AI Governance Bill — Public Consultation Discussion Prompts and References 4457 words

AI Governance Bill — Public Consultation Discussion Prompts and References

FOR DISCUSSION PURPOSES ONLY — NATIONAL AI OFFICE

Prepared by the National AI Office (NAIO), Malaysia

This document contains six fact sheets to assist members of the public in providing preliminary feedback and input on the formation of a national AI Bill.

Disclaimer: This document has been prepared solely for public consultation purposes only and does not constitute the complete Bill. The Government is not bound by the contents of this fact sheet in developing the final Bill, and all proposals remain subject to further review and amendment.


Fact Sheet 1: Definitions and Scope of the Bill

1. Definitions under the Bill

As it stands, there are five (5) key definitions which are considered by the Bill. They are:

a) Artificial Intelligence "Artificial Intelligence" or "AI" means a functional capacity, or a set of methods or automated entities that, whether individually or in combination, build, optimise or apply a feature or model so as to enable a system, for a given set of defined or pre-defined tasks, to simulate cognitive functions characteristic of a natural person.

b) Artificial Intelligence Systems A system shall be deemed to be an "Artificial Intelligence system" or "AI system" if the system features or has Artificial Intelligence.

c) Artificial Intelligence Lifecycle "Artificial Intelligence lifecycle" means the actions carried out in relation to an AI system from its creation until its withdrawal, and includes any activity carried out before, during or after deployment.

d) Developer "Any person (natural or legal) who creates, causes to be created, materially modifies, or changes the intended purpose of an AI system or its underlying model."

e) Deployer "Any person (natural or legal) who puts an AI system into service, or makes it available for use by a third party."

2. Scope of the Bill

The Bill intends to regulate AI systems which:

(a) Are placed on the market or put into service within Malaysia (b) Designed, developed, or used in Malaysia; and (c) Used by a deployer established in Malaysia, regardless of where the system is physically hosted.

3. Exemptions


Fact Sheet 2: The Central AI Authority

This fact sheet explains how the proposed AI Bill establishes a Central Authority to lead and coordinate AI governance across Malaysia.

1. Why a Central Authority Is Needed

Artificial intelligence ("AI") is not confined to a single sector. It is used across finance, healthcare, transport, education, public administration, and many other fields. The differing sectors and industries in which AI may be deployed comes with it the risk of fragmentation of how it is governed applying inconsistent standards and expectations.

Through a Central AI Authority with a clear set national "baseline" principles and standards, it strengthens the overall system by addressing areas of uneven capacity between differing sectors. Ultimately, a concerted governance ecosystem uplifts Malaysia's regulatory framework by achieving a balance between promoting innovation while ensuring safe use.

2. Core Functions (Four Pillars)

The Central AI Authority will have the following four (4) core functions:

3. Key Powers

The Central AI Authority will have the following key powers:

Functions Related powers
Operationalising National AI Principles • Operationalising baseline AI Principles
• Coordinate with Sectoral Leads in implementing the AI Principles
• Issuing mandatory or non-mandatory legal instruments (where necessary) for the implementation of the principles
AI Safety Functions • Undertaking research, analysis, and provide recommendations to improve AI adoption.
• Developing Incident Reporting mechanisms for AI Risks and Harms
• Provide recommendations to address any AI related risks or harm
Investigation and Enforcement functions • Issue governance instruments (subsidiary regulations, codes, standards, guidelines)
• Oversee and enforce compliance with statutory requirements
• Issue directions or orders to mitigate risk and prevent harm
• Impose interim risk-control measures and administrative penalties
AI enablement functions • Undertake AI Capacity Building initiatives and functions
• Supervisory role for the implementation of specific standards, principles, or instruments.

4. Relationship with Sectoral Regulators

The Central AI Authority will operate a co-regulatory model with other Sectoral Regulators through a Sector Lead. The Sector Lead may support the implementation of the AI Principles where they have sufficient legal authority, technical expertise, and governance capacity. This ultimately empowers each Sector Lead to implement sector specific guidance which remains consistent with the AI Principles.

