Malaysia & Defence AI: Left Behind or Being Careful? — Malay Tech JournalSkip to content

Malaysia & Defence AI: Left Behind or Being Careful?

Singapore has deployed autonomous drones, DSTA runs AI detection systems — and Malaysia? We need to ask this question honestly: where do we stand, and where should we go?

Field notes. This is not an attack on the Malaysian government — it’s a question that young Malaysian engineers need to take seriously. All sources used are publicly available reports, parliamentary records, and open policy documents.

Every time another country war-games with drone swarms, what is Malaysia doing?

Every time an AI targeting system is announced, where are we?

This isn’t about embarrassing anyone. It’s a question that matters to every young Malaysian engineer working in cloud, AI, or security — because the answer determines whether we become players or users in the defence technology landscape of this decade.


Before focusing on Malaysia, let’s look at our neighbours.

DSTA (Defence Science and Technology Agency) is the backbone of Singapore’s defence technology. They don’t just buy weapons — they build systems:

  • SAF (Singapore Armed Forces) runs active autonomous drone programmes, including urban environment testing
  • DSO National Laboratories — AI researchers for defence applications, collaborating with universities and industry
  • Singapore has integrated AI into logistics, C2 (command and control), and perimeter detection systems

Singapore is geographically small, but in terms of defence AI capability, they are several generations ahead of most ASEAN nations.

Indonesia has BRIN (National Research and Innovation Agency) and its own military drone programme, but remains in early phases. The complex geographic terrain drives a focus on conventional defence.

As a US treaty ally, the Philippines gains access to systems and data unavailable to other regional nations — including JADC2-adjacent intelligence relevant to the South China Sea.

Both have military drone programmes but limited to purchased platforms rather than domestically developed autonomous AI systems.


STRIDE (Science and Technology Research Institute for Defence) is Malaysia’s primary defence research body under the Ministry of Defence.

What we know (from public sources):

  • Core focus: materials, electronics, and conventional weapons systems
  • Some R&D in C4I (Command, Control, Communications, Computers, and Intelligence)
  • No public announcements on specific AI programmes for autonomous systems or AI-assisted targeting

What remains unknown:

  • How much of STRIDE’s budget goes to AI R&D? Annual reports are not publicly detailed.
  • Is there formal collaboration with local universities (UTM, UTP, UM) on defence AI? No clear public data.

NACSA (National Cyber Security Agency), established 2017 under the Prime Minister’s Department. Mandate:

  • Protect national critical infrastructure
  • Coordinate cyber incident response
  • Regulate the cybersecurity industry

NACSA is important cyber defence — but their mandate does not cover offensive AI or autonomous weapons. This is a fundamentally different capability from what Singapore’s DSTA does.

ATM (Angkatan Tentera Malaysia / Malaysian Armed Forces) comprises the Army, Navy, and Air Force. Based on public statements and defence budgets:

  • Malaysia has procured modern weapons platforms (Rafale jets, Scorpène submarines) — conventional platforms
  • No publicly declared AI doctrine for autonomous weapons or AI-integrated C2
  • ATM drone programmes exist (ALUDRA MKII for RMAF) but these are conventional reconnaissance platforms, not autonomous AI systems

Malaysia’s AI Roadmap (AIRMAP 2.0), released by MDEC, is a comprehensive AI policy document — but is almost entirely focused on:

  • Digital economy
  • Industry 4.0
  • Education and talent pipeline

Defence and national security are barely mentioned in AIRMAP 2.0’s public documents. This is a stark contrast with, for example, the US National AI Strategy or Singapore’s Digital Defence blueprint.


DimensionMalaysiaSingaporeIndonesia
Defence AI R&D bodySTRIDE (limited public output)DSTA + DSO (active, published)BRIN (early stage)
Autonomous systems programmeNo public announcementSAF active drone programmeEarly stage
Industry-defence collaborationLimited (DEFTECH, SME Aerospace)Broad ecosystem (ST Engineering, Thales SG)Growing
Public AI defence doctrineNonePartially in Singapore Defence White PaperNone
AI talent in defence sectorLimited — no clear pipelineSystematic — NSmen with AI background placedLimited
Defence budget (% GDP)~1.0%~3.0%~0.8%
Autonomous weapons policyNo public stanceEngaged in UN CCW discussionsNo public stance

This isn’t just about numbers. It’s about strategic intent — is AI defence a national priority or not?


