Two colleagues discussing a tablet at a standing desk

AI regulation in Southeast Asia, for the CEO.

Singapore has a framework for agents. Malaysia is drafting a law.

In short

Southeast Asia is moving from voluntary AI guidance towards enforceable rules. Enterprises should build governance once, to the strictest market they operate in.

Executive briefing · By Aaron Goh, CEO, Azend Group · 2 October 2026 · 3 min read

For most of the last decade, AI rules in Southeast Asia were principles: fair, explainable, human-centred. Useful, but easy to file and forget. That is changing. Two of the region's most active markets are now writing guidance and law aimed at how AI is actually used, including agents that act on their own.

What has Singapore done?

On 22 January 2026, Minister Josephine Teo announced Singapore's Model AI Governance Framework for Agentic AI at the World Economic Forum. Developed by IMDA, it covers four dimensions: bounding risks upfront by choosing suitable use cases and limiting agents' powers; making humans meaningfully accountable through checkpoints for approval; technical controls across the agent lifecycle; and end-user responsibility through transparency and training. It is a framework, not a law, but it is the clearest statement yet of what a regulator expects.

What is Malaysia doing?

KPMG in Malaysia reports that the Ministry of Digital is drafting an AI Governance Bill to move from voluntary guidance to enforceable obligations across the AI lifecycle, including risk classification, harm assessment and incident reporting. The MY-AI Standards platform, launched on 10 March 2026, gives access to more than 80 international ISO/IEC AI standards. All of this sits alongside the amended PDPA, which already governs the customer data your AI uses.

Build governance once.

One control set that maps to Singapore's framework and Malaysia's direction.

01INVENTORYEvery AI tool and agentOwner and purpose 02CLASSIFYRisk and autonomy levelData each one reads 03CONTROLApproval checkpointsLogs and an off switch 04EVIDENCEIncident runbookRecords a regulator reads INVENTORY01Every AI tool and agentOwner and purpose CLASSIFY02Risk and autonomy levelData each one reads CONTROL03Approval checkpointsLogs and an off switch EVIDENCE04Incident runbookRecords a regulator reads

An Azend framework, drawing on the dimensions in IMDA's agentic AI framework and KPMG's summary of Malaysia's draft bill.

What about the rest of the region?

Every market moves at its own pace. The practical answer for a regional enterprise is not to track every draft. It is to build one set of controls to the strictest standard you face, then map each market to it. This briefing is operational guidance, not legal advice; confirm your position with counsel in each market.

What does a regulator-ready setup look like?

  • A register of every AI tool and agent, its owner and its purpose.
  • A risk and autonomy level for each, with matching controls. See governing agents by autonomy level.
  • Human checkpoints, written down, for decisions that affect customers.
  • Logs of what agents read and did, so you can reconstruct an incident.
  • Data protection by design, built to each market's law. See our data protection answer.

Is this a reason to slow down?

No. Clear rules make it easier to say yes. A board that can see the register and the controls approves agents faster, and customers trust them sooner. Enterprises that wait for final laws will be retrofitting controls onto agents already in production, which is slower and costs more.

Where does customer data fit?

At the centre. Most enterprise AI in revenue and service teams reads personal data: names, numbers, purchase history, messages. Data protection law already applies to all of it, whatever happens to the new AI bills. In practice, the cleanest way to meet both is one customer record with clear consent, known access and a log of what each agent touched. Customer data scattered across spreadsheets, messaging phones and old systems is hard to govern for people, and harder for agents. Consolidating it is good compliance as well as good AI. Our CRM and data platform work builds exactly this, to each market's data protection law.

What to do on Monday.

  1. Ask who owns AI governance. If the answer is unclear, name one executive.
  2. Start the AI register this month, beginning with customer-facing agents.
  3. Have legal map your controls to Singapore's agentic AI framework as a working benchmark.
  4. Ask your platform and implementation partners how they log and limit agent actions.

Questions.

What is Singapore's Model AI Governance Framework for Agentic AI?

Guidance developed by IMDA and launched in January 2026. It covers bounding risks upfront, human accountability through approval checkpoints, technical controls across the agent lifecycle and end-user responsibility.

Does Malaysia have an AI law?

Not yet. KPMG reports the Ministry of Digital is drafting an AI Governance Bill covering risk classification, harm assessment and incident reporting.

Make governance part of the build.

A strategy call maps your AI tools and agents against the rules in each market you serve.