panel's consideration.

We strongly support the Government's move to introduce a national AI governance framework, and believe safety, accountability and transparency must remain its foundation. At the same time, we believe the Bill should not only regulate AI, but also create the conditions for Malaysian AI companies to thrive.

We have applied these principles throughout our responses in this consultation. We believe responsible governance and strong AI innovation can grow together, and we welcome further engagement with the Panel.

BA
Balakrishnan Rajagopal
July 26, 2026

Welcome strongly on this legislation. Suggestion as per attachment, kindly consider adopting if relevant. Thank you for the opportunity.

TA
TANG CHEE LIAN
July 26, 2026

(Super Urgent Revisions Required for the Proposed AI Governance Bill)
While we strongly welcome the introduction of the AI Governance Bill as a crucial step toward regulating our digital future, we must express our deep concern over severe legal gaps within the current draft. If left unaddressed, the net effect of this legislation will not be better regulation, but a disastrous diminishment, and even potential disappearance, of any high-quality AI development in our ecosystem.

Most alarmingly, the Bill leaves the two largest players in the AI value chain unaccountable for liability: government entities (including Ministries and Government-Linked Companies) and the banking industry. As the primary funders and specifiers of AI platforms, these "Principals" dictate project requirements. By excluding them from the legal definitions of both "deployers" and "developers," the Bill creates a dangerous loophole. Principals may refuse to absorb the additional costs required for strict governance, effectively forcing developers to either execute non-compliant instructions or lose their business. Furthermore, this shields procurement officers within government agencies from accountability, allowing the continued acquisition of ungovernable AI systems.

Additionally, the Bill’s framework for harm and risk is very fundamentally and legally flawed. Its harm categories fail to recognize critical, holistic societal damages, specifically the loss of wealth, intellect, and lineage. Moreover, by basing risk classifications strictly on intended uses, the framework ignores unintended systemic risks, leaving susceptible and vulnerable communities entirely out of the loop and unprotected.

The current draft also diminishes the vital role of Sectoral Leads. By downplaying their domain-specific technical expertise and bypassing existing gazetted regulations, the Bill loses essential industry context, and jeopordize any enforce-ability. Furthermore, the legislation glaringly lacks a "safe harbour" provision. If an unforeseen misfortune occurs despite a developer achieving full governance compliance, they are offered no legal protection by this Bill.

A bill that shifts massive, disproportionate liability entirely onto developers without rewarding and protecting compliance will force the market to stifle innovation. To be fair, equitable, and effective, this Bill requires severe rework. We urge lawmakers to address these critical blind spots to foster an AI ecosystem that is both truly safe and highly innovative. We have submitted our comment in the online form and sincerely hope these legal loopholes are to be fixed super-urgently.

GE
Geetha Nadarajan
July 26, 2026

welcome the National AI Office’s initiative to develop a national Artificial Intelligence Governance Bill. A principle-based, risk-based framework is an important step towards building trust, encouraging innovation, and strengthening Malaysia’s digital competitiveness.
As Artificial Intelligence becomes embedded within enterprise operations, governance should not be viewed solely as a regulatory obligation. It should become an organisational capability that enables innovation while protecting citizens, businesses, and national interests.
Based on enterprise AI governance experience across multiple industries, I respectfully submit the attached recommendations for consideration.

SH
Sharuna Verghis
July 24, 2026

Please see the attached submission addressing Focus Areas 1, 3, 4 and 6.

I support the proposed Bill and its proposals on national coordination, sectoral leadership, proportionate regulation, incident reporting and controlled testing. The Bill would be stronger if it stated clearly the social purposes that should guide the development and use of AI in Malaysia: strengthening human capabilities, reducing avoidable inequities, protecting ecological systems and serving the public interest.

My submission calls for community-led governance in healthcare and education with affected communities involved in setting priorities, deciding whether AI is appropriate, identifying harms and assessing outcomes. Equity should be explicitly incorporated into the final Bill and its sectoral instruments, supported by disaggregated reporting on access, benefit, misclassification and exclusion.

I also support the submission by the AI @ Planetary Health Working Group in Malaysia, particularly its call for double literacy within the AI Enablement function and for broader recognition of collective, cumulative and context-specific harms. Sandboxes should support community-led initiatives without weakening protections and advance socially useful work that may not attract conventional commercial investment.

SU
SUJATHA GANASEGERAN
July 22, 2026

Protection for Children & Vulnerable Persons

Children require a higher standard of protection because they may be less able to understand AI-generated content, manipulation, data collection, or automated decisions.

AN
Anonymous
July 21, 2026

Malaysia’s proposed Artificial Intelligence (AI) Governance Bill is a crucial step toward shaping a safe, ethical, and sustainable AI ecosystem. As AI becomes deeply embedded in daily life, economic systems, public services, and global digital infrastructure, governance must extend beyond sector‑specific risks and address the broader implications for human wellbeing, societal stability, and planetary sustainability. A comprehensive ESG‑aligned approach is essential to ensure that AI contributes positively to Malaysia and the world.

From an Environmental (E) perspective, AI systems consume significant computational resources, driving energy usage and carbon emissions. As Malaysia expands its digital infrastructure and AI adoption, the Bill should encourage responsible energy practices, including efficient model design, sustainable data‑centre operations, and transparency around environmental impact. AI can also support environmental protection such as climate modelling, disaster prediction, and resource optimisation but governance must ensure these benefits are realised without creating new ecological burdens.

The Social (S) dimension is central to AI governance. AI influences how people access healthcare, education, financial services, employment opportunities, and public assistance. Poorly governed AI can amplify inequality, reinforce bias, or harm vulnerable communities. The Bill should require fairness testing, inclusive design, and protections against discriminatory outcomes. It must also safeguard mental and emotional wellbeing by preventing manipulative AI behaviour, misinformation, and harmful automated decisions. Human dignity must remain at the core: AI should enhance human capability, not replace human judgment in high‑stakes decisions affecting livelihoods, rights, or safety.

