Malaysia's digital regulators are ramping up their enforcement against manipulated media and artificial intelligence-generated content, with the Malaysian Communications and Multimedia Commission successfully removing nearly 12,400 deepfake posts during the opening half of 2024. The figures, disclosed in parliamentary replies tabled this week, underscore the growing challenge posed by image and video manipulation technology as it becomes increasingly accessible to bad actors seeking to deceive the public or perpetrate fraud.
The MCMC filed 13,122 removal requests with social media platforms between January 1 and June 30, targeting content created or altered using deepfake technology. Of these submissions, licensed service providers complied with 12,353 takedowns—a 94 per cent success rate that demonstrates relatively smooth cooperation between Malaysia's regulatory apparatus and international technology firms operating within the country. The high compliance rate reflects both platform companies' desire to maintain their operating licences in Malaysia and the technical capacity of moderation teams to identify and remove flagged material.
Beyond deepfake content alone, Malaysia's enforcement machinery has been stretched across a broader spectrum of online harms. The same six-month period saw the MCMC request removal of 275,787 pieces of scam-related content, encompassing fake accounts, impersonation schemes, and other fraudulent material. Service providers succeeded in taking down 262,293 such posts, again achieving approximately 95 per cent compliance, suggesting that platforms take financial fraud allegations particularly seriously given the direct consumer harm and regulatory liability they entail.
The drive to tackle manipulated media represents a significant policy shift in Malaysia's approach to digital regulation. Beginning June 1, the newly implemented Risk Mitigation Code mandates that licensed platform operators affix clear labels to any content generated, synthesised, or substantially altered through artificial intelligence systems. This requirement extends to deepfakes, manipulated photographs, and doctored audio recordings. The labelling regime aims to provide users with transparency about content authenticity before they share or act upon information, addressing a fundamental vulnerability in how information spreads through social platforms.
For Malaysian consumers and voters, the implications are substantial. During elections and political campaigns, deepfakes have proven particularly corrosive to democratic discourse, with manipulated videos of politicians or public figures sowing confusion and undermining trust in media institutions. The region has witnessed several high-profile deepfake incidents in neighbouring countries, making Malaysia's proactive stance timely. The new labelling system functions as a first line of defence, flagging suspicious content to users who might otherwise assume they are viewing authentic material.
Parallel enforcement under the newly enacted Online Safety Act 2025 has also commenced. During the January-to-June window, authorities submitted five removal requests specifically targeting financial scam content under this legislation, and all five were successfully taken down. The Online Safety Act represents Malaysia's most comprehensive framework yet for combating harmful online conduct, moving beyond traditional defamation and obscenity laws to address emerging categories of digital harm including scams, harassment, and identity fraud.
The broader investigation landscape reveals both progress and persistent challenges. The MCMC conducted 574 investigations into false or misleading online content under Section 233 of the Communications and Multimedia Act 1998 during the January 2022 through June 2024 timeframe. Of these cases, 23 were forwarded for prosecution, with 12 concluded in court. Those completed prosecutions resulted in total fines of RM79,000, with one offender additionally receiving a six-month jail sentence after defaulting on financial penalties. The relatively modest number of prosecutions relative to investigations suggests that many cases either lack sufficient evidence for court proceedings or are resolved through alternative enforcement mechanisms.
Compound settlements and administrative penalties have become a preferred tool for regulators seeking to deter online misconduct without burdening the courts. As of late June, authorities had offered compounds totalling RM1.22 million across 31 cases, issued 84 warning letters, and left 47 cases pending investigation. This tiered enforcement approach allows regulators to address lower-level violations efficiently while preserving prosecutorial resources for serious offenders. Many cases are also classified as requiring no further action, reflecting determinations that content, while flagged, does not ultimately breach applicable laws or platform guidelines.
The parliamentary responses also touched on a specific controversy involving HarakahDaily, an opposition-affiliated news outlet whose Facebook account drew scrutiny over its content. The ministry confirmed that no formal First Information Report had been lodged as of June 30, though it reserved the right to take action should the content violate legal standards or platform terms. This measured stance avoids accusations of political selectivity while maintaining that enforcement authorities remain prepared to act if genuine breaches occur.
For Malaysia's position within Southeast Asia, these regulatory developments matter considerably. The region faces common challenges around election integrity, financial fraud, and social cohesion threats posed by synthetic media. Malaysia's approach—combining technological labelling requirements, cooperative takedown procedures, and targeted prosecution—offers a model that neighbouring countries may study and adapt. However, the relative scarcity of prosecutions to date also highlights the difficulty of translating regulatory intent into courtroom outcomes, particularly when deepfake creators operate across borders or employ sophisticated techniques to evade detection.
The figures themselves require careful interpretation. A 94 per cent takedown success rate sounds impressive but reflects only the universe of content that authorities successfully identified and reported to platforms—an unknown fraction of deepfakes actually circulating online. Adversaries continue developing more convincing synthetic media while regulation and detection technology struggle to keep pace. The MCMC's enforcement activity is fundamentally reactive, depending on users or platform algorithms to flag problematic content rather than proactively scanning for new deepfakes before they spread.
Looking ahead, Malaysia's regulatory framework will face mounting pressure as generative AI tools become cheaper and more widely available to ordinary users. Distinguishing between malicious deepfakes created to defraud or deceive and legitimate uses of AI-assisted media production remains a nuanced challenge. The Risk Mitigation Code's labelling requirement provides a blunt but practical instrument for this purpose, though sophisticated users and bad actors may learn to circumvent labels or strip them from content before redistribution. Sustained investment in detection technology, investigative capacity, and cross-border cooperation will likely be essential if Malaysia is to maintain its current enforcement trajectory as the scale of synthetic media threats expands.
