{"id":7790,"date":"2026-05-29T09:00:00","date_gmt":"2026-05-29T01:00:00","guid":{"rendered":"https:\/\/drhariz.com\/blog\/?p=7790"},"modified":"2026-05-21T18:02:04","modified_gmt":"2026-05-21T10:02:04","slug":"ai-governance-malaysia","status":"publish","type":"post","link":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/","title":{"rendered":"MY-AI Standards &#038; AI Governance in Malaysia: A Practical Compliance Guide"},"content":{"rendered":"<h2>What is AI governance in Malaysia and why does it matter?<\/h2>\n<p><a href=\"https:\/\/drhariz.com\/blog\/mengapa-kursus-ai-online-dari-upsi-adalah-pilihan-terbaik-untuk-masa-depan-anda\/\">AI<\/a> governance Malaysia is the framework of laws, standards, and internal policies that ensure AI systems are safe, fair, and accountable. It matters because Malaysian organisations now face the MY-AI Standards, the National AI Roadmap, and PDPA 2010 obligations, with regulators expecting documented controls for AI risk, bias, and data protection.<\/p>\n<p>Dr. Muhamad Hariz Muhamad Adnan, an HRD Corp Certified AI Trainer at Universiti Pendidikan Sultan Idris (<a href=\"https:\/\/drhariz.com\/blog\/why-upsi-is-a-good-choice-for-pursuing-a-master-or-phd-in-artificial-intelligence-malaysia\/\">UPSI<\/a>), helps Malaysian agencies and enterprises map their AI use to these frameworks and build practical, auditable controls before deployment.<\/p>\n<h2>What are the MY-AI Standards and who must follow them?<\/h2>\n<p>The MY-AI Standards are Malaysia\u2019s national guidelines for trustworthy AI, covering ethics, risk, data governance, transparency, and accountability. They apply to government agencies, GLCs, and increasingly to private firms that handle citizen data or critical services. Compliance is voluntary today but expected to become mandatory for high-risk AI by 2027.<\/p>\n<h3>The seven MY-AI principles at a glance<\/h3>\n<ol>\n<li>Fairness and non-discrimination<\/li>\n<li>Reliability, safety, and control<\/li>\n<li>Privacy and security<\/li>\n<li>Inclusiveness<\/li>\n<li>Transparency<\/li>\n<li>Accountability<\/li>\n<li>Pursuit of human benefit and happiness<\/li>\n<\/ol>\n<h2>How does AI governance Malaysia interact with PDPA 2010?<\/h2>\n<p>AI governance in Malaysia must align with PDPA 2010 because most AI systems process personal data. Organisations must obtain consent, limit purpose, secure data, and respect data-subject rights when training or running AI. The 2024 PDPA amendments add mandatory breach notification, making AI logging and incident response especially important.<\/p>\n<table>\n<tr>\n<th>Requirement<\/th>\n<th>PDPA 2010<\/th>\n<th>MY-AI Standards<\/th>\n<\/tr>\n<tr>\n<td>Consent for data use<\/td>\n<td>Mandatory<\/td>\n<td>Reinforced<\/td>\n<\/tr>\n<tr>\n<td>Purpose limitation<\/td>\n<td>Mandatory<\/td>\n<td>Reinforced<\/td>\n<\/tr>\n<tr>\n<td>Bias and fairness testing<\/td>\n<td>Not explicit<\/td>\n<td>Required<\/td>\n<\/tr>\n<tr>\n<td>Model documentation<\/td>\n<td>Not explicit<\/td>\n<td>Required<\/td>\n<\/tr>\n<tr>\n<td>Breach notification<\/td>\n<td>Mandatory (2024)<\/td>\n<td>Reinforced<\/td>\n<\/tr>\n<tr>\n<td>Cross-border transfer<\/td>\n<td>Regulated<\/td>\n<td>Regulated<\/td>\n<\/tr>\n<\/table>\n<h2>What does a Malaysian AI governance programme look like in practice?<\/h2>\n<p>A practical AI governance programme in Malaysia has six components: an AI register, a risk-tiering policy, model cards, bias and safety testing, human oversight, and an incident response plan. Organisations should appoint an AI lead, integrate governance into procurement, and review high-risk systems at least quarterly.<\/p>\n<ul>\n<li><strong>AI Register:<\/strong> Catalogue every AI system, owner, purpose, and data source.<\/li>\n<li><strong>Risk Tiering:<\/strong> Classify use cases as low, medium, or high risk.<\/li>\n<li><strong>Model Cards:<\/strong> Document training data, performance, and limitations.