Consultation Information

Ministry/Agency Ministry of Digital - Not Applicable
Consultation Period 10/07/2026 - 31/07/2026 Due in 8 days
Consultation Stage Pre-drafting
Classification Digital technology and innovation

Purpose

As part of a series of public consultations, the National AI Office (NAIO) invites stakeholders to provide feedback on the proposed AI Governance Bill, which aims to establish a comprehensive, coherent, and future-ready AI governance framework for Malaysia. The proposed framework is intended to support the responsible development, deployment, and use of Artificial Intelligence (AI) while keeping pace with rapid technological advancements and increasing AI adoption across all sectors.

The proposed Bill seeks to establish central institutional oversight, introduce principle-based national governance requirements, and implement a risk-based regulatory framework to ensure proportionate regulation. By clearly defining the roles and responsibilities of AI actors, the framework aims to promote a safe, responsible, and trustworthy AI ecosystem that balances innovation with the protection of individuals, society, and national interests.

Your feedback is essential in ensuring that the proposed framework is practical, effective, and responsive to the needs of industry, developers, deployers, researchers, civil society, government, and the wider public.

Please fill in the google form attached to share your thoughts.

Affected Stakeholder

  1. Members of the public
  2. Private sector organisations (SMEs and large enterprises)
  3. Academia and research institutions
  4. Professional bodies and Industry associations
  5. Civil society organisations (CSOs) & Non-governmental organisations (NGOs)
  6. Government ministries and agencies
  7. Statutory bodies and regulators
  8. Other interested organisations or individuals.

Documents

Main Consultation Document
Public Consultation Paper of the Proposed Artificial Intelligence (AI) Governance Bill_ 10 JULY 2026_.docx.pdf
Main Consultation Document â€ĸ 0.34 MB
Download
Questionnaire Document_Proposed Artificial Intelligence (AI) Governance Bill_Public Consultation_ 10 JULY 2026_.docx.pdf
Main Consultation Document â€ĸ 0.35 MB
Download
Summary of the Proposed Artificial Intelligence (AI) Governance Bill_Public Consultation_ 10 JULY 2026_.pdf
Main Consultation Document â€ĸ 2.89 MB
Download

Have Your Say

Share your thoughts and feedback

Engage with stakeholders and provide administrative oversight on feedback.

Allowed: PDF, DOC, DOCX, XLS, XLSX, PPT, PPTX, TXT, JPG, JPEG, PNG, GIF, ZIP, RAR (Max 10MB)
0 / 500 words
Showing 5 of 28 comments
SU
SUJATHA GANASEGERAN
July 22, 2026

Protection for Children & Vulnerable Persons

Children require a higher standard of protection because they may be less able to understand AI-generated content, manipulation, data collection, or automated decisions.

AN
Anonymous
July 21, 2026

Malaysia’s proposed Artificial Intelligence (AI) Governance Bill is a crucial step toward shaping a safe, ethical, and sustainable AI ecosystem. As AI becomes deeply embedded in daily life, economic systems, public services, and global digital infrastructure, governance must extend beyond sector‑specific risks and address the broader implications for human wellbeing, societal stability, and planetary sustainability. A comprehensive ESG‑aligned approach is essential to ensure that AI contributes positively to Malaysia and the world.

From an Environmental (E) perspective, AI systems consume significant computational resources, driving energy usage and carbon emissions. As Malaysia expands its digital infrastructure and AI adoption, the Bill should encourage responsible energy practices, including efficient model design, sustainable data‑centre operations, and transparency around environmental impact. AI can also support environmental protection such as climate modelling, disaster prediction, and resource optimisation but governance must ensure these benefits are realised without creating new ecological burdens.

The Social (S) dimension is central to AI governance. AI influences how people access healthcare, education, financial services, employment opportunities, and public assistance. Poorly governed AI can amplify inequality, reinforce bias, or harm vulnerable communities. The Bill should require fairness testing, inclusive design, and protections against discriminatory outcomes. It must also safeguard mental and emotional wellbeing by preventing manipulative AI behaviour, misinformation, and harmful automated decisions. Human dignity must remain at the core: AI should enhance human capability, not replace human judgment in high‑stakes decisions affecting livelihoods, rights, or safety.

Under Governance (G), accountability, transparency, and ethical oversight are essential. AI systems evolve rapidly, and frequent updates can destabilise operations, create inconsistent outcomes, or introduce new risks. The Bill should mandate structured change‑management processes, clear documentation, and continuous monitoring. Responsibility for harm must be clearly defined, especially when AI systems are developed by third‑party vendors. Shared liability frameworks, contractual safeguards, and recourse mechanisms are necessary to ensure fairness and prevent concentration of risk on deployers alone.

Finally, the Bill should promote global alignment, recognising that AI impacts transcend borders. Malaysia’s governance framework should encourage international cooperation, ethical standards, and cross‑border learning to ensure AI contributes positively to global human wellbeing and environmental sustainability.

A holistic ESG‑aligned AI Governance Bill will help Malaysia build an AI ecosystem that is safe, fair, sustainable, and centred on human flourishing.

NI
Nishaline Priya A/P Pubalan
July 21, 2026

I support the direction of the proposed Artificial Intelligence (AI) Governance. However, the success of the legislation will ultimately depend on whether Malaysia can translate stand for HUMAN RIGHTS, not against but complementing AI? Who is governing the AI? Who audits them? Who is responsible and how risks are assessed? What controls must exist and how AI systems are tested and HOW ARE HUMANS AFFECTED BY AI?

I have shared three grounds to consider about this bill.
1. AI governance must be designed around all affected stakeholders, particularly individuals. Is the system fair? Is it fair to humans?

