The global digital asset landscape has moved beyond its phase of speculative alternative investment, to an era where it functions as core financial infrastructure. A primary example of this occurred during the recent conflict in the Middle East involving Iran, where significant cryptocurrency flows were observed as more than USD 10 million worth of digital assets moved out of local Iranian exchanges within a matter of days. Where conventional banking is restricted or unavailable, digital assets have stepped in as an alternative way to move and hold value.
Artificial Intelligence (“AI”) is accelerating all of this. Markets are already deploying AI agents to execute transactions, manage liquidity and interact with decentralised finance (DeFi) protocols — often without any human in the loop. Blockchain combined with autonomous AI creates genuinely new risks for financial services, and the law has not caught up. If Malaysia formalises digital assets as a payment instrument, market operators will need to navigate legal obligations that the current framework has not yet resolved.
At present, while the ownership and trading of digital assets are permitted in Malaysia, such assets are not recognised as legal tender nor regulated by Bank Negara Malaysia (“BNM”) as a payment instrument. This is due to the persistent concerns surrounding the structural limitations of digital assets, including acute price volatility, cybersecurity vulnerabilities, scalability constraints and, in certain cases, significant energy consumption. That said, the regulatory environment is moving. The introduction of the Digital Asset Innovation Hub (“DAIH”) in June 2025 marked the first concrete step. By 2026, BNM had onboarded three initiatives to pilot Ringgit-pegged stablecoins and tokenised deposits for wholesale payments.
The same pattern is playing out globally. Mastercard and Visa are both building stablecoin payment infrastructure into their core offerings. Mastercard’s proposed acquisition of BVNK — a dedicated stablecoin infrastructure firm — for up to USD 1.8 billion makes clear where institutional money is moving. Traditional payment rails and digital asset infrastructure are drawing closer together, and Malaysia will not stay outside that shift indefinitely.
Digital assets are currently governed primarily by the Capital Markets and Services Order 2019 (“CMSO 2019”), which officially classifies digital currencies and tokens as “securities”. Digital assets are therefore placed under the regulatory authority of the Securities Commission Malaysia (“SC”), which enforces Malaysia’s securities laws. Recognition as a payment instrument would, however, bring such assets within the purview of BNM under the Financial Services Act 2013 (“FSA 2013”). The FSA 2013 incorporates provisions to regulate payment system operators and payment instrument issuers in order to promote safe, efficient and reliable payment systems and instruments. As such, the concurrent application of both statutory regimes to the same underlying asset would expose market operators to dual regulatory obligations, duplicative licensing requirements, and the real prospect of conflicting regulatory directions from two separate authorities. This jurisdictional overlap without express legislative resolution constitutes a systemic legal risk that market operators must account for in their compliance architecture.
From a Shariah perspective, an additional layer of legal complexity arises in assessing whether digital assets can satisfy the requirements of Shariah-compliant financial instruments. Certain categories of digital assets may give rise to Shariah concerns, particularly where they contain elements of speculation, uncertainty, or non-asset backing. However, the underlying blockchain technology also presents features that may support Shariah compliance if appropriately structured. In particular, blockchain transactions are generally irreversible, transparent and traceable, allowing the full transaction flow to be auditable and reducing information asymmetry. These features sit well with the Islamic finance principles of al-ṣidq (truthfulness and transparency) and adl (justice), where parties to a contract must have full knowledge of the terms and conditions to ensure fairness and prevent gharar (excessive uncertainty). The near-instant settlement of blockchain transactions may also help avoid riba (interest), depending on how the arrangement is structured. In short, digital assets built on blockchain can potentially operate in line with Shariah principles if appropriately designed.
This is not a theoretical risk. Circle and Stripe are already building infrastructure to support autonomous AI agents that execute high volumes of stablecoin transactions continuously. These agents run directly on blockchain-based stablecoin rails, bypassing traditional card networks — and they operate around the clock without human authorisation of each transaction.
Malaysian law has yet to develop in conjunction with these advancements. The Contracts Act 1950 — the primary statute on contract formation — assumes that only natural persons or corporations can enter agreements or bear liability for misconduct. When an autonomous AI agent makes a financial error, there is no clear legal person who owns that mistake. AI has no legal personhood and no capacity for moral judgment.
A definitive example of the risks associated with AI-driven digital assets occurred in February 2026. An AI agent named Lobstar Wilde, created by OpenAI engineer Nik Pash, accidentally sent 52.4 million LOBSTAR tokens worth USD 450,000 to a random stranger. The bot had been designed to autonomously trade memecoins and had started with USD 50,000 in SOL. The error was traced to an API misunderstanding in the older OpenClaw framework, where a decimal misinterpretation caused the bot to transfer 52.4 million LOBSTAR tokens instead of the intended 52,439 tokens.
Where an AI agent such as Lobstar Wilde commits an error, the immediate legal question is who is liable. Under current Malaysian law, that points to the humans behind it: (i) the developers who designed or trained the system, (ii) the operators who deployed and configured it, (iii) beneficiaries who materially profited from its activity, or (iv) others behind the agent’s actions in executing transactions. Using AI does not remove liability — it spreads it across a wider chain. As AI becomes more central to digital asset operations, the question of who owns the risk when something goes wrong is one market operators cannot afford to leave unanswered.
Recognising these gaps, the Malaysian government approved the establishment of the National AI Office (NAIO) in August 2024, with NAIO officially launched by the Prime Minister on 12 December 2024 to oversee the National AI Roadmap 2021-2025 and the subsequent Action Plan 2026-2030. Malaysia’s National AI Office has since published a Public Consultation Paper seeking feedback on the proposed AI Governance Bill; as of 1 August 2026, that public consultation has closed. The Consultation Paper indicates the Bill will adopt three core approaches — institutional oversight through a proposed Central AI Authority, principle-based governance, and a risk-based framework — anchored to a three-tier risk classification of unacceptable, high, and low risk, with compliance obligations scaled according to potential impacts on safety, rights, and public interest.
The third risk follows naturally from the second. As AI agents execute transactions, manage liquidity and interact with DeFi protocols, they will process large amounts of personal data. Where that involves automated decision-making and profiling (“ADMP”), the Malaysian Personal Data Protection Act 2010 (“PDPA”) applies. On 30 April 2026, the Department of Personal Data Protection issued the ADMP Guideline, setting out what is required when AI is involved in decisions affecting individuals:
As Malaysia moves from treating digital assets as a speculative instrument to integrating them into its core financial infrastructure, the burden of preparedness falls on market operators. Getting ahead of these risks requires more than a compliance tick-box exercise.
Specifically, market operators should focus on:
Those who put the right governance structures in place now will be better positioned to use what blockchain and AI genuinely offer — and to do it in a way that is both legally sound and Shariah-compliant.
This article was authored by Suaran Singh Sidhu (Partner) and Joel Prashant (Senior Associate).
Please contact our team if you have any questions.
Suaran Singh Sidhu | Head, Technology, Media and Telecommunications