Malaysia is grappling with one of the digital age's most intractable governance puzzles: how to protect users—especially children—from the harms of social media without throttling the freedoms that underpin democratic societies. Datuk G. Thiyagu, Deputy Director-General (Law Reform) at the Legal Affairs Division of the Prime Minister's Department, articulated this tension at the International Regulatory Conference here this week, noting that countries across the Commonwealth and beyond continue to stumble over the same regulatory tightrope. The challenge intensifies because online safety does not exist in isolation; it is intrinsically bound to questions of fundamental rights and the scope of state intervention in digital spaces.

Thiyagu emphasised that Malaysia's newly minted Online Safety Act 2025 attempts to thread this needle through what officials term a "system-based approach." Rather than micromanaging individual pieces of content—a model that quickly devolves into censorship—the legislation places the onus on platform operators themselves to build safer ecosystems. This represents a philosophical shift: regulation operates at the architectural level, holding companies accountable for the safeguards embedded in their systems rather than policing every post. The legislation explicitly acknowledges Article 10 of the Federal Constitution, which guarantees Malaysians the right to freedom of speech while conceding that such freedoms are not unbounded. The law carves out permissible restrictions on grounds including public order, morality, and national security—familiar categories that reflect the broader framework used across democracies, though their application remains hotly contested.

The proportionality principle sits at the heart of this regulatory architecture, Thiyagu explained. Without it, lawmakers risk crafting rules so expansive they become tools for silencing legitimate speech. This concern is not academic; Southeast Asia has witnessed repeated instances where broadly drafted online regulations morph into instruments of political control. Malaysia's designers appear conscious of this danger, yet the burden falls on courts and regulators to police the boundaries in practice. The legislation is not monolithic; Thiyagu indicated that future iterations will likely refine terminology, strengthen measures around content duration, and introduce more granular system-based requirements. This iterative posture suggests an acknowledgment that no single legislative framework can adequately capture the fluid, rapidly evolving nature of online harms.

Yet legal architecture alone cannot deliver safety. Dr Farah Nini Dusuki, Children's Commissioner at the Human Rights Commission of Malaysia (Suhakam), offered a sobering diagnosis: Malaysia does not lack laws, but rather effective enforcement. The country's existing statutes protecting children are reasonably comprehensive on paper. The real bottleneck lies upstream, in the monitoring systems, oversight mechanisms, and institutional capacity needed to actually apply these rules. Without rigorous review cycles and mechanisms to identify shortcomings, laws calcify, becoming monuments to good intentions rather than instruments of protection. Dusuki pressed for a preventive mindset, drawing an analogy to urban safety: just as societies invest in designing safer roads and playgrounds rather than instructing children to defend themselves against hazards, digital governance must build safer platforms rather than casting children as responsible for their own protection.

This preventive orientation has profound implications for how Malaysia structures its online safety ecosystem. A reactive approach—one that responds to harms after they occur—perpetually chases yesterday's problems. It also places the burden of safety on parents and children, many of whom lack the technical sophistication to navigate algorithmic manipulation, predatory behaviour, and content designed to exploit cognitive vulnerabilities. By contrast, a preventive system compels platform designers to consider child safety during the development phase, embedding safeguards into the product itself. Dusuki's remarks suggest that the true test of the Online Safety Act 2025 will not be the elegance of its text but the vigour with which regulators and courts enforce its provisions and hold platforms accountable when they falter.

Platform accountability itself remains contested terrain. Gurtaj Singh Padda, co-founder and Chief Executive Officer of Tune Talk, advanced a provocative thesis: financial penalties, no matter how hefty, rarely compel compliance from technology giants. He pointed to Australia's recent decision to raise maximum fines for non-compliance with child age-verification rules to A$99 million (approximately RM284 million) as evidence that even punitive measures face limits. Instead, Padda advocated for a more direct lever—the ability to restrict access to non-compliant platforms entirely. Tune Talk has positioned itself as a vanguard by becoming Malaysia's first telecommunications company to offer parents the technical means to block access to specific social media platforms and customise internet access through simple, one-touch controls. This approach sidesteps the enforcement bottleneck: rather than relying on regulatory agencies to police platform behaviour, it enlists the market itself, giving users and parents the power to vote with their feet.

Padda's argument contains economic logic, but it also raises questions about who bears responsibility and what transparency looks like. If telecommunications companies become gatekeepers deciding which platforms reach consumers, do we simply relocate the accountability problem rather than solve it? The model does have force, however, particularly in jurisdictions where regulatory capacity is stretched thin. By distributing the enforcement function to multiple points in the ecosystem—platforms, telcos, and parents—the system creates redundancy. No single bottleneck can become a chokepoint. Malaysia's regulatory design would benefit from incorporating such thinking, recognising that formal law and market mechanisms can reinforce one another.

Australia's experience offers instructive contrasts and parallels. Australian High Commissioner Danielle Heinecke outlined her country's approach to age verification, which requires platforms to take "reasonable steps" to prevent users under 16 from creating accounts. The legislation casts a net over age inference and verification technologies, acknowledging that perfect age certainty is neither technically feasible nor practically necessary. Australia has also escalated penalties—the A$99 million maximum is substantial—signalling that enforcement is not theoretical. Yet Heinecke did not claim victory; her remarks implied that Australia, too, continues learning by doing, adjusting strategies as platforms discover workarounds and as technologies evolve. For Malaysian policymakers, Australia's trajectory suggests that online safety regulation is inherently iterative. The most sophisticated legislative frameworks will require periodic overhaul as the digital landscape transforms.

The International Regulatory Conference convening senior officials, industry leaders, and human rights practitioners underscores a broader regional shift. Southeast Asian governments are no longer content to be passive recipients of technology policy innovations developed elsewhere. Malaysia's Online Safety Act 2025, shaped in dialogue with international experience but tailored to local conditions, reflects a growing confidence in regional norm-setting. This matters because digital regulation cannot be one-size-fits-all; cultural contexts, constitutional frameworks, and existing institutional capacities vary significantly. What works in Australia may require substantial adaptation in Malaysia, where telecommunications penetration, educational levels, and regulatory capacity differ. Yet the conference also revealed consensus around certain principles: child protection is non-negotiable, platform accountability is essential, and the preservation of freedom of expression remains a foundational goal.

The path forward hinges on execution and honest assessment of trade-offs. Malaysia cannot achieve perfect safety without perfect surveillance, nor can it preserve absolute free expression while shielding children from genuine harms. The regulatory challenge is therefore one of managing tensions rather than eliminating them. This demands institutions with sufficient expertise, autonomy, and resources to interpret and enforce legislation fairly. It requires platforms to move beyond rhetorical commitments to genuine systemic change. And it necessitates a civil society willing to scrutinise both government and corporate power, holding both accountable when regulations become pretexts for censorship or when companies shirk responsibility. The Online Safety Act 2025 represents Malaysia's current best attempt at this balance. Its effectiveness will depend not on the statute's elegance but on the collective will to implement it wisely.