Back
23 July, 2026

Malaysia’s proposed AI Governance Bill: weigh in before the window closes

On 10 July 2026, Malaysia’s National AI Office (NAIO) published a Consultation Paper on a proposed AI Governance Bill. The scope of the bill covers any AI System used by a Deployer established in Malaysia, regardless of where that system is physically hosted. In practice, this could capture foreign AI companies, cloud-hosted AI services, and AI value chains such as semiconductors, data centres, and global platforms.

The consultation is only open until 31 July 2026 – companies are encouraged to respond in a timely manner, as the Bill is anticipated to introduce a significantly more regulated and potentially onerous compliance requirement, with direct business and operational implications.

The proposed Bill establishes a Central AI Authority to oversee AI regulatory matters across the board

The Bill proposes a Central AI Authority to anchor national AI governance, built on three core functions: AI Safety (risk framework, assessments, testing, incident reporting), Investigation and Enforcement (technical fact-finding and corrective action), and AI Enablement (capacity building and oversight of AI Sandboxes). Existing regulators and sectoral institutions may be appointed as Sectoral Leads, translating the national baseline into sector-specific instruments such as guidelines or codes of practice.

AI Governance Principles set a national baseline that Developers and Deployers must apply proportionately

The Bill remains agile by setting out five AI Governance Principles as a national baseline: human dignity and agency, proportionate transparency, accountability and redress, safety and resilience, and responsible data governance. Developers and Deployers must have “due regard” for these principles throughout an AI System’s lifecycle, applied proportionately to risk, context, and impact.

Regulatory obligations are risk-based

Regulatory obligations will be proportionate to the nature, context, and level of risk posed by an AI System.

  • Low-risk tier sets responsibility at baseline level, with due regard to principles and lighter compliance
  • High-risk tier assumes no intention to cause harm, but subjects the system to stronger, structured obligations covering risk assessment, documentation, human oversight, and monitoring
  • Unacceptable-risk tier prohibits AI-specific harm

The Bill does not name every high-risk activity, but the consultation paper points to the kinds of use cases it envisages: clinical care, welfare determination, employment, and critical infrastructure. Companies running AI in those areas should assume they sit closer to the high-risk tier than the low-risk one.

New reporting mechanisms give the Central AI Authority tools to act once a challenge is identified

The Bill also introduces reporting mechanisms for failures, misuse, near misses, and unexpected effects. These can be reported directly by the Developer or Deployer, or through a public complaint to the Central AI Authority, which would oversee the investigative process. It would then produce formal findings and recommend mitigations, which may be recorded in a centralised repository of AI-related incidents to identify emerging policy development risks.

Why this matters

  • Broad jurisdictional reach: The extraterritorial “Deployer established in Malaysia” test means foreign-hosted AI systems used by Malaysian entities may still fall within scope
  • Foreign companies are accountable: The AI Governance Bill will include any foreign platforms whose services reaches Malaysian consumers, reinforcing “use in Malaysia” as the key basis for the Bill’s scope
  • Dual accountability: Developers and Deployers face distinct duties that can overlap, which may require contractual and governance realignment across AI supply chains
  • Sector fragmentation risk: Reliance on Sectoral Leads could produce inconsistent obligations across industries; organisations operating across sectors should monitor for divergence
  • A closing window to influence the framework: As the Bill is still pre-drafting and principle-based, this consultation is a meaningful, time-limited opportunity to shape definitions, risk tiers, and compliance thresholds before they are locked in.

What to expect in the next six months

Access Partnership expects the Act to follow this timeline, which remains subject to change while the Bill is in its pre-drafting phase:

MilestoneIndicative date
Closed-door industry consultationJune 2026
Public consultation windowCloses 31 July 2026
Submission to CabinetAround end of July 2026
Formal drafting and handover to the Attorney General ‘s Chambers (AGC)August – October 2026
Presentation to ParliamentNovember – December 2026

Companies that are likely to be most affected include foreign AI investors whose products are used by Malaysia-based deployers – including IT systems and platforms with AI components – and companies operating in regulated activities such as financial services, healthcare, and employment or hiring decisions, as well as companies involved in the use case industries of clinical care, welfare determination, and critical infrastructure. How far each is affected will depend on how “Deployer,” “high-risk,” and “harm” are ultimately defined.

The consultation process closes on 31 July 2026. With just over a week remaining, now is a good time to assess your position. We welcome the opportunity to speak with you on how this Bill could affect your operations, contracts, and risk exposure in Malaysia.

For further insights into Malaysia’s AI Governance Bill and guidance on engaging with the consultation process, please contact Kamles Kumar at [email protected]or Nazween Nazri at [email protected]


Contact us

Need a problem solved?

Our dedicated experts, located around the world, are here to help.