Malaysia has positioned itself as a preferred Southeast Asian destination for AI investment, and its governance architecture reflects that ambition. There is no AI statute. There are national guidelines that carry no statutory duty, a national AI agency that coordinates rather than regulates, and a Personal Data Protection Act that reaches AI indirectly through the data it consumes. For global operators entering the Malaysian market or running AI deployments that affect Malaysian users, the work is to see clearly which of these layers actually binds, and to recognise that the heaviest obligations they carry will usually come from somewhere else, most often the EU AI Act.
Key takeaways
- Malaysia has no enacted AI statute. Nothing at ai.gov.my, mosti.gov.my or digital.gov.my identifies an AI act or an AI bill before Parliament. Anyone who tells you Malaysia regulates AI by legislation is describing a country that does not exist yet.
- The national instrument is the National Guidelines on AI Governance and Ethics, AIGE, launched on 20 September 2024 by the Ministry of Science, Technology and Innovation. Malaysia's official AI portal describes it as resting on seven key AI principles. It is guidance. Non-adoption carries no statutory penalty.
- The National AI Office, launched on 12 December 2024 under the Digital Ministry, was replaced on 28 July 2026 by AI Malaysia Berhad, described at source as the national agency mandated to lead, coordinate and accelerate the AI ecosystem. It is a coordinating agency. Nothing at its own site gives it powers to license, inspect, order or fine.
- The National AI Action Plan 2026-2030 was launched on 28 July 2026 and supersedes the AI Roadmap 2021-2025. Alongside it, AI Malaysia published a Voluntary AI Code of Ethics, which its own download page requires readers to acknowledge is not legally binding.
- The Personal Data Protection Act 2010, Act 709, amended by the Personal Data Protection (Amendment) Act 2024, is the practical binding layer for AI that touches personal data. Its seven principles under section 5 do not include any right against solely automated decisions. Registration duties under section 15 now attach to thirteen classes of data controller.
- For financial institutions, Bank Negara Malaysia's binding technology instrument is the Risk Management in Technology policy document of 28 November 2025. Its AI work so far is a discussion paper issued on 5 August 2025, which imposes nothing.
- The EU AI Act (Regulation (EU) 2024/1689) applies to any operator whose AI outputs affect persons located in the EU, regardless of where the operator is incorporated. For most Malaysian operators with European exposure, this is the heaviest obligation in the file.
Malaysia's position in regional AI governance
Malaysia's approach to AI governance is shaped by two strategic priorities that sit in productive tension. The first is the ambition to become a leading AI hub in Southeast Asia, attracting data centre capacity, AI talent and AI-enabled enterprise activity. The second is the need to protect consumers and maintain market integrity as AI penetration deepens across financial services, healthcare, manufacturing and public administration.
The response so far has been institutional rather than legislative. Malaysia built an agency, published guidelines, and left the statute book alone. There is no AI act. There is no AI bill listed at the Digital Ministry. The binding constraints on an AI deployment in Malaysia come from laws that were written for other purposes and happen to reach AI, above all the Personal Data Protection Act 2010 and, for licensed financial institutions, Bank Negara Malaysia's technology risk standard.
This is close to Singapore's posture, and readers running both markets will find the comparison useful. See our Singapore AI governance guide for a parallel analysis. The practical consequence in both places is the same: an operator who builds a compliance programme by reading the national AI guidelines will have built almost nothing enforceable, and will still be exposed on data protection and on any European market they touch.
From the AI Roadmap to the National AI Action Plan
The Artificial Intelligence Roadmap 2021-2025 is held in the publications catalogue of the Malaysian Science and Technology Information Centre, MASTIC, which sits within the Ministry of Science, Technology and Innovation. It is a MOSTI document. Its detailed strategic thrusts could not be read at source and are therefore not restated here.
