Resources

Welcome to our knowledge base of research that demonstrates our understanding of complex business challenges faced by companies around the world.

Reset all
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The National AI Office (“NAIO”) has launched a public consultation on the proposed AI Governance Bill through the Unified Public Consultation (“UPC”) platform. The consultation invites stakeholders and members of the public to submit written feedback, comments, or proposals by 31 July 2026. You can find access to the public consultation here.

Background

Artificial Intelligence (“AI”) is rapidly emerging as one of the most powerful technologies of our generation, with the ability to transform industries, enhance productivity, improve public services, and create new economic opportunities. However, the current regulatory landscape poses the risk of differing standards and approaches being applied across various sectors. In response, Malaysia is developing a national AI Governance Bill to establish a comprehensive and coherent governance framework that aims to ensure responsible and trustworthy use of AI while stimulating innovation.

It is noteworthy that the formulation of the Bill is built upon three core approaches: institutional oversight through a Central AI Authority whilst leveraging existing sectoral institutions, a principle-based approach that allows the framework to remain agile and adaptable, and a risk-based approach ensuring that regulatory obligations are proportionate to the level of risk posed by an AI System.

Key Features of the Proposed AI Governance Bill

NAIO has released a Consultation Paper setting out six key areas of the Bill for preliminary public feedback. These areas are summarised below.

Scope of the Bill

The Bill proposes to regulate the AI Lifecycle of AI Systems which are placed on the market or put into service within Malaysia, designed, developed, or used in Malaysia, or used by a Deployer established in Malaysia regardless of where the system is physically hosted. The Bill introduces definitions for key concepts including “Artificial Intelligence”, “AI Systems”, and “AI Lifecycle”, and identifies two primary regulated parties which are “Developers, who materially shape what an AI System is capable of doing, and “Deployers”, who cause the AI System to operate in the real world or domain of deployment. Exemptions are proposed for personal use and national security applications.

AI Governance Architecture

The Bill proposes the establishment of a Central AI Authority which operates as an institutional anchor for the AI governance framework. The Central AI Authority would have three core functions: AI Safety, Investigation and Enforcement, and AI Enablement. The Bill further proposes leveraging existing frameworks through the appointment of Sectoral Leads who may be appointed and delegated specific powers under the Bill to support implementation where they have sufficient legal authority, technical expertise, and governance capacity.

AI Governance Principles

Adopting a principle-based approach, the Bill sets out five guiding AI Governance Principles:

  1. Protecting, promoting, and preserving human dignity by upholding human agency and safeguarding human rights.
  2. Transparency and explainability proportionate to risk and impact;
  3. Clear accountability through traceability and effective redress;
  4. Safe and secure use through robust and resilient AI Systems; and
  5. Responsible data governance and stewardship in relation to AI Systems.

Developers and Deployers of AI Systems would be required to have “due regard” for these principles throughout the AI System’s lifecycle, with compliance scaled based on the level of risk, context, and purpose of the AI System.

Implementation of these principles is expected to take a phased approach with voluntary documents issued at the early stages of the Bill and progressively moving towards codifying full implementation once a level of maturity is reached by the ecosystem.

AI Risk Framework

The Bill proposes a risk-based approach anchored to four categories of harm: death, bodily injury, unlawful deprivation of fundamental liberty anchored to the Federal Constitution, and contravention of any written law. Based on this, a three-tier risk framework is envisaged namely Tier 1 (Unacceptable Risk), Tier 2 (High Risk), and Tier 3 (Low Risk). Requirements set on these tiers will be proportionate to the nature, context, and level of risk posed by an AI System.

AI Incident Reporting

The Bill proposes a structured AI incident reporting mechanism to ensure a systematic approach in identifying, assessing, learning from, and addressing AI-related incidents. AI Incidents may include an event, failure, weakness, misuse, unexpected effect, material circumstances, or near misses.

Reporting may be made by Developers or Deployers as well as through public complaints to the Central AI Authority, and in cases where a similar mechanism exists, the Central AI Authority may leverage them through Sectoral Leads.

AI Sandbox

The Bill proposes the establishment of an AI Sandbox as a controlled environment to test AI Systems under supervised conditions. The AI Sandbox is intended to encourage innovation, facilitate flexible testing, and support evidence-based policymaking. It may be implemented either as a centralised sandbox operated by the Central AI Authority or by designating and leveraging existing infrastructures through Sectoral Leads.

