Data Breaches and The Corporate Trust Deficit

DATA BREACHES AND THE CORPORATE TRUST DEFICIT

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

For Malaysians, the cycle has become exhaustingly predictable. From massive ransomware attacks crippling statutory bodies to recent headlines of internal employees casually leaking sensitive customer billing details online, the public is caught in a continuous loop of data compromises.

While the nature of these threats varies wildly—ranging from highly sophisticated, AI-driven external cyberattacks to rudimentary internal snooping—the corporate response is almost always identical. The public is inevitably met with a standard public relations script: the company assures us it was an “isolated incident,” claims no broader systems were compromised, and reiterates that they take data privacy “very seriously.”

However, as these incidents compound, a critical legal and governance question must be asked: How can the public independently verify these claims? When a breach occurs, how do we know if the data controller truly implemented all necessary and reasonable security measures prior to the failure, or if their architecture was fundamentally inadequate from the start?

This is particularly relevant when examining insider threats. If a company’s system architecture allows an employee to casually browse a customer’s sensitive billing or identification details without a verified, logged business justification, it points to a systemic failure in basic internal access controls. If an organisation fails to implement fundamental “Zero Trust” protocols internally, it is difficult to trust their capacity to defend against complex, external cyber threats.

Recognising the importance of these risks, the Personal Data Protection Department (JPDP) earlier this year issued guidelines on Data Protection by Design (DPbD) and Data Protection Impact Assessments (DPIA).

These guidelines should not be treated as mere administrative guidance. DPbD encourages organisations to build privacy safeguards into their systems from the outset, rather than addressing weaknesses only after deployment. Where proposed data processing is likely to pose a high risk, the DPIA requires data controllers to identify, assess and reduce those risks before processing begins.

Yet, the persistent pattern of data leaks suggests that much of corporate Malaysia is treating these critical guidelines as mere paperwork exercises to be filed away, rather than architectural mandates to be engineered into their daily operations.

We cannot continue to accept a culture where data security is only prioritised after a crisis has occurred. Suing a rogue employee or issuing an apology after data has already surfaced online or on the dark web is purely reactive.

To break this loop, regulatory oversight must fundamentally shift. Regulators must move beyond issuing post-incident fines and begin conducting proactive, unannounced audits of corporate access controls. Data controllers must be compelled to actively demonstrate exactly how data protection principles are hardcoded into their systems.

Until companies are held accountable for their internal architecture before a breach happens, the public will remain vulnerable to the next “isolated incident.”

Written By:

Thulasy Suppiah,
Managing Partner,
Suppiah & Partners,

UG-13, Lexa Galleria, 45, Jalan 34/26,
Wangsa Maju, 53300 Kuala Lumpur.
Handphone no: 012-4915238

© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Newsletter

Warfare has a new face, and it’s powered by AI

Warfare has a new face, and it’s powered by AI

How hyper-fast, low-cost AI systems are completely upending traditional military math, economies and legal frameworks

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

Introduction

The world’s first fully autonomous attack mission using Artificial Intelligence (AI), happened in the fall of 2023. The Ukrainian Ministry of Defense officially approved the Saker Scout – an autonomous weapon system – to complete the final strike phase of a mission, completely cut off from its human handlers.

The system was developed in response to the intense electronic warfare (EW) landscape in Ukraine’s eastern Donbas region. Russian forces deployed massive jamming networks, such as the Pole-21 and Zhitel systems, which blanked out the radio and GPS signals Ukrainian drone pilots used to navigate.

The Saker Scout is a First Person View (FPV) kamikaze quadcopter drone. If heavy jamming breaks the connection to its pilot, its onboard computer-vision software fully takes over to identify, track, and detonate on military targets without human intervention.

Militaries are constantly looking for flawless partners in war, and they may have found it.

The Spark of a New Revolution

The integration of AI into military hardware has sparked a third revolution in warfare. Unlike the nuclear arms race, which relied on building expensive stockpiles, the AI arms race is defined by software, processing speed, and the mass production of cheap, autonomous systems.

By using Decision Support Systems (DSS) such as the Pentagon’s Maven Smart System integrated with advanced large language models, forces can process massive amounts of targeting data in minutes rather than days. This efficiency has triggered a global rush to develop AI-based targeting weapons, pushing global military spending to $2.88 trillion (RM 11.38 trillion) in 2025—a 41 per cent increase over the last decade.

The real-world impact of this technology was demonstrated during the recent US war against Iran. Powered by AI-driven DSS, the US hit more targets in the first four days of the campaign than it did against ISIS over an entire six-month period. In total, the US struck 13,000 targets in just 38 days, including thousands of command centres and air defences. While these systems promise unprecedented tactical results, their speed and automation raise troubling ethical questions.

The Fundamental Problem

Today’s arms race is uniquely destructive because cheap, asymmetric technology (like inexpensive drones) forces defenders to buy increasingly complex, multi-million-dollar countermeasures. This locks nations into an unsustainable economic spiral where billions are spent defending against cheap threats, completely freezing capital needed to solve existential global crises.

The direct diversion of capital from human welfare to weapons is a primary ethical critique of military spending as just a fraction of this, roughly USD$150 billion to USD$200 billion (RM593 billion to RM791 billion) annually, could eradicate global hunger, provide clean water, and fund universal primary education. Economists and humanitarians warn that this aggressive rearmament creates a moral deficit by diverting vital resources away from pressing global crises.