Under Governance (G), accountability, transparency, and ethical oversight are essential. AI systems evolve rapidly, and frequent updates can destabilise operations, create inconsistent outcomes, or introduce new risks. The Bill should mandate structured change‑management processes, clear documentation, and continuous monitoring. Responsibility for harm must be clearly defined, especially when AI systems are developed by third‑party vendors. Shared liability frameworks, contractual safeguards, and recourse mechanisms are necessary to ensure fairness and prevent concentration of risk on deployers alone.

Finally, the Bill should promote global alignment, recognising that AI impacts transcend borders. Malaysia’s governance framework should encourage international cooperation, ethical standards, and cross‑border learning to ensure AI contributes positively to global human wellbeing and environmental sustainability.

A holistic ESG‑aligned AI Governance Bill will help Malaysia build an AI ecosystem that is safe, fair, sustainable, and centred on human flourishing.

NI
Nishaline Priya A/P Pubalan
July 21, 2026

I support the direction of the proposed Artificial Intelligence (AI) Governance. However, the success of the legislation will ultimately depend on whether Malaysia can translate stand for HUMAN RIGHTS, not against but complementing AI? Who is governing the AI? Who audits them? Who is responsible and how risks are assessed? What controls must exist and how AI systems are tested and HOW ARE HUMANS AFFECTED BY AI?

I have shared three grounds to consider about this bill.
1. AI governance must be designed around all affected stakeholders, particularly individuals. Is the system fair? Is it fair to humans?

2. Malaysia should also develop a national AI assurance and testing capability. Singapore provides a useful regional reference – the AI Verify. Malaysia does not necessarily need to replicate that model, but should consider developing an interoperable national toolkit aligned with AIGE, the AI Technology Action Plan 2026–2030 and international standards. This gap is also an opportunity for Malaysia to become an early mover in ASEAN AI assurance, since we also recently signed the WAIC 2026 (to which Singapore didn’t sign). We can be a big player in ASEAN in terms of AI Adoption and AI Governance.

3. If this bill is passed and comes into effect, sensitive and high-risk sectors should be subject to stronger governance and assurance requirements. ISO/IEC 42001 should be considered as one recognised pathway for organisations operating high-risk AI systems, while professional competency requirements should be established. Malaysia needs to professionalise AI governance.

DU
Dustin Chung
July 18, 2026

I am glad that the government has opened this draft up for public comments, and I hope that they truly read them all and consider all feedback, as it comes directly from the people of the nation they are meant to serve.

I have attached my personal thoughts as a document~

AN
Anonymous
July 18, 2026

I am writing from a health informatics perspective and attached an opinion covering Focus Areas 2, 3, 5, and 6. My core point:
1) the Bill correctly places accountability on the Deployer rather than the individual worker, but needs to specify what that requires in practice — proper training, clear protocols, and monitored overrides/near-misses with preventive action.
2) I also flag staffing/workload as a factor outside the Deployer's control (especially where workforce sits with JPA), the need for protected good-faith reporting, patient-facing transparency, an internal escalation path feeding back to Developers, and Deployer-side local validation in the Sandbox so smaller facilities aren't left behind.

AN
Anonymous
July 17, 2026

Public Consultation Feedback: Proposed Artificial Intelligence (AI) Governance Bill
Position: Strongly Against the Bill in its Current Form

1. Failure to Address Severe Environmental Harm
While the proposed bill establishes a risk-based framework to allow the legal deployment of "High-Risk" (Tier 2) AI systems, it completely ignores the physical infrastructure driving them. The aggressive expansion of data centers required for Large Language Models (LLMs) and Generative AI is severely degrading the quality of life for local residents. The rapid construction of these facilities has accelerated deforestation, disrupted ecosystems, and put an unsustainable strain on our national grid and water security. The bill's risk framework must explicitly classify severe environmental degradation and resource depletion as an "Unacceptable Risk" (Tier 1) category rather than treating ecological collapse as a secondary concern outside the scope of AI safety.

2. Downgrading Local Creative Talent and National Reputation
By delegating powers to sectoral leads and establishing permissive deployment rules, this bill actively paves the way for the government's uncritical adoption of Generative AI in public sector projects. This demonstrates a blatant lack of appreciation for our local talent, particularly in fields like graphic design and the creative arts. Replacing human creators with algorithmic tools defunds our cultural economy. Furthermore, relying on cheap, AI-generated assets for official government initiatives severely downgrades our country’s reputation internationally. Instead of presenting ourselves as a sophisticated digital hub, we look like a joke to our own citizens who expect high-quality, authentic human craftsmanship from their leaders.

3. Flawed Institutional Focus and Inadequate Protections
While the bill allows the creation of a Central AI Authority and an "AI Sandbox" to foster commercial innovation, its institutional focus is deeply flawed. Technology should serve the welfare of the people and protect the planet, not just chase corporate trends or tech-monopoly marketing. Artificial intelligence is much more than just frontier LLMs sold by the loudest bidder. If this Bill does not include strict statutory limitations on data center carbon/water footprints, and robust legal protections for local human workers against AI displacement, it fails the fundamental pillars of sustainable development.

Conclusion:
I am strictly against the passage of this Bill in its current form. The framework prioritizes technology deployment and corporate experimentation at the absolute cost of our environment, our local creative talent, and our national dignity. I urge the Ministry of Digital and the National AI Office (NAIO) to halt this trajectory and completely re-evaluate the true socio-environmental and cultural costs of GenAI before proceeding with any legislation.

DR
Dr. Mukhtar Sadykov
July 17, 2026

As someone who previously studied in Malaysia, I am particularly pleased to see the country developing its own approach to AI governance. I am currently working in Kazakhstan’s law enforcement system, and my doctoral research focused on the legal, organisational and operational aspects of using AI in law enforcement. I therefore offer these comments from both a research and practical perspective.

