The Malaysian Communications and Multimedia Commission (MCMC) has intensified its crackdown on manipulated digital content, taking down 12,353 deepfake-related posts in the first six months of 2024. The success rate underscores how aggressively the regulator is pursuing online harms, with social media platforms complying with 94 percent of removal requests submitted between January and June. These figures, revealed in parliamentary responses tabled at Parliament yesterday, paint a picture of a regulatory environment becoming increasingly sophisticated in detecting and neutralizing synthetic media that could deceive the public or manipulate opinion.

The MCMC filed 13,122 removal requests targeting image manipulation and deepfake content during the six-month period, demonstrating the scale of the problem facing Southeast Asia's third-largest economy. The high compliance rate from licensed service providers—Facebook, Instagram, TikTok, and other platforms operating in Malaysia—suggests that tech companies are responding to government pressure and understand the regulatory stakes. Only 769 posts remained unremoved by the end of June, a gap that raises questions about whether platform enforcement mechanisms are sufficiently responsive or whether certain types of content evade detection algorithms.

The enforcement push extends well beyond deepfakes alone. Between January 2022 and June 2024, MCMC submitted 275,787 requests to remove scam-related content, including fraudulent accounts and identity impersonation cases. The removal success rate for these requests reached 95 percent, with 262,293 posts taken down across the two-year window. This parallel enforcement effort reveals how scams and deepfakes often operate together in Malaysia's digital ecosystem—malicious actors use synthetic media to impersonate legitimate businesses or government officials before executing financial fraud. The sheer volume of removal requests signals that these crimes remain endemic to Malaysian social media platforms despite growing awareness and regulatory attention.

Governing deepfakes and synthetic media presents unique challenges that Malaysia is attempting to address through new regulatory frameworks. The Risk Mitigation Code, which became enforceable on June 1 this year, requires all licensed platform operators to apply labels to any content that has been generated or altered using artificial intelligence technology. This includes not only deepfake videos but also manipulated still images and audio recordings. The labelling regime represents a transparency-focused approach, assuming that informed users will be more skeptical of synthetic content once they recognize it as artificially generated or modified. However, the effectiveness of such labels remains contested, as research worldwide shows that many users share flagged content without reading warnings.

The Online Safety Act 2025, mentioned in the parliamentary response, introduces another layer of enforcement specifically targeting financial deception. Between January and June, MCMC submitted five removal requests for content involving financial scams under this new legislation, and all five instances were successfully removed by platforms. While the number seems modest compared to overall deepfake removals, it suggests that the new act is being deployed strategically against the most damaging variants of synthetic content—those designed to steal money. The fact that every request resulted in removal also implies that platforms understand the legal jeopardy they face and prioritize compliance when financial crimes are involved.

Criminal prosecutions for false online content remain slower and more selective than administrative removals. Between January 2022 and June 2024, MCMC investigated 574 cases involving false online content under Section 233 of the Communications and Multimedia Act 1998. Of these, only 23 cases proceeded to court prosecution, with 12 already concluded and 11 still undergoing trial. This wide gap between investigations and prosecutions suggests that many false content cases do not meet the threshold for criminal charges, or that the authorities exercise prosecutorial discretion by pursuing only the most egregious offenders. The low prosecution rate also reflects resource constraints within MCMC and the judiciary, both common challenges in Southeast Asia's digital law enforcement.

Penalties imposed so far have been relatively modest. In the 12 concluded prosecutions, courts have imposed total fines amounting to RM79,000—an average of approximately RM6,583 per case. One offender received a six-month prison sentence after failing to pay a court-ordered fine, indicating that custodial sentences remain rare even for convicted false content spreaders. Additionally, 31 cases have been resolved through compound payments totaling RM1.22 million, while 84 warning letters were issued. This enforcement landscape suggests that Malaysia relies heavily on administrative and financial penalties rather than incarceration, though the threat of jail time may serve a deterrent function. The remaining 47 cases under investigation and those classified as requiring no further action point to a selective approach that prioritizes cases with clearer public impact.

The government has also been cautious about targeting specific online news outlets, particularly when content moderation decisions could be perceived as politically motivated. When asked about the HarakahDaily Facebook account, MCMC indicated that no formal First Information Report had been lodged as of June 30, despite the outlet's known track record of publishing controversial or disputed content. The ministry stated that firm action would be taken only if content breached the law or platform guidelines, suggesting a threshold-based enforcement model rather than blanket suppression. This restraint may reflect concerns about accusations of political censorship, a sensitive issue in Malaysia's polarized media environment.

The regional implications of Malaysia's deepfake enforcement strategy extend beyond national borders. As other Southeast Asian countries grapple with similar challenges, Malaysia's regulatory approach—combining labelling requirements, platform compliance mechanisms, and selective criminal prosecution—offers a working model. However, the approach also reveals persistent tensions between transparency (through labelling) and removal (through deletion), between administrative efficiency and due process rights, and between protecting the public from harm and avoiding accusations of state censorship. These tensions are particularly acute in Southeast Asia, where governments sometimes use fake news and deepfake regulations as cover for suppressing legitimate dissent.

Looking ahead, the success of Malaysia's deepfake enforcement will depend on sustained investment in detection technology, platform cooperation, and prosecutorial resources. The 94 percent removal rate is encouraging, but it masks the fact that many deepfakes may not be reported to MCMC in the first place, or may already have circulated widely before being flagged. Deepfakes targeting political figures, religious figures, or prominent business leaders tend to spread faster and wider than scam-related synthetic media, yet may be underrepresented in official removal statistics if victims are reluctant to report or if platforms underestimate their severity. The parliamentary data provides a snapshot of enforcement activity but cannot fully capture the true scale of synthetic media circulating in Malaysian digital spaces or its downstream effects on public discourse and social cohesion.