Conclusion

This public consultation is timely, particularly in light of Malaysia’s aspiration to become an AI Nation by 2030 under the recently launched Malaysia Digital 2030 Action Plan. As the country seeks to position itself at the forefront of AI innovation and adoption, a robust governance framework will be essential in building trust, ensuring safety, and maintaining competitiveness on the global stage.

The consultation is also in line with the National Policy on Good Regulatory Practice (NPGRP), reflecting the Government’s commitment to inclusive, transparent, and evidence-based policy-making. Thus, all stakeholders are encouraged to take this opportunity to contribute to the shaping of Malaysia’s AI governance landscape.

This alert is for general information only and is not a substitute for legal advice.

Article
Law Reform and Government Advisory

Consultation Alert: Public Consultation on Malaysia’s AI Governance Bill

Key Changes. Merger-Control Benched.

Introduction

Two Bills were tabled in Parliament to amend the Competition Act 2010 (Act 712) and the Competition Commission Act 2010 (Act 713), introducing key reforms.

However, as surprising as a star player missing a World Cup opening match was the omission of the long-awaited merger controls.

This article summarises the principal reforms introduced by the Bills.

Key Reforms in the Competition (Amendment) Bill 2026

The Competition (Amendment) Bill 2026 introduces a wide range of institutional and procedural reforms to strengthen MyCC’s investigation, enforcement and decision-making framework. Principal changes include:

Expanded scope:

  • The Act would apply to any “commercial or economic activity”. Activities with an economic character—even if not expressly commercial—may now be subject to scrutiny.
  • This wider framing captures non-traditional commercial arrangements and economic conduct that may not fit neatly within the previous definition, for example trade associations.
  • Businesses should consider whether activities previously assumed to fall outside competition law—such as arrangements involving non-profit elements or activities with an economic character but not expressly commercial—may now be subject to scrutiny.
  • Question: Does this raise questions on previous decisions where non-commercial enterprises, such as not for profit trade associations, were found liable for anti-competitive conduct?

Broader section 4 prohibition:

  • The prohibition would apply to “any agreement”, not just horizontal or vertical agreements.
  • Businesses should review all commercial arrangements for potential exposure. Any agreement—regardless of the parties’ position in the supply chain or industry—may be caught if it has the object or effect of significantly preventing, restricting or distorting competition.
  • Question: Does this raise questions on previous findings against hub-and-spoke cartels?

Other key amendments:

  • Enhanced information-gathering: MyCC would have wider powers to compel information from Government entities (such as ministries and statutory bodies) and conduct market reviews.
  • Warning letters and interim measures: MyCC may issue warning letters after preliminary inquiries and impose interim directions during ongoing investigations. The Bill expands interim-measures powers so that MyCC can act to prevent serious and irreparable harm while an investigation is ongoing. Businesses may face binding directions to suspend agreements or cease conduct at an earlier stage, before any final infringement decision.
  • Settlement mechanism: Enterprises admitting liability may receive up to 40% penalty reduction, in addition to any leniency discount. Enterprises under investigation may now resolve matters more efficiently by admitting liability and accepting a settlement. In return, MyCC may reduce the financial penalty by up to 40%. This creates a clear incentive for early co-operation, potentially shortening investigation timelines for both the regulator and the enterprise. The settlement discount is in addition to any leniency reduction available under section 41.
  • Leniency programme updates: Up to 100% penalty reduction remains available, but enterprises that coerced others into the cartel will likely receive lower reductions. This change sharpens the incentive for whistle-blowing by non-coercive cartel members and increases the risk for ringleaders.
  • Decision-making procedures: Formalised process for proposed decisions, written and oral representations, and supplementary proposed decisions.
  • Appeals: CAT decisions are no longer final. Appeals to the High Court are available on questions of law or penalty quantum only. This provides an additional layer of judicial oversight but does not open a full merits review. Enterprises planning to challenge MyCC decisions should anticipate a two-tier appellate process.
  • Whistleblower and informer protections: Informer identities are protected and rewards may be paid.
  • Confidentiality and obstruction: Enhanced confidentiality obligations and offences for attempted destruction of records.