Malaysia has legitimate reasons to move deliberately:

1. Malaysia is not a great power We have no active conflict. No existential threat requiring autonomous weapons. Excessive defence spending would compromise social development.

2. Non-Aligned Foreign Policy Malaysia has historically maintained balanced foreign relations — not overly aligned with any bloc. Aggressively deploying defence AI could disrupt this diplomatic equilibrium.

3. LAWS ethical concerns are valid Autonomous weapons capable of killing without human decision are a serious ethical issue. 31+ countries want a LAWS ban. Malaysia could be a principled voice in UN CCW.

4. High development costs Singapore can invest heavily due to their fiscal position. Malaysia must balance defence against education, infrastructure, and healthcare.

But “being careful” has limits:

1. Cyber threats are real and AI-assisted today Volt Typhoon, APT41 — these are not future threats. NACSA already faces increasingly sophisticated attacks. Without AI-assisted defence, we’re bringing a knife to a gunfight.

2. The South China Sea is a real issue Malaysia has overlapping claims in the South China Sea. Maritime surveillance without AI means relying on limited assets to cover vast waters.

3. Foreign AI surveillance entering unchecked Huawei Safe City deployments exist in Malaysia — urban camera and analytics systems supplied by a Chinese company using the same technology deployed for surveillance in Xinjiang. We don’t yet have a clear policy response to this.

4. Brain drain risk is compounding Malaysian AI engineers are leaving for Singapore, the US, and UK — because opportunities are better there. Without a strong defence tech ecosystem, we keep losing the talent that could build national capability.


These aren’t political demands. These are technical recommendations from an engineering perspective:

1. Publish a clear AI Defence Strategy Malaysia needs a document equivalent to Singapore’s Defence White Paper that explicitly addresses AI. Not just “we use AI for the economy” — but “here is our position on defence AI and offensive cyber.”

2. Give STRIDE an explicit AI mandate STRIDE needs a dedicated AI unit with formal partnerships with UTM, UTP, and UM. Model after Israel’s Technion-military pipeline or DARPA-university grant structures.

3. Audit foreign technology in critical infrastructure Before building our own capability, we need to know what’s already embedded in our systems. Huawei Safe City, Hikvision cameras — these demand policy answers, not silence.

4. Build a defence tech talent pipeline Singapore’s NSmen AI/cyber programme doesn’t need to be copied exactly — but Malaysia needs a mechanism to keep tech talent in the national ecosystem, whether in public sector or defence-adjacent private industry.

5. Engage actively in LAWS discussions at UN Malaysia can be a meaningful voice in UN CCW on autonomous weapons. This isn’t weakness — it’s authentic soft power aligned with our values.


You might be working in fintech, e-commerce, or SaaS. This all feels distant.

But the skills you have — cloud architecture, AI/ML, security engineering — are exactly what defence AI requires.

Questions worth thinking about:

  • If your company receives a government contract for a surveillance system or AI security tool, do you understand the ethical and legal implications?
  • Do you know what Malaysia’s PDPA 2010 says about facial recognition and public biometric data?
  • As an engineer, do you have a responsibility to ask “what will this system be used for?”

Malaysia is behind in several dimensions. But we have a generation of young engineers who can change that — if we recognise that these questions matter.


“Left behind or being careful?” has no easy answer.

What’s clear: silence is not a strategy. The defence AI landscape is moving fast, cyber threats are real today, and our neighbours are already moving.

Malaysia needs an honest public conversation about where we’re going — not just inside government, but within our own engineering and tech community.

This series continues with: AI surveillance, intelligence, and civilian privacy in Southeast Asia.