Malaysia plans to enact a national artificial intelligence (AI) law to govern the AI ecosystem within the country and to address risks posed by the technology, according to the public consultation document released by the National AI Office (NAIO) recently. The proposed AI Governance Act will apply to all entities involved in the AI lifecycle including AI developers and deployers as long as the technology is designed, developed or used in Malaysia regardless of where its underlying hardware system is physically hosted.
Exemptions are allowed only in two situations, namely personal use and in matters of national security.
Intended to create a safe, responsible and innovation-led use of AI, the proposed law is underpinned by five guilding principles, namely, protecting human dignity and rights, transparency and explainability, accountability, safety and security, and responsible data governance.
The bill for the proposed Act outlines the national AI Governance Principles to guide the responsible development, deployment and use of AI. Guidelines, standards and other instruments would follow to ensure smooth and effective implementation.
The risk-based approach categorises risk into three levels – unacceptable, high and low – each with obligations commensurate with its risk. For example, a high risk system will have stricter governance requirements compared to a lower-risk application. Examples of high risk would include negative impacts that cause death, bodily injury, deprivation of fundamental liberty and the contravention of any written law.
System failures, abuses, near misses and unexpected effects would fall under AI incidents which have to be reported. The report should include details like the nature of the incident, its foreseeable harm, the containment measures taken, the root cause (where applicable), and the remediation actions implemented.
The Bill proposes a central AI authority to oversee the national principles and AI safety. This authority will be vested with powers to investigate and enforce any breaches, as well as conducting technical fact-finding for AI incidents.
The Bill is still subject to amendments and revisions including taking into account views from the public.
In June, Digital Minister Gobind Singh Deo reportedly said the legislation is needed to manage the risk posed by AI such as deepfakes, synthetic content and identity manipulation. The government will adopt a two-pronged approach – firstly, apply existing laws to prosecute wrong-doers and secondly, enact the AI legislation.