2. Malaysia should also develop a national AI assurance and testing capability. Singapore provides a useful regional reference – the AI Verify. Malaysia does not necessarily need to replicate that model, but should consider developing an interoperable national toolkit aligned with AIGE, the AI Technology Action Plan 2026–2030 and international standards. This gap is also an opportunity for Malaysia to become an early mover in ASEAN AI assurance, since we also recently signed the WAIC 2026 (to which Singapore didn’t sign). We can be a big player in ASEAN in terms of AI Adoption and AI Governance.

3. If this bill is passed and comes into effect, sensitive and high-risk sectors should be subject to stronger governance and assurance requirements. ISO/IEC 42001 should be considered as one recognised pathway for organisations operating high-risk AI systems, while professional competency requirements should be established. Malaysia needs to professionalise AI governance.

DU
Dustin Chung
July 18, 2026

I am glad that the government has opened this draft up for public comments, and I hope that they truly read them all and consider all feedback, as it comes directly from the people of the nation they are meant to serve.

I have attached my personal thoughts as a document~

AN
Anonymous
July 18, 2026

I am writing from a health informatics perspective and attached an opinion covering Focus Areas 2, 3, 5, and 6. My core point:
1) the Bill correctly places accountability on the Deployer rather than the individual worker, but needs to specify what that requires in practice — proper training, clear protocols, and monitored overrides/near-misses with preventive action.
2) I also flag staffing/workload as a factor outside the Deployer's control (especially where workforce sits with JPA), the need for protected good-faith reporting, patient-facing transparency, an internal escalation path feeding back to Developers, and Deployer-side local validation in the Sandbox so smaller facilities aren't left behind.

AN
Anonymous
July 17, 2026

Public Consultation Feedback: Proposed Artificial Intelligence (AI) Governance Bill
Position: Strongly Against the Bill in its Current Form

1. Failure to Address Severe Environmental Harm
While the proposed bill establishes a risk-based framework to allow the legal deployment of "High-Risk" (Tier 2) AI systems, it completely ignores the physical infrastructure driving them. The aggressive expansion of data centers required for Large Language Models (LLMs) and Generative AI is severely degrading the quality of life for local residents. The rapid construction of these facilities has accelerated deforestation, disrupted ecosystems, and put an unsustainable strain on our national grid and water security. The bill's risk framework must explicitly classify severe environmental degradation and resource depletion as an "Unacceptable Risk" (Tier 1) category rather than treating ecological collapse as a secondary concern outside the scope of AI safety.

2. Downgrading Local Creative Talent and National Reputation
By delegating powers to sectoral leads and establishing permissive deployment rules, this bill actively paves the way for the government's uncritical adoption of Generative AI in public sector projects. This demonstrates a blatant lack of appreciation for our local talent, particularly in fields like graphic design and the creative arts. Replacing human creators with algorithmic tools defunds our cultural economy. Furthermore, relying on cheap, AI-generated assets for official government initiatives severely downgrades our country’s reputation internationally. Instead of presenting ourselves as a sophisticated digital hub, we look like a joke to our own citizens who expect high-quality, authentic human craftsmanship from their leaders.

3. Flawed Institutional Focus and Inadequate Protections
While the bill allows the creation of a Central AI Authority and an "AI Sandbox" to foster commercial innovation, its institutional focus is deeply flawed. Technology should serve the welfare of the people and protect the planet, not just chase corporate trends or tech-monopoly marketing. Artificial intelligence is much more than just frontier LLMs sold by the loudest bidder. If this Bill does not include strict statutory limitations on data center carbon/water footprints, and robust legal protections for local human workers against AI displacement, it fails the fundamental pillars of sustainable development.

Conclusion:
I am strictly against the passage of this Bill in its current form. The framework prioritizes technology deployment and corporate experimentation at the absolute cost of our environment, our local creative talent, and our national dignity. I urge the Ministry of Digital and the National AI Office (NAIO) to halt this trajectory and completely re-evaluate the true socio-environmental and cultural costs of GenAI before proceeding with any legislation.

DR
Dr. Mukhtar Sadykov
July 17, 2026

As someone who previously studied in Malaysia, I am particularly pleased to see the country developing its own approach to AI governance. I am currently working in Kazakhstan’s law enforcement system, and my doctoral research focused on the legal, organisational and operational aspects of using AI in law enforcement. I therefore offer these comments from both a research and practical perspective.

The proposed risk-based approach is a sound starting point. In my experience, however, the main difficulty is not setting out general principles, but making them work when an AI-supported decision affects a real person.

For high-risk systems, particularly those used by public authorities, law enforcement agencies, border services or the justice system, human oversight should not become a formal box-ticking exercise. There should be a clearly identified officer or official who understands the limitations of the system, can verify its output and has the authority to disregard it.

Risk classification should also take into account the area of use, the sensitivity of the data, the degree of autonomy and the possible consequences for an individual. A system may create a serious risk even when it was introduced for a legitimate purpose and no harm was intended.

Kazakhstan’s recent regulatory experience has also shown the importance of transparency, explainability and preserving meaningful human decision-making. Malaysia could strengthen the proposed framework by requiring impact assessments for high-risk systems, records of human review and clear procedures for challenging decisions made with the assistance of AI.

For me, the central question is practical. When an AI-supported decision affects a person’s rights, liberty or legal status, can we establish who actually made the decision, what information was relied upon and how that decision can be reviewed?

ZU
Zulkifli Musa
July 17, 2026

Thank you for providing this platform for public feedback. Here are my 10-point comments (I have also submitted my answers via the feedback form):

1. Retain the proposed principle-based and risk-based approach, with obligations proportionate to the level of risk and the organisation’s actual control over the AI system.