The Central AI Authority may appoint a Sector Lead and subsequently delegate the following functions:

a) Advise the Central Authority for the issuance of Sector-Specific legal instruments including subsidiary regulations, guidelines, or code of ethics; b) Be delegated the power to implement its own sector specific policies; and c) Assist the Central Authority in implementing and enforcing the Bill.

5. International Benchmark

Country / Organisation Legal Instrument Description
European Union EU AI Office, established by Commission Decision of 24 January 2024; designated under the AI Act (Regulation (EU) 2024/1689) as the central implementation body Serves as the foundation for a single AI governance system in the EU; enforces rules for general-purpose AI models; supports governance bodies in Member States
Japan Act on Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technologies ("AI Act") Establishes a national AI "control tower" for the implementation of the Act. Primarily, the Council may issue recommendations to any entity which in turn "shall take appropriate follow-up measures"

Fact Sheet 3: AI Principles

This fact sheet outlines the five fundamental principles that guide the development and use of AI systems under the proposed Bill.

1. Why a Principle-based approach

The Bill establishes five (5) core AI Principles that every developer and deployer must have "due regard" throughout the AI lifecycle. These principles are aligned with local and international frameworks, including the Federal Constitution of Malaysia, the OECD Recommendation on AI, and ASEAN guidelines.

The Bill adopts a principle-based approach rather than prescribing detailed, technology-specific rules. AI is a rapidly evolving technology, hence rigid rules risk becoming outdated quickly and may stifle innovation. A principle-based framework offers two key benefits:

(a) Provides flexibility, allowing the Central Authority to remain agile in implementation by among others, issue practical guidance across different sectors without amending primary legislation; and (b) Enables proportionate regulation as lower-risk AI applications are not subject to the same burden as higher-risk ones; and

2. The Proposed AI Principles

The proposed principles have been distilled based on insights from international frameworks, as well as local legal instruments such as the Federal Constitution.

3. How the Principles Work

Developers and deployers of AI systems must have "due regard" for these principles throughout the AI system's lifecycle. "Due regard" means actively applying the principles in a way that is proportionate to the system's nature, context, and potential impact.

Compliance is scaled based on the level of risk, context, and purpose of the AI system. Developers and deployers should anticipate future developments and consider these principles over the long term.

The Bill intends to be agile by setting out the principles, while reserving any operational requirements of the principles to other governance instruments including, but not limited to, subsidiary regulations or guidelines.

The implementation of the principles will also take a phased approach. In the initial stages of the Bill, focus will be given to socialising the principles and creating awareness while other efforts such as codifying full implementation of the principles to be done at a later stage.

4. International Benchmarks

Country / Organisation Legal Instrument Description
OECD OECD Council Recommendation on AI (OECD/LEGAL/0449; adopted May 2019, revised November 2023 and May 2024) The first intergovernmental standard on AI; establishes principles of inclusive growth, human-centred values and fairness, transparency and explainability, robustness, security and safety, and accountability; adopted by 49 adherents as of 2024
UNESCO Recommendation on the Ethics of AI (adopted 23 November 2021 by all 193 Member States) The first global standard-setting instrument on AI ethics; provides universal normative orientation covering privacy, dignity, transparency, accountability, and broader ethical direction
Council of Europe Framework Convention on AI and Human Rights, Democracy and the Rule of Law (adopted 17 May 2024; opened for signature 5 September 2024) The first international legally binding treaty on AI; requires graduated and differentiated governance measures anchored in human rights, democracy, and the rule of law
European Union AI Act (Regulation (EU) 2024/1689; entered into force 1 August 2024) Structures regulation through prohibited practices, high-risk systems, transparency duties, and general-purpose AI models; embeds principles of safety, fundamental rights, human oversight, and accountability
ISO/IEC ISO/IEC 42001:2023; ISO/IEC 23894:2023; ISO/IEC 22989:2022 Provides voluntary organisational-level management-system governance for AI including risk identification, documentation, transparency, human oversight, and continual improvement; ISO/IEC 42001 is the first AI management-system standard
ASEAN ASEAN Guide on AI Governance and Ethics (2024); expanded Generative AI Guide (2025) Regional guidance promoting human-centricity, fairness, transparency, accountability, and robustness; designed for interoperability across ASEAN member states

Fact Sheet 4: AI Risk and Harm Framework

This fact sheet explains how the proposed Bill identifies, categorises, and manages AI-related risks and harms.

