Malaysia - AI Governance Guidelines

National Guidelines on AI Governance & Ethics (AIGE)

Malaysia

RAI-MY-NA-NGAGEXX-2024
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The National Guidelines on AI Governance & Ethics (AIGE) were published by Malaysia's Ministry of Science, Technology & Innovation (MOSTI) on 20 September 2024 as a voluntary, national framework setting seven core principles for responsible AI. AIGE provides stakeholder-specific guidance for end users, policymakers and AI developers to promote trustworthy, inclusive and human-centred AI while aligning with international instruments.

Summary

The National Guidelines on AI Governance & Ethics (AIGE) are a voluntary national framework published by the Ministry of Science, Technology and Innovation (MOSTI) and launched on 20 September 2024 to operationalise Malaysia’s National Artificial Intelligence Roadmap (AI-RMAP 2021–2025). AIGE articulates seven foundational principles — fairness; reliability, safety and control; privacy and security; inclusiveness; transparency; accountability; and the pursuit of human benefit and happiness — and provides targeted guidance for three principal stakeholder groups: (1) end users (members of the public, consumers and workers); (2) policymakers and public-sector agencies; and (3) designers, developers, technology providers and suppliers. The Guidelines are explicitly non‑binding but intended to act as a national reference point to encourage adoption of responsible AI practices across sectors and to inform future sectoral or statutory measures.

AIGE emphasises a risk-based, proportionate approach: organisations are asked to identify and assess risks arising from AI systems, implement human‑in‑the‑loop or human‑on‑the‑loop controls for high‑impact applications, perform testing and validation, and maintain documentation and audit trails. For data handling the Guidelines cross‑reference existing Malaysian data protection obligations (including the Personal Data Protection Act 2010 and subsequent amendments) and recommend privacy‑by‑design practices, consent best practices, data minimisation, and secure model training pipelines. On transparency, AIGE encourages disclosure where AI is used in decision‑making and calls for user information on system purpose, limitations, and channels for redress. Accountability measures include defined internal governance structures, incident response processes and clear assignment of roles among providers, deployers and procurers.

Although AIGE does not introduce immediate statutory penalties, it signals likely future regulatory developments and recommends that public procurement and sectoral regulators (e.g., financial and health authorities) use the Guidelines as a baseline for mandatory requirements in high‑risk contexts. AIGE also promotes international alignment — citing OECD and UNESCO principles and ASEAN guidance — and asks Malaysian agencies to coordinate via the National AI Office / MyDIGITAL structures. The Guidelines therefore serve as both a national standard‑setting instrument for voluntary adoption and as preparatory material that will influence compliance expectations, sectoral guidance, procurement conditions and potential future legislation. Primary official copies and references are published by MOSTI and summarised by the Malaysia National AI Office (NAIO).

Full article

Read full text ↗

Overview

The National Guidelines on AI Governance & Ethics (AIGE) were published by the Ministry of Science, Technology and Innovation (MOSTI) and launched on 20 September 2024 as Malaysia’s foundational, voluntary guidance on responsible AI. AIGE defines seven core principles and delivers targeted guidance for three stakeholder groups (end users, policymakers and developers) to implement responsible, human-centred AI while supporting the National AI Roadmap (AI‑RMAP 2021–2025). The Guidelines are positioned as a non‑binding national reference that aligns Malaysia with international instruments and regional practice; see the official MOSTI publication MOSTI – AIGE flipbook and the Malaysia National AI Office overview NAIO – Governance.

Definitions

AIGE defines key concepts for consistent application across stakeholders, including "AI system" (software or systems that use statistical, probabilistic or machine‑learning methods to produce recommendations, predictions or decisions), "developer/provider" (entities that design, build or supply AI tools), "deployer/operational user" (organisations that implement AI into products or services), "end user" (individuals interacting with AI products), "human‑in‑the‑loop" and other human oversight modalities, and "high‑risk application" (systems whose failure or misuse could materially affect safety, rights, or economic outcomes). These definitions are pragmatic and risk‑focused to support sectoral adaptation and interoperability with existing Malaysian law and international definitions.

