AI GovernanceAI RegulationPDPA

Malaysia's AI Governance Bill: Why the Compliance Work Starts Before the Law Does

Lestar Team
Content Team
26 August 2026
5 min read
Malaysia's AI Governance Bill: Why the Compliance Work Starts Before the Law Does

Malaysia's first dedicated AI law hasn't passed Parliament, and its penalty schedule isn't even written. That's not the same as "nothing to do yet." Public consultation on the AI Governance Bill closed 31 July 2026, and the National AI Office (NAIO) is now institutionalized as AI Malaysia Berhad, the country's central AI coordinating body. Underneath both sits a set of obligations — incident reporting, mapping where AI touches personal data, deciding who counts as "developer" versus "deployer" — that take months to build properly. Teams operating AI in Malaysia have more runway than the headlines suggest, but less than "wait for the final text" implies.

What's Happening

The Ministry of Digital opened consultation on 10 July 2026, with submissions due by month's end. NAIO — running since December 2024 — became AI Malaysia Berhad around the same time; founding director Shamsul Izhan Abdul Majid stepped down in June 2026, and new leadership is still unnamed. Anwar Ibrahim has said the bill covers the "full lifecycle" of AI systems — training through deployment and monitoring — and in July 2026 described the government as still finalizing text meant to complement, not replace, existing cybersecurity and data protection law. It still needs Parliamentary Special Select Committee scrutiny before tabling, reportedy later in 2026.

This builds on voluntary guidelines from 2024 and the MY-AI Standards (completed March 2026). What's new is a binding law with its own enforcement body, layered on a PDPA regime with sharper teeth since mid-2025.

Why It Matters

The bill splits responsibility between Developers (who shape what a system can do) and Deployers (who run it) — most teams building on foundation models will likely land as Deployer, and possibly Developer too if they fine-tune model behavior. The split decides who reports incidents, including near misses, not just failures.

Separately, the bill proposes treating both AI training data and AI-generated output as intellectual property — reportedly an ASEAN first, and one that will need reconciling with the existing Copyright Act 1987 if it survives to the final text.

The Framework

Three risk tiers, EU-adjacent but not identical: unacceptable (prohibited outright), high (foreseeable harm, rigorous controls), and low (baseline compliance). Malaysia diverges from the EU AI Act on philosophy — the EU leans on pre-deployment conformity assessment; Malaysia leans on post-deployment incident reporting and sandboxes, "enablement-first" rather than certification-first, at least initially.

A proposed Central AI Authority would handle safety, investigation/enforcement, and sandboxing. AI Malaysia Berhad is notably not that body — government commentary frames its role as coordination, with actual enforcement expected once the bill is enacted. Worth not conflating the two: Berhad is who you'd work with on adoption and standards; the Authority, once formed, is who you'd answer to on incidents.

What the Industry Is Learning

KPMG's read on governance readiness: infrastructure investment has outpaced governance capability. Most large organizations have an AI policy on paper; few can show continuous assurance over their actual AI estate — including AI nobody in IT approved.

A legal submission (Edwin Lee & Partners) flagged a more concrete risk: the bill runs parallel to the PDPA, Copyright Act, Online Safety Act, and Evidence Act rather than integrating with them — risking duplicate risk assessments and incident reports for the same event; foreign AI developers were also largely absent from the consultation. None of this is in a vacuum, either: PDPA obligations are already enforced today (mandatory DPOs since June 2025, penalties up to RM1,000,000 and three years' imprisonment), independent of the AI bill.

Our Engineering Perspective

As a technology partner building AI-assisted systems for Malaysian enterprises, the Developer/Deployer split and the fragmentation risk are what we'd tell engineering leads to take seriously first. A defined risk-tier vocabulary is worth designing against even before the penalty schedule exists, and an inventory of which systems you're the Deployer versus Developer for is worth building regardless of how the bill lands — most teams can't answer that cleanly today.

The risk is waiting: teams that start this only after enactment do regulatory mapping under deadline pressure while the rest of the organization is still interpreting a new statute, and the PDPA precedent suggests enforcement can arrive fast. An organization running only off-the-shelf SaaS AI, with no fine-tuning or customer data exposure, will likely land at baseline compliance — worth tracking, not a governance overhaul. What would change our posture: published penalty ranges, and clarity on whether the Authority harmonizes reporting with the Personal Data Protection Commissioner rather than running a seperate process.

Where to start: an AI system inventory (what's in production, who owns it, Developer or Deployer status per system); incident monitoring that captures near misses; and mapping any system touching personal or biometric data against existing PDPA obligations, already enforceable now.

Conclusion

The real failure mode with new AI regulation isn't ignoring it — it's waiting for the final text before doing the work that doesn't depend on it. Teams that build the inventory now spend the post-enactment period adjusting something that already exists, rather than building it from scratch under deadline.

Working with Lestar

Governance-ready data — the kind that makes a PDPA DPIA or a future Tier 2 assessment straightforward to answer rather than a scramble — doesn't happen by accident. If your organisation is still mapping what AI systems are actually running and what data they touch, that's a conversation worth having sooner rather than later. Talk to Lestar about what governance-ready data infrastructure could look like for your organisation.

Share:

Ready to Centralise Your Enterprise Data?

Whether you need Lestar ESG for sustainability reporting, Lestar CEO360 for executive intelligence, or a fully customised enterprise data implementation — Mandrill Tech will tailor the solution to your organisation's needs.

AI-driven centralised data management solution by Mandrill Tech. Featuring Lestar ESG for sustainability reporting and Lestar CEO360 for executive intelligence.

hello@mandrill.com.my+6014-886 8842
Level 9, Hextar Tower Empire City
Jalan PJU 8, Damansara Perdana
47820 Petaling Jaya, Selangor
Malaysia

Products

Mandrill Ecosystem

Quick Links

© 2026 Mandrill Tech Sdn. Bhd. (201501005176 | 1130506-W). All rights reserved.