THE world has not stopped talking about AI. From students to world leaders, everyone has something to say. We hear about massive investments, IPO hypes, and even the American president renaming it “Super Intelligence.” But amidst this global noise, what we really need to focus on is the impact of AI on our daily lives and our work. We need to talk seriously about AI governance.
Recently, I attended an event in Kuala Lumpur attended by senior corporate board members focusing on sustainability, governance and effective board strategies. This time, digital innovation and AI governance has become a central agenda. As someone deeply invested in this space, I was looking forward to hearing from the experts.
The government has proactively transformed the national AI office into a full-scale organization, AI Malaysia Berhad, which is a step in the right direction. Their early published guidelines and frameworks have been useful.
But my optimism quickly turned to concern.
During the event, the Director of Policy at AI Malaysia took the stage. Instead of a sober discussion on risk and accountability, he treated the audience to a 15-minute showcase where a part of the presentation is what I could only describe as a textbook case of Shadow AI.
He shared that he had developed a personal interest in AI agents, named them after characters from his favourite science fiction show, and gave them programmatic read-and-write access to his official work email. He then casually recounted a story of how one of these agents sent out emails without his express approval—bypassing his supposed “human-in-the-loop” rule. He described frantically checking his emails to see what else the AI had sent without his knowledge.
While some in the audience chuckled, I sat there shocked.
In my view, this was not just a private enthusiast tinkering in a sandbox. This was the head of policy for Malaysia’s leading AI agency, speaking to an audience whose main purpose was to improve governance, yet he was candidly sharing practices that highlight a significant operational risk without framing it in the context of strict enterprise compliance or monitoring.
When a private hacker does this, it is framed as scrappy learning. When a national policy director does it on a live corporate platform, documents it publicly, and shares it so casually, it risks undermining the organisation’s credibility and the standard of stewardship the public sector requires.
Key systemic vulnerabilities
A critical assessment points to potential vulnerabilities across governance, institutional risk, and professional ethics.
Potential Risk to Information and Data Governance: A director of policy receives highly sensitive correspondence—cabinet briefings, regulatory deliberations, draft policies, and confidential memos. Wiring an autonomous agent to this inbox potentially passes unstructured, sovereign data through third-party model APIs, which raises serious questions about basic data residency and confidentiality principles. Unless this agent underwent rigorous threat modelling and IT clearance, it functions as unvetted shadow automation executed by the very individual charged with shaping policy.
The Illusion of Control: Admitting that an AI sent an unreviewed email is not an amusing anecdote; it is a documented failure. Somehow causing an agent to take arbitrary outbound actions creates exposure to potential hallucinated commitments and accidental disclosures. If an agent misrepresents policy or defames a partner from an official address, the agency could bear full legal liability.
A Concerning Tone: Speaking highly of “digital coworkers” and treating them as named companions could obscure genuine accountability. Public sector AI leaders are tasked with instilling sober, risk-adjusted governance.
Blurring Personal Productivity and Stewardship: A policy executive’s primary deliverable is systemic integrity and institutional trust. Prioritising personal productivity hacks over corporate security suggests a blurring of lines between the duties of public office and the experiments of an unconstrained hobbyist.
If this setup were unaudited or did not pass governance, there is a strong likelihood that the mailbox integration would be flagged as an unauthorised security vulnerability, and the public sharing of such practices as an institutional reputation risk.
AI Malaysia and the director must come forward to clarify its internal policies, assure us that the agents complied with basic and fundamental audits before deployments.
We also need to be assured that regular reviews are made to avoid the possibilities of any agents turning “rogue” as demonstrated recently by some leading AI models.
Moving forward
As Malaysian organisations race to adopt AI, we must be far more knowledgeable and committed to real governance in an ever evolving, at times, unpredictable, technological landscape. Beyond these global noises, what we really need to focus on is the impact of AI on our daily lives and our work.
True leadership in our national AI strategy requires building reliable, transparent, accountable, and legally defensible systems that set a rigorous benchmark for the entire nation. Given the stakes of institutional trust and sovereign data security, AI Malaysia must do better. – October 3, 2026
KV Soon (Soon Koi Voon) is a Malaysian entrepreneur, digital transformation strategist and corporate advisor
