Malaysia has intensified its crackdown on artificially manipulated content, with the Malaysian Communications and Multimedia Commission removing nearly 12,400 deepfake posts since the start of the year. Between January and June 2024, the MCMC filed 13,122 removal requests with social media platforms, achieving a 94 per cent success rate with licensed service providers taking down 12,353 posts, according to parliamentary responses tabled this week.
The aggressive removal campaign reflects growing regulatory concern about deepfakes and image manipulation technology, which can be weaponised for electoral interference, financial fraud, and reputation damage. For Malaysian social media users and content creators, the statistics underscore a rapidly evolving enforcement landscape where artificial intelligence-generated or altered media faces increasing scrutiny. The high removal rate suggests effective coordination between regulators and major platforms, though the scale of initial requests indicates that problematic content remains widespread across Malaysia's digital ecosystem.
Complementing the deepfake enforcement, authorities have simultaneously targeted scam-related content with comparable vigour. The MCMC submitted 275,787 removal requests for fraudulent posts including fake accounts and impersonation schemes, with 262,293 items—representing 95 per cent—successfully deleted by platform operators. This parallel enforcement effort demonstrates that scams and deepfakes often operate together, with malicious actors using manipulated images and false identities to establish credibility before defrauding victims. For Malaysian consumers increasingly vulnerable to online fraud, these numbers highlight both the scale of the threat and the government's commitment to intervention.
A significant regulatory shift occurred on June 1 when Malaysia's new Risk Mitigation Code came into force, requiring all licensed platform providers to implement AI content labelling. This requirement mandates that content generated or significantly altered using artificial intelligence—including deepfakes, manipulated images, and synthetic audio—must be clearly labelled for users. The move aligns Malaysia with international best practices, particularly those emerging in the European Union and other jurisdictions grappling with AI-generated misinformation. For Malaysian digital platforms, the code represents a fundamental change in content governance, shifting responsibility for transparency directly onto service providers rather than relying solely on post-hoc removal.
The enforcement framework has expanded further with the Online Safety Act 2025, which came into effect earlier this year. Between January and June, authorities submitted five removal requests specifically targeting financial scams under this legislation, with all content successfully taken down. While the figure appears modest compared to broader enforcement efforts, it signals that authorities now possess statutory tools specifically designed to address online safety threats beyond traditional communications law. The Online Safety Act represents a generational shift in Malaysia's approach to digital regulation, moving beyond reactive content removal toward proactive platform accountability.
Broader investigations into false information reveal the extensive investigative burden facing regulators. The MCMC examined 574 cases involving false online content under Section 233 of the Communications and Multimedia Act 1998 across the January 2022 to June 2024 period. Of these, 23 cases proceeded to court, with 12 concluded and 11 still in trial. The courts imposed combined fines totalling RM79,000 against convicted offenders, while one individual faced six months' imprisonment after defaulting on financial penalties. These prosecutions, though numerically modest relative to the investigation caseload, establish important legal precedent and demonstrate that courts are willing to impose custodial sentences for false information offences.
Outside formal prosecution, the MCMC has employed a graduated enforcement approach reflecting administrative efficiency. A total of 31 cases received compound offers amounting to RM1.22 million, allowing offenders to settle without court proceedings. Simultaneously, 84 warning letters were issued to content creators and account holders, providing opportunities for compliance without financial penalty. A further 47 cases remained under active investigation, while others were classified as requiring no further action. This tiered approach recognises that not all false information originates from bad faith actors; some results from misunderstanding or negligence, making graduated enforcement more proportionate than blanket prosecution.
The response to specific platforms demonstrates the complexity of content moderation in Malaysia's polarised online environment. When questioned about the HarakahDaily Facebook account, authorities confirmed that no First Information Report had been filed as of June 30, despite apparent scrutiny. The ministry's statement that firm action would follow if any content breached legal or platform standards suggests that HarakahDaily faces ongoing monitoring but has not yet crossed thresholds triggering formal intervention. This measured approach indicates that regulators distinguish between controversial political content and demonstrable legal violations—an important distinction for preserving space for legitimate political discourse.
For Malaysian readers and digital economy participants, these enforcement statistics carry several implications. The high removal rates suggest that platforms are responsive to regulatory pressure, which may incentivise users to report problematic content. However, the sheer volume of initial requests—nearly 290,000 across deepfakes and scams combined—suggests that the underlying problem remains substantial. Content creators and ordinary users must navigate increasingly complex rules around AI-generated media, particularly with the Risk Mitigation Code's labelling requirements now in effect. Small businesses and individual entrepreneurs who use AI tools for legitimate purposes may face compliance burdens.
The regulatory environment also raises questions about enforcement consistency across different platforms and content categories. While statistics demonstrate removal efficacy at aggregate level, questions persist about whether emerging platforms, encrypted services, and cross-border content distribution receive equivalent scrutiny. Southeast Asian readers should recognise that Malaysia's experience reflects broader regional concerns about AI misuse, with Singapore, Thailand, and Indonesia implementing comparable measures. Malaysia's approach—combining removal-based enforcement with code-based labelling requirements—may serve as a model for neighbouring jurisdictions developing AI governance frameworks.
Looking forward, the maturation of Malaysia's regulatory toolkit suggests that future enforcement will increasingly emphasise platform accountability and ex-ante prevention rather than post-hoc removal. The Risk Mitigation Code and Online Safety Act represent this institutional evolution. However, the challenge of false information enforcement remains formidable; with 574 investigations yielding only 23 prosecutions, authorities face capacity constraints and definitional complexities around what constitutes actionable false information versus protected speech. As artificial intelligence capabilities advance, Malaysia's regulatory framework will require continuous updating to maintain effectiveness without stifling legitimate innovation.
