World leaders opened the UN General Assembly’s high-level week on Tuesday with artificial intelligence near the top of the agenda. The day before, OpenAI published a policy paper asking the United States to lead the writing of global technical standards for frontier AI. Its chief executive briefs the UN Security Council on Wednesday. None of that is happening in Kuala Lumpur. All of it lands on Malaysian desks anyway, because the AI Governance Bill Malaysia has been drafting since 2024 reaches the same finish line this year.
The two processes are answering different questions. New York is arguing about who sets the rules for the largest models. Putrajaya is deciding what a company that uses AI has to be able to prove. The second one is the part with a deadline attached to your business.
What the AI Governance Bill Malaysia will actually do
The Ministry of Digital, working through the National AI Office, opened a nationwide public consultation on the proposed Bill on 10 July 2026, through the Unified Public Consultation portal. The Ministry’s own press release describes it as “Malaysia’s first horizontal legal framework specifically dedicated to AI governance”.
Four design choices in that release matter more than the rest of it:
- It is risk-based. The framework “recognises that AI threats can emerge at any stage of the system’s lifecycle”, and distributes governance responsibility “based on the roles and level of control of the parties involved”.
- It complements existing law rather than replacing it. The Bill sets common principles across sectors. Digital Minister Gobind Singh Deo told Parliament on 24 June 2026 that it will not directly regulate AI output, and that illegal content stays with the existing acts.
- It expects incident reporting and sandboxes. Pre-emptive measures including incident reporting systems, safeguards and AI sandboxes are “highly encouraged”.
- It is a horizontal framework, not a sectoral one. That is the difference between a rule that lives inside one regulator’s rulebook and a rule that every regulated business eventually has to answer to.
Malaysia is late to this by regional standards but not embarrassingly so. Singapore and Korea both built AI safety institutes early; both are named in OpenAI’s proposal as part of the network the company wants to build standards on. Malaysia’s approach, as described by the US International Trade Administration’s market note, leans towards interoperability and towards reducing compliance cost for small business rather than toward heavy ex-ante licensing.
Three things happened this week
OpenAI asked for US leadership on standards. The paper, titled “Building standards for the next phase of AI”, went up on 21 September. It asks for two things: a mechanism that lets national and international frontier standards work alongside each other, and common measurement and incident-reporting protocols. It also names recursive self-improvement — a system improving the next generation of AI — as something standards must cover, and states plainly that fully autonomous RSI “is not happening today, and we should not pursue it unless and until it can be done safely”.
The argument it makes for standards is the commercially interesting part. OpenAI says international standards “may be as important to pacing the frontier as alignment research itself”, because they create shared definitions of what counts as good evidence. Without them, evaluations and incident definitions differ by country, and cross-border evidence stops being comparable.
“Leading now will determine whether the United States shapes the global AI framework or watches a fragmented, uneven, and conflict-ridden system take hold around it.”
The UN rights chief named red lines. Volker Türk told the Human Rights Council in Geneva that AI that “escapes its testing environment or blackmails developers to prevent itself from being turned off is AI that is too powerful”. He asked for international red lines, independent verification rather than self-reporting, and assessment of AI’s effect on employment — and pointed at the concentration of control, saying “a handful of men have almost unlimited power over AI”.
Altman takes it to the Security Council. France holds the Council presidency this month and convened the session; French Foreign Minister Jean-Noël Barrot chairs it. The briefing is a discussion, not a vote — no draft resolution has been announced. Security Council agreement on AI would need all five permanent members, and the United States has already declined to join the multilateral scientific panel on AI that was approved 117 to 2.

Where Malaysia already stands
There is no dedicated AI law on the statute book yet, and the National AI Office says so in as many words. What exists is a stack of adjacent legislation that already reaches AI use, whether or not it was written for it.
| Instrument | Why it already touches an AI deployment |
|---|---|
| Personal Data Protection Act 2010 (Act 709) | Training data, prompts containing personal data, automated decisions about customers |
| Cyber Security Act 2024 (Act 854) | Incident reporting duties for entities within the Act’s scope |
| Online Safety Act 2025 (Act 866) | Synthetic and harmful content on platforms and services |
| Communications and Multimedia Act 1998 (Act 588) | Content and network regulation |
| Copyright Act 1987 (Act 332) | Ownership and attribution questions around generated material |
Above the legislation sits a strategy layer. The National AI Office now runs under AI Malaysia Berhad, which announced its inaugural board of directors on 11 September 2026. The National AI Action Plan 2026–2030 sets the adoption targets. And the National Guidelines on AI Governance and Ethics, already in force as guidance rather than law, list seven principles: fairness; reliability, safety and control; privacy and security; inclusiveness; transparency; accountability; and the pursuit of human benefit and happiness.
Those seven are the shape of what the Bill is likely to harden. Guidance is voluntary; a horizontal Act is not.

What it means for a Malaysian SME
Two things, and they pull in opposite directions.
