Malaysia's Online Safety Codes: What Platforms Need to Know

Summary

Malaysia has published two new codes under the Online Safety Act 2025 that impose detailed obligations on social media and content platforms operating in the country. The Child Protection Code requires verification of users' ages against government-issued records for platforms likely to be accessed by children, with a minimum age of 16. The Risk Mitigation Code introduces broader obligations on harmful content management, advertiser verification, synthetic media labelling, and internal assurance, with fines of up to RM10 million for non-compliance.

The Codes are part of a fast-developing regional landscape on online child safety, alongside Australia's under-16 social media ban, Indonesia's PP Tunas framework, and Singapore's Codes of Practice for app stores and social media services. While regulatory direction across Asia-Pacific is broadly aligned, specific obligations, age thresholds, verification standards, and penalty exposure differ considerably. For multinational platforms, the central challenge is increasingly how to meet these different requirements simultaneously without fragmenting products by market.

The Codes also represent the first AI-specific duties attached directly to user-facing platform services in Malaysia. Until a separate AI Bill is finalised, online safety obligations will be the primary regulatory hook for several generative AI features in the Malaysian market.

On 22 May, the Malaysian Communications and Multimedia Commission (MCMC) published the Child Protection Code (CPC) and Risk Mitigation Code (RMC) under the Online Safety Act 2025 (ONSA). Both Codes take effect on 1 June.  

The Codes arrive at a moment when child online safety is a hotly debated issue across Asia-Pacific. Australia is enforcing its world-first under-16 social media ban, Indonesia has brought minimum age threshold and child safety design obligations into force through its PP Tunas framework, and Singapore is implementing age assurance requirements for app stores. Malaysia's Codes sit broadly within the regional mainstream, though with some distinctive operational features that companies will need to navigate. 

The Codes in a nutshell 

While the ONSA set out the overarching regulatory framework for online safety, the Codes now translate that framework into practical obligations for regulated services.  

The CPC is focused on child online safety, adopting a stringent approach to age verification. The CPC requires platforms likely to be accessed by children to verify users' ages against government-issued records before allowing registration on a social media service, and to set the minimum age at 16. Beyond age gating, the Code requires safety by design obligations, including mandating providers to default child accounts to the highest privacy settings, limit adults' ability to contact or view personal information of child users, restrict design features that drive compulsive use, and ensure search and recommendation systems do not surface harmful content to children. 

The RMC imposes broader obligations on service providers to proactively identify and reduce harmful content for all users. Platforms must conduct annual harmful content risk assessments documented in writing, with electoral periods explicitly flagged as situations of heightened risk. Based on those assessments, they must put in place content reporting and removal systems, advertiser verification against government-issued records, labelling for synthetic or manipulated media that could appear authentic, and pre-deployment risk evaluation for new features. The RMC also requires an internal assurance function that reports to the audit committee or governing body. Failure to comply with the RMC can attract fines of up to RM10 million. 

MCMC has described its approach under the Codes as "outcomes-based", giving providers flexibility to implement solutions that align with safety, privacy and legal requirements rather than prescribing specific technologies or rigid takedown timelines. For example, rather than mandating a fixed timeframe for content removal, the RMC requires only "timely identification, assessment and removal" of harmful content and "prompt and effective" responses to requests from MCMC or other enforcement agencies, leaving broad regulatory discretion to MCMC. Both Codes also include an explicit "alternative measures" provision, allowing providers to deviate from the prescribed requirements if they can demonstrate to MCMC that an alternative approach better achieves the underlying objective. 

Where Malaysia sits in the region 

Online child safety has moved rapidly up the global policy agenda, with Australia's social media minimum age law acting as a catalyst for parallel debates in the UK, EU, US, and across Asia-Pacific. What makes APAC distinctive is the speed and the range of regulatory tools being deployed. Indonesia became the first non-Western country to legislate an under-16 social media ban, in force from March 2026. Vietnam's Decree 147 requires parental registration for under-16 accounts and imposes gaming time limits. Singapore has taken a layered approach that applies differentiated obligations to different categories of service: app stores must now implement age assurance to prevent under-18s from downloading age-inappropriate apps, while social media services are required to minimise users' exposure to harmful content, provide differentiated accounts and parental tools for children, and report annually on their safety measures.  

While the regulatory direction is broadly aligned, the operational specifics differ considerably. One key area for potential divergence concerns the type of content targeted by regulatory frameworks. There is convergence in some aspects: child sexual abuse material is classified as harmful across regimes,  and most jurisdictions also treat content promoting terrorism and content that encourages self-harm or suicide, as harmful. But Malaysia’s ONSA includes within its definition of “harmful content” content which is “profane in nature, improper and against generally accepted behaviour or culture”. The interpretation of this relatively broad wording will be particular to the Malaysian context. Other countries bring their own approaches to defining what is harmful: Vietnam’s prohibited content categories, derived from its Cybersecurity Law, include false information, content distorting history, content offensive to religion, gender or racial discrimination, and propaganda against the State. 

