Independent map & monitor Malaysia Est. 2026 AI Governance Observatory

Mapping the governance of artificial intelligence in Malaysia

Malaysia has no binding AI-specific rule. What binds is general law, written for other things. Everything written for AI is voluntary or still in draft. This site maps the instruments by force and tracks the proceedings that turn on AI.

WAICO founding memberFounding member of the World AI Cooperation Organization, signed in Shanghai on 16 July 2026; membership confirmed in national records, though no signatory is named in them.
Explore the map Analyze the case tracker
18instruments mapped
5binding (general law)
5soft-law / guidance
2draft / pipeline
6regional / international
01The map

An enforceability spectrum

Eighteen instruments, stacked by force. Everything above the binding line is general law never written for AI; everything written for AI sits below it. Malaysia is not an OECD or G20 member, so those AI principles appear here as reference points, not commitments. Each entry links to its source.

All Binding Soft law Draft / pipeline Regional
All types AI-specific Data protection Digital and telecom Copyright
Binding lawgeneral law · enforceable
Horizontal · Data

PDPA 2010

Personal Data Protection Act, as amended by Act A1734 (2024)
Parliament / Personal Data Protection Department · In force (2024 amendments phased in from 2025)
Governs personal data, including the data that trains and runs AI systems. The 2024 amendments add breach notification, a data-protection-officer duty, processor obligations, portability and tighter cross-border rules.
Data protectionVia data
Binding Source ↗
Binding and enforceable, but general. Malaysia has no AI-specific binding rule; these laws reach AI only through their general terms.
Horizontal · Communications & content

CMA 1998

Communications and Multimedia Act, as amended (2024)
Parliament / MCMC · In force
Regulates communications and online content. Section 233 is the baseline charge against AI-generated harmful content and deepfakes; the 2024 amendments expanded MCMC removal and enforcement powers.
Digital and telecomGeneral catch
BindingSource ↗
Horizontal · Online harms

Online Safety Act 2024

Platform duties for harmful content
Parliament / MCMC · In force 1 Jan 2026
Puts safety duties on platforms and messaging services for "harmful content" (scams, CSAM, harassment). Broad enough to reach deepfakes, though it does not criminalise their creation.
Digital and telecomGeneral catch
BindingSource ↗
Horizontal · Intellectual property

Copyright Act 1987

Authorship & AI-generated works
Parliament / MyIPO · In force
Requires a human author and "sufficient effort" that is "original in character." With no computer-generated-works provision, purely AI-generated output likely gets no protection.
CopyrightGeneral catch
BindingSource ↗
Sectoral · Finance

BNM RMiT

Risk Management in Technology policy document
Bank Negara Malaysia · In force (binding on financial institutions)
Mandatory technology-risk governance for licensed financial institutions. It captures AI/ML systems indirectly, through model-risk and third-party controls, and is not AI-specific.
Digital and telecomGeneral catch
Binding (sector)bnm.gov.my · RMiT policy document
Soft law & guidanceAI-specific · voluntary
AI-specific · Guidelines

AIGE

National Guidelines on AI Governance & Ethics
MOSTI (MASTIC) · Launched Sep 2024
Seven voluntary principles (fairness, safety, privacy, inclusiveness, transparency, accountability, human benefit) for users, policymakers and developers. No penalties; it signals future mandatory measures for high-risk sectors.
Digital and telecomGeneral catch
Soft lawSource ↗
Strategy

AI-RMAP 2021-2025

Malaysia National AI Roadmap
MOSTI · Adopted 2021
The five-year strategy to build the AI ecosystem, with priority-sector use cases and a top-20 readiness target. Strategy, not obligation; succeeded by the National AI Action Plan 2026-2030.
AI-specificAI-native
Soft lawSource ↗
Sectoral · Finance

BNM AI discussion paper

AI in the Financial Sector (consultation)
Bank Negara Malaysia · Aug 2025
BNM's proposed approach: responsible-AI principles across the AI lifecycle, with flags on model bias, data leakage and third-party overreliance. Consultation closed Oct 2025; a binding policy document is expected to follow.
AI-specificAI-native
ConsultationReporting ↗
National policy

MyDIGITAL

Malaysia Digital Economy Blueprint
Economic Planning Unit · Launched 2021
The 2021 digital-economy blueprint, and the policy umbrella over AI-RMAP, AIGE and the National AI Office. It called for a responsible-AI framework and is carried forward by MD2030.
Digital and telecomGeneral catch
Soft lawSource ↗
National policy