1. What Is "Harm" Under the Bill?

The Bill uses "harm" as the primary anchor of the regulatory framework, focusing on actual outcomes and intent rather than purely technical classifications. Harm refers to any adverse effect arising from an AI system that results in:

2. What Is "Risk"?

Risk is the possibility that an AI system may cause the defined harms across its lifecycle. Risk is not a static label but is evaluated by assessing:

3. The Three-Tier Risk Framework

4. How regulations may be created under the framework

Any regulations which may be issued by the Central Authority under the Bill may be issued to govern one of the three categories:

5. International Benchmarks

Country / Organisation Legal Instrument Description
European Union AI Act (Regulation (EU) 2024/1689; entered into force 1 August 2024) Adopts a risk-based model with four tiers (prohibited, high-risk, limited risk, minimal risk), concentrating obligations on higher-risk uses anchored to real-world impacts; includes a prohibited-practices regime
Canada Directive on Automated Decision-Making; Algorithmic Impact Assessment (binding for federal public bodies); proposed AIDA (not enacted; Bill C-27 lapsed) Provides an impact-oriented model for the public sector where automated systems are assessed through structured scoring examining effects on rights, fairness, and safety; safeguards scale with impact level
United Kingdom White Paper: A Pro-Innovation Approach to AI Regulation (2023); Government Response and central-function package (2024) Follows a cross-sector, principles-based framework implemented by existing domain regulators; risk assessed by context of use rather than a universal classification
South Korea Framework Act on the Development of AI and the Establishment of a Foundation for Trust (in force 22 January 2026) Adopts a high-impact AI assessment model using criteria such as application area, risks to basic rights, severity, and frequency; operational detail left to subordinate guidance
Australia AI Ethics Framework; Guidance for AI Adoption Provides a nationally consistent framework building public confidence in government AI through explicit harm mitigation and ethical responsibility
OECD OECD AI Principles (adopted 2019; revised May 2024) Provides the central intergovernmental reference emphasising trustworthy AI through robustness, safety, and respect for rights

Fact Sheet 5: AI Incident Reporting

This fact sheet explains the national AI incident reporting framework proposed by the Bill, including how incidents are reported, investigated, and learned from.

1. Why Malaysia Needs AI Incident Reporting

AI is deployed across many sectors, and harms can arise in varied and unexpected contexts. Simultaneously, existing sectoral reporting mechanisms operate in silos without AI-specific coordination. Thus a consistent and structure incident reporting mechanism is required to ensure a systematic approach in identifying, assessing, learning, and addressing any AI-related incidents. This framework complements rather than displaces existing sectoral reporting mechanisms.

2. The Dual-Intake Model

The Bill uses a dual-intake model combining two pathways:

3. When Must an Incident Be Reported?

Reporting is triggered by any event, outcome, or credible allegation where an AI system is suspected of causing "Harm" (death, physical injury, deprivation of fundamental liberty, or contravention of any written law).

4. What Happens After Reporting?

5. National AI Incident Repository

The Bill establishes a National AI Incident Repository to give Malaysia a structured national picture of AI-related incidents, hazards, and emerging patterns of harm. It serves a policymaking and learning function: identifying recurring risks, refining governance measures, and informing future regulatory responses.

