Malaysia's First AI Law Is Coming. Here's What's Actually in It
For years, Malaysia governed artificial intelligence the way most countries did before they had to, with guidelines nobody could be fined for ignoring. The National Guidelines on AI Governance and Ethics, published by Malaysia's Ministry of Science, Technology and Innovation back in September 2024, told developers and deployers what "responsible AI" should look like. It just never made anyone legally responsible for anything.
Malaysia is now attempting to change that. On 10 July 2026, the National AI Office (NAIO), operating under the Ministry of Digital, released a Public Consultation Paper for what would become Malaysia's first horizontal AI statute: a single law covering AI across every sector, rather than a patchwork of guidelines, data protection rules, and whatever a particular regulator happens to think about algorithms this year. Written submissions closed on 31 July 2026, and the government has said it wants the Bill tabled and completed before the year is out. That is an aggressive timeline for a law this broad, and it tells you something about how urgently Putrajaya wants this on the books.
Why "horizontal" matters here
Most of the world's AI rules so far have been vertical. A banking regulator handles AI in banking, a health authority handles AI in diagnostics, and everything in between is grey space. Malaysia's own consultation paper is refreshingly candid about the problem this creates: it warns of "differing standards and approaches" building up across sectors, and notes that existing tools only really respond after something has already gone wrong.
The Bill tries to fix that by sitting above the sector specific rules rather than replacing them. It rests on three pillars.
- First, a Central AI Authority, which would still lean on existing regulators (think Bank Negara Malaysia for financial services or the Securities Commission for capital markets) through what the paper calls "Sectoral Leads."
- Second, a set of baseline principles written into law rather than left as suggestions: human dignity, transparency and explainability, accountability, safety and security, and data governance.
- Third, a structure that scales obligations to how dangerous a given AI system actually is, instead of regulating a spam filter and a hospital triage algorithm with the same rulebook.
The mechanics: three tiers, two roles, one authority
The risk framework itself splits into three tiers: Tier 1 for unacceptable risk, Tier 2 for high risk, and Tier 3 for low risk, with obligations scaling up as the potential for harm does. Obligations fall on two kinds of actors: Developers, who materially shape what a system can do, and Deployers, who actually run it in the real world. A single company can be both. This split deliberately echoes the controller and processor distinction from Malaysia's Personal Data Protection Act, though not perfectly, a point several legal commentators have already flagged as a source of future confusion, since a Deployer processing personal data will usually be a controller under the PDPA, while a Developer offering a hosted model might only be a processor.
The Central AI Authority itself is proposed to run three functions: an AI Safety function that maintains the risk framework and oversees testing and incident reporting; an Investigation and Enforcement function with power to demand fact finding and issue directions after incidents; and an AI Enablement function that produces guidance, templates, training, and runs the AI Sandbox, a controlled testing environment meant to let companies experiment before the full weight of compliance lands on them. For smaller businesses without in house compliance teams, that enablement mandate may end up mattering more day to day than the enforcement powers do.
Two more features round out the design. An incident reporting mechanism would require Developers and Deployers to flag not just failures but near misses and unexpected effects, with the public also able to lodge complaints directly. And the Bill's territorial reach is broad by design: it would apply to any AI system designed, developed, or used in Malaysia, regardless of where the underlying infrastructure sits, carving out exemptions only for personal use and national security matters.
How this stacks up against the EU AI Act
Malaysia's drafters have clearly been reading Brussels' homework, and it shows in the structure: a tiered risk model, a central authority, mandatory obligations tied to risk level. But the resemblance is more skeletal than skin deep once you look at the details.
The EU AI Act is a fully codified regulation running to hundreds of pages, with named prohibited practices spelled out in an annex, specific high risk categories listed by sector, and detailed conformity assessment procedures before a system ever reaches the market. Malaysia's Bill, at consultation stage, is still working from principles and a harm list rather than an exhaustive catalogue of prohibited or high risk use cases, closer in spirit to a framework law that leaves the granular detail to subsidiary guidelines and Sectoral Leads. That's partly a function of timeline: the EU spent roughly three years negotiating its Act before adoption, while Malaysia is trying to move from consultation paper to finished statute inside a single year.
