AI and copyright in Malaysia: a hand drawing a glowing network over the Kuala Lumpur skyline

Public consultation submission

AI and copyright in Malaysia: our submission on the Copyright Act amendments

On 14 August 2026 we filed a written submission with the Intellectual Property Corporation of Malaysia (MyIPO) on the proposed amendments to the Copyright Act 1987: eleven recommendations on AI training, AI-generated works and the interface with personal data law, together with three annexures. This page collects the full papers and tracks the amendments as they develop.

Filed by Edwin Lee & Partners, Kuala Lumpur, with a contribution from Global Law Office, Beijing. Four documents. Last updated .

In brief

  • MyIPO's consultation proposes the most substantial modernisation of the Copyright Act 1987 in over a decade, across five reform clusters. The AI proposals ask two questions that matter to every business using or building AI in Malaysia: may copyright works be used to train AI, and does copyright protect what AI produces?
  • On training, the consultation poses one express policy question: should Malaysia follow Japan's purpose-based model, Singapore's lawful-access model, or a hybrid? Our answer is a hybrid, and we explain exactly how it should be built.
  • On AI-generated works, Malaysian law currently has no express answer. Our submission recommends codifying one: copyright requires meaningful human creative contribution, judged on the evidence, whatever the tool used.
  • A copyright exception is only half the clearance. Training data at scale almost always contains personal data, and the Personal Data Protection Act 2010 is a separate gate. Our submission asks for the interface to be made express.
  • This submission is the companion to our filing on the proposed AI Governance Bill. The two consultations are two halves of the same question, and we have answered both halves consistently.

The papers

These documents may be quoted with attribution to Edwin Lee & Partners. Journalists and researchers are welcome to contact us for comment.

The one question MyIPO asked

The Consultation Document poses one express policy question: should Malaysia adopt a purpose-based exception for text and data mining, as Japan has; a lawful-access exception, as Singapore has; or a hybrid?

Our answer is the hybrid, and the design matters more than the label. Japan's model asks why a work is being used: analysis is permitted, enjoyment is not, subject to a proviso protecting rights holders from unreasonable prejudice. But it imposes no condition on how the works were obtained, a gap Japan's own copyright authority has since had to patch through administrative guidance. Singapore's model asks the better first question, whether the user has lawful access to the works, and its answer cannot be contracted away. But once access is lawful, Singapore applies no further test, and courts get no tool for the hard cases: outputs that substantially reproduce the works they were trained on, or training that bypasses a licensing market rights holders have actually built.

The hybrid takes the lawful-access gate from Singapore, the unreasonable-prejudice safety valve from Japan, and adds a transparency obligation: developers relying on the exception keep records of their data sources and publish a summary of the categories of data used, at a level of generality that protects trade secrets.

Malaysia's creative and media sectors pressed for an opt-in consent rule instead. We take that position seriously, and our submission answers it directly rather than dismissing it: an opt-in rule binds only the developers who ask, and it has no purchase on training that happens outside Malaysia. The hybrid protects the licensing markets the creative sector wants to build, because once a genuine licensing market for training exists, training that bypasses it is unreasonable prejudice and falls outside the exception. The exception shrinks as licensing grows.

Two gates: copyright and personal data

A TDM exception clears the copyright gate. It says nothing about the second gate, and the second gate is the one most businesses miss.

Training data at scale almost always contains personal data: names, faces, opinions about identifiable people, user-generated content. Processing that data is governed by the Personal Data Protection Act 2010, and Act 709 is demanding here. Its default rule is consent. Its exceptions are narrow, and none of them is a general legitimate-interests ground of the kind found in other jurisdictions. Consent from everyone represented in a web-scale corpus is impossible in practice. Since the 2024 amendments, contravening the data protection principles carries a fine of up to RM1,000,000, imprisonment of up to three years, or both.

The danger is predictable: a TDM exception gets enacted, and developers read it as a general clearance for AI training. It is not. A developer can satisfy every condition of the copyright exception and still contravene Act 709. Our submission asks for two things: an express provision that the exception is without prejudice to the PDPA, and joint or aligned guidance from MyIPO and the Personal Data Protection Department, so that one set of records satisfies both regulators.

We raised the training-data question first in our AI Governance Bill submission. This is the same finding, arriving at the second gate.

Does copyright protect AI-generated work?

The Consultation Document asks the right question first: not who owns AI-generated output, but whether it qualifies for protection at all.