MD2030

Malaysia Digital 2030 Action Plan
Ministry of Digital · Launched 29 Jun 2026
The 2026-2030 action plan, launched under the banner of an AI Nation by 2030. Seven pillars, targets like a 30% digital-economy share of GDP, and the umbrella for the coming National AI Action Plan. Direction, not obligation.
Digital and telecomGeneral catch
Soft lawSource ↗
Draft & pipelinenot yet in force
AI-specific · Bill

Proposed AI Governance Bill

Comprehensive AI legal framework
Ministry of Digital / NAIO · Public consultation 10-31 Jul 2026
Now in pre-drafting public consultation through MPC's Unified Public Consultation portal. The proposal sets out central institutional oversight, principle-based national requirements and a risk-based regulatory framework, with roles for AI developers and deployers, incident reporting and testing sandboxes. It would be the first instrument to bind operators on AI. Not yet law.
AI-specificAI-native
ConsultationSource ↗
Strategy

National AI Action Plan 2026-2030

Successor to AI-RMAP, under MD2030
National AI Office · In development
The AI-specific plan in development under MD2030, succeeding the roadmap. It may seed rules that define high-risk categories and require impact assessments.
AI-specificAI-native
DraftIn development: no public text yet
Regional & internationalvoluntary
ASEAN

ASEAN Guide on AI Governance

Regional responsible-AI principles
ASEAN · Endorsed 2024 (GenAI expansion)
Voluntary, risk-based principles, expanded in 2024 for generative AI. As ASEAN Chair in 2025, Malaysia championed an ASEAN AI Safety Network. Implementation sits with member states.
VoluntarySource ↗
UNESCO

UNESCO Recommendation on AI Ethics

First global AI-ethics standard (194 states)
UNESCO · Adopted 2021
The first global standard on AI ethics. Malaysia adopted it, and the AIGE principles draw partly from it.
VoluntarySource ↗
UNESCO

UNESCO AI Readiness Assessment (RAM)

Malaysia readiness diagnostic
UNESCO · Completed
A diagnostic scoring Malaysia's legal, social, economic and technical readiness for ethical AI. Voluntary, but a structured baseline for reform.
AssessmentSource ↗
United Nations

Global Digital Compact

UN digital & AI commitments
United Nations · Adopted Sep 2024
Adopted by consensus with the Pact for the Future; Malaysia did not dissociate. Shared commitments on digital and AI governance, including an international scientific panel on AI.
VoluntarySource ↗
BRICS

BRICS partner country

Partner status in the BRICS grouping
BRICS · Partner since 1 Jan 2025
Malaysia became a BRICS partner country on 1 January 2025. The July 2025 BRICS leaders' statement on AI governance was adopted by full members, so it does not bind Malaysia; partner status is cooperation, not commitment.
PartnerSource ↗
APEC

APEC AI Initiative (2026-2030)

Regional AI cooperation agenda
APEC · Endorsed Nov 2025
Endorsed by consensus of all 21 APEC economies in the Gyeongju Declaration. A cooperation agenda for AI adoption and governance across the region.
VoluntarySource ↗
02Second reading

Making sense of Malaysia's AI governance model

The map ranks instruments by force. This view adds a second question: does an instrument set out principles or prescriptions? One corner stays empty. Tap any marker.

Prescriptive Principles Nonbinding Binding
No AI-specific instrument is binding yet. The draft AI Governance Bill is the first pointed here.
Binding and enforceable
Binding, no direct sanction
Soft law / guidance
Regional / international
Draft / pipeline

Tap a marker

Eighteen instruments, two readings

The binding column is all general law, written for data, content and copyright rather than for AI. Everything AI-specific sits on the nonbinding side. Dashed markers are drafts; the AI Governance Bill is the first pointed at binding.

All eighteen instruments
Compare this model with
03Case compendium

Malaysian legal proceedings that turn on AI

A running record of Malaysian proceedings where AI is part of the facts: deepfake fraud, face-swap imagery, voice-clone scams, and the regulator's move against X/xAI over Grok. None has reached judgment yet.

The pattern: every action here runs on general law. The Penal Code's obscenity and modesty provisions assume real images; synthetic face-swap content falls outside them.
5proceedings tracked
1regulatory action
4investigation
03The record

Cases and proceedings

Tap a case for the facts, the legal basis, and where it stands. These are reported proceedings from public sources, not judgments.

