National Cancer Institute (IKN), Ministry of Health Malaysia
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
Success for the first Global Dialogue on AI Governance must be measured not by consensus on principles — those already exist in abundance — but by progress on implementation architecture, particularly for lower-and-middle-income countries (LMICs). Three outcomes would mark genuine success: First, agreement on a minimum validation threshold for clinical and high-stakes AI tools — a baseline below which no AI system may be deployed in healthcare or public safety contexts, regardless of the developer's geography or institutional affiliation. The current vacuum is being filled by well-intentioned but clinically unqualified actors, with no adverse event reporting, no liability framework, and no patient-facing transparency. Second, differentiation between AI literacy and AI deployment governance. Training clinicians to use AI is not equivalent to governing how AI tools enter clinical workflows. The Dialogue should produce clarity on this distinction and call for country-level regulatory guidance that does not assume enforcement infrastructure that LMICs do not yet have. Third, a concrete follow-up mechanism — not another consultation cycle, but an accountable reporting structure that tracks whether recommendations from Geneva 2026 translate into national policy action by New York 2027. The Dialogue will succeed if it produces outputs that a Ministry of Health in a resource-constrained setting can actually operationalize — not frameworks designed for contexts with mature regulatory bodies, then handed downstream as if they are universally applicable. The measure of success is not what Geneva produces on paper. It is what a frontline health system can do differently because Geneva happened.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Transparency, accountability, and human oversight
- AI capacity-building
- Protection and promotion of human rights
Please briefly explain your selection.
6
These four priorities reflect an urgent and observable governance gap at the intersection of clinical AI deployment and regulatory capacity in lower-and-middle-income health systems. 1. Safe, secure and trustworthy AI is the foundation. In healthcare contexts across the Asia-Pacific region, AI-powered diagnostic tools are being built and deployed by developers without clinical training (VIBE CODERS), often promoted through informal coaching networks that then upskill licensed clinicians. There is no pre-deployment validation requirement, no adverse event reporting mechanism, and no equivalent of clinical trial oversight. The harm is not malicious - it is architectural. 2. Transparency, accountability, and human oversight follows directly. Patients interacting with these tools have no visibility into who built them, under what standards, or who bears liability if the output causes harm. Clinicians using them are often unaware of the absence of validation. Human oversight is nominally present but structurally uninformed. 3. AI capacity-building is selected not as an adoption agenda but as a governance agenda. The gap in LMIC health systems is not access to AI tools - it is the regulatory, technical, and institutional capacity to evaluate, intercept, and govern those tools before they reach clinical workflows. Capacity-building frameworks must explicitly include this dimension. 4. Protection and promotion of human rights anchors the patient. Receiving AI-assisted clinical assessment without knowledge of the tool's provenance, validation status, or accountability chain is a transparency and dignity issue, not merely a technical one. Together, these four priorities describe a single systemic failure: the absence of a globally harmonized minimum standard for clinical AI deployment, with disproportionate impact on health systems least equipped to self-regulate.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
2
One critical emerging issue is absent from the listed themes: the rise of "vibe coding" in clinical AI development - the practice of building functional software through AI-assisted, intuition-driven development without formal engineering or domain expertise. Vibe-coded clinical tools are now actively deployed in healthcare settings. Diagnostic interfaces, symptom checkers, and clinical decision-support tools are being built by self-taught developers with no medical training, no understanding of clinical validation methodology, and no awareness of the regulatory frameworks governing medical devices and health informatics. These tools are publicly accessible, visually credible, and increasingly used by patients and clinicians alike. What makes this an urgent governance issue is the knowledge transfer inversion that follows: non-clinical AI coaches - themselves the builders of these tools - are now conducting AI literacy training for licensed physicians. The epistemic chain runs backwards. Clinicians are being taught to trust and use tools that were never designed to clinical standards, by instructors who lack the clinical epistemology to identify what is missing. This phenomenon does not fit neatly into any single listed theme. It is simultaneously a safety issue, a human rights issue, a capacity-building issue, and a transparency failure. It requires a dedicated governance response: minimum validation standards for any AI tool that interfaces with clinical decision-making, mandatory disclosure of developer qualifications and validation methodology, and explicit differentiation between AI literacy training and clinical AI deployment governance. The Global Dialogue must name this explicitly. Vibe coding is not a future risk. It is happening now, disproportionately in health systems with the least regulatory capacity to intercept it.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
