Malaysia's regulators have intensified their battle against artificial intelligence-generated manipulation and online deception, with the Malaysian Communications and Multimedia Commission (MCMC) successfully removing over 12,000 malicious posts in the first six months of 2024. According to a parliamentary response tabled in Parliament this week, the agency submitted 13,122 removal requests to social media platforms between January 1 and June 30, with service providers complying in 12,353 cases—representing a 94 percent success rate. The figures underscore both the scale of the problem and the effectiveness of current enforcement mechanisms, though they also hint at the relentless pace at which harmful content proliferates across digital channels.
The deepfake crisis represents a distinctly modern threat to public discourse in Malaysia and the region. Image manipulation technology, which uses AI to create convincing but false visual and audio content, poses particular risks during sensitive periods such as elections or moments of political tension. The ability to fabricate videos of public figures making inflammatory statements or engaging in compromising behaviour can rapidly damage reputations, undermine institutional trust, and inflame communal tensions—consequences that carry particular weight in Malaysia's multicultural society where online narratives can quickly translate into real-world friction.
Paralleling the deepfake enforcement effort, the MCMC has also aggressively targeted scam-related content that exploits AI technology and fraudulent impersonation tactics. Between the same six-month period spanning 2022 to mid-2024, authorities requested removal of 275,787 items of scam content, fake accounts, and impersonation material, with 262,293 successfully taken down—a 95 percent removal rate. This two-pronged approach reflects an understanding that AI-enabled fraud and misinformation often operate through similar distribution networks and technical infrastructure, making coordinated enforcement more efficient than treating these issues in isolation.
A significant regulatory shift arrived on June 1 when the Risk Mitigation Code entered force, requiring all licensed platform providers to implement labelling systems for content generated or manipulated using artificial intelligence. This requirement applies not only to deepfakes but also to altered images, synthesised audio, and other AI-manipulated material. The obligation to transparently disclose AI involvement in content creation represents a more nuanced approach than outright removal—it acknowledges that AI-generated material exists on a spectrum from purely entertainment-focused synthetic media to weaponised disinformation, and that informed consumers deserve visibility into how content was produced rather than simply having it erased from public view.
The Online Safety Act 2025 provided additional enforcement tools, with authorities submitting five removal requests specifically targeting financial scams between January and June. All requested content was removed, suggesting that financial crimes may occupy a different category of online harms than political or social deepfakes, with platforms potentially maintaining more stringent compliance standards around clearly illegal commercial fraud. These tools represent Malaysia's evolving legal framework designed to address technologies that barely existed a decade ago.
Broader efforts to combat false information have produced mixed but measurable results. The MCMC investigated 574 cases of allegedly false online content under Section 233 of the Communications and Multimedia Act 1998 over the two-and-a-half-year period from January 2022 through June 2024. Of these, 23 cases proceeded to prosecution, with 12 concluded and 11 currently in trial. Courts imposed total fines of RM79,000 in concluded cases, and one offender received six months' imprisonment after failing to pay issued penalties. These prosecutorial outcomes, while significant symbolically, represent a small fraction of investigated cases and suggest the challenges authorities face in scaling legal action across the volume of potentially problematic content.
Additional enforcement mechanisms beyond prosecution offer authorities greater flexibility in responding to online harms. As of the end of June, the MCMC had issued 31 compound offers totalling RM1.22 million, deployed 84 warning letters to offenders or content creators, and maintained 47 cases under active investigation. A substantial portion of cases were classified as requiring no further action (NFA), indicating that not all flagged content ultimately meets the threshold for enforcement—a reality that underscores the inherent subjectivity in distinguishing between protected speech and harmful misinformation.
The parliamentary response also addressed specific concerns about the HarakahDaily Facebook account, which has drawn scrutiny in recent years. As of June 30, no First Information Report had been filed relating to that account, though authorities indicated that enforcement action would follow if content breaches applicable law or platform guidelines. The measured response suggests a desire to avoid appearing to suppress legitimate news operations while remaining prepared to act if legal boundaries are crossed.
These enforcement statistics arrive amid broader global anxiety about AI's role in degrading information ecosystems. Malaysia's experience mirrors patterns documented in Southeast Asia and beyond, where deepfakes and synthetic media are increasingly weaponised in political contexts, scams, and harassment campaigns. The relatively high compliance rates achieved by the MCMC—in the 94-95 percent range—suggest that major platforms recognise both legal liability and reputational risk in Malaysia, a market of some 35 million internet users. However, these figures also mask the cat-and-mouse dynamics of content removal, where bad actors continuously upload new versions of removed material or adjust it slightly to evade detection systems.
Looking forward, Malaysia's regulatory approach reflects a middle path between the permissiveness of some democracies and the restrictiveness of authoritarian regimes. The Risk Mitigation Code's labelling requirement, rather than blanket prohibition, suggests confidence in consumers' ability to assess disclosures about AI-generated content. Yet the continuing volume of submissions to platforms and the ongoing investigations demonstrate that Malaysian authorities recognise neither market forces nor user discretion alone will solve the problem—coordinated, sustained regulatory pressure remains necessary to maintain information integrity in an age of synthetic media.
