01

Policy and legal terms

These terms come from Malaysian law and policy directly. Each is discussed in more depth in the field note noted alongside it.

  • AIGE. Malaysia’s National Guidelines on AI Governance and Ethics, a voluntary seven-principle framework published by the Ministry of Science, Technology and Innovation in September 2024.
  • PDPA. The Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024, Malaysia’s general data protection law.
  • DPO. Data Protection Officer, mandatory under the amended PDPA for organisations meeting defined data-volume or monitoring thresholds, registered within 21 days of appointment.
  • TIA. Transfer Impact Assessment, the documented basis required to transfer personal data to a jurisdiction on the ground of substantially similar protection, valid for three years under Malaysia’s 2025 cross-border transfer guidelines.
  • AI Governance Bill. The proposed Artificial Intelligence Governance Bill that Malaysia opened for public consultation in July 2026, not yet enacted law.
02

Standards and frameworks

These are not Malaysian law, but they are the reference points most often used to give a governance claim a testable meaning.

  • NIST AI RMF. The US National Institute of Standards and Technology’s AI Risk Management Framework, whose GOVERN function sets out accountability structures and human oversight requirements widely referenced outside the United States.
  • ISO/IEC 42001. The first international standard for AI management systems, specifying requirements for governing AI development, provision and use through a plan-do-check-act cycle.
  • MCCG. The Malaysian Code on Corporate Governance, which the Securities Commission proposed in 2026 to extend with board-level AI and technology oversight expectations for listed companies.
03

System and architecture terms

These describe how a governed AI system is typically built, independent of any specific vendor.

  • Governed memory layer. An architecture where approved organisational knowledge becomes permission-aware memory, so a person or agent can retrieve only what their active scope allows.
  • Permission-aware retrieval. Search or retrieval that is scoped to the requesting identity’s access rights, rather than querying the same index for every user regardless of role.
  • Model routing. Directing a given request to a specific approved language model, based on the request’s sensitivity, cost or capability needs, rather than sending everything to a single fixed model.
  • RAG. Retrieval-augmented generation, where a language model’s answer is grounded in retrieved documents or data rather than relying only on what the model learned during training.
  • System register. An inventory of every AI system in use, including its business owner, data categories, connected tools and current approval status.
04

Oversight and control terms

These describe the mechanisms that keep a consequential AI action under human authority.

  • Human-in-the-loop. A design in which a person must review or approve an AI-driven action before it takes effect, at least for actions above a defined consequence threshold.
  • Approval gate. A checkpoint that pauses an agent’s proposed action until a named reviewer approves it, with a validity window and a logged denial path.
  • Audit trail. A record connecting an AI system’s identity, active scope, retrieved sources, model version, action and outcome, sufficient to reconstruct a single decision after the fact.
  • Agentic AI. AI systems that can take multi-step action toward a goal, such as researching, drafting and executing tasks, rather than only answering a single query.
05

Enforcement and risk terms

These describe what happens when governance fails, and what regulators ask for when it does.

  • DPIA. Data Protection Impact Assessment, a structured evaluation of privacy risk before deploying a system that processes personal data at scale.
  • Breach notification. The obligation to inform a regulator, and in serious cases affected individuals, within a fixed period after discovering a personal data breach; 72 hours to the Malaysian regulator, and 7 further days to affected individuals where significant harm is likely.
  • Statutory penalty tier. A fixed maximum fine and imprisonment term set by law for an offence, as distinct from a revenue-percentage penalty such as the EU AI Act’s up to 7% of global turnover.
  • Incident reconstruction. The process of assembling the identity, data access, model version and human decisions behind a specific AI-driven outcome after something has gone wrong.
PRIMARY SOURCES

Official references.

These field notes interpret official materials for enterprise teams. They are not legal advice.