Competition Commission (Amendment) Bill 2026

The companion Bill amends Act 713 primarily to:

  • rename the “Competition Commission” as the “Malaysia Competition Commission”;
  • clarify and expand the Commission’s functions to include advising the Minister or other public or regulatory authority on policies, procedures and programmes relating to competition;
  • empower the Commission to impose financial penalties, late-payment charges, fees, and administrative charges;
  • permit delegation of the Commission’s functions and powers; and
  • update provisions relating to the appointment of Commission officers and secrecy provisions.

What happened to the Merger-Control Proposals?

Not all proposals from the 2022 public consultation have been carried into the 2026 amendments. Most significantly, the proposed merger-control regime is absent from both Bills.

In April 2022, MyCC issued a public consultation proposing to add a comprehensive merger-control chapter to the Competition Act 2010. The key elements of that proposal were:

  • a prohibition on mergers (or anticipated mergers) that result, or may result, in a substantial lessening of competition;
  • a hybrid notification model combining mandatory pre-notification for transactions exceeding prescribed thresholds with voluntary notification for those below;
  • a standstill obligation prohibiting consummation of mandatorily notifiable anticipated mergers pending MyCC’s determination; and
  • ancillary provisions for penalties and merger-specific investigation powers.

The Competition (Amendment) Bill 2026 however does not include the proposed merger provisions.

Practical Implications

  • No merger filing obligation: There remains no statutory requirement to notify mergers or acquisitions to MyCC.
  • Not withstanding the absence of merger notification requirements, parties to mergers involving competitors should be aware that the Chapter 1 prohibition continues to apply. Merger parties who are competitors in the same market must therefore take care during the transaction process to ensure that any exchange of information or coordination does not amount to an anti-competitive agreement.
  • Accordingly, parties to mergers between competitors should implement sufficient safe guards to mitigate competition law risk during the pre-completion period. These safeguards typically include clean team protocols to restrict access to competitively sensitive information, strict confidentiality obligations, and information barriers that prevent commercial teams from accessing the other party’s pricing, customer or strategic data until closing.
  • Sector-specific regimes still apply: The aviation and communications sectors retain their own merger-control rules under the Civil Aviation Authority of Malaysia Act 2017 and the Communications and Multimedia Act 1998 respectively.
  • Future developments: The omission of merger control from the present Bills does not preclude its introduction in a subsequent legislative exercise.

Alternative Pathway: Merger Control Through Subsidiary Legislation

Does the Competition Act 2010 need to be amended to introduce merger controls?

  • The Minister has broad powers under the Competition Act 2010 to make regulations necessary or expedient for giving full effect to the provisions of the Act.
  • Accordingly, the Minister could issue regulations to regulate mergers under section 65, prescribing notification thresholds, stand still obligations and assessment procedures. This approach would allow Malaysia to establish a functional merger-control framework without the need for further primary legislation.
  • This regulatory approach mirrors the model adopted by the Malaysian Communications and Multimedia Commission (“MCMC”) in the communications sector. The Communications and Multimedia Act 1998 does not contain any express provisions for merger notification and assessment. Nevertheless, MCMC published its Guidelines on Mergers and Acquisitions, establishing a voluntary merger-assessment framework under existing provisions of the Act—specifically sections 133 and 139(1), which prohibit conduct that substantially lessens competition. MCMC achieved this without any amendment to its primary legislation, relying instead on its general regulatory powers and the broad prohibition on anti-competitive conduct.
  • MyCC could adopt a similar approach under the Competition Act.

This briefing is for general informational purposes only and does not constitute legal advice. Please contact us if you require advice on how these developments may affect your business.

Article
Competition Law

Malaysia’s Competition (Amendment) Bill 2026 and Competition Commission (Amendment) Bill 2026

This publication highlights an in-depth analysis of Malaysia’s product liability regime, highlighting the legal responsibilities of manufacturers, importers, and suppliers, as well as the remedies available to consumers. Covering statutory, contractual, and tortious liability, it also explores key procedural considerations, recent developments, and the anticipated introduction of “lemon law” protections, providing valuable guidance for businesses operating in Malaysia’s consumer market.

This publication was first published in ICLG- Product Liability Laws and Regulations 2026.

