Key Takeaway
- Creating an AI image of a real person is not automatically illegal, but how you use and publish it matters.
- Legal problems may arise if the image is defamatory, sexually explicit, deceptive, fraudulent or used as a fake endorsement.
- A publicly available photograph is not automatically free to copy, alter or use in advertising.
- Writing “AI-generated” or “for entertainment purposes” does not automatically protect you from liability.
- Businesses should obtain clear permission and review potentially sensitive AI images before publishing them.
Table of Contents
ToggleIt is not automatically illegal to create an AI-generated image of a real person in Malaysia. However, the image could create legal problems depending on what it shows, how it was created, where it is published and whether it harms or misleads anyone.
For example, generating a harmless fantasy portrait of a friend with (their permission) is very different from creating a fake image that makes a politician appear to accept a bribe or makes a celebrity seem to endorse a questionable investment scheme.
The technology itself is not the only issue. The more important question is what you are making the image communicate, something funny or nefarious?
The Cybercrimes Bill 2026, which includes provisions concerning deepfakes and digitally manipulated intimate images, was passed by the Dewan Rakyat on 1 July 2026 and by the Dewan Negara on 20 July 2026.
However, businesses should distinguish between a bill passing Parliament and the law formally coming into force.
Does It Matter Whether You Publish the Image?
Imagine that you create a silly AI image of your colleague as an astronaut but never share it. That may carry relatively low legal risk, although questions could still arise about how their photograph was obtained or processed.
Now imagine that you post the same colleague’s face onto a fake image showing them being arrested. You add their full name, tag their employer and let people assume the event really happened.
The image has been communicated to other people and may damage the person’s reputation, leaving you liable to defamation lawsuits because it is.
Risk can increase further when an image is:
- Posted publicly on social media
- Shared repeatedly through WhatsApp or Telegram
- Used in an advertisement
- Sold or monetised
- Presented as genuine news
- Used to request money or personal information
- Created to humiliate, threaten or sexually exploit someone
In other words, clicking “generate” and clicking “publish” are not legally identical actions.
Example case:
In 2025, a teenager in Kulai, Johor allegedly used AI to create explicit deepfake images of dozens of female students using photographs taken from their social media profiles. The images were reportedly sold online, leading to police investigations and criminal charges. The incident highlighted that while AI itself is not illegal, using it to create harmful, non-consensual images of identifiable people can lead to serious legal consequences
Is Parody or Satire Automatically Safe?
Parody and satire can be relevant to the context, but they are not magic legal shields.
A clearly exaggerated image of a public figure riding a dinosaur may be understood as a joke. A realistic image of the same person secretly meeting a criminal could be interpreted very differently.
The distinction often comes down to questions such as:
- Would a reasonable viewer believe the image might be real?
- Is the image making a factual allegation?
- Is the person clearly identifiable?
- Is the image intended as humour, criticism, harassment or deception?
- Could the person’s reputation, safety or livelihood be affected?
- Does the caption clarify the joke or make the false impression worse?
Public figures may receive greater scrutiny and criticism, but that does not mean anyone can publish fabricated allegations about them without risk.
Yes, even your friend can’t be displayed hands with a famous criminal.
Can You Use a Celebrity’s Face in an AI Advertisement?
This is very risky, like super risky.
A company might generate an image of a well-known Malaysian athlete holding its supplement. Even if the image is completely synthetic, customers may assume the athlete approved the product.
Depending on the facts, this could raise questions involving:
- Passing off
- False endorsement
- Misrepresentation
- Defamation
- Consumer protection
- Copyright in the source material
- Personal data processing
The risk is not limited to famous people. Using an employee, customer or ordinary person’s face in a commercial campaign without proper permission may also cause legal and reputational problems.
Does the PDPA Protect Someone’s Face?
Malaysia’s Personal Data Protection Department lists pictures among examples of personal data.
The Personal Data Protection Act 2010 may therefore be relevant where a business collects, stores, uploads, analyses or otherwise processes identifiable photographs.
Its application has important limits. It generally relates to personal data processed in connection with commercial transactions, and certain personal or household uses may fall outside its scope.
This means an AI image could fall outside the PDPA but still create problems under defamation, copyright, criminal or other legal principles.
What If the Original Photograph Was Publicly Available?
A photograph being visible online does not mean it is free for everyone to reuse.
There are at least three separate layers to consider:
The Person in the Image
The person may have concerns involving reputation, personal data, consent, dignity or false endorsement.
The Original Photograph
The photographer, agency, employer, media company or another party may own copyright in the source image.
The AI-Generated Output
The resulting image raises separate questions about its publication, ownership, platform terms and intended use.
For example, you might generate an image that does not closely reproduce the original photograph. That could reduce one type of copyright concern, but it does not necessarily remove the risk of falsely portraying or commercially exploiting the person shown.
Likewise, receiving permission from the person in the photograph does not automatically mean you have permission from the photograph’s copyright owner.
Does an “AI-Generated” Disclaimer Make It Legal?
