Request for Proposal (RFP): Study of AI Sandbox - MyDIGITAL
Skip links

Request for Proposal (RFP): Study of AI Sandbox

Request for Proposal (RFP): Study of AI Sandbox

Procurement Notice

Request for Proposal (RFP): Study of AI Sandbox

Introduction:

National AI Office Malaysia (NAIO) under MyDIGITAL Corporation is seeking proposals from experienced and qualified organisations to support a study on the development of a Sandbox for Artificial Intelligence (AI Sandbox Study) as a safety-oriented AI governance mechanism, and to provide advisory, technical and implementation support on the possible design, governance and operationalisation of AI sandbox arrangements in Malaysia. The study will provide the evidence base, options and recommended pathway for NAIO and relevant stakeholders to determine the most suitable approach for controlled testing of AI systems before wider deployment, scaling or regulatory reliance.

Under this initiative, NAIO intends to facilitate coordination among relevant public-sector bodies, regulators, industry, academia and technical partners to clarify the purpose, scope, control boundaries, risk-monitoring mechanisms, governance model, evidence requirements and operational requirements of AI sandbox arrangements. The study is expected to support Malaysia’s broader AI Nation 2030 aspirations by contributing to safe, responsible and trusted AI adoption, particularly in relation to AI safety, risk management, responsible governance, regulatory learning, sectoral coordination and practical implementation readiness.

The outcomes of the study should assist NAIO and relevant subject-matter experts in understanding the appropriate model for AI sandboxing in Malaysia. This includes identifying legal, policy, technical, operational and institutional requirements, and determining whether AI systems, AI-enabled services or AI implementation should continue, be modified, be limited to certain conditions, be subjected to further safeguards, undergo additional testing, be restricted or be prevented. The study should also determine whether further policy instruments, standards, regulation, implementation guidelines or pilot arrangements may be required.

In addition, the study should examine whether and how a common safety baseline, evidence requirements, testing protocols, performance benchmarks and governance practices may support greater consistency across sectors. This should be done without displacing the role of sectoral regulators, existing approval mechanisms or sector-specific legal requirements, and should focus on enabling evidence-based practices for safe AI development, deployment and adoption.

Summary Scope of Work:

The vendor will be responsible for a comprehensive range of services including but not limited to:

  1. Baseline Study, Ecosystem Analysis, Problem Definition and Benchmarking for an AI Sandbox
    • Conduct a focused study to understand Malaysia’s landscape of controlled testing environments and programmes in order to identify current practices, institutional roles, sectoral gaps, technical capabilities, regulatory uncertainties, data governance requirements, privacy, cybersecurity, AI safety, human oversight, ethical AI considerations and the practical problems that an AI sandbox is expected to solve.
    • The vendor shall assess regulatory and technical readiness, identify key risks and compliance gaps, benchmark relevant international AI sandbox, AI safety evaluation and virtual testing models, and survey suitable governance and approval mechanisms in order to provide findings and options that support secure, safety-oriented and practical sandbox arrangements. The vendor shall analyse the different sandbox archetypes and determine which elements may be relevant for Malaysia, including technical testing, data access, model assurance, product or service pilots, operational workflow testing, learning or simulation arrangements, and regulatory or supervisory arrangements, with emphasis on how each element contributes to risk containment, safety assurance and evidence-based decision-making.
  2. Proposed AI Sandbox Governance Options
    • Design a proposed structured AI sandbox governance options paper for NAIO’s consideration, including:
      • Sandbox objectives, scope, structure, and governance model;
      • Categories of use cases suitable for testing and categories that may require exclusion, restriction, heightened scrutiny or additional safeguards;
      • Participation eligibility criteria, application requirements and onboarding processes;
      • Entry, monitoring, reporting, escalation, exit and post-sandbox decision pathways, including criteria for deployment, scaling, restriction, further testing or discontinuation;
      • Roles and responsibilities of stakeholders (e.g. NAIO, regulators, participants, and technical partners);
      • Control boundaries, including scale limits, time limits, user restrictions, data controls, human oversight, logging, incident reporting, audit trails, kill-switch arrangements and rollback mechanisms;
      • AI risk assessment, safety assessment, compliance assessment and performance evaluation mechanisms; and
      • Operational procedures and implementation guidelines for the AI sandbox, including safety monitoring, incident response, evidence preservation and post-sandbox decision processes.
  3. AI Assurance Framework
    • Develop the AI assurance overarching approach for the sandbox, the processes by which AI systems are tested, verified, documented and monitored to demonstrate they are trustworthy and fit for their intended use as a complement to AI Safety, the AI Governance Bill and the MY-AI Standards initiative:
      • Certification process;
      • Data governance, privacy, cybersecurity, safety and ethical AI considerations;
      • Sectoral regulatory overlaps and relevant approval or notification mechanisms;
      • AI risk management considerations and evidence requirements for sandbox participation;
      • Possible compliance assessment processes within a sandbox environment;
      • Standards, testing protocols, performance metrics and benchmarking approaches that may be referenced or adapted; and
      • Options for future non-binding guidance, implementation instruments, standards-referencing documents or regulatory proposals, where appropriate.
  4. Virtual Testing Environment Framework
    • Propose and define the architecture for a virtual testing environment and safety assurance process, including:
      • Technical infrastructure, data environment and platform requirements;
      • Testing protocols, validation procedures, red-teaming or stress-testing approaches, and performance evaluation metrics; and
      • Risk identification, monitoring and mitigation mechanisms, including incident logging, audit trails, human override and rollback arrangements.
  5. Pilot Design and Safety Validation
    • Design a pilot implementation and safety validation plan using selected illustrative use cases or stakeholder scenarios. This may include engagement with government agencies, regulators, industry, academia, technical experts and other relevant stakeholders, to:
      • Test and refine the safety controls, governance tools and operational processes;
      • Validate regulatory, technical and safety assurance components; and
      • Capture lessons learned, risk signals, evidence gaps and improvement areas.
  6. Stakeholder Engagement and Capacity Building
    • Engage with key stakeholders (government, industry, academia) through workshops, consultations, and focus groups to:
      • Ensure alignment and adoption
      • Gather feedback for continuous improvement
      • Build awareness and capability in AI safety, AI governance and practical implementation
  7. Final Deliverables & Recommendations
    • Provide a complete set of deliverables, including:
      • Malaysia sandbox ecosystem and readiness assessment, including governance gap analysis;
      • AI Sandbox Framework and Governance Model Proposal;
      • Regulatory, Compliance and AI Safety Issues Paper with recommended options;
      • Virtual Testing Environment and Safety Assurance Blueprint;
      • Pilot Design, Safety Validation and Stakeholder Engagement Report; and
      • Final Recommendations Report, including implementation roadmap, safety and governance decision matrix, and proposed next steps for NAIO’s consideration

