FOR DISCUSSION PURPOSES ONLY — NATIONAL AI OFFICE
Prepared by the National AI Office (NAIO), Malaysia
This document contains six fact sheets to assist members of the public in providing preliminary feedback and input on the formation of a national AI Bill.
Disclaimer: This document has been prepared solely for public consultation purposes only and does not constitute the complete Bill. The Government is not bound by the contents of this fact sheet in developing the final Bill, and all proposals remain subject to further review and amendment.
As it stands, there are five (5) key definitions which are considered by the Bill. They are:
a) Artificial Intelligence "Artificial Intelligence" or "AI" means a functional capacity, or a set of methods or automated entities that, whether individually or in combination, build, optimise or apply a feature or model so as to enable a system, for a given set of defined or pre-defined tasks, to simulate cognitive functions characteristic of a natural person.
b) Artificial Intelligence Systems A system shall be deemed to be an "Artificial Intelligence system" or "AI system" if the system features or has Artificial Intelligence.
c) Artificial Intelligence Lifecycle "Artificial Intelligence lifecycle" means the actions carried out in relation to an AI system from its creation until its withdrawal, and includes any activity carried out before, during or after deployment.
d) Developer "Any person (natural or legal) who creates, causes to be created, materially modifies, or changes the intended purpose of an AI system or its underlying model."
e) Deployer "Any person (natural or legal) who puts an AI system into service, or makes it available for use by a third party."
The Bill intends to regulate AI systems which:
(a) Are placed on the market or put into service within Malaysia (b) Designed, developed, or used in Malaysia; and (c) Used by a deployer established in Malaysia, regardless of where the system is physically hosted.
This fact sheet explains how the proposed AI Bill establishes a Central Authority to lead and coordinate AI governance across Malaysia.
Artificial intelligence ("AI") is not confined to a single sector. It is used across finance, healthcare, transport, education, public administration, and many other fields. The differing sectors and industries in which AI may be deployed comes with it the risk of fragmentation of how it is governed applying inconsistent standards and expectations.
Through a Central AI Authority with a clear set national "baseline" principles and standards, it strengthens the overall system by addressing areas of uneven capacity between differing sectors. Ultimately, a concerted governance ecosystem uplifts Malaysia's regulatory framework by achieving a balance between promoting innovation while ensuring safe use.
The Central AI Authority will have the following four (4) core functions:
The Central AI Authority will have the following key powers:
| Functions | Related powers |
|---|---|
| Operationalising National AI Principles | • Operationalising baseline AI Principles • Coordinate with Sectoral Leads in implementing the AI Principles • Issuing mandatory or non-mandatory legal instruments (where necessary) for the implementation of the principles |
| AI Safety Functions | • Undertaking research, analysis, and provide recommendations to improve AI adoption. • Developing Incident Reporting mechanisms for AI Risks and Harms • Provide recommendations to address any AI related risks or harm |
| Investigation and Enforcement functions | • Issue governance instruments (subsidiary regulations, codes, standards, guidelines) • Oversee and enforce compliance with statutory requirements • Issue directions or orders to mitigate risk and prevent harm • Impose interim risk-control measures and administrative penalties |
| AI enablement functions | • Undertake AI Capacity Building initiatives and functions • Supervisory role for the implementation of specific standards, principles, or instruments. |
The Central AI Authority will operate a co-regulatory model with other Sectoral Regulators through a Sector Lead. The Sector Lead may support the implementation of the AI Principles where they have sufficient legal authority, technical expertise, and governance capacity. This ultimately empowers each Sector Lead to implement sector specific guidance which remains consistent with the AI Principles.