Additionally, traditional military targeting involved rooms full of human intelligence analysts manually comparing satellite photos with radio log. It’s a process that takes hours, days, or weeks. The AI compresses this OODA Loop (Observe, Orient, Decide, Act) into seconds.

When systems process data instantly, the quantity of targets skyrockets. The resulting dilemma? The logic shifts from human-driven intuition to machine-driven pattern recognition. If a human analyst is handed 500 machine-generated targets a day rather than 5, they no longer have the time to deeply question the data. This creates a severe risk of automation bias where human operators simply trust what the algorithm tells them, treating a highly complex probability estimate as an absolute fact.

Finally, the concept of faster escalation cycles due to machine-speed reactions describes a dangerous military feedback loop. When opposing militaries both deploy AI to make decisions, the speed of conflict shifts from human speed (minutes, hours, or days) to algorithmic speed (milliseconds).

What happens if one AI system misinterprets an action and reacts instantly? The opposing AI will react to that reaction just as quickly. Before human commanders can even figure out what is happening, a minor misunderstanding can spiral into a major conflict.

Ethical and strategic risks

The new global AI arms race is making the world much more dangerous in three simple ways. First, it creates a stockpile problem: because AI can find thousands of targets in seconds, armies are rapidly running out of real-world missiles and drones to actually hit them. This forces factories into a frantic race to build more weapons. Second, it destabilises hidden defences: because AI can instantly map out an enemy’s hidden bases or submarines, countries feel completely exposed, forcing them to build thousands of fake decoys and extra weapons just to survive a surprise attack. Finally, it breaks peace treaties: traditional peace deals only work when you can count an enemy’s tanks or ships on a satellite map, but you cannot count or see a hidden AI computer code, making it almost impossible for nations to agree on safety rules.

Today, global stability no longer rests on how many weapons a country possesses but on who has the fastest data networks and the most aggressive code. In the current environment, every military power feels deeply exposed, creating intense, unremitting pressure to strike first before the enemy’s algorithm beats them to the punch.

As the Australian Institute of Internation Affairs noted, “A world where no one feels safe cannot be stable. It is not in the national interest of any state to create an environment of continuous arms racing and nuclear buildup.”

Impact on Smaller or Less Powerful Nations

AI tools (especially open-source models and commercial drones) make it easier for smaller states – or even non-state actors, to develop meaningful military capabilities. This has caused a cost asymmetry advantage. Across the region, inexpensive drones and missiles are forcing the US and its Gulf partners to expend their most sophisticated, high-cost air defences.

While an Iranian Shahed-136 one-way attack drone costs a mere USD$20,000 to USD$50,000 (RM79,092 to RM197,730), intercepting it frequently requires multi-million-dollar munitions. A single Patriot interceptor costs roughly USD$4 million (RM15.82 million), while a THAAD missile ranges from USD$12 million to USD$15 million (RM47.46 million to RM59.32 million). That over 200 Ukrainian specialists are now advising the US military on how to intercept Iran’s Shahed drones without firing Patriot missiles that cost 200 times more, proves that the era of modern drone warfare has arrived – and the US is lagging behind.

Iran does not just use these weapons directly; it exports the low-tech blueprints, commercial components, and localised manufacturing capabilities to non-state proxies like the Houthis in poverty-stricken Yemen and militias in Iraq. Using Iranian-supplied, low-cost drone and anti-ship missile kits, the Houthis successfully disrupted global shipping lanes for years.

Iran is also able to frequently bypass sanctions because the components they require are entirely civilian. Recent intelligence disclosures showed the Islamic Revolutionary Guard Corps (IRGC) using front companies in global trade hubs to procure commercial Chinese satellite communication gear and antenna accessories.

By integrating commercial guidance systems with open-source machine learning models, Iran can upgrade unguided rockets into precision-guided weapons without needing a multi-billion-dollar military-industrial complex.

AI in warfare reshapes the global balance in ways that sometimes place smaller or developing countries at an advantage. However, top-tier AI systems still require infrastructure, talent, and data – areas dominated by countries like the United States, Russia and China.

Increased vulnerability through automated threats

Automated cyberattacks have eliminated human fatigue by operating continuously at scale, requiring only a single success to breach networks at zero cost to attackers. This dynamic severely disadvantages smaller economies. They lack the budget and expertise to counter autonomous algorithms that scan public infrastructure and exploit flaws faster than human defenders can patch them. A striking precedent occurred between December 2025 and February 2026, when a lone hacker bypassed the safety filters of commercial models like Claude Code and GPT-4 to deploy over 5,000 automated commands against Mexico. This single AI-driven campaign rapidly exfiltrated 150 gigabytes of data, compromised the identities of 195 million citizens, and breached the federal tax authority, to prove that outdated state networks are utterly unable to cope with the velocity of modern AI intrusions.

Cascading Infrastructure Risk

Critical infrastructure like banks, power grids, and satellite communications increasingly relies on interconnected third-party software. This leaves less-protected nations with systemic exposure. While a fully autonomous, purely AI-generated supply-chain attack has not yet been publicly documented, a landmark precedent exists: the 2017 NotPetya cyberattack. State-sponsored hackers hijacked a mandatory Ukrainian accounting software update (M.E.Doc), and unleashed a destructive data-wiping worm. Within hours, the infection spread globally via interconnected corporate networks. It crippled shipping giant Maersk, froze multinational logistics and pharmaceutical systems, and disabled radiation monitoring at Chernobyl. It resulted in USD$10 billion (approximately RM39.7 billion) in global damages.

NotPetya remains the most destructive cyberattack in history and offers a terrifying blueprint if augmented by AI.