All Regulatory action Investigation

What the record shows

The charges rest on the Communications and Multimedia Act (s.233), the Penal Code, the Sexual Offences Against Children Act and the Online Safety Act. A National AI Governance Bill is in draft but not yet law.

How this is compiled

Compiled June 2026 from regulator statements and credible reporting, with status noted per case. A record of reported proceedings, not legal advice.

Malaysia · AI-IP Index

How Malaysia aligns AI and intellectual property

Malaysian doctrine asks for human time, labour and skill, and MyIPO treats AI output as an infringement risk rather than a new protected class. Its one concrete institutional move is a filing declaration: the copyright form makes applicants attest the work used no AI.

Accommodation 0.67 · Institution 0.33. Cautious on what it will protect, unusually concrete on disclosure. Its copyright form makes applicants attest that no AI was used.
The framework

What the index measures

The AI-IP Index reads a country on two questions that usually get folded together. Accommodation asks how far the law will go to protect intellectual property that a machine helped produce. Institution asks how much administrative machinery sits behind that law: its guidance, its international submissions, its disclosure duties.

A country can be generous on paper and have built almost nothing, or cautious and highly organised, so the two are scored apart and reported as a pair. Each rests on three questions, scored 0, 0.5 or 1.

Accommodation

How far the law will protect intellectual property that a machine helped make.

  • Q1. Patentability of AI-assisted inventionsWhether an invention developed with AI help, filed with a human named as inventor, can be granted. It decides whether AI-assisted research can be protected at all.
  • Q2. Copyright in AI-generated outputWhether output made with AI attracts copyright when a person directed the work. It sets who, if anyone, owns AI-assisted creative work.
  • Q3. Training and text-and-data-miningWhether copyrighted works can be used to train a model without the owner's permission. This is the main fault line between model builders and rights holders.
Institution

How much administrative machinery sits behind that law.

  • Q4. WIPO Conversation participationWhether the IP office has engaged the WIPO Conversation on IP and Frontier Technologies with a substantive submission. It shows the office is working the question at the international level.
  • Q5. National IP office AI guidanceWhether the office has published dedicated guidance on examining AI-related filings. It tells applicants where they stand before they file.
  • Q6. Disclosure or transparency dutyWhether a filing has to declare that AI was used. It is the office's main lever for provenance.

The scale runs the same way on both axes: 0 is the open or developed end, 1 is the restrictive or absent one, and 0.5 sits between for anything conditional or untested. Read as a pair, the two scores show whether AI-assisted work can be protected here, and whether the office has said so in writing.

Within each axis the three questions carry equal weight. That is a deliberate choice, not an oversight. An AI developer might reasonably value freedom to train above patent inventorship, but weighting is where indices lose their credibility, so the score stays a flat mean and the choice is stated in the open. Each cell also cites a statute section, a case or an office page, so any single score can be challenged without disputing the rest.

Two positions are worth naming. A country can be open on the law but thin on machinery, an open-but-undeveloped stance that bets on ambiguity. Or it can be restrictive on rights yet run an active office, a restrictive-but-developed stance that reflects a settled policy choice rather than a gap. The pair of scores tells those two apart where a single ranking would blur them.

Calibration

Testing the scale against known ground

A rubric is only as good as the results it produces on cases where the answer is already known. These three jurisdictions sit outside this series and are scored with the same six questions, as a check. Their law is the best documented anywhere, so if the scale puts them where the law actually sits, the scale is doing its job. They are reference points, not editions.

United StatesAccommodation 0.33 · Institution 0.17
Q10Q20.5Q30.5Q40Q50Q60.5

Firm judicial settlement at both poles and the weakest statutory position on training. The courts have closed the door on AI inventors and AI authors, while everything on training rides on unresolved fair-use litigation. There is no per se duty to declare AI use in a filing, only a candour duty that bites where the use is material.

Thaler v. Vidal, 43 F.4th 1207 (Fed. Cir. 2022); Thaler v. Perlmutter (D.C. Cir. 2025), cert. denied 2 Mar 2026; Bartz v. Anthropic (N.D. Cal. 2025); USPTO revised inventorship guidance, 90 Fed. Reg. 54636 (28 Nov 2025); 89 Fed. Reg. 58128 (17 Jul 2024); 89 Fed. Reg. 25609 (11 Apr 2024).