The Central AI Authority may appoint a Sector Lead and subsequently delegate the following functions:
a) Advise the Central Authority for the issuance of Sector-Specific legal instruments including subsidiary regulations, guidelines, or code of ethics; b) Be delegated the power to implement its own sector specific policies; and c) Assist the Central Authority in implementing and enforcing the Bill.
| Country / Organisation | Legal Instrument | Description |
|---|---|---|
| European Union | EU AI Office, established by Commission Decision of 24 January 2024; designated under the AI Act (Regulation (EU) 2024/1689) as the central implementation body | Serves as the foundation for a single AI governance system in the EU; enforces rules for general-purpose AI models; supports governance bodies in Member States |
| Japan | Act on Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technologies ("AI Act") | Establishes a national AI "control tower" for the implementation of the Act. Primarily, the Council may issue recommendations to any entity which in turn "shall take appropriate follow-up measures" |
This fact sheet outlines the five fundamental principles that guide the development and use of AI systems under the proposed Bill.
The Bill establishes five (5) core AI Principles that every developer and deployer must have "due regard" throughout the AI lifecycle. These principles are aligned with local and international frameworks, including the Federal Constitution of Malaysia, the OECD Recommendation on AI, and ASEAN guidelines.
The Bill adopts a principle-based approach rather than prescribing detailed, technology-specific rules. AI is a rapidly evolving technology, hence rigid rules risk becoming outdated quickly and may stifle innovation. A principle-based framework offers two key benefits:
(a) Provides flexibility, allowing the Central Authority to remain agile in implementation by among others, issue practical guidance across different sectors without amending primary legislation; and (b) Enables proportionate regulation as lower-risk AI applications are not subject to the same burden as higher-risk ones; and
The proposed principles have been distilled based on insights from international frameworks, as well as local legal instruments such as the Federal Constitution.
Principle 1: Human Dignity, Agency, and Rights AI governance must uphold human dignity and prevent individuals from being reduced to mere data points. AI systems must remain subject to human-centred values. This is the first and foundational principle of the proposed Bill.
Principle 2: Transparency and Explainability Where AI is used in decision-making, affected persons should not be left unaware that AI is involved, nor left unable to understand the system's purpose or challenge its outputs. This principle requires clear, meaningful, and context-appropriate information, framed proportionately.
Principle 3: Accountability and Redress Responsibility for AI systems must remain attributable to identifiable persons or organisations. Responsibility must never be displaced onto the AI system itself. Affected individuals must have accessible avenues to challenge and remedy harmful outcomes.
Principle 4: Safety, Security, and Robustness AI systems must be designed, developed, deployed, and maintained in a manner that is safe, secure, robust, and resilient. This supports duties concerning risk identification, pre-deployment testing, validation, cybersecurity controls, monitoring for drift or failure, and incident management.
Principle 5: Responsible Data Stewardship Data used across the AI lifecycle must be governed responsibly, lawfully, and with sufficient quality, traceability, integrity, and safeguards appropriate to the intended purpose and context.
Developers and deployers of AI systems must have "due regard" for these principles throughout the AI system's lifecycle. "Due regard" means actively applying the principles in a way that is proportionate to the system's nature, context, and potential impact.
Compliance is scaled based on the level of risk, context, and purpose of the AI system. Developers and deployers should anticipate future developments and consider these principles over the long term.
The Bill intends to be agile by setting out the principles, while reserving any operational requirements of the principles to other governance instruments including, but not limited to, subsidiary regulations or guidelines.
The implementation of the principles will also take a phased approach. In the initial stages of the Bill, focus will be given to socialising the principles and creating awareness while other efforts such as codifying full implementation of the principles to be done at a later stage.