6. International Benchmarks

Country / Organisation Legal Instrument Description
European Union AI Act (Regulation (EU) 2024/1689), Article 73 Imposes serious-incident reporting on providers of high-risk AI systems linked to supervisory oversight and corrective action; recognises that duplication with sectoral regimes may be unnecessary in some regulated settings (Articles 73(9)–(10))
Japan AI Safety Institute of Japan (J-AISI) Approach Book for AI Incident Response Emphasises that reporting alone is insufficient unless institutions are also capable of detecting, containing, and responding to incidents in practice; treats incident response as an implementation-level capability
United States NIST AI Risk Management Framework (AI RMF 1.0, released 26 January 2023) and Generative AI Profile (NIST AI 600-1, 2024) Voluntary frameworks emphasising lifecycle risk management and incident response/recovery; convert broad governance concepts into risk-management functions and practices
Singapore Model AI Governance Framework (issued jointly by IMDA and PDPC, 2nd edition January 2020) Encourages incident management systems for continuous improvement; accountability-based framework enabling tailored governance measures alongside legal duties
India TEC Standard 57090:2025 (Telecommunication Engineering Centre, Department of Telecommunications) Provides a common schema and taxonomy for AI incident classification and data architecture in telecommunications and critical digital infrastructure
OECD OECD AI Incidents Monitor (AIM) and related interoperability work under the OECD.AI Policy Observatory Focused on comparability and interoperability across jurisdictions; supports building a shared evidence base, identifying patterns of risk, and coordinated learning

Fact Sheet 6: AI Enabling Powers

This fact sheet explains the enabling powers included in the proposed Bill that allow the governance framework to remain current and responsive as AI technology evolves.

1. Three Key Enabling Powers

2. Why These Powers Are Needed

AI governance is dynamic, technically complex, and cross-sectoral. Parliament cannot exhaustively legislate once and not adapt regulations to be up to speed with any developments in the ecosystem. This situation results in the "regulate and forget" problem. In order to move towards an "adapt and learn" mindset in regulations, the Bill intends to be agile by setting out a principle-based approach, while reserving matters relating to operationalising them to subsidiary regulations.

3. What Future Regulations May Cover

The regulations or other governance instruments that the Central Authority may issue, among others, cover the following aspects:

a) Classification and thresholds (risk tiers, prohibited classes) b) Procedures for Incident reporting and repository c) Technical and organisational safeguards (documentation, traceability, logging, human oversight, testing) d) Sandbox arrangements (eligibility, testing conditions, exit conditions) e) Implementation of specific standards to a class of AI, a domain of AI, or Sector.

4. Governance Instruments

Under the powers of the Central Authority, it may issue necessary governance instruments either as mandatory or voluntary instruments. Crucially, the instruments may be issued depending on various factors including:

a) Mandatory Instruments

b) Voluntary Instruments

5. International Benchmarks

Country / Organisation Legal Instrument Description
European Union AI Act (Regulation (EU) 2024/1689; entered into force 1 August 2024) Structures regulation through both fixed statutory provisions and implementing and delegated acts; includes prohibited practices, high-risk lifecycle obligations, and post-market surveillance powers enabling corrective action
United Kingdom White Paper: A Pro-Innovation Approach to AI Regulation (2023); central-function package (2024) Regulator-led, context-based approach where existing sectoral regulators apply AI governance principles proportionately within their domains; avoids a single omnibus AI Act in favour of flexible regulatory tooling
Japan Act on Promotion of Research and Development, and Utilization of AI-related Technology (Act No. 53 of 2025; enacted 28 May 2025, in full force 1 September 2025) Enabling national framework combining industrial promotion with governance expectations; establishes an AI Strategic Headquarters chaired by the Prime Minister; supplemented by detailed soft-law guidance
South Korea Framework Act on the Development of AI and the Establishment of a Foundation for Trust (enacted 21 January 2025, in force 22 January 2026) Combines industrial promotion with trust and safety obligations; contemplates a central "control tower" with power to issue instruments, intervene on high-impact AI, and coordinate across sectors
Canada Directive on Automated Decision-Making (binding for federal public bodies); Voluntary Code of Conduct on Responsible Development of Advanced Generative AI Systems (2024) Binding public-sector governance for automated decision-making plus non-binding generative AI governance; demonstrates phased approach from soft guidance to structured governance
China Interim Measures for the Management of Generative AI Services (issued 10 July 2023, effective 15 August 2023); Administrative Provisions on Algorithm Recommendation (effective 1 March 2022); Deep Synthesis Provisions (effective 10 January 2023) Develops a targeted binding stack aimed at specific AI functions; combines platform regulation, information control, and state supervision through service-specific measures

