In June, Alibaba Cloud opened two data centers in Johor, bringing the number of Alibaba facilities in Malaysia to a total of five–its largest data center presence in Southeast Asia. The opening came four months after ASEAN endorsed a Malaysia-led framework governing cross-border cloud computing, which set regional principles for data protection, regulatory access, and cross-border data hosting.
Yet even as Malaysia helps write ASEAN’s cloud rules, the region’s growing reliance on Chinese infrastructure may embed norms shaped by Chinese law and comparatively weak or opaque safeguards against cyber misuse, regardless of the principles expressed in member state policies. It may also favor Chinese models whose developers disclose less about such safeguards, even as Beijing tightly controls politically sensitive content in Chinese-developed models. ASEAN governments should thus treat data center investment as a form of AI governance and norms diffusion, rather than a matter primarily or solely of industrial policy.
Only a few companies can provide data centers, computing capacity, and complete cloud and AI systems at the required scale. Cloud providers can influence technical practices beyond their own facilities. Firms and agencies building on their platforms must make their systems compatible with the providers’ services and meet requirements for access, configuration, and security. Because so many digital services depend on data centers, the technical specifications and operating practices adopted in Chinese-built or Chinese-operated facilities will shape the services that run on them.
These facilities are therefore an early place to examine whether Chinese involvement is translating into broader influence over technical standards and operational norms. Dependency through platform lock-in allows this influence to develop and become durable within systems and creates a risk that the government could lose practical control over its use of those systems. Once government agencies and highly regulated industries build services around one provider, implementing different privacy or security standards would often require redesigning entire ecosystems, retraining workers, and shouldering substantial migration costs.
Chinese cloud providers have expanded their footprint in Malaysia and Indonesia through partnerships with governments and businesses to embed their cloud services into the core infrastructure of the digital economy. Even when operating abroad, Chinese cloud providers must comply with China’s Cybersecurity Law, Data Security Law, and National Intelligence Law. These laws create pathways for the Chinese government to compel access to data deemed relevant to national security, not unlike the USA PATRIOT Act, CLOUD Act, and FISA 702. Those same obligations helped U.S. prosecutors build their case against Chinese intelligence officer Xu Yanjun. Under a warrant issued in December 2017, Apple provided the FBI with his iCloud data, which supported his arrest in Belgium and extradition to the U.S. the following year. ASEAN governments are likely aware that using Chinese infrastructure carries risks to personal data, as does using U.S. infrastructure.
In addition to building AI infrastructure in Malaysia, Alibaba is also beginning to train people in how to use it. In 2025, Selangor state recognized Alibaba Cloud as a provider under its Multi Cloud Services initiative. The company now offers training in its proprietary AI Toolkit and certification courses to government agencies, educators, students, and local communities. It has also partnered with the Malaysia Digital Economy Corporation – the government agency under the Ministry of Digital leading the Malaysian economy’s technological transformation – to train small and medium-sized enterprises in adopting cloud computing and AI.
In Indonesia, Huawei has developed similar relationships, such as partnering with the National Cyber and Crypto Agency and the Institut Teknologi Del, establishing a Huawei Academy, and providing digital literacy and cybersecurity training to the Indonesian Air Force. Huawei describes these programs as a means of sharing cybersecurity “best practices” built on its tools and expertise. Through training and socialization, such practices can become the foundation of professional norms.
Sharing best practices and developing norms is not inherently malicious. But these practices are taking root in a region where digital rules and enforcement remain uneven, while intensifying U.S.-China AI competition is making ASEAN countries an increasing focus of U.S. law enforcement action. In Indonesia, a 2024 study found that vague definitions, limited enforcement, and inadequate provisions for AI or big data weakened implementation of the country’s 2022 data protection law. Although the European Union’s General Data Protection Regulation has influenced regional privacy laws, it has not produced uniform standards or enforcement, leaving room for providers’ practices to become defaults. Malaysia’s proposed safeguards may help, but businesses and agencies dependent on one provider may find switching too costly and accommodate practices at odds with domestic privacy goals.
This Chinese infrastructure buildout may also directly support advanced Chinese AI development. The Financial Times reported in November 2025 that Alibaba and ByteDance were training advanced models in Southeast Asian data centers in order to access Nvidia chips unavailable in China. As these facilities become vital to Chinese AI developers’ ability to train advanced models, Beijing may come to view Chinese-operated data centers in ASEAN as strategic assets rather than ordinary overseas investments. As China’s Data Security Law authorizes countermeasures against countries that restrict Chinese investment or trade involving data technologies, any actions within those bounds by ASEAN governments could become a potential area of friction.
While there is no definitive proof that Beijing directs Chinese data centers abroad, the domestic intelligence and data security laws with which they must comply do complicate the idea that this infrastructure will always remain purely commercial. ASEAN’s focus on faster development and accessing its latent potential as a future digital economic power is understandable, especially when foreign providers offer capital, expertise, and capacity that domestic firms cannot yet match. But a digital economy built on systems governed elsewhere raises a basic question about how much digital sovereignty ASEAN actually retains. Affecting the norms upon which ASEAN’s nascent digital economies and AI ecosystems are built may pose a threat that member country governments may underestimate.
In short, ASEAN need not wholly reject the foreign capital and expertise driving its digital growth. Rather, ASEAN governments should diversify data center providers, clarify foreign data access obligations, focus on creating domestic AI capacity, and require full visibility into the flow of data into and out of the data center. They must also preserve the ability to audit operations and intervene if they uncover unauthorized access or foreign interference. Otherwise, member governments may retain the formal authority to write their own AI and privacy rules, but lose the practical ability to enforce them.
This work was supported by the Fulbright Program.














Leave a Reply