Publication
Intellectual Property

ICLG - Product Liability Laws and Regulations 2026

New Regulatory Framework for Consumer Credit Industry Now in Effect

The Consumer Credit Commission (Suruhanjaya Kredit Pengguna, "SKP") has today, 5 June 2026, issued its Authorisation Standards (Version 1.0) pursuant to section 123 of the Consumer Credit Act 2025 ("CCA"). The Standards take immediate effect and establish the licensing and registration framework for entities carrying on credit businesses and credit service businesses in Malaysia.

Who is affected?

The Standards apply to entities carrying on or intending to carry on the following regulated activities:

  • Credit business (requiring a licence): buy now pay later schemes, factoring, and leasing, including their Islamic equivalents.
  • Credit service business (requiring registration): impaired loan or financing acquisition, debt collection, and debt counselling and management.

Entities already engaged in these activities, as well as new entrants to the market, must familiarise themselves with the authorisation criteria and ensure compliance.

Key requirements at a glance

The Standards prescribe minimum financial thresholds of RM2 million in shareholders' funds or total equity for credit businesses, and RM500,000 (or RM250,000 with professional indemnity insurance of RM250,000) for credit service businesses. Applicants must be companies incorporated in Malaysia under the Companies Act 2016 and must demonstrate organisational competence, sound business management, and the fitness and propriety of their key persons, including controllers, directors, and senior management.

All applications must be submitted via SKP's new digital regulatory platform, the Consumer Credit Commission Online Regulatory System ("CORE System"), together with the prescribed processing fee of RM2,000 per type of business.

Islamic credit business

The Standards include dedicated provisions for Islamic credit providers, who may operate either as full-fledged Islamic entities or through an Islamic window model. Key obligations include end-to-end Shariah compliance, establishment of an Islamic Credit Business Fund for window operators, prohibition on commingling of Islamic and conventional funds, and the appointment of a qualified Shariah adviser or Shariah committee.

Post-authorisation obligations

Authorised entities face ongoing compliance obligations, including periodic data submissions to SKP (annual audited financial statements, quarterly operational data, and monthly complaints data), notification requirements within 14 calendar days of specified events, and the obligation to submit credit consumer data to a credit reporting agency within 12 months of authorisation. Prior approval from SKP is required for matters such as changes in control, appointment of the chief executive, and addition of new business types.

Fees

Inaugural authorisation fees are RM8,000 per licence (credit business) and RM5,000 per registration (credit service business), with a 50% reduction for approvals granted in the second half of the calendar year. Annual fees are tiered by revenue, ranging from RM8,000 to RM100,000 for credit businesses and RM5,000 to RM50,000 for credit service businesses.

Entities not serving credit consumers

Entities carrying on a credit business or credit service business that does not involve credit consumers are not subject to the licensing or registration requirement. However, they must submit an annual declaration to SKP under section 79(2) of the CCA confirming their noninvolvement with credit consumers.

What should affected entities do now?

Entities currently carrying on or planning to carry on any of the regulated activities should review the Authorisation Standards in full, assess their readiness against the authorisation criteria, and take steps to prepare their applications via the CORE System. Particular attention should be given to ensuring that key persons meet the fit and proper criteria and that the requisite policies, procedures, and financial resources are in place.

We are available to assist clients in navigating the new framework, including advising on authorisation applications, corporate structuring, Shariah governance arrangements, and ongoing compliance obligations.

The full text of the Authorisation Standards is available on SKP's website at www.skp.gov.my.

If you have any questions or require any additional information, please contact Sharifah Shafika Alsagoff or the partner you usually deal with in Zaid Ibrahim & Co

This alert is for general information only and is not a substitute for legal advice.

Article
Islamic Financial Services

Malaysia's Consumer Credit Commission Issues Authorisation Standards

The Personal Data Protection Commissioner’s Office (“JPDP”) has issued three new non-binding guidelines under the Personal Data Protection Act 2010 (“PDPA”): Data Protection by Design, Data Protection Impact Assessment, and Automated Decision-Making and Profiling. Together, they advance Malaysia’s data protection framework from reactive compliance to proactive, risk-based governance aligned with global standards.

Data Protection by Design

The DPbD Guideline requires embedding personal data protection throughout the data processing lifecycle—from design to decommissioning. It is structured around proactiveness, end-to-end protection, transparency, and user-centricity, applying these across the seven Personal Data Protection Principles. The DPbD Guideline encourages a risk-based approach tailored to each organisation’s processing activities.