Dependence on external technology

Many nations lack the domestic infrastructure to build sovereign artificial intelligence models, forcing them to rely on AI ecosystems developed by foreign tech giants. This creates dependency, transforming commercial software agreements into national security risks. As AI models function as black boxes hosted on external cloud servers, client states have zero visibility into the underlying source code. This exposes them to structural vulnerabilities, such as digital backdoors, intentional data exfiltration, or sudden supply-chain termination. If geopolitical tensions flare, a foreign provider can simply cut off access to the cloud infrastructure, instantly blinding a nation’s automated logistical, banking, or administrative networks.

Following international sanctions stemming from the war in Ukraine, major Western tech giants such as Microsoft, Amazon Web Services (AWS), Google Cloud, and enterprise software giant SAP, systematically cut off access to their cloud platforms in Russia. Tens of thousands of businesses and organisations were given strict deadlines before their data access was permanently terminated. Amidst the chaos, businesses were forced to migrate to inferior domestic software alternatives.

Another stark example of strategic supply-chain termination, is the US using export controls to cripple its adversaries’ AI capabilities. Washington forced Dutch firm Advanced Semiconductor Materials Lithography (which monopolises advanced chip-lithography machines) and the Taiwan Semiconductor Manufacturing Company (the world’s largest advanced contract chipmaker) to instantly halt sales and servicing to Chinese tech companies and data centres. Consequently, nations dependent on Western-licensed hardware were frozen out of the computing power required to build or maintain cutting-edge AI models. It exposed the extreme risk of relying on a supply chain controlled by a foreign superpower.

Economic trade-offs

Governments with constrained budgets must balance the exorbitant cost of investing in AI defence capabilities against immediate domestic needs like healthcare, education, and economic development. AI infrastructure requires massive capital investments in high-performance data centres, microchips, and specialised tech talent. Funding such systems starves essential public services. But to focus resources entirely on social infrastructure creates compounding military risks.

This leaves developing countries trapped in a brutal financial tug-of-war. For example, Kenya recently had to choose between spending its limited cash to fight a massive wave of cyberattacks, or funding schools, hospitals, and food amidst public protests over the high cost of living. If a government picks cyber-defence, its citizens may riot over the lack of public services. But if it ignores the cyber threats, hackers can instantly freeze the country’s banks and power grids. This leaves poorer nations in a dangerous loop: they cannot afford to buy modern AI defences, but they cannot afford to ignore them either. Truly, modern AI-driven rearmament forces developing economies into a destabilising financial paradox.

Exposure to information warfare

According to the World Economic Forum’s Global Risks reports, mis- and disinformation are now ranked among the highest short-term global threats precisely because they allow cash-strapped or isolated regimes to strike at the societal core of democratic nations for pennies on the dollar.

Imagine if a bully didn’t have to fight you physically, but could instead instantly whisper a different, perfectly tailored lie into the ear of every kid in school to make them turn on each other. That is exactly what AI-driven information warfare does on a global scale.

By using advanced AI tools, bad actors or rival countries can create incredibly realistic fake videos, audio clips, and social media posts for almost zero cost. Instead of trying to convince everyone of one big lie, they create a digital fog of thousands of small lies designed to target specific arguments people are already having. This makes it impossible for citizens to agree on what is actually real.

While big, wealthy countries have the money and technology to build digital shields to spot and flag these fakes, smaller or less-developed nations often do not. They might not have strong local news stations to double-check the facts, or the right laws to police social media networks. As a result, an attacker can cheaply throw an entire country’s elections or government into total chaos without ever using a real weapon.

Regulatory and governance challenges

Smaller nations face severe regulatory and governance challenges in the age of AI, primarily operating as rule-takers rather than rule-makers. As global frameworks and compliance standards are dictated almost entirely by major powers and supranational bodies like the European Union or NATO, smaller states are forced to adopt external regulations that may not align with their domestic interests. Further, politically fragile states frequently lack the internal institutional capacity and legal frameworks required to regulate and secure AI within their own national defence sectors, leaving them structurally dependent on foreign superpowers.

Conclusion

The idea of introducing thinking machines into war is not new, and attempts have been made by militaries since World War II with little result. Then, innovations in microchips made it possible to introduce microprocesses into military weaponry. This resulted in precision guided munitions that could hit targets on their own once fired but also in systems that could fire automatically. Many US-built legacy systems, such as the Navy’s Close-In Weapon System (CIWS), smart anti-ship mines, and the Army’s Patriot Air Defence System, can engage targets autonomously once activated. Yet, none contain AI, and no one would accuse them of “thinking”. Their logic is entirely predictable, and they operated for decades without triggering global alarm.

Now, something has changed. The inclusion of AI into military systems has shifted the paradigm from mere automation to true machine autonomy, enabling weapons to select, track, and engage targets using algorithms that operate beyond direct human oversight and predictability. This is immoral and a grave threat to national and global security. As algorithms are incapable of comprehending the value of human life they should never be empowered to decide who lives or dies.

The United Nations Secretary General António Guterres agrees that “machines with the power and discretion to take lives without human involvement are politically unacceptable, morally repugnant and should be prohibited by international law.”

Allowing algorithms to decide when to use lethal force also raises significant questions about who is ultimately responsible and accountable.  

What’s scary is experts – including the heads of OpenAI and Google DeepMind – have warned that Artificial intelligence could lead to the extinction of humanity. Dozens have supported a statement published on the webpage of the Centre for AI Safety.  

