TRUST AS THE NEW COMPETITIVE ADVANTAGE IN MALAYSIA’S AI ECONOMY


Shanti says that Malaysian enterprises are short of unified visibility that helps to identify risks and respond before they become major incidents.

MALAYSIAN organisations are moving quickly to put artificial intelligence (AI) to work.

Boards are tracking use cases, productivity gains and time saved. One question receives far less attention: who is accountable when an AI system exposes sensitive information, makes the wrong decision or is manipulated by an attacker?

For TM One executive vice-president Shanti Jusnita Johari, closing that accountability gap must become a leadership priority.

As AI becomes embedded across operations, customer engagement and decision-making, accountability is emerging as one of the defining governance challenges facing boards today.

“Boards should not only ask how quickly AI can be deployed. They should ask whether the organisation can still keep its promises to customers and citizens when something goes wrong,” she says.

“That is a leadership question.”

A mandate for boardrooms

Cybersecurity has moved from an IT line item to a boardroom mandate. Increasingly, boards must govern cyber and AI risks with the same discipline they apply to financial, operational and regulatory risks. As AI, cloud and automation become central to organisations, one incident can disrupt operations, weaken trust, interrupt supply chains and invite regulatory fallout.

Leaders therefore need to set clear accountability, define the organisation’s tolerance for cyber risk and ensure continuity plans are tested, not merely documented.

“Cybersecurity isn’t a cost centre. It’s a condition for doing business with confidence,” Shanti explains. “Boards should ask for evidence that critical services can continue during an incident, not simply reassurance that security tools are in place.”

Malaysia’s regulatory environment is also evolving alongside these risks. The Cyber Security Act 2024 places statutory obligations, including risk assessments, audits and incident notification, on National Critical Information Infrastructure operators, while the National Cyber Security Agency’s Malaysia Cyber Security Strategy 2025-2030 sets the country’s five-year resilience roadmap.

The pace of adoption adds to the urgency. Within two years, the National AI Office evolved into AI Malaysia, a centralised apex agency steering the AI Nation 2030 ambition, including a Malaysian AI Safety Institute for model testing and red-teaming. In tandem, enterprise AI adoption has nearly doubled since 2020, according to the AIBP 2025/2026 AI Readiness Survey.

“These shifts reflect Malaysia’s move to treat cyber resilience as a national imperative,” Shanti says. “For boards, that means making resilience a part of the AI agenda from the start, with clear ownership, investment and progress reviewed at leadership level.”

AI cuts both ways

Beyond reshaping efficiency, AI has changed the digital fight on both sides. Attackers can automate reconnaissance, generate phishing content and adapt faster than before. At the same time, organisations are accelerating AI adoption across operations, customer engagement and decision-making.

For leaders, the challenge is no longer simply deploying AI. Governance, visibility and accountability must evolve at the same speed.

For Shanti, one of AI’s biggest effects is the compression of decision time. Threats can be identified, adapted and executed more quickly, while organisations themselves are becoming more interconnected and automated. The ability to see what is happening and act quickly is therefore becoming as important as the security technology itself.

Recent industry studies illustrate the growing cost and sophistication of cyber incidents. IBM’s 2026 Cost of a Data Breach Report puts the global average breach cost at a record US$4.99mil, up 12% in a year, with AI-enabled attacks behind one in four malicious breaches.

Closer to home, Pikom’s Beyond Compliance: The State of Cyber Resilience in Malaysia 2026 report found the average cost of a data breach in Malaysia climbed to RM3.2mil in 2025, up from RM2.9mil the year before, with some organisations reporting losses of more than RM5mil from a single incident. AI-generated phishing or deepfake impersonation now rank among the most common attacks Malaysian organisations face.

“The issue for leadership is decision speed,” she says. “Can the organisation see a threat early enough, understand its impact and make the right decision before the situation escalates? Buying more tools does not automatically give you that capability.”

The gap TM CYDEC was built to close

For many organisations, the challenge is no longer a lack of cybersecurity investment. It is maintaining visibility across increasingly fragmented digital environments.

“Malaysian enterprises aren’t short of security tools; they’re short of unified visibility,” Shanti says.

“Chief executives should ask where visibility and ownership break down across cloud platforms, hybrid infrastructure and third-party ecosystems. Those gaps are often where incidents begin.”

This challenge also shaped TM CYDEC, TM’s Cyber Fusion operating model for enterprise, government and critical infrastructure customers.

Rather than treating network, cloud and cyber risks separately, the model brings visibility, threat intelligence and response capabilities into a more integrated operating environment.

For Shanti, the principle is straightforward: attackers do not operate according to an organisation’s internal structure.

“A threat can move across your network, cloud environment, applications and third-party connections without caring which team owns what,” she says.

“The organisation needs enough visibility across those boundaries to understand what is happening and act quickly.”

Looking ahead, TM One plans to progressively enhance TM CYDEC through AI Assurance, a set of capabilities designed to identify weaknesses in AI systems, protect them while

they are in use, and help organisations adopt AI with greater confidence.

Building trust

As organisations accelerate AI adoption and deliver more services digitally, trust is becoming a strategic asset that boards can no longer take for granted.

According to Shanti, the question is no longer whether organisations can innovate, but whether customers, regulators and stakeholders trust them to do so responsibly.

For Shanti, digital trust is ultimately practical. Organisations need clear accountability, visibility over their digital environment and confidence that capable people can act when an incident occurs.

Technology and governance have to work together if customers and stakeholders are to trust increasingly digital and AI-enabled services.

TM is also strengthening its own AI governance. It recently became the first Malaysian telco to earn the ISO/IEC 42001:2023 AI Management System certification, independently validated by SIRIM QAS International.

Sharing next steps, Shanti suggests organisations test their readiness against four questions:

> Who is accountable for AI decisions?;

> Can management see risks across the organisation’s digital environment?;

> Can management respond quickly during an incident?; and

> Can critical services continue while the incident is being handled?

Governance and monitoring should develop alongside AI adoption, not after a breach forces the issue.

“The next generation of market leaders will not be defined by how quickly they adopt AI,” she says.

“They will be judged by whether customers, regulators and stakeholders trust them to use it responsibly.

“That makes trust a leadership responsibility.”

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Business News

French consumers cut back spending
Asia seen as sweet spot in physical AI
Cheap labour, costly future
Europe’s AI debt rush
AI’s trillion-dollar gamble
Defence, space go SPACs
SMEs yet to tap AI’s full power
Hedge fund veteran bets on ‘abundance’
ETA Group to dispose of stakes in two subsidiaries for RM22.73mil
Insas proposes disposal of up to 218 million Inari shares

Others Also Read