Governing AI Agents in Regulated Enterprises | Wiki Labs

Governing AI Agents in Regulated Enterprises: A Framework for Malaysian CIOs

August 19, 20269 min read

As Malaysian enterprises expand their use of generative and agentic AI, governance is becoming an increasingly important technology-risk consideration. For regulated organisations, the challenge is not only what an AI system can do, but also who approved it, what data and systems it can access, how its actions are monitored, and how accountability is maintained.

On 10 July 2026, Malaysia’s National AI Office opened public consultation on the proposed AI Governance Bill. The consultation has since closed, and the proposed framework remains under development. This guide looks at practical AI-agent governance considerations alongside AIGE, PDPA and Bank Negara Malaysia’s RMiT requirements where applicable.

What Governing AI Agents in Regulated Enterprises Takes

Governing AI agents in regulated enterprises means tracking what each agent accesses, who approved it, and what happens when it acts outside its scope. Unlike a conventional question-and-answer chatbot, an agentic AI system may be given tools, permissions and varying levels of autonomy to perform actions across enterprise systems. Governance for this kind of system covers three layers. Visibility into every deployed agent. Control over what data and systems each agent touches. A recorded trail proving why an agent did what it did.

AI governance should not remain only a policy exercise. For agentic systems, governance controls also need to be reflected in architecture, access management, monitoring and operational processes. Governing AI agents in regulated enterprises properly means building these three layers into the architecture itself, not adding them after deployment.

Malaysia's AI Governance Bill Changes The Timeline

Malaysia's AI Governance Bill Changes The Timeline
Prime Minister Anwar Ibrahim says a new AI Governance Bill is in the works to complement existing laws like the Cybersecurity Act and data protection regulations. Photo: NST

The National AI Office, known as NAIO, released its Public Consultation Paper on 10 July 2026, and feedback closes this month. The proposed Bill organizes risk into four harm categories: The consultation paper proposes a three-tier risk framework anchored to four baseline categories of harm: death, bodily injury, unlawful deprivation of fundamental liberty, and contravention of written law.

The proposed tiers are Unacceptable Risk, High Risk and Low Risk, with requirements intended to scale according to the nature, context and level of risk posed by the AI system. This structure marks the shift from voluntary guidance to enforceable law, and it changes what governing AI agents in regulated enterprises means for every CIO reading this now.

Malaysia’s National Guidelines on AI Governance and Ethics (AIGE), introduced in 2024, remain voluntary and set out seven responsible-AI principles, including fairness, reliability, privacy and security, transparency and accountability.

The proposed AI Governance Bill takes a related but distinct approach. It proposes five governance principles, namely human dignity, transparency and explainability, accountability, safety and security, and data governance, supported by a risk-based regulatory framework. If enacted, the Bill would introduce statutory AI-governance obligations rather than simply making the existing AIGE principles mandatory.

How Malaysia’s AI Governance Framework Is Developing

Malaysia’s AI governance landscape is developing through several complementary initiatives rather than a single sequential framework. AIGE provides voluntary responsible-AI guidance, while the MY-AI Standards platform provides access to recognised technical standards and implementation resources. The proposed AI Governance Bill would add a national statutory framework if enacted.

Organisations in regulated sectors must also continue to consider existing requirements that already apply to them, including BNM RMiT for relevant financial institutions and the PDPA where personal data is processed.

Where AIGE Ends And The New Rules Begin

AIGE still applies today, and every enterprise governing AI agents in regulated enterprises should treat its seven principles as the working baseline until the AI Governance Bill passes. The difference going forward sits in enforcement. AIGE asked organizations to self assess. The proposed Bill assigns statutory obligations by risk tier, with incident reporting expected through a central portal once the framework takes effect.

Baker McKenzie's legal analysis of the NAIO consultation paper notes organizations should use this feedback period to position themselves ahead of the compliance requirements rather than wait for the final text. Governing AI agents in regulated enterprises now means planning for both frameworks running in parallel during the transition.

Five Control Domains For Governing AI Agents In Regulated Enterprises

Five Control Domains For Governing AI Agents In Regulated Enterprises

A practical enterprise framework for governing AI agents can be organised around five control domains. These are not the formal control categories of the proposed AI Governance Bill, but they provide a useful operating model for translating governance principles into technical and operational controls. Governing AI agents in regulated enterprises means treating all five domains as one connected system, not five separate checklists.

Centralized Agent Inventory

Maintain one live registry of every deployed agent, the systems it touches, and the model behind it. Maintain a current inventory of deployed agents, their owners, intended purpose, underlying models, connected systems and approval status. This gives governance and security teams a clear starting point for risk assessment and review.

Runtime Data Access Boundaries

Define what data each agent is permitted to read, write or transmit, and enforce access according to approved purpose and least-privilege principles. Where personal data is processed, the relevant PDPA requirements should be incorporated into the access and data-handling design.

Identity And Permission Scoping

Each agent needs its own identity, not a borrowed login from the employee who built it. Shared credentials remove the ability to trace which agent performed which action.