The Centre for AI Safety website suggests a number of possible disaster scenarios:

  • AI could be weaponised – for example, drug-discovery tools could be used to build chemical weapons;
  • AI-generated misinformation could destabilise society and undermine collective decision-making;
  • The power of AI could become increasingly concentrated in fewer and fewer hands, enabling regimes to enforce narrow values through pervasive surveillance and oppressive censorship;
  • Enfeeblement, where humans become dependent on AI similar to the scenario portrayed in the film Wall-E.

These scenarios highlight the central paradox of advanced AI: the very technology designed to maximize human efficiency possesses the latent capacity to render humanity obsolete. Far from mere science fiction, these warnings from the industry’s own pioneers underscore that the window for preventing systemic catastrophe is rapidly closing.

Top AI-driven systems currently in use for military operations:

  • Intelligence, surveillance, and reconnaissance (ISR): When the US and Israel struck Iran in February 28 this year, it marked the first time in history, the entire architecture of a major interstate conflict, from intelligence fusion and target generation to post-strike battle damage assessment, was fundamentally governed by AI. It used a special military method called ISR. Instead of humans doing all the spying, an AI system was used to scan through thousands of satellite pictures, radio signals, and internet posts every single second. The AI combines all this massive information into one live, unified digital twin, which is like a giant 3D computer video game map that mirrors everything happening at that exact moment. By constantly watching this digital map, the AI can automatically spot strange patterns or dangers that humans might miss, giving commanders a superpower called situational awareness so they always know what the enemy is doing. The computer doesn’t just watch; it also uses predictive analysis to guess what the enemy will do next, and picks out the best targets for military strikes. Once the mission is over, the AI looks at new pictures to check if the job was done right. Computers are now helping to plan and guide almost every single step of a modern war.
  • Cyber Warfare: Automated threats or cyberattacks executed independently by software scripts, bots, or AI algorithms rather than human operators. As they operate continuously and at scale, they strip away human fatigue, allowing attackers to fail 99.9% of the time at zero cost. Only a single success is required to breach a network.
  • Unmanned Ground Vehicles (UGVs): Platforms like the THeMIS (Estonia) or Uran-9 (Russia) patrol hostile terrain, clear mines, and engage targets with mounted weapons.
  • Unmanned Aerial Vehicles (UAVs): Remote-piloted drones like the MQ-9 Reaper (US) are built for long-endurance global surveillance and precision strikes.
  • Unmanned Underwater Vehicles (UUVs). Iran has introduced UUVs such as the Azdhar autonomous torpedo. Fuelled by quiet lithium-ion electric propulsion, these low-cost submersibles can patrol underwater for days, waiting to lock onto the hull pixels or acoustic signatures of passing tankers. Because they are incredibly cheap to manufacture compared to traditional submarines, Iran can deploy them in large numbers, making detection and clearance a costly nightmare for foreign minesweepers and anti-submarine units.
  • Lethal Autonomous Weapons Systems (LAWS) In seeking a battlefield advantage, Ukraine’s weapons developers deployed the world’s first operational LAWS to execute mission-critical strikes independently. Instead of managing every tactical step manually, a human commander simply issues a high-level directive, such as “destroy the target”. The AI then automatically generates and executes a complex checklist of tasks, controlling multiple military assets simultaneously at blistering speed.
  • Humanoid Military Robots: Bipedal, AI-driven machines are designed to mimic human soldiers. Whilst still in development by firms like Ghost Robotics (US) and Unitree (China), they represent the next frontier in combat tech.
  • Military robots: Machines designed to support or replace soldiers in combat, reconnaissance, logistics, and other defence roles. These robots range from simple bomb-disposal bots to advanced AI-powered systems capable of decision-making on the battlefield. They reduce risk, extend operational range, and take on tasks too dangerous for humans.
  • Decision Support Systems (DSS)—most notably platforms like the Pentagon’s Maven Smart System integrated with advanced large language models (like Anthropic’s Claude or specialized tools from Microsoft, Amazon, and Google). These systems act as hyper-advanced data fusion engines. They ingest a chaotic, overwhelming torrent of raw battlefield intelligence simultaneously, including: Live drone video feeds, satellite radar and imagery, intercepted electronic communications and radio signals and local geography and historical troop movements. The AI sifts through this massive mountain of data in seconds. It automatically flags anomalies, identifies hidden structures, translates languages, classifies vehicles, and links separate puzzle pieces together.

© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Newsletter

[Media Feature] The Star: Safeguards Needed for CCTV Data

Safeguards Needed for CCTV Data

Quoted by The Star on 18 June 2026

by Martin Carvalho, Ragananthini Vethasalam and Divya Theresa Ravi

© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Featured Articles

[Feature Article] The Star Newspaper: Banks Must Rethink Fraud Controls as AI Risks Rise

Banks Must Rethink Fraud Controls as AI Risks Rise

Published by The Star on 20 May 2026

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

The recent Sessions Court ruling ordering a local bank to pay RM166,000 for failing to monitor anomalous transactions represents a critical inflection point for corporate governance in Malaysia. By holding the institution liable for ignoring sudden, uncharacteristic account activity, the court effectively dismantled the legacy defence that merely having a secure system—such as sending automated SMS alerts—absolves an organisation of its duty of care.

The ruling sets a clear legal baseline: financial institutions cannot remain passive when faced with glaring transactional anomalies. It reinforces the expectation that financial compliance requires active, intelligent monitoring of escalation triggers, particularly when a transaction drastically deviates from established customer behaviour.

