Malaysian AI Governance Grounding Note (S6–S7) 856 words

Malaysian AI Governance Grounding Note (S6–S7)

Built from the NAIO AI Governance Bill public-consultation fact sheets (copy in this folder: AI_Governance_Bill_Fact_Sheet.md). Status caveat for decks: the fact sheets are consultation documents — the Government is not bound by them; verify current Bill status the week of delivery and keep slide language as "proposed."

1. The reuse thesis

The proposed national framework and the capstone guideline are the same governance pattern at two scales. Teach the mapping explicitly in S6 — it converts "write a policy" from committee chore into applied national governance:

"Your institution's guideline is the proposed AI Bill scaled to a faculty: principles over rigid rules, obligations proportional to risk, incidents reported and learned from, a named authority that maintains the framework. Same logic, smaller jurisdiction."

2. The Bill's five principles ↔ the course's five principles (S6 crosswalk slide)

The Bill proposes five AI Principles that developers/deployers must have "due regard" for across the AI lifecycle. They align almost one-to-one with the Floridi/AI4People lens taught in S2:

Bill principle (NAIO) Course principle (S2) Guideline component it feeds
1. Human Dignity, Agency, and Rights Autonomy (+ beneficence) Principles; permission architecture
2. Transparency and Explainability Explicability Disclosure standard
3. Accountability and Redress The responsibility triad; justice Integrity procedure; ownership
4. Safety, Security, and Robustness Non-maleficence Assessment design; crutch-effect guardrails
5. Responsible Data Stewardship Justice + privacy risk Data & privacy rules (PDPA)

Landing line: participants aren't adopting a foreign framework — the national direction and the classroom ethics converge on the same five ideas.

3. The Bill's risk framework ↔ the three lanes (S6 core slide)

The Bill anchors regulation on harm (death, injury incl. mental, unlawful deprivation of liberty, contravention of written law) and evaluates risk by likelihood, severity/scale, duration/reversibility. Three tiers:

Bill tier Obligations Course-level equivalent
Tier 1 — Unacceptable risk Prohibited (manipulation, exploitative targeting, unlawful social scoring…) Uses that corrupt the credential itself (AI sitting a licensure exam) — 🔴 plus procedural bar
Tier 2 — High risk Mandatory measures: risk assessment, documentation, traceability, human oversight, testing, monitoring, incident notification Anything touching grades, references, admissions, records: human decision, AI second-reader at most, records kept, disclosure mandatory
Tier 3 — Low risk Baseline duties + "due regard" + voluntary instruments Ordinary coursework — 🟡 permitted-with-disclosure; 🟢 where fluency is the outcome

Note the Tier-2 obligation list — risk assessment, documentation, traceability, human oversight, monitoring — is the EAI-CMM Governance pillar and the verification-log habit from S4, at institutional scale.

4. Other Bill mechanisms worth borrowing (S6–S7 talking points)

5. PDPA 2010 — the statutory floor (component 6)

The Bill's Principle 5 (Responsible Data Stewardship) sits on top of existing law. PDPA 2010 governs personal data in commercial transactions; operationally for educators:

6. [LOCAL] slots the guideline owner must fill