The proposed risk-based approach is a sound starting point. In my experience, however, the main difficulty is not setting out general principles, but making them work when an AI-supported decision affects a real person.

For high-risk systems, particularly those used by public authorities, law enforcement agencies, border services or the justice system, human oversight should not become a formal box-ticking exercise. There should be a clearly identified officer or official who understands the limitations of the system, can verify its output and has the authority to disregard it.

Risk classification should also take into account the area of use, the sensitivity of the data, the degree of autonomy and the possible consequences for an individual. A system may create a serious risk even when it was introduced for a legitimate purpose and no harm was intended.

Kazakhstan’s recent regulatory experience has also shown the importance of transparency, explainability and preserving meaningful human decision-making. Malaysia could strengthen the proposed framework by requiring impact assessments for high-risk systems, records of human review and clear procedures for challenging decisions made with the assistance of AI.

For me, the central question is practical. When an AI-supported decision affects a person’s rights, liberty or legal status, can we establish who actually made the decision, what information was relied upon and how that decision can be reviewed?

ZU
Zulkifli Musa
July 17, 2026

Thank you for providing this platform for public feedback. Here are my 10-point comments (I have also submitted my answers via the feedback form):

1. Retain the proposed principle-based and risk-based approach, with obligations proportionate to the level of risk and the organisation’s actual control over the AI system.

2. Provide clear definitions, thresholds, practical examples and decision tools to help organisations distinguish AI systems from ordinary software and identify their roles as Developers, Deployers or both.

3. Support the governance principles with sector-specific guidance, checklists, templates, training and clear advisory channels.

4. Include explicit consideration of fairness and non-discrimination, information integrity, intellectual property, confidentiality, research integrity, authorship and public trust.

5. Broaden the proposed categories of harm to include financial loss, reputational harm, privacy breaches, discrimination, misinformation and other significant non-physical harms.

6. Assess AI risk according to the severity, likelihood, scale, duration and reversibility of harm.

7. Avoid excessive compliance burdens, inconsistent classification and over-regulation of low-risk uses. Requirements should be proportionate to organisational role, size and capacity.

8. Clarify responsibility where organisations use third-party AI systems that they did not develop and cannot fully inspect or control.

9. Establish the AI Sandbox as a controlled environment to test uncertain applications, identify risks and unintended consequences, and refine safeguards before wider deployment.

10. Ensure the Sandbox has clear entry and exit criteria, protects confidential information and intellectual property, assigns responsibility for harms, and remains accessible to universities, public institutions and smaller organisations.

AN
Anonymous
July 17, 2026

As an ordinary public citizen. There are many who are better able to suggest and recommend policies, checks & balances, good governance, etc.
But as Rakyat Malaysia, all I ask is:
1. Ensure to include and consider all 3 pillars of Sustainable Development (remember that whatever we develop today, is always borrowing from future generations)
2. Enforcement of penalties and/or management mechanisms, grievance and remediation processes
3. Maintain good actionable practices

The MADANI government is not showing good practices in how it is using LLMs and Generative AI.
Artificial intelligence is so much more than just the frontier LLMs or whomever has the best marketing strategy to sell their Generative AI at the cheapest price. Especially so, when the negative impacts are affecting 2 out of 3 pillars of Sustainable Development. Rich billionaires might be able to buy their way out of problems. But the rest of "us poorer folks", including future generations cannot survive on tokens and scarcity of water.

I'm sure we can observe and learn from all the good examples, and especially the worst examples, when the primary driver of AI (Gen AI) is only money. (and probably the power to control its users after that)

CO
Cornelia C. Walther
July 17, 2026

Submitted by the Proocial AI 4Planetary Health Working Group in Malaysia

We welcomes the proposed Artificial Intelligence Governance Bill as a necessary step toward safe, responsible and innovation-enabling AI. We support the Bill's institutional architecture, principle-based approach and risk-based framework. Malaysia needs clear national coordination, sectoral interpretation, practical guidance, incident reporting and sandboxes that allow innovation while protecting people and public trust.

We recommend four refinements.

The Bill rightly identifies human dignity and agency as a core principle. However, human oversight is meaningful only when people have the capacity to understand, question and intervene. Malaysia should embed human literacy, which strengthens judgment, attention, ethical reasoning and responsibility; and algorithmic literacy, which enables users, procurers, regulators and affected communities to understand what an AI system optimises for, whose interests it serves, what data it uses, and how it may shape the human ability to think, feel and act autonomously (so-called ‘double literacy’). To make accountability meaningful his should be a requirement for public-sector training, procurement guidance, organisational risk assessments and human-oversight requirements.

Second, the Bill should include explicit requirements to protect planetary health and treat the environment responsiby. The proposed principles address dignity, transparency, accountability, safety and data stewardship, but they do not pay due attention to the environmental footprint of AI. Energy demand, water use, emissions, hardware dependency, land impacts and e-waste are not secondary issues. They must be included as elements of AI governance. High-impact AI systems, especially those using significant compute or which are deployed at scale, should be required to disclose material environmental impacts and demonstrate proportionate mitigation. The risk framework must recognise and price in cumulative social-ecological harm, not only immediate physical or legal harm.

Third, Malaysia should adopt a practical way to measure AI, one that goes beyond simply calling it "responsible." We propose piloting the ProSocial AI Index as a shared dashboard to map, measure, monitor and manage AI systems across two dimensions. The first is how a system is built and run: is it designed for the people it serves, trained on data that fairly represents them, tested for its real social and environmental effects before and after launch, and aimed at outcomes that someone actually keeps watching. The second is what the system is for: its stated purpose measured against what it actually does, how it treats the people who use it, the prosperity it creates or takes away, and its toll on the planet. This would let regulators, deployers and boards see clearly whether an AI system builds human capability, earns institutional trust, spreads prosperity, and protects the planet.