| Country / Organisation | Legal Instrument | Description |
|---|---|---|
| OECD | OECD Council Recommendation on AI (OECD/LEGAL/0449; adopted May 2019, revised November 2023 and May 2024) | The first intergovernmental standard on AI; establishes principles of inclusive growth, human-centred values and fairness, transparency and explainability, robustness, security and safety, and accountability; adopted by 49 adherents as of 2024 |
| UNESCO | Recommendation on the Ethics of AI (adopted 23 November 2021 by all 193 Member States) | The first global standard-setting instrument on AI ethics; provides universal normative orientation covering privacy, dignity, transparency, accountability, and broader ethical direction |
| Council of Europe | Framework Convention on AI and Human Rights, Democracy and the Rule of Law (adopted 17 May 2024; opened for signature 5 September 2024) | The first international legally binding treaty on AI; requires graduated and differentiated governance measures anchored in human rights, democracy, and the rule of law |
| European Union | AI Act (Regulation (EU) 2024/1689; entered into force 1 August 2024) | Structures regulation through prohibited practices, high-risk systems, transparency duties, and general-purpose AI models; embeds principles of safety, fundamental rights, human oversight, and accountability |
| ISO/IEC | ISO/IEC 42001:2023; ISO/IEC 23894:2023; ISO/IEC 22989:2022 | Provides voluntary organisational-level management-system governance for AI including risk identification, documentation, transparency, human oversight, and continual improvement; ISO/IEC 42001 is the first AI management-system standard |
| ASEAN | ASEAN Guide on AI Governance and Ethics (2024); expanded Generative AI Guide (2025) | Regional guidance promoting human-centricity, fairness, transparency, accountability, and robustness; designed for interoperability across ASEAN member states |
This fact sheet explains how the proposed Bill identifies, categorises, and manages AI-related risks and harms.
The Bill uses "harm" as the primary anchor of the regulatory framework, focusing on actual outcomes and intent rather than purely technical classifications. Harm refers to any adverse effect arising from an AI system that results in:
Risk is the possibility that an AI system may cause the defined harms across its lifecycle. Risk is not a static label but is evaluated by assessing:
Tier 1: Unacceptable risk Systems developed or used to cause harm or with the intent of committing harm, and whose core function is inherently capable of causing harm justifying prohibition. Examples include serious manipulation, exploitative targeting of vulnerability, unlawful social scoring, serious biometric abuse, or developing an AI with the intent of causing harm.
Tier 2: High Risk Systems not inherently prohibited but creating a level of risk of causing harm, justifying heightened mandatory measures including risk assessment, documentation, traceability, human oversight, testing, validation, monitoring, and incident notification.
Tier 3: Low Risk Systems governed through baseline obligations, the due regard requirement, and voluntary or lighter instruments.
Any regulations which may be issued by the Central Authority under the Bill may be issued to govern one of the three categories:
| Country / Organisation | Legal Instrument | Description |
|---|---|---|
| European Union | AI Act (Regulation (EU) 2024/1689; entered into force 1 August 2024) | Adopts a risk-based model with four tiers (prohibited, high-risk, limited risk, minimal risk), concentrating obligations on higher-risk uses anchored to real-world impacts; includes a prohibited-practices regime |
| Canada | Directive on Automated Decision-Making; Algorithmic Impact Assessment (binding for federal public bodies); proposed AIDA (not enacted; Bill C-27 lapsed) | Provides an impact-oriented model for the public sector where automated systems are assessed through structured scoring examining effects on rights, fairness, and safety; safeguards scale with impact level |
| United Kingdom | White Paper: A Pro-Innovation Approach to AI Regulation (2023); Government Response and central-function package (2024) | Follows a cross-sector, principles-based framework implemented by existing domain regulators; risk assessed by context of use rather than a universal classification |
| South Korea | Framework Act on the Development of AI and the Establishment of a Foundation for Trust (in force 22 January 2026) | Adopts a high-impact AI assessment model using criteria such as application area, risks to basic rights, severity, and frequency; operational detail left to subordinate guidance |
| Australia | AI Ethics Framework; Guidance for AI Adoption | Provides a nationally consistent framework building public confidence in government AI through explicit harm mitigation and ethical responsibility |
| OECD | OECD AI Principles (adopted 2019; revised May 2024) | Provides the central intergovernmental reference emphasising trustworthy AI through robustness, safety, and respect for rights |
This fact sheet explains the national AI incident reporting framework proposed by the Bill, including how incidents are reported, investigated, and learned from.
