top of page
Search

Malaysia’s New Online Safety Rules: What the Risk Mitigation Code Means for Social Media Users

  • Dr Kevin Ho
  • Aug 7
  • 8 min read
Teens on social media have become the norm rather than the rule, before the era of regulations
Teens on social media have become the norm rather than the rule, before the era of regulations

Updated: 7 August 2026


For years, concerns about social media have largely focused on what users themselves should do: don't click suspicious links, don't share personal information, report scams and be careful about what you believe online.


But Malaysia is now taking a different approach.


Rather than placing the responsibility entirely on individual users, the government is increasingly placing responsibility on the platforms themselves.

Malaysia's Online Safety Act 2025 (Act 866) came into force on 1 January 2026. Then, on 1 June 2026, two important regulatory codes came into effect: the Risk Mitigation Code (RMC) and the Child Protection Code (CPC), issued by the Malaysian Communications and Multimedia Commission (MCMC).


So what does this actually mean for Malaysians?



Has Malaysia's new online safety regime actually been enforced?

Yes — but implementation is still ongoing.

This is an important distinction.

The Risk Mitigation Code and Child Protection Code formally took effect on 1 June 2026. They are therefore no longer simply proposed measures.


However, the government has acknowledged that platforms need additional time to fully implement some of the requirements.

On 4 July, Deputy Communications Minister Teo Nie Ching said the government was still assessing the level of compliance among licensed social-media platforms.

Then, on 21 July, Communications Minister Fahmi Fadzil said social-media platforms had requested additional time to fully comply with the new requirements, and that the government had agreed to give them more time while discussions continued.


In other words:

The rules are in force. The transition and compliance process is still underway.

That makes the subject particularly relevant for businesses, advertisers, parents and social-media users today.


What is the Risk Mitigation Code?

The Risk Mitigation Code is essentially a framework requiring online platforms to take greater responsibility for identifying and reducing the risks associated with harmful content on their services.

Rather than simply waiting for users or regulators to report harmful material after it appears, platforms are expected to develop systems to identify risks, assess them and put appropriate safeguards in place.


The approach is deliberately risk-based and outcome-oriented. Platforms have some flexibility in deciding how they achieve the required outcomes, rather than being given a single prescribed technical solution.

This is significant because social-media platforms are not passive noticeboards.

Their algorithms determine what users see, recommendation systems determine what gets amplified, and advertising systems determine what commercial messages reach particular audiences.


The new framework therefore increasingly asks:

What risks does the platform's own design create, and what is the platform doing about them?

What counts as harmful content?

The framework addresses a range of online harms, including:

  • Child sexual abuse material

  • Financial fraud and scams

  • Obscene and indecent content

  • Content that causes harassment, distress, fear or alarm

  • Content inciting violence or terrorism

  • Content that could induce children to harm themselves

  • Content promoting hostility

  • Content promoting the use or sale of dangerous drugs


The focus is therefore considerably broader than simply "fake news" or offensive comments.

It covers some of the most serious forms of harm that can occur online.


1. Platforms must conduct risk assessments

Platforms are expected to assess the risks arising from their services.

This includes looking at how platform features, recommendation systems, user behaviour and other aspects of the service might contribute to exposure to harmful content.

The assessment is not supposed to be a one-off exercise.


Platforms must maintain records and review their assessments, including taking account of circumstances in which risks may increase.

This is an important shift in thinking.

Instead of asking only:

"Did something harmful happen?"

platforms are increasingly expected to ask:

"What features of our system could allow something harmful to happen, and how can we reduce that risk?"

That is essentially a risk-management approach to digital safety.


2. Reporting and content moderation must improve

Platforms must provide mechanisms that allow users to report harmful content.

Those mechanisms are expected to be accessible and user-friendly, while platforms must have processes for identifying, assessing and responding to harmful material.

For repeat offenders, platforms may use measures such as warnings, restrictions, suspensions or account termination, depending on the circumstances.


This could eventually change the experience of reporting harmful content online.

Instead of users feeling as though they are simply "sending a complaint into the void", the regulatory framework expects platforms to have meaningful systems for responding to those reports.


3. Advertisers must be verified

One of the most interesting parts of the new framework concerns online advertising.

Advertisers using sponsored advertisements on social-media platforms are required to undergo identity verification.

The purpose is particularly relevant to the fight against scams.

Malaysians have increasingly encountered advertisements promoting dubious investments, financial schemes, gambling and other fraudulent activities — sometimes using the images or identities of well-known personalities.


The new requirements are intended to make it more difficult for scammers to hide behind anonymous advertising accounts.

Government-issued documents such as identity cards, passports, work permits and business registration documents may be used for verification, subject to applicable privacy and data-protection requirements.

For legitimate businesses advertising online, this represents another reason to ensure that their corporate and advertiser information is accurate and properly documented.


4. AI-generated and manipulated content must become easier to identify

Perhaps one of the most forward-looking parts of the framework concerns artificial intelligence.

AI can now create photographs, videos and audio that look and sound remarkably real.

A fake video of a politician.

A fabricated investment endorsement from a celebrity.

A manipulated voice recording of a company executive.

A completely artificial photograph presented as a real event.


These technologies can be entertaining and useful, but they also create an enormous potential for deception.

The Risk Mitigation Code therefore requires platforms to introduce measures that help users distinguish manipulated or AI-generated material from genuine content and provide tools or guidance for disclosure where appropriate.


This is likely to become increasingly important as generative AI becomes more sophisticated.

The ability to ask "Is this real?" is becoming an essential part of digital literacy.


5. Recommendation algorithms are now part of the safety conversation

This may be one of the most consequential changes.

