
Public consultation submission
Malaysia's AI Governance Bill: our submission to the consultation
On 31 July 2026 we filed a written submission with the National AI Office on Malaysia's proposed AI Governance Bill: 24 recommendations across the Bill's architecture, scope, principles, risk framework, incident reporting and sandbox, together with three annexures. This page collects the full papers and tracks the Bill as it develops.
Filed by Edwin Lee & Partners, Kuala Lumpur, with a contribution from Global Law Office, Beijing. 40 pages across four documents. Last updated .
In brief
- The AI Governance Bill would be Malaysia's first horizontal statute dedicated to artificial intelligence, replacing a patchwork of data protection law, sector regulation and voluntary ethics guidelines.
- The National AI Office released its Public Consultation Paper on 10 July 2026. Consultation closed on 31 July 2026. The Bill is reported as targeted for completion by the end of 2026.
- It proposes a risk-based framework with three tiers, two regulated roles (Developer and Deployer), and a Central AI Authority supported by Sectoral Leads.
- Our submission makes 24 recommendations. Its central thesis is that the Bill should integrate with the law Malaysia already has — one vocabulary for the actors, one assessment per system, one filing per incident — rather than run parallel to it.
- Our three principal findings concern whether the Bill binds the Government, whether Malaysian law provides a lawful basis for training AI on personal data, and the absence of foreign developers from the consultation.
The papers
These documents may be quoted with attribution to Edwin Lee & Partners. Journalists and researchers are welcome to contact us for comment.
What the AI Governance Bill proposes
The AI Governance Bill would be Malaysia's first horizontal legal framework dedicated to artificial intelligence. Rather than regulating AI sector by sector, it sets common principles and a single risk-based structure intended to sit alongside existing law.
The National AI Office released its Public Consultation Paper on , together with a Summary and a Full Questionnaire. Written feedback closed on . The Bill is reported as targeted for completion by the end of 2026.
Two regulated roles: Developer and Deployer
A Developer is any person or organisation that materially shapes what an AI system is capable of doing — expressly including a party that adapts a model for a specific use case, integrates it into a wider system, or modifies it after deployment. A Deployer operates the system in the real world. One organisation can hold both roles at once.
These roles track the controller and processor concepts under the Personal Data Protection Act 2010 closely but not perfectly. A Deployer running an AI system on personal data will usually be a controller; a Developer providing a hosted model may be a processor for its customers' data and a controller for its own training data. Our submission recommends the mapping be made express rather than left to inference.
A three-tier risk framework
The framework is anchored to categories of harm rather than to technology. Tier 2 carries the substantive obligations: risk assessment, documentation, internal controls, human oversight, monitoring and mitigation. For organisations already conducting Data Protection Impact Assessments under the Commissioner's guideline, this describes an exercise they are largely performing already.
A Central AI Authority with Sectoral Leads
The proposed Authority holds three functions: AI Safety, Investigation and Enforcement, and AI Enablement. Sectoral Leads may be appointed and delegated powers where they already hold sufficient legal authority, technical expertise and governance capacity.
The institutional picture moved during the consultation itself. On the National AI Office was institutionalised as AI Malaysia Berhad under the Ministry of Digital, alongside the National AI Action Plan 2026–2030 and the establishment of a Malaysian AI Safety Institute.
Three principal findings
Most of the submission is detailed and technical. Three findings are not, and we put them first because they are the points most likely to be useful to the drafters.
The Bill does not say whether it binds the Government, and the answer changes the architecture
Malaysia's two most recent statutes in this field made opposite choices on the face of the Acts. The Personal Data Protection Act 2010 does not apply to the Federal or State Governments (section 3(1)). The Cyber Security Act 2024 does bind them, while preserving them from prosecution (section 2). The Consultation Paper does not say which course the Bill will take, although it assumes public-sector application in substance: its capacity-building functions expressly cover the public sector, and its own examples of high-consequence AI include welfare determination and government service delivery.