AI is deployed across many sectors, and harms can arise in varied and unexpected contexts. Simultaneously, existing sectoral reporting mechanisms operate in silos without AI-specific coordination. Thus a consistent and structure incident reporting mechanism is required to ensure a systematic approach in identifying, assessing, learning, and addressing any AI-related incidents. This framework complements rather than displaces existing sectoral reporting mechanisms.
The Bill uses a dual-intake model combining two pathways:
Reporting is triggered by any event, outcome, or credible allegation where an AI system is suspected of causing "Harm" (death, physical injury, deprivation of fundamental liberty, or contravention of any written law).
The Bill establishes a National AI Incident Repository to give Malaysia a structured national picture of AI-related incidents, hazards, and emerging patterns of harm. It serves a policymaking and learning function: identifying recurring risks, refining governance measures, and informing future regulatory responses.
| Country / Organisation | Legal Instrument | Description |
|---|---|---|
| European Union | AI Act (Regulation (EU) 2024/1689), Article 73 | Imposes serious-incident reporting on providers of high-risk AI systems linked to supervisory oversight and corrective action; recognises that duplication with sectoral regimes may be unnecessary in some regulated settings (Articles 73(9)–(10)) |
| Japan | AI Safety Institute of Japan (J-AISI) Approach Book for AI Incident Response | Emphasises that reporting alone is insufficient unless institutions are also capable of detecting, containing, and responding to incidents in practice; treats incident response as an implementation-level capability |
| United States | NIST AI Risk Management Framework (AI RMF 1.0, released 26 January 2023) and Generative AI Profile (NIST AI 600-1, 2024) | Voluntary frameworks emphasising lifecycle risk management and incident response/recovery; convert broad governance concepts into risk-management functions and practices |
| Singapore | Model AI Governance Framework (issued jointly by IMDA and PDPC, 2nd edition January 2020) | Encourages incident management systems for continuous improvement; accountability-based framework enabling tailored governance measures alongside legal duties |
| India | TEC Standard 57090:2025 (Telecommunication Engineering Centre, Department of Telecommunications) | Provides a common schema and taxonomy for AI incident classification and data architecture in telecommunications and critical digital infrastructure |
| OECD | OECD AI Incidents Monitor (AIM) and related interoperability work under the OECD.AI Policy Observatory | Focused on comparability and interoperability across jurisdictions; supports building a shared evidence base, identifying patterns of risk, and coordinated learning |
This fact sheet explains the enabling powers included in the proposed Bill that allow the governance framework to remain current and responsive as AI technology evolves.
AI governance is dynamic, technically complex, and cross-sectoral. Parliament cannot exhaustively legislate once and not adapt regulations to be up to speed with any developments in the ecosystem. This situation results in the "regulate and forget" problem. In order to move towards an "adapt and learn" mindset in regulations, the Bill intends to be agile by setting out a principle-based approach, while reserving matters relating to operationalising them to subsidiary regulations.
The regulations or other governance instruments that the Central Authority may issue, among others, cover the following aspects:
a) Classification and thresholds (risk tiers, prohibited classes) b) Procedures for Incident reporting and repository c) Technical and organisational safeguards (documentation, traceability, logging, human oversight, testing) d) Sandbox arrangements (eligibility, testing conditions, exit conditions) e) Implementation of specific standards to a class of AI, a domain of AI, or Sector.