The institutional picture has since moved twice. The National AI Office was launched on 12 December 2024 under the Digital Ministry. On 28 July 2026 it was replaced by AI Malaysia Berhad, described on its own site as "the national agency under the Digital Ministry, mandated to lead, coordinate, and accelerate the nation's artificial intelligence (AI) ecosystem towards realising the AI Nation 2030 vision." The same day, AI Malaysia launched the National AI Action Plan 2026-2030, the successor to the roadmap.
Read the mandate carefully. Lead, coordinate, accelerate. Not license, not inspect, not sanction. Nothing published at ai.gov.my confers a supervisory power on AI Malaysia Berhad, and an operator should not treat correspondence from it as regulatory action. Seven working groups sit under the agency, drawing on industry, academia, government and civil society. The governance output of that machinery to date is guidance.
The AIGE guidelines and the Voluntary AI Code of Ethics
The National Guidelines on AI Governance and Ethics, universally called AIGE, were launched on 20 September 2024 at an event organised by the Ministry of Science, Technology and Innovation, and are catalogued by MASTIC with a publication date of September 2024. The launch record states that the guidelines were developed on the basis of seven principles of responsible AI, and Malaysia's national AI portal likewise refers to the "7 Key Principles of AI" and to "Malaysia's Seven (7) AI Principles" from AIGE.
The names of those seven principles could not be read at any Malaysian government source during this check, and they are therefore not listed here. Any list of six principles attributed to a Malaysian body should be treated as unreliable until the reader has the AIGE document itself in hand. This matters more than it sounds: principle lists are the part of an AI governance framework most often reproduced from memory, and a wrong list quietly reshapes a compliance programme around duties nobody imposed.
In July 2026, AI Malaysia Berhad published a Voluntary AI Code of Ethics, AICE, described at source as "a voluntary, non-binding guideline that supports organisations in translating Malaysia's ethical AI principles into practical, real-world implementation." The download gate requires the reader to acknowledge that its contents are not legally binding. It addresses organisations, developers, deployers and researchers across sectors, and its stated function is to operationalise the seven AIGE principles across the AI lifecycle. A companion Boardroom Primer to AI Adoption and Governance was published at the same time.
Neither document creates an obligation. Neither is enforced. Their value to an operator is as a common vocabulary for conversations with Malaysian counterparties and public bodies, and as a structure for internal documentation that will be needed anyway for European purposes. They should not be mistaken for the reason to build that documentation.
Bank Negara Malaysia: a discussion paper, and a technology standard that does bind
Bank Negara Malaysia's own standards and guidelines index lists two documents relevant to an AI deployment inside a licensed institution.
The first is the Discussion Paper on Artificial Intelligence in the Malaysian Financial Sector, issued on 5 August 2025. A discussion paper is the earliest stage of the central bank's policy process. It gathers views. It imposes nothing, and an institution cannot be found non-compliant with it. Its existence is nonetheless the clearest available signal of where BNM intends to go, and an institution deploying AI in credit, pricing or customer-facing decisions should expect a policy document to follow it in due course.
The second is the Risk Management in Technology policy document, RMiT, issued on 28 November 2025, with a FAQ last updated on 1 July 2026. RMiT is a policy document, which in BNM's hierarchy is binding on the institutions it addresses. It is not an AI instrument, but it is the instrument under which AI systems in a Malaysian bank, insurer or takaful operator are actually supervised today: technology governance, change management, third party arrangements, resilience and control testing all reach an AI deployment without ever naming it.
The practical reading for a financial institution is that AI governance in Malaysia is currently a subset of technology risk governance. Build the AI register, the approval path, the validation record and the incident route inside the RMiT frame rather than beside it, and the same evidence will serve when a dedicated AI policy document arrives.
No document called the Responsible AI Framework for Financial Institutions, and nothing abbreviated RAFT, appears on Bank Negara Malaysia's own index. An earlier version of this guide described such a framework and its five pillars in detail. That description was wrong and has been removed.