AI governance should not merely prevent harm after deployment; it should guide design, procurement and scaling toward systems that restore capability, reduce exclusion and respect planetary boundaries. Regenerative intent should be built into the algorithmic architecture of Malaysia's hybrid future.

Fourth, the Bill should do more than manage risk. It should be prosocial, setting a positive direction, ensuring AI in Malaysia serves people and the planet, not just profit.

AN
Anonymous
July 16, 2026

This submission is made in the capacity of an individual member of the public with a mixed/neutral stance flagging technical and practical issues. Detailed submission is emailed to policy@ai.gov.my
Overall position: Broadly supportive of the Bill's three-pronged approach — institutional oversight, principle-based regulation, and risk-based obligations — as sound and internationally aligned, but argues the gap between good architecture and workable law lies in operational detail left to future guidance.
Executive Summary — 15 key recommendations (R1–R15), drawing on comparative regulation from the EU AI Act, UK's sector-led model, Canada's failed AIDA bill, Singapore's IMDA framework, Australia's voluntary AI standards, and UK/Bank Negara sandboxes. Highlights include: a hybrid sector-led delegation model with codified coordination protocols between the Central AI Authority and Sectoral Leads; avoiding Canada's mistake of vague "high-risk" definitions; expanding the Bill's four harm categories (currently limited to death, bodily injury, deprivation of liberty, and breach of law) to include discrimination, financial harm, psychological harm, and environmental/democratic harm; fixing the "Tier 1 intent" loophole so unacceptable-risk systems are defined by practice, not provable intent; a voluntary safety standard with safe-harbour effect; mandatory PDPA-integrated bias audits; incident reporting integrated with the Cybersecurity Act 2024; a sandbox with a genuine graduation pathway; and an SME/academia enablement programme.
Part A answers all questions across the consultation's six official Focus Areas in full:
1. AI Governance Architecture — supports a Central AI Authority but demands statutory independence, clear primacy rules with Sectoral Leads, and a public register of applicable rules.
2. Scope of the Bill — supports the Developer/Deployer distinction anchored to degree of control, but flags gaps in defining borderline/hybrid AI systems, third-party foundation-model deployers, and extraterritorial thresholds.
3. AI Governance Principles — supports the five principles but proposes adding Fairness/Non-Discrimination and Environmental Sustainability as explicit principles, plus worked sector examples (finance, healthcare, e-commerce).
4. AI Risk Framework — the most detailed section, critiquing the narrow harm categories and intent-based Tier 1 trigger, and proposing mandatory impact assessments, public registration of high-risk systems, and periodic review cycles.
5. AI Incident Reporting — supports a national framework but pushes for near-miss reporting, whistleblower protections, and integration with existing breach-reporting regimes.
6. AI Sandbox — supportive but stresses the need for a defined exit/graduation pathway, subsidised SME/academic access, and PDPA safeguards during testing.
Part B adds cross-cutting recommendations: PDPA-AI integration, treatment of data centres and autonomous AI agents, deepfake/content-labelling rules, an SME compliance toolkit, and a phased implementation timeline with statutory review cycles.
The document is supported by a 26-item numbered reference list citing international frameworks and legal instruments. A later addendum incorporated lessons from Australia's 15 July 2026 national AI standards announcement.

YO
Yohann Azlee
July 15, 2026

Volley is an AI governance, risk and compliance advisory with offices in Australia and Malaysia. I write as its founder: an ISO/IEC 42001 Lead Implementer, a former group CEO and ASX-listed fintech operator, and a serving board director accountable for AI risk decisions. We advise boards, executives and regulated firms in both markets, and this submission brings that practice to the Malaysian context.

NAIO has built a sound architecture. The principle-based spine, the Developer and Deployer split by degree of control, the harm-anchored tiers and the sandbox are the right bones. The real risk from here is quieter: a framework that reads well on paper and never operates. We have watched capable organisations pass an assessment, file it, and drift. Three changes would close that gap.

First, govern the operation, not the assessment. "Due regard" as drafted is a point-in-time, self-assessed duty, yet the Bill's stated aim is to be proactive rather than reactive. High-risk AI does not hold still. Models update, data ages, and real use creeps past the purpose the system was approved for. For Tier 2 systems, require conformance to be demonstrable at the point of consequential use, through an audit trail, a human checkpoint and logging tied to the authorised purpose and risk boundary. Today that sign-off is filed once and rarely revisited.

Second, resource the AI Enablement function properly. It sits third behind Safety and Enforcement and reads as an afterthought. Malaysia's economy runs on SMEs, and a duty an organisation has no capacity to discharge becomes paper compliance. Enablement should ship reference operating models, a starter control set that scales by risk tier and organisation size, and templates a 20-person firm can actually run.

Third, make assurance count. Recognise established standards, ISO/IEC 42001 and the NIST AI Risk Management Framework, as a compliance safe harbour so firms already certified are not tested twice for the same thing. And give sandbox outcomes binding effect on exit, a provisional classification or safe harbour, so participation lowers a firm's regulatory risk rather than only informing policy.

Our attached submission develops these and adds four points: Tier 1 is gated by intent rather than severity, which lets a dangerous but non-malicious system fall short of "unacceptable"; the harm taxonomy is narrower than where AI harm actually lands, in credit, hiring and insurance decisions; the "resembles human cognition" definition can be gamed in both directions; and the Central AI Authority holds rule-making, enforcement and advice in one set of hands.

We would welcome the opportunity to contribute as the Bill moves to drafting.

Yohann Azlee
Founder, Volley
volley.cx

JE
Jemilah Mahmood
July 15, 2026

Tan Sri Jemilah Mahmood, Executive Director, Sunway Center for Planetary Health

I welcome Malaysia’s move to develop an Artificial Intelligence Governance Bill. This is an important national moment. AI is now part of how we learn, work, diagnose, govern, consume, communicate and imagine the future. The question is therefore whether Malaysia will shape it with wisdom, courage and a clear commitment to people, planet and public trust.