In Malaysia and across the Asia-Pacific region, the governance gaps identified are not theoretical — they are visible in active clinical and institutional practice. The most significant challenge is regulatory interception failure. Malaysia has a nascent but developing AI governance landscape, including adoption of ISO/IEC 42001 and ongoing national digital health initiatives. However, no specific regulatory mechanism currently exists to intercept AI tools before they enter clinical workflows. The Medical Device Authority (MDA) framework covers hardware and software as medical devices under defined thresholds — but vibe-coded diagnostic web applications frequently fall outside these thresholds by design or by ignorance, not by legitimacy. The second challenge is the coaching economy. Across Southeast Asia, a growing market of AI coaches — many without clinical or technical credentials — are selling AI upskilling programmes to healthcare professionals. These programmes train clinicians to use tools the coaches themselves built, without validation, without adverse event awareness, and without reference to clinical governance standards. This is an active patient safety risk operating entirely outside existing regulatory sight lines. The opportunity is timing. Malaysia is at an inflection point — actively developing national AI policy, building ISO 42001 audit capacity, and integrating AI governance into hospital accreditation frameworks. A globally harmonised minimum standard for clinical AI validation, produced through the Geneva Dialogue, would provide immediate policy anchoring for countries at exactly this stage. It would also provide institutional cover for regulators to act — which is often what is needed when domestic political will is present but international precedent is absent. The window to shape this before harm scales is narrow. Geneva 2026 is the right moment.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The AI Dialogue's most valuable role is not producing another principles document. It is building the connective tissue between existing frameworks and national implementation capacity. Three specific contributions matter: 1.Harmonisation without homogenization. Dozens of AI governance frameworks exist — OECD, UNESCO, EU AI Act, ISO/IEC 42001, national strategies. The Dialogue can map these into a coherent minimum baseline that countries can adopt regardless of their regulatory maturity, without requiring wholesale adoption of frameworks designed for high-income regulatory environments. 2. South-South knowledge transfer. Countries navigating early-stage AI governance — Malaysia, Rwanda, Costa Rica — have more to learn from each other than from jurisdictions whose regulatory infrastructure is decades ahead. The Dialogue should institutionalize structured exchange between countries at similar implementation stages, not only between global north standard-setters and everyone else. 3. Accountability bridge between 2026 and 2027. Geneva to New York is one year. The Dialogue should establish a lightweight but binding reporting mechanism — what commitments were made, what changed, what did not. Without this, Geneva 2026 produces recommendations and New York 2027 produces fresh recommendations with no audit trail connecting them. The Dialogue cannot legislate. But it can create the shared language, minimum standards, and peer accountability structures that make national action politically and technically easier. For countries that have the will but lack the precedent, that is precisely what international cooperation is for.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
Several existing mechanisms provide foundations the Dialogue should connect with rather than duplicate: 1. ISO/IEC 42001 — the international standard for AI management systems — provides an auditable, certifiable governance framework already being adopted globally. The Dialogue should reference this as a minimum institutional baseline and support LMIC access to certification infrastructure. 2. WHO guidance on AI for health — particularly the Ethics and Governance of AI for Health report — establishes sector-specific principles the Dialogue should operationalize, not merely acknowledge. Health remains the highest-stakes deployment context and deserves explicit treatment beyond generic AI governance framing. 3. The OECD AI Principles and Hiroshima AI Process — provide existing soft law architecture with broad but incomplete country coverage. The Dialogue's added value is extending their reach into jurisdictions absent from their original design. 