AI Governance / AI news for Malaysia
From the archive · Event date 27 February 2025
Malaysia gave public agencies an AI rulebook in 2025. The self-assessment was the important part
The 158-page reference was designed to move government AI projects beyond enthusiasm. It asked agencies to identify affected people, assign responsibility, assess risk and decide whether an AI use case should proceed at all.

In brief
- The National Digital Department launched Malaysia's Public Sector AI Adaptation Guidelines on 27 February 2025 after developing them with MDEC as a specialised reference for government agencies.[1][2]
- The guidelines contain six chapters and three appendices covering AI basics, ethical principles, roles and responsibilities, risk management, adoption methods and a self-assessment template.[1]
- Bernama reported that the document runs to 158 pages and that accountability, transparency and fairness were presented as core principles, with the minister warning against unchecked black-box decisions.[3]
JDN turned responsible public-sector AI into a structured agency process
Malaysia's National Digital Department launched a dedicated rulebook for public-sector AI on 27 February 2025. Developed with the Malaysia Digital Economy Corporation, the guidelines were aimed at agencies, department heads, chief digital officers, ICT managers and civil servants deciding how AI should enter government work.[1]
The document did more than list ethical aspirations. Its six chapters and three appendices covered who is responsible, how risk should be managed, how an agency should approach adoption and how it can assess the likely scope and impact of a proposed use case. Bernama described the complete reference as 158 pages.[1][3]
For the public, the self-assessment is the most consequential part. It creates a point before procurement or deployment where an agency should be able to explain the problem, the people affected, the data involved, the possible harm, the human decision owner and the evidence that AI is actually a better option.[1][3]

The guidelines were built as an agency reference, not a general AI brochure
The launch audience included state secretaries, department heads, chief digital officers, public-sector ICT managers and industry partners. That matters because these are the people who translate broad policy into a system specification, procurement decision, operating procedure and frontline service.[1]
The programme paired the document launch with public-sector use cases and a forum on AI ethics and governance. The structure recognised that responsible adoption needs both practical examples and a way to challenge them. A useful system is not responsible merely because it automates an existing task faster.[1][2]

Roles and responsibilities stop an agency from blaming the algorithm
An AI model cannot be the accountable owner of a public decision. An agency needs named people who approve the use case, control access, verify data quality, monitor performance, respond to incidents and decide when the system must be changed or stopped. Vendors may support those tasks, but they cannot absorb the public body's duty to citizens.[1][3]
That is why accountability, transparency and fairness matter together. Accountability names who must answer. Transparency gives reviewers enough information to understand the system and its limits. Fairness requires the agency to examine whether errors or exclusions fall unevenly on particular groups.[3]
The same model can be low-risk in one workflow and unacceptable in another
Using AI to organise internal meeting notes is not equivalent to using it to rank benefit applicants, flag a person for investigation or recommend a medical or licensing outcome. The affected rights, data sensitivity, reversibility and cost of an error are different. Risk assessment has to begin with the decision and the people exposed to it, not with the brand name of the tool.[1]
A credible assessment should ask how often the system is wrong, whether those errors can be detected, what happens before human review and how someone can challenge an outcome. It should also consider security, data leakage, model drift, vendor dependence and whether staff will defer to the system simply because it appears technical.[1][3]
A completed template is useful only if it changes the decision
The self-assessment template gives agencies a repeatable starting point, but a checklist can become ceremonial if every project passes. The record should show what evidence was considered, which risks were reduced, which controls remain, who approved the residual risk and why a non-AI option was rejected.[1]
For higher-impact systems, agencies should be able to publish a non-sensitive summary before or soon after deployment: the purpose, data categories, human review, performance measures, affected groups, complaint route and stop conditions. That public trail would turn the 2025 guidance into something Malaysians can verify rather than only trust.[1][3]
Why Malaysia should care
Public-sector AI can affect access to services, inspections, benefits, enforcement and the information used by officials. Malaysians therefore need agencies to show who owns an AI-assisted decision, which risks were assessed, how people can challenge an error and whether the system improves a real public outcome.
Public agencies
The guidance provides a common starting point for deciding whether and how an AI use case should proceed.[1]
Practical move: Keep the self-assessment, evidence, approval and monitoring plan as a living record rather than a one-time form.
Civil servants and system owners
Human responsibility remains even when a vendor supplies the model or an automated recommendation.[1][3]
Practical move: Define who checks outputs, handles incidents, corrects records and has authority to suspend the system.
Malaysians using public services
The guidelines create a basis for asking how an AI-assisted decision was assessed and who can correct an error.[3]
Practical move: Look for a plain-language purpose, human review, complaint route, outcome measure and stop condition for higher-impact uses.
What Malaysians can do now
- Ask what public problem an agency is solving before accepting AI as the chosen method.
- For higher-impact systems, look for a named human owner, risk assessment, complaint route and measurable outcome.
- Treat the self-assessment as a decision record that can stop or reshape a project, not as a form that automatically approves it.
What we still do not know
The guidelines define a process, but public adoption evidence remains the next test.
- How many agencies have completed the self-assessment and how many proposed uses were changed, deferred or stopped.
- Which public-sector AI systems are covered by published impact, performance or incident summaries.
- How agencies will audit vendor models, handle appeals and report material failures across departments.
Sources
- 1.Launch Ceremony of the Public Sector Artificial Intelligence Adaptation Guidelines Ministry of Digital Malaysia, 27 February 2025
- 2.27 February 2025: Launch of the Public Sector AI Adaptation Guidelines National Digital Department, 6 March 2025
- 3.Digital Ministry launches Public Sector AI Adaptation Guidelines Bernama, 27 February 2025


