The Malaysian Communications and Multimedia Commission (MCMC) has demonstrated significant progress in combating deepfake content, successfully removing over 12,000 posts in the first six months of 2024. According to a written parliamentary response tabled in Parliament, the regulator issued 13,122 removal requests to social media platforms between January 1 and June 30, with licensed service providers complying with 12,353 requests—achieving a 94 per cent removal rate. The figures underscore both the scale of the deepfake problem in Malaysia's digital ecosystem and the effectiveness of coordinated enforcement efforts between the government and platform operators.
Deepfakes, which involve synthetic media created or manipulated using artificial intelligence technology, have emerged as a significant threat to information integrity and individual privacy in Malaysia. The high compliance rate from social media platforms suggests that when provided with clear legal directives and evidence of policy violations, companies operating in Malaysia are generally responsive to government requests for content moderation. This outcome contrasts with the historically contentious relationship between Malaysian authorities and tech platforms over content removal, indicating that targeted, evidence-based requests generate better results than blanket demands.
The enforcement effort extends beyond deepfakes into the broader landscape of online fraud and identity manipulation. During the same six-month period, the MCMC submitted 275,787 requests for removal of scam-related content, including fake accounts and impersonation schemes. Of these, 262,293 posts were successfully removed, representing a 95 per cent compliance rate. This slightly higher success rate for fraud-related content suggests that platform operators may view financial scams as more clear-cut violations warranting swift action, compared to the more nuanced questions surrounding deepfakes and manipulated media.
A watershed moment in Malaysia's regulatory approach arrived on June 1 with the implementation of the Risk Mitigation Code, which introduces mandatory transparency requirements for AI-generated and altered content on licensed platforms. The code requires service providers to clearly label content that has been synthesized or modified using artificial intelligence, encompassing deepfakes, manipulated images, and altered audio. This labelling regime represents a shift from purely reactive content removal toward proactive disclosure, empowering users to make informed judgments about the authenticity of what they encounter online. The measure addresses a fundamental problem: deepfakes are becoming increasingly sophisticated, and removal alone cannot fully solve the problem if original false content has already circulated widely.
Parallel legislative measures have further strengthened the enforcement toolkit. The Online Safety Act 2025 represents Malaysia's most comprehensive effort to date to regulate digital content ecosystems. Under this legislation, the MCMC submitted five requests for removal of financial scam content between January and June 2024, with full compliance achieved. While the number appears modest, the existence of this additional legal avenue demonstrates a layered regulatory approach, allowing authorities to address financial crime through multiple statutory frameworks tailored to specific harms.
The enforcement against false online content more broadly reveals the judicial dimension of Malaysia's digital governance strategy. Between January 2022 and June 2024, the MCMC investigated 574 cases involving false online content under Section 233 of the Communications and Multimedia Act 1998. Of these, 23 cases proceeded to prosecution, with 12 concluding and 11 still undergoing trial. The concluded cases resulted in total fines of RM79,000, while one offender received a six-month imprisonment sentence after failing to satisfy a fine. These outcomes indicate that Malaysia's courts are applying criminal penalties in this domain, though the relatively low prosecution rate—approximately 4 per cent of investigated cases—suggests that many matters are resolved through administrative rather than judicial channels.
Administrative remedies have played a more prominent role in enforcement. As of June 30, the MCMC had issued compound fines totaling RM1.22 million across 31 cases, distributed warning letters in 84 cases, and maintained 47 cases under ongoing investigation. A substantial portion of investigated cases were closed with a determination of no further action required, suggesting that investigative scrutiny itself may serve a deterrent function. The preference for compounds and warnings over prosecution may reflect pragmatic enforcement prioritization, with authorities focusing limited prosecutorial resources on the most egregious violations while using administrative measures to address lower-level infractions.
The case of HarakahDaily's Facebook account illustrates the complexities facing regulators in this space. Despite widespread public concern about the account's content, the MCMC confirmed as of June 30 that no First Information Report had been filed, suggesting that reported content had not been conclusively determined to breach specific laws or platform guidelines. The ministry nonetheless indicated readiness to pursue enforcement action if future content breaches applicable rules. This measured stance reflects the tension between addressing public concern and adhering to evidentiary standards required for legal action, a challenge that will likely intensify as deepfake technology becomes more accessible and prevalent.
The implications for Malaysia's digital future extend beyond current enforcement metrics. As deepfake technology becomes cheaper and easier to deploy, the demand for regulatory capacity will almost certainly outpace supply. The current 94 per cent removal success rate masks important questions about response time—how quickly are posts removed after flagging, and how much reputational or financial damage occurs in the interim? Additionally, the focus on removal addresses symptoms rather than root causes. Understanding the motivations behind deepfake creation, whether political interference, financial fraud, or personal harassment, remains essential for developing prevention-focused strategies.
Regional context matters significantly for Malaysia's approach. Southeast Asian nations including the Philippines, Indonesia, and Thailand have experienced documented deepfake campaigns linked to elections and political movements. Malaysia's proactive regulatory posture, combining rapid content removal with mandatory labelling and potential criminal penalties, positions the country as a regional leader in addressing synthetic media threats. However, the success of these measures depends on sustained coordination with platform providers, adequate resourcing for investigation teams, and public awareness about the risks and indicators of deepfake content.
Looking forward, Malaysia faces the challenge of calibrating enforcement intensity to avoid suppressing legitimate speech while effectively curtailing harmful content. The evolution from purely reactive removal toward preventive labelling and disclosure requirements represents progress, yet further refinement will be necessary as technology advances. International cooperation will prove increasingly important, given that deepfake creation and distribution often transcend national boundaries. The MCMC's current approach, emphasizing swift takedowns combined with emerging transparency requirements, provides a foundation upon which more sophisticated frameworks can be built as our understanding of synthetic media harms deepens.
