Malaysia AI Regulation Overview
Malaysia AI Regulation Overview
Malaysia
RAI-MY-NA-SUMMARY-2026Tracked instruments in Malaysia
16 instruments tracked — 10 In Force, 4 Adopted, 1 In Force (Amended), 1 Repealed. Built directly from our records, so — unlike the article below — it cannot go stale.
Malaysia combines national AI strategies, voluntary ethical guidelines, binding sectoral rules in finance and capital markets, and statutory cybersecurity mandates under the Cyber Security Act 2024, with a dedicated AI Governance Bill under public consultation.
Full article
Overview
Malaysia's approach to artificial intelligence regulation is defined by a whole-of-government digital transformation agenda that balances economic innovation with risk-informed governance. Rather than relying on a single horizontal AI statute, Malaysia employs a hybrid regulatory model combining national strategic playbooks, voluntary ethical guidelines, binding financial and capital market technology risk regulations, and statutory cybersecurity legislation. The foundation of this strategy rests on long-term policy instruments designed to transition Malaysia into a digitally-driven, high-income nation under its "AI Nation 2030" vision.
Policy steering and institutional oversight are distributed across key federal entities. The Ministry of Digital serves as the primary ministry driving national digital strategy, supported by MyDIGITAL Corporation and AI Malaysia Berhad—an apex national entity that institutionalizes and enhances the National AI Office (NAIO) and houses the Malaysia AI Safety Institute. Concurrently, the Ministry of Science, Technology and Innovation (MOSTI) leads research, development, and national ethics standard-setting. Together, these entities coordinate national AI adoption across public and private sectors in alignment with broader economic plans, including the Malaysia MADANI framework and the Thirteenth Malaysia Plan.
Regulatory Approach
Malaysia predominantly utilizes a soft-law, voluntary, and risk-based governance approach for general AI adoption, complemented by strict, mandatory rules for high-impact and regulated sectors. The central policy framework is guided by non-binding instruments such as the National Guidelines on AI Governance & Ethics (AIGE) and the National AI Action Plan 2026-2030 (Pelan Tindakan AI Kebangsaan 2026-2030). These frameworks advocate for risk-proportional governance, encouraging deployers and developers to adopt human-in-the-loop oversight, pre-deployment evaluations, and transparency measures proportional to the risk tier of the AI system.
In contrast, specific regulatory domains operate under binding mandates. In financial and capital markets, Bank Negara Malaysia (BNM) and the Securities Commission Malaysia (SC) enforce enforceable technology risk guidelines that explicitly incorporate emerging technologies like AI and machine learning. Furthermore, testing and controlled experimentation are facilitated through supervised national sandboxes, such as the AI Sandbox 2024 under the National Technology & Innovation Sandbox (NTIS) framework managed by the Malaysian Research Accelerator for Technology & Innovation (MRANTI). This dual approach allows Malaysia to foster technological innovation while maintaining strict oversight over systemic risks, data security, and critical national infrastructure.
Key AI Legislation
- National AI Action Plan 2026-2030 (Pelan Tindakan AI Kebangsaan 2026-2030): Officially launched in July 2026, this policy instrument serves as Malaysia's primary five-year roadmap to realize its "AI Nation 2030" vision. Formulated under the Ministry of Digital, it outlines 14 sectoral impact engine initiatives and 14 enabler initiatives across human capital, infrastructure, governance, and financing.
- National Guidelines on AI Governance & Ethics (AIGE): Published by MOSTI in September 2024, AIGE sets out seven foundational ethical principles—including fairness, reliability, safety, privacy, inclusiveness, transparency, and accountability—providing voluntary guidance for users, policymakers, and developers.
- Cyber Security Act 2024 (Act 854): Brought into force in August 2024, this statute establishes a mandatory national framework to secure National Critical Information Infrastructure (NCII), mandating risk assessments, periodic audits, incident reporting, and licensing for cybersecurity service providers.
- Bank Negara Malaysia Policy Document on Risk Management in Technology (RMiT): Reissued in November 2025, this binding policy sets enhanced technology and cyber risk management standards for financial institutions, establishing expectations for board oversight, cloud security, multi-factor authentication, zero-trust architecture, and ethical AI governance.
- Securities Commission Malaysia Guidelines on Technology Risk Management (GTRM): Revised in August 2024, GTRM establishes mandatory standards for capital market entities, including pre-deployment cybersecurity assessments, penetration testing for critical systems, near-miss reporting, and ethical principles for AI/ML adoption.
- Malaysia National Artificial Intelligence Roadmap 2021-2025 (AI-RMAP): MOSTI's foundational playbook framing AI across six strategic thrusts and 11 national use cases in agriculture, healthcare, smart cities, education, and public services.