EuropeAccommodation 0.17 · Institution 0
Q10Q20.5Q30Q40Q50Q60

The most permissive statutory position on training and the strongest transparency duty in force, sitting over an authorship question no court has answered. Read the label carefully: training and transparency run through EU law, but patents run through the EPO under the European Patent Convention, which is not an EU institution and covers 39 states.

Directive (EU) 2019/790, arts. 3 and 4; Regulation (EU) 2024/1689, art. 53(1)(c) and (d); EPO J 8/20 (2021); EPO Guidelines G-II 3.3.1 (2026 edition); Infopaq C-5/08; Painer C-145/10.

United KingdomAccommodation 0.33 · Institution 0.67
Q10Q20.5Q30.5Q40.5Q50.5Q61

Liberal on patents since the Supreme Court abandoned the Aerotel test in February 2026, conservative on copyright, and currently thin on AI-specific machinery after the dedicated AI examination guidance was withdrawn. Section 9(3) nominally protects a work with no human author for 50 years, the widest AI-output right on paper, but no court has ever applied it to generative AI.

CDPA 1988 ss. 9(3), 12(7), 29A, 178; Thaler v Comptroller-General [2023] UKSC 49; Comptroller-General v Emotional Perception AI [2026] UKSC 3; UKIPO practice notice, 14 Jul 2026; Data (Use and Access) Act 2025 ss. 135 to 137.

The check earned its keep twice. The untested rule held: section 9(3) of the UK Copyright Act reads like the widest AI-output right anywhere, yet because no court has applied it to generative AI it scores as untested rather than open, which is the correct answer and the one a headline reading would miss. The check also exposed a limit worth stating. The Institution axis measures AI-specific machinery, not general office capacity, so a long-established office can score poorly when it has withdrawn its AI guidance and imposes no disclosure duty. Read that axis as what an office has built for AI, nothing wider.

Scorecard

The evidence, question by question

Each row below carries the test we applied and the finding behind the score, with a source. The rationale, not the number, is the point.

Direction of travelTightening. MyIPO's 2026 Copyright Act consultation proposes transparency and remuneration for AI training use, strengthening rights holders on the input side. This is recorded apart from the scores: a pending change is signal, not yet the rule.

Scores verified 16 July 2026, against AIP Index codebook v1.0. A score is only true as of its date.

0 · open or developed0.5 · conditional or emerging1 · restrictive or absent

Accommodation: what the law permits

Mean 0.67
0.5
Q1. Patentability of AI-assisted inventions

What we look forA granted patent or a clearly workable examination route, not merely a silent statute.

The findingAI inventions with a human inventor are examined under the general computer-program practice, patentable where the claim carries technical character. Workable but untested in a decision.

Patents Act; MyIPO practice
0.5
Q2. Copyright in AI-generated output

What we look forProtection applied where human choices shape the work, and refusal of purely machine output.

The findingSection 7(3)'s human sufficient-effort test leaves AI-assisted output to a case-by-case showing, with no AI-specific rule and no case law.

Copyright Act s. 7(3)
1
Q3. Training and text-and-data-mining

What we look forA statutory or judicial mining lane. Silence scores against the miner, since the reserved-rights default governs.

The findingThere is no mining exception, and the copyright reform points to remuneration for rights holders. Silent copyright means the reserved default governs training.

Copyright Act; reform consultation

Institution: how developed the machinery is

Mean 0.33
0.5
Q4. WIPO Conversation participation

What we look forA traceable, substantive submission on the record, not bare membership.

The findingMyIPO participates in WIPO and ran a national IP-and-AI dialogue, but filed no traceable submission to the Conversation.

WIPO submissions archive
0.5
Q5. National IP office AI guidance

What we look forA standalone AI examination text, not AI handled quietly under general practice.

The findingMyIPO has published no dedicated AI examination guidance. AI inventions are handled under the general computer-program provisions, and its recent AI work is operational rather than doctrinal.

MyIPO examination manual
0
Q6. Disclosure or transparency duty

What we look forA mandatory declaration inside the filing, not a proposal or an informal request.

The findingMyIPO's copyright notification form carries a mandatory declaration, in its Section G, that the work was created without the assistance of AI. A binding AI-use attestation inside the filing.

