Developer vs Deployer — the split that matters. A Developer trains or builds an AI system. A Deployer puts one into use. If your clinic runs a WhatsApp chatbot, if your F&B business uses ChatGPT for ad copy, if your ecommerce site uses a recommendation engine — you are a Deployer, not a Developer. The Tier 2 obligations sit on you.
What the Bill actually proposes
NAIO\'s consultation paper sets out five proposed principles: Human Dignity, Transparency and Explainability, Accountability, Safety and Security, and Data Governance. Obligations scale by tier. Tier 1 is light-touch. Tier 2 is where substantive duties sit — risk assessment, documentation of intended use, internal controls, human oversight, monitoring in production, and mitigation of harms as they surface.
The Bill is a proposal, not law. The consultation closed 31 July 2026. The Bill is targeted for completion by end of 2026 but the passage date is not fixed. Two facts, however, are already stable enough to plan against: the Developer/Deployer split is core, and Tier 2 obligations sit primarily on Deployers.
Why almost every Malaysian SME is a Deployer
Read the definition literally. A Developer trains, builds or materially fine-tunes an AI system. A Deployer procures one and puts it into operational use in their business. A Malaysian clinic that installs a chatbot to answer patient enquiries is not a Developer of the underlying LLM — they are deploying it. A Petaling Jaya boutique using an off-the-shelf ad-copy generator is deploying it. A Klang F&B chain using an AI recommendation engine on their website is deploying it.
The published Malaysian legal-alert coverage — Baker McKenzie / Wong & Partners, Rahmat Lim & Partners, both July 2026 — has been aimed at Developer-facing clients (regional tech companies, model providers). The Deployer side has been left to inference. That is the gap this post is written to close.
Practical Deployer checklist for a 5–20 person Malaysian business
Not every item below will be law when the Bill passes. This checklist is the minimum defensible position under the proposed Tier 2 framework, and every item is defensible today under the existing PDPA (Amendment) Act 2024 and platform terms.
- Keep a written inventory of every AI system you use. One row per tool: vendor, purpose, data it touches, who inside the business owns it. If you cannot name your AI tools on one page, you cannot risk-assess them.
- Do a risk assessment per system. What decision does the AI influence? What happens if it is wrong? Who is affected? A chatbot that quotes prices carries different risk from one that answers "what are your opening hours".
- Document intended use. Write down what the tool is for and — importantly — what it is not for. Staff will use tools for what you let them use them for; the Bill\'s "intended use" language means undocumented drift is your problem, not the vendor\'s.
- Human oversight on any decision that affects a customer. AI-suggested pricing gets reviewed by a human before it goes out. AI-drafted ad copy gets reviewed for KKM/MDC compliance (see below) before publish. The oversight itself must be documented — a review that leaves no record is not oversight.
- Monitor the outputs in production. A chatbot that started answering correctly can drift. Sample 20 conversations a month. Record what you found.
- Have a mitigation path. If the AI produces something harmful — an incorrect price, a claim you cannot substantiate, a leak of information it should not have — you need to know who turns it off, who tells the customer, and who logs the incident.
- PDPA data-flow: know where the input goes. When a patient types a symptom into your clinic\'s chatbot, that data leaves your control the moment it hits the vendor\'s API. The PDPA (Amendment) Act 2024\'s mandatory breach-notification obligation applies to you, not to the model provider.
The Gobind carve-out: AI-generated content is not regulated by the Bill
On 24 June 2026, Digital Minister Gobind Singh Deo told Parliament the Bill would not regulate AI-generated content directly. That is important and counter-intuitive. It means that when your business runs an AI ad-copy generator for a Malaysian clinic, the copy is not exempt from anything — it just remains governed by the existing KKM/MDC advertising rules, unchanged, with no AI carve-out. See our detailed post on AI-generated ad copy under KKM/MDC rules.
What to do this quarter
The Bill is not law yet. But four practical steps have zero downside and every upside:
- Write the AI inventory. One page. Now.
- Nominate an internal AI owner. A specific human, not "IT".
- Read the PDPA implications for AI marketing tools if you handle any personal data.
- Check ad-copy tools against the KKM Ad Checker before publishing anything AI-drafted.
References
- National AI Office (NAIO), Public Consultation Paper on the AI Governance Bill, 10 July 2026 — ai.gov.my
- Baker McKenzie / Wong & Partners client alert, "Malaysia\'s Proposed AI Governance Framework", July 2026
- Rahmat Lim & Partners client alert on the AI Governance Bill, July 2026
- Hansard, Parliamentary reply by Minister Gobind Singh Deo, 24 June 2026