# Malaysian AI Governance Grounding Note (S6–S7)
*Built from the NAIO **AI Governance Bill public-consultation fact sheets** (copy in this folder: `AI_Governance_Bill_Fact_Sheet.md`). Status caveat for decks: the fact sheets are consultation documents — the Government is not bound by them; verify current Bill status the week of delivery and keep slide language as "proposed."*

## 1. The reuse thesis
The proposed national framework and the capstone guideline are **the same governance pattern at two scales**. Teach the mapping explicitly in S6 — it converts "write a policy" from committee chore into applied national governance:

> "Your institution's guideline is the proposed AI Bill scaled to a faculty: principles over rigid rules, obligations proportional to risk, incidents reported and learned from, a named authority that maintains the framework. Same logic, smaller jurisdiction."

## 2. The Bill's five principles ↔ the course's five principles (S6 crosswalk slide)
The Bill proposes five AI Principles that developers/deployers must have **"due regard"** for across the AI lifecycle. They align almost one-to-one with the Floridi/AI4People lens taught in S2:

| Bill principle (NAIO) | Course principle (S2) | Guideline component it feeds |
|---|---|---|
| 1. Human Dignity, Agency, and Rights | Autonomy (+ beneficence) | Principles; permission architecture |
| 2. Transparency and Explainability | Explicability | Disclosure standard |
| 3. Accountability and Redress | The responsibility triad; justice | Integrity procedure; ownership |
| 4. Safety, Security, and Robustness | Non-maleficence | Assessment design; crutch-effect guardrails |
| 5. Responsible Data Stewardship | Justice + privacy risk | Data & privacy rules (PDPA) |

Landing line: participants aren't adopting a foreign framework — **the national direction and the classroom ethics converge on the same five ideas.**

## 3. The Bill's risk framework ↔ the three lanes (S6 core slide)
The Bill anchors regulation on **harm** (death, injury incl. mental, unlawful deprivation of liberty, contravention of written law) and evaluates **risk** by likelihood, severity/scale, duration/reversibility. Three tiers:

| Bill tier | Obligations | Course-level equivalent |
|---|---|---|
| **Tier 1 — Unacceptable risk** | Prohibited (manipulation, exploitative targeting, unlawful social scoring…) | Uses that corrupt the credential itself (AI sitting a licensure exam) — 🔴 plus procedural bar |
| **Tier 2 — High risk** | Mandatory measures: risk assessment, documentation, traceability, **human oversight**, testing, monitoring, incident notification | Anything touching **grades, references, admissions, records**: human decision, AI second-reader at most, records kept, disclosure mandatory |
| **Tier 3 — Low risk** | Baseline duties + "due regard" + voluntary instruments | Ordinary coursework — 🟡 permitted-with-disclosure; 🟢 where fluency is the outcome |

Note the Tier-2 obligation list — risk assessment, documentation, traceability, human oversight, monitoring — **is** the EAI-CMM Governance pillar and the verification-log habit from S4, at institutional scale.

## 4. Other Bill mechanisms worth borrowing (S6–S7 talking points)
- **Central Authority with four functions** (principles, safety, investigation/enforcement, enablement) ↔ the guideline's **named owner** (component 7): a policy without a maintainer is graffiti; the Bill institutionalizes the maintainer at national scale. Co-regulatory Sector Leads ↔ faculty-level implementation of an institution-level floor (the devolved-but-scaffolded shape from S6).
- **Principle-based, phased approach** — the Bill deliberately avoids rigid technology-specific rules ("regulate and forget" → "adapt and learn"), reserving detail for subsidiary instruments. Identical to the guideline design rule: *principles survive model churn; rules below them get versioned.* v0.1 + review date = phased implementation.
- **Incident reporting + National AI Incident Repository** (dual intake: statutory reports + user complaints) ↔ the guideline's integrity procedure and **v0.2 backlog**: capture failures, produce findings, feed review. An institution can run a miniature version: log AI-related incidents (false accusation, data leak, fabricated reference in materials) and review them at the policy's review date.
- **Sandbox** (controlled testing, not deregulation) ↔ piloting the guideline in one course/department before faculty-wide adoption; time-bound pilots with feedback are the Bill's own logic (function 6).
- **Definitions matter** — the Bill leads with five definitions (AI, AI system, lifecycle, developer, deployer). Mirrors guideline component 1: most policy fights are secretly definition fights. Note educators are usually **deployers** (duty-holders by domain of deployment) — a useful frame for who owns what.

## 5. PDPA 2010 — the statutory floor (component 6)
The Bill's Principle 5 (Responsible Data Stewardship) sits on top of existing law. PDPA 2010 governs personal data in commercial transactions; operationally for educators:

- Personal data is broad: names, IDs, contactable details, assessed work tied to an identifiable student.
- Principles that bite: general (consent/necessity), disclosure (stated purposes only), security (safeguards), retention.
- **Practical floor for the guideline:** no personal student data into external AI tools without institutional agreements; anonymize before pasting (S4 Lab-2 rule is PDPA rehearsal); institutional accounts over personal ones; `[LOCAL]` slot names the DPO/compliance owner. 2024-era amendments (breach notification, DPO requirements) raise the bar — verify current state at delivery.

## 6. `[LOCAL]` slots the guideline owner must fill
- MQA programme standards terminology alignment
- Current MOHE guidance (verify at delivery)
- Institutional DPO / data-governance committee (PDPA clause owner)
- Senate/faculty approval path and review cadence
- Current status of the AI Bill (consultation → tabling — check week of delivery)