2. Provide clear definitions, thresholds, practical examples and decision tools to help organisations distinguish AI systems from ordinary software and identify their roles as Developers, Deployers or both.

3. Support the governance principles with sector-specific guidance, checklists, templates, training and clear advisory channels.

4. Include explicit consideration of fairness and non-discrimination, information integrity, intellectual property, confidentiality, research integrity, authorship and public trust.

5. Broaden the proposed categories of harm to include financial loss, reputational harm, privacy breaches, discrimination, misinformation and other significant non-physical harms.

6. Assess AI risk according to the severity, likelihood, scale, duration and reversibility of harm.

7. Avoid excessive compliance burdens, inconsistent classification and over-regulation of low-risk uses. Requirements should be proportionate to organisational role, size and capacity.

8. Clarify responsibility where organisations use third-party AI systems that they did not develop and cannot fully inspect or control.

9. Establish the AI Sandbox as a controlled environment to test uncertain applications, identify risks and unintended consequences, and refine safeguards before wider deployment.

10. Ensure the Sandbox has clear entry and exit criteria, protects confidential information and intellectual property, assigns responsibility for harms, and remains accessible to universities, public institutions and smaller organisations.

AN
Anonymous
July 17, 2026

As an ordinary public citizen. There are many who are better able to suggest and recommend policies, checks & balances, good governance, etc.
But as Rakyat Malaysia, all I ask is:
1. Ensure to include and consider all 3 pillars of Sustainable Development (remember that whatever we develop today, is always borrowing from future generations)
2. Enforcement of penalties and/or management mechanisms, grievance and remediation processes
3. Maintain good actionable practices

The MADANI government is not showing good practices in how it is using LLMs and Generative AI.
Artificial intelligence is so much more than just the frontier LLMs or whomever has the best marketing strategy to sell their Generative AI at the cheapest price. Especially so, when the negative impacts are affecting 2 out of 3 pillars of Sustainable Development. Rich billionaires might be able to buy their way out of problems. But the rest of "us poorer folks", including future generations cannot survive on tokens and scarcity of water.

I'm sure we can observe and learn from all the good examples, and especially the worst examples, when the primary driver of AI (Gen AI) is only money. (and probably the power to control its users after that)

CO
Cornelia C. Walther
July 17, 2026

Submitted by the Proocial AI 4Planetary Health Working Group in Malaysia

We welcomes the proposed Artificial Intelligence Governance Bill as a necessary step toward safe, responsible and innovation-enabling AI. We support the Bill's institutional architecture, principle-based approach and risk-based framework. Malaysia needs clear national coordination, sectoral interpretation, practical guidance, incident reporting and sandboxes that allow innovation while protecting people and public trust.

We recommend four refinements.

The Bill rightly identifies human dignity and agency as a core principle. However, human oversight is meaningful only when people have the capacity to understand, question and intervene. Malaysia should embed human literacy, which strengthens judgment, attention, ethical reasoning and responsibility; and algorithmic literacy, which enables users, procurers, regulators and affected communities to understand what an AI system optimises for, whose interests it serves, what data it uses, and how it may shape the human ability to think, feel and act autonomously (so-called ‘double literacy’). To make accountability meaningful his should be a requirement for public-sector training, procurement guidance, organisational risk assessments and human-oversight requirements.

Second, the Bill should include explicit requirements to protect planetary health and treat the environment responsiby. The proposed principles address dignity, transparency, accountability, safety and data stewardship, but they do not pay due attention to the environmental footprint of AI. Energy demand, water use, emissions, hardware dependency, land impacts and e-waste are not secondary issues. They must be included as elements of AI governance. High-impact AI systems, especially those using significant compute or which are deployed at scale, should be required to disclose material environmental impacts and demonstrate proportionate mitigation. The risk framework must recognise and price in cumulative social-ecological harm, not only immediate physical or legal harm.

Third, Malaysia should adopt a practical way to measure AI, one that goes beyond simply calling it "responsible." We propose piloting the ProSocial AI Index as a shared dashboard to map, measure, monitor and manage AI systems across two dimensions. The first is how a system is built and run: is it designed for the people it serves, trained on data that fairly represents them, tested for its real social and environmental effects before and after launch, and aimed at outcomes that someone actually keeps watching. The second is what the system is for: its stated purpose measured against what it actually does, how it treats the people who use it, the prosperity it creates or takes away, and its toll on the planet. This would let regulators, deployers and boards see clearly whether an AI system builds human capability, earns institutional trust, spreads prosperity, and protects the planet.

AI governance should not merely prevent harm after deployment; it should guide design, procurement and scaling toward systems that restore capability, reduce exclusion and respect planetary boundaries. Regenerative intent should be built into the algorithmic architecture of Malaysia's hybrid future.

Fourth, the Bill should do more than manage risk. It should be prosocial, setting a positive direction, ensuring AI in Malaysia serves people and the planet, not just profit.