Governance and Institutional Framework

AIGE sets out a multi‑layered governance architecture that leverages MOSTI as the coordinating authority while promoting cross‑agency collaboration. The Guidelines recommend establishing or strengthening internal AI governance bodies within organisations (e.g., AI ethics committees, risk committees, compliance officers) and coordination between national authorities through the National AI Office (NAIO) incubated under MyDIGITAL. The approach balances central coordination with sectoral regulator roles: financial, health, telecommunications and critical infrastructure regulators are encouraged to adopt sector‑specific rules that build on AIGE. For the public sector, AIGE advocates embedding responsible AI checks into procurement and policy design processes and using central repositories for model registration and impact assessments; see the NAIO institutional pages NAIO – About and MOSTI materials MOSTI – AIGE flipbook for official context.

Key Focus Areas

AIGE concentrates on seven principle‑based areas: fairness (mitigating bias and disparate impacts), reliability/safety/control (robustness, testing and fail‑safes), privacy/security (data governance, secure model training and protection against misuse), inclusiveness (accessibility and non‑discrimination), transparency (disclosure of AI use, explainability and documentation), accountability (clear assignment of roles, audit trails and incident reporting), and pursuit of human benefit and happiness (human‑centred design and ethical alignment). The Guidelines detail operational practices: pre‑deployment risk assessments, dataset provenance checks, validation/testing regimes, continuous monitoring, user communication and redress pathways. AIGE emphasises special attention to high‑impact domains such as healthcare, finance, public services and critical infrastructure where harms can be acute, and it supports sector regulators developing mandatory rules for those domains.

Implementation Framework

AIGE recommends a staged implementation model: (1) awareness and capability building across the public and private sectors; (2) governance setup (policies, roles, committees); (3) risk categorisation and impact assessment for AI systems; (4) technical and organisational controls (testing, security, privacy by design); (5) documentation, transparency and recordkeeping (model cards, datasheets, logs); and (6) monitoring, incident management and remediation. The Guidelines encourage organisations to adopt international standards where available and to document conformity efforts to facilitate procurement and cross‑border interoperability. MOSTI signals that AIGE will inform future sectoral guidance and procurement rules, and organisations are urged to consider AIGE compliance as part of best practice for contract terms and third‑party risk management.

Monitoring and Evaluation

AIGE calls for continuous monitoring and periodic evaluation of AI systems and national governance arrangements. Monitoring mechanisms include automated performance and fairness metrics, human oversight checkpoints, red‑flag incident reporting, and centralised reporting to coordinating agencies when public harm is suspected. Evaluation occurs via post‑deployment audits, third‑party reviews and periodic public reporting of uptake and impact. The Guidelines recommend that NAIO and sectoral regulators compile national statistics on AI adoption, incidents, and compliance trends to drive iterative policy updates.

Penalties, Liability, and Appeals

As a voluntary instrument, AIGE does not itself create new criminal or administrative penalties; rather, it clarifies how existing liability regimes and sectoral laws (for instance, data protection and cybersecurity statutes) apply to AI practices and signals that future mandatory measures may follow for high‑risk uses. The Guidelines recommend that organisations implement internal remediation and appeals mechanisms for affected individuals and that policymakers consider formal enforcement routes (administrative fines, suspension from procurement lists, civil liability) where non‑compliance to sectoral mandatory rules causes harm.

Relationship to Other Instruments

AIGE explicitly situates itself alongside Malaysia’s National AI Roadmap (AI‑RMAP 2021–2025) and existing legal instruments such as the Personal Data Protection Act (PDPA) and the national cybersecurity framework. It also complements sectoral regulatory initiatives (e.g., finance, health, telecommunications) and existing national digital strategies (MyDIGITAL). The Guidelines reference international soft‑law instruments — OECD AI Principles, UNESCO Recommendation on the Ethics of AI, and ASEAN AI guidance — to promote interoperability and provide a bridge to future bilateral or multilateral regulatory alignment.

International Alignment

AIGE was drafted to align Malaysia with multinational norms and to reduce friction for cross‑border AI services. The Guidelines reference OECD and UNESCO principles and encourage adoption of internationally accepted technical standards and testing regimes. They also highlight the need to monitor extraterritorial rules (for example the EU AI Act) that may affect Malaysian providers operating internationally, and they promote participation in regional ASEAN coordination efforts to harmonise principles and facilitate trade in AI services.

