01

What happened in Malaysia

Malaysia opened a public consultation on a proposed Artificial Intelligence Governance Bill in July 2026. The consultation described a pre-drafting effort to create a comprehensive, coherent and future-ready framework for the responsible development, deployment and use of AI across sectors.

The distinction matters: Malaysia does not yet have a dedicated AI law, and the proposal should not be described as enacted regulation. But enterprises should treat the consultation as a strong directional signal. Voluntary principles are moving toward governance that can be demonstrated, assigned and tested.

Prepare for the direction of travel without claiming that a proposal is already law.

02

Start with an AI system register

An organisation cannot govern systems it cannot name. Build one register covering purchased AI features, internally developed models, copilots, autonomous agents and AI embedded in third-party services.

For each system, record its business owner, purpose, users, affected people, data categories, deployment location, connected tools, model providers and current approval path. This becomes the control plane for risk assessment, procurement and incident response.

  • Name an accountable business owner and technical owner.
  • Record every model, knowledge source and external tool.
  • Classify the decisions or actions the system can influence.
  • Document deployment, data location and cross-border dependencies.
  • Set a review date and a retirement path.
03

Turn principles into evidence

Policy statements are useful only when an organisation can show that they affected a real request. Evidence should connect the identity, active knowledge scope, retrieved sources, selected model, tool calls, cost and outcome.

Denied retrievals and rejected approvals matter as much as successful work. They show that a boundary operated when it was needed, rather than existing only in a policy document.

The practical unit of AI governance is a reconstructable decision—not a slide about responsible AI.

04

Keep consequential action under human authority

Agents can research, compare, draft and prepare transactions, but meaningful checkpoints should remain with named people. Approval must happen before an external consequence, not after an agent has already acted.

Define which actions require review, what evidence the reviewer receives, how long an approval remains valid and what happens when it is denied or expires. The audit record should preserve the request, reviewer, decision, time and resulting action.

05

A practical 90-day preparation plan

Use the policy window to improve foundations that will remain valuable under any final framework. Begin with high-consequence use cases rather than trying to classify every experiment at once.

In the first month, establish the register and owners. In the second, test data and knowledge boundaries. In the third, run an incident reconstruction and prove that one important agent action cannot proceed without approval.

  • Days 1–30: inventory systems, owners, models and data flows.
  • Days 31–60: test permission boundaries and model-provider exits.
  • Days 61–90: test monitoring, approval and incident reconstruction.
PRIMARY SOURCES

Official references.

These field notes interpret official materials for enterprise teams. They are not legal advice.