The consequence is structural. Our submission throughout is that the Bill should build on the PDPA. Section 3(1) removes that foundation entirely where a public authority delivers services to citizens through AI. There is no data-protection floor beneath the Bill in the public sector, so the Bill has to do more work there, not less: it must supply the assessment, notice and oversight standards directly, because no other instrument will.
Principle 5 presupposes a lawful basis for training AI on personal data that Malaysian law does not clearly provide
Principle 5 requires that data used in AI systems be "properly sourced", with attention to provenance. For the central input activity of AI development — training or fine-tuning a model on personal data — Malaysian law does not presently give a settled answer to what proper sourcing means. The uncertainty operates at three separate levels:
- Whether the PDPA applies at all. Act 709 regulates processing "in respect of commercial transactions". Whether personal data harvested at scale from open web sources meets that description is genuinely arguable and undecided.
- Whether the material is personal data in the relevant sense. Effectively anonymised data falls outside the Act. What counts as effective anonymisation, against a model that may memorise and reproduce training examples, is unresolved both technically and legally.
- If the Act applies to identifiable data, what the lawful basis is. Act 709 permits processing of non-sensitive personal data with consent or under one of six narrow necessity grounds; none is a legitimate-interests ground, and the Act contains no general publicly-available-data exception. The research exemption is unavailable where the data is also processed for another purpose — which commercial deployment is.
We raise this in the Bill's interest and in industry's. Our recommendation is coordination and restraint rather than resolution: this gap is not the Bill's to close, but the Bill should not be drafted as though it were already closed.
The Bill's most consequential audience has not been asked
Malaysia's stated ambition is to attract AI investment. The developers actually entering this market are to a significant degree foreign, and they are the parties least likely to respond to a Malaysian consultation — for reasons of language, unfamiliarity with the process, and limited incentive to engage at pre-drafting stage. The Bill therefore risks being drafted without evidence of how its central definitions land on the organisations it most needs to reach.
Annexure C addresses that gap directly. Two findings were significant enough to promote into the core submission: the Authority's information demands on foreign Developers will collide with foreign secrecy and data-export law unless the framework provides a cooperation route; and a Malaysian sandbox becomes a genuine regional entry pathway if its exit outcomes are recognised across ASEAN.
The Bill does not arrive on empty ground
A single theme connects everything else in the submission. Malaysia finished building a data-governance framework for AI in 2025. It has an operating cyber incident regime, a new online content regime, a product liability statute, an evidence code and a copyright act — each of which the Bill will touch on its first day in force.
What the Bill needs to do, and what only the Bill can do, is connect: one vocabulary for the actors, one assessment per system, one filing per incident, one transfer standard. Each collision point can be resolved now at essentially no cost. Resolving them later, through practice and dispute, will be expensive for everyone.
The 24 recommendations
The full list, with the paragraph where each is developed, is set out in the written submission. They group into six areas.
Coordination with the regulators that already exist
Designate the Personal Data Protection Commissioner as a Sectoral Lead for AI systems processing personal data; codify a coordination protocol rather than leaving it to administrative practice; provide single-window incident filing across the Bill, the PDPA and the Cyber Security Act; and provide an independent review route for the Authority's directions and penalties.
Scope and definitions
Map Developer and Deployer expressly onto controller and processor; state whether the Bill binds the Federal and State Governments; narrow the national security exemption so dual-use systems fall inside; give the extraterritorial scope an enforcement anchor and a mechanism for conflicts with foreign law; and define the further terms on which operative duties silently depend.
The governance principles
Redraft Principle 5 to incorporate the PDPA expressly rather than gesture at it; do not draft as though a lawful basis for training on personal data already exists; add a sixth principle on fairness and non-discrimination, grounded in Malaysia's own regulatory materials; and give the "due regard" duty a demonstrable floor for high-risk systems.