<\/li>\n<li><strong>Bias Testing:<\/strong> Evaluate across gender, ethnicity, and age subgroups.<\/li>\n<li><strong>Human Oversight:<\/strong> Define approval thresholds and escalation paths.<\/li>\n<li><strong>Incident Response:<\/strong> Pre-write playbooks for hallucination, bias, or leakage.<\/li>\n<\/ul>\n<h2>Which AI governance roles should a Malaysian organisation create?<\/h2>\n<p>Malaysian organisations should establish three core AI governance roles: an AI Lead or Chief AI Officer, an AI Risk Committee, and embedded AI champions in each business unit. The AI Lead owns policy, the committee approves high-risk uses, and champions ensure day-to-day compliance with MY-AI and PDPA.<\/p>\n<ol>\n<li><strong>AI Lead \/ CAIO:<\/strong> Owns the AI governance programme and reports to executives.<\/li>\n<li><strong>AI Risk Committee:<\/strong> Includes legal, IT security, data protection, and business heads.<\/li>\n<li><strong>AI Champions:<\/strong> Trained staff in each department who run first-line checks.<\/li>\n<li><strong>External Auditor:<\/strong> Independent annual review of high-risk AI.<\/li>\n<\/ol>\n<h2>How can Malaysian organisations train staff on AI governance?<\/h2>\n<p>The fastest path is HRD Corp claimable AI governance training delivered by a certified trainer who understands both global frameworks and Malaysian regulation. Dr. Muhamad Hariz at UPSI runs one and two-day workshops mapping ISO\/IEC 42001, NIST AI RMF, and EU AI Act controls to MY-AI Standards and PDPA for Malaysian teams.<\/p>\n<h3>Recommended training tracks<\/h3>\n<ul>\n<li>Half-day executive briefing for boards and C-suite<\/li>\n<li>One-day workshop for risk, legal, and compliance teams<\/li>\n<li>Two-day deep dive for IT, data, and AI product teams<\/li>\n<li>Quarterly refreshers as standards evolve<\/li>\n<\/ul>\n<h2>What are the penalties for non-compliance in Malaysia?<\/h2>\n<p>Non-compliance with PDPA 2010 in Malaysia can attract fines up to RM1 million and imprisonment under the 2024 amendments. While MY-AI Standards do not yet carry direct fines, regulators such as the Personal Data Protection Department and sectoral bodies including Bank Negara Malaysia can suspend operations or revoke licences for AI-related breaches.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is the MY-AI Standard mandatory in Malaysia?<\/h3>\n<p>The MY-AI Standards are currently voluntary in Malaysia but strongly recommended by MOSTI and MyDIGITAL for government, GLCs, and high-risk private use cases. Industry expects them to become mandatory for high-risk AI by 2027, so leading Malaysian organisations are adopting them now to avoid costly retrofits later.<\/p>\n<h3>Who enforces AI governance in Malaysia?<\/h3>\n<p>AI governance in Malaysia is enforced through a combination of the Personal Data Protection Department, Bank Negara Malaysia, MCMC, and sectoral regulators. MOSTI and MyDIGITAL coordinate the National AI Roadmap, while individual ministries set sector-specific guidance for healthcare, education, finance, and government AI use.<\/p>\n<h3>Is AI governance training HRD Corp claimable?<\/h3>\n<p>Yes, AI governance training in Malaysia is HRD Corp claimable when delivered by a certified trainer under an approved scheme. Dr. Muhamad Hariz at UPSI offers HRD Corp claimable governance workshops covering MY-AI Standards, PDPA, ISO 42001, and NIST AI RMF for Malaysian organisations of all sizes.<\/p>\n<h3>Do small SMEs need AI governance?<\/h3>\n<p>Yes, small SMEs in Malaysia need lightweight AI governance, especially when AI handles customer data or financial decisions. A simple register, basic risk tiering, and clear human oversight are usually sufficient. Dr. Muhamad Hariz provides SME-scaled governance templates for Malaysian businesses adopting AI for the first time.<\/p>\n<h3>Where can I get an AI governance assessment in Malaysia?