AN
Anonymous
July 16, 2026

This submission is made in the capacity of an individual member of the public with a mixed/neutral stance flagging technical and practical issues. Detailed submission is emailed to policy@ai.gov.my
Overall position: Broadly supportive of the Bill's three-pronged approach — institutional oversight, principle-based regulation, and risk-based obligations — as sound and internationally aligned, but argues the gap between good architecture and workable law lies in operational detail left to future guidance.
Executive Summary — 15 key recommendations (R1–R15), drawing on comparative regulation from the EU AI Act, UK's sector-led model, Canada's failed AIDA bill, Singapore's IMDA framework, Australia's voluntary AI standards, and UK/Bank Negara sandboxes. Highlights include: a hybrid sector-led delegation model with codified coordination protocols between the Central AI Authority and Sectoral Leads; avoiding Canada's mistake of vague "high-risk" definitions; expanding the Bill's four harm categories (currently limited to death, bodily injury, deprivation of liberty, and breach of law) to include discrimination, financial harm, psychological harm, and environmental/democratic harm; fixing the "Tier 1 intent" loophole so unacceptable-risk systems are defined by practice, not provable intent; a voluntary safety standard with safe-harbour effect; mandatory PDPA-integrated bias audits; incident reporting integrated with the Cybersecurity Act 2024; a sandbox with a genuine graduation pathway; and an SME/academia enablement programme.
Part A answers all questions across the consultation's six official Focus Areas in full:
1. AI Governance Architecture — supports a Central AI Authority but demands statutory independence, clear primacy rules with Sectoral Leads, and a public register of applicable rules.
2. Scope of the Bill — supports the Developer/Deployer distinction anchored to degree of control, but flags gaps in defining borderline/hybrid AI systems, third-party foundation-model deployers, and extraterritorial thresholds.
3. AI Governance Principles — supports the five principles but proposes adding Fairness/Non-Discrimination and Environmental Sustainability as explicit principles, plus worked sector examples (finance, healthcare, e-commerce).
4. AI Risk Framework — the most detailed section, critiquing the narrow harm categories and intent-based Tier 1 trigger, and proposing mandatory impact assessments, public registration of high-risk systems, and periodic review cycles.
5. AI Incident Reporting — supports a national framework but pushes for near-miss reporting, whistleblower protections, and integration with existing breach-reporting regimes.
6. AI Sandbox — supportive but stresses the need for a defined exit/graduation pathway, subsidised SME/academic access, and PDPA safeguards during testing.
Part B adds cross-cutting recommendations: PDPA-AI integration, treatment of data centres and autonomous AI agents, deepfake/content-labelling rules, an SME compliance toolkit, and a phased implementation timeline with statutory review cycles.
The document is supported by a 26-item numbered reference list citing international frameworks and legal instruments. A later addendum incorporated lessons from Australia's 15 July 2026 national AI standards announcement.

YO
Yohann Azlee
July 15, 2026

Volley is an AI governance, risk and compliance advisory with offices in Australia and Malaysia. I write as its founder: an ISO/IEC 42001 Lead Implementer, a former group CEO and ASX-listed fintech operator, and a serving board director accountable for AI risk decisions. We advise boards, executives and regulated firms in both markets, and this submission brings that practice to the Malaysian context.

NAIO has built a sound architecture. The principle-based spine, the Developer and Deployer split by degree of control, the harm-anchored tiers and the sandbox are the right bones. The real risk from here is quieter: a framework that reads well on paper and never operates. We have watched capable organisations pass an assessment, file it, and drift. Three changes would close that gap.

First, govern the operation, not the assessment. "Due regard" as drafted is a point-in-time, self-assessed duty, yet the Bill's stated aim is to be proactive rather than reactive. High-risk AI does not hold still. Models update, data ages, and real use creeps past the purpose the system was approved for. For Tier 2 systems, require conformance to be demonstrable at the point of consequential use, through an audit trail, a human checkpoint and logging tied to the authorised purpose and risk boundary. Today that sign-off is filed once and rarely revisited.

Second, resource the AI Enablement function properly. It sits third behind Safety and Enforcement and reads as an afterthought. Malaysia's economy runs on SMEs, and a duty an organisation has no capacity to discharge becomes paper compliance. Enablement should ship reference operating models, a starter control set that scales by risk tier and organisation size, and templates a 20-person firm can actually run.

Third, make assurance count. Recognise established standards, ISO/IEC 42001 and the NIST AI Risk Management Framework, as a compliance safe harbour so firms already certified are not tested twice for the same thing. And give sandbox outcomes binding effect on exit, a provisional classification or safe harbour, so participation lowers a firm's regulatory risk rather than only informing policy.

Our attached submission develops these and adds four points: Tier 1 is gated by intent rather than severity, which lets a dangerous but non-malicious system fall short of "unacceptable"; the harm taxonomy is narrower than where AI harm actually lands, in credit, hiring and insurance decisions; the "resembles human cognition" definition can be gamed in both directions; and the Central AI Authority holds rule-making, enforcement and advice in one set of hands.

We would welcome the opportunity to contribute as the Bill moves to drafting.

Yohann Azlee
Founder, Volley
volley.cx

JE
Jemilah Mahmood
July 15, 2026

Tan Sri Jemilah Mahmood, Executive Director, Sunway Center for Planetary Health

I welcome Malaysia’s move to develop an Artificial Intelligence Governance Bill. This is an important national moment. AI is now part of how we learn, work, diagnose, govern, consume, communicate and imagine the future. The question is therefore whether Malaysia will shape it with wisdom, courage and a clear commitment to people, planet and public trust.

For me, responsible AI governance must start from a simple truth: technology is never neutral once it enters human life at scale. It changes incentives, habits, institutions and power. We have seen this in very clear and accelerating terms with the invention of personal computers, mobile phones, the internet, social media and now with AI. We also know that tech can widen opportunity, but it can also deepen exclusion and exacerbate vulnerability. It can support better decisions, but it can also weaken human judgement when people become passive users of systems they do not fully understand. It can improve efficiency, but efficiency without purpose is not progress.

The Bill must therefore go beyond compliance. It should create a practical framework that helps Malaysia map, measure, monitor and manage AI systems across their full life cycle. A risk-based approach is welcome, but risk must be understood broadly. We should consider not only data privacy, cybersecurity and misuse, but also impacts on human agency, social cohesion, mental health, jobs, inequality, democratic trust, climate and resource use. AI has a material footprint. Data centres need energy, water, land and minerals. A future-facing Bill should acknowledge this openly. The ProSocial AI Index piloted currently at Sunway University is one way of making responsible AI tangible and pragmatic.