On the current Act, we think the answer is this. Every limb of the definition of "author" in section 3 assumes a human being. Section 7(3)(a) requires sufficient effort to make the work original in character. A work generated by an AI system without meaningful human creative contribution has no author and attracts no copyright. A work created by a human using AI as a tool, where the human's selection, arrangement, refinement and creative choices show in the output, is protected in the ordinary way. But all of this rests on inference rather than express words, and the inference will be tested soon and often.

Our submission recommends codifying the threshold, and drawing it in a way that is neutral as to the tool. What matters is whether human creative choices are traceable in the expression, not whether they were made with a pen, a camera or a prompt. Creative direction through iterative refinement can qualify, where it is evidenced in the output. A bare instruction to a machine cannot.

The comparative landscape supports drawing the line here, because the leading jurisdictions are converging on it from different directions. The United States protects the human layers of AI-assisted works case by case. Chinese courts have protected AI-assisted images where iterative prompting showed real intellectual investment, and in 2025 began refusing protection where claimants could not produce their generation records. Korea registers AI-assisted works to the extent of the demonstrated human contribution. And the United Kingdom, the one major jurisdiction that took the opposite route by deeming a legal author for computer-generated works, concluded in March 2026 that the provision should be repealed. Our submission recommends Malaysia codify the converged position rather than adopt what the UK is discarding.

One practical lesson falls out of this for any business creating with AI today, whatever the amendments eventually say: keep your generation records. The prompts, the iterations, the human edits. In China they are already the difference between winning and losing, and every serious jurisdiction is heading the same way.

The Register and AI-assisted works

The consultation proposes strengthening the Copyright Voluntary Notification system, so that CVN certificates and certified extracts of the Register are admissible in evidence. We support the direction, with one addition. As AI-assisted works are notified in growing numbers, the Register will fill with works whose protection depends on the degree of human contribution, and the notification process does not currently ask. Our submission recommends an AI-assistance declaration at notification, with the enhanced evidentiary status remaining a rebuttable presumption. Korea's registry has operated on exactly this basis since mid-2025.

The 11 recommendations

The full text of each recommendation, with the analysis behind it, is set out in the written submission.

No.SubjectRecommendation in brief
1TDM modelAdopt a hybrid TDM exception for computational data analysis including AI training
2Access gateCondition the exception on lawful access to the works used
3ContractMake the exception non-excludable by contract
4Market harmExclude uses conflicting with normal exploitation or unreasonably prejudicing owners' legitimate interests, including output substitution and licensing-market displacement
5TransparencyRequire source records and published training-data summaries, at guideline level
6PDPA interfaceProvide expressly that the exception is without prejudice to Act 709
7Joint guidanceMyIPO and JPDP to issue joint or aligned guidance on AI training across both regimes
8SubsistenceCodify a human-authorship threshold in sections 3 and 7
9No deemingDo not adopt a UK s.9(3)-style computer-generated works provision
10CVNRequire AI-assistance declarations in CVN notifications; enhanced evidentiary status to remain a rebuttable presumption
11Foreign developersAttach transparency obligations to deployment in Malaysia; open a channel for foreign developer input

Four questions to Global Law Office, Beijing

Most of the AI systems Malaysians use every day were built by companies that never saw this consultation. Our final recommendation asks MyIPO to give foreign AI developers a way to be heard before the Bill is finalised. Rather than only recommend that they be asked, we went and asked.

Annexure C sets out four questions we put to Global Law Office, Beijing, and their answers: how Chinese courts approach copyright in AI-generated content, which training-data model works better in practice, what Chinese law requires on training-data transparency, and how the proposed enforcement measures look from the platform side.

Contributor to Annexure C Global Law Office, Beijing

Annexure C was prepared with a contribution from Global Law Office, established in 1984 as the first law firm founded following the implementation of China's reform and opening-up policy, and today among the largest full-service firms in the People's Republic of China. The responses were prepared by Xu Guosheng, Senior Consultant, and Zheng Qiwen, Associate. This is our second collaboration with GLO, following their contribution to our submission on the proposed AI Governance Bill.

GLO's answers appear substantially as they gave them, with only light editing for style. GLO describes the law and practice of the People's Republic of China; nothing in the annexure is advice on Malaysian law, and GLO should not be taken to endorse the recommendations in our submission, which are ours alone. Neither firm advises on the other's jurisdiction.

Common questions about AI and copyright in Malaysia

Can AI-generated work be copyrighted in Malaysia?