For me, responsible AI governance must start from a simple truth: technology is never neutral once it enters human life at scale. It changes incentives, habits, institutions and power. We have seen this in very clear and accelerating terms with the invention of personal computers, mobile phones, the internet, social media and now with AI. We also know that tech can widen opportunity, but it can also deepen exclusion and exacerbate vulnerability. It can support better decisions, but it can also weaken human judgement when people become passive users of systems they do not fully understand. It can improve efficiency, but efficiency without purpose is not progress.

The Bill must therefore go beyond compliance. It should create a practical framework that helps Malaysia map, measure, monitor and manage AI systems across their full life cycle. A risk-based approach is welcome, but risk must be understood broadly. We should consider not only data privacy, cybersecurity and misuse, but also impacts on human agency, social cohesion, mental health, jobs, inequality, democratic trust, climate and resource use. AI has a material footprint. Data centres need energy, water, land and minerals. A future-facing Bill should acknowledge this openly. The ProSocial AI Index piloted currently at Sunway University is one way of making responsible AI tangible and pragmatic.

Malaysia has the chance to lead by developing a governance model that is both innovation-enabling and deeply human. This means clear duties for developers, deployers procurers, and users of AI systems; transparent incident reporting; independent audits for high-impact use cases; meaningful human oversight; accessible complaint and redress mechanisms; and sandboxes that test not only technical performance, but real social consequences.

Just as importantly, the Bill should invest in literacy. People cannot exercise agency over systems they cannot question. We need double literacy: human literacy, to understand our values, biases, emotions and responsibilities; and algorithmic literacy, to understand the strengths, limits and influence of AI. This should be embedded in education, public service, business and community programmes.

Malaysia should not aim merely to adopt AI quickly. We should aim to adopt it conscientiously. A strong AI Bill can help ensure that technology serves people, and provides shared prosperity and planetary health. That is the standard we should set — not because it is easy, but because the future we are building will be shaped by the safeguards we put in place now.

DE
Devan Arumugam
July 15, 2026

This is my first pass review on your draft. Please read the exhaustive review. I will again hand in the 2nd or final pass in another few days. DEVCO represents not just an advisory and assurance firm in this niche but also a think tank via DEVCO Institute and we are also an MD status software development company specializing in Regulatory Technology and secure communications.

https://www.linkedin.com/pulse/malaysias-ai-governance-bill-must-act-nation-building-dr-devan-u8dyc/

LA
Laura Lyons
July 15, 2026

Thank you for the opportunity to review Malaysia's proposed AI Governance Bill as part of the public consultation process. Please see attached for recommendations and additional standards, frameworks, and approaches to consider.

AN
Anonymous
July 14, 2026

To whom it may concern. We would like to submit our feedback as in the file attached. The main take away is that we propose the establishment of a National AI Governance Deployment and Assurance Framework to complement the proposed Bill.

AN
Anonymous
July 13, 2026

Feedback on AI in the Arts Industry

Artificial Intelligence (AI) is no longer a distant concept in the creative arts—it is already embedded in the workflows of Grammy-winning producers, major label executives, and iconic artists. From Timbaland’s AI entertainment ventures to Grimes open-sourcing her voice, and even Randy Travis regaining his voice through AI, the technology is reshaping how music is created, distributed, and experienced. While public debates often question whether AI-generated works are “real art,” the reality is that AI is now a practical tool used across the industry. It is a future of today!

Opportunities and Benefits

1. Creative expansion: AI enables artists to explore new sounds, styles, and collaborations that may not be possible through traditional methods.

2. Accessibility: Independent musicians and smaller labels gain access to production-quality tools, lowering barriers to entry.

3. Preservation and restoration: AI can revive voices and performances, offering cultural and emotional value.

4. Efficiency: Streamlined workflows allow faster production and experimentation, supporting innovation, reducing creation and production costs.

Risks and Concerns

1. Intellectual property: Without clear regulation, AI-generated works risk infringing on existing copyrights or misusing artists’ likenesses.

2. Authenticity and trust: Audiences may feel misled if AI contributions are hidden or uncredited.

3. Economic impact: Fully-reliance on AI could reduce opportunities for human creators, especially session musicians and lyricists.

4. Ethical use of voices and identities: Cases like voice cloning demand strict consent and transparency.

Recommendations for Regulation

1. Transparency requirements: Works created or assisted by AI should be clearly labeled, ensuring audiences and stakeholders understand the role of AI. For example: FULL CREATION OF AI or MIXED CREATION BY HUMAN & AI.

2. Consent and licensing: Use of an individual’s voice, likeness, or style must require explicit permission and fair compensation.

3. Balanced copyright frameworks: AI-generated works should also be protected, as of human creators’ rights. A mixed system recognizing both human authorship and AI-assisted creation may be necessary. Human composers who subscribe to or utilize AI music and artwork generators as creative tools should be afforded EQUAL LEGAL RECOGNITION as those who employ modern instruments, applications, or systems in the creation of their works.

4. Industry standards: Establish guidelines for metadata, credits, and royalty flows to ensure fair distribution when AI is involved.

5. Education and awareness: Regulators should support initiatives that help artists, audiences, and businesses understand AI’s role, risks, and opportunities.

Conclusion

AI is neither a threat nor a miracle—it is a tool. The challenge for Malaysia’s creative ecosystem is to regulate AI in a way that protects artistry, ensures fairness, and embraces innovation. By setting clear standards for transparency, consent, and rights management, MPC can help the industry EVOLVE responsibly while safeguarding cultural integrity and ensuring that independent artists are not left behind.

AN
Anonymous
July 13, 2026

In addition to the proposed definitions and scope, the Bill should recognise the environmental impact of AI systems. High-compute AI models and data centres consume substantial amounts of electricity and water, particularly for cooling. The framework should encourage AI developers and deployers to adopt renewable energy where practicable, improve energy efficiency, and implement sustainable water management practices to protect clean water supplies. Environmental sustainability should be recognised as a cross-cutting consideration alongside safety, transparency, accountability, and human rights to ensure that AI development supports Malaysia's long-term sustainability goals.