Securities Commission Malaysia: what could not be confirmed
Securities Commission Malaysia maintains its regulatory instruments at sc.com.my under Acts, Guidelines, Practice Notes, Guidance Notes and Guiding Principles, Technical Notes and Circulars, and Consultation Papers. During this check, no AI-specific guideline could be located on that index, and the Guidelines on Digital Investment Management could not be read at the Commission's own site.
Accordingly, this guide makes no claim about Securities Commission AI obligations. Capital markets licence holders should take the Commission's guidelines index as the authority and confirm the current instrument list directly, rather than relying on any secondary description, including this one. Where an automated advisory or algorithmic system is in use, the governing conditions will be found in the licensing and conduct instruments that already apply to the activity, not in a separate AI rulebook.
Personal Data Protection Act 2010 and the 2024 amendments
The Personal Data Protection Act 2010, Act 709, regulates the processing of personal data in commercial transactions and protects the interests of data subjects. It was passed by Parliament on 5 April 2010 and assented to on 2 June 2010. It has been amended by the Personal Data Protection (Amendment) Act 2024, which the Digital Ministry records as approved by Cabinet and passed by the Dewan Rakyat in July 2024, and which the regulator lists among the legislation it administers.
The Act number of the amendment and the commencement dates of its individual provisions could not be read at either pdp.gov.my or the federal legislation portal during this check, and are therefore not stated here. Operators who need the precise in-force position of a given provision should obtain it from the Attorney General's Chambers rather than from any secondary summary. One consequence of the amendment is visible at the regulator's own site: the Act's central actor is now the data controller, not the data user, and section 15 requires registration by individuals, companies and organisations falling within thirteen classes of data controller.
The seven data protection principles under section 5 remain the foundation of the framework: the General Principle, the Notice and Choice Principle, the Disclosure Principle, the Security Principle, the Retention Principle, the Data Integrity Principle and the Access Principle. Read that list again and note what is absent. There is no right not to be subject to a decision based solely on automated processing. The rights in Article 22 of the GDPR are a European construct with no Malaysian counterpart, and importing them into a Malaysian compliance memo produces a duty that no Malaysian body can enforce and no Malaysian data subject can claim.
For AI deployments, the Act bites in three places, all of them upstream of the model. First, the General Principle governs the basis on which the personal data was obtained at all. Training or operating an AI system on Malaysian customer data without a proper basis is a problem with the collection, not with the model. Second, the Data Integrity Principle requires that personal data be accurate, complete, not misleading and up to date. A system that decides well on stale inputs is still exposed. Third, the Notice and Choice Principle requires that the data subject was told what would happen to the data, which means a notice drafted before AI processing existed is unlikely to cover it.
Enforcement sits with the Personal Data Protection Commissioner, whose office is the Personal Data Protection Department, Jabatan Perlindungan Data Peribadi. The abbreviation PDPC belongs to Singapore's regulator and should not be used for Malaysia. The Department operates a data breach notification channel and has issued guidance on data protection officers, including a Data Protection Officer Competency Guideline dated 1 August 2025. The specific notification deadline, the penalty ceilings under the amended Act, and any data portability right could not be read at the Department's own site during this check and are not asserted here. No guidance from the Department on AI or automated decision making could be found; an earlier version of this guide cited such guidance, and that citation has been removed.
Comparison with the EU AI Act
The structural contrast is stark. Malaysia has guidance and an agency. The European Union has a regulation with fines and explicit extraterritorial reach.
A Malaysian company that places an AI system on the EU market, or whose AI system's outputs affect persons located in the EU, is within the scope of Regulation (EU) 2024/1689 regardless of where it is incorporated or where the system is hosted. Timing has changed and needs stating precisely. The Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III high-risk obligations now apply from 2 December 2027 and Annex I obligations from 2 August 2028. The Article 5 prohibitions, the Article 50 transparency duties, the GPAI obligations and the Article 4 AI literacy duty were not deferred and have applied since 2 August 2026. An operator who reads the deferral as a general reprieve has misread it.