There is no express answer in the Copyright Act 1987 yet, and no Malaysian court has decided the point. On the current Act, our view is that a work generated by AI without meaningful human creative contribution has no author under section 3 and attracts no copyright, while a work created by a human using AI as a tool, where the human's creative choices show in the output, is protected in the ordinary way. The proposed amendments are expected to address this, and our submission recommends codifying a human-authorship threshold.

Is it legal to train AI on copyrighted works in Malaysia?

The position is currently uncertain. The Copyright Act 1987 has no text and data mining exception, and its fair dealing provision was not designed for corpus-scale computational analysis. Copying works into a training dataset is a reproduction, which is a restricted act. The consultation proposes introducing a TDM exception, and asks whether Malaysia should follow Japan's model, Singapore's, or a hybrid. Our submission recommends a hybrid: lawful access as the gate, protection against unreasonable prejudice as the safety valve, and transparency obligations alongside.

If my company uses AI to create content, who owns it?

Ownership only arises if copyright subsists at all, which is the threshold question above. Where a human's creative contribution qualifies the work for protection, copyright vests in the author, and for employees creating in the course of employment it belongs to the employer under section 26. Two practical safeguards matter today regardless of how the amendments land: keep records of the human creative process, and put written assignments in place with any external contributor, because an assignment of copyright is only effective in writing.

Does training an AI on personal data require consent in Malaysia?

The Personal Data Protection Act 2010 applies to personal data in training datasets independently of copyright law. Its default rule is consent, its exceptions are narrow, and it has no general legitimate-interests ground. Whether and how AI training on personal data can be conducted lawfully under Act 709 is an open question, which we have raised in both of our consultation submissions. A copyright exception, if enacted, will not answer it.

What are the proposed amendments to the Copyright Act 1987?

The consultation covers five reform clusters: international commitments (the Beijing Treaty and Brussels Convention), technology and the digital economy (AI, technological protection measures, injunctions, service provider liability), economic value creation (IP financing, the artist's resale right, orphan works), governance (collective management organisations, the Copyright Tribunal, voluntary notification), and legal certainty (the copyright and industrial design boundary). Our submission addresses the AI-related proposals only.

When will the amendments become law?

No date has been announced. The public consultation closed on 14 August 2026. An amendment Bill has not yet been published, and the proposals will change between consultation and enactment. We track material developments on this page.

What should businesses using AI do now?

Three things that hold whatever the amendments say. First, keep generation records for any AI-assisted work that matters commercially: prompts, iterations, and the human edits, because courts in comparable jurisdictions already decide cases on them. Second, check the terms of every AI tool in your stack: who owns the output, whether commercial use is permitted on your plan, and what survives if you leave the platform. Third, remember the two gates: clearing copyright does not clear personal data, and vice versa.

Developments

We record material developments here as they occur.

  • Public consultation closes. Our submission filed with MyIPO by email, comprising the written submission and Annexures A, B and C.
  • MyIPO opens the public consultation on the Unified Public Consultation portal, publishing the Consultation Document and the consolidated text of Act 332.

Primary sources

  • Unified Public Consultation portal: the consultation listing for the proposed amendments, including the Consultation Document and supporting materials
  • MyIPO, the Intellectual Property Corporation of Malaysia, under the Ministry of Domestic Trade and Cost of Living
  • Copyright Act 1987 (Act 332), consolidated text, available from the consultation listing above

Related reading

Key contact

Edwin Lee, Founder and Managing Partner of Edwin Lee & Partners

Edwin Lee

Founder and Managing Partner, Edwin Lee & Partners

Edwin advises Malaysian and international organisations on data protection, technology and commercial matters, including compliance with the Personal Data Protection Act 2010 and the Commissioner's 2024 to 2025 instruments, and acts as the named Data Protection Officer on client engagements. He co-edited Beyond Data Protection: Strategic Case Studies and Practical Guidance (Springer, 2013), and has filed written submissions on both of Malaysia's 2026 consultations shaping the law of artificial intelligence: the AI Governance Bill and the Copyright Act amendments.

If your organisation builds with AI, deploys it, or is negotiating with parties who do, we are happy to discuss how the proposed framework is likely to apply.

The documents on this page were prepared by Edwin Lee & Partners and submitted in response to a public consultation. They set out our proposals to that consultation and do not describe what the law will be. Nothing on this page constitutes legal advice to any person; specific advice should be sought for particular circumstances.

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.