Malaysia's communications regulator has intensified its battle against artificial intelligence-powered image manipulation and online fraud, with the Malaysian Communications and Multimedia Commission successfully deleting thousands of malicious posts within the opening half of the year. Between January and June 2024, the MCMC lodged 13,122 removal requests with social media companies, targeting content created or altered through deepfake technology, resulting in the deletion of 12,353 posts—representing a 94 per cent compliance rate from licensed service providers. The figures, disclosed in a parliamentary response tabled in Parliament on July 23, reveal the scale of authorities' ongoing enforcement push and the effectiveness of their engagement with global platforms operating within Malaysian jurisdiction.

The deepfake crackdown forms part of a broader regulatory strategy addressing multiple forms of online harm simultaneously. During the same six-month window, MCMC submitted 275,787 requests to remove scam-related material, encompassing fraudulent accounts and impersonation schemes designed to deceive Malaysian internet users. Platform operators successfully removed 262,293 of these posts, translating to a 95 per cent removal rate that slightly surpasses the deepfake takedown performance. These parallel enforcement efforts underscore the interconnected nature of AI-enabled crimes, where deepfake technology frequently serves as a tool within larger fraud operations targeting vulnerable online communities. The consistency in removal rates across both categories suggests that social media platforms have developed effective detection systems and maintain relatively swift response protocols when Malaysian authorities file formal requests.

Responding to parliamentary inquiries from Senator Musoddak Ahmad and Senator Baharuddin Ahmad, the Ministry of Communications outlined the regulatory framework now governing artificial intelligence misuse across digital platforms. Most significantly, the Risk Mitigation Code commenced operation on June 1, introducing mandatory requirements for platform providers to affix clear labels to all content generated, synthesised, or materially altered through AI tools. This labelling obligation extends to deepfakes, manipulated imagery, and doctored audio recordings, establishing transparency mechanisms that allow Malaysian users to identify synthetic or altered material before engaging with it. The requirement represents a preventative approach complementing the reactive removal strategy, attempting to educate and empower users while simultaneously creating audit trails for regulatory oversight.

Enforcement activity under newer legislation has commenced, though deployment remains limited at this early stage. The Online Safety Act 2025 provides additional legal instruments for tackling digital harms, and between January and June 2024, authorities submitted five removal requests specifically addressing financial scams under this statute. All five submissions resulted in successful content deletion, though the low volume suggests the provision may still be underutilised or that scam content is being more readily addressed through existing channels. This legislative layering—combining the Communications and Multimedia Act 1998, the Risk Mitigation Code, and the Online Safety Act 2025—creates multiple enforcement pathways that authorities can deploy depending on the nature and severity of violations.

Criminal prosecution remains a critical enforcement tool, with 574 cases initiated under the Communications and Multimedia Act between January 2022 and June 2024 targeting false online content. Of this substantial caseload, 23 have proceeded to prosecution, with 12 already concluded in the courts. The completed cases resulted in total fines reaching RM79,000, while one offender received a six-month custodial sentence after defaulting on their financial penalty. The remaining 11 prosecutions continue through the court system, suggesting that legal proceedings against serious online falsehood perpetrators remain protracted. This enforcement pattern reflects the resource-intensive nature of criminal prosecution, where gathering evidence, building cases, and navigating judicial processes inevitably consume significant time.

Beyond prosecution, authorities have employed alternative enforcement mechanisms including compounding, warning notices, and ongoing investigation. The statistics reveal that 31 cases had been offered compound settlements totalling RM1.22 million, reflecting the government's willingness to resolve matters through financial penalties without full criminal trials. Furthermore, 84 warning letters were issued to individuals and entities engaged in online falsehood, serving notice that regulatory attention had been directed toward their activities. As of June 30, forty-seven cases remained under investigation, representing the investigative pipeline that may ultimately feed into prosecution, compounding, or closure. A substantial number of cases were classified as requiring no further action, indicating that not all false content reports meet the threshold for regulatory intervention or that the relevant material had already been remedied.

The political sensitivity surrounding online falsehood enforcement became apparent when the ministry addressed concerns regarding HarakahDaily, a news outlet with documented political alignment. As of June 30, no First Information Report had been filed despite apparent scrutiny of the platform's Facebook operations. The ministry's statement that it would pursue firm action upon discovering law or guidelines violations appears measured, suggesting that no specific breach has yet been substantiated or formally reported. This cautious approach reflects the contentious nature of content regulation in Malaysia, where distinctions between legitimate political speech and actionable falsehood remain contested among various stakeholders.

The regulatory environment governing online content in Malaysia has undergone significant evolution, particularly regarding artificial intelligence. The transition toward mandatory labelling under the Risk Mitigation Code represents an approach gaining international traction, adopted by several democracies grappling with deepfake proliferation. Unlike outright prohibition, labelling preserves freedom of expression while enabling users to make informed decisions about content authenticity. However, the effectiveness of this strategy depends substantially on user literacy and platform algorithm design—if labelled content remains algorithmically amplified, labels alone may prove insufficient to prevent viral spread of manipulated material.

For Malaysian users and digital ecosystem stakeholders, these statistics convey several important messages. The high removal success rates demonstrate that platforms generally respond appropriately to regulatory direction from Malaysian authorities, suggesting that the country's legal frameworks carry sufficient weight to compel compliance. The diversity of enforcement approaches—from removal requests to criminal prosecution to compounding—indicates a graduated system capable of matching remedies to violation severity. However, the lag between investigation initiation and case conclusion highlights the prosecutorial challenges inherent in online content regulation, where evidence preservation, technical expertise, and legal complexity create inevitable delays.

The deepfake and scam content removal figures must be contextualised within the broader volume of social media activity across Malaysia. While 12,353 deletions represent a substantial enforcement achievement, the raw numbers alone cannot reveal whether this volume constitutes adequate protection against synthetic media proliferation. This metric proves particularly significant for Malaysia, where digital literacy rates vary considerably across demographics and where vulnerable populations may be disproportionately targeted by sophisticated scams leveraging deepfake technology. The 94-95 per cent success rates, while impressive, also acknowledge that a small percentage of problematic content successfully evades removal despite regulatory intervention.

Looking forward, Malaysia's regulatory approach reflects broader Southeast Asian trends toward stricter digital governance. Regional peers including Singapore, Thailand, and Indonesia have similarly expanded legal frameworks addressing online harms, creating a competitive regulatory environment where jurisdictions adopt progressively more comprehensive controls. For multinational platforms operating across the region, this fragmentation creates compliance burdens, as each market imposes distinct requirements. The Risk Mitigation Code's mandatory labelling requirement positions Malaysia within a cohort of jurisdictions prioritising transparency measures, contrasting with other regional approaches emphasizing removal and prosecution. As deepfake technology continues advancing and scams become increasingly sophisticated, the sustainability and proportionality of Malaysia's regulatory response will require ongoing evaluation and potential refinement to balance security concerns with fundamental rights protections.