However, if our institutions are currently facing legal liability for missing traditional, rudimentary anomalies, they are alarmingly exposed to the incoming wave of AI-driven financial manipulation. What used to be neatly divided into IT risk versus finance risk is now one combined problem. Cybersecurity and financial compliance can no longer sit in separate rooms.

AI does not necessarily create new categories of fraud; it amplifies existing ones with devastating precision. The 2024 Arup incident, where a multinational engineering firm lost US$25mil after an employee transferred funds based on a deepfake video call with fabricated “senior management,” serves as the global anchor case. It proves an uncomfortable reality: we can no longer trust the channel. Relying on email authenticity, or even live video confirmation, is now an outdated assumption.

Furthermore, AI enables virtually undetectable fraud at scale. Instead of a single large, suspicious transfer, malicious actors can execute hundreds of micro-transactions over time. In this modern “One Cent Thief” scenario, each transaction sits comfortably below automated detection limits and approval thresholds, yet aggregates into significant corporate losses.

This is where our current regulatory frameworks face a critical gap. The Cybersecurity Act 2024 provides a strong foundation for strengthening system resilience and reporting breaches. However, AI introduces a fundamentally different risk. It does not necessarily hack the system; rather, it manipulates how human decisions are made. While current cybersecurity laws protect the infrastructure, they do not fully address the deception embedded within the financial workflow itself.

To survive this shift, corporate boards and audit committees must recognise that the answer is not simply telling employees to “be careful.” Financial approval systems must be actively redesigned to withstand deception. High-risk actions—such as large payments, urgent transfers, or changes to vendor bank details—must trigger mandatory, independent, out-of-band verification using pre-approved contact channels.

Equally critical is the human factor. Fraud often succeeds not because a policy does not exist, but because an employee is pressured by urgency or perceived authority into bypassing it. Corporate culture must empower people to pause, question, and escalate suspicious, time-sensitive instructions. Crucially, no employee should ever be penalised for slowing down a transaction to exercise independent judgment.

The future of financial security is not just building stronger firewalls. It is disciplined human decision-making, better audit trails, and structured verification built directly into financial processes. As the recent court ruling demonstrates, the expectation of accountability is not new. The law is simply evolving to demand that our internal controls are robust enough to manage exactly how decisions are made and acted upon.

© 2025 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Featured Articles

[Feature Article] The Star Newspaper: AI Adoption Cannot Justify Dismissal

AI ADOPTION CANNOT JUSTIFY DISMISSAL

Published by The Star on 13 May 2026

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

A recent Chinese court ruling—declaring that replacing a worker with AI to cut costs does not legally justify termination—serves as a stark warning: rapid technological adoption cannot bypass established labour protections.

For Malaysia, where TalentCorp projects nearly 700,000 workers will face disruption from AI, digitalisation and the green economy within three to five years, this is a legal reality we must urgently confront.

Under the Industrial Relations Act 1967, terminations require “just cause or excuse.” While companies will inevitably claim “redundancy” to justify AI-driven layoffs, procuring an enterprise AI license is not a legal blank cheque. The burden remains on employers to prove a role has genuinely ceased to exist.

If a company dismisses junior staff but uses algorithms to produce the exact same volume of work—still requiring human prompting, editing, and supervision—the role has simply evolved, not disappeared. Claiming redundancy here could be successfully challenged in the Industrial Court as a sham.

However, the most profound threat to our workforce is not the legally actionable layoff; it is “invisible displacement.” This silent attrition occurs when departing employees are simply not replaced because AI absorbs their workload. No termination letter is issued, and no legal claim arises, but entry-level opportunities permanently evaporate.

We must acknowledge the employer’s reality: in a hyper-competitive global landscape, it is economically irrational to artificially sustain obsolete roles. The law can punish unfair dismissals, but it cannot compel companies to create new jobs.

While TalentCorp anticipates the emergence of 120 new high-value roles, placing the burden entirely on workers to aggressively upskill is a flawed strategy. We cannot rely on 20th-century labour laws to manage 21st-century technological disruption. We urgently need a new “digital social contract” bridging statutory reform and corporate governance.

First, the Human Resources Ministry must establish modernised guidelines explicitly defining “technological redundancy.” The Industrial Court should not be left to interpret AI displacement using decades-old precedents designed for factory closures. We need clear statutory definitions that distinguish genuine business restructuring from opportunistic AI cost-cutting.

Second, corporate governance must evolve. Adopting enterprise AI is a profound human resources event, not merely an IT procurement. Environmental, Social, and Governance (ESG) standards should encourage internal workforce impact audits. Before defaulting to silent attrition or redundancy, employers hold a duty of care to explore how at-risk workers can be transitioned to manage the very AI systems replacing their tasks.

AI will undoubtedly alter existing roles, but more importantly, it will dictate the jobs companies choose not to create tomorrow. True job security in the algorithmic age requires not just an agile workforce, but modernised labour laws and a corporate sector willing to take responsibility for its technological upgrades.

© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Featured Articles

[Feature Article] The Star & The Sun Newspaper: A Balanced Blueprint For Youth Online Safety

A BALANCED BLUEPRINT FOR YOUTH ONLINE SAFETY

Published by The Star & The Sun on 28 Apr 2026

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

The government’s plan to restrict children under 16 from accessing social media by June, using the framework of the Online Safety Act (ONSA), signals a strong commitment to youth protection. However, a “total lockout” approach and the proposed MyKad-based age verification raise critical practical and cybersecurity concerns.

