Policy & Financial Services / AI news for Malaysia
From the archive · Event date 5 August 2025
BNM found AI adoption rising across Malaysia's financial sector
The central bank's survey found that AI use was moving beyond experiments, but its paper was a consultation—not a new rulebook or a promise that every automated decision was safe.

In brief
- BNM's August 2025 discussion paper drew on responses from 120 financial service providers and found that adoption had risen across banks, development financial institutions, insurers and takaful operators.[1]
- In 2024, 71% of banks and development financial institutions and 77% of insurers and takaful operators reported at least one AI application.[1]
- BNM said the existing technology-neutral framework was broadly adequate at that stage, while leaving room for stronger supervisory expectations if AI risks became more material.[1]
BNM paired adoption data with a risk-based policy direction
Bank Negara Malaysia published a 37-page discussion paper on 5 August 2025 to explain how artificial intelligence was being adopted across the financial sector and to gather industry feedback. The paper was explicitly non-binding. It described BNM's proposed posture and questions for consultation rather than announcing a finished AI regulation.[1]
The evidence showed a sector moving quickly. Among banks and development financial institutions, 71% had implemented at least one AI application in 2024, up from 56% a year earlier. Adoption among insurance and takaful operators rose to 77% from 58%. More than 60% of banks and insurers viewed AI as a strategic priority for the following one to three years.[1]
Those numbers did not mean autonomous systems were making every important decision. BNM said most near-term applications augmented rather than replaced people and were concentrated in non-financial-risk work. Customer analytics, internal operations, technology and cyber risk, and fraud and anti-money-laundering work were the most common reported areas.[1]

Adoption was accelerating before autonomy arrived
Financial service providers reported more than eight times as many pilot or exploratory AI applications in 2024 as in the previous year. Limited and full deployments grew by 30%. The largest share of reported projects was customer analytics and marketing at 28%, followed by internal operational improvements at 22%, technology and cyber risk at 10%, and fraud and AML at 8%.[1]
Generative AI was attracting attention, especially for staff chatbots, claims assessment, HR onboarding and internal communication. Yet senior use lagged the organisational enthusiasm: only one in five providers said senior leaders and C-suite executives were actively using internal or public GenAI tools for their own work. Customer-facing GenAI remained limited, and providers had not indicated plans to use it in financial-risk areas at the time of the survey.[1]

BNM's starting point was existing rules, applied to AI
BNM framed its regulatory posture around parity, proportionality and technology neutrality. In plain language, the same risks should receive the same regulatory treatment, scrutiny should match the seriousness and likelihood of harm, and firms should be judged on outcomes rather than being forced to use one technical method. The paper said existing outcome-focused requirements remained broadly adequate at that stage because many AI risks were familiar and most applications were not replacing humans in critical decisions.[1]
That was not permission to deploy first and govern later. Providers were expected to manage models across their full lifecycle, keep controls proportionate to complexity and intended use, handle personal information responsibly, and validate reliability. The paper highlighted accountability, fairness, transparency, explainability, reliability, ethics and security as responsible-AI principles that could be embedded into existing institutional processes.[1]
The practical test was whether AI helped consumers too
BNM proposed prioritising what it called win-win-win uses: applications that benefit consumers, improve business outcomes for providers and support regulatory objectives such as stability, development and inclusion. Fraud and AML detection was one example because better monitoring can reduce losses, lower false positives and strengthen trust. Permission-based personal financial management was another because it could help people budget and save while giving providers more relevant ways to serve them.[1]
The counterweight was equally clear. Hallucinated customer advice, biased outcomes, weak model monitoring, data leakage, deepfake-enabled fraud and opaque third-party systems could all erode trust. BNM said supervisory focus could escalate if AI moved into critical functions, replaced more human decision-making or created risks that existing rules did not adequately address. That makes the paper a map of regulatory direction, not a permanent ceiling on future requirements.[1]
Why Malaysia should care
For Malaysians, the paper showed where AI was already entering banking and insurance, and why accountability, fairness, data controls and human oversight matter when technology touches money, identity or access to financial services.
Banking and insurance customers
More AI may sit behind service, fraud checks and personalisation, but the provider remains accountable for outcomes.[1]
Practical move: Ask for a human review path when an automated outcome affects access, pricing, claims or identity verification.
Financial institutions
Existing obligations still apply even when a model or external vendor supplies the decision support.[1]
Practical move: Keep an inventory of models, owners, data, validation evidence, monitoring thresholds and escalation routes before expanding deployment.
Technology vendors
A black-box product is harder for a regulated customer to govern across the model lifecycle.[1]
Practical move: Provide traceable data controls, testing evidence, explainability boundaries and incident support as part of the product contract.
What Malaysians can do now
- Separate experiments, decision-support tools and autonomous decisions in the organisation's AI inventory.
- Define who can stop a model and how a customer can obtain meaningful human review.
- Measure consumer outcomes and model failures, not only productivity or adoption counts.
What we still do not know
The discussion paper left the final supervisory shape open.
- Which consultation responses would become formal guidance, supervisory expectations or later policy requirements.
- How adoption and risk controls differed by institution size and by individual high-impact use case.
- Whether reported pilots later moved into production and produced measurable customer benefits.
Sources
- 1.Artificial Intelligence in the Malaysian Financial Sector Bank Negara Malaysia, 5 August 2025


