Answer for Oral Question PL178
QUESTION
Yang Berhormat Dayang Hajah Safiah binti Sheikh Haji Abd. Salam
YANG BERHORMAT DAYANG HAJAH SAFIAH BINTI SHEIKH HAJI ABD SALAM asked the MINISTER OF TRANSPORT AND INFOCOMMUNICATIONS to state the Ministry’s direction in strengthening legislation, accountability and enforcement mechanisms to protect consumers, individual identities and the rights of copyright owners from the misuse of technology and the increasing misuse of AI, such as false advertisements, deepfakes, identity impersonation and the use of works without permission, taking into account the existence of the Second Edition of the Guide on AI Governance and Ethics, which takes into account the risks of Generative AI.
ANSWER
Yang Berhormat Menteri Pengangkutan dan Infokomunikasi
As a basis, we need to understand that AI is not an isolated technology, but forms part of the development of computing and digital technology, with more advanced capabilities to process, analyse and generate information.
Therefore, the Ministry’s approach is not merely to determine whether an act involves the use of AI. Instead, we look at the act committed, the risks arising and the harm suffered by the public. With this approach, many forms of AI misuse can in fact already be addressed through existing laws, depending on the type of offence and the jurisdiction of the relevant agency.
First, in terms of personal data and privacy. If AI is used to collect, use, disclose or process personal data without permission or improperly, the matter may be addressed under the Personal Data Protection Order. This includes data used to train or operate an AI system.
Second, in terms of cybersecurity and computer misuse. The Cybersecurity Act (Chapter 272) provides a framework for preventing, managing and responding to cybersecurity threats, particularly those involving Critical Information Infrastructure. Meanwhile, the Computer Misuse Act (Chapter 194) addresses offences targeting computers or using computers as tools to commit unlawful acts, including hacking and the use of malware.
Third, in terms of fraud and identity impersonation. The Penal Code (Chapter 22) contains relevant provisions for offences such as fraud and identity theft. If AI is used as a tool to commit such offences, legal action may still be taken under the relevant provisions.
This means that, for example, the use of a deepfake to impersonate someone in order to obtain money or deceive others does not necessarily require a new offence specifically relating to AI. If the act fulfils the elements of an existing offence, action may be taken under the relevant law.
The same applies to false advertisements. If technology is used to produce content intended to deceive or defraud the public, action may be taken.
Fourth, in terms of intellectual property. For offences involving works and intellectual property, BruIPO is the lead agency. Laws such as the Copyright Order 1999 and the Trade Marks Act (Chapter 98) may be applied when protected works are used or reproduced without permission, or when trademarks are misused, including through the use of AI technology.
Therefore, enforcement does not rest with a single agency; appropriate action will be taken depending on the type of offence and the agency with jurisdiction under its respective laws.
In addition to action after an offence has occurred, the Ministry also places emphasis on AI prevention and governance. In this regard, AITI, together with the Working Group on AI Governance and Ethics, has published several guidelines relating to AI. Among them is the Second Edition of the Guide on AI Governance and Ethics, which was published in April 2026.
This second edition takes into account the developments and risks brought about by Generative AI and provides guidance to organisations that shape, develop, use and benefit from AI, so that the technology is used safely, ethically and responsibly.
This guidance is important because we do not want our approach to focus only on what happens after someone becomes a victim. We also want to ensure that organisations using AI have a responsibility to identify risks, implement appropriate controls and protect users from the outset.
Next, from the security perspective, Cyber Security Brunei (CSB) is strengthening controls through two main initiatives, namely:
First, the Code of Practice for Critical Information Infrastructure has been updated to include aspects of an AI Security Policy, in order to establish the security controls that must be implemented by organisations developing and using AI.
Second, the AI Security Policy Guideline is currently in the process of being published. This guideline will provide more detailed guidance on security controls for Generative AI, Agentic AI and Autonomous AI technologies, including risk assessment, threat management and incident response mechanisms.
This is important because AI risks are not only related to false content or fraud. They also encompass system security, data, access to systems and the potential misuse of the technology itself.
In terms of the way forward, the Ministry will not adopt a wait-and-see approach until new forms of misuse occur before taking action. We will continue to assess whether existing legal provisions remain sufficient to address increasingly complex forms of technology misuse.
This is also in line with Digital Brunei 2030 through the Data and AI Strategy, which places emphasis on the legal and governance aspects of AI to ensure that the development and use of AI are carried out safely, ethically and responsibly, and in accordance with the national interest.
At the same time, the Ministry will continue to work with relevant agencies, including enforcement authorities, sector regulators and related agencies, to ensure that there are:
- clarity regarding the responsibilities of parties developing and using AI;
- effective mechanisms for detecting and reporting misuse;
- appropriate enforcement action when offences occur; and
- adequate protection for the public, particularly where personal data, identity, finances and intellectual property rights are involved.
Should there be gaps in the existing legislation, the Ministry will continue to conduct reviews together with relevant agencies so that legislation and enforcement mechanisms can be strengthened in line with technological developments and international practices.
The Ministry’s direction is to ensure that the advancement of AI does not move faster than the protection provided to society. We want to encourage innovation and leverage AI for national development. At the same time, however, we must ensure that users are not exposed to fraud, individual identities are not misused, personal data is protected and the rights of copyright owners are respected.
Our approach is clear: AI is a tool, but responsibility remains with the people and organisations that develop, provide and use it.
Therefore, the Ministry will continue to strengthen three areas simultaneously, namely legislation, governance and enforcement, so that AI technology can develop in a safe, responsible and trusted environment, for the protection of the interests of the people and the country.
In no event will we be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from loss of data or profits arising out of, or in connection with, the use of this website.
Through this website, you may be able to link to other websites which are not under our control. We have no control over the nature, content, and availability of those sites. The inclusion of any links does not necessarily imply a recommendation or endorse the views expressed within them.
Every effort is made to keep the website up and running smoothly. However, we take no responsibility for, and will not be liable for, the website being temporarily unavailable due to technical issues beyond our control.