A sweeping ban is a blunt regulatory tool that is notoriously difficult to enforce. Banning youths will inevitably drive them to use Virtual Private Networks (VPNs) or migrate to encrypted messaging apps like Telegram, rendering them entirely invisible to parents and regulators. What we need is to foster digital literacy alongside these restrictions.

In this context, Meta’s recent rollout of revamped “Teen Accounts” offers a highly instructive case study. By placing younger users under strict default settings for privacy, disabling recommendations for sensitive content, and embedding mandatory parental controls, Meta has provided a tangible blueprint for what “safety by design” looks like in practice, rather than relying on reactive moderation after the fact.

From a regulatory standpoint, this is a significant and welcome shift. By mandating safe, highly restricted environments, we give youths a secure “training ground” to develop digital resilience.
Rather than pursuing an unenforceable blanket ban, policymakers should use this model to establish an industry-wide baseline. The Malaysian Communications and Multimedia Commission (MCMC) regulatory sandbox should pivot from testing how to block youths entirely, to testing how to protect them. The upcoming ONSA subsidiary instruments should make these strict default privacy settings and restricted algorithmic feeds a mandatory licensing condition for all platforms operating in Malaysia.

This brings us to a major cybersecurity concern. The Communications Minister recently suggested standardising “age verification” using official government documents like the MyKad. If this verification requires platforms to directly collect and store MyKad, we are facing a massive risk.

Social media platforms suffer massive data breaches. The 2021 Facebook data leak exposed details of 533 million users, and in 2023, hackers posted email addresses linked to 200 million Twitter accounts. If social media giants cannot guarantee the absolute security of user data based on these past incidents, trusting them to directly verify and store our MyKad could expose millions to severe identity theft. Trading one potential harm for another, more severe one is a deeply flawed policy.

Furthermore, if age verification requires platforms to collect and store MyKad, it does not meet the spirit of data minimisation under Section 6 of Malaysia’s Personal Data Protection Act (PDPA). The General Principle of the PDPA dictates that personal data processed must be “adequate but not excessive” in relation to its purpose. We cannot create a system where ONSA requirements actively conflict with the spirit of the PDPA.

If age verification is deemed absolutely necessary, we must look to privacy-preserving global best practices. Rather than submitting MyKad to tech companies, Malaysia should adopt the “double-blind tokenised approach” recommended by Australia’s eSafety Commissioner.

This approach involves an independent, regulated third party that verifies a user’s age. This verifier then provides a secure token to the social media platform, confirming only that the user meets the age requirement. Crucially, the platform never receives or handles the user’s personal identification documents, thereby protecting their privacy.

We must protect our youths, but not at the expense of their digital literacy or national data security. By pivoting towards mandated “safety by design” and privacy-preserving tokenisation, Malaysia can create a gold-standard regulatory framework that avoids the dangerous pitfalls of blunt bans and mass data collection.

© 2026 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Featured Articles

[Feature Article] Navigating ONSA Through Safety by Design

Navigating Onsa Through Safety by Design

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

The recent US$375mil verdict against Meta in a New Mexico court represents a watershed moment in digital governance. While the staggering financial penalty has dominated headlines, the true significance lies in the legal precedent it establishes for corporate risk and product liability in the tech sector.

Crucially, the jury did not penalise the platform merely for a failure in content moderation. The liability was rooted in the finding that the platform’s core recommendation algorithms actively steered underage users towards harmful material, violating unfair practices laws. This verdict effectively signals the death knell for the industry’s legacy playbook of reactive content moderation.

For multinational tech companies operating in Malaysia, this global legal shift arrives at a critical juncture. Under our Online Safety Act 2025 (ONSA), tech executives face personal liability for platform failures. However, the legislation provides a crucial defence clause, allowing leadership to avoid liability if they can demonstrate they took “reasonable steps” to prevent the offence.

The New Mexico verdict serves as a stark warning on how courts and regulators will interpret this threshold moving forward. Relying on after-the-fact measures, such as launching new parental controls or relying on human moderators only after a crisis has occurred, is no longer a viable legal strategy. As public scrutiny intensifies, this landmark verdict demonstrates that relying on reactive fixes is an increasingly perilous legal position when the underlying product design remains fundamentally flawed.

Instead of viewing legislation like ONSA as a hostile threat, the tech industry must embrace “safety by design” as its ultimate corporate shield. Implementing mandatory Algorithmic Impact Assessments before launching new features is no longer just red tape. It is the most effective way to transform unpredictable litigation risks into a predictable, manageable compliance framework.

By building architectural safety measures into their code from the outset, platforms provide a clear, auditable trail of these “reasonable steps”, thereby protecting their executives and ensuring regulatory certainty. Beyond mere legal compliance, there is a profound governance and reputational imperative. Tech giants play an undeniable role in shaping society, and the loss of parental trust is a devastating blow to long-term brand equity.

Ensuring the safety of children and making parents feel secure that their families are protected online is not just a moral obligation. It is foundational to maintaining a platform’s social license to operate.

Ultimately, robust digital governance is a competitive advantage. By proactively pivoting from reactive moderation to structural safety by design, tech platforms can simultaneously protect their leadership under ONSA, fulfill their societal responsibilities, and secure the enduring trust of their user base.

Just as we require safety certifications for physical infrastructure, we must now demand Algorithmic Impact Assessments from our digital landlords. The message is unequivocal: the future belongs to these algorithmic platforms, but their deployment requires a social license to operate.