MyIPO Form CR-1, Section G

Conclusions

Can AI be named as inventor?
No
Statutory opt-out from training?
None
Volume of disputes
None reported

Instruments where AI meets IP

Copyright

Copyright Act 1987, ss. 3 and 7(3)

Human authorship by construction
Parliament / MyIPO · In force
Silent on AI, but the author is the "creator of the work" and originality demands "sufficient effort," read as human time, labour and skill. Malaysia has no computer-generated-works provision like the UK's CDPA section 9(3), so purely AI-generated output has no route to protection.
Patents

Patents Act 1983 and Regulations, reg. 6

The inventor declaration barrier
Parliament / MyIPO · In force
Silent on AI. The signed inventor declaration is read as something a machine cannot execute, so AI inventorship would fail on filing. The point is untested: the DABUS project never filed in Malaysia.
Filing practice

MyIPO Copyright Form CR-1

A no-AI declaration on the form
MyIPO · December 2025 revision
The copyright notification form carries a mandatory declaration, in its Section G, that the work was created without the assistance of AI. Notification is voluntary, but for those who use it the form screens AI works out at the point of filing. The clearest operational signal of Malaysia's posture.
AI statute

Proposed AI Governance Bill

The IP promise that is not yet text
Ministry of Digital / NAIO · Consultation 10-31 Jul 2026
Political statements, including the Prime Minister's February 2026 remarks, put intellectual property at the Bill's core, and reporting said it would treat training data and AI output as protected IP. The consultation paper itself is principle-based and contains no IP provisions, so the claim remains announced intent.
ConsultationAnalysis ↗
Copyright reform

MyIPO Copyright Act amendment consultation

Input-side protection for rights holders
MyIPO · Consultation reported Jul 2026
Proposes a framework for AI's use of copyrighted works: transparency about training uses, fairness, and remuneration for rights holders. A reform that protects humans from AI, rather than protecting AI output.
ConsultationReporting ↗

The case record

No reported decision. No Malaysian court has ruled on AI and IP, and the DABUS AI-inventorship project never filed here (Singapore is its only Southeast Asian filing). The nearest authority is YKL Engineering (2022), not an AI case, whose human reading of "sufficient effort" is the anchor practitioners cite for why AI output fails originality. The closest thing to an office decision is MyIPO's February 2024 warning that AI-generated content resembling registered works is an infringement risk.

Method. Six questions, three per axis, scored 0, 0.5 or 1 against AIP Index codebook v1.0. The three questions in each axis are weighted equally by choice, and the two axes are reported as a pair, never blended into one number. Every score cites a statute, case or office page, carries a verified date, and records its direction of travel apart from the level. Positions are editorial judgements read from primary law and office practice, not official scores. WIPO's public catalogue of IP-office AI initiatives does not score jurisdictions on this basis, so the readings here come straight from the source law. Not legal advice.

04About

Why this exists

Malaysia's approach to AI is built almost entirely on soft law. Guidelines and roadmaps set the direction, but none of them binds an operator. What does bind comes from general law written for other purposes. Reading those two layers against each other is the whole exercise.

The site does two things: it maps that structure as an enforceability spectrum, sourced instrument by instrument, and it tracks the proceedings where AI is part of the facts. There is no observatory yet because an observatory needs a binding AI-specific duty to watch, and Malaysia has none. When the AI Governance Bill becomes law, that section opens.

What stands out is the gap between an active soft-law agenda and the absence of any binding AI rule. The National AI Office, set up in December 2024, is drafting the framework meant to close it.

Behind this country report

Muhammad Deckri AlgamarIP & digital law · LL.M. (IE-WIPO), AIGP
Prof. Abu Bakar MunirCyber law & data protection · Advisor on Malaysia's PDPA 2010, DPEX Chairman, APPDI Co-founder

Contribute

Know of a Malaysian proceeding where AI is part of the facts? Send a source link; it will be reviewed before publishing.

Submit a case
05Outlook

What comes next

Malaysia is mid-transition. The proposed AI Governance Bill entered public consultation on 10 July 2026 through MPC's Unified Public Consultation portal, closing 31 July, with a National AI Action Plan to follow. If enacted, the Bill would be the first instrument to bind operators on AI, and the first marker to cross from the soft-law side of the map into binding law.

Until then, courts and the regulator absorb AI harms through statutes written for other things. This site keeps the map and the record current, so the crossing is easy to spot.

An independent research and educational project. Information is provided as-is, may be incomplete, and does not constitute legal advice. Case entries record reported proceedings on a stated date, drawn from public sources, not a legal finding of guilt or liability.