A school leader asked me recently whether their school was "AIGE compliant," and the honest answer took longer to give than the question deserved, because AIGE is not the kind of thing a school can be compliant with, not yet, and the law that already binds them on this subject is one they were not asking about at all.
That confusion is understandable and, in my experience, close to universal among the school leaders I talk to. Malaysia now has two AI-adjacent policy instruments circulating in the same conversations, AIGE and the proposed AI Governance Bill, plus one that has quietly applied to every school for years without anyone calling it an "AI law": the Personal Data Protection Act. Getting the three straight is worth ten minutes, because only one of them can actually be enforced against a school today.
AIGE: guidance, not law
The National Guidelines on AI Governance & Ethics, AIGE for short, were launched by the Ministry of Science, Technology and Innovation in September 2024, and they remain exactly what the name says: guidelines. They set out seven principles, fairness, reliability and safety, privacy and security, inclusiveness, transparency, accountability, and human-centricity, and they give three audiences, end users, policymakers, and developers, guidance on what responsible AI use should look like. Nothing in AIGE is enforceable. A school that ignored it entirely would not be breaking any rule, because it is voluntary by design, a foundation for future law rather than the law itself.
Where AIGE is genuinely useful to a school is as a checklist for the questions a good AI policy should already be answering, whether or not the ministry ever makes it mandatory. If a school's AI use touches fairness, safety, or transparency in ways it cannot currently describe in a sentence, AIGE has told it exactly where the gap is.
The AI Governance Bill: coming, not here
The instrument that will eventually carry legal force is the AI Governance Bill, and it is worth being precise about where it actually stands, because I have heard it described to me, more than once, as though it were already in effect. It is not. The National AI Office ran a public consultation on the Bill from 10 to 31 July 2026, gathering feedback from government, industry, and academia on a proposed risk-based framework built around a new Central AI Authority. The Bill is targeted for completion by the end of 2026, which means, at the time of writing, it is still a proposal working its way through consultation and drafting, not a statute a school can be found in breach of.
When a vendor, consultant, or well-meaning parent tells you a school "must" do something for AIGE or AI Governance Bill compliance, ask them to point to the specific clause. Neither instrument currently imposes a mandatory obligation on schools. The honest answer to "are we compliant" today is "there is nothing yet to be compliant with," and saying so plainly is better than pretending otherwise.
PDPA: the one that already binds you
"Maximum fine of RM1 million and imprisonment of up to three years." "What?" The principal looked at me, incredulous. The PDPA is serious about data protection, especially where children are concerned, and plenty of people running businesses, education included, have not quite kept up with how far it has moved. How well is your own institution doing in this area?
Here is the part that gets missed in nearly every conversation I have on this subject: the Personal Data Protection Act already governs almost everything a school does with AI, because almost everything a school does with AI touches a student's personal data, and PDPA has applied to that data for years, mandate or no mandate. A chatbot a teacher uses to draft feedback, a marking tool that ingests essays, an admissions system that screens applications, each of these processes personal data belonging to a minor, and PDPA requires parental consent for that processing, restricts its use to the purpose it was collected for, and, following the 2024–2025 amendments, requires many organisations to appoint a Data Protection Officer and to notify affected individuals of a data breach. The penalties behind all of this are not symbolic: a breach can carry a fine of up to RM1 million and imprisonment of up to three years, the figure that produced the principal's reaction above, and schools handling minors' data are exactly the kind of case the Act was written with in mind. None of that is new because of AI. AI has simply made it obvious how much of a school's daily practice was always a PDPA question.
International schools carry an extra layer of this worth naming directly: many of the AI and EdTech platforms in common classroom use route student data through servers outside Malaysia, and cross-border transfer is one of the areas PDPA treats with particular care. A school that has not asked its vendors where the data actually goes has not finished the PDPA question, whatever its AIGE reading looks like.
Why the order matters
Put the three side by side and the practical order becomes obvious, even though it is the reverse of the order most schools instinctively reach for. PDPA is the one with existing legal force, and it deserves a school's first and most rigorous attention. AIGE is the one worth reading now precisely because it previews what a future mandatory framework will likely ask for, so a school that builds its policy around AIGE's seven principles today is doing preparation, not compliance, but preparation that will not need redoing later. The AI Governance Bill is the one to watch, not yet the one to act on, and a school's time is better spent on the first two than on drafting a response to a law that does not exist.
Want this mapped against your school's own policy?
The Principal's AI Toolkit includes a plain-language policy checklist that separates what PDPA already requires from what AIGE previews, so your SLT can act on the first and prepare for the second without confusing the two.
Get the Free ToolkitWhat This Means for You
A school does not need to wait for the AI Governance Bill to have its AI policy in order, and treating AIGE as a compliance deadline mistakes a guideline for a law. What a school does need, today, is an honest audit of where AI tools touch student data, because that question was already answerable under PDPA before AI made it urgent. Get that part right, read AIGE as a preview rather than a requirement, and the eventual mandatory framework will find a school with the groundwork already done rather than a policy written in a hurry.