Malaysia's fight against synthetic media is intensifying, with authorities reporting the successful removal of more than 12,000 deepfake posts during the first half of 2024. The Malaysian Communications and Multimedia Commission submitted 13,122 takedown requests to social media platforms between January and June, achieving a 94 per cent removal rate as confirmed in parliamentary responses tabled this week. The data underscores the growing challenge posed by artificial intelligence-generated content manipulation across the digital landscape, a concern increasingly shared by governments across Southeast Asia grappling with similar threats to information integrity.
Deepfake technology—which uses AI to synthesise realistic but false images, videos, and audio—has emerged as a potent tool for spreading misinformation, committing fraud, and damaging reputations. The scale of Malaysia's intervention suggests the problem extends well beyond isolated incidents. With nearly 95 per cent of flagged content being successfully removed by platform operators, the regulatory framework appears to be functioning effectively, though the raw volume of requests indicates that detection and reporting mechanisms continue to be tested by the sheer volume of manipulated content flowing through social networks daily.
Concurrently, Malaysia's regulatory apparatus has expanded its reach into broader online harms. Between the same six-month period, the MCMC processed 5,275,787 takedown requests targeting scam-related content, encompassing fake accounts, impersonation schemes, and fraudulent solicitations. Of these, 262,293 posts were successfully removed, maintaining a 95 per cent success rate that mirrors the deepfake takedown effectiveness. This dual assault on synthetic fraud and manipulated media reflects a coordinated strategy to address overlapping threats that often exploit similar technological capabilities and prey on identical vulnerabilities in user trust and verification systems.
A significant regulatory milestone arrived on June 1 when Malaysia's Risk Mitigation Code took effect, establishing mandatory labelling requirements for platform operators handling AI-generated or altered content. The code mandates that licensed service providers clearly identify deepfakes and manipulated images or audio, creating transparency that allows users to make informed judgments about content credibility. This approach aligns with international best practices adopted by regulators in Europe and parts of North America, acknowledging that detection alone is insufficient—users themselves must be equipped to recognise synthetic content when algorithms and automated systems cannot reliably do so. The measure also shifts responsibility toward platforms to implement technical infrastructure capable of identifying and tagging such content at scale.
The enforcement landscape has further tightened through the Online Safety Act 2025, under which five financial scam-related takedown requests have been processed so far this year. While the number appears modest compared to deepfake and scam removals, it reflects a new statutory pathway specifically designed to address online financial crimes that increasingly leverage deepfake technology to impersonate authority figures or manipulate victims into fraudulent transactions. Every successful removal under this legislation represents a potential fraud prevented and consumer protection strengthened across Malaysia's digital economy.
Broader efforts to combat false information show mixed results. The MCMC has investigated 574 cases of false online content under Section 233 of the Communications and Multimedia Act 1998 since January 2022, bringing 23 to prosecution with 12 concluded. Courts have imposed total fines of RM79,000 across concluded cases, with one offender facing six months' imprisonment after failing to settle a penalty. An additional 31 cases have proceeded through compound settlements totalling RM1.22 million, while 84 warning letters were issued and 47 cases remained under active investigation as of June. This enforcement approach combines graduated penalties—from warnings through compounds to prosecution—creating deterrent effects across the spectrum of online falsehood from minor violations to serious crimes.
The regulatory response must navigate delicate constitutional terrain. Malaysia operates under frameworks protecting free expression while establishing limits around national security, public order, and individual dignity. The scale of investigation and enforcement activity indicates authorities are prioritising cases meeting these thresholds rather than pursuing every instance of online misinformation, a necessary restraint given resource constraints and the principle that not all false statements warrant state intervention. Yet the volume of cases still generating investigation and compound settlement suggests that public concerns about online falsehoods have driven increased reporting and enforcement resource allocation toward the most harmful instances.
For Malaysian businesses and citizens, the implications are substantial. Companies increasingly vulnerable to reputation damage through deepfake video or audio have clearer pathways to rapid content removal, while individuals targeted by identity fraud schemes face a regulatory environment actively working to disrupt such schemes. The labelling requirements should reduce vulnerability to synthetic content, particularly among less digitally sophisticated users who may struggle to distinguish authentic from manipulated material through visual inspection alone. Financial institutions and e-commerce platforms benefit from active enforcement against the fraud and impersonation schemes that frequently target their customers.
Regionally, Malaysia's approach offers a model worth scrutiny. The combination of rapid administrative takedown through the MCMC, criminal prosecution for the most egregious cases, graduated civil remedies through compounding, and proactive labelling requirements creates layered enforcement that other Southeast Asian nations contemplating similar challenges might reference. Indonesia, the Philippines, and Thailand face comparable deepfake and online scam problems, and Malaysia's demonstrated 94 per cent removal success rate provides a benchmark for effectiveness. The approach balances speed—administrative requests rather than court orders enabling swift action—with proportionality, avoiding the wholesale censorship that might invite international criticism while maintaining real enforcement teeth.
Looking forward, the regulatory environment will likely intensify further as AI capabilities advance. Deepfakes that currently fool platforms may become harder to detect as generative technology improves, potentially rendering the current removal rates unsustainable without corresponding investments in detection technology. The Risk Mitigation Code's labelling requirement addresses this by acknowledging that when automated detection fails, user awareness becomes the fallback defence. Regulatory bodies across Asia, including Malaysia, will need sustained funding for technical infrastructure, staff training, and cross-platform coordination to maintain effectiveness against an adversary—synthetic media misuse—that is simultaneously becoming more sophisticated and more accessible to bad actors with minimal technical expertise.