4. ITU's AI for Good platform — offers multistakeholder technical exchange infrastructure already spanning UN member states. The Dialogue should leverage this convening capacity rather than building parallel structures. 5. ASEAN's AI governance frameworks — represent regional implementation attempts in a diverse, multi-speed bloc. Lessons from Southeast Asia on governing AI across varying regulatory maturity levels are directly transferable to other regions. The Dialogue's unique added value is UN legitimacy and universal convening authority — something no existing initiative holds. That authority should be used to connect, harmonise, and extend reach — not compete with mechanisms already doing valuable work.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
Governments set policy floors; industry discloses deployment realities; civil society surfaces harms before they scale; academia provides independent validation; technical experts translate principles into implementable standards. Each role is distinct and must be structurally protected — not collapsed into a single "multistakeholder" category that privileges the loudest voices. For format: structured thematic working groups with written submission tracks, not only plenary debate. Ensure asynchronous participation pathways for contributors from time-zone-disadvantaged or under-resourced contexts. Outputs must include a named accountability mechanism connecting Geneva 2026 commitments to New York 2027 review.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Frontline clinical practitioners in LMIC health systems are critically underrepresented — they observe AI deployment failures first but have no formal channel into global governance discussions. Patients in non-English-speaking contexts, disability communities, and indigenous populations face AI systems not designed for or validated against their realities. Inclusion requires more than translation. It requires structural seats — dedicated submission tracks for practitioner voices, civil society quotas from underrepresented regions, and active outreach beyond established UN-affiliated networks. Representation must be verified, not assumed. A governance process that does not hear from those most affected by AI harm cannot credibly govern it.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
Three formats would shift the Dialogue from performative to generative: 1. Red team sessions — structured adversarial panels where practitioners from LMIC contexts actively challenge proposed governance frameworks for real-world implementability. Not debate — stress testing. Outputs become part of the formal record. 2. Live case submissions — short, structured presentations of active governance failures from the field. Not hypotheticals. Real tools, real harms, real gaps. Submitted in advance, curated for thematic relevance, presented in plenary with protected anonymity where needed. 3. Commitment tracking dashboards — publicly visible, updated in real time during the Dialogue, mapping each stakeholder's stated commitments against the four thematic clusters. Accountability begins in the room, not after the communiqué. Meaningful engagement is not about format novelty. It is about whether the room changes its mind because of what it heard. Design for that outcome.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
3
Several concrete approaches demonstrate what effective AI governance looks like in practice: 1. The EU AI Act's risk-tiered classification - categorizing AI systems by deployment risk rather than technical architecture - provides a replicable model that countries without full regulatory infrastructure can adapt. Its explicit high-risk designation for clinical AI tools is directly relevant to health system governance gaps. 2. Singapore's Model AI Governance Framework - one of the earliest national frameworks from the Asia-Pacific region - demonstrates how principles can be translated into sector-specific implementation guidance without waiting for binding legislation. Its iterative, consultation-based revision process is a replicable model for other jurisdictions. 3. Canada's Algorithmic Impact Assessment - requires federal agencies to evaluate AI systems before deployment, documenting risk level, data provenance, and human oversight mechanisms. Applied to clinical contexts, this directly addresses the absence of pre-deployment validation requirements. 4. WHO's Ethics and Governance of AI for Health framework - provides sector-specific governance principles grounded in patient rights, safety, and equity. Its explicit attention to LMIC implementation constraints makes it more actionable than generic AI ethics documents. 5. Hospital accreditation as governance infrastructure - embedding AI governance requirements into institutional accreditation conditions makes compliance enforceable through existing mechanisms, without requiring new legislation or dedicated enforcement bodies. The common thread: governance that attaches to functioning institutional processes scales faster than parallel structures built from scratch.