Malaysia's regulatory authorities have ramped up efforts to combat synthetic media and manipulated content, with the Malaysian Communications and Multimedia Commission removing over 12,000 deepfake-related posts during the opening six months of this year. The MCMC submitted 13,122 removal requests to social media platforms between January and June, successfully taking down 12,353 posts—a 94 per cent success rate that underscores both the scale of the problem and the effectiveness of the regulator's enforcement strategy in an increasingly digital landscape.
The figures reveal just how prevalent image and video manipulation has become across Malaysian digital spaces. Deepfakes—synthetic media created using artificial intelligence to impersonate real people or fabricate events—present a significant threat to public discourse and individual security. The high removal success rate suggests that major social media platforms are cooperating effectively with MCMC directives, though the sheer volume of requests indicates that malicious actors are continuously uploading compromised content faster than ever before. For ordinary Malaysians, this enforcement activity represents a critical shield against identity fraud, financial scams, and political manipulation that could undermine social stability.
Beyond deepfakes alone, the regulatory picture extends to a broader ecosystem of online fraud. Between January 2022 and June 2024, the MCMC requested removal of 275,787 scam-related posts encompassing fake accounts and impersonation schemes, with 262,293 successfully deleted—achieving a 95 per cent removal rate. This parallel enforcement effort shows that Malaysian authorities view synthetic media manipulation as one component of a larger coordinated campaign targeting vulnerable internet users. The consistency between deepfake and scam removal rates suggests systematic cooperation from platforms and demonstrates that regulatory pressure is translating into tangible protection for consumers and citizens.
A significant development in Malaysia's digital governance framework arrived with the Risk Mitigation Code, which took effect on June 1 this year. Under this new standard, licensed digital platform operators must now label content that has been generated, edited, or altered using artificial intelligence systems. This labelling requirement represents a shift from reactive content removal toward proactive transparency, giving users better tools to assess the authenticity of what they encounter online. For the Malaysian context, where digital literacy remains uneven and misinformation can spread rapidly through messaging apps and social platforms, transparent labelling serves as a crucial safeguard against manipulation at the point of consumption rather than merely after harm has occurred.
The Online Safety Act 2025 has further expanded the regulatory arsenal available to Malaysian authorities. Between January and June, the MCMC submitted five removal requests specifically targeting financial scam content under this new legislation, with all five successfully processed. Though this figure appears modest compared to broader enforcement numbers, it signals that Malaysia now possesses dedicated legislative tools designed specifically to address emerging threats in the online environment. The relatively new status of this act means enforcement patterns are still establishing themselves, and the regulatory infrastructure supporting it remains under development as the government and platforms calibrate their responses.
Fake news enforcement presents a more complex challenge, with varying outcomes across prosecutorial channels. Over the thirty-month period from January 2022 through June 2024, the MCMC investigated 574 distinct cases involving false online content under Section 233 of the Communications and Multimedia Act 1998. Of these, 23 proceeded to court—just four per cent of investigations—suggesting that many cases are resolved through administrative channels rather than criminal proceedings. Twelve cases have concluded with judicial determinations, while eleven remain in active trial, indicating that the criminal process moves slowly and courts are working through a substantial backlog of digital-age cases.
The judicial outcomes in concluded cases demonstrate meaningful consequences for offenders. Malaysian courts imposed total fines amounting to RM79,000 across the twelve concluded prosecutions, with one individual receiving six months' imprisonment after defaulting on financial penalties. This punitive approach sends a deterrent signal to potential perpetrators, though the relatively modest fine amounts raise questions about whether financial penalties alone suffice to discourage wealthy operators of disinformation networks or organised fraud rings. The imprisonment sentence, conversely, signals that Malaysian courts recognise serious fake news cases as worthy of custodial sentences comparable to minor fraud convictions.
Administrative remedies have been deployed more extensively than criminal prosecution. As of June 30, the MCMC had issued compound offers totalling RM1.22 million across 31 cases, suggesting that settlement pathways are preferred for lower-level violations or first-time offenders. The issuance of 84 warning letters indicates that many suspected violations are addressed through graduated enforcement beginning with cautions rather than immediate prosecutions. Simultaneously, 47 cases remained under ongoing investigation as of month-end, with additional cases classified as requiring no further action—highlighting the reality that not all reported content necessarily violates applicable law, and that regulatory discretion plays a substantial role in case prioritisation.
The MCMC's approach to controversial content platforms reflects the complexity of balancing free expression with harm mitigation. Regarding the HarakahDaily Facebook account, authorities stated that no First Information Report had been lodged as of June 30, indicating no formal criminal complaint had been registered. However, the ministry emphasised that firm action would follow if content breaches legal standards or platform guidelines. This measured stance suggests that Malaysian regulators prefer targeted enforcement against specific harmful content rather than platform-wide bans, a strategy that preserves space for legitimate expression while maintaining capacity to act decisively when genuine breaches occur.
For Malaysian businesses and professionals, these enforcement mechanisms carry practical implications for digital operations. The Risk Mitigation Code's labelling requirements mean that anyone creating synthetic media—whether for entertainment, marketing, or research—must ensure clear disclosure to platform operators. Individuals working in creative industries using AI-generated imagery or video must navigate compliance carefully to avoid inadvertent violations. The prosecution and compounding activity also signals that false information submitted as factual reporting, especially in commercial or political contexts, carries genuine legal risk that extends beyond platform enforcement to criminal liability.
The regulatory landscape reflects Malaysia's positioning as a Southeast Asian leader in digital governance, establishing frameworks that neighbouring countries monitor closely. The integration of new legislative tools like the Online Safety Act 2025 with established mechanisms under the Communications and Multimedia Act 1998 creates a layered enforcement environment. Regional peers considering their own approaches to synthetic media and fake news increasingly reference Malaysian precedents, making the effectiveness and fairness of MCMC enforcement consequential not merely domestically but regionally.
Moving forward, the sustainability of these enforcement efforts depends on resource availability, platform cooperation consistency, and regulatory agility in responding to evolving AI capabilities. The removal rates documented thus far are encouraging, yet the underlying volume of flagged content suggests that the challenge continues expanding. Malaysian authorities face the ongoing task of updating frameworks to match technological advancement—a perpetual cat-and-mouse dynamic that will require sustained vigilance, adequate funding, and refined strategic focus on the highest-impact threats to information integrity and citizen security.
