Malaysia Advances AI Governance Bill as New Enterprise Rules Take Shape Malaysia's Digital Ministry has completed the draft of its proposed AI Governance Bill and is preparing it for Cabinet, Digital Minister Gobind Singh Deo said Sept. 10, with the legislation potentially reaching Parliament in Q3 2026 or Q1 2027. The principle-based, risk-based framework would distinguish Developers from Deployers, place AI systems into three risk tiers, and could reach Malaysia-based Deployers even when systems are hosted abroad, according to Baker McKenzie's analysis of the July 10 public consultation. AI Malaysia named the Bill and the Malaysia AI Safety Institute among its immediate priorities in a Sept. 12 update. Malaysia’s AI rulebook is moving closer to law. The Digital Ministry has completed the draft of its proposed AI Governance Bill and is preparing it for Cabinet, Digital Minister Gobind Singh Deo said Sept. 10. AI Malaysia followed Sept. 12 by naming the Bill and the Malaysia AI Safety Institute among its immediate priorities. Enterprises developing, adapting or deploying AI in Malaysia could eventually face formal requirements for risk management, human oversight, data governance and incident reporting. Gobind said the legislation could reach Parliament in Q3 2026 or, at the latest, Q1 2027, according to Bernama’s Sept. 10 report https://www.bernama.com/en/news.php?id=2605398 . The regulatory push coincides with an expanding domestic AI infrastructure market, including two planned Firmus AI Factory sites https://www.techrepublic.com/article/news-openai-firmus-data-centers-apac-malaysia/ where OpenAI has reserved future computing capacity. A broad proposal could reach vendors and customers The legislation is not final. Malaysia’s July 10 public consultation https://upc.mpc.gov.my/view-consultation/264 outlined a principle-based, risk-based framework spanning the AI lifecycle, but provisions may change before the Bill reaches Parliament. A central proposal distinguishes between Developers and Deployers. Under Baker McKenzie’s analysis https://www.bakermckenzie.com/en/insight/publications/2026/07/malaysia-public-consultation-on-the-ai-governance-bill , a company could qualify as a Developer by training a model, adapting one for a specific use case, integrating it into another system or materially modifying it after deployment. A Deployer determines whether, where and how an AI system is used. One organization could hold both roles, potentially extending obligations to companies that significantly customize third-party models rather than simply use them. The proposal could also cover systems used by Malaysia-based Deployers even when hosted abroad. That would put multinational model, cloud and software providers serving Malaysian operations within potential reach. AI systems would fall into three risk tiers. Systems intentionally developed or deployed to cause harm would be prohibited, while high-risk systems could face risk assessments, documentation, human oversight, monitoring and mitigation requirements. Proposed incident-reporting rules could also cover failures, misuse, unexpected effects and some near misses. Existing laws already shape enterprise AI use Malaysia does not yet have a dedicated AI law. AI Malaysia lists existing legislation https://www.ai.gov.my/faq/ai-governance-policy/ covering privacy, cybersecurity, copyright, communications and online safety that can already apply to AI deployments. IT teams should inventory active AI systems, document how models are selected, customized and monitored, and determine whether proposed Developer or Deployer definitions could apply. Vendor contracts should also address incident notification, audit rights and access to technical information. Those controls are becoming more important as APAC companies increase AI spending https://www.techrepublic.com/article/news-apac-ai-spending-roi-proof/ while governments pursue different oversight models. Malaysia has also issued voluntary board-level guidance through is Boardroom Primer for AI Adoption and Governance https://www.ai.gov.my/governance/boardroom-primer-to-ai-adoption-and-governance/ . Regional fragmentation adds another layer for multinational IT teams. Singapore and Thailand are already deepening cooperation on AI governance https://www.techrepublic.com/de/article/news-digital-ties-apac-singapore-thailand/ , while Malaysia develops its own national framework. Shared platforms, vendors and data flows may therefore face different governance requirements across Southeast Asian markets. AI Malaysia’s Sept. 12 update https://www.bernama.com/en/general/news.php?id=2606395 places the Bill and safety institute within the wider AI Nation 2030 program. The final requirements remain uncertain until the legislation clears Cabinet and Parliament, but enterprises operating in Malaysia now have a concrete regulatory process to prepare for. Let us teach you How to Talk to AI for free Try our six-minute course at The Neuron Academy and learn a few simple ways to write better prompts and get more useful results from AI, or browse our other AI course for free for seven days. Check out all the lessons here →