The scope of services targeted by regulation is another area of potential divergence. Malaysia’s Codes apply to Licensed Service Providers – broadly, the social media, internet messaging and content service platforms themselves, not the app stores or operating systems through which users download them. This puts Malaysia in line with most of the region, with Singapore the main outlier in placing obligations on app stores (though limited to preventing under-18s from downloading age-inappropriate apps rather than blocking downloads outright). 

Minimum ages and their flexibility vary across the region: Malaysia and Australia both set the bar at 16, but Australia's ban is absolute (with no parental consent override) and limited to designated platforms, while Malaysia's threshold applies to social media services likely to be accessed by children more broadly. Indonesia's regime is tiered, with a minimum age of 16 for high-risk platforms and 13 to 15-year-olds permitted on medium-risk services with parental consent. Singapore requires age verification at 18 for age-inappropriate app downloads.  

Malaysia’s requirement for government-issued ID as the basis for age verification diverges from its otherwise “outcomes-based” approach, instead restricting the ways in which services can comply. It remains to be seen how far Malaysia will diverge from emerging international approaches to age assurance: in contrast to Malaysia, for example, the UK’s Ofcom takes a tech-neutral approach but mandates that age assurance should be “highly effective”, and the UK, EU, and Australia are deepening international exchanges of perspective on age assurance.  

What this means for business 

Informally, a short grace period is likely for services to operationalise the requirements after they come into effect on 1 June. Platforms covered under Codes should consider using the grace period to engage with MCMC on its expectations, with a view to demonstrating how their planned approach to compliance meets the outcomes MCMC outlines in the Codes.   

For now, and until Malaysia's separate AI Bill is finalised, the Codes will serve as the main regulatory hook for several generative AI features in the Malaysian market. The synthetic media labelling and pre-deployment evaluation requirements under the RMC are the first AI-specific duties attached directly to user-facing platform services. Platforms launching new AI features in the near term should therefore expect Malaysian online safety obligations to bite before any AI-specific framework comes into effect, and should factor this into their pre-launch product reviews accordingly. 

More broadly, two features of the regional online child safety landscape stand out for business. The first is the speed at which it is developing. In the past six months, Australia, Singapore, Indonesia and Malaysia have all introduced or activated new regulatory obligations. Further changes are likely, with Indonesia signalling extension of PP Tunas to e-commerce and Singapore considering age assurance obligations for social media services. The second feature is fragmentation, and how definitions of harmful content, specific obligations, age thresholds, verification standards and penalty exposure vary considerably. For multinational platforms, the practical challenge is increasingly how to design compliance systems that can meet these different requirements simultaneously without fragmenting their products by market. 

Companies with regional footprints should be prepared to track developments closely across multiple markets, build flexibility into their compliance architecture, and engage early with regulators to shape their implementation of emerging frameworks. 


In Asia-Pacific, Flint Global is a strategic advisory firm helping businesses and investors navigate political, regulatory, and geopolitical complexity across the region. We combine on-the-ground knowledge, regional expertise, and global insight to help clients manage risk, engage effectively with governments, and make informed commercial decisions that create competitive advantage. 

Key Takeaways
  • New codes in force from 1 June 2026: Malaysia's Child Protection Code and Risk Mitigation Code under the Online Safety Act 2025 introduce binding obligations on social media, internet messaging, and content platforms, with fines of up to RM10 million for non-compliance.
     
  • Stringent age verification under the Child Protection Code: Platforms likely to be accessed by children must verify users' ages against government-issued records, setting Malaysia apart from international approaches that allow a wider range of age assurance techniques.
     
  • Broader platform obligations under the Risk Mitigation Code: New duties include annual harmful content risk assessments, advertiser verification, synthetic media labelling, pre-deployment risk evaluation, and an internal assurance function reporting to the audit committee.
     
  • First AI-specific duties on platforms in Malaysia: Until the separate AI Bill is finalised, the Risk Management Code's synthetic media labelling and pre-deployment evaluation requirements are the primary AI-specific regulatory hook for user-facing platforms in the Malaysian market.
     
  • Fast-moving regional context: In the past six months, Australia, Singapore, Indonesia and Malaysia have all introduced or activated new regulatory obligations on online child safety, with further changes likely in Indonesia (e-commerce extension) and Singapore (age assurance for social media services).
     
  • Aligned objectives, divergent operational requirements: While regulatory direction across Asia-Pacific is broadly aligned, definitions of harmful content, age thresholds, verification standards and penalty exposure differ considerably across jurisdictions.

Flint Enquiries

For enquiries, please contact us here