policy · Effective Jan 1, 2026
MY regulates AI through AI Technology Action Plan 2026–2030 (planned / NAIO deliverable).
AI Technology Action Plan 2026–2030 (planned / NAIO deliverable) · effective 2026
Updated 60 days ago · 3 sources · confidence: medium
Overview
Malaysia is actively shaping a comprehensive and forward-looking regulatory landscape for Artificial Intelligence, reflecting a strategic intent to become a regional leader in the digital economy by 2030. The nation's approach is characterized by a blend of strategic policy documents, national roadmaps, and guidelines, with a clear trajectory towards establishing more formal regulatory frameworks for high-risk AI systems. This ecosystem is designed to foster innovation and economic growth through AI adoption, while simultaneously addressing critical concerns related to ethics, data protection, cybersecurity, and societal impact. The establishment of the National Artificial Intelligence Office (NAIO) as the central coordinating authority underscores Malaysia's commitment to a harmonized and coherent national AI agenda, integrating efforts across government, industry, and academia.The overarching philosophy emphasizes a human-centric approach, ensuring that AI development is inclusive, responsible, and beneficial for all citizens. This is evident in initiatives like the AI untuk Rakyat program, aimed at enhancing public AI literacy, and the integration of ethical principles into national guidelines. The regulatory framework is evolving, moving from foundational policy documents like the Malaysia National Artificial Intelligence Roadmap 2021-2025 (AI-RMAP) and the National Guidelines on AI Governance & Ethics (AIGE) towards more concrete implementation through action plans, talent roadmaps, and specialized sandboxes. This iterative development signifies a pragmatic and adaptive strategy, allowing Malaysia to respond to rapid technological advancements while building a resilient and trustworthy AI environment.
Regulatory approach
Malaysia's regulatory approach to AI is predominantly risk-based and currently leans towards soft law instruments, such as policies, guidelines, and roadmaps, rather than immediate prescriptive legislation. This allows for flexibility and adaptability in a rapidly evolving technological domain. The AI Technology Action Plan 2026–2030, a key deliverable of the NAIO, explicitly adopts a risk-based approach, differentiating obligations and oversight intensity based on the potential harm, social importance, and scale of AI systems. This includes defining high-risk categories, such as biometric identification, safety-critical infrastructure, and clinical decision-support, for which stricter requirements around risk assessment, impact assessment, documentation, testing, transparency, and human oversight are anticipated.The regulatory landscape is characterized by a horizontal coordination mechanism, with the NAIO serving as the central hub for strategy and harmonization, while acknowledging the continued supervisory authority of sectoral regulators. This multi-stakeholder model, often described as a 'quadruple-helix' approach (government, academia, industry, and civil society), is evident in initiatives like the Malaysia Artificial Intelligence Consortium (MAIC). While current guidelines like the National Guidelines on AI Governance & Ethics (AIGE) are voluntary, they are intended to inform future mandatory requirements, particularly in high-risk contexts. The use of innovation sandboxes, such as the AI Sandbox 2024, further exemplifies this approach by providing controlled environments for testing AI solutions under regulatory flexibility, thereby informing future policy and regulatory design without stifling innovation. Malaysia's AI governance and enforcement landscape is characterized by a multi-institutional approach, with several key bodies playing distinct yet coordinated roles. The National Artificial Intelligence Office (NAIO), incubated under MyDIGITAL Corporation, stands as the central authority responsible for driving Malaysia's national AI agenda. Its mandate includes drafting the AI Technology Action Plan 2026–2030, developing a national AI code of ethics, designing a regulatory and governance framework for AI deployments, and fostering public-private partnerships. NAIO's role is primarily strategic planning, policy drafting, stakeholder convening, and technical guidance, coordinating with sectoral regulators rather than acting as a single-sector regulator itself.The Ministry of Science, Technology and Innovation (MOSTI) plays a crucial role in spearheading research, development, commercialization, and innovation in science and technology, including AI. It was responsible for publishing the National Guidelines on AI Governance & Ethics (AIGE) and the Malaysia National Artificial Intelligence Roadmap 2021-2025 (AI-RMAP). The Personal Data Protection Commissioner (JPDP), an agency under the Ministry of Digital, is the primary regulator for personal data protection, enforcing the Personal Data Protection Act 2010 (PDPA) and its 2024 amendments. It oversees compliance, investigates complaints, and issues enforcement notices related to data processing in commercial transactions. The National Cyber Security Agency (NACSA), under the National Security Council, is the lead agency for cybersecurity matters, responsible for securing and strengthening Malaysia's resilience against cyber threats. It plays a critical role in implementing the Cyber Security Act 2024, designating National Critical Information Infrastructure (NCII) sectors, and requiring compliance with security obligations.In the financial sector, the Securities Commission Malaysia (SC) regulates capital market entities, issuing guidelines like the Guidelines on Technology Risk Management (GTRM) to manage technology risk, including AI/ML. Similarly, Bank Negara Malaysia (BNM), the central bank, issues policy documents such as the Policy Document on Risk Management in Technology (RMiT) to regulate technology-related risks for financial institutions. Other key players include MyDIGITAL Corporation, which acts as a strategic change management office for the Malaysia Digital Economy Blueprint, Malaysian Research Accelerator for Technology & Innovation (MRANTI), which operationalizes the National Technology & Innovation Sandbox (NTIS) and the AI Sandbox pilot program, Malaysia Digital Economy Corporation (MDEC), a government agency under the Ministry of Digital leading Malaysia's digital economy, and the Ministry of Higher Education (MOHE), which leads initiatives for AI talent development and academic reform.