The Bill may also consider proportionate exemptions for low-risk AI systems used for research, education, or personal, non-commercial purposes, provided they do not pose significant risks to individuals or society. This would avoid imposing unnecessary regulatory burdens while allowing innovation to flourish.

AN
Anonymous
July 12, 2026

I wish to commend the government for initiating the proposed AI Governance Bill and welcoming public feedback. It is refreshing to see an agile, principle-based baseline rather than rigid technical definitions that would quickly become obsolete.

Delineating the duties of "developers" and "deployers" based on their degree of control is a practical, real-world approach. Similarly, anchoring risk tiers directly to concrete legal and constitutional harms protects the public without strangling early-stage innovation. The supervised AI Sandbox is also an excellent touch, offering local startups and SMEs a vital space to safely test ideas while helping regulators close the knowledge gap in real time. By doing this, Malaysia has successfully synthesized the best elements of the EU AI Act, China's legislation model, Singapore’s enterprise-driven approach, and the US framework into a conceptually balanced, innovation-friendly architecture.

However, because the primary law relies so heavily on secondary guidelines to fill in the blanks later, the framework currently lacks the structural "teeth" needed to truly deter corporate negligence right out of the gate. To make this bill reliable, a few critical gaps must be addressed.

As a start, while the text outlines the AI Authority's power to issue administrative penalties, it leaves the actual limits completely open. I want to see clear, escalating penalty floors and ceilings codified directly into the law so that companies bypassing mandatory high-risk assessments face serious consequences.

On top of that, relying on the phrase "in accordance with applicable laws" under Principle 5 essentially kicks data privacy down the road to the existing Personal Data Protection Act (PDPA). The AI Bill should boldly stand on its own feet by explicitly stating that any AI models processing Malaysian citizens' Personally Identifiable Information (PII) must strictly respect local data sovereignty, prohibiting data usage outside the authorized purpose.

I also urge the government to introduce explicit safe harbors to protect local businesses (Deployers) who hook into global APIs (Developers). Without this, small local companies could easily be held legally liable for systemic biases embedded deep within a foreign tech stack that they have zero control over.

Additionally, the Bill must ensure absolute legal symmetry between the private sector and the state. As drafted, the AI Authority holds massive, concentrated powers—simultaneously managing the risk matrix, investigating incidents, and levying administrative fines. To prevent regulatory overreach or political weaponization, the Bill must mandate an independent judicial appeal mechanism so companies have immediate recourse to challenge interim orders before an objective tribunal.

Finally, the government cannot give itself an escape hatch. State agencies, statutory bodies, and government-linked companies must be held to the exact same compliance audits, incident reporting rules, and financial liabilities as private enterprises. The state must not hide behind sovereign immunity when its own AI deployments cause real-world harm. To reinforce this equity, the absolute exemption for "national security" must be tightly and narrowly redefined to prevent regular civil agencies from falsely branding invasive, poorly implemented AI tools under the banner of defense to dodge accountability.

AN
Anonymous
July 12, 2026

As a technology professional working in Malaysia's AI industry, I welcome the opportunity to provide feedback on the proposed AI Governance Bill. I support the Government's intent to establish Malaysia's first comprehensive statutory framework for AI, and I would like to share a few thoughts to help ensure the Bill achieves its goals of trust, safety, and innovation in a balanced manner.
I strongly support the Bill's adoption of a risk-based, proportionate regulatory model, consistent with the AI Risk and Classification Framework referenced by the Government. That said, I hope the classification criteria and compliance obligations for each risk tier will be published in clear, practical guidance well ahead of enforcement. Local SMEs and startups, which form the backbone of Malaysia's digital economy, have far less legal and technical capacity than large multinational developers, so compliance requirements such as incident reporting, documentation, and audits should scale with company size and risk exposure rather than apply uniformly. A regulatory sandbox or transitional grace period would also help businesses adapt their systems and processes before penalties take effect.
On the safety side, recent incidents involving the misuse of generative AI tools to produce non-consensual and explicit imagery in Malaysia show how urgent robust harm-prevention provisions really are. I support mandatory incident reporting and clear obligations on both developers and deployers to detect and mitigate misuse, including deepfakes and synthetic media targeting individuals. It would also help if the Bill explicitly cross-referenced and harmonised with the Personal Data Protection Act, the Online Safety Act framework, and MCMC's enforcement powers, so that companies aren't left navigating duplicative or conflicting obligations. Clear takedown timelines, victim redress mechanisms, and platform accountability standards should ideally be spelled out in the Bill itself rather than left entirely to subsidiary regulations.
At the same time, Malaysia's ambition to be a competitive regional AI and data centre hub depends on regulatory clarity that doesn't stifle innovation. I would encourage the Bill to designate NAIO as a clear central coordinating authority, so that overlapping or conflicting compliance demands don't arise from multiple sectoral regulators such as Bank Negara Malaysia, the Securities Commission, and MCMC governing the same AI system. Alignment with recognised international standards, such as the ISO/IEC AI standards referenced under MY-AI Standards, could also be treated as a safe harbour for compliance where applicable, so companies already certified internationally aren't forced through duplicate assessments. I'd also encourage continued industry consultation through the drafting of subsidiary regulations and technical codes, not just at this primary legislation stage.
Overall, I fully support the Government's effort to introduce a modern, risk-based AI Governance Bill. With calibrated compliance burdens, strong harm-prevention mechanisms, and coordinated, innovation-friendly enforcement, Malaysia can build a trusted AI ecosystem that protects citizens while remaining competitive regionally and globally. I look forward to further engagement with NAIO and the Ministry of Digital as the Bill progresses through drafting and parliamentary review.

