For most of the last decade, AI rules in Southeast Asia were principles: fair, explainable, human-centred. Useful, but easy to file and forget. That is changing. Two of the region's most active markets are now writing guidance and law aimed at how AI is actually used, including agents that act on their own.
What has Singapore done?
On 22 January 2026, Minister Josephine Teo announced Singapore's Model AI Governance Framework for Agentic AI at the World Economic Forum. Developed by IMDA, it covers four dimensions: bounding risks upfront by choosing suitable use cases and limiting agents' powers; making humans meaningfully accountable through checkpoints for approval; technical controls across the agent lifecycle; and end-user responsibility through transparency and training. It is a framework, not a law, but it is the clearest statement yet of what a regulator expects.
What is Malaysia doing?
KPMG in Malaysia reports that the Ministry of Digital is drafting an AI Governance Bill to move from voluntary guidance to enforceable obligations across the AI lifecycle, including risk classification, harm assessment and incident reporting. The MY-AI Standards platform, launched on 10 March 2026, gives access to more than 80 international ISO/IEC AI standards. All of this sits alongside the amended PDPA, which already governs the customer data your AI uses.