Under the powers of the Central Authority, it may issue necessary governance instruments either as mandatory or voluntary instruments. Crucially, the instruments may be issued depending on various factors including:
a) Mandatory Instruments
b) Voluntary Instruments
| Country / Organisation | Legal Instrument | Description |
|---|---|---|
| European Union | AI Act (Regulation (EU) 2024/1689; entered into force 1 August 2024) | Structures regulation through both fixed statutory provisions and implementing and delegated acts; includes prohibited practices, high-risk lifecycle obligations, and post-market surveillance powers enabling corrective action |
| United Kingdom | White Paper: A Pro-Innovation Approach to AI Regulation (2023); central-function package (2024) | Regulator-led, context-based approach where existing sectoral regulators apply AI governance principles proportionately within their domains; avoids a single omnibus AI Act in favour of flexible regulatory tooling |
| Japan | Act on Promotion of Research and Development, and Utilization of AI-related Technology (Act No. 53 of 2025; enacted 28 May 2025, in full force 1 September 2025) | Enabling national framework combining industrial promotion with governance expectations; establishes an AI Strategic Headquarters chaired by the Prime Minister; supplemented by detailed soft-law guidance |
| South Korea | Framework Act on the Development of AI and the Establishment of a Foundation for Trust (enacted 21 January 2025, in force 22 January 2026) | Combines industrial promotion with trust and safety obligations; contemplates a central "control tower" with power to issue instruments, intervene on high-impact AI, and coordinate across sectors |
| Canada | Directive on Automated Decision-Making (binding for federal public bodies); Voluntary Code of Conduct on Responsible Development of Advanced Generative AI Systems (2024) | Binding public-sector governance for automated decision-making plus non-binding generative AI governance; demonstrates phased approach from soft guidance to structured governance |
| China | Interim Measures for the Management of Generative AI Services (issued 10 July 2023, effective 15 August 2023); Administrative Provisions on Algorithm Recommendation (effective 1 March 2022); Deep Synthesis Provisions (effective 10 January 2023) | Develops a targeted binding stack aimed at specific AI functions; combines platform regulation, information control, and state supervision through service-specific measures |
This fact sheet explains the AI Sandbox proposed by the Bill — a controlled environment for testing new AI systems under supervision before wider deployment.
A sandbox is a controlled environment established to understand the opportunities and risks of specific AI innovations and develop appropriate responses. It is a governance mechanism, not a deregulated exception. It operates within the Bill by reference to the Principles, the risk framework, and the Central Authority's supervisory powers. It is not a licence for unmanaged experimentation but a structured supervisory pathway.
The sandbox intends on providing nine (9) potential functions:
| Country / Organisation | Legal Instrument | Description |
|---|---|---|
| European Union | AI Act (Regulation (EU) 2024/1689), Articles 57–60 | Requires each Member State to establish at least one AI regulatory sandbox at national level by 2 August 2026; sandboxes operate under competent authority supervision with defined entry conditions, testing periods, and exit/transition arrangements |
| Singapore | Model AI Governance Framework (IMDA/PDPC); AI Verify Foundation (launched 2023 by IMDA, 90+ member organisations) | Emphasises testing, demonstrable governance, and responsible deployment practices; AI Verify provides a practical testing toolkit for organisations to demonstrate responsible AI |
| United Kingdom | Financial Conduct Authority (FCA) Regulatory Sandbox; Information Commissioner's Office (ICO) Regulatory Sandbox | Uses sectoral regulatory sandboxes to test innovative use cases under existing regulator supervision; demonstrates how controlled testing generates supervisory insight |
| OECD | OECD Regulatory Sandbox Toolkit (published July 2025) | Defines a regulatory sandbox as "a controlled environment established to understand the opportunities and risks associated with specific innovations and to develop an appropriate regulatory environment"; provides guidance on design, implementation, and evaluation |
| Japan | AI Guidelines for Business (published April 2024 by METI/MIC; updated to version 1.01 on 28 March 2025) | Treats governance as something that must be updated as conditions change; supports experimental approaches through structured learning and iterative policy cycles |
| South Korea | Framework Act on the Development of AI and the Establishment of a Foundation for Trust (in force 22 January 2026) | Contemplates regulatory sandboxes as part of an innovation-oriented framework; combines trust and safety obligations with mechanisms for testing and graduated deployment |