I flagged a few weeks ago that this sitting had a heavy ICT agenda on the order paper. The answers have now come through, and there is real substance here for anyone in the ICT Federation, or in tech more broadly.
AI misuse: government is not creating new AI specific law, and that is deliberate
YB Dayang Chong Chin Yee asked directly how government plans to protect consumers, identity and intellectual property from AI misuse, deepfakes, impersonation and unauthorised use of creative work.
The Ministry’s answer was clearer than I expected. Their position is that AI is not a separate legal category, it is a tool. So instead of writing new AI specific offences, they are mapping AI harms onto existing law based on which agency has jurisdiction over the underlying harm.
Practically, that means a deepfake used to defraud someone falls under the Penal Code’s fraud and identity theft provisions. Personal data scraped or misused to train or run an AI system falls under the Personal Data Protection Order. AI generated content that infringes copyright or trademarks falls under the Copyright Order 1999 and Trade Marks Act, with BruIPO as the lead agency. Cyber intrusion involving AI tools falls under the Cyber Security Act and Computer Misuse Act.
Alongside that, AITI’s Working Group on AI Governance and Ethics released the second edition of the Guide on AI Governance and Ethics in April 2026, specifically addressing generative AI risk. Cyber Security Brunei has also updated the Code of Practice for Critical Information Infrastructure to include an AI Security Policy, and a more detailed AI Security Policy Guideline covering generative, agentic and autonomous AI is in the pipeline.
For anyone building or deploying AI systems commercially here, this is worth reading closely. The regulatory direction is enforcement through existing law plus a growing governance framework, not a standalone AI Act. If you are advising clients on compliance, that framing matters.
Cyber threat monitoring capability, more mature than I expected
YB Dayang Hajah Rosmawatty asked how far government’s actual capability goes on data collection, risk based monitoring, early warning systems and platform cooperation.
The answer laid out four layers. Cyber Security Brunei and BruCERT run the Cyber Watch Centre around the clock using advanced security intelligence monitoring. BruCERT issues real time alerts and technical advisories, and shares threat intelligence nationally, regionally and internationally. On the public facing side, the Secure Verify Connect platform pushes warnings to schools, communities, the elderly and persons with disabilities, and AITI runs Waspada.bn for fact checking scam claims and reporting suspicious content.
Two things worth flagging for the industry specifically. A Scamwatch portal is being built as the main reporting channel, aimed at speeding up fund freezing after a scam. And government confirmed active cooperation with Meta on threat intelligence sharing, coordinated response and content takedown requests. If your company works in fraud detection, identity verification, or platform trust and safety, both of these are worth watching, they could turn into real partnership or procurement opportunities.
Government is finally measuring digital services beyond usage numbers
YB Dr Awang Haji Mahali asked whether government looks past adoption rates to actually measure user experience and service reliability.
The answer confirmed a proper governance structure exists. New digital transformation projects go through a Digital Transformation Review Committee after CIO sign off at ministry level, coordinated through the CIO Forum to avoid duplicate systems. On the user side, EGNC and the Public Service Management Department run the Pemedulian satisfaction survey platform, and there is a stated commitment to build feedback mechanisms directly into government apps going forward, not just bolt them on afterward.
Critical services are also required to have backup and recovery mechanisms plus a defined incident communication process. If you do UX work, service design, or systems integration with government platforms, this is a useful signal that procurement criteria are shifting from just build it toward build it, measure it, and keep it running.
Port and trade digitalisation is moving, with real infrastructure behind it
Several members asked about maritime digitalisation, and the answer here was the most detailed of the batch.
MPABD is rolling out a Port Community System in phases starting this year, connecting government agencies, port operators, shipping lines, agents and logistics providers on shared data rather than each running separate systems. This sits alongside a Maritime Single Window as the regulatory front door. A National Maritime Data Hub Dashboard is also being built to track vessel clearance times, cargo processing times, and port and logistics chain performance in real time.
For cross border trade specifically, digitalisation of the Cross Border Permit for commercial vehicles is targeted for completion by January 2027. Government was upfront that digitalisation will not automatically lower shipping rates, those are commercial decisions by carriers, but it should cut the cost and time lost to manual processes, duplicate paperwork and delays.
If your company touches logistics tech, trade documentation, or port operations software, this is a live, funded, multi year integration programme with a real dashboard and real data outputs. Worth getting in front of MPABD directly if you have not already.
Internet coverage numbers, for context
Fixed broadband now covers 96 percent of the population, mobile network covers 99 percent, and 5G specifically covers 97.65 percent. As of June 2026, 99.97 percent of residential fixed broadband subscribers get speeds matching their subscribed plan of 100 Mbps or above. 38 new telecom towers have gone up since 2021, with three more underway in rural areas including Kampung Kuala Unggar and Kampung Lamaling.
Useful baseline numbers if you are pitching anything that assumes a certain level of connectivity outside Bandar.
Why this matters
Taken together, this batch of answers gives a clearer read than usual on where government’s digital priorities and procurement appetite actually sit right now, AI governance mapped onto existing law, cyber threat sharing partnerships with global platforms, service quality accountability structures, and a genuinely large port and trade digitalisation programme with real deadlines attached. Worth a proper read if any of this touches your business.