- Malaysia Digital Economy Blueprint (MyDIGITAL) / Malaysia Digital Action Plan 2030 (MD2030): The overarching national digital strategy for 2021–2030, realigned in June 2026 under MD2030 to prioritize AI adoption and homegrown innovation.
- AI Talent Roadmap for Malaysia 2024–2030: Strategic roadmap overseen by the Ministry of Higher Education to bridge the national AI talent deficit through academic curriculum standardization, the Faculty of AI at Universiti Teknologi Malaysia, and micro-credentials.
- AI Sandbox 2024: A national pilot program launched under the NTIS framework by MOSTI and MRANTI to provide supervised testing environments and compute infrastructure for AI startups and enterprises.
- AI untuk Rakyat: A self-paced national AI literacy initiative launched by the Ministry of Digital, MyDIGITAL Corporation, and Intel Malaysia to build baseline public awareness.
Governance & Enforcement Bodies
Institutional oversight of Malaysia's digital and AI ecosystem is divided among policy coordination agencies, sectoral statutory regulators, and national security bodies. The Ministry of Digital holds primary responsibility for national digital strategy, overseeing MyDIGITAL Corporation and AI Malaysia Berhad. AI Malaysia Berhad functions as the national apex AI entity, institutionalizing the National AI Office (NAIO). Its mandate encompasses high-impact monitoring of national plans, formulating ethical codes and governance standards, coordinating international partnerships, and housing the Malaysia AI Safety Institute to conduct technical safety testing and red-teaming.
MOSTI leads scientific research, technology commercialization, and foundational AI ethics, managing national innovation frameworks alongside MRANTI. Academic and research alignment is facilitated through the Malaysia Artificial Intelligence Consortium (MAIC), hosted at Universiti Teknologi Malaysia (UTM). Sector-specific enforcement remains anchored within established regulators: Bank Negara Malaysia oversees financial institutions, the Securities Commission regulates capital market operators, and the National Cyber Security Agency (NACSA) under the Prime Minister's Department enforces cybersecurity standards for designated NCII sectors.
Penalties & Enforcement
Enforcement in Malaysia depends directly on whether an instrument is a strategic policy/guideline or a statutory regulation. Strategic policy frameworks and guidelines—such as the National AI Action Plan 2026-2030, the National Guidelines on AI Governance & Ethics (AIGE), the AI Talent Roadmap, and AI untuk Rakyat—are non-binding policy instruments. They carry no statutory penalties, legal sanctions, or financial fines under the instruments themselves. Instead, adherence is managed via administrative reporting, program participation terms, academic accreditation criteria, or funding conditions.
Conversely, binding sectoral guidelines and statutory acts carry strict legal and administrative compliance mechanisms. Under the Cyber Security Act 2024, contraventions of NCII duties, failure to submit required risk assessments or audits, or operating regulated cybersecurity services without a license subject entities to criminal prosecution—resulting in fines or custodial sentences—or administrative settlement under the Cyber Security (Compounding of Offences) Regulations 2024. In the financial and capital market sectors, failure to comply with BNM's RMiT or SC's GTRM can trigger administrative sanctions under underlying legislation (such as the CMSA 2007), including regulatory enforcement actions or mandatory independent technology audits funded by the non-compliant entity.
Data Protection Framework
Data protection considerations for artificial intelligence in Malaysia are governed primarily by the Personal Data Protection Act 2010 (PDPA) alongside administrative rules issued by the Department of Personal Data Protection (JPDP). Organizations developing or deploying AI systems that process personal data must ensure full compliance with statutory data protection principles, including notice and consent, data security, retention limitations, and data integrity. Ethical frameworks such as AIGE explicitly cross-reference the PDPA, instructing deployers to adopt privacy-by-design practices, data minimization, and secure model training pipelines.
The regulatory ecosystem is actively evolving to address data governance challenges unique to automated decision-making and modern digital infrastructure. Anticipated legal and policy developments include amendments to the Personal Data Protection Act, the introduction of a national Data Sharing Bill to facilitate secure public-private data exchange, and forthcoming JPDP guidance specifically covering automated decision-making, Data Protection Impact Assessments (DPIAs), and privacy-enhancing technologies in AI systems.
Sector-Specific Rules
Sector-specific AI rules in Malaysia are most advanced in the financial and capital markets domains. Bank Negara Malaysia's RMiT policy document (updated November 2025) requires financial institutions to implement rigorous technology risk frameworks, mandatory multi-factor authentication (MFA), zero-trust network architectures, cloud due diligence, and ethical governance structures when deploying emerging technologies like AI. Similarly, the Securities Commission's revised GTRM (August 2024) mandates that capital market entities conduct pre-deployment cybersecurity assessments and penetration testing for new critical systems, establish near-miss reporting protocols, and adhere to guiding principles for ethical AI and machine learning adoption.