Malaysia has the chance to lead by developing a governance model that is both innovation-enabling and deeply human. This means clear duties for developers, deployers procurers, and users of AI systems; transparent incident reporting; independent audits for high-impact use cases; meaningful human oversight; accessible complaint and redress mechanisms; and sandboxes that test not only technical performance, but real social consequences.

Just as importantly, the Bill should invest in literacy. People cannot exercise agency over systems they cannot question. We need double literacy: human literacy, to understand our values, biases, emotions and responsibilities; and algorithmic literacy, to understand the strengths, limits and influence of AI. This should be embedded in education, public service, business and community programmes.

Malaysia should not aim merely to adopt AI quickly. We should aim to adopt it conscientiously. A strong AI Bill can help ensure that technology serves people, and provides shared prosperity and planetary health. That is the standard we should set — not because it is easy, but because the future we are building will be shaped by the safeguards we put in place now.

DE
Devan Arumugam
July 15, 2026

This is my first pass review on your draft. Please read the exhaustive review. I will again hand in the 2nd or final pass in another few days. DEVCO represents not just an advisory and assurance firm in this niche but also a think tank via DEVCO Institute and we are also an MD status software development company specializing in Regulatory Technology and secure communications.

https://www.linkedin.com/pulse/malaysias-ai-governance-bill-must-act-nation-building-dr-devan-u8dyc/

LA
Laura Lyons
July 15, 2026

Thank you for the opportunity to review Malaysia's proposed AI Governance Bill as part of the public consultation process. Please see attached for recommendations and additional standards, frameworks, and approaches to consider.

AN
Anonymous
July 14, 2026

To whom it may concern. We would like to submit our feedback as in the file attached. The main take away is that we propose the establishment of a National AI Governance Deployment and Assurance Framework to complement the proposed Bill.

AN
Anonymous
July 13, 2026

Feedback on AI in the Arts Industry

Artificial Intelligence (AI) is no longer a distant concept in the creative arts—it is already embedded in the workflows of Grammy-winning producers, major label executives, and iconic artists. From Timbaland’s AI entertainment ventures to Grimes open-sourcing her voice, and even Randy Travis regaining his voice through AI, the technology is reshaping how music is created, distributed, and experienced. While public debates often question whether AI-generated works are “real art,” the reality is that AI is now a practical tool used across the industry. It is a future of today!

Opportunities and Benefits

1. Creative expansion: AI enables artists to explore new sounds, styles, and collaborations that may not be possible through traditional methods.

2. Accessibility: Independent musicians and smaller labels gain access to production-quality tools, lowering barriers to entry.

3. Preservation and restoration: AI can revive voices and performances, offering cultural and emotional value.

4. Efficiency: Streamlined workflows allow faster production and experimentation, supporting innovation, reducing creation and production costs.

Risks and Concerns

1. Intellectual property: Without clear regulation, AI-generated works risk infringing on existing copyrights or misusing artists’ likenesses.

2. Authenticity and trust: Audiences may feel misled if AI contributions are hidden or uncredited.

3. Economic impact: Fully-reliance on AI could reduce opportunities for human creators, especially session musicians and lyricists.

4. Ethical use of voices and identities: Cases like voice cloning demand strict consent and transparency.

Recommendations for Regulation

1. Transparency requirements: Works created or assisted by AI should be clearly labeled, ensuring audiences and stakeholders understand the role of AI. For example: FULL CREATION OF AI or MIXED CREATION BY HUMAN & AI.

2. Consent and licensing: Use of an individual’s voice, likeness, or style must require explicit permission and fair compensation.

3. Balanced copyright frameworks: AI-generated works should also be protected, as of human creators’ rights. A mixed system recognizing both human authorship and AI-assisted creation may be necessary. Human composers who subscribe to or utilize AI music and artwork generators as creative tools should be afforded EQUAL LEGAL RECOGNITION as those who employ modern instruments, applications, or systems in the creation of their works.

4. Industry standards: Establish guidelines for metadata, credits, and royalty flows to ensure fair distribution when AI is involved.

5. Education and awareness: Regulators should support initiatives that help artists, audiences, and businesses understand AI’s role, risks, and opportunities.

Conclusion

AI is neither a threat nor a miracle—it is a tool. The challenge for Malaysia’s creative ecosystem is to regulate AI in a way that protects artistry, ensures fairness, and embraces innovation. By setting clear standards for transparency, consent, and rights management, MPC can help the industry EVOLVE responsibly while safeguarding cultural integrity and ensuring that independent artists are not left behind.

AN
Anonymous
July 13, 2026

In addition to the proposed definitions and scope, the Bill should recognise the environmental impact of AI systems. High-compute AI models and data centres consume substantial amounts of electricity and water, particularly for cooling. The framework should encourage AI developers and deployers to adopt renewable energy where practicable, improve energy efficiency, and implement sustainable water management practices to protect clean water supplies. Environmental sustainability should be recognised as a cross-cutting consideration alongside safety, transparency, accountability, and human rights to ensure that AI development supports Malaysia's long-term sustainability goals.

The Bill may also consider proportionate exemptions for low-risk AI systems used for research, education, or personal, non-commercial purposes, provided they do not pose significant risks to individuals or society. This would avoid imposing unnecessary regulatory burdens while allowing innovation to flourish.

AN
Anonymous
July 12, 2026

I wish to commend the government for initiating the proposed AI Governance Bill and welcoming public feedback. It is refreshing to see an agile, principle-based baseline rather than rigid technical definitions that would quickly become obsolete.