The risk framework
Expand the harm categories to include significant financial harm, unjustified discriminatory treatment, and denial of access to essential services; qualify "contravention of any written law" by reference to gravity; define Tier 1 by use-case severity rather than intent; and provide a primacy rule where the three classification axes conflict.
The AI Sandbox
Codify how the PDPA applies inside the sandbox; give exit a defined regulatory effect rather than a report alone; distinguish the technology-sandbox functions from the regulatory-sandbox function; and frame the sandbox additionally as an inbound-investment instrument, with a Malaysian initiative for ASEAN-level mutual recognition of sandbox outcomes.
The wider statute book
Coordinate with the Online Safety Act 2025 on AI-generated content; state the Bill's position on civil liability; review the interaction between AI-generated documents and section 90A of the Evidence Act; coordinate data-provenance expectations with copyright reform; and include a proportionate synthetic-content transparency obligation as the connective tissue the other regimes depend on.
A contribution from Global Law Office, Beijing
Contributor to Annexure C
Annexure C was prepared with a contribution from Global Law Office, established in 1984 as the first law firm founded following the implementation of China's reform and opening-up policy, and today among the largest full-service firms in the People's Republic of China. The responses were prepared by Xu Guosheng and Dai Chang.
The division of responsibility is stated in the annexure itself. Statements of foreign law and market practice are Global Law Office's, attributed as such. The Malaysian analysis, and every conclusion about the operation of the proposed Bill, are ours alone. Neither firm advises on the other's jurisdiction.
Common questions about the AI Governance Bill
Does Malaysia have a law regulating artificial intelligence?
Not a dedicated one. AI in Malaysia is currently governed by a patchwork: the Personal Data Protection Act 2010 where personal data is involved, sector regulation from Bank Negara Malaysia and the Securities Commission, the Online Safety Act 2025 for content harms, and the National Guidelines on AI Governance and Ethics (2024), which are voluntary. The proposed AI Governance Bill would be the first horizontal statute dedicated to AI.
When will the AI Governance Bill become law?
No date has been announced. Public consultation on the Consultation Paper closed on 31 July 2026, and the Bill is reported as targeted for completion by the end of 2026. A draft Bill has not yet been published, and the Bill will change between consultation and enactment.
Who will regulate AI in Malaysia?
The Consultation Paper proposes a Central AI Authority holding AI Safety, Investigation and Enforcement, and AI Enablement functions, supported by Sectoral Leads appointed from existing regulators. Separately, AI Malaysia Berhad was launched on 28 July 2026 as the national AI entity under the Ministry of Digital. The relationship between the two is one of the points our submission asks the Bill to clarify.
What is the difference between a Developer and a Deployer?
A Developer materially shapes what an AI system can do, expressly including a party that adapts a model for a specific use case, integrates it into a wider system, or modifies it after deployment. A Deployer operates the system in the real world. One organisation can be both, and duties are proposed to attach according to the degree of control each party exercises.
Does the AI Governance Bill apply to companies outside Malaysia?
The Consultation Paper proposes extraterritorial reach, covering AI systems designed, developed or used in Malaysia, including systems used by a Malaysian-established Deployer regardless of where the system is hosted. Our submission recommends the scope be given an enforcement anchor: a local representative for foreign Developers of high-risk systems, or the Malaysian Deployer as express compliance interface.
Is it lawful to train AI on personal data in Malaysia?
The position is unresolved. Under the Personal Data Protection Act 2010, three questions are open: whether the Act reaches personal data collected at scale from open web sources; what counts as effective anonymisation against a model that may reproduce training examples; and, if identifiable data is involved, which lawful basis applies. Act 709 permits processing of non-sensitive personal data with consent or under one of six narrow necessity grounds; none is a legitimate-interests ground, and the Act contains no general publicly-available-data exception.
Will the AI Governance Bill apply to the Government?
The Consultation Paper does not say. The Personal Data Protection Act 2010 excludes the Federal and State Governments under section 3(1); the Cyber Security Act 2024 binds them under section 2. Our first finding is that the Bill should state its position expressly, because there is no data-protection floor beneath it where a public authority delivers services through AI.