Enforcement & penalties
Penalties and enforcement mechanisms in Malaysia's AI regulatory landscape are primarily derived from existing statutory frameworks, with new legislation like the Cyber Security Act 2024 and amendments to the Personal Data Protection Act 2010 introducing more stringent provisions. Under the Cyber Security Act 2024, contraventions can lead to criminal prosecution, including fines and/or custodial sentences, depending on the severity of the offense. Lower-level infractions may be compounded under the Cyber Security (Compounding of Offences) Regulations 2024. NACSA, as the lead enforcement body, is empowered with investigatory, directive, and enforcement powers, including the authority to issue technical directions, require remedial actions, and demand records or audits from National Critical Information Infrastructure (NCII) entities.The Personal Data Protection Act 2010 (PDPA), as amended by the Personal Data Protection (Amendment) Act 2024, significantly increases criminal penalties for failures to notify data breaches and other contraventions. Fines can reach up to RM1,000,000 and/or imprisonment for up to three years for specified provisions. The Personal Data Protection Commissioner (JPDP) has expanded powers to investigate complaints, conduct inspections, issue enforcement notices, and compound offenses. For financial institutions, non-compliance with guidelines like BNM's Policy Document on Risk Management in Technology (RMiT) or SC's Guidelines on Technology Risk Management (GTRM) can result in administrative monetary penalties, directions, or other enforcement measures imposed by the respective regulators. The SC, for instance, can appoint independent reviewers at the capital market entity's expense to assess compliance. While many AI-specific guidelines are currently voluntary, they signal future regulatory expectations, and non-adherence can impact an entity's standing or lead to more stringent oversight.
Data protection
Malaysia's data protection framework is primarily governed by the Personal Data Protection Act 2010 (PDPA), which regulates the processing of personal data in commercial transactions. The PDPA establishes seven core principles: General, Notice and Choice, Disclosure, Security, Retention, Data Integrity, and Access. These principles mandate lawful and fair processing, require informing data subjects and obtaining consent where necessary, restrict data disclosure and cross-border transfers, set limits on data retention, ensure data accuracy and security, and grant data subjects rights of access and correction. The Act applies to "data users" (now largely referred to as "data controllers" and "data processors" following recent amendments) and is enforced by the Personal Data Protection Commissioner (JPDP).The Personal Data Protection (Amendment) Act 2024 significantly strengthens this framework, aligning it with contemporary digital practices and international standards. Key amendments include the statutory requirement for data controllers and data processors to appoint Data Protection Officers (DPOs) and notify the Commissioner of these appointments. It also formalizes breach management, requiring controllers to notify the Commissioner as soon as practicable upon a personal data breach, and affected data subjects without undue delay if significant harm is likely. The Amendment introduces the right to data portability and reforms provisions on cross-border transfers, moving towards a conditions-based framework supported by new guidelines from the JPDP. While Malaysia does not have a direct equivalent to the EU's GDPR, these amendments demonstrate a clear move towards enhanced accountability, data subject rights, and robust data governance, particularly relevant for AI systems that heavily rely on personal data.
Sector-specific rules
Malaysia has begun to implement sector-specific rules for AI, particularly in highly regulated industries like finance and critical infrastructure, often integrating AI considerations into broader technology risk management frameworks. Bank Negara Malaysia (BNM), the central bank, has updated its Policy Document on Risk Management in Technology (RMiT) to include explicit expectations for financial institutions in managing technology-related risks, encompassing new technologies like AI/ML. The RMiT sets strengthened requirements for technology risk governance, cybersecurity controls, third-party and outsourcing governance (including cloud service providers), and incident resilience, with a proportionate approach based on the institution's size and complexity. This ensures that AI deployments in the financial sector adhere to rigorous standards for stability, security, and data integrity.Similarly, the Securities Commission Malaysia (SC) has issued its revised Guidelines on Technology Risk Management (GTRM), which establish mandatory expectations for capital market entities in managing technology risk across the lifecycle of critical systems and services. The GTRM explicitly includes controls for new technologies such as AI/ML, requiring comprehensive risk assessments, pre-deployment cybersecurity assessments, and penetration testing for critical systems. While direct AI-specific legislation for sectors like healthcare or autonomous vehicles is still developing, the AI Technology Action Plan 2026–2030 and the Malaysia National Artificial Intelligence Roadmap 2021-2025 (AI-RMAP) identify these as priority sectors for AI adoption and governance, signaling that future sector-specific regulations or guidelines will likely emerge, building upon the foundational ethical principles outlined in the National Guidelines on AI Governance & Ethics (AIGE).