Delineating the duties of "developers" and "deployers" based on their degree of control is a practical, real-world approach. Similarly, anchoring risk tiers directly to concrete legal and constitutional harms protects the public without strangling early-stage innovation. The supervised AI Sandbox is also an excellent touch, offering local startups and SMEs a vital space to safely test ideas while helping regulators close the knowledge gap in real time. By doing this, Malaysia has successfully synthesized the best elements of the EU AI Act, China's legislation model, Singapore’s enterprise-driven approach, and the US framework into a conceptually balanced, innovation-friendly architecture.

However, because the primary law relies so heavily on secondary guidelines to fill in the blanks later, the framework currently lacks the structural "teeth" needed to truly deter corporate negligence right out of the gate. To make this bill reliable, a few critical gaps must be addressed.

As a start, while the text outlines the AI Authority's power to issue administrative penalties, it leaves the actual limits completely open. I want to see clear, escalating penalty floors and ceilings codified directly into the law so that companies bypassing mandatory high-risk assessments face serious consequences.

On top of that, relying on the phrase "in accordance with applicable laws" under Principle 5 essentially kicks data privacy down the road to the existing Personal Data Protection Act (PDPA). The AI Bill should boldly stand on its own feet by explicitly stating that any AI models processing Malaysian citizens' Personally Identifiable Information (PII) must strictly respect local data sovereignty, prohibiting data usage outside the authorized purpose.

I also urge the government to introduce explicit safe harbors to protect local businesses (Deployers) who hook into global APIs (Developers). Without this, small local companies could easily be held legally liable for systemic biases embedded deep within a foreign tech stack that they have zero control over.

Additionally, the Bill must ensure absolute legal symmetry between the private sector and the state. As drafted, the AI Authority holds massive, concentrated powers—simultaneously managing the risk matrix, investigating incidents, and levying administrative fines. To prevent regulatory overreach or political weaponization, the Bill must mandate an independent judicial appeal mechanism so companies have immediate recourse to challenge interim orders before an objective tribunal.

Finally, the government cannot give itself an escape hatch. State agencies, statutory bodies, and government-linked companies must be held to the exact same compliance audits, incident reporting rules, and financial liabilities as private enterprises. The state must not hide behind sovereign immunity when its own AI deployments cause real-world harm. To reinforce this equity, the absolute exemption for "national security" must be tightly and narrowly redefined to prevent regular civil agencies from falsely branding invasive, poorly implemented AI tools under the banner of defense to dodge accountability.

AN
Anonymous
July 12, 2026

As a technology professional working in Malaysia's AI industry, I welcome the opportunity to provide feedback on the proposed AI Governance Bill. I support the Government's intent to establish Malaysia's first comprehensive statutory framework for AI, and I would like to share a few thoughts to help ensure the Bill achieves its goals of trust, safety, and innovation in a balanced manner.
I strongly support the Bill's adoption of a risk-based, proportionate regulatory model, consistent with the AI Risk and Classification Framework referenced by the Government. That said, I hope the classification criteria and compliance obligations for each risk tier will be published in clear, practical guidance well ahead of enforcement. Local SMEs and startups, which form the backbone of Malaysia's digital economy, have far less legal and technical capacity than large multinational developers, so compliance requirements such as incident reporting, documentation, and audits should scale with company size and risk exposure rather than apply uniformly. A regulatory sandbox or transitional grace period would also help businesses adapt their systems and processes before penalties take effect.
On the safety side, recent incidents involving the misuse of generative AI tools to produce non-consensual and explicit imagery in Malaysia show how urgent robust harm-prevention provisions really are. I support mandatory incident reporting and clear obligations on both developers and deployers to detect and mitigate misuse, including deepfakes and synthetic media targeting individuals. It would also help if the Bill explicitly cross-referenced and harmonised with the Personal Data Protection Act, the Online Safety Act framework, and MCMC's enforcement powers, so that companies aren't left navigating duplicative or conflicting obligations. Clear takedown timelines, victim redress mechanisms, and platform accountability standards should ideally be spelled out in the Bill itself rather than left entirely to subsidiary regulations.
At the same time, Malaysia's ambition to be a competitive regional AI and data centre hub depends on regulatory clarity that doesn't stifle innovation. I would encourage the Bill to designate NAIO as a clear central coordinating authority, so that overlapping or conflicting compliance demands don't arise from multiple sectoral regulators such as Bank Negara Malaysia, the Securities Commission, and MCMC governing the same AI system. Alignment with recognised international standards, such as the ISO/IEC AI standards referenced under MY-AI Standards, could also be treated as a safe harbour for compliance where applicable, so companies already certified internationally aren't forced through duplicate assessments. I'd also encourage continued industry consultation through the drafting of subsidiary regulations and technical codes, not just at this primary legislation stage.
Overall, I fully support the Government's effort to introduce a modern, risk-based AI Governance Bill. With calibrated compliance burdens, strong harm-prevention mechanisms, and coordinated, innovation-friendly enforcement, Malaysia can build a trusted AI ecosystem that protects citizens while remaining competitive regionally and globally. I look forward to further engagement with NAIO and the Ministry of Digital as the Bill progresses through drafting and parliamentary review.

MU
MUHAMMAD SUKRI BIN RAMLI
July 11, 2026

While the draft Bill does a great job setting up rules for Developers and Deployers, it currently lacks a defined mechanism for the individuals affected by automated decisions. If a Malaysian citizen is denied a critical public service by an AI, a high-level corporate checklist won't help them. In future I believe there will be more autonomous decision service that face citizen made by government and organisation that require check and balance.

To bridge this gap, I am sharing my writing on "The UX of Administrative Justice: Standardizing Citizen-Facing AI Decision Receipts in Public Sector Automation."