Across other key sectors—including healthcare, agriculture, public services, smart cities, and transport—AI deployment is guided by sector-specific use cases outlined in national policy instruments. The Malaysia National AI Roadmap (AI-RMAP) identifies 11 national use cases across five priority sectors, while the National AI Action Plan 2026-2030 outlines 14 sectoral impact engine initiatives. Furthermore, designated National Critical Information Infrastructure (NCII) entities across defense, energy, finance, health, transport, and water sectors are subject to mandatory operational resilience standards, annual risk assessments, and expedited incident reporting to NACSA under the Cyber Security Act 2024.
International Alignment
Malaysia's AI governance strategy emphasizes international interoperability and alignment with established global frameworks. National guidelines—most notably MOSTI's National Guidelines on AI Governance & Ethics (AIGE)—are explicitly benchmarked against international standards, incorporating key principles from the OECD Council Recommendations on Artificial Intelligence, UNESCO's Recommendation on the Ethics of Artificial Intelligence, and the ASEAN Guide on AI Governance and Ethics. This alignment ensures that domestic standards remain compatible with cross-border trade and international technical norms.
Furthermore, Malaysia actively leverages international public-private partnerships to build technical and infrastructure capacity. Key strategic frameworks, such as the AI Sandbox 2024, the National AI Action Plan, and the Teraju AI Selangor initiative, involve direct collaboration with global technology leaders including NVIDIA, Google Cloud, and Intel Malaysia. These partnerships support sovereign compute facilities, AI safety evaluation methodologies, and joint R&D pipelines, positioning Malaysia as a competitive digital hub within ASEAN.
Future Developments
The most significant legislative milestone on Malaysia's horizon is the proposed AI Governance Bill, which is currently undergoing public consultation. Intended to establish a formal risk-based legal framework for artificial intelligence across the nation, the bill aims to introduce binding statutory requirements and regulatory oversight mechanisms for high-impact AI systems, building upon the voluntary foundation established by AIGE.
In parallel, the implementation of the National AI Action Plan 2026-2030 (Pelan Tindakan AI Kebangsaan 2026-2030) and the Malaysia Digital Action Plan 2030 (MD2030) will drive Phase 3 of Malaysia's digital transformation strategy. Over the coming years, AI Malaysia Berhad will mature its operational mandate following its initial incubation period, fully establishing the technical capabilities of the Malaysia AI Safety Institute in AI red-teaming, safety testing, and risk evaluations alongside complementary legislative updates including the Data Sharing Bill and PDPA amendments.
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| AI Malaysia Berhad / National AI Office (NAIO) | Apex national entity under the Ministry of Digital mandated to unify AI policy coordination, governance, and safety implementation. | High-impact monitoring of national AI plans, formulation of ethical frameworks and standards, conducting AI safety evaluations and red-teaming via the Malaysia AI Safety Institute. | https://ai.gov.my |
| Ministry of Digital / MyDIGITAL Corporation | Lead ministry and strategic change office driving Malaysia's digital economy and transformation blueprints. | Policy leadership, monitoring implementation of MyDIGITAL and the Malaysia Digital Action Plan 2030 (MD2030), inter-agency coordination. | https://mydigital.gov.my |
| National Cyber Security Agency (NACSA) | National cybersecurity authority responsible for securing National Critical Information Infrastructure (NCII) under Act 854. | Issuing technical directives, enforcing mandatory incident reporting via NC4, directing cybersecurity audits, licensing cybersecurity service providers. | https://www.nacsa.gov.my |
| Ministry of Science, Technology and Innovation (MOSTI) | Lead policy sponsor for national AI R&D, innovation sandboxes, AI-RMAP, and AIGE guidelines. | Program sponsorship, issuing national governance and ethics guidelines, policy oversight of NTIS and MRANTI. | |
| Bank Negara Malaysia (BNM) | Central bank and regulatory authority for financial institutions in Malaysia. | Enforcing RMiT policy document, mandating technology risk controls, board oversight requirements, and cloud security governance. | |
| Securities Commission Malaysia (SC) | Statutory regulator for Malaysian capital markets under the Capital Markets and Services Act 2007. | Enforcing GTRM, requiring pre-deployment cybersecurity assessments/penetration testing, appointing independent technology reviewers at entity expense. |
Related Regulations
More AI regulation in Malaysia
© Regulations.AI using Gemini 3.6 Flash · updated on 12 Sep 2026