Enforcement philosophy differs too. Brussels built the AI Act around compliance that happens before deployment: conformity assessments, technical documentation, and sign off procedures similar to product safety certification, particularly for high risk systems. Malaysia's design leans more on an enablement first posture, with sandboxes, guidance, and incident reporting sitting alongside enforcement powers rather than in front of them, at least as currently framed. Whether that survives contact with the final legislative text is an open question. The consultation drew real pushback from law firms wanting harsher penalty ranges and clearer thresholds, so the version tabled in Parliament may look tougher than the one made public in July.
There's also a jurisdictional difference worth flagging. The EU AI Act has genuine extraterritorial teeth backed by the largest single market in the developed world, which is why companies far outside Europe still comply with it. Malaysia's Bill claims similarly broad reach on paper, covering any system used in Malaysia regardless of where it's hosted, but the practical leverage to enforce that against a foreign Developer is a different question entirely, and one the Edwin Lee and Partners (Law firm based in malaysia) submission specifically raised as a gap needing an international cooperation mechanism.
India and AI Regulation
India has spent the past year deliberately walking in the evolving direction. Through MeitY's India AI Governance Guidelines, released in November 2025 ahead of the India AI Impact Summit, explicitly reject a standalone AI statute in favour of what officials have repeatedly called a "light touch" model: seven guiding principles, trust, people first, innovation, fairness, accountability, transparency, and safety, layered on top of existing law rather than a new one. The Digital Personal Data Protection Act, 2023 and the IT Act, 2000 with amendment rules, do most of the actual legal work, with sector regulators like the RBI and SEBI handling the specifics for their own industries.
The contrast with Malaysia is almost a case study in two governance philosophies. Where Malaysia is building a central authority with enforcement teeth from day one, India has so far preferred advisory bodies, an AI Governance Group and a proposed AI Safety Institute, that shape norms without imposing binding cross sectoral obligations.
Where Malaysia's Bill would be justiciable law with penalties attached, India's framework is closer to a philosophy statement with sandboxes and a national incident database bolted on. That is not a weaker approach so much as a different, and arguably shrewd, bet. India is the world's largest testing ground for AI adoption at scale, from welfare delivery to vernacular language tools, and a heavy compliance regime risks slowing exactly the kind of grassroots experimentation the government is trying to encourage. Betting on existing law and institutional judgment, at least for now, keeps that door open, and it has let India move fast without waiting for a perfect law first.
That said, India's position has been visibly shifting. In July 2026, MeitY Secretary S. Krishnan signalled the government is now exploring dedicated AI legislation after all, a notable departure from the "no early regulation" stance the ministry had held in 2023, and this is likely accelerated by growing concern over deepfakes and synthetic media, which already prompted binding traceability and labelling obligations under amended intermediary rules earlier this year.
The stakes for the next few months
None of this is finished. Malaysia's Bill is still a consultation paper, not enacted law, and the gap between what NAIO proposed in July and what Parliament eventually passes could be significant. Several submissions are already pushing for a wider harm list, sharper enforcement thresholds, and clearer rules for foreign Developers who never set foot in Kuala Lumpur. But the direction is set. Malaysia has decided AI governance can no longer run on goodwill and voluntary guidelines, and it now attempts to write enforceable AI law on a real deadline rather than settling for guidelines. However, the final Bill lives up to that ambition, or gets watered down in the process, is something only the next few months will show.