We suggest mandating a simple, readable AI Decision Receipt the exact moment someone is rejected by a government AI system. It gives citizens three clear things:

Input Snapshot: A quick look at the data the AI used, so the citizen can easily spot typos or old database errors.
Clear Breakdown: A visual explanation showing exactly which factors heavily influenced the AI's choice.
Next Steps: A plain-language guide on the minimum changes needed to get an approval next time.

It also includes a one-click button to instantly appeal to a human officer, backed by a "blind review" process so the officer doesn't just rubber-stamp the AI's mistake.

This moves AI governance from passive paperwork to real, everyday protection for Malaysians. The full paper is attached, and I would love to discuss how we can pilot this framework with the NAIO.

AN
Anonymous
July 11, 2026

the Bill assigns no role to the person affected by an AI system.
The draft defines two duty holders, Developer and Deployer. The individual affected by a system appears once, as a source of user complaint that the Authority may collect. The draft therefore covers the parties who build and operate AI systems, but assigns no defined role or right to the individuals those systems act upon.
This creates three problems.
It is inconsistent with the Bill's own principles. Principle 1 states that individuals must not be reduced to mere data points, yet the affected individual's only function in the draft is to supply complaint data. Principle 3 requires accountability to identifiable persons, yet the draft does not specify any accountable person at the moment an automated decision affects an individual.
It weakens early detection of harm. The risk and incident provisions are anchored to harms that have already occurred, and reporting flows mainly from Developers and Deployers. Self-reporting places the reporting duty on the party a report would expose. The draft does not provide for signals from affected individuals before harm occurs, although service systems already collect such signals in the form of rejected outcomes, repeat contacts, and abandoned interactions.
The personal-use exemption may widen the gap. The exemption for personal, family, or household affairs could be read to cover a resident using a private AI agent to interact with a public service. If so, citizen-facing government interactions would fall outside the Bill's protection.
Recognising the affected individual as a defined party, with a right to obtain review of an automated outcome by a person with authority to correct it, would close this gap and bring the operative provisions into line with Principles 1 and 3 as drafted.

CO
Cornelia C. Walther
July 11, 2026

Malaysia’s proposed AI Governance Bill sets in place a valuable architecture: risk tiers, a Central AI Authority, Developer-Deployer accountability, sandboxes. Two additions would carry that architecture from institutional oversight into lived protection for citizens navigating AI daily.
Individual agency erodes quietly under algorithmic systems. No single incident marks the moment a person stops deciding and starts merely accepting what an interface recommends; the shift happens recommendation by recommendation, largely unnoticed by the person it happens to. This harm sits outside the Bill’s current taxonomy of physical, legal, and reputational damage, though it shapes how most Malaysians will experience AI long before any incident report gets filed.
First: integrate Double Literacy into the Bill’s human oversight and public education provisions. Double Literacy names two capacities that grow together: Human Literacy, the deliberate cultivation of judgment, discernment, and self-knowledge that AI cannot substitute for, and Algorithmic Literacy, the ability to read how a system was trained, what it optimizes for, and where its blind spots sit. A population fluent in only one strand drifts. Citizens skilled at prompting a chatbot but blind to its incentive structure hand over agency without noticing the transfer. Citizens wary of algorithms but unable to name their own values default to whatever the interface suggests. The Bill’s principle-based language on “human oversight” stays abstract without a literacy requirement behind it. Embedding Double Literacy into school curricula, civil-service training, and the Sectoral Leads’ capacity-building mandates gives individual agency a concrete, teachable foundation rather than a hoped-for byproduct of good design.
Second: adopt the ProSocial AI Index as the national standard for AI procurement and public-sector policy making. The Index scores a system across four dimensions of build, Tailored, Trained, Tested, Targeted, against four dimensions of impact, Purpose, People, Prosperity, Planet. Sixteen cells replace the vague self-assessed “due regard” language currently proposed, giving procurement officers, auditors, and Sectoral Leads a shared, auditable grid instead of sixteen separate judgment calls made informally and inconsistently across ministries. Any agency buying or deploying AI could run a system through the same matrix a hospital, a bank, or a school uses, producing comparable results across sectors that the current Developer-Deployer split cannot deliver alone. A national standard here turns “trustworthy AI” from a slogan into a repeatable measurement, exportable as a model to ASEAN partners.
Together, these two additions answer the consultation’s own question about pathways from compliance to adoption. Double Literacy protects the citizen inside the system. The ProSocial AI Index gives government a concrete instrument for choosing which systems deserve public trust and public money.

https://www.psychologytoday.com/us/blog/harnessing-hybrid-intelligence/202605/ai-ethics-is-a-double-misnomer

VI
Vivegavalen Vadi Valu
July 11, 2026

Please find attached Trustethica’s submission on Malaysia’s proposed AI Governance Bill. It addresses a specific gap in prevailing AI governance approaches, where high-impact AI should not be treated as governed merely because it has been assessed or approved at a point in time. Deploying organisations should be able to demonstrate, at the moment of consequential use, that the system remains within its authorised purpose, authority and risk boundary.

The submission translates this principle into a technology-neutral operating model, concrete legislative language and a proposed 90-day pilot in a regulated Malaysian environment to establish what is technically enforceable, operationally proportionate and suitable for sector guidance.

We would value the opportunity to discuss how this approach could support NAIO in moving from policy principles to testable operational controls, and help establish Malaysia as a leader in practical, interoperable AI governance across ASEAN.

