How Malaysia is building the ‘trust infrastructure’ for AI

Through a blend of ethical grounding and technical enforcement, Malaysia is positioning itself not just as a consumer of AI, but as a regional leader in governing it responsibly.

How Malaysia is building the ‘trust infrastructure’ for AI

PUTRAJAYA: As artificial intelligence (AI) moves from science fiction to a daily tool for millions of Malaysians, the conversation is shifting. It is no longer just about what AI can do, but how to ensure it does so safely.

To achieve this, Malaysia is moving away from “wait-and-see” policies towards a structured, four-layered governance model – ethics, standards, legislation, and adaptive regulation. This strategy is about building a trust infrastructure where innovation can thrive without compromising public safety.

The journey began in 2024 with the AI Governance and Ethics Guidelines. Rather than reinventing the wheel, Malaysia established seven principles, including fairness, reliability, and privacy, aligned with international standards.

These act as a compass for developers, ensuring that as local AI technology grows, it remains interoperable – or compatible – with the rest of the world.

The technical backbone – MY AI standards

In March 2026, the Digital Ministry turned these abstract ethics into technical reality with the launch of the MY-AI Standards initiative.

Think of this as a “one-stop shop” for digital trust. Developed by the National AI Office (NAIO) and CyberSecurity Malaysia, the platform provides businesses – from tech giants to local small and medium enterprises (SMEs) – with access to over 80 internationally recognised standards, including those from the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC).

By embedding these standards into the design phase of AI, the government is moving away from “black box” algorithms towards systems that are transparent, auditable, and reliable.

Speaking at the recent launch of the MY-AI Standards initiative in Cyberjaya, Digital Minister Gobind Singh Deo said AI standards will serve as a common language between the government, industry, investors, and the public – translating digital trust from principles into practical implementation.

A key driver behind this structured approach is the surge in AI-driven crime. Gobind had also raised the alarm over the “industrialised” nature of modern scams.

With RM2.77 billion lost to online fraud in 2025 alone, the ministry is prioritising tools to combat deepfake videos and voice cloning.

To move from defence to offence, the ministry – through CyberSecurity Malaysia and Universiti Kebangsaan Malaysia (UKM) – is finalising an AI-based verification tool.

This “deepfake detector” will allow enforcement agencies to authenticate images and videos in real time, providing a critical shield against digital identity theft and sophisticated financial fraud that mimics prominent figures to lure victims into fake investment schemes.

Moving ahead, every day

The Digital Ministry is not stopping at voluntary guidelines. Work on the AI Governance Bill is in its final stages, with the Bill expected to be tabled in Parliament later this year.

The upcoming law will introduce a risk-based classification system.

Instead of a one-size-fits-all hammer, the law will be surgical – low-risk AI will face minimal hurdles, while high-risk applications, especially those capable of generating synthetic media, will be subject to strict accountability and mandatory incident reporting.

This legislation will be bolstered by the National Digital Trust and Data Security Strategy (2026–2030), which aims to modernise the Computer Crimes Act. The goal is to ensure that “synthetic documents” and AI-enabled impersonation carry clear, enforceable legal penalties.

Looking ahead, Malaysia is eyeing 2030 as the year it becomes an AI Nation.

To get there, the Government is fostering a proactive sandboxing approach. Through the AI Sandbox for Industries, companies can access high-performance computing power to test new applications in a safe environment before they reach the mass market.

By updating legacy laws such as the Evidence Act 1950 and the Contracts Act 1950 to recognise AI-driven transactions, Malaysia is signalling to global investors that its legal system is ready for the AI age.

The message is clear – Malaysia is building an ecosystem that is not only innovation-friendly, but also trusted, predictable, and resilient against evolving digital threats.

The long game

Ultimately, the Digital Ministry is playing a long game. By building this four-layered framework, Malaysia is signalling to global investors and local citizens alike that the ‘Intelligent Age’ does not have to be an era of uncertainty.

This framework provides the legal clarity businesses seek and the protection the rakyat deserves.

Through this blend of ethical grounding and technical enforcement, Malaysia is positioning itself not just as a consumer of AI, but as a regional leader in governing it responsibly.

As Gobind said at the launch of the MY-AI Standards initiative: “We want an AI that is both innovative and trusted. Confidence can only be built through clear standards, measurable implementation, and governance that is transparent and grounded in integrity. This is the core of building national digital trust, ensuring that technological innovation always moves in tandem with safety, ethics, and the interests of the people.”