<\/h3>\n<p>You can get an AI governance assessment in Malaysia from UPSI consulting engagements, HRD Corp claimable workshops, or specialised AI advisory firms. Visit <a href=\"https:\/\/drhariz.com\">drhariz.com<\/a> to enquire about a tailored assessment, or <a href=\"https:\/\/drhariz.com\/blog\">read more on the blog<\/a> for governance templates.<\/p>\n<p><em>Dr. Muhamad Hariz Muhamad Adnan is a Senior Lecturer and Acting Deputy Dean at Universiti Pendidikan Sultan Idris (UPSI), HRD Corp Certified AI Trainer, and digital transformation consultant. For AI training or postgraduate supervision enquiries, visit <a href=\"https:\/\/drhariz.com\">drhariz.com<\/a> or <a href=\"https:\/\/drhariz.com\/blog\">read more on his blog<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI governance Malaysia: a practical compliance guide to MY-AI Standards, PDPA, and the National AI Roadmap for 2026. <\/p>\n","protected":false},"author":1,"featured_media":7812,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":4,"footnotes":""},"categories":[53],"tags":[],"class_list":["post-7790","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence-ai"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>AI Governance Malaysia: MY-AI Standards Compliance 2026<\/title>\n<meta name=\"description\" content=\"AI governance Malaysia: how to comply with MY-AI Standards, PDPA, and the National AI Roadmap. Practical guide by Dr. Muhamad Hariz, HRD Corp trainer at UPSI.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Governance Malaysia: MY-AI Standards Compliance 2026\" \/>\n<meta property=\"og:description\" content=\"AI governance Malaysia: how to comply with MY-AI Standards, PDPA, and the National AI Roadmap. Practical guide by Dr. Muhamad Hariz, HRD Corp trainer at UPSI.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/\" \/>\n<meta property=\"og:site_name\" content=\"Dr. Muhamad Hariz Adnan\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-29T01:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"801\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Dr Muhamad Hariz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dr Muhamad Hariz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/\",\"url\":\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/\",\"name\":\"AI Governance Malaysia: MY-AI Standards Compliance 2026\",\"isPartOf\":{\"@id\":\"https:\/\/drhariz.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg\",\"datePublished\":\"2026-05-29T01:00:00+00:00\",\"author\":{\"@id\":\"https:\/\/drhariz.com\/blog\/#\/schema\/person\/681757f6490465d5c106cfee83e9eefc\"},\"description\":\"AI governance Malaysia: how to comply with MY-AI Standards, PDPA, and the National AI Roadmap. Practical guide by Dr. Muhamad Hariz, HRD Corp trainer at UPSI.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/#primaryimage\",\"url\":\"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg\",\"contentUrl\":\"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg\",\"width\":1200,\"height\":801,\"caption\":\"blog.drhariz.com A person in a blue shirt writes with a pen on several sheets of paper spread out on a dark table. The focus is on their hands and the documents, with a blurred background. Dr. Muhamad Hariz Adnan\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/drhariz.com\/blog\/#website\",\"url\":\"https:\/\/drhariz.com\/blog\/\",\"name\":\"Dr. Muhamad Hariz Adnan\",\"description\":\"Certified AI Trainer Malaysia &amp; Digital Transformation Consultant\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/drhariz.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/drhariz.com\/blog\/#\/schema\/person\/681757f6490465d5c106cfee83e9eefc\",\"name\":\"Dr Muhamad Hariz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/drhariz.