On 28 July 2026, the Government of Malaysia launched AI Nation 2030, the National AI Action Plan 2026–2030. The plan marks a deliberate transition from building readiness to delivering results, and its trust pillar sets out the most ambitious AI governance programme Malaysia has attempted.

The programme includes a hybrid, risk-based national framework intended as the foundation for future AI legislation (E11); a national AI Trust Function with evaluation, certification, assessor accreditation and an incident registry (E12); a national classification scheme for Made by Malaysia AI (E13); and board-level stewardship duties for Large Public Listed Companies through amendment of the Malaysian Code on Corporate Governance (E14).

E11National frameworkHybrid, risk-based; the foundation for future AI legislation.
E12AI Trust FunctionEvaluation, certification, assessor accreditation, incident registry.
E13Classification schemeNational scheme for Made by Malaysia AI.
E14Board stewardshipDuties for Large Public Listed Companies via the MCCG.
Fig. 1 — The trust pillar’s four governance enablers, E11–E14.

What AI Nation 2030 changes

The framework becomes law. E11 commits Malaysia to a principles-based, risk-based framework, codifying core definitions, risk tiers and foundational obligations, with a central governance authority coordinating sector regulators who retain enforcement. The plan is explicit that this framework is the foundation for future AI legislation. Read together with the current public consultation on the proposed AI Governance Bill, the trajectory from voluntary guidance under the National Guidelines on AI Governance and Ethics to attestable statutory duty is no longer speculative.

Governance acquires an operational arm. E12 establishes a national AI Trust Function responsible for safety and security standards, evaluation and certification, assessor accreditation, incident monitoring and forensics, and a public AI incident registry, with incident visibility mandated across enforcement agencies. Once that capability exists, “we did not know” stops being an available answer. Institutions should expect their internal evidence to be tested against an external record.

Boards receive a dated target. E14 is the only governance enabler in the plan with numbers and dates attached: adoption of emerging technology governance practices by 30% of Large Public Listed Companies by 2028, rising to 50% by 2030, delivered through the MCCG. The contemplated practices include an Emerging Technology Governance Statement in the annual report and a board-approved AI system inventory and risk map, subject to internal audit review, coordinated by a joint working group of the Securities Commission, Bursa Malaysia, the National AI Office, the Personal Data Protection Commission and MOSTI, in step with the annual MCCG Monitor. Directors who sign that statement are making a representation. The distance between disclosure and defensibility will be measured by the evidence chain behind the signature.

2026AI Nation 2030 launchedAI Governance Bill under public consultation.
202830% of Large PLCsEmerging technology governance practices via the MCCG.
203050% of Large PLCsGovernance statement, board-approved AI inventory and risk map.
AheadFramework becomes legislationE11 is explicit: the foundation for future AI law.
Fig. 2 — The dated trajectory: E14 targets through the MCCG, with E11 pointing to statute.

The State becomes a deployer at scale. The plan’s end-state for public services is a single agentic interface that completes tasks on citizens’ behalf, alongside sovereign models and AI-augmented government operations. The duties described here apply with at least equal force to the public sector’s own consequential systems. A government that will certify, assess and register incidents in the market must be able to evidence its own runtime authority first.

We applaud the Malaysian government for setting the right direction. Every duty the plan contemplates, and every duty the proposed AI Governance Bill may impose, reduces to one question the institution must be able to answer at the moment AI produces a consequential output or initiates an action:

The operating question

Is this use authorised now, and can we evidence the decision?

Answering the above requires organizations to effectively operationalize enterprise AI governance. Our position is as follows:

  • Govern the purpose-anchored contextual use. Enterprise risk does not live in the model in isolation. The same model can be low-impact in one workflow and material in another, because risk follows purpose, affected persons, data, autonomy and downstream consequence. Classification, impact assessment and duty should turn on the actual or reasonably foreseeable use.
  • Monitoring is not control. A log created after external effect is evidence of what happened, not a control over whether it should have happened. A binding control claim requires a decision the enforcement boundary is obliged to honour, together with a record of the result.
  • The decisive moment sits before external effect. Where AI initiates an action or directly determines an outcome affecting rights, access, safety, financial position or a regulated workflow, the check should occur before the effect takes place, where reasonably practicable. Agentic systems forces this architectural shift. The governance event moves from approval and retrospective review to the point immediately before the action takes effect.
  • Human oversight is an engineering requirement. Oversight is real when the reviewer has the evidence, the time window, the capacity and the decision rights to change the outcome, and when unresolved high-impact events default to a defined safe state. An unmanageable escalation queue is an undisclosed fail-open posture.
  • Evidence must exist by construction. The record of the applicable baseline, rule, decision, exception, human action and outcome should be preserved as events occur. Attestation without an evidence chain is exposure with a signature on it.

Malaysia should not have to choose between innovation and accountability. Precise operating duties make responsible deployment easier, where organizations know what they must control, regulators receive testable evidence, and low-impact uses remain proportionate. AI Nation 2030 sets the ambition and, for the first time, attaches dates and numbers to governance.

Responsible AI Solutions Sdn Bhd is a Malaysian specialist firm that combines AI governance, cloud architecture and implementation so consequential AI can operate with clear authority, enforceable controls and defensible evidence. The practice · Contact

← All perspectives