Implementation Timeline

MilestoneDate / Target
Publication & Launch of AIGE2024‑09‑20
National AI Roadmap published2022‑08 (AI‑RMAP 2021–2025)
Incubation of NAIO under MyDIGITAL2024‑11 to 2024‑12 (established/operationalisation)
Anticipated sectoral guidance rollouts2024–2026 (ongoing)

Sources and References

SourceType
Ministry of Science, Technology & Innovation (MOSTI) – National Guidelines on AI Governance & Ethics (AIGE) flipbookPrimary Source
Malaysia National AI Office (NAIO) – GovernancePrimary Source

Requirements for a company

What an organisation has to do under Malaysia - AI Governance Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

14
  • Ensure compliance with the Personal Data Protection Act (PDPA).Organizations processing personal data with AI systems.
  • Establish or strengthen internal AI governance bodies.Organizations using AI systems.
  • Map internal policies to AIGE's seven core principles.Organizations using AI systems.
  • Conduct pre-deployment impact and risk assessments for AI systems.Organizations deploying AI systems.
  • Perform dataset provenance checks for AI systems.Organizations developing or deploying AI systems.
  • Implement validation, bias testing, and testing regimes for AI systems.Organizations developing or deploying AI systems.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Consider AIGE compliance for contract terms and third-party risk management.Organizations procuring or managing third-party AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Malaysia - AI Governance Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organizations processing personal data with AI systems.Ensure compliance with the Personal Data Protection Act (PDPA).
AIGE explicitly situates itself alongside... existing legal instruments such as the Personal Data Protection Act (PDPA).
Relationship to Other InstrumentsCritical
2Organizations using AI systems.Establish or strengthen internal AI governance bodies.
The Guidelines recommend establishing or strengthening internal AI governance bodies within organisations.
Governance and Institutional FrameworkImportant
3Organizations using AI systems.Map internal policies to AIGE's seven core principles.
Map internal policies to AIGE's seven principles
Key Focus AreasImportant
4Organizations deploying AI systems.Conduct pre-deployment impact and risk assessments for AI systems.
The Guidelines detail operational practices: pre-deployment risk assessments...
Before deploymentKey Focus AreasImportant
5Organizations developing or deploying AI systems.Perform dataset provenance checks for AI systems.
...dataset provenance checks...
Before deploymentKey Focus AreasImportant
6Organizations developing or deploying AI systems.Implement validation, bias testing, and testing regimes for AI systems.
Implement validation, bias testing and continuous monitoring
Before deploymentKey Focus AreasImportant
7Organizations deploying AI systems.Define human oversight arrangements (HITL/HOTL/HIC) for AI decisions.
Define HITL/HOTL/HIC arrangements for decisions
Before deploymentKey Focus AreasImportant
8Organizations deploying AI systems.Document and disclose AI system use to affected users.
Document and disclose AI use to affected users
Before deploymentKey Focus AreasImportant
9Organizations developing or deploying AI systems.Implement data minimisation and secure training pipelines for AI systems.
Ensure... data minimisation and secure training pipelines
Key Focus AreasImportant
10Organizations developing or deploying AI systems.Maintain model cards, datasheets, and audit logs for AI systems.
Maintain model cards, datasheets, audit logs
Implementation FrameworkImportant
11Organizations deploying AI systems.Implement continuous monitoring, including performance and fairness metrics, for AI systems.
Implement validation, bias testing and continuous monitoring
Monitoring and EvaluationImportant
12Organizations deploying AI systems.Establish incident reporting and remediation workflows for AI systems.
Establish incident reporting and remediation workflows
Monitoring and EvaluationImportant
13Organizations deploying AI systems.Implement internal remediation and appeals mechanisms for affected individuals.
The Guidelines recommend that organisations implement internal remediation and appeals mechanisms.
Penalties, Liability, and AppealsImportant
14Public sector organizations.Embed responsible AI checks into public sector procurement and policy design processes.
For the public sector, AIGE advocates embedding responsible AI checks into procurement and policy design processes.
Governance and Institutional FrameworkImportant
15Organizations procuring or managing third-party AI systems.Consider AIGE compliance for contract terms and third-party risk management.
organisations are urged to consider AIGE compliance as part of best practice for contract terms.
Implementation FrameworkRecommended

© Regulations.AI · updated on 13-Jun-2026