MU
MUHAMMAD SUKRI BIN RAMLI
July 11, 2026

While the draft Bill does a great job setting up rules for Developers and Deployers, it currently lacks a defined mechanism for the individuals affected by automated decisions. If a Malaysian citizen is denied a critical public service by an AI, a high-level corporate checklist won't help them. In future I believe there will be more autonomous decision service that face citizen made by government and organisation that require check and balance.

To bridge this gap, I am sharing my writing on "The UX of Administrative Justice: Standardizing Citizen-Facing AI Decision Receipts in Public Sector Automation."

We suggest mandating a simple, readable AI Decision Receipt the exact moment someone is rejected by a government AI system. It gives citizens three clear things:

Input Snapshot: A quick look at the data the AI used, so the citizen can easily spot typos or old database errors.
Clear Breakdown: A visual explanation showing exactly which factors heavily influenced the AI's choice.
Next Steps: A plain-language guide on the minimum changes needed to get an approval next time.

It also includes a one-click button to instantly appeal to a human officer, backed by a "blind review" process so the officer doesn't just rubber-stamp the AI's mistake.

This moves AI governance from passive paperwork to real, everyday protection for Malaysians. The full paper is attached, and I would love to discuss how we can pilot this framework with the NAIO.

AN
Anonymous
July 11, 2026

the Bill assigns no role to the person affected by an AI system.
The draft defines two duty holders, Developer and Deployer. The individual affected by a system appears once, as a source of user complaint that the Authority may collect. The draft therefore covers the parties who build and operate AI systems, but assigns no defined role or right to the individuals those systems act upon.
This creates three problems.
It is inconsistent with the Bill's own principles. Principle 1 states that individuals must not be reduced to mere data points, yet the affected individual's only function in the draft is to supply complaint data. Principle 3 requires accountability to identifiable persons, yet the draft does not specify any accountable person at the moment an automated decision affects an individual.
It weakens early detection of harm. The risk and incident provisions are anchored to harms that have already occurred, and reporting flows mainly from Developers and Deployers. Self-reporting places the reporting duty on the party a report would expose. The draft does not provide for signals from affected individuals before harm occurs, although service systems already collect such signals in the form of rejected outcomes, repeat contacts, and abandoned interactions.
The personal-use exemption may widen the gap. The exemption for personal, family, or household affairs could be read to cover a resident using a private AI agent to interact with a public service. If so, citizen-facing government interactions would fall outside the Bill's protection.
Recognising the affected individual as a defined party, with a right to obtain review of an automated outcome by a person with authority to correct it, would close this gap and bring the operative provisions into line with Principles 1 and 3 as drafted.

CO
Cornelia C. Walther
July 11, 2026

Malaysia’s proposed AI Governance Bill sets in place a valuable architecture: risk tiers, a Central AI Authority, Developer-Deployer accountability, sandboxes. Two additions would carry that architecture from institutional oversight into lived protection for citizens navigating AI daily.
Individual agency erodes quietly under algorithmic systems. No single incident marks the moment a person stops deciding and starts merely accepting what an interface recommends; the shift happens recommendation by recommendation, largely unnoticed by the person it happens to. This harm sits outside the Bill’s current taxonomy of physical, legal, and reputational damage, though it shapes how most Malaysians will experience AI long before any incident report gets filed.
First: integrate Double Literacy into the Bill’s human oversight and public education provisions. Double Literacy names two capacities that grow together: Human Literacy, the deliberate cultivation of judgment, discernment, and self-knowledge that AI cannot substitute for, and Algorithmic Literacy, the ability to read how a system was trained, what it optimizes for, and where its blind spots sit. A population fluent in only one strand drifts. Citizens skilled at prompting a chatbot but blind to its incentive structure hand over agency without noticing the transfer. Citizens wary of algorithms but unable to name their own values default to whatever the interface suggests. The Bill’s principle-based language on “human oversight” stays abstract without a literacy requirement behind it. Embedding Double Literacy into school curricula, civil-service training, and the Sectoral Leads’ capacity-building mandates gives individual agency a concrete, teachable foundation rather than a hoped-for byproduct of good design.
Second: adopt the ProSocial AI Index as the national standard for AI procurement and public-sector policy making. The Index scores a system across four dimensions of build, Tailored, Trained, Tested, Targeted, against four dimensions of impact, Purpose, People, Prosperity, Planet. Sixteen cells replace the vague self-assessed “due regard” language currently proposed, giving procurement officers, auditors, and Sectoral Leads a shared, auditable grid instead of sixteen separate judgment calls made informally and inconsistently across ministries. Any agency buying or deploying AI could run a system through the same matrix a hospital, a bank, or a school uses, producing comparable results across sectors that the current Developer-Deployer split cannot deliver alone. A national standard here turns “trustworthy AI” from a slogan into a repeatable measurement, exportable as a model to ASEAN partners.
Together, these two additions answer the consultation’s own question about pathways from compliance to adoption. Double Literacy protects the citizen inside the system. The ProSocial AI Index gives government a concrete instrument for choosing which systems deserve public trust and public money.

https://www.psychologytoday.com/us/blog/harnessing-hybrid-intelligence/202605/ai-ethics-is-a-double-misnomer

VI
Vivegavalen Vadi Valu
July 11, 2026

Please find attached Trustethica’s submission on Malaysia’s proposed AI Governance Bill. It addresses a specific gap in prevailing AI governance approaches, where high-impact AI should not be treated as governed merely because it has been assessed or approved at a point in time. Deploying organisations should be able to demonstrate, at the moment of consequential use, that the system remains within its authorised purpose, authority and risk boundary.

The submission translates this principle into a technology-neutral operating model, concrete legislative language and a proposed 90-day pilot in a regulated Malaysian environment to establish what is technically enforceable, operationally proportionate and suitable for sector guidance.

We would value the opportunity to discuss how this approach could support NAIO in moving from policy principles to testable operational controls, and help establish Malaysia as a leader in practical, interoperable AI governance across ASEAN.

