The Malaysian Communications and Multimedia Commission has intensified its battle against synthetic media and artificial intelligence-generated fraud, removing over 12,000 deepfake posts in the first six months of this year. According to parliamentary responses tabled by the Ministry of Communications, the MCMC lodged 13,122 removal requests with social media platforms concerning content created or altered using deepfake technology between January 1 and June 30. The high success rate—with licensed service providers taking down 12,353 posts, representing 94 per cent of all requests—demonstrates both the regulator's effectiveness and the relative willingness of major platforms to cooperate with Malaysian authorities when presented with clear evidence of policy violations.

This enforcement effort reflects growing international concern about the proliferation of digitally manipulated content, which poses distinct threats beyond traditional misinformation. Deepfakes can be weaponised against public figures, used to extort victims through blackmail, or deployed to undermine institutional trust by creating fabricated evidence of wrongdoing. In Malaysia's context, where election cycles periodically intensify political tensions and social media remains a primary news source for many citizens, the removal of such content serves a critical public interest function. The sheer volume of requests—nearly 13,000 in six months—suggests that deepfake misuse is becoming increasingly common rather than remaining an occasional phenomenon.

Parallel to the deepfake crackdown, authorities have ramped up enforcement against scam-related content more broadly. Between the start of 2022 and mid-2024, the MCMC submitted 275,787 requests to remove content related to financial fraud, including fake accounts and impersonation schemes. The removal rate for this category reached 95 per cent, with 262,293 posts successfully taken down. This encompasses a substantial portion of the online deception ecosystem—fraudsters routinely create fake identities, steal existing profiles, and impersonate legitimate businesses or government agencies to siphon money from unsuspecting victims. Southeast Asian nations have been particularly vulnerable to such schemes, with criminals leveraging language proficiency and cultural familiarity to target fellow regional citizens.

A pivotal regulatory development came into effect on June 1 with the implementation of the Risk Mitigation Code, which imposes fresh obligations on licensed platform operators. Under this framework, any content that has been generated, altered, or manipulated using artificial intelligence must now carry clear labelling. This requirement extends to deepfake videos and audio, as well as manipulated images and synthetic media more generally. The measure represents a significant shift toward transparency, enabling users to make informed judgements about content authenticity before sharing or acting upon it. While labelling alone cannot eliminate the threat posed by deepfakes, it creates friction in the viral spread cycle and serves as an important informational safeguard.

The government has also begun invoking newer legislative tools to combat online deception. The Online Safety Act 2025, which appears to have recently entered force, provides an additional mechanism for addressing harmful content. Between January and June this year, authorities submitted five removal requests under this legislation specifically targeting financial scam content, and all five were successfully taken down. This represents a modest deployment of the new statute, but it signals that Malaysia's regulatory arsenal has expanded beyond the longstanding Communications and Multimedia Act 1998, which had previously served as the primary legal basis for enforcement actions.

Investigations into false online content under Section 233 of the Communications and Multimedia Act have revealed the complex pipeline from detection to prosecution. Between January 2022 and June 2024, the MCMC investigated 574 cases involving false online material. Of these, 23 have proceeded to court prosecution, with 12 cases concluded and 11 still ongoing. The courts have imposed fines totalling RM79,000 across the concluded cases, while one offender received a six-month prison sentence for failing to settle an imposed fine. These outcomes illustrate the range of consequences available to the judiciary, though the progression from investigation to successful prosecution remains slow.

Beyond criminal prosecution, the regulator has employed a tiered enforcement approach incorporating warnings and financial penalties short of court action. As of June 30, the MCMC had issued compounds in 31 cases, generating RM1.22 million in collective fines. An additional 84 warning letters had been sent to parties deemed to have violated the law. Meanwhile, 47 cases remained under investigation, with the remainder classified as requiring no further action. This graduated response structure recognises that not every instance of false content warrants expensive court proceedings, yet still applies meaningful consequences to deter future violations.

The regulatory response to specific high-profile cases provides insight into how authorities navigate sensitive situations. When asked about the HarakahDaily Facebook account—presumably a reference to an opposition-aligned news outlet—authorities reported that no First Information Report had been filed as of June 30. However, the ministry indicated that firm action would be taken should any content from this source be found to breach applicable laws or platform guidelines. This language reflects the delicate balance between content regulation and press freedom, both significant issues in the Malaysian context.

For ordinary Malaysians and residents of the broader Southeast Asian region, these enforcement figures carry multiple implications. The prevalence of deepfakes and financial scams reflects the maturing of cybercriminal capabilities in Asia, where technical sophistication increasingly outpaces user awareness. Citizens should remain sceptical of unexpected media depicting public figures, particularly during sensitive political periods, and exercise caution before transferring money online or clicking on links from unknown sources. The removal of 12,353 deepfake posts and 262,293 scam-related posts represents real protection for vulnerable populations, yet the underlying technology continues to advance.

Looking forward, Malaysia's regulatory framework faces evolving challenges as artificial intelligence becomes more accessible and realistic. The requirement for AI-generated content labelling provides a foundation, but enforcement depends on platforms' willingness to identify manipulated material accurately and consistently. International cooperation will become increasingly important, as deepfakes and scams routinely cross national boundaries within minutes of creation. The MCMC's removal rates remain high, but the absolute numbers suggest that the problem is expanding faster than the number of removal requests processed. Sustained investment in detection technologies, user education, and platform partnerships will likely prove essential to staying ahead of malicious actors.