Does the Bill replace the PDPA?
No. The two would operate together. Most AI systems of regulatory interest process personal data and are already subject to the PDPA and the Commissioner's 2024–2025 instruments, including the mandatory breach notification regime, mandatory Data Protection Officer appointments, and the Data Protection Impact Assessment guideline. Our central submission is that the Bill should integrate with that framework rather than run parallel to it.
What is AI Malaysia Berhad?
AI Malaysia Berhad was launched on 28 July 2026 under the Ministry of Digital, institutionalising the National AI Office established in December 2024. It coordinates national AI policy and the implementation of the National AI Action Plan 2026–2030. The Malaysian AI Safety Institute was established alongside it to conduct safety assessments, model testing and red-teaming.
What is the proposed AI Sandbox?
A supervised environment for testing AI systems, implemented through Sectoral Leads' existing infrastructure. The Consultation Paper describes nine functions, eight of which are technical. The ninth — testing regulated activities under a relaxed regulatory environment — is a regulatory sandbox and requires express statutory power. Our submission recommends the two be separated in the drafting, and that successful exit carry defined regulatory effect.
What should organisations do before the Bill is tabled?
Identify which AI systems your organisation develops and which it deploys, since duties differ. Check whether existing Data Protection Impact Assessments cover those systems. Confirm your incident response can satisfy the PDPA breach notification regime and, for critical sector entities, the Cyber Security Act 2024. And identify who inside the organisation owns AI risk: for systems processing personal data, the mandatorily appointed Data Protection Officer is the natural candidate.
Developments
The Bill is reported as targeted for completion by the end of 2026. We record material developments here as they occur.
- Public consultation closes. Our submission filed with the National AI Office.
- National AI Action Plan 2026–2030 published, comprising 28 sectoral and enabling initiatives.
- AI Malaysia Berhad launched under the Ministry of Digital, institutionalising the National AI Office. Malaysian AI Safety Institute established.
- Cybercrimes Bill 2026 passed by the Dewan Negara, completing its passage through Parliament. Royal assent and gazettement pending.
- Malaysia becomes a founding member of the World AI Cooperation Organization, established in Shanghai.
- National AI Office releases the Public Consultation Paper, Summary and Full Questionnaire.
Primary sources
- AI Malaysia / National AI Office — the national AI entity under the Ministry of Digital
- Unified Public Consultation portal — the consultation listing for the proposed AI Governance Bill
- Ministry of Digital — announcements and the National AI Action Plan 2026–2030
Related reading
The Bill's closest neighbour in Malaysian law is the data protection regime, and most of the systems the Bill will reach are already regulated by it:
- Personal data protection in Malaysia — the PDPA framework and the Commissioner's 2024–2025 instruments
- The Data Protection Officer — mandatory appointment, and why that officer is the natural owner of AI risk classification
- Corporate governance — board-level oversight of technology deployment
Key contact


Edwin Lee
Founder and Managing Partner, Edwin Lee & Partners
Edwin advises Malaysian and international organisations on data protection, technology and commercial matters, including compliance with the Personal Data Protection Act 2010 and the Commissioner's 2024–2025 instruments, and acts as the named Data Protection Officer on client engagements. He analysed the Personal Data Protection Bill 2009 at the same pre-enactment stage this consultation now occupies (LL.M research, Faculty of Law, University of Malaya, 2010), and later co-edited Beyond Data Protection: Strategic Case Studies and Practical Guidance (Springer, 2013).
If your organisation is planning AI deployment ahead of the Bill, we are happy to discuss how the framework is likely to apply.
The documents on this page were prepared by Edwin Lee & Partners and submitted in response to a public consultation. They set out our proposals to that consultation and do not describe what the law will be. Nothing on this page constitutes legal advice to any person; specific advice should be sought for particular circumstances.