AN
Anonymous
July 11, 2026

I am concerned about government or ministry having central authority to levers and weights of AI being used in Malaysia because people should be free to pick their technology

AN
Anonymous
July 10, 2026

Good job NAIO. The proposed AI Governance Bill provides a strong and timely foundation for Malaysia’s AI governance. Several aspects are particularly positive:
It adopts a principle-based and risk-proportionate approach, allowing higher-risk systems to be subject to stronger safeguards without unnecessarily burdening lower-risk innovation.
- It recognises accountability across the AI lifecycle, including the distinct roles of Developers and Deployers.
- It proposes incident reporting, testing and sandboxes, which can support continuous learning, safer deployment and responsible experimentation.
- It also seeks to balance central coordination with sectoral expertise, which is appropriate given the different risks in areas such as healthcare, finance, transport and public services.
The following seven areas may merit further consideration as the Bill is refined:
Central and sectoral roles
1. Further clarity may be useful on how the Central AI Authority and Sectoral Leads will divide responsibilities, particularly for supervision, investigation and enforcement.
Breadth of the Central AI Authority’s mandate
2. The proposed Authority covers safety, enablement, investigation, enforcement and sandbox functions. Consideration may be given to whether sufficient functional separation, oversight and review mechanisms are needed to manage potential conflicts between these roles.
3. Regulatory interoperability
The Bill could further explain how it will interact with existing regulators and laws, and how conflicting or overlapping requirements will be resolved.
4. Definition of harm and unacceptable risk
Consideration may be given to whether the framework should more explicitly cover material economic, discriminatory, reputational, societal and systemic harm, beyond physical harm or breaches of existing law.
5. Foundation models and the wider AI value chain
The Developer–Deployer model is useful, but further guidance may be needed for foundation-model providers, fine-tuners, system integrators and other intermediaries.
6. Pathways from compliance to adoption
The standards, certification and sandbox mechanisms could be further developed as practical pathways to help organisations move safely from experimentation to deployment, especially for SMEs and Made-by-Malaysia AI solutions.
7. Adaptive review mechanisms
The Bill may benefit from clear periodic review arrangements so that incident data, sandbox experience, technology developments and international standards can inform future updates.

AN
Anonymous
July 10, 2026

The key risk in this Bill, once enacted, is that it will lower the tort standard applicable to AI Systems rather than raise it.

AI Systems, by virtue of their capacity to produce unanticipated outcomes even from fully deterministic processes, coupled with emergent properties of systems integration, warrant a higher standard of care under ordinary negligence than conventional software — yet the Bill's undefined, self-assessed "due regard" and "proportionate" language, combined with a harm taxonomy narrower than negligence's own recoverable damage categories, functions as a statutory carve-out that would hold Developers and Deployers to a weaker standard than they already face under existing Malaysian common law.

The "AI System" gate tests behavioural resemblance to human cognition rather than the mechanism that determines actual risk, and this produces gaming in both directions: a high-stakes, opaque scoring model can argue it doesn't "resemble cognition" and escape the gate entirely, while a low-stakes, fully deterministic system can be swept in on the strength of a conversational interface alone. This asymmetry favours sophisticated, well-resourced actors with the most at stake in being exempted from a statutory scheme that, properly designed, should be tightening their liability rather than loosening it.

This carve-out runs through the Bill's remaining structure as well. The five AI Governance Principles should not sit in primary legislation at all — taken at face value, they award a self-defined duty of care to Developers/Deployers, and the consultation paper's own justification for principle-based drafting (flexibility to issue guidance without amending the Act) concedes that the principles carry no operational content in the statute itself, meaning their only function there is symbolic. They belong in a Central AI Authority code of practice the Authority can revise on a short cycle, not in an Act Parliament must reopen.

In their place, the Bill's most useful role is elucidating how existing tort doctrine — foreseeability, proximity, causation, duty of care — applies specifically to AI Systems, rather than inventing a parallel statutory standard. The clearest example is liability attribution across complex, multi-actor systems integration. Even accepting the Developer/Deployer distinction as drafted, the Bill never states how liability apportions when a foundation model provider, a system integrator, and a Deployer each contribute to a single harmful outcome — the "degree of control" test allocates regulatory compliance duties, but not which actor bears responsibility for a specific harm once several actors' contributions interact. Singapore's IMDA is working through exactly this question for agentic AI, treating value-chain allocation by control, access to information, and proximity as an open private-law problem requiring deliberate resolution, and Malaysia's Bill would benefit from the same treatment rather than leaving the question implicit. No provision anywhere allows a binding, pre-deployment classification ruling on this or any other point of scope; self-assessment stands unreviewed until an incident occurs. The AI Sandbox is well placed to serve this function if the Bill gives it binding legal effect on exit.

Full response has been communicated in the Google Form.

AN
Anonymous
July 10, 2026

1. As an academician in AI and engineering, I welcome the proposed AI Governance Bill as a step towards responsible and trustworthy AI adoption in Malaysia.
2. I support the risk-based and principle-based approach.
3. The roles of the Central AI Authority and Sectoral Leads should be clearly defined to avoid overlapping responsibilities, inconsistent requirements and additional administrative burden.
4. Universities, researchers, professional bodies, industry, SMEs and civil society should remain actively involved in developing technical standards, implementation guidance and capacity-building programmes.
5. Accountability should reflect the actual control of each party, including developers, deployers, model providers, system integrators & organisations that modify/operate AI systems.
6. Practical guidance is needed on risk assessment, human oversight, documentation, data governance, cybersecurity, bias testing & redress mechanisms.
7. I support the AI Sandbox and incident-reporting mechanism, provided that they encourage learning.
8. Finally, the gov should publish a transparent summary showing how stakeholder feedback has influenced the final Bill.

No Surveys Available

Officer to Contact

AI Policy Department - National AI Office
Contact Person
policy@ai.gov.my
Email
03-21818090
Phone