
Malaysia has strengthened its position as one of Southeast Asia’s fast-digitalising economies. In 2024, the combined contributions of ICT and e-commerce represented 23.4% of the economy, totalling USD 108.8 billion (MYR 451.3 billion). This growth is anchored by sustained investment in digital infrastructure. In the first quarter of 2026, for example, the information and communications subsector attracted USD 9.38 billion (MYR 38.9 billion), with data centres and cloud computing representing USD 8.34 billion (MYR 34.6 billion) of that total.
Building on a previously approved digital investment for 2024, the government targets to raising the digital economy’s contribution to 30% of GDP by 2030 under the Malaysia Digital 2030 (MD2030), with 2026 identified as a pivotal transition year in its ambition to establish the nation as an “AI Nation” by 2030. That ambition has been matched by significant investment in digital infrastructure such as the 2026 budget committed approximately USD 496 million (MYR 2 billion) for Sovereign AI Cloud, as well as dedicated funding for the National AI Office and national cybersecurity. Malaysia’s leadership role during its ASEAN Chairmanship in 2025, in advancing negotiations on the ASEAN Digital Economy Framework Agreement (DEFA), has further positioned the country as an important contributor to the region’s evolving digital governance landscape. These developments highlight the growing necessity of flexible, interoperable, and forward-thinking governance models that foster innovation while ensuring trust, security, and regional digital integration.
The Tech for Good Institute (TFGI), in collaboration with the Social and Economic Research Initiative (SERI), convened government officials, industry representatives, and policy researchers for a closed-door roundtable discussion to discuss Malaysia’s evolving digital ecosystem.
Moderators and Speakers
- Ellina Roslan, Senior Director, MyDigital
- Raja Segaran, Director, Regional Digital Economy Office, Malaysia Digital Economy Corporation
- Bryan Yeoh, Senior Manager, Strategy and Knowledge Leadership, Malaysia 4IR Center
- Darmain Segaran, Manager, AI Policy Lab, NAIO
- Hasnul Nadzrin Shah, Government Affairs Director, American Malaysia Chamber of Commerce
- Nabila Hussain, Director, Government Affairs and Public Policy, Microsoft
- Wan Khatina binti Wan Mohd Nawawi, Managing Director, EconWorks Advisory
- Shariffah Rashidah Syed Othman, Deputy Director General, Personal Data Protection Department, Ministry of Digital
- Farlina Md Said, Director, Institute of Strategic and International Studies
- Dr Jun-E Tan, Senior Research Associate, Khazanah Research Institute
- Arifah Sharifuddin, Institute Director, Tech for Good Institute
- Keith Detros, Programme Manager, Tech for Good Institute
Key Takeaways
- Safety and trust are the foundation for innovation
Participants emphasised that trust and safety should serve as a fundamental foundation for AI adoption. Several speakers noted that integrating safety and security into the deployment of AI is essential for ensuring that there is sustainable and wider adoption of AI tools. This is because AI’s natural-language capabilities can act on human vulnerability. This perspective is also reflected structurally. The recently updated MD2030 action plan is organised around seven strategic pillars that incorporate governance, trust, security and ethical use of data and AI, signalling that governance is now a central concern of the government.
Participants also noted that AI failures often display in subtle ways, in contrast to conventional system errors. An AI harm can emerge slowly and in critical areas that permit minimal or no margin for error, which is why safety and trust must be established from the beginning. In this context, existing voluntary frameworks such as the National Guidelines on AI Governance and Ethics (AIGE) can serve as a basis for adoption, with the National AI Office (NAIO) tasked with translating high-level principles into operational standards and sectoral guidance.
- New legislation should close structural gaps, not duplicate existing instruments.
As the country is drafting an AI governance bill to strengthen prevention and accountability across the lifecycle of AI systems, there was broad agreement that such legislation should take the form of a structural, governance-oriented framework. Participants noted that many AI-enabled harms can be addressed through existing frameworks, including personal data protection, communications and multimedia regulation, cybercrime laws, and sector-specific rules. Hence, the new bill should be able to address genuine regulatory gaps and clarify accountability across the AI lifecycle, rather than duplicate existing legal provisions.
Consistent with Malaysia’s sectoral approach, speakers emphasised that more sector-specific regulators are often best placed to manage industry-specific risk. Any central AI governance architecture should therefore build upon existing regulatory expertise. Competition policy and industry stakeholders similarly stressed the importance of proportionality, noting that requirements designed for large platforms and concentrated markets can impose disproportionate burdens on smaller firms.
Furthermore, participants highlighted several areas where additional clarity may be needed, particularly around accountability, coordination, and AI incident reporting. While Malaysia already maintains incident-reporting mechanisms covering cybersecurity, personal-data breaches, and sector-specific risks, participants suggested that a new AI bill could help define mandates, interfaces, and cooperation mechanisms across these regimes, avoiding duplicate reporting while improving oversight and understanding of AI-related harms.
- AI governance must be approached as an ecosystem, requiring coordination across stakeholders, sectors and borders.
AI governance must be approached as a whole ecosystem, spanning infrastructure, data, models, and applications, alongside the talent and firm-level adoption that bring them into use. Participants noted that a healthy market requires both a supply side of local AI solutions and a demand side to adopt them. The AI Growth Zones, beginning with firm-level work in Johor, were cited as an example of efforts to build that demand from the ground up and strengthen the broader AI ecosystem.
Participants also stressed that effective AI governance requires coordination beyond national borders. Both sovereignty and interoperability should be treated as necessary components of a resilient AI ecosystem and not competing objectives. For instance, discussion on data governance has moved beyond a narrow focus on where data physically resides towards questions of operational and legal control. Meanwhile, sovereign capability was seen as extending beyond data to encompass strategic infrastructure such as compute, cloud capacity, data centres, and semiconductors. At the same time, participants cautioned against approaches that prioritise control at the expense of innovation, competition, and regional integration. Malaysia’s role in operationalising the ASEAN AI Safety Network in 2026 was highlighted as a concrete step towards trusted interoperability across jurisdictions.
Participants further emphasised that no single actor can govern AI alone. The government was seen as an enabler and coordinator, responsible for setting cross-cutting principles, shaping public-sector adoption, and investing in talent and infrastructure. Industry plays a pivotal role not only to innovation and deployment but also to informing the development of sector-specific regulations through practical deployment experience and best practices. Academia and research institutes contribute expertise and evidence, while civil society and practitioners help surface real-world issues and strengthen digital literacy. Effective AI governance will rely on ongoing collaboration among stakeholders, sectors, and borders, supported by enhanced institutional capacity and regional interoperability, rather than on legislation alone.