Data Protection Impact Assessment

The DPIA Guideline provides guidance on identifying, assessing, and managing risks in personal data processing. A DPIA is required where processing is likely to result in high risk—determined quantitatively (more than 20,000 data subjects, or 10,000 data subjects where sensitive personal data (including financial data) is involved) or qualitatively (potential legal or significant effects on the data subject, systematic monitoring of the data subject, use of innovative technologies, denial or restriction of the data subject’s rights, tracking of the data subject’s location or behaviour, targeting of children or vulnerable individuals, and automated decision-making and profiling that present a high risk to the data subject). The Guideline prescribes the five-step “DEICA” methodology (Describe, Evaluate, Identify, Consider, Assess) and requires that DPIAs be refreshed every two years.

Automated Decision-Making and Profiling

The ADMP Guideline addresses automated systems used in personal data processing, despite the PDPA not containing specific provisions on such activities. It applies where outcomes may have legal or significant effects on data subjects (e.g., financial, employment, or service access decisions). Compliance with the Notice and Choice Principle is required, preserving the data subject’s right to withdraw consent. Notably, AI must not be the sole factor in decisions concerning data subjects, and the use of ADMP itself triggers the requirement for a DPIA.

JPDP’s power to issue guidelines

The PDPA confers on JPDP functions that include issuing guidance. Each of the three documents—the DPbD, DPIA and ADMP Guidelines—expressly records that it is issued by JPDP pursuant to subsection 48(g) of PDPA. They supplement the Act and related subsidiary instruments and are not intended to override them or to be prescriptive.

Are the Guidelines binding or legally effective?

The DPbD, DPIA and ADMP Guidelines provide guidance and promote good practice; they expressly state that they supplement and do not override the Act or subsidiary legislation. A failure to follow a Guideline does not, by itself, constitute an offence unless such non-compliance triggers a breach of the PDPA or subsidiary legislation.      

Conclusion

Taken together, these guidelines form a cohesive framework reinforcing the obligations of data controllers and processors under the PDPA. The DPbD Guideline embeds privacy at the design stage, the DPIA Guideline ensures high-risk processing is rigorously assessed, and the ADMP Guideline addresses the particular challenges of automated technologies and AI.

If you have any questions or require any additional information, please contact Nadarashnaraj Sargunaraj or the partner you usually deal with in Zaid Ibrahim & Co. This alert was prepared with the assistance of Hana Wong Xin Yi, Associate in Zaid Ibrahim & Co.

This alert is for general information only and is not a substitute for legal advice.

Article
Communications, Media and Technology

Design. Assess. Automate—Safely: Malaysia’s New PDPA Guidelines at a Glance

This note highlights key bank secrecy obligations under Malaysian law, including guidance on disclosure of customer data and compliance with the Personal Data Protection Act 2010.

Reproduced from Practical Law with the permission of the publishers. For further information, visit practicallaw.com.

Publication
Banking and Finance

Practical Law Global - Practice Note Bank Secrecy Laws (Malaysia)

In this chapter, we take a closer look at Malaysia’s competition law framework on cartels — covering key legal principles, investigative powers, and notable enforcement developments over the past 12 months.

 This article was first published in GLI – Cartels 2026 by Global Legal Group.

Publication
Competition Law

Global Legal Insights - Cartels 2026

Zaid Ibrahim & Co contributed to the Lexology Panoramic: Private Equity 2026 (Fund Formation)Malaysia.

Authored by Chief Operating Officer, Chua Wei Min, Partner, Geraldine Oh and Partner (Tax) Kellie Allison Yap, the article offers a detailed overview of essential information regarding Malaysia’s private equity fund formation regime whether through the use of Malaysia vehicles of a Sdn Bhd, LLP or Labuan entities of an LP, LLP. Each with its own pros and cons.

The guide explores, among other, formation, regulation, licensing and registration requirements (CMSL/PEMC), taxation, selling restrictions and investors generally and finally, updates and trends in the vibrant VC/PE space in the last year with a continued forward momentum in 2026.

Read the full article here.

Publication
Corporate and Commercial

Lexology Panoramic: Private Equity 2026 (Fund Formation) Malaysia