In the US, a bipartisan group of senators recently introduced the NO FAKES Act. It’s a game-changer, especially in this digital era. It essentially gives everyone, from Taylor Swift to a random high school teacher, ownership over their own voice and face. If someone clones them with AI (deepfake), they can sue.

Now, let’s look at home. If someone creates a deepfake of you in Malaysia, you can’t simply sue them for “stealing your face. Because Malaysia does not recognise “Image Rights” as a standalone law.

In the US, your face is your property. In Malaysia, your face is just your face. If it gets stolen by AI, you have to get creative with how you fight back.

Alternative Solutions to Deepfakes in Malaysia

So, Malaysia doesn’t recognise your “Image Rights”, what do you do?

Well, you can rely on a few older laws, none of which were built for AI, depending on the circumstances.

  1. Tort of Defamation
  2. Passing Off
  3. Section 233 of the Malaysia Communications and Multimedia Act 1988 (CMA)

Tort of Defamation (Defamation Act 1957)

To rely on this, you’ll need to prove that the deepfake lowered your reputation in the eyes of the public. Downside is, if the deepfakes are ridiculous, like making famous politicians break sing and dance along to K-pop songs, the defendant can argue that no one would believe it was true, meaning no harm to your reputation

Passing Off

Passing off is a common law tort used to prevent one person from “misrepresenting” their goods or services as someone else’s. In the context of deepfakes, you are essentially arguing: “This scammer used my face to sell their crypto scam, making people think I endorsed it.”

To prove this, you need to rely on the “Classic Trinity” Test established in Reckitt & Colman Products Ltd v Borden Inc (1990). This test is adopted by Malaysian Courts in Yong Sze Fun v Syarikat Zamani and requires the following elements:

  • Goodwill
  • Misrepresentatoin
  • Damages

The drawback is that normal citizens probably couldn’t use this, as they fail at the goodwill element. Goodwill does not mean having a good reputation, it is the attractive force that brings in business. So, for instance, if a high school student has a reputation, but they do not have commercial goodwill. Their face does not “sell” anything. Therefore, they fail Step 1 of the Classic Trinity immediately.

Section 233 of the Malaysia Communications and Multimedia Act 1988 (CMA)

This is where things change, instead of you suing them, the government steps in and changes the perpetrator. Section 233(1)(a) criminalises the “improper use of network facilities” to make any comment or communication that is “obscene, indecent, false, menacing or offensive in character with intent to annoy, abuse, threaten or harass another person”.

If the deepfake creator is caught and convicted under s.233, they face a fine of up to RM50,000 (to the State) or 1 year in jail. While the creator is jailed, the victim does not receive any compensation, and to gain compensation, the victim must pay from their own pocket to sue them in a separate Civil Court case.

Case Study: Foon Yew High School

It’s not just about politicians like Datuk Seri Anwar Ibrahim or Tony Fernandes being used for investment scams. The real danger is quieter and affects people who never asked to be famous.

April 2025, a scandal erupted at Foon Yew High School in Johor. A 16-year-old student allegedly used AI tools to “undress” photos of his female classmates and alumni. He went on to allegedly monetise them on Telegram.

Dozens of female students found their faces attached to pornographic bodies they had never seen, circulating among strangers and classmates

The Legal Headache emerged after police arrested the student (and a 19-year-old accomplice), and prosecutors faced a wall. There is no “Anti-Deepfake Act” in Malaysia. To charge him, they had to dig through the archives of the Malaysian Penal Code, which might settle on Section 292 of the Penal Code (sales of obscene materials) or Section 233 of the Communications and Multimedia Act 1998. [*]

The problem? The police are using an Act designed to stop people from selling dirty magazines in the 1950s to fight hyper-realistic, AI-generated sexual violence in 2025. Moreover, even if the charge is successful, the victims would not receive any form of compensation as the RM3,000 fine would go to the State. Another question, why not charged with child pornography? While the Sexual Offences Against Children Act 2017 defines child pornography as depictions of a child. Defence lawyers in other jurisdictions have successfully argued that AI deepfakes are not “real” children—they are synthetic pixels.

What Now?

Until we have our own version of the “NO FAKES Act,” Malaysians are effectively living in a digital glass house with very few stones to throw.

Are you concerned about protecting your brand, your creative work, or your personal image in the age of AI? Contact us at Quality Oracle to soothe your worries.