The penalties under Article 99 are tiered: up to EUR 35 million or 7 per cent of total worldwide annual turnover for the prohibited practices in Article 5, up to EUR 15 million or 3 per cent for other operator obligations, and up to EUR 7.5 million or 1 per cent for supplying incorrect information, whichever is higher in each case. They are imposed by national market surveillance authorities in the member states, not by the European AI Office.
Malaysian companies entering the EU market should read this as requiring a formal EU AI Act compliance programme, not as an extension of their Malaysian governance posture. The documentation requirements of Articles 9 to 17, covering risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, and cybersecurity, are substantially more prescriptive than anything in the Malaysian guidance. A full analysis of EU AI Act obligations for deployers is available at agentliability.eu.
Conversely, a European company operating in Malaysia faces a lighter environment than at home: guidance that does not bind, technology risk supervision if it is a licensed financial institution, and the Personal Data Protection Act for personal data. The Act overlaps with the GDPR in structure but not in scope, and the difference runs in the direction that surprises people. Malaysia grants no right against solely automated decisions, so a GDPR programme carries more than Malaysian law asks for on that point. The attention belongs instead where Malaysian law is its own thing, notably the registration duty under section 15 and the Malaysian notice and consent framework.
Operator compliance priorities for Malaysia in 2026
The following priorities reflect the position confirmed at source on 17 August 2026.
For BNM-regulated financial institutions: the binding instrument is the Risk Management in Technology policy document of 28 November 2025. Bring AI systems inside that frame: senior ownership, an inventory of material AI applications, documented validation for systems used in credit, pricing or consumer-facing recommendation, change control and incident routes. Treat the 5 August 2025 discussion paper as a forecast of where supervision is heading, not as a present duty. Institutions also operating in the EU should build one documentation set, since the European requirements are the more prescriptive of the two.
For capital markets licence holders: confirm the current instrument list directly at Securities Commission Malaysia. No AI-specific guideline could be located on the Commission's own index during this check, and this guide therefore states no Securities Commission AI obligation. Where an automated advisory or algorithmic system is in use, the governing conditions sit in the licensing and conduct instruments that already apply to that activity.
For organisations processing personal data of Malaysian individuals: review the basis on which data used in AI systems was collected, the currency and accuracy of that data, and whether existing notices actually describe AI processing. Check whether the organisation falls within the thirteen classes of data controller that must register under section 15. Confirm current breach notification and data protection officer duties directly with the Personal Data Protection Department, because the commencement position of the 2024 amendment could not be established from public sources.
For general commercial operators: the AIGE guidelines and the Voluntary AI Code of Ethics are the common reference, and alignment with them is worth doing for the shared vocabulary it gives you in Malaysian procurement and partnership conversations. It is not a legal obligation and no penalty follows from ignoring it. Obtain the AIGE document itself before writing its principles into a policy. The Agent Certified framework at agentcertified.eu provides a structured evidence trail across accountability, transparency and safety that serves the same documentation need.
For organisations with EU market exposure: the EU AI Act applies regardless of Malaysian incorporation. Assess which AI systems are in scope, classify them, and build the documentation required by Articles 9 to 17 for any high-risk systems, working to the revised dates of 2 December 2027 for Annex III and 2 August 2028 for Annex I while treating the Article 5, Article 50, GPAI and Article 4 duties as already live. Malaysian compliance does not substitute for European compliance. On the insurance side, cover for AI liability and regulatory defence is arranged through a small number of specialist markets: Armilla writes as a Lloyd's coverholder with a policy limit of USD 25 million per organisation, and Munich Re's aiSure product came to market through Mosaic on 26 February 2026 with initial capacity of 15 million in euros, dollars or Canadian dollars. Details at agentinsured.eu.
Frequently asked questions
What are Malaysia's national AI principles?