References
- Ministry of Digital. "Kementerian Digital Mulakan Libat Urus Cadangan Rang Undang Undang Tadbir Urus Kecerdasan Buatan (AI)." 10 July 2026. https://www.digital.gov.my/en-GB/siaran/Kementerian-Digital-Mulakan-Libat-Urus-Cadangan-Rang-Undang-Undang-Tadbir-Urus-Kecerdasan-Buatan-(AI)
- Digital Watch Observatory. "Malaysia launches consultations on AI Governance Bill." July 2026. https://dig.watch/updates/malaysia-ai-governance-bill-consultation
- Baker McKenzie, Wong and Partners. "Malaysia: Public Consultation on the AI Governance Bill." July 2026. https://www.bakermckenzie.com/en/insight/publications/2026/07/malaysia-public-consultation-on-the-ai-governance-bill
- Digital Policy Alert. "Testing requirements in AI Governance Bill" and related entries on the National AI Office consultation. https://digitalpolicyalert.org
- Rahmat Lim and Partners. "National AI Office issues public consultation paper on proposed Artificial Intelligence (AI) Governance Bill." https://www.rahmatlim.com/perspectives/articles/33264/mykh-national-ai-office-issues-public-consultation-paper-on-proposed-artificial-intelligence-ai-governance-bill
- Edwin Lee and Partners. "Malaysia's AI Governance Bill: Our Submission to the Consultation." https://lpplaw.my/ai-governance-malaysia/
- Kiizen. "Overview of the Proposed Malaysia's AI Governance Bill." https://www.kiizen.com.my/proposed-malaysias-ai-governance-bill/
- Zicelegal. "Consultation Alert: Public Consultation on Malaysia's AI Governance Bill." https://www.ziclegal.com/resources/consultation-alert-public-consultation-on-malaysias-ai-governance-bill
- Welcome.AI. "Malaysia's AI Governance Bill Expands Regulation and Accountability for Businesses." July 2026. https://www.welcome.ai/content/malaysias-ai-governance-bill-expands-regulation-and-accountability-for-businesses
- Regulations.ai. "Malaysia AI Regulation Overview." https://regulations.ai/regulations/RAI-MY-NA-SUMMARY-2026
- w.media. "Malaysia to enact AI law." https://w.media/malaysia-to-enact-ai-law/
- VisionIAS. "India's New AI Governance Guidelines Push Hands Off Approach." November 2025. https://visionias.in/blog/current-affairs/indias-new-ai-governance-guidelines-push-hands-off-approach
- EY India. "AI governance guidelines: A bet on innovation." https://www.ey.com/en_in/insights/ai/ai-governance-guidelines-a-bet-on-innovation
- TechnoSports. "Airegulation: Indian Government Finalizes AI Regulation." May 2026. https://technosports.co.in/airegulation-india-framework/
- The AI Track. "India AI Governance Guidelines Released for 2025 to 26." https://theaitrack.com/india-ai-governance-guidelines-2025/
- Lexology, contributed by a law firm. "India's AI Governance Model: MeitY's AI Guidelines and The Evolving Copyright Landscape." March 2026. https://www.lexology.com/library/detail.aspx?g=ffc0c58c-3727-4472-9914-5fa6a33ffffd
- Srishti IAS. "India's First AI Governance Framework 2026: Principles, Oversight, and Inclusive Growth Strategy." February 2026. https://srishtiias.com/india-first-ai-governance-framework-ahead-of-impact-summit-2026/
- Whalesbook. "India Plans Dedicated AI Law, Shifting From Light Touch Approach." July 2026. https://www.whalesbook.com/news/English/other/India-Plans-Dedicated-AI-Law-Shifting-From-Light-Touch-Approach/6a4811c9c7db2a6cf1650f24
- Saikrishna and Associates. "Decoding the India AI Governance Guidelines." November 2025. https://www.saikrishnaassociates.com/decoding-the-india-ai-governance-guidelines/
- News on Air. "MeitY Unveils India AI Governance Guidelines to Promote Safe and Responsible AI Adoption." 5 November 2025. https://www.newsonair.gov.in/meity-unveils-india-ai-governance-guidelines-to-promote-safe-and-responsible-ai-adoption
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Senior Research Analyst, Policy & Advocacy, CyberPeace








