Digital Safety / AI news for Malaysia
From the archive · Event date 5 August 2025
Malaysia's anti-scam AI plan mixed rules, training and a detection tool. What each part could do
Deepfake video and voice cloning made impersonation easier, but no single guideline or detector could stop a payment. The 2025 plan worked only as a chain: safer systems, trained investigators, evidence tools and a fast human response.

In brief
- On 5 August 2025, the Digital Ministry linked rising deepfake and voice-clone risks to a package of data-protection guidelines, public-sector guidance, enforcement training and an AI-based image and video verification application.[1][2][3]
- The Ministry cited 35,368 online financial-fraud cybercrime cases in 2024 with RM1.58 billion in losses, followed by 12,110 online-scam cases and RM573.7 million in losses in the first quarter of 2025.[1]
- The proposed verification application was described as support for cybercrime investigations; it was not announced as a public tool that could certify every suspicious voice, video or message.[1][2][3]
Malaysia described four different layers of an anti-scam response
Malaysia's Digital Ministry set out a multi-part response to AI-assisted online scams on 5 August 2025. The announcement covered guidelines on data-protection impact, privacy-by-design, automated decision-making and profiling; training for enforcement officers and civil servants; and an AI-based application being developed by CyberSecurity Malaysia with Universiti Kebangsaan Malaysia.[1][2][3]
The scale of the underlying problem was already large. The Ministry cited police records of 35,368 cybercrime cases involving online financial fraud in 2024, up 2.53 per cent from 2023, with RM1.58 billion lost. In the first three months of 2025, it cited 12,110 online-scam cases involving RM573.7 million.[1]
AI changes the quality and speed of impersonation, but it does not change the final pressure point. A scammer still needs the target to trust a request, disclose information or move money. That is why the announcement's different measures should be judged separately: governance reduces unsafe system design, training improves human decisions, forensic tools support investigations and rapid reporting helps after a suspicious transfer.[1][4]

AI made imitation stronger, but the scam still depended on urgency and trust
Deepfake video can place a familiar face into a fabricated endorsement or call. Voice cloning can imitate a relative, employer or public figure. The realistic media creates social proof, while the request often uses an older tactic: act now, keep the conversation secret, click a link or transfer money before checking.[1][2]
The safest response therefore does not depend on spotting every visual glitch or strange pause. A person can end the call, open a separately saved contact, use an official website or speak to the supposed sender through another channel. Independent verification breaks the scam's control of the conversation even when the media looks and sounds convincing.[1]

The planned guidelines governed organisations; they were not a detector for every call
The Personal Data Protection Department was developing guidance on data-protection impact assessments, data protection by design, automated individual decision-making and profiling, with completion expected in early 2026. Those instruments can make organisations identify data risks, build controls earlier and explain automated processes more clearly.[1][2]
That matters to scam prevention because poorly protected data and opaque automated systems can increase exposure. But a governance document cannot inspect an incoming WhatsApp call in real time, freeze a transfer or decide that a clip is authentic. Presenting it as a universal anti-scam shield would promise more than the Ministry announced.[1][2]
The proposed AI tool was for evidence support, not automatic truth
CyberSecurity Malaysia and UKM were developing an AI-based application to verify the authenticity of images and videos. The stated purpose was to assist investigations involving online scams, identity fraud and digital disinformation. The announcement did not publish a launch date, accuracy result, supported media list or public-access route.[1][2][3]
Even a capable detector produces evidence that needs context. Recompression, editing, screenshots and newly generated media can change performance. Investigators also need the original file, account history, payment trail and testimony. A probability score should not become the sole reason to accuse a person or dismiss a victim's report.[1][3]
Training and a fast response chain still carried the operational burden
The Ministry said enforcement agencies and civil servants were receiving cybersecurity and AI capacity-building through AI Untuk Rakyat and MDEC's MD Workforce programme. Training matters because investigators, frontline officers and public servants have to preserve evidence, recognise manipulation, communicate uncertainty and avoid treating an AI output as a final verdict.[1][2]
The National Scam Response Centre represented another part of the chain. Its official 997 materials and inter-agency press conference placed reporting, police, financial institutions and communications authorities in one response system. The later operations-room photograph below shows that anti-scam work remained a coordinated human process, not an autonomous AI service.[4][5]
Why Malaysia should care
Malaysians were already losing money to fake e-commerce offers, bogus loans and investment schemes when generative AI made voices and videos easier to imitate. The practical issue is not whether a clip looks convincing, but whether the request can be verified through an independent channel before money or personal data moves.
Malaysians receiving an urgent request
A convincing voice or video no longer proves who is controlling the account.[1][2]
Practical move: End the conversation and verify through a known number, official website or separate trusted contact before sharing data or money.
Banks, platforms and public agencies
Governance and privacy-by-design can reduce how personal data and automated decisions create new scam opportunities.[1]
Practical move: Document data flows, impersonation risks, escalation paths and human decision owners before deployment.
Investigators and response teams
AI verification can add evidence, but case decisions still need original media, account activity, payment records and human review.[3][4]
Practical move: Preserve files and transaction details, record uncertainty and route suspected financial fraud through the official response chain.
What Malaysians can do now
- Treat urgency, secrecy and unusual payment instructions as warning signs even when the caller's voice or face appears familiar.
- Verify a request through a separately obtained number or official channel; do not use the contact details supplied inside the suspicious message.
- If money has moved, contact the financial institution and the official NSRC 997 route immediately, then preserve messages, account details and transaction records.
What we still do not know
The 2025 announcement left important delivery questions open.
- Whether the three planned data-protection and automated-decision guidelines were completed in early 2026 and how compliance is measured.
- When the CyberSecurity Malaysia-UKM verification application became operational, which media it supports and how its accuracy is independently tested.
- How many enforcement officers and civil servants completed the named training programmes and whether investigation outcomes improved.
Sources
- 1.AI Guidelines, Training Programmes Among Proactive Measures by the Ministry of Digital to Combat Online Scams Ministry of Digital Malaysia, 5 August 2025
- 2.AI Guidelines Drafted To Combat Online Fraud - Gobind Bernama, 5 August 2025
- 3.Gobind: Digital Ministry developing AI tool to detect deepfakes, fight cybercrime Malay Mail, 5 August 2025
- 4.Press Conference: National Scam Response Centre National Anti-Financial Crime Centre, 24 July 2025
- 5.Official Visit by the Minister of Communications to the National Scam Response Centre National Anti-Financial Crime Centre, 15 December 2025