Audit Trails And Decision Accountability

Maintain audit records appropriate to the risk of the system, including relevant inputs and outputs, tool calls, actions taken, approvals, access events and material configuration or model changes. Regulators reviewing an incident will ask for this record first, and an incomplete trail counts against you even if the agent behaved correctly.

Kill Switches And Purpose Binding

Define a suspension or manual-override process for agents that operate outside their approved purpose or risk tolerance. Test the process periodically and after material changes so that it remains usable when an incident occurs.

What Changes For BNM Regulated Institutions

The July 2026 RMiT FAQ specifically identifies Generative AI and Agentic AI as examples of emerging technologies

BNM-regulated financial institutions have an additional technology-risk layer to consider. The July 2026 RMiT FAQ specifically identifies Generative AI and Agentic AI as examples of emerging technologies. Under the revised RMiT framework, first-time adoption of emerging technology for critical systems is subject to consultation with BNM, supported by risk assessment and governance requirements. Subsequent adoption may be subject to notification requirements depending on the circumstances.

RMiT also requires financial institutions to establish governance, acceptance criteria, monitoring and risk controls for emerging technologies, and to be prepared to suspend their use when extreme events occur. AI-agent governance should therefore be integrated into the institution’s existing technology-risk framework rather than treated as an isolated policy exercise.

A Rollout Framework For Governing AI Agents In Regulated Enterprises

Governing AI agents in regulated enterprises follows a clear sequence, not a checklist completed all at once.

  1. Build the inventory first. List every agent already running before adding controls around agents you have not yet found.

  2. Map each agent against the five control domains and flag every gap.

  3. Prioritise agents with the greatest potential business, customer, regulatory or operational impact. This may include agents handling sensitive or personal data, influencing financial decisions, accessing critical systems, or operating with broader autonomous permissions.

  4. Build the audit trail and kill switch before expanding an agent's permissions further, not after.

  5. Review the governance framework periodically and whenever there is a material change to the agent, model, connected systems, permissions, applicable regulation or risk profile. Continue monitoring developments in the proposed AI Governance Bill as the framework moves beyond public consultation.

Final Considerations

AI-agent governance is becoming a more immediate consideration for Malaysian enterprises as agentic systems gain greater access to data, applications and operational processes. Organisations do not need to wait for the final AI Governance Bill before establishing basic controls such as ownership, access boundaries, monitoring, auditability and suspension procedures.

AIGE can provide a voluntary responsible-AI reference point today, while organisations should continue complying with the laws and sector-specific requirements already applicable to them, including PDPA and BNM RMiT where relevant. The proposed AI Governance Bill should be monitored as its final scope and obligations continue to develop.

Start Your AI Governance Assessment

Wiki Labs Sdn Bhd helps Malaysian enterprises build the inventory, access controls, and audit trails governing AI agents in regulated enterprises requires, mapped against RMiT and PDPA from day one.

Custom HTML/CSS/JavaScript

WikiBlox: What You Should Know

WikiBlox is the platform Wiki Labs runs a rebuilt SOE on, not a separate product added after migration. It combines Red Hat OpenShift with Lenovo hardware and AMD EPYC processors, hosted and supported inside Malaysia. Every WikiBlox deployment ships with a golden image pipeline built in, so a rebuilt SOE inherits standardized hardening and version control from the first day instead of waiting on a second project to add it.

Because WikiBlox runs on OpenShift Virtualization, the golden image work covered in this playbook maps directly onto the platform your team is already committed to. Teams rebuilding their SOE this way skip the gap between choosing a platform and proving it meets RMiT and PDPA controls, since both get validated together instead of as two separate workstreams.


How Wiki Labs Helps Manage Virtualisation Costs

Wiki Labs Sdn Bhd provides full-lifecycle services for enterprise virtualisation, from assessing existing VMware environments to designing migration frameworks and optimising operations post-deployment.

Through cost-transparency analysis, predictable licensing models, and Malaysia-based support, Wiki Labs helps organisations identify and reduce hidden expenses associated with legacy systems. Its consultants offer clear insights into the total cost of ownership across leading VMware alternatives, ensuring each client selects the most cost-effective and scalable approach for long-term growth.

With deep local expertise and platform-agnostic hardware integration, Wiki Labs enables Malaysian enterprises to achieve operational clarity and sustainable cost efficiency in their modernisation journey.


Ready to Move Forward with Modern VMware Alternatives?

WikiBlox isn’t just another platform. It’s your all-in-one foundation for Malaysia’s enterprise IT future.

👉 Schedule a free consultation with Wiki Labs experts today to see how WikiBlox can power your transformation.

Custom HTML/CSS/JavaScript

Disclaimer:

The information in this article is provided for general informational purposes only. All product names, trademarks, and registered trademarks are the property of their respective owners. References to third-party technologies such as VMware, Red Hat, Lenovo, AMD, and others are made solely to describe compatibility or comparison context and do not imply any endorsement or affiliation.

Wiki Labs Sdn Bhd makes reasonable efforts to ensure the accuracy of information at the time of publication; however, readers are encouraged to verify technical details and licensing information directly with the respective vendors.

Custom HTML/CSS/JavaScript
Back to Blog