AN
Anonymous
July 11, 2026

I am concerned about government or ministry having central authority to levers and weights of AI being used in Malaysia because people should be free to pick their technology

AN
Anonymous
July 10, 2026

Good job NAIO. The proposed AI Governance Bill provides a strong and timely foundation for Malaysia’s AI governance. Several aspects are particularly positive:
It adopts a principle-based and risk-proportionate approach, allowing higher-risk systems to be subject to stronger safeguards without unnecessarily burdening lower-risk innovation.
- It recognises accountability across the AI lifecycle, including the distinct roles of Developers and Deployers.
- It proposes incident reporting, testing and sandboxes, which can support continuous learning, safer deployment and responsible experimentation.
- It also seeks to balance central coordination with sectoral expertise, which is appropriate given the different risks in areas such as healthcare, finance, transport and public services.
The following seven areas may merit further consideration as the Bill is refined:
Central and sectoral roles
1. Further clarity may be useful on how the Central AI Authority and Sectoral Leads will divide responsibilities, particularly for supervision, investigation and enforcement.
Breadth of the Central AI Authority’s mandate
2. The proposed Authority covers safety, enablement, investigation, enforcement and sandbox functions. Consideration may be given to whether sufficient functional separation, oversight and review mechanisms are needed to manage potential conflicts between these roles.
3. Regulatory interoperability
The Bill could further explain how it will interact with existing regulators and laws, and how conflicting or overlapping requirements will be resolved.
4. Definition of harm and unacceptable risk
Consideration may be given to whether the framework should more explicitly cover material economic, discriminatory, reputational, societal and systemic harm, beyond physical harm or breaches of existing law.
5. Foundation models and the wider AI value chain
The Developer–Deployer model is useful, but further guidance may be needed for foundation-model providers, fine-tuners, system integrators and other intermediaries.
6. Pathways from compliance to adoption
The standards, certification and sandbox mechanisms could be further developed as practical pathways to help organisations move safely from experimentation to deployment, especially for SMEs and Made-by-Malaysia AI solutions.
7. Adaptive review mechanisms
The Bill may benefit from clear periodic review arrangements so that incident data, sandbox experience, technology developments and international standards can inform future updates.

AN
Anonymous
July 10, 2026

The key risk in this Bill, once enacted, is that it will lower the tort standard applicable to AI Systems rather than raise it.

AI Systems, by virtue of their capacity to produce unanticipated outcomes even from fully deterministic processes, coupled with emergent properties of systems integration, warrant a higher standard of care under ordinary negligence than conventional software — yet the Bill's undefined, self-assessed "due regard" and "proportionate" language, combined with a harm taxonomy narrower than negligence's own recoverable damage categories, functions as a statutory carve-out that would hold Developers and Deployers to a weaker standard than they already face under existing Malaysian common law.

The "AI System" gate tests behavioural resemblance to human cognition rather than the mechanism that determines actual risk, and this produces gaming in both directions: a high-stakes, opaque scoring model can argue it doesn't "resemble cognition" and escape the gate entirely, while a low-stakes, fully deterministic system can be swept in on the strength of a conversational interface alone. This asymmetry favours sophisticated, well-resourced actors with the most at stake in being exempted from a statutory scheme that, properly designed, should be tightening their liability rather than loosening it.

This carve-out runs through the Bill's remaining structure as well. The five AI Governance Principles should not sit in primary legislation at all — taken at face value, they award a self-defined duty of care to Developers/Deployers, and the consultation paper's own justification for principle-based drafting (flexibility to issue guidance without amending the Act) concedes that the principles carry no operational content in the statute itself, meaning their only function there is symbolic. They belong in a Central AI Authority code of practice the Authority can revise on a short cycle, not in an Act Parliament must reopen.

In their place, the Bill's most useful role is elucidating how existing tort doctrine — foreseeability, proximity, causation, duty of care — applies specifically to AI Systems, rather than inventing a parallel statutory standard. The clearest example is liability attribution across complex, multi-actor systems integration. Even accepting the Developer/Deployer distinction as drafted, the Bill never states how liability apportions when a foundation model provider, a system integrator, and a Deployer each contribute to a single harmful outcome — the "degree of control" test allocates regulatory compliance duties, but not which actor bears responsibility for a specific harm once several actors' contributions interact. Singapore's IMDA is working through exactly this question for agentic AI, treating value-chain allocation by control, access to information, and proximity as an open private-law problem requiring deliberate resolution, and Malaysia's Bill would benefit from the same treatment rather than leaving the question implicit. No provision anywhere allows a binding, pre-deployment classification ruling on this or any other point of scope; self-assessment stands unreviewed until an incident occurs. The AI Sandbox is well placed to serve this function if the Bill gives it binding legal effect on exit.

Full response has been communicated in the Google Form.

AN
Anonymous
July 10, 2026

1. As an academician in AI and engineering, I welcome the proposed AI Governance Bill as a step towards responsible and trustworthy AI adoption in Malaysia.
2. I support the risk-based and principle-based approach.
3. The roles of the Central AI Authority and Sectoral Leads should be clearly defined to avoid overlapping responsibilities, inconsistent requirements and additional administrative burden.
4. Universities, researchers, professional bodies, industry, SMEs and civil society should remain actively involved in developing technical standards, implementation guidance and capacity-building programmes.
5. Accountability should reflect the actual control of each party, including developers, deployers, model providers, system integrators & organisations that modify/operate AI systems.
6. Practical guidance is needed on risk assessment, human oversight, documentation, data governance, cybersecurity, bias testing & redress mechanisms.
7. I support the AI Sandbox and incident-reporting mechanism, provided that they encourage learning.
8. Finally, the gov should publish a transparent summary showing how stakeholder feedback has influenced the final Bill.

No Surveys Available

Officer to Contact

AI Policy Department - National AI Office
Contact Person
policy@ai.gov.my
Email
03-21818090
Phone