Fact Sheet 7: AI Sandbox Function

This fact sheet explains the AI Sandbox proposed by the Bill — a controlled environment for testing new AI systems under supervision before wider deployment.

1. What Is a Sandbox?

A sandbox is a controlled environment established to understand the opportunities and risks of specific AI innovations and develop appropriate responses. It is a governance mechanism, not a deregulated exception. It operates within the Bill by reference to the Principles, the risk framework, and the Central Authority's supervisory powers. It is not a licence for unmanaged experimentation but a structured supervisory pathway.

2. Why Malaysia Is Building a Sandbox

3. What could the sandbox do?

The sandbox intends on providing nine (9) potential functions:

  1. Assist in testing the execution of AI Systems such as running code, files, or software components in isolation.
  2. Provides a platform to develop AI systems in a non-production environment for building and configuring systems safely.
  3. Offer an integration platform for simulate or test different systems to connect and exchange data.
  4. Facilitating controlled access to data by anonymising or synthesising personal information, logging user activity and checking outputs, allowing researchers and model developers to analyse data safely.
  5. Evaluating AI models or algorithms under diverse scenarios, measuring accuracy, fairness, robustness and safety. This produces assurance evidence for certification, deployment or improvement.
  6. Testing AI-enabled products or services with limited users, time-bound pilots or restricted markets to gather feedback and performance data before a full launch.
  7. Assessing new workflows, organisational processes or policies by trialling them in a controlled setting to reveal operational risks and inform process redesign; and
  8. Providing simulated environments for individuals or teams to practise tasks, build competence and test decision-making without real-world consequences, such as cyber ranges or flight simulators.
  9. Permit regulated activities or innovations to be testing under a relaxed regulatory environment to test new innovations.

4. International Benchmarks

Country / Organisation Legal Instrument Description
European Union AI Act (Regulation (EU) 2024/1689), Articles 57–60 Requires each Member State to establish at least one AI regulatory sandbox at national level by 2 August 2026; sandboxes operate under competent authority supervision with defined entry conditions, testing periods, and exit/transition arrangements
Singapore Model AI Governance Framework (IMDA/PDPC); AI Verify Foundation (launched 2023 by IMDA, 90+ member organisations) Emphasises testing, demonstrable governance, and responsible deployment practices; AI Verify provides a practical testing toolkit for organisations to demonstrate responsible AI
United Kingdom Financial Conduct Authority (FCA) Regulatory Sandbox; Information Commissioner's Office (ICO) Regulatory Sandbox Uses sectoral regulatory sandboxes to test innovative use cases under existing regulator supervision; demonstrates how controlled testing generates supervisory insight
OECD OECD Regulatory Sandbox Toolkit (published July 2025) Defines a regulatory sandbox as "a controlled environment established to understand the opportunities and risks associated with specific innovations and to develop an appropriate regulatory environment"; provides guidance on design, implementation, and evaluation
Japan AI Guidelines for Business (published April 2024 by METI/MIC; updated to version 1.01 on 28 March 2025) Treats governance as something that must be updated as conditions change; supports experimental approaches through structured learning and iterative policy cycles
South Korea Framework Act on the Development of AI and the Establishment of a Foundation for Trust (in force 22 January 2026) Contemplates regulatory sandboxes as part of an innovation-oriented framework; combines trust and safety obligations with mechanisms for testing and graduated deployment