© 2025 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Featured Articles

Maturing With Sophistication and Speed: Malaysia’s Intellectual Property Landscape​

Maturing With Sophistication and Speed: Malaysia's Intellectual Property Landscape

How Malaysia IS Re-Engineering Ip Laws for the Machine Age

By Thulasy Suppiah, Managing Partner of Suppiah & Partners

Introduction

As of 2025, Malaysia’s intellectual property (IP) landscape is undergoing significant modernisation, fundamentally redefined by rapid technological acceleration and artificial intelligence (AI). Patent and copyright laws need to be fitted for purpose in an automated age and to address the complexities of AI-generated solutions. Malaysia is modernising its IP framework to better address digital technologies and AI, while continuing to balance innovation with traditional IP protections.

KEY DEVELOPMENTS

Malaysia administers its IP rights through the Intellectual Property Corporation of Malaysia (MyIPO), which operates under the Ministry of Domestic Trade and Cost of Living (KPDN). The Patents (Amendment) Act 2022 and the related 2025 regulations brought post-grant opposition into force on 31 December 2025, allowing interested persons to oppose granted patents or utility innovation certificates before the Registrar.

Malaysia’s IP reforms are aligned with ASEAN’s broader IP direction, including the ASEAN Intellectual Property Rights Action Plan 2016–2025 and related Hague-accession efforts. This reflects a regional focus on future-ready economies, the valuation of intangible assets, and stronger IP enforcement to support micro, small, and medium enterprises.

In another significant development, MyIPO transitioned its Copyright Voluntary Notification system to an online platform in December 2025. This allows authors and artists to record their works more efficiently without visiting physical counters, and streamlines protection for creators.

MyIPO has also announced plans to amend several key pieces of legislation starting in 2026 including the Patents Act, Copyright Act, and Trademarks Act to ensure Malaysia remains a pro-investor hub and stays aligned with international standards.

Meanwhile, the Malaysian government is currently drafting an AI Governance Bill. In February 2026, Prime Minister Datuk Seri Anwar Ibrahim said the AI Governance Bill would address copyright and IP concerns, while the bill remained at an early drafting and consultation stage.

In a move to accelerate the nation’s shift toward a high-value Orange Economy, the Malaysian government has integrated IP excellence into the Thirteenth Malaysia Plan (2026–2030). The plan places strong emphasis on IP and technology-centric investment, semiconductor development, and the creation and commercialisation of Made by Malaysia products.

To prepare for the complex intersection of technology and sports, MyIPO is hosting a National IP Law Moot Competition focused on IP and sport. The competition is an inaugural 2026 initiative and is planned to cover current IP issues affecting sports, media, branding, and technology.

Finally, Malaysia has been moving toward Hague-accession through industrial design reforms. Once accession is completed, it will allow Malaysian designers to file a single international application to seek design protection in multiple jurisdictions under the Hague System, potentially reducing costs for local businesses looking to export to global markets.

TYPES OF IP RIGHTS IN MALAYSIA

In Malaysia’s evolving economy, IP rights serve as a cornerstone of a company’s intangible wealth. These legal protections act as a vital shield, ensuring that a business owner’s unique creations and innovations cannot be copied or exploited without permission, thereby safeguarding their exclusive control over their most valuable assets. There are six primary categories that frame Malaysia’s IP laws:

CategoryWhat it ProtectsPrimary LegislationDuration of Protection
Patents & Utility InnovationsInventions: Technical solutions, new processes, or improved machineryPatents Act 198320 Years
TrademarksBrand Identity: Logos, names, slogans and even non-traditional marks like sounds and colors.Trademarks Act 201910 Years (Renewable Indefinitely)
Industrial DesignsAesthetics: The visual shape, pattern, or configuration applied to a mass-produced product.Industrial Designs Act 1996Max 25 Years (5-year blocks)
CopyrightCreative Works: Literary works, software code, music, films and artistic expressions.Copyright Act 1987Life of Author + 50 Years for literary, musical or artistic works; different terms apply to other categories of protected works under the Copyright Act 1987.
Geographical Indications (GI)Origin-Based Reputation: Products with a specific quality linked to a place (e.g., Sarawak Pepper).Geographical Indications Act 202210 years, renewable for further 10-year periods upon renewal
Layout Designs of Integrated CircuitsMicrochip Logic: The three-dimensional disposition of elements in an integrated circuit.Layout- Designs of Integrated Circuits Act 2000The protection term runs for a prescribed period measured from the earlier of first commercial exploitation or the relevant filing/registration date, and should be stated precisely from the Act before publication.

GOVERNANCE & PENALTIES

In Malaysia, criminal enforcement of IP rights is primarily handled by KPDN’s enforcement machinery. While patents and industrial designs are largely civil matters, Trademarks and Copyright carry heavy criminal penalties to deter counterfeiting and piracy. As of 2026, the penalties are structured as follows:

1. Trademarks (Trademarks Act 2019)

The law is particularly strict regarding counterfeit goods and the false application of marks.

  • Counterfeiting a Registered Mark:
    • Individuals: A fine of up to RM1,000,000, imprisonment for up to 5 years, or both.
    • Companies: A fine of up to RM1,000,000.
  • Possession or Sale of Counterfeit Goods:
    • Individuals: A fine of up to RM10,000 per item (1st offence) or RM20,000 per item (subsequent offences), and/or up to 3–5 years in prison.
    • Companies: A fine of up to RM15,000 per item (1st offence) or RM30,000 per item (subsequent offences).
2. Copyright (Copyright Act 1987 & 2022 Amendments)

Penalties here often target digital piracy and the distribution of infringing copies.

