A Guide To AI Usage Policies For Malaysian Businesses

A Guide To AI Usage Policies For Malaysian Businesses

Table of Contents

As AI tools become increasingly common in Malaysian workplaces, employers should implement clear AI usage policies to ensure PDPA 2010 compliance. Without proper controls, companies risk data leakage and quality control issues. 

This guide breaks down what Malaysian employers should include in a workplace AI policy to promote responsible use of artificial intelligence and protect themselves from potential legal liability. 

The law on workplace AI use

Malaysia currently has no specific legislation regulating workplace AI use. However, key points to note are that: 

  • employers should set clear boundaries on AI tool usage through documented policies 
  • existing laws still apply, including confidentiality obligations, data protection principles, and intellectual property rights 
  • employees remain accountable for work outputs, even when AI tools are used to assist or generate content 

Why employment contracts aren’t enough 

Most employment contracts include brief confidentiality clauses  but don’t specifically address AI tool usage or data handling with artificial intelligence platforms or other generative AI systems.  

An AI usage policy fills the gaps by explaining: 

  • which AI tools are approved for work use 
  • what data can and cannot be input into AI systems 
  • quality control and verification requirements for AI-generated content 
  • consequences for unauthorised AI tool use or data breaches 

This ensures employees understand how to use AI tools safely while protecting company confidential information and maintaining work quality standards. 

Key inclusions  

AreaWhat the policy should cover
Approved and prohibited AI tools

Clearly specify which AI tools employees may and may not use for work purposes, including:

  • Approved company-provided or IT-authorised AI tools
  • Prohibited tools such as free public AI platforms
  • Unauthorised third-party applications
Data protection and confidentiality with AI tools

Establish clear boundaries on what information may be shared with AI systems, ensuring sensitive data is not input into AI tools, including:

  • Client data
  • Employee personal data
  • Proprietary and confidential information
  • NDA-protected information
Quality control and human oversight
  • Require human review of AI-generated outputs
  • Ensure employees remain accountable for accuracy and quality
  • Maintain professionalism in all AI-assisted work
  • Require appropriate disclosure of AI use where applicable
Prohibited uses of AI tools

Clearly define unacceptable AI usage, including:


  • Creating misleading or fraudulent content

  • Bypassing security controls

  • Relying solely on AI outputs without verification

  • Breaching company rules such as social media policies

Consequences for policy violations
  • Clear explanation of how violations are assessed
  • Warnings and mandatory retraining
  • Suspension or termination of employment
  • Regulatory reporting where required

Balance innovation and risk management 

The goal of an AI usage policy is to enable productive AI use while managing risks, and the best practice approach will likely involve: 

  • providing clear approved AI tools so employees can work efficiently 
  • focusing restrictions on real risks rather than banning all AI use 
  • regularly reviewing and updating policy as AI tools and capabilities evolve 
  • encouraging employees to suggest useful AI tools for company evaluation 

Realistically, it’s not possible to stop employees from using AI tools at work, so the focus should therefore be on ensuring employees to understand data leakage risks and take measures to prevent them. 

Safely grow your business with AI

A clear AI usage policy ensures your business benefits from AI innovation while managing associated risks. If you are looking to develop an AI Usage Policy or update your existing framework, we can help you draft clear policies that enable productive AI use while protecting your business, integrated with your employment contracts and workplace policies. 

shen-ming-casual

Wong Shen Ming

Shen Ming is a corporate and commercial lawyer who is deeply committed to supporting her clients in achieving their business goals. Specialising in commercial and employment law, she demonstrates her expertise by crafting and reviewing various types of commercial agreements.

View her full profile here.

Let us know how we can support your business

Drop us a message and let us better understand your needs. Get your first consultation within 24-hours, absolutely free of charge.
Share this article:
Post might interest you:
ABOUT THE AUTHOR

Wong Shen Ming

Legalising Ride-Sharing Services

Legalising Ride-Sharing Services

Taxi-booking services such as MyTeksi and Easy Taxi, as well as ride-sharing booking services such as Uber and GrabCar, have been touted as the game changers as they set to

How To Be A Savvy IP Blogger

How To Be A Savvy IP Blogger

With about 2 blogs created each second every day, blogging is growing at a speed faster than any other web activities on the Internet. Bloggers are not immune from legal

Want more content like this?

Drop us your email and be the first to know when we have more informative contents on the latest legal updates, just like this one.

A boutique corporate & commercial law firm in Kuala Lumpur.

FREE Legal Updates

Sign up for our newsletter to get the latest updates, happenings and goodies!
We don't spam, promise.
Global Chamber of Business Leaders logo - Light

 © Copyright 2025, Edwin Lee & Partners (Reg No.: 000020008633)

Edwin Lee & Partners is a Malaysian law firm registered with the Malaysian Bar and is regulated under the Legal Profession Act 1976. 
Click here to see our certificate of registration

Responsibilities of Executor:

  • Apply for and extract the grant of probate.
  • Make arrangements for the funeral of the deceased.
  • Collect and make an accurate inventory of the deceased’s assets.
  • Settling the debts and obligations of the deceased.
  • Distributing the assets.

Note for Digital Executor:
If you wish to leave your digital assets to certain people in your Will, there are important steps that need to be taken to ensure that your wishes can be carried out:

  • Keep a note of specific instructions on how to access your username and password of your digital asset.
  • You are advised to store these private and confidential information in a USB stick, password management tool or write them down.
  • Please inform your executor or a trusted person of the whereabouts of the tools so that they will have access to your digital asset.