International alignment
Malaysia is actively pursuing international alignment in its AI regulatory development, recognizing the global nature of AI technology and its governance challenges. The National Guidelines on AI Governance & Ethics (AIGE) explicitly cite and align with principles from international bodies such as the OECD and UNESCO, indicating a commitment to global best practices. This alignment is further emphasized in the AI Technology Action Plan 2026–2030, which stresses interoperability with ASEAN partners and other international frameworks, aiming to adopt global best practices while retaining policy space for national priorities. The National Artificial Intelligence Office (NAIO) is tasked with coordinating this international engagement, ensuring that Malaysia's evolving regulatory framework facilitates cross-border trade, investment, and research collaboration.The Malaysia Digital Economy Blueprint (MyDIGITAL) also highlights international alignment as a strategic thrust, aiming to position Malaysia as a regional digital leader. This includes fostering international cooperation in digital trade, cybersecurity, and data governance. While there is no direct adoption of the EU AI Act, its risk-based approach and emphasis on high-risk systems are conceptually mirrored in Malaysia's planned AI regulatory framework. The country's participation in international forums and partnerships, such as those facilitated by the Malaysia Artificial Intelligence Consortium (MAIC), further demonstrates its commitment to contributing to and learning from global discussions on AI governance, ensuring that its domestic policies are robust, competitive, and compatible with international norms.
What's next
Malaysia's AI regulatory landscape is poised for significant future developments, with several key initiatives already planned or in progress. The most prominent is the AI Technology Action Plan 2026–2030, a core deliverable of the National Artificial Intelligence Office (NAIO). This plan is expected to translate Malaysia's policy goals into concrete programs, governance instruments, and implementation milestones, building upon the existing National AI Roadmap (2021–2025) and the National Guidelines on AI Governance & Ethics (AIGE). It is anticipated to define high-risk AI categories and set mandatory requirements around risk assessment, impact assessment, documentation, testing, transparency, and human oversight, potentially leading to new secondary legislation or statutory powers to operationalize these obligations.Further legislative and policy developments are also expected to strengthen the overall digital trust environment. The Personal Data Protection (Amendment) Act 2024, with its staged commencement dates throughout 2025, will fully implement new duties for Data Protection Officers and mandatory data breach notifications, significantly impacting how AI systems handle personal data. The NAIO, currently in an incubation period, is also tasked with developing a national AI code of ethics and an AI regulatory framework, which will further shape the future legal and ethical landscape for AI in Malaysia. Additionally, ongoing initiatives like the AI Sandbox 2024 and the Malaysia Artificial Intelligence Consortium (MAIC) will continue to inform policy through practical experimentation and multi-stakeholder collaboration, ensuring that future regulations are evidence-based and responsive to technological advancements and industry needs. The MyDIGITAL Corporation has also issued procurement notices for a mid-term review of the MyDIGITAL Aspirations, which will cover initiatives from 2026 to 2030, further refining the national digital and AI strategy.
policy · Effective Jan 1, 2026
policy · Effective Jan 1, 2025
Sources:
central_coordinator
Central authority for driving Malaysia's AI agenda, including strategy, governance framework, and ethical development.
central_coordinator
Spearheads science, technology, and innovation for economic growth, technological advancement, and societal well-being.
central_coordinator
Strategic Change Management Office for driving the execution of the Malaysia Digital Economy Blueprint and National 4IR Policy.
data_protection
Regulates the processing of personal data in commercial transactions under the PDPA.