  • General Infringement (Sale/Hire/Distribution):
    • Fines between RM2,000 and RM20,000 for each infringing copy.
    • Imprisonment for up to 5 years.
  • Streaming Technology (Anti-Piracy):
    • For manufacturing, importing, or selling technology that facilitates copyright infringement (e.g., "pirate" streaming boxes), the penalty is a fine of RM10,000 to RM200,000, up to 20 years in prison, or both.
  • Possession of Infringing Copies:
    • A fine of RM1,000 to RM10,000 per copy or up to 5 years in prison.
3. Other Significant Penalties
  • Circumventing Technological Protection Measures (TPMs): Breaking digital locks on software or media can lead to fines up to RM250,000 or 5 years in prison.
  • False Representation: Using the ® symbol for an unregistered or pending trademark is a criminal offence carrying a fine of up to RM10,000.

GLOBAL RANKING

Malaysia is currently regarded as a regional leader in IP, often ranked just behind Singapore in Southeast Asia. As of 2026, Malaysia’s IP regime is characterised by high compliance with international treaties but faces ongoing challenges in commercialising its high volume of patents.

Malaysia maintains a strong position among middle-income nations and is consistently improving its standing in global innovation and property rights indices.

In the Global Innovation Index (GII) 2025, Malaysia is ranked 34th out of 139 economies. Crucially, it ranks 2nd among the 36 upper-middle-income group economies, trailing only China.

Under the International Property Rights Index (IPRI) 2025, Malaysia ranks 41st globally and 7th in the Asia-Oceania region. While its IP score remains stable (ranked 26th globally for IP specifically), it saw a slight dip in overall property rights due to shifting perceptions of physical property and finance access.

Finally, The U.S. Chamber’s International IP Index places Malaysia at 28th out of 55 economies in the 2025 edition, reflecting its relative success in aligning local laws with US and EU standards.

Malaysia typically leads in digital piracy enforcement, with some of the strictest laws in the world against illicit streaming devices (ISDs), with potential jail terms of 20 years – and puts Malaysia ahead of its neighbours in fighting digital copyright theft.

Malaysia protects geographical indications through its own GI regime, which is conceptually similar to France’s appellation d’origine contrôlée.

However, there are areas where Malaysia still lags. Although we have a high volume of filings for patent commercialisation, there is very low commercial take-up (less than 1 per cent), compared to high commercialisation and venture capital support in Singapore. While Singapore has one of the world’s fastest IP offices, Malaysia is only now rapidly improving its digital-only filing.

But the most significant international comparison noted by expects in 2025/2026 is, unlike the US or Singapore, where patents are quickly turned into startups and products, many Malaysian patents remain academic, highlighting a need for better industry-university collaboration to address this innovation gap.

LEGAL ALIGNMENT & TREATIES

Malaysia is a contracting party to almost all major international IP treaties, making its legal framework very similar to those of the UK, Australia, and the US.

TRIPS (Trade-Related Aspects of Intellectual Property Rights) Agreement: Malaysia is generally aligned with TRIPS minimum standards. The TRIPS Agreement is the most comprehensive international legal agreement on IP to date. Established in 1994 as part of the founding of the World Trade Organisation (WTO), it serves as the global rulebook that sets the minimum standards for how member nations must protect and enforce IP rights within their borders.

The Madrid Protocol: Like the US and EU, Malaysia allows business owners to protect trademarks in over 130 countries through a single application. Rather than hiring lawyers in 50 different countries to file 50 separate applications, you file once through your home IP office (MyIPO in Malaysia). This application is then sent to the World Intellectual Property Organisation (WIPO) in Switzerland, which coordinates with all the other countries you selected.

Patent Prosecution Highway (PPH): Malaysia has fast-track agreements with the United States (USPTO), European Patent Office (EPO), and Japan (JPO). This means if you get a patent in the US, your Malaysian application can be expedited, and vice versa.

The Hague Agreement: Malaysia has been reforming its industrial designs framework in anticipation of Hague accession, including proposals to broaden the scope of protectable designs.

BRIDGING THE GAPS

MyIPO’s IP Online Portal is designed to streamline filing across Malaysia’s IP registries, including industrial designs and other rights administered through MyIPO. This improves the efficiency of filing and notification processes and makes it easier for Malaysian innovators to manage cross-border protection strategies. Rather than dealing with separate foreign filings one by one, local creators will eventually be able to use the Hague System to seek design protection in over 90 countries through a single international application, in one language and with one set of fees in one currency. This administrative streamlining can support the Orange Economy by lowering barriers for small and medium enterprises seeking to export their designs and brand value.

Beyond technical and legal mechanics, Malaysia is also cultivating the human expertise required to sustain this new era of innovation. MyIPO’s launch of the Malaysia National IP Law Moot Competition will focus on IP and sport, as a training ground for future practitioners dealing with contemporary IP issues in sports, media branding and technology. This holistic approach, which balances digital tools with legal education, positions Malaysia as a jurisdiction steadily strengthening its IP ecosystem.

CONCLUSION

The continued expansion of immersive digital worlds and the metaverse is creating new frontiers for trademark and brand protection, while the global push for sustainability is fuelling a surge in green technology patents. Meanwhile, the strategic value of data as a core business asset elevates the importance of strong trade secret protection. Malaysia is pivoting to meet these changes, and its IP legal framework remains broadly aligned with international standards across multiple IP domains.

© 2025 Suppiah & Partners. All rights reserved. The contents of this newsletter are intended for informational purposes only and do not constitute legal advice.

More Newsletter