Not necessarily, a disclaimer can reduce confusion but, it cannot automatically fix an image that is defamatory, fraudulent, sexually exploitative or commercially misleading.
Consider these two examples:
Example one: A clearly fictional artwork is labelled “AI concept art” in the caption and shown in an artistic portfolio.
Example two: A fake investment advertisement uses a politician’s face and includes a tiny “AI-generated” label that most viewers will never notice.
Both images contain a disclosure, but their purpose and likely effect are very different.
A court or regulator is unlikely to look only at the label. The overall impression, audience, intention and potential harm will still matter.
How Can You Check an AI Image Before Publishing It?
A useful way to assess the risk is the FACE Test.
F: Factual Implication
Does the image make it look as though the person attended an event, committed an act, endorsed a product or made a statement?
A: Authorisation
Did the person give permission for their face or likeness to be used, especially in advertising or sensitive content?
C: Context and Circulation
Is the image being used privately, artistically, commercially, politically, sexually or fraudulently? How widely will it be shared?
E: Effect
Could the image cause reputational damage, emotional distress, financial loss, harassment, deception or danger?
The more serious the factual implication, lack of permission, public circulation and likely harm, the greater the legal risk.
What Should Businesses Do Before Using AI Images of People?
Businesses should treat AI images with the same care they would give to photography, advertising claims and customer data.
Before publishing, check:
- Where the source images came from
- If the person agreed to the proposed use
- Whether the consent covers advertising and AI manipulation
- Who owns copyright in the original material
- Can the image implies an endorsement
- Could it be mistaken for a real event
- Could the campaign could embarrass or harm the person
- Had a human review has taken place
Agencies should also record who supplied the image, who approved the concept and what instructions were given. Informal approval through a vague WhatsApp message may be difficult to rely on later.
What Can You Do If Someone Creates an AI Image of You?
Act quickly, but do not rush to confront the creator before preserving evidence.
Start by:
- Taking screenshots of the image, caption, account and comments
- Recording the URL, date and time
- Saving messages showing who created or distributed it
- Reporting the content through the platform
- Asking trusted contacts not to reshare it
- Keeping evidence of reputational, emotional or financial harm
- Making a police or MCMC report where criminal conduct may be involved
- Seeking legal advice if the image is defamatory, sexual, threatening, fraudulent or spreading rapidly
Deleting the original post does not necessarily end the problem. Copies may continue circulating, so evidence preservation and a coordinated takedown strategy can be important.
So, Is It Illegal?
Using an AI-generated image of a real person is not automatically illegal in Malaysia.
A harmless, clearly fictional image created with permission may carry relatively low risk. A realistic image used to spread false allegations, advertise products, impersonate someone or create non-consensual sexual content may be much more serious.
AI tools make image creation easy, but they do not remove the legal responsibilities that come with publication.
At PRESS, we understand that AI-generated images can be creative and convenient, but they can also carry reputational risks if used carelessly. As a PR agency, we help brands assess how sensitive content may affect public trust before it becomes a bigger issue.
Source:
- Dewan Rakyat passage of the Cybercrimes Bill 2026 — 1 July 2026: The Edge Malaysia.
- Dewan Negara passage — 20 July 2026: Free Malaysia Today.
- Photographs as personal data: Malaysia Personal Data Protection Commissioner FAQ.
- PDPA’s commercial-transaction scope: Personal Data Protection Commissioner’s Act overview.
- Kulai deepfake investigation: The Star, The Straits Times and Malay Mail.
- Malaysian copyright basics: MyIPO.
- Malaysian false-endorsement and passing-off principle: Mohammad Hafiz Hamidun v Kamdar and a Federal Court case summary
Frequently Asked Questions About AI-Generated Images
Do I Need Permission to Create an AI Image of Someone?
Not in every situation, but permission becomes particularly important when the person is identifiable and the image will be published, altered in a sensitive way or used commercially. Lack of consent can increase the risk of disputes involving personal data, reputation or false endorsement.
Can I Use a Celebrity’s Face in an AI Advertisement?
Doing so without permission is legally risky. The advertisement may falsely imply that the celebrity endorses or is connected with the product, even when the image is labelled as AI-generated.
Is It Legal to Make AI Memes of Politicians?
It depends on the content and context. Obvious satire may carry less risk than a realistic image that falsely suggests corruption, criminal conduct or another damaging event. Public figures are not automatically excluded from legal protection.
Can I Sue Someone for Creating a Deepfake of Me?
Potential remedies depend on what the image shows, how it was distributed and what harm it caused. Possible legal issues may include defamation, copyright, passing off, misuse of personal data or criminal conduct.
Is Sharing a Deepfake as Risky as Creating It?
It can be. Republishing harmful content may spread the false impression and increase the damage. Saying that you did not create the image does not automatically remove responsibility for sharing it.
Are AI-Generated Sexual Images of Real People Illegal?
They can result in serious legal consequences, particularly when created or shared without consent or when children are involved. The Cybercrimes Bill 2026 specifically addresses digitally manipulated intimate images, although its formal commencement status must be checked.

