Malaysia used its own stage to make the announcement. At the Malaysian Communications and Multimedia Commission's International Regulatory Conference (IRC) 2026, running July 21-22 at the Shangri-La Kuala Lumpur under the theme "Shaping the Next Digital Era: Regulation, Resilience and Trust," Communications Minister Fahmi Fadzil confirmed the government is drafting legislation to regulate artificial intelligence, framing the conference as a platform to "exchange views, discuss future directions and explore the best ways to work together in addressing online harms" with regulators from other countries (MCMC IRC 2026; Free Malaysia Today).
The legislation itself is already in motion. On July 10, 2026, the National AI Office (NAIO) under the Ministry of Digital published a Public Consultation Paper on Malaysia's proposed AI Governance Bill — the country's first horizontal legal framework dedicated specifically to AI, rather than a patchwork of sector-by-sector guidance. Written submissions close July 31, 2026, via the government's Unified Public Consultation portal (upc.mpc.gov.my).
What the Bill Actually Does
The draft is notable for what it doesn't do: it doesn't ban categories of AI outright or impose a single compliance regime on every system. Instead, per Baker McKenzie's analysis of the consultation paper, it sorts AI systems into three risk tiers — Tier 1 "unacceptable" systems intentionally designed to cause harm (prohibited outright), Tier 2 "high-risk" systems with foreseeable harm potential (subject to assessment and monitoring), and Tier 3 low-risk systems (baseline compliance only) (Baker McKenzie). A new Central AI Authority would oversee enforcement while coordinating with existing sectoral regulators like MCMC and Bank Negara, and a regulatory sandbox would let developers test applications in supervised production settings with reduced immediate compliance burden. Personal use and national security applications are exempted from scope.
Steelmanning the Urgency
The case for moving now is stronger than reflexive skepticism of new tech law usually allows. Fahmi disclosed at a separate briefing that MCMC has logged 345,712 pieces of harmful content since January 1, 2026 — 91% of it gambling and scam-related — consuming an estimated 19.7 years of cumulative man-hours to process, because each case takes 30-45 minutes of manual review (Malay Mail). That is not an abstract policy problem; it's a regulator being outpaced by the volume of content that AI tools now make cheap to generate. MCMC's own recent intervention against Grok after users exploited it to produce inappropriate images — cited by Fahmi at IRC 2026 — illustrates the gap between platform self-policing and actual harm. A horizontal AI law that forces incident reporting and safeguards before deployment, rather than after MCMC discovers a problem manually, is a defensible response to that gap, and cross-border cooperation genuinely matters when the platforms generating the harm sit outside Malaysian jurisdiction.
Where the Design Still Needs Work
Even granting the urgency, the Bill's execution carries real risk of overreach if implemented carelessly. The Tier 2 "foreseeable harm" standard is doing enormous work without a settled definition — plenty of ordinary automation (fraud-scoring, content recommendation, HR screening tools) could plausibly be read into that category by an under-resourced Central AI Authority looking to justify its mandate, dragging routine SaaS deployments into assessment and monitoring obligations designed for genuinely high-stakes systems. A three-week consultation window, running through the year-end reporting crunch for many businesses, is thin for SMEs and civil society groups to meaningfully weigh in on a framework this consequential — the NAIO should extend the July 31 deadline or commit to a formal second-reading comment period once a bill text exists.
The overlap between the new Central AI Authority and sector regulators like MCMC and Bank Negara Malaysia also needs clearer delineation before enactment, not after. Malaysia's Online Safety Act — which Fahmi credited to lessons from past IRC-style international engagement — already governs platform content obligations; without an explicit carve-out, AI systems used for content moderation itself could face dual compliance regimes from two different authorities simultaneously.
The Right Instinct, If Held To It
What distinguishes Malaysia's approach from heavier-handed models is the sandbox and tiering structure itself: it presumes most AI activity is low-risk and lets it proceed with baseline obligations, reserving intensive scrutiny for systems that can actually cause foreseeable harm. That is the correct starting posture for a country positioning itself, per its "AI Nation 2030" ambitions under MyDigital's Phase 3 (2026-2030), as a regional data-centre and AI investment hub rather than a cautionary tale. The test now is whether the final bill text preserves that proportionality once ministries, industry lobbies, and an under-pressure MCMC all get a say in drafting — or whether the 19.7-years-of-backlog urgency ends up justifying broader authority than the harm actually requires.