Malaysia's AI Governance Bill Would Reach Any Deployer Here, Wherever the Model Runs

The National AI Office has sketched a three-tier risk regime and a central authority, but left penalties and deadlines blank and given industry three weeks to respond.

3 min read ·

On 10 July the National AI Office (NAIO) published a consultation paper on a proposed AI Governance Bill. If it passes, it would be Malaysia's first horizontal AI law: one statute covering every sector, rather than the current mix of voluntary guidelines, data protection rules and whatever an individual regulator decides. Feedback closes on 31 July, which gives companies roughly three weeks to read a framework that could shape how every AI feature in the country is built and run.

I have read the summaries from the law firms that went through the paper line by line. What follows is what matters if you ship software in Malaysia, not if you write policy for a living.

Who is in scope: almost certainly you

Responses (2)

Sign in to leave a response.

  • Classifying by intent is going to be very hard to apply to general-purpose models. Nobody builds a base model intending harm, so in practice almost everything ends up arguing over what counts as foreseeable.

  • Agree on the near-miss threshold. Security learned this with breach notification: if you define incidents too broadly, people either drown in reports or quietly stop filing them.

More from Fakhrul

Recommended from Horizon