AI Policy / AI news for Malaysia
From the archive · Event date 8 August 2025
Malaysia's AI Action Plan 2030 took shape in four roundtables. Here is what each one proposed
The sessions produced a clearer policy blueprint for safety, regulation, talent and adoption. They did not, by themselves, prove that the proposed controls or programmes were already operating.

In brief
- The National AI Office said four roundtables had helped refine the National AI Action Plan 2030 for 2026 to 2030, covering safety and security, policy and regulation, talent, and industry engagement.[1][3]
- The proposals ranged from tiered AI-risk classification and incident response to sector-specific regulation, school and workforce skills, corporate adoption, research and infrastructure investment.[1][2]
- The August 2025 announcement documented policy design and consultation. It did not establish that every proposed safeguard, programme or funding mechanism had already been implemented.[1][2]
Four consultations gave the national plan a more testable structure
Malaysia's National AI Office used four strategic roundtables to turn a broad national AI ambition into a more specific policy blueprint. The Ministry of Digital said the sessions brought together government, business, universities, regulators and industry groups to refine the National AI Action Plan 2030 before its planned launch.[1][3]
The four tracks were AI Safety and Security, Policy and Regulation, Talent, and Advisory and Industry Engagement. Together they addressed two sides of the same problem: how Malaysia could accelerate useful AI adoption while building the trust, skills and institutional controls needed to manage harm.[1]
The details mattered because the sessions went beyond saying that AI should be responsible. They named threats, regulatory approaches and talent routes. But they were still consultation records. A proposed risk function is not the same as an operating unit, and a proposed education pathway is not the same as learners completing it. The plan's credibility would depend on what was adopted, funded and reported after the roundtables.[1][2]

The safety session separated harm to people from attacks on AI systems
The AI Safety and Security Roundtable was chaired by Digital Minister Gobind Singh Deo. In his public account of the session, Gobind drew a useful distinction: AI safety concerns protecting people and society when a system behaves badly or causes harm, while AI security concerns protecting the system, its data and its model artefacts from malicious access, tampering or misuse.[2]
The Ministry's later release named five risk areas discussed at the session: deepfakes, cyberattacks, algorithmic bias, data-privacy violations and generative misuse. NAIO presented a safety structure that included a regulatory baseline supported by voluntary guidelines, a tiered risk-classification model aligned with international standards, a dedicated risk function and an incident-response capability.[1][3]
That combination suggests that not every AI use would be treated identically. Higher-risk systems could face stronger expectations while lower-risk uses might rely more heavily on guidance. The unanswered operational questions were who would classify a system, which incidents had to be reported, what evidence an operator must retain and which authority could intervene when harm appeared.[1][2]

The proposed regulatory model was layered rather than one rule for every sector
At the Policy and Regulation Roundtable, stakeholders discussed what the ministry called a hybrid-tiered regulatory model. The proposed structure combined principles-based oversight by NAIO with sector-specific mechanisms led by the regulators already responsible for areas such as finance, communications, health or other regulated services.[1]
The policy toolkit was also broader than a single AI law. The official release referred to hard-law requirements, market-forcing tools such as licensing and compliance assessments, and soft-law instruments such as standards and circulars. In practice, those tools can move at different speeds: guidance can arrive quickly, sector regulators can issue rules within existing mandates, and legislation usually requires a longer public process.[1]
A layered model can be practical because the risk from an internal writing assistant is different from the risk of an automated decision affecting money, employment, health or access to public services. It can also become confusing if organisations do not know which rule applies. The final plan therefore needed a clear map of responsibilities, thresholds and escalation routes—not only a list of governance principles.[1]
Talent and industry discussions connected education to real adoption
The Talent Roundtable considered the pipeline from early education to the existing workforce. The ministry listed AI skills in primary and secondary education, non-traditional and vocational pathways, university courses aligned with industry needs, educator upskilling, fellowship programmes and efforts to retain or attract Malaysian AI talent, including people in the diaspora.[1]
The Advisory and Industry Roundtable then looked at the demand side. Leaders from Konsortium AI Nasional and the AI Advisory Working Group discussed corporate adoption, investment in research and infrastructure, stronger links between talent and employers, and governance that remained practical, proportionate and business-friendly.[1]
Putting the two tracks together was important. Training numbers alone do not prove that Malaysia has the capabilities employers need, and investment announcements alone do not show that local workers or smaller companies can participate. Strong follow-through would connect curricula to specific roles, adoption support to real business use cases, and public reporting to completion, placement, productivity and safety outcomes.[1]
Why Malaysia should care
The roundtables showed how Malaysia was trying to move from broad AI ambition to a plan that connects risk controls, sector regulation, education and business adoption. For Malaysians, the useful test is whether those proposed structures later gained named owners, published rules, delivery routes and measurable results.
Businesses deploying AI
The plan pointed toward proportionate obligations rather than identical rules for every use case.[1]
Practical move: Identify the regulator, risk tier, required assessment and incident route for each material system before deployment.
Schools, universities and training providers
Talent policy was intended to connect early education, alternative pathways, universities and workforce reskilling.[1]
Practical move: Tie learning programmes to published competencies, completion evidence and roles that employers actually need.
What Malaysians can do now
- Publish a responsibility map showing which body owns each risk tier, sector rule, talent programme and adoption initiative.
- Convert the roundtable proposals into dated delivery measures, including reporting and incident-handling routes.
- Report outcomes that go beyond participation counts, such as safe deployments, completed skills, job pathways and SME adoption.
What we still do not know
The roundtables clarified the blueprint, but implementation details still required public proof.
- Which roundtable proposals entered the final National AI Action Plan 2030 without material change.
- How AI systems would be assigned to risk tiers, who could review that classification and when incidents must be reported.
- Which agencies, budgets, timelines and outcome measures would support the education, workforce and industry programmes.
Sources
- 1.Building the Blueprint: NAIO's AI Roundtables Drive National AI Strategy Forward Ministry of Digital Malaysia, 9 August 2025
- 2.AI Roundtable: Safety and Security Gobind Singh Deo, 4 August 2025
- 3.Siri Perbincangan NAIO Pacu Pelan Tindakan AI Kebangsaan 2030 Bernama, 9 August 2025


