Malaysia’s first AI law has a name for your company. It’s probably not the one you’d choose for yourself: Deployer.

The word comes from the AI Governance Bill, released for public consultation on 10 July 2026 by the National AI Office. It’s Malaysia’s first horizontal AI law, meaning one set of rules that cuts across every sector rather than industry by industry. And it sorts every organisation that touches AI into one of two roles.

Developers shape what an AI system can do. Deployers operate it in the real world. If your team uses AI to screen CVs, draft contracts, answer customers, or price a quote, you’re a Deployer. Almost every Malaysian company using AI tools is one, whether it has thought about it in those terms or not.

Most people are reading this Bill as procurement and paperwork. Risk registers, documentation, a compliance officer’s problem, filed away until it’s enforced. That read is comfortable, and it misses the part that lands on everyone else in the building.

Two roles, and you’re the one on the hook

The split matters because the accountability lands differently for each side. Developers answer for how a system is built. Deployers answer for how it behaves once it’s switched on and making decisions that affect real people.

You can’t buy your way out of that with better software, and you can’t fully outsource it to the vendor who built the model. The moment your staff point an AI tool at a live decision, your company owns the outcome. That’s the quiet shift in the Bill. It puts AI accountability on named people and boards, not on a tool.

This isn’t a one-off gesture either. A 5-year national AI plan sits behind the Bill, and Malaysia’s framework is being lined up with the EU AI Act, Singapore’s AI Verify, and the OECD principles. Malaysia sits 24th of 193 on Oxford Insights’ 2024 government AI readiness index: mid-table, and clearly trying to climb. AI capability is national policy now, not a passing trend. Any serious AI adoption strategy for Malaysian corporations has to plan around it.

Three tiers, five principles, one clean pass

Here’s the shape of the Bill in a single breath.

It’s risk-based, sorted into three tiers. Tier 1 is unacceptable risk, and it’s prohibited outright. Tier 2 is high risk, and it carries the strict obligations: assessments, controls, and human oversight. Tier 3 is low risk, with a baseline set of expectations. Risk can show up anywhere across a system’s life, not just on the day you buy it.

On top of the tiers sit five principles that both Developers and Deployers must show “due regard” to: human dignity, transparency and explainability, accountability, safety and security, and data governance.

2
regulated roles: Developer and Deployer. Almost every company using AI is a Deployer (Baker McKenzie, 2026)
3
risk tiers: unacceptable (prohibited), high risk (strict duties), low risk (baseline) (Baker McKenzie, 2026)
5
principles both parties must show due regard to, including transparency and explainability (Baker McKenzie, 2026)

Read that list as a lawyer and it’s a checklist. Read it as an operator and two items jump out, because they can’t be satisfied by a document. They can only be satisfied by people.

The two duties nobody can outsource

Human oversight and explainability are the duties that quietly decide everything else.

Human oversight means a person is watching the AI closely enough to step in when it’s wrong. Not a policy that says someone should. An actual person, doing it. Explainability means that when a customer, a regulator, or your own board asks why the system produced a given answer, someone can explain it in plain terms.

Now ask the uncomfortable question. The person assigned to oversee your hiring model, or your credit-scoring tool, or your customer-service agent: do they understand it well enough to catch it when it drifts? Can they explain what it did, and why, without reading from the vendor’s brochure?

For most Malaysian companies right now, honestly, the answer is no. The staff running these tools were handed a login and a getting-started guide. That’s enough to use AI. It is nowhere near enough to oversee it.

Human oversight isn’t a policy you write. It’s a person who understands the system well enough to catch it when it’s wrong. That person has to be trained.

This is the reframe the Bill forces, whether it means to or not. Its core compliance duties are human-capability duties in disguise. You cannot oversee, and you cannot explain, an AI system your people don’t actually understand. Governance obligation, it turns out, is a training obligation wearing a suit.

What “oversight” actually asks of your people

So treat it as the workforce question it really is, and the path gets practical fast.

Start by baselining what your people actually know. Not who has used ChatGPT, but who can spot a confidently wrong answer, who understands where a model’s data came from, who knows the difference between a task AI is good at and one it quietly fumbles. That baseline is usually humbling, and it’s the honest starting point for any real AI governance training.

Then close the gap with training that builds judgement, not familiarity. Watching a video builds neither oversight nor explainability. Applied, assessed practice does. People learn to oversee AI by working with it under real conditions and getting told, specifically, where their judgement was off.

Then measure it, and keep measuring. The Bill’s whole logic is that oversight is an ongoing state, not a one-time certificate. If you can’t show what your workforce understands today, you can’t claim to be overseeing anything. And when the consultation closes on 31 July and the rules start to firm up, “we ran a lunch-and-learn” is not going to read as due regard.

None of this is about panic. It’s about noticing that the thing you’ll be asked to prove, that competent humans are in the loop, is built long before any law is enforced. It’s built in how you train.

Oversight starts with knowing what your people know

This is where the Bill and the day-to-day job of running a company meet. Every duty in it, above the prohibited tier, eventually resolves to a single question: do the humans operating this system understand it well enough to be accountable for it?

You can’t answer that with a policy PDF. You answer it with capability you can see and measure across your whole team, not just your two power users.

That’s the layer SkillTrainer AI is built for. Our assessment agents baseline what your people actually understand about the AI they use, our analytics dashboard shows you where the gaps sit and whether they’re closing, and the enterprise AI governance training itself is applied and measured rather than watched and forgotten. It’s the difference between hoping your staff can oversee AI and being able to show it. We’re HRD Corp registered, and our courses are claimable under SBL-Khas, so the funding to close this gap is already sitting in an account most companies never touch.

The Bill asks for human oversight. Human oversight starts with knowing what your people actually know. Everything the law wants from you is downstream of that.

Sources

Baker McKenzie — Malaysia: Public Consultation on the AI Governance Bill (2026)

Digital Watch Observatory — Malaysia AI Governance Bill consultation (2026)

Malaysia Productivity Corporation — Public Consultation on the Proposed AI Governance Bill (2026)

National AI Office (NAIO) — AI Governance in Malaysia (2026)

Oxford Insights — Government AI Readiness Index 2024 (2024)