Eligibility Criteria that qualified vendors should have:

  1. Demonstrated experience in AI governance, AI safety, regulatory frameworks, AI policy development, digital transformation or emerging technology advisory at national, regional or international levels.
  2. Proven capability in designing and implementing AI sandbox frameworks, AI safety evaluation arrangements, regulatory sandboxes, innovation testbeds, virtual testing environments or similar controlled experimentation platforms.
  3. Strong understanding of AI regulations, ethical AI principles, data governance, cybersecurity, privacy requirements, AI safety, risk management and compliance frameworks aligned with national and international standards.
  4. Experience in conducting nationwide assessments, benchmarking studies, readiness assessments, maturity evaluations or standardisation initiatives related to AI safety, AI governance, digital technologies or innovation ecosystems.
  5. Technical expertise in designing virtual testing environments, cloud-based architectures, validation mechanisms, testing protocols, performance monitoring frameworks, AI solution evaluation methodologies and AI safety assurance processes.
  6. Demonstrated ability to develop governance models, operational frameworks, standard operating procedures (SOPs), implementation guidelines, incident escalation processes and compliance mechanisms for multi-stakeholder environments.
  7. Proven experience in stakeholder engagement and facilitation involving government ministries, regulators, public sector agencies, industry players, academia, and technology communities.
  8. Capability to design and execute pilot programmes, proof-of-concept initiatives or validation exercises involving AI systems, safety validation, regulatory testing or technology deployment.
  9. Availability of a qualified multidisciplinary team comprising experts in AI, AI safety and evaluation, technology architecture, cybersecurity, governance, public policy, legal and regulatory compliance, research and analytics, and project management.
  10. Demonstrated experience working with government agencies, regulators, GLCs, or national strategic initiatives will be an added advantage.
  11. Vendors must be legally registered entities in Malaysia (or internationally registered entities with a local presence/partner, if applicable), with sound financial standing and sufficient operational capability to deliver the project within the stipulated timeline.
  12. Ability to deliver high-quality outputs, including frameworks, technical blueprints, safety and evaluation instruments, benchmarking models, governance guidelines, pilot implementation reports and strategic recommendations aligned with national policy requirements and standards

Registration of Interest and NDA Submission:

  • Interested organisations are invited to fill out the registration form at link [https://forms.gle/Wa3f6o8xCtAFsG6f9] and submit the Non-Disclosure Agreement to the Procurement Secretariat at admin@mydigital.gov.my with email subject: <company name> NDA AI Sandbox
  • Please note that only participants who successfully registered their interest and submitted their NDA by the deadline will receive the RFP document and are eligible to proceed with proposal submissions.

Deadlines:

  1. Registration of interest and submission of the NDA is 12:00 PM, 12 August 2026.
  2. Proposals must be submitted by 11:59 PM, 23 August 2026.

Terms and Conditions:

MyDIGITAL Corporation reserves the right to reject any or all registrations or proposals and to negotiate with any vendor.