Apr 29, 2026 · guideline_issued
Malaysia JPDP publishes guidelines on DPIA, Privacy by Design, and automated decision-making and profiling
Open source →Apr 26, 2026 · news
Malaysia digital minister weighs AI legal personality, stresses human accountability
Open source →Mar 1, 2026 · news
Malaysia's AI-focused approval strategy will accelerate market consolidation in Johor
Open source →Feb 13, 2026 · news
Government Innovation Initiative (GII) to accelerate Malaysia's journey of becoming an AI Nation by 2030
Open source →Jan 22, 2026 · news
No tracked international memberships yet
Last checked May 26, 2026
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
act · Effective Jan 1, 2024
Sources:
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
act · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
regulation · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2020
act · Effective Jan 1, 2010
act · Effective Jan 1, 2010
policy · Effective n/a
policy · Effective Jan 1, 2021
sectoral
National lead agency for cybersecurity matters, securing and strengthening Malaysia's resilience against cyber threats.
advisory
Regulates and systematically develops the capital markets in Malaysia.
central_coordinator
Central bank responsible for promoting monetary and financial stability, and regulating financial institutions.
advisory
Lead agency in driving Malaysia's digital economy.
central_coordinator
Malaysia's central research & innovation commercialisation agency that accelerates ideas to market.
central_coordinator
Responsible for higher education, polytechnic, community college, student loan, accreditation, student volunteer.
MCMC lifts temporary restriction on access to Grok application on X platform
Jan 14, 2026 · news
Communications Ministry mulls revising social media user threshold following Grok AI issues
Open source →Jan 10, 2026 · news
MCMC orders temporary restrictions against Grok
Open source →Jan 2, 2026 · news
MCMC investigates misuse of AI by X
Open source →Nov 23, 2025 · guideline_issued
AI legislative framework to be presented to Cabinet in June 2026
Open source →Nov 21, 2025 · law_amended
Malaysia moves to curb AI’s harmful impact on children
Oct 26, 2025 · news
Malaysia and Brazil deepen ties in technology and innovation
Open source →Oct 7, 2025 · law_amended
Malaysia preparing risk-based AI law to address rising harms, minister says
Open source →Oct 7, 2025 · news
UK and Malaysia elevate regional AI partnership to drive growth
Open source →Sep 7, 2025 · news
Malaysia’s 2026 budget to prioritise AI nation 2030 and GovTech initiatives
Open source →Aug 3, 2025 · news
2025 APEC Digital and AI Ministerial Statement
Open source →Jul 31, 2025 · news
UAE, Malaysia, and Rwanda forge AI alliance to empower Global South
Open source →Jul 30, 2025 · guideline_issued
13th Malaysian Plan unveiled, targeting Malaysian AI and green tech leadership in Southeast Asia by 2030
Open source →Jul 22, 2025 · law_amended
Malaysia PM Anwar calls for AI laws to protect local arts scene
Open source →Jul 20, 2025 · news
Malaysia eyes AI leadership with new national blueprint
Open source →Jul 13, 2025 · news
Malaysia tightens export controls on US-origin AI chips
Open source →Jul 6, 2025 · news
Malaysia Prime Minister backs BRICS call for global AI governance
Open source →Jun 15, 2025 · news
Updates on Malaysia AI-specific legislation
Open source →Jun 2, 2025 · guideline_issued
Malaysia AI regulatory framework report expected by end of June 2025
Open source →May 13, 2025 · guideline_issued
Malaysia plans ASEAN-focused AI trust framework
Open source →May 2, 2025 · law_amended
Science, Technology and Innovation Minister reveals there is no clear timeline for Malaysian AI law
Open source →Mar 23, 2025 · law_amended
Malaysia set to strengthen regulations on semiconductor, AI chips export
Open source →Mar 4, 2025 · news
Malaysia signs $250 million deal with ARM for chip design blueprints
Open source →Mar 3, 2025 · law_amended
Malaysia probes alleged Nvidia chips moved from Singapore, vows ‘necessary action’ against local firms involved
Open source →Feb 16, 2025 · news
Malaysian Ministry of Digital seeking consultancy on proposal to establish ASEAN AI Safety Network
Open source →Jan 27, 2025 · law_amended
Malaysia government launches fact-checking AI chatbot 'AIFA'
Open source →Dec 11, 2024 · news
Malaysia launches national AI office
Open source →Nov 17, 2024 · law_amended
Malaysia Parliament lower house to discuss impact of AI on local culture and values
Open source →Sep 30, 2024 · law_amended
Malaysia plans national cloud policy, AI regulations
Open source →Sep 19, 2024 · guideline_issued
National Guidelines on AI Governance and Ethics adopted
Open source →Aug 18, 2024 · guideline_issued
Update to Technology Risk Management Guidelines, covering AI
Open source →Jul 26, 2024 · news
Malaysia introduces licensing regime for social media companies
Open source →Jun 3, 2024 · law_amended
Malaysian Communications and Multimedia Commission says AI regulation needs to be expedited
Open source →May 27, 2024 · news
Malaysia Digital Minister states Malaysia is "strategically positioned" to capitalise on AI
Open source →Dec 3, 2023 · guideline_issued
MOSTI to present full framework for AI Code of Ethics in Q1 2024
Open source →Jul 22, 2023 · law_amended
Law on AI being studied
Open source →Jun 6, 2023 · guideline_issued
Putrajaya working towards framework to regulate AI
Open source →