Malaysia's national AI ethics instrument is the National Guidelines on AI Governance and Ethics, AIGE, launched on 20 September 2024 by the Ministry of Science, Technology and Innovation and catalogued by MASTIC. Malaysia's official AI portal describes it as resting on seven key AI principles. The names of those seven principles could not be read at any Malaysian government source during this check and are not reproduced here. AIGE is guidance and creates no statutory duty. In July 2026 AI Malaysia Berhad added a Voluntary AI Code of Ethics, whose own download page requires readers to acknowledge that it is not legally binding. There is no document called the MDEC AI Principles.
Does Malaysia's PDPA give data subjects a right against automated decisions?
No. The Personal Data Protection Act 2010, Act 709, rests on seven principles under section 5: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity and Access. None creates a right not to be subject to a solely automated decision, and no such right could be found at the regulator's site. The GDPR Article 22 rights have no Malaysian equivalent. AI is reached indirectly, through the basis on which the data was collected, the accuracy requirement in the Data Integrity Principle, and the specificity of the notice given to the data subject.
What has Bank Negara Malaysia published on AI in financial services?
Bank Negara Malaysia's standards and guidelines index lists a Discussion Paper on Artificial Intelligence in the Malaysian Financial Sector issued on 5 August 2025, which imposes no obligations. The binding technology instrument is the Risk Management in Technology policy document of 28 November 2025, whose FAQ was updated on 1 July 2026. AI systems inside licensed institutions are supervised under that standard today. No document called the Responsible AI Framework for Financial Institutions, or RAFT, appears on the central bank's own index.
How does Malaysia's AI governance compare with the EU AI Act?
Malaysia has no enacted AI statute, and its national AI agency, AI Malaysia Berhad, coordinates rather than regulates. The EU AI Act is binding cross-sector legislation with tiered fines under Article 99 and explicit extraterritorial application. For organisations in both markets the European obligations are far heavier. Malaysia's practical AI-relevant duties run through the Personal Data Protection Act 2010 and, for licensed financial institutions, the Risk Management in Technology policy document.
Does the EU AI Act apply to Malaysian companies operating in Europe?
Yes. The Act applies to any provider placing an AI system on the EU market and to any deployer whose AI system's outputs affect persons located in the EU. Timing has moved: the Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744, so Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028, while the Article 5 prohibitions, Article 50 transparency duties, GPAI obligations and the Article 4 AI literacy duty were not deferred and have applied since 2 August 2026. Penalties under Article 99 reach EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for incorrect information, whichever is higher, and are imposed by national market surveillance authorities.
References
- Ministry of Science, Technology and Innovation (MOSTI) and MASTIC. The National Guidelines on AI Governance and Ethics (AIGE). Launched 20 September 2024. Catalogued at mastic.mosti.gov.my.
- MASTIC, Ministry of Science, Technology and Innovation. Artificial Intelligence Roadmap 2021-2025. Catalogued at mastic.mosti.gov.my.
- AI Malaysia Berhad (formerly the National AI Office), Digital Ministry. National AI Action Plan 2026-2030. Launched 28 July 2026. ai.gov.my.
- AI Malaysia Berhad. Voluntary AI Code of Ethics (AICE) and Boardroom Primer to AI Adoption and Governance. July 2026. ai.gov.my/governance.
- Bank Negara Malaysia. Discussion Paper on Artificial Intelligence in the Malaysian Financial Sector. Issued 5 August 2025. bnm.gov.my/standardsandguidelines.
- Bank Negara Malaysia. Risk Management in Technology (RMiT), policy document. Issued 28 November 2025, FAQ updated 1 July 2026.
- Malaysia. Personal Data Protection Act 2010 (Act 709), as amended by the Personal Data Protection (Amendment) Act 2024. Administered by the Personal Data Protection Department, pdp.gov.my.
- Personal Data Protection Department. Data Protection Officer (DPO) Competency Guideline. 1 August 2025.
- OECD. OECD Principles on Artificial Intelligence. Revised 3 May 2024. OECD Publishing, Paris.
- European Parliament and Council. Regulation (EU) 2024/1689 on Artificial Intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024, as amended by Regulation (EU) 2026/1744 (Digital Omnibus), in force 27 July 2026.