Malaysia Malaysia MCMC content takedown Communications Act

Malaysia Shifts the Burden of Scam and Gambling Takedowns From Regulator to Platform — a Rare Case Where Automation Fits the Problem

MCMC is giving platforms time to automate scam and gambling takedowns after manual review buckled under 271,000+ requests in five months.

Malaysia's Takedown Backlog, By the Numbers People of Internet Research · Malaysia 271,472 Content removals, Jan–May 2026 Pieces of content MCMC ordered tak… 91% Share tied to scams/gambling Of all removed content, the vast m… 19.7 years Staff time spent filing takedowns Cumulative MCMC working time spent… RM10 million Maximum non-compliance fine Penalty platforms face for failing… peopleofinternet.com
Malaysia's Takedown Backlog, By the Nu… People of Internet Research · Malaysia 271,472 Content removals, Jan–May 2026 91% Share tied to scams/gambling 19.7 years Staff time spent filing takedowns RM10 million Maximum non-compliance f… peopleofinternet.com

Key Takeaways

A regulator drowning in its own success

Malaysia's Communications and Multimedia Commission (MCMC) has spent the first half of 2026 proving that its Online Safety Act 2025 (Act 866) works — and proving that manual enforcement of it does not scale. Communications Minister Fahmi Fadzil told reporters on August 5 that takedown requests for scam and online gambling content have already exceeded all of last year's total, and that the volume "had strained MCMC's resources and manpower" (Malay Mail). The numbers explain why. Between January and late May, MCMC ordered 271,472 pieces of content removed, 91% of it scam or gambling material, with 81% of the gambling content found on a single platform, Facebook (The Edge Malaysia). Weeks earlier, Fahmi had put a price tag on the manual process itself: at roughly 30–45 minutes per request, MCMC staff spent the equivalent of 19.7 years of working time filing takedown paperwork in just the first six months of the year (The Star). In response, MCMC is giving platforms a grace period to build automated detection and takedown systems that comply with the Child Protection Code (CPC) and Risk Mitigation Code (RMC), the two subsidiary codes issued under the Online Safety Act that took effect June 1, 2026 (MCMC).

The case for automation here is genuinely strong

It's worth stating plainly why this is a defensible ask rather than a shortcut. Fahmi noted the detected scam and gambling content is overwhelmingly repetitive — the same visual templates and text strings recur across thousands of posts. That is close to a best-case scenario for automated filtering: a narrow, well-defined content category with high pattern redundancy and no serious First Amendment-style contestability, since fraudulent financial solicitations and unlicensed gambling ads are illegal to advertise in Malaysia regardless of medium. Fahmi has also linked the stakes directly to consumer harm, citing Bank Negara figures that scam syndicates defrauded Malaysians of RM2.7 billion last year even as banks blocked roughly RM1.2 billion in attempted theft through their own security systems (The Edge Malaysia). A regulator asking platforms to deploy classifiers against a repetitive, high-volume, low-ambiguity harm — rather than open-ended "harmful content" — is a narrower and more defensible mandate than most automated-moderation regimes attempt.

But the incentive structure still points toward over-removal

The risk is not that Malaysia picked the wrong content category to automate — it's what happens at the edges once platforms build the machinery. The Risk Mitigation Code carries penalties of up to RM10 million for non-compliance (Rahmat Lim & Partners), and Act 866 makes clear that duties under Part III are enforceable as recoverable civil debt. That is a one-sided incentive: a platform that under-blocks risks a regulatory fine, while a platform that over-blocks — sweeping in legitimate fintech marketing, licensed lottery operators, gaming-industry commentary, or financial-literacy content that merely uses adjacent language — faces no matching downside. EFF's recent review of automated moderation is a useful caution here, not because it discusses Malaysia, but because it documents what happens when detection systems are deployed under liability pressure without matching accountability: Meta's own terrorist-content classifier, EFF notes, misclassified nonviolent Arabic-language posts as violating 77% of the time (EFF). Gambling and scam detection is a narrower, lower-ambiguity target than terrorism classification, so the failure rate should be materially lower — but "should be lower" is not the same as "MCMC is measuring it."

What proportionate implementation looks like

Nothing in Fahmi's announcement, MCMC's own ONSA page, or the RMC text as summarized by practitioners mentions a false-positive audit requirement, a public error-rate disclosure, or a fast-track appeals channel for wrongly removed accounts. That's the gap regulators should close before, not after, platforms flip the automation switch. A grace period that lets platforms build detection systems is sound policy design — better than demanding instant compliance with a standard nobody can yet meet. But a grace period that only measures success by whether the takedown backlog shrinks, without also tracking what legitimate content gets caught in the net, optimizes for exactly the metric MCMC is currently drowning in and none of the ones that protect the businesses and speakers who aren't scammers. Malaysia has picked a comparatively good test case for automated enforcement. Whether it becomes a template other regulators can trust, rather than a cautionary tale EFF cites next, depends on whether MCMC builds the accountability layer alongside the detection layer — not after platforms report the backlog is finally clear.

Sources & Citations

  1. MCMC — Online Safety Act (ONSA) overview
  2. Online Safety Act 2025 (Act 866), full text
  3. Malay Mail — Fahmi: platforms given time to align with ONSA
  4. The Star — takedowns cost MCMC 19.7 years in man-hours
  5. The Edge Malaysia — 271,472 takedowns, 91% scam/gambling
  6. Rahmat Lim & Partners — RMC/CPC penalties under ONSA
  7. EFF — Automated Moderation Is Here to Stay