The National AI Office has spent July running a public consultation on what would be Malaysia's first horizontal AI law, and the reflex reaction from most SME owners I speak to is that this is a bank-and-big-tech problem. It is not, and the risk-based structure being proposed is precisely what makes it an SME problem too.
To be clear about where this actually stands: this is a bill still in consultation, not enacted law, and the Prime Minister has framed it as complementing existing cybersecurity and data protection legislation, not replacing it. Nobody needs to panic about a compliance deadline that hasn't arrived. But the direction of travel is clear enough that waiting for the final gazetted version before thinking about it is a mistake.
Why "risk-based" is the detail that matters
The proposed approach, as described in the Ministry of Digital's own consultation materials, is proportionate to risk rather than uniform across every organisation that touches AI. That is good news in one sense, it means a ten-person marketing agency using AI writing tools is not going to face the same obligations as a bank running AI-driven credit decisions. But proportionate to risk still means every organisation has to have done the work of figuring out which risk category its own AI use actually falls into, and that classification exercise is the part most SMEs have not started.
Write down, in one page, every place your business currently uses AI, customer chatbots, hiring screening, content generation, financial forecasting, and rate each one honestly: low, medium, or high risk to a customer or employee if it gets something wrong. That single page is most of the classification work a future compliance requirement will ask for anyway.
Why this matters for Malaysian SMEs specifically
Malaysian SMEs have watched PDPA compliance arrive in stages over the years, first as a voluntary good idea, then as an expectation, then as something regulators actually asked about. AI governance is very likely to follow the same arc, and the organisations that treated PDPA as a genuine internal practice rather than a document exercise are, without exception, the ones now finding this new conversation easier. The same discipline, know what you're doing, know why, be able to explain it plainly, is what a risk-based AI law will eventually ask for as well.
Not sure where your AI use actually stands?
The AI Readiness Assessment is a 15-minute diagnostic that maps exactly where your organisation's AI use sits today, governance included, before any law forces the question.
Explore the Assessment (RM297)What This Means for You
Nothing about this bill requires action from an SME today, and treating a consultation as an emergency helps nobody. But the direction is settled even if the wording is not: AI governance in Malaysia is moving from "nice to have" to "expected," the same path PDPA took, and the businesses that start the honest internal accounting now will find the eventual formal requirement a formality rather than a scramble.