
KUALA LUMPUR (Aug 5): Bank Negara Malaysia (BNM) on Tuesday published a discussion paper seeking feedback on its proposed regulatory framework for artificial intelligence (AI) adoption in the financial sector.
The central bank said the paper details its proposed approach to AI regulation and development, aimed at enhancing consumer outcomes, while supporting broader policy goals.
“We are open to innovation that brings genuine value to the economy and supports productive use cases,” BNM governor Datuk Seri Abdul Rasheed Ghaffour said.
“But we also remain cautious of developments that introduce risk, or operate outside the safeguards needed to preserve financial stability and public trust,” he said in his keynote address at MyFintech Week 2025.
BNM is inviting written feedback on the issues raised in the paper, including suggestions for alternative proposals and areas requiring further clarification. Feedback should be supported with clear rationale, evidence, or illustrative examples.
All responses must be sent via email to [email protected] by Oct 17, 2025.
Abdul Rasheed said that BNM will also issue an exposure draft on open finance and discussion paper on asset tokenisation by year-end.
According to the governor, the exposure draft on open finance aims to support a secure data-sharing framework based on customer consent.
Meanwhile, the discussion paper on asset tokenisation will explore potential use cases, outline key risks, and propose safeguards to ensure the safe and effective integration of tokenisation in financial markets.
Through open finance, a customer may give permission to third-party service providers to access banking details directly through open application programming interfaces (APIs), and opens the door for the creation of differentiated products and services that let consumers manage their financials, such as under one single platform.
Tokenisation is the creation of a digital placeholder to represent something else — such as converting a sensitive data into non-sensitive digital token that can be handled safely by third parties, while allowing it to be mapped back to the original data.