Malaysia's National AI Office has published a consultation document for a binding Artificial Intelligence Governance Act, moving the country off voluntary ethics guidelines and onto the European regulatory model.
What the framework covers
It would regulate AI systems placed on the Malaysian market or deployed in Malaysia across their entire lifecycle, binding both developers and deployers. Personal use and matters of national security are excluded. The structure is a familiar one: three risk tiers — unacceptable, high, low — with obligations scaling accordingly.
Principles and enforcement
Five governing principles are named: human dignity and rights, transparency and explainability, accountability, safety and security, and responsible data governance. A central AI authority would act as the principal national body — running safety assessments, investigating AI incidents, enforcing baseline requirements — and could appoint "Sectoral Leads" with delegated powers for sector-specific implementation. Incident reporting would be a duty rather than a courtesy.
A consultation, not a law
Nothing here is enacted. This is a consultation document, which precedes a bill, which precedes a parliamentary vote — and no tabling date exists. Coverage announcing that Malaysia has passed an AI act is describing three steps that have not been taken.
What is still missing
The consultation's start and end dates are not stated in the reporting, and the official document was not yet posted on the NAIO's own site at the time of checking. The office's formal launch is set for July 28. For now the framework is known through a single outlet.
The regional signal
Digital minister Gobind Singh Deo flagged the bill in June as one half of a two-pronged approach — existing law to prosecute misuse, new law to build prevention and accountability. Southeast Asia's third-largest economy adopting a risk-tiered regime is the clearest sign yet that the EU template is propagating across ASEAN rather than the lighter-touch US one.
