Risk-Based AI Rules Take Shape
Coverage from IFLR, Lexology, and others

Malaysia is developing a horizontal AI Governance Bill that would assign duties to developers and deployers, create central oversight, classify systems by harm and risk, and require safeguards such as assessments, incident reporting, and supervised testing.
Taiwan’s AI Basic Act is already in force and is being implemented through distributed ministry responsibilities, risk-classification guidance, and sector-specific rules. Together, the developments show a shift from voluntary principles toward formal obligations, while leaving open questions about authority, technical standards, general-purpose AI, data governance, and implementation capacity.
If you read one thing
It clearly explains Malaysia’s proposed lifecycle-based, risk-tiered AI framework and its planned central authority.
Best explainer
It explains how Taiwan is translating national AI principles into distributed, sector-specific implementation.
Latest development
It captures the material shift from consultation toward a completed Malaysian draft bill and possible parliamentary introduction.
The local angle
It shows how Taiwan’s broader governance and capacity constraints appear in the specialized context of military AI.
Malaysia is moving toward formal, centralized AI oversight
Malaysia has completed a draft horizontal AI Governance Bill that would impose lifecycle duties on developers and deployers, use harm-based risk tiers, cover some foreign-hosted systems, and establish a Central AI Authority. The initiative is closer to legislation, but parliamentary introduction remains prospective for late 2026 or early 2027.
Taiwan is implementing AI rules through distributed sector governance
Taiwan’s AI Basic Act is being operationalized through national risk classification, ministry responsibilities, and sector-specific guidance rather than a single universal control list. The framework extends into specialized areas such as healthcare and military AI oversight.
Implementation authority and capacity remain unsettled
The corpus leaves open how Taiwan will define and enforce controls for high-risk and general-purpose AI and coordinate central principles with sector regulators. Across Taiwan’s military and broader governance efforts, fragmented authority, infrastructure and interoperability gaps, cybersecurity tradeoffs, limited data systems, and talent shortages constrain implementation.
three risk tiers
AI system risk classification
“The proposal could apply to systems used by Malaysia-based Deployers even when hosted abroad, potentially bringing multinational model, cloud and software providers within its scope. AI systems would fall into three risk tiers. Systems intentionally developed or deployed to cause harm would be prohibited, while high-risk systems could require risk assessments, documentation, human oversight, monitoring and mitigation. Incident-reporting provisions could cover failures, misuse, unexpected effects and some near misses.”
first quarter of 2027
latest possible parliamentary introduction
“Malaysia’s Digital Ministry has completed a draft AI Governance Bill and is preparing it for Cabinet consideration, Digital Minister Gobind Singh Deo said on Sept. 10. The bill could reach Parliament in the third quarter of 2026 or, at the latest, the first quarter of 2027.”
Malaysia’s AI bill moves from consultation toward parliamentary consideration
Malaysia has completed its draft AI Governance Bill and is preparing to advance it through Cabinet and potentially Parliament, although the timetable and final institutional arrangements remain unsettled.
Previously
Malaysia is consulting on its first horizontal AI Governance Bill, proposing a Central AI Authority, risk-based duties, incident reporting, enforcement powers, and sandboxes across the AI lifecycle. Taiwan has already enacted an AI Basic Act and is distributing implementation across ministries, supported by risk-classification guidance and sector-specific rules. Together, the developments show national efforts to move from voluntary principles toward enforceable oversight while leaving important questions about institutional authority, high-risk systems, data governance, and implementation unresolved.
Malaysia’s initiative has advanced from consultation toward a completed draft bill, with parliamentary tabling now discussed for late 2026 or early 2027. The framework’s scope also becomes clearer by covering certain systems used by Malaysian deployers from abroad, while Taiwan’s implementation is largely reinforced rather than materially changed.
Taiwan’s framework has moved from an enacted model to active implementation, with ministries issuing risk guidance and applying governance questions to defense AI. This broadens the story from Malaysia’s proposal to the practical difficulties of implementing national AI oversight.