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6366747cf0faf531a369105da0a985d37e7a4daaca25253e8b592f345eeeb42b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6366747cf0faf531a369105da0a985d37e7a4daaca25253e8b592f345eeeb42b?s=96&d=mm&r=g\",\"caption\":\"Dr Muhamad Hariz\"},\"sameAs\":[\"https:\/\/drhariz.com\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Governance Malaysia: MY-AI Standards Compliance 2026","description":"AI governance Malaysia: how to comply with MY-AI Standards, PDPA, and the National AI Roadmap. Practical guide by Dr. Muhamad Hariz, HRD Corp trainer at UPSI.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/","og_locale":"en_US","og_type":"article","og_title":"AI Governance Malaysia: MY-AI Standards Compliance 2026","og_description":"AI governance Malaysia: how to comply with MY-AI Standards, PDPA, and the National AI Roadmap. Practical guide by Dr. Muhamad Hariz, HRD Corp trainer at UPSI.","og_url":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/","og_site_name":"Dr. Muhamad Hariz Adnan","article_published_time":"2026-05-29T01:00:00+00:00","og_image":[{"width":1200,"height":801,"url":"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg","type":"image\/jpeg"}],"author":"Dr Muhamad Hariz","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Dr Muhamad Hariz","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/","url":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/","name":"AI Governance Malaysia: MY-AI Standards Compliance 2026","isPartOf":{"@id":"https:\/\/drhariz.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/#primaryimage"},"image":{"@id":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/#primaryimage"},"thumbnailUrl":"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg","datePublished":"2026-05-29T01:00:00+00:00","author":{"@id":"https:\/\/drhariz.com\/blog\/#\/schema\/person\/681757f6490465d5c106cfee83e9eefc"},"description":"AI governance Malaysia: how to comply with MY-AI Standards, PDPA, and the National AI Roadmap. Practical guide by Dr. Muhamad Hariz, HRD Corp trainer at UPSI.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/drhariz.com\/blog\/ai-governance-malaysia\/#primaryimage","url":"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg","contentUrl":"https:\/\/drhariz.com\/blog\/wp-content\/uploads\/2026\/05\/art03-ai-governance-malaysia.jpg","width":1200,"height":801,"caption":"blog.drhariz.com A person in a blue shirt writes with a pen on several sheets of paper spread out on a dark table. The focus is on their hands and the documents, with a blurred background. Dr. Muhamad Hariz Adnan"},{"@type":"WebSite","@id":"https:\/\/drhariz.com\/blog\/#website","url":"https:\/\/drhariz.com\/blog\/","name":"Dr. Muhamad Hariz Adnan","description":"Certified AI Trainer Malaysia &amp; Digital Transformation Consultant","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/drhariz.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/drhariz.com\/blog\/#\/schema\/person\/681757f6490465d5c106cfee83e9eefc","name":"Dr Muhamad Hariz","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/drhariz.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6366747cf0faf531a369105da0a985d37e7a4daaca25253e8b592f345eeeb42b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6366747cf0faf531a369105da0a985d37e7a4daaca25253e8b592f345eeeb42b?s=96&d=mm&r=g","caption":"Dr Muhamad Hariz"},"sameAs":["https:\/\/drhariz.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/posts\/7790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/comments?post=7790"}],"version-history":[{"count":1,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/posts\/7790\/revisions"}],"predecessor-version":[{"id":7801,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/posts\/7790\/revisions\/7801"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/media\/7812"}],"wp:attachment":[{"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/media?parent=7790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/categories?post=7790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/drhariz.com\/blog\/wp-json\/wp\/v2\/tags?post=7790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}