Safer Online, Less Free? Cybercrimes Bill’s Real Test Lies In Its Investigative Powers | #cybercrime | #infosec


Malaysia’s Cybercrimes Bill 2026 has been presented as a long-overdue answer to deepfakes, artificial intelligence (AI)-enabled scams and increasingly sophisticated digital attacks.

Few would dispute the need for reform as the Computer Crimes Act 1997 was written before smartphones, social media, cryptocurrency and generative AI reshaped the way people communicate, conduct business and commit crimes.

However, the most important question is no longer whether Malaysia needs a modern cybercrime law; it is whether the country can make Malaysians safer online without making them less free.

Monash University Malaysia’s senior lecturer at the Department of Business Law and Taxation, School of Business Dr Ridoan Karim and Kuala Lumpur advocate and solicitor Sathish Mavath Ramachandran both view the legislation as necessary.

Their concern lies elsewhere: The Bill may modernise the offences Malaysia can prosecute without sufficiently modernising the safeguards governing how those offences are investigated.

A Law Built for Today’s Digital Threats

The case for replacing the nearly three-decade-old Computer Crimes Act is compelling.

Cybercrime is no longer confined to hackers breaking into computer systems or interfering with data as criminals can now use AI to clone voices, impersonate executives, fabricate identities, manipulate financial transactions and create convincing intimate images without consent.

“Cybercrime is no longer simply about hacking computers. It is increasingly about manipulating trust,” Dr Ridoan said.

The Cybercrimes Bill attempts to close these gaps by introducing offences covering AI-generated deepfakes, synthetic voice scams, identity fraud, digitally manipulated intimate images and misuse of the MyDigital ID system.

It also strengthens protections against attacks on critical infrastructure, including essential systems such as power grids and water facilities.

Dr Ridoan stressed that the Bill does not criminalise AI or prohibit content simply because AI was used to create it.

Prosecutors must still prove elements such as criminal intention, purpose and harmful consequences.

The distinction is critical. AI is a tool, and the law is intended to target malicious conduct rather than technological innovation.

For victims who have struggled to obtain redress under a patchwork of older laws, the new offences could provide clearer legal protection and give investigators and prosecutors more appropriate tools.

The Real Controversy Is Not the Offences

The more difficult debate centres on the investigative and enforcement powers contained in the Bill.

Sathish said the controversy is not about whether deepfake pornography, identity theft or AI-assisted fraud should be criminalised.

It is about whether the powers granted to investigate such offences are accompanied by adequate checks and balances.

Among the provisions drawing scrutiny are powers allowing authorities to preserve and obtain digital data, compel the disclosure of passwords or decryption codes, collect traffic data in real time and, in certain circumstances, proceed without first obtaining a warrant.

Sathish highlighted concerns over provisions that allow some of these powers to be exercised with the authorisation of the public prosecutor rather than prior approval from a court.

He also pointed to a provision allowing officers to bypass the warrant process when they are satisfied that seeking one could prejudice an investigation.

The danger, he argued, is that the officer exercising the power may also be the person deciding whether external scrutiny is necessary.

Dr Ridoan similarly acknowledged government assurances that investigators would remain bound by legal procedures, written authorisation and statutory requirements.

However, he said concerns remain over whether the Bill provides sufficiently strong independent judicial oversight for intrusive actions involving private computer systems, digital preservation orders, compelled disclosure and surveillance.

The issue is therefore not whether enforcement agencies need strong powers.

They clearly do.

The issue is whether equally strong accountability mechanisms exist to prevent those powers from being misused.

Powers That Could Reach Beyond Cybercrime

The stakes extend far beyond journalists, lawyers or civil society groups.

Sathish warned that the Bill could allow certain investigative powers to be used in connection with offences under other written laws, rather than restricting them strictly to cybercrime cases.

This raises the possibility that tools introduced to investigate scams, ransomware and deepfakes could eventually be deployed in cases involving speech, dissent, journalistic sources or whistleblowers.

Privileged communications between lawyers and clients could also be exposed unless they are explicitly protected.

“Extraordinary powers, once granted, could be used for more than their original intended purpose,” he said.

That risk affects ordinary Malaysians as much as it does the media or legal profession.

A company could be compelled to disclose sensitive commercial information. A service provider could be ordered to preserve user data. An individual could be required to surrender access credentials, while being prohibited from disclosing that an order had been issued.

Without independent scrutiny, the public may be asked to trust that these powers will always be exercised proportionately.

Trust, however, is not a substitute for safeguards.

Cybersecurity Is Also Economic Infrastructure

There is also a strong business case for an effective cybercrime framework.

Malaysia’s ambitions in fintech, AI, cloud computing, digital services and semiconductor manufacturing depend heavily on confidence in the country’s digital systems.

Dr Ridoan described modern cybercrime legislation as part of Malaysia’s investment infrastructure.

International investors increasingly evaluate cybersecurity governance alongside taxation, regulatory stability and ease of doing business. Companies need assurance that fraud, intellectual-property theft and cyberattacks can be investigated effectively.

Yet, businesses also require confidence that confidential data will not be accessed arbitrarily and that enforcement powers will be exercised predictably.

A law that is perceived as overly broad or insufficiently supervised could undermine the very trust it is intended to strengthen.

Malaysia’s competitiveness will therefore depend not only on tougher offences but also on a credible enforcement framework that protects both security and legal certainty.

Stronger Safeguards Would Strengthen the Bill

Neither Dr Ridoan nor Sathish is calling for Malaysia to abandon cybercrime reform.

Their proposals are intended to make the legislation more durable, credible and effective.

Dr Ridoan said greater judicial oversight should be required for intrusive investigative powers wherever practicable. He also called for clearer definitions relating to AI-generated content to ensure that satire, journalism, parody, artistic expression and political commentary are not inadvertently criminalised.

He proposed specialised cybercrime courts or designated judges capable of handling complex matters involving encryption, blockchain transactions, AI-generated evidence and digital forensics.

Karim also urged closer cooperation among the police, National Cyber Security Agency, Malaysian Communications and Multimedia Commission, financial institutions and international partners.

Annual reporting on warrants, investigations, prosecutions and convictions would further help demonstrate that the law is being used proportionately.

Sathish pointed to calls for a defined data-retention period, limits restricting intrusive powers to serious offences, protection for privileged communications and public reporting on how frequently enforcement tools are deployed.

For urgent situations, investigators could be permitted to act immediately, provided their actions are subjected to prompt judicial review.

Such safeguards would not weaken enforcement; they would protect the legitimacy of enforcement.

The Bill’s Success Will Be Measured by Public Trust

Passing a law is the easiest part of responding to cybercrime. Effective implementation will require trained digital forensic specialists, prosecutors capable of handling technically complex evidence and judges who understand rapidly evolving technologies.

Cybercriminals adapt quickly; therefore, institutions must be able to do the same.

But capability alone is not enough.

Malaysia must also demonstrate that powers introduced to protect the public will not be expanded, repurposed or exercised without meaningful scrutiny.

The Cybercrimes Bill should not force the country to choose between security and freedom; instead, a modern digital economy requires both.

Malaysians deserve protection from deepfake abuse, synthetic-voice fraud, identity theft and attacks on essential infrastructure. They also deserve confidence that their data, communications and fundamental liberties will not be compromised without lawful and proportionate justification.

The Bill’s ultimate success will not be measured by the number of offences it creates or the severity of the penalties it imposes.

It will be measured by whether Malaysians feel safer online without feeling less free.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW