Malaysia has spent two years regulating AI with a document nobody has to follow. That is about to change. The National AI Office issued a public consultation paper on a proposed Artificial Intelligence Governance Bill on 10 July 2026, closed feedback on 31 July, and the Bill is reported as targeted for tabling before year-end.
If it passes, it would be Malaysia's first comprehensive national law on AI. Most coverage so far has been written for corporate compliance teams. Here is what is actually in it.
What the AI Governance Bill proposes
The consultation paper, summarised by law firm Rahmat Lim & Partners, sets out three core approaches.
Central institutional oversight. A single Central AI Authority, supported by existing regulators acting as "sectoral leads" in their own domains.
A principle-based framework. Five national baseline principles: human dignity, transparency and explainability, clear accountability, safety and security, and responsible data governance.
A risk-based approach. Obligations scaled to the risk a system actually poses, rather than applied flat.
This is a departure. Since September 2024, AI governance here has rested on the non-binding National Guidelines on AI Governance and Ethics published by MOSTI — principles developers were encouraged to adopt voluntarily, alongside whatever sector rules already applied.
Who gets regulated: developer, deployer, and why you are probably neither
The Bill proposes two regulated roles.
A developer is anyone who materially shapes what an AI system can do — training the model, adapting it, integrating it into a wider system, or modifying it after deployment.
A deployer is anyone who causes the system to operate in the real world — deciding whether, where and under what conditions the capability is used, and controlling its configuration, monitoring and withdrawal.
The territorial hook is wide: systems placed on the market in Malaysia, developed or used in Malaysia, or used by a deployer established here regardless of where the system is hosted. A model running overseas for a Malaysian company is still in scope.
Then the exemptions. The Bill proposes to carve out personal use — individuals using AI for personal, family or household affairs — and systems used solely for national defence or security.
That matters for the average reader. Using a chatbot to draft an email or plan a trip is not what this law is aimed at. The obligations land on organisations building and deploying systems, not on you asking a model a question — a separate question from which AI apps Malaysians are quietly using day to day.
The three risk tiers
The Bill classifies risk into three tiers, and the dividing line is intent.
Tier 1 — unacceptable risk. An AI system developed or deployed with an intent to cause harm.
Tier 2 — high risk. No intent to cause harm, but the system creates a risk of harm occurring.
Tier 3 — low risk. No foreseeable material AI harm.
Harm is anchored to a baseline list: death, bodily injury, unlawful deprivation of a fundamental liberty under the Federal Constitution, and contravention of any written law. Risk is evaluated on likelihood, severity and scale, and duration and reversibility. Depending on the tier, the Authority may impose mandatory or voluntary compliance requirements.
Unlike the EU approach, which enumerates specific prohibited practices, Malaysia's draft leans on an intent-and-harm test — broader, and leaving more to the Authority's later determinations.
Incident reporting is the part with teeth
The Bill proposes a reporting requirement for all AI incidents — defined expansively as any failure, weakness, misuse, unexpected effect or near-miss arising from an AI system that causes or could cause AI-related harm. Notifications would cover the nature of the incident, foreseeable harm, containment measures, root cause and remediation.
Reports could come from developers and deployers, or from the public through channels the Authority implements. That public complaints route is the quietly significant bit — it lets individuals raise an AI failure without being a customer, an employee or a regulator.
The Bill also proposes an AI sandbox regime so systems can be tested in controlled conditions that reflect real deployment.
What it does not do
On the consultation paper's face, it does not create a licensing regime for AI models, does not impose obligations on individual users, and does not replace sectoral regulation — the intent is to sit over the top, integrating with reporting mechanisms regulators have already built.
It also does not stand alone. It joins a widening stack of Malaysian digital law: the Online Safety Act framework in force since 1 January 2026, a Cybercrimes Bill under discussion, the data rights you have under the PDPA, and the platform rules now reaching existing social accounts.
The Bill has not been tabled at time of writing, and a consultation paper is not a draft statute. Definitions, tiers and thresholds can all move before a first reading.
FAQ
When will Malaysia's AI law come into force?
There is no confirmed date. The consultation ran from 10 to 31 July 2026 and the Bill is reported as targeted for tabling in 2026. Tabling is not the same as coming into force — a passed Act would still need gazetting and a commencement date.
Does the AI Governance Bill apply to individuals?
The paper proposes an exemption for personal use — individuals using AI for personal, family or household affairs. Obligations are aimed at developers and deployers: the organisations that build or operate AI systems.
What is the Central AI Authority?
A proposed body with three functions: AI safety, investigation and enforcement, and AI enablement — covering risk frameworks, incident investigation, guidance and sandboxes. It may delegate powers to sectoral leads.
What counts as an AI incident?
Any failure, weakness, misuse, unexpected effect or near-miss arising from an AI system that causes or could cause AI-related harm. Near-misses are explicitly included, which is a notably low reporting threshold.
How is this different from the existing AI guidelines?
The National Guidelines on AI Governance and Ethics, published by MOSTI in September 2024, are voluntary. The Bill would convert that baseline into legally enforceable accountability across the AI lifecycle, with an authority attached.