The first is cost. A horizontal framework with a risk-based structure is only cheap if you are not in a high-risk tier, and the definition of high-risk is exactly what the consultation has not settled. If your use of AI touches credit decisions, hiring, medical triage or anything that materially determines a person’s outcome, the obligation set being discussed — impact assessment before deployment, incident reporting on a clock, documented safeguards — is real work, not a form.
The second is the opposite. Malaysia’s stated position, as read by the US trade agency’s market note, is to support SME adoption by reducing compliance cost and regulatory uncertainty. That is a policy intention, not a guarantee, but it is the reason to read the Bill before it is passed rather than after.
The practical point: the thing that catches SMEs in every new digital regulation is not the headline rule. It is the record-keeping that proves you complied. If you deploy AI in a process that affects customers or staff, you will eventually be asked for a decision log, a data map and an owner. Starting that now costs almost nothing; reconstructing it later does not.
What to do before the Bill lands
- Write down every AI tool in use, and who owns it. Not the vendor list — the actual inventory. Shadow adoption is the finding that embarrasses companies in an audit.
- Classify each one by the decision it influences. Anything that affects a person’s access to credit, employment, insurance or healthcare should be treated as high-risk until told otherwise.
- Check your existing PDPA housekeeping. If personal data enters a model you did not build, that flow needs a lawful basis and a retention answer today, not after the Act.
- Start a decision log. Which model, which version, what prompt, what output, which human reviewed it. This is the artefact the incident-reporting duty will lean on.
- Read the consultation paper and respond. The Unified Public Consultation portal is where definitions get argued. The definition of high-risk AI in a Malaysian context is still open, and it is the single clause that decides your cost.
- Do not wait for the Act to fix content problems. The Minister has said illegal content stays with the existing acts. Nothing about the Bill delays your obligations under the Online Safety Act.
About BD Media
BD Media is the trade and business journal of Big Domain, edited in Penang. We cover the commercial, compliance and technology decisions Malaysian small and medium businesses have to make, with sourced numbers, named documents and dates you can check.
Sources
- Ministry of Digital, Ministry Of Digital Initiates Engagement On Proposed Artificial Intelligence (AI) Governance Bill, media release, Putrajaya, 10 July 2026 — digital.gov.my. Source for the description of the Bill as Malaysia’s first horizontal AI legal framework, the risk-based approach, the distribution of governance responsibility, incident reporting and AI sandboxes, the Minister’s 24 June 2026 statement in Parliament, and the opening of the public consultation on 10 July 2026.
- AI Malaysia Berhad (National AI Office), AI Governance and Policy FAQ — ai.gov.my/faq/ai-governance-policy. Source for the statement that Malaysia has no dedicated AI law yet, the list of adjacent legislation and its Act numbers, the seven principles of the AI Governance and Ethics guidelines, and the National AI Action Plan 2026–2030.
- AI Malaysia Berhad, homepage and news — ai.gov.my. Source for the announcement of the inaugural board of directors of AI Malaysia Berhad on 11 September 2026 and for the agency’s mandate under the Ministry of Digital.
- OpenAI, Building standards for the next phase of AI, 21 September 2026 — openai.com/index/building-standards-next-phase-ai. Source for the call for US-led frontier standards, the two proposed pillars, the statement on recursive self-improvement, the quoted sentence on leading now, and the reference to the network of national AI safety institutes.
- Reuters, OpenAI calls for US to take lead in global efforts to develop technical standards, by Michelle Nichols, 21 September 2026 — as carried at yahoo.com/news. Source for the Altman briefing of the UN Security Council in person on Wednesday 23 September, the French presidency and chair, the absence of a draft resolution, the US vote against the 40-member scientific panel, and the UN General Assembly high-level week context.
- The Next Web, UN rights chief calls for international red lines on AI, warning of existential risk — thenextweb.com, reporting Volker Türk’s global update to the 63rd session of the Human Rights Council. Source for the quoted thresholds, the call for independent verification, and the observation on concentration of control.
- International Trade Administration, US Department of Commerce, Malaysia AI Governance Framework, market intelligence — trade.gov. Used only for the characterisation of Malaysia’s stated intent to support SME AI adoption by reducing compliance cost and regulatory uncertainty, and the emphasis on interoperability. This is a foreign government’s reading of Malaysia’s position, not a Malaysian government statement.
- Unified Public Consultation portal (Malaysian Productivity Corporation) — upc.mpc.gov.my. The channel named by the Ministry of Digital for public consultation on the proposed Bill.
What could not be checked: the draft Bill’s text has not been published, so the specific statutory provisions circulating in law-firm summaries of the July 2026 consultation paper — deepfake offences, copyright attribution for generated content, restrictions on cross-border transfer of training data, the definition of high-risk systems — could not be verified against the Ministry’s own document and are therefore not stated here as fact. The timetable for tabling in Parliament is likewise not confirmed by the Ministry’s release. Treat any figure on compliance cost for Malaysian SMEs, in this article or elsewhere, as unquantified until the Bill is tabled.