Social-media algorithms determine much of what people see.

If a user watches one particular type of content, the recommendation system may provide another similar video, followed by another, and another.

The problem is that harmful material can sometimes spread in exactly the same way.

Malaysia's framework therefore requires platforms to assess and manage risks arising from their recommendation systems.


Importantly, MCMC has clarified that it does not directly regulate or dictate the design of individual algorithms.

Instead, it uses a risk-based approach: platforms are responsible for assessing the effects of their systems and taking reasonable measures to reduce the amplification of unlawful or harmful content.


This distinction matters.

The government is not simply saying:

"Here is how your algorithm must work."

It is saying:

"You are responsible for understanding the risks your system creates and managing those risks."


6. Users should get better safety controls

The framework also expects platforms to provide tools that allow users to exercise greater control over their online experience.

These can include:

  • Controls over who can interact with an account

  • Filters for search and recommendations

  • Privacy and safety settings

  • Mechanisms for reporting harmful material

  • Accessible user-assistance systems


The broader objective is to give users more practical control over their digital environment.


And what about children?

This is where the second major development comes in.

Alongside the Risk Mitigation Code, Malaysia introduced the Child Protection Code (CPC) on 1 June 2026.

The CPC places additional responsibilities on platforms to provide "child safety by design".


For major social-media platforms with at least eight million users in Malaysia, the framework includes age-verification measures intended to prevent users below 16 from registering for social-media accounts.

The measures also cover areas such as content moderation, parental controls, privacy settings and recommendation systems.


The government has acknowledged that implementation is still being worked through with the platforms, however, and additional time has been granted for full compliance.

This means the under-16 restrictions should not be viewed as a single switch that was simply flipped on 1 June.

It is better understood as an ongoing implementation process.


Does this affect ordinary Malaysians?

For most adults, the new rules do not mean that you personally need to apply for a new licence or register with the government simply to use Facebook, Instagram, TikTok, YouTube or other platforms.


The primary legal responsibilities fall on the licensed service providers, rather than ordinary users.


However, users may gradually notice changes in how platforms operate.

You may encounter:

  • More verification when purchasing advertisements

  • More prominent reporting and safety tools

  • Changes to recommendation systems

  • Greater labelling of AI-generated or manipulated material

  • More stringent measures against harmful content

  • Age-verification mechanisms

  • Greater restrictions for younger users


The experience may therefore change gradually rather than overnight.


What happens if platforms do not comply?

Non-compliance can result in enforcement action, with financial penalties of up to RM10 million under the relevant framework.

But the more interesting question is not simply how large the potential fine is.

It is whether regulation will actually change the behaviour of the world's largest technology platforms.


That is something Malaysia's regulators will need to demonstrate through implementation and enforcement.

As of July 2026, the government was still assessing compliance, while platforms were continuing discussions with the authorities.


Is the Risk Mitigation Code really about censorship?

This is perhaps the most sensitive question.

Any regulation governing online content inevitably raises concerns about freedom of expression.


The answer depends significantly on how the framework is enforced.

The stated objective of the RMC is to address clearly identified categories of harmful content, scams, exploitation, child safety and other online risks.

At the same time, regulators are giving platforms flexibility in how they achieve the required safety outcomes.


That means the real test will be whether the framework can reduce genuine online harm without unnecessarily suppressing lawful expression or legitimate disagreement.

Good regulation needs both.

Online safety matters.

So does freedom of expression.

The challenge is finding the balance between them.


Why this matters beyond social media

There is a bigger lesson here for businesses.

Digital safety is increasingly becoming a matter of governance and risk management, rather than simply an IT problem.


A company's online reputation can be damaged by:

  • Fraudulent advertising

  • Deepfakes impersonating executives

  • Cyberbullying

  • Data breaches

  • Fake reviews

  • Social-media misinformation

  • Employee misuse of digital platforms

  • Harmful content involving customers or employees


This makes digital safety increasingly relevant to the "G" in ESG — Governance, as well as the "S" — Social.

It is also a human-capital issue.

Employees, customers and children are all increasingly exposed to digital environments that can affect their safety, wellbeing and trust.


In that sense, Malaysia's new online safety framework is part of a much broader global movement:

technology companies are increasingly being expected to take responsibility for the risks created by the systems they build.


What happens next?

Malaysia's online safety framework is still evolving.

The government has been developing additional subsidiary legislation, guidelines and implementation mechanisms under the Online Safety Act. In July, the Communications Ministry was also finalising further regulations concerning characteristics of private messaging services.


Meanwhile, MCMC is assessing the Online Safety Plans submitted by licensed service providers and their ability to manage platform risks effectively. Licence holders were given 180 days from 1 July to submit those plans, with the government indicating that it expects to assess their robustness toward the end of the year.

So the story that began on 1 June is not finished.


In fact, 1 June may have been the beginning of the more interesting part.

The real question is no longer whether Malaysia has introduced online safety regulation.

It has.

The question now is:

Will these new rules actually make the internet safer for Malaysians?

That is something worth watching.


Key takeaway

Malaysia's Risk Mitigation Code is already in force.

But it would be misleading to suggest that everything changed overnight on 1 June.

The better description is that Malaysia has entered a new phase of online safety regulation, with the rules now legally operative while platforms, regulators and other stakeholders continue working through implementation and compliance.


For ordinary users, the most visible changes are likely to appear gradually — through stronger reporting systems, advertiser verification, AI-content transparency, recommendation controls and greater protections for children.


For businesses and technology platforms, however, the message is much more immediate:

Online safety is increasingly becoming a governance responsibility.


 
 
 

Comments


bottom of page