Country-specific legal context¶
The Southeast Asian legal environment for online speech in 2024–2026 has moved in a recognisable direction. Explicit "fake news" branding has receded as a primary instrument. Multi-purpose digital-control frameworks have spread in its place. Cybercrime statutes, online-safety acts, anti-terror provisions, computer-crime codes, lèse-majesté laws and electronic-information laws now overlap inside layered enforcement architectures that can be justified as cybercrime control, online safety or terrorism prevention while still binding on public-interest verification work. The six focus countries sit at different points on that gradient. Indonesia operates inside the UU ITE framework after the April 2025 Constitutional Court rulings narrowed several of its more elastic readings. Malaysia operates inside the CMA Section 233 oscillation, the Online Safety Act 2025 implementation environment, and the 3R enforcement frame. Thailand operates inside Article 112 lèse-majesté, the April 2025 Emergency Decree on Technological Crimes amendments, and the July 2025 24-hour-takedown rules. The Philippines operates inside the cyber-libel framework, the anti-terror enforcement layer, and the COMELEC Resolution 11064 AI-election rules. Sri Lanka operates inside the Online Safety Act 2024 plus the Prevention of Terrorism Act legacy with a successor statute under drafting. Laos operates inside Decree 327 with a draft 2025 cybersecurity law under National Assembly review.
This page is the operational read of those six environments. The country pages already carry the legal facts. The job here is to make the operational implications cross-country comparable, so that a regional fact-check coalition can plan workflow, source-protection posture and verification disclosure with one comparative frame in view. The page is read alongside the T6 source-protection tree, which routes a current case to the S2 sub-section that fires; this page is the layer behind T6 that explains what S2 actually means in each jurisdiction and how the response posture differs from one country to the next.
Cross-country observation: what 2024–2026 made operational¶
Three patterns recur across the six countries and shape the operational implications below.
The first pattern is overlap. The legal-risk surface is not produced by a single statute; it is the product of statutes stacked. A claim that touches public officials in Indonesia can attract UU ITE complaints, criminal-defamation provisions, and Penal Code provisions arriving in 2026 in a layered way, and the offence count does not collapse to one. The Malaysian fact-checker working a 3R-coded claim faces CMA Section 233, the Sedition Act, Penal Code 505©, and the Online Safety Act 2025 enforcement environment in parallel. The Filipino verifier on a security-forces-named case faces cyber-libel, anti-terror provisions, and red-tagging-adjacent enforcement together. Reading the legal-risk question as "which statute applies" misreads the operational environment. The operational read is "which combination of statutes will the regulator and the complainant reach for", and that question is answered by the kind of subject the verification work touches.
Second, courts have produced partial relief, but the relief is unstable. Indonesia's Constitutional Court narrowed UU ITE in April 2025 (public unrest meaning physical not digital, hate-speech narrowed to intentional public risk-creation, defamation complainants restricted from government agencies and corporates). Malaysia's Court of Appeal narrowed CMA Section 233 in August 2025 in Heidy Quah, and the Federal Court reinstated "offensive" and "annoy" in February 2026. Thailand's June 2025 NACC anti-SLAPP amendment is real but narrow. Sri Lanka's OSA amendment process is in motion without a completed reform. None of this is a stable predicate to plan workflow against. The underlying offence architecture remains available in every country, and the response posture has to assume continued exposure even where a partial victory has been won.
Third, AI-specific regulation is emerging unevenly. The Philippines has the clearest worked AI-specific rule set in COMELEC Resolution 11064 and the AI-election framework for the 2025 cycle. Indonesia has moved further on AI-in-journalism governance through Press Council Regulation No. 1/2025 and the Komdigi AI Roadmap consultation, though without criminal-statute consequences. Malaysia's communications minister has signalled mandatory AI-generated labelling under the ONSA framework, though no separately enacted deepfake statute exists at the close of the review period. Thailand, Sri Lanka and Laos sit further down the gradient, with AI risk absorbed into older speech-control architectures and not into dedicated AI statutes. For verification work, the asymmetry produces a working rule: synthetic media is rising fastest where legal clarity is thinnest, and the response posture has to assume that synthetic content will be handled through general speech-control instruments in most jurisdictions, not through AI-specific ones.
Indonesia – UU ITE after the April 2025 Constitutional Court rulings¶
The Electronic Information and Transactions Law (Undang-Undang Informasi dan Transaksi Elektronik, UU ITE) is the central instrument. The second amendment, Law No. 1 of 2024, took effect 2 January 2024 and did not remove the existing framework. The 29 April 2025 Constitutional Court rulings narrowed several contested provisions: Article 28(3)/45A(3) public-unrest meaning was clarified as physical not digital space; criminal-defamation complainants under Article 27A/45(4) cannot be government agencies, institutions, companies or groups with specific identities; the hate-speech clause was narrowed to content that intentionally and publicly creates a real risk of discrimination, hostility or violence. Human Rights Watch read the rulings as significant but partial restraints on a law still used to silence critics.
For a working fact-checker on Indonesian content, the operational implication is reduced surface, not absent surface. Individuals can still file complaints. Investigations still chill reporting. The 2026 Penal Code transition keeps uncertainty high through the rest of the year. The Daniel Tangkilisan arc (2023 defamation conviction over the shrimp-farming case, May 2024 acquittal, successful 2025 challenge to UU ITE) shows both the exposure and the strategic-litigation route to narrowing the law after the fact. The practical implication for Indonesia is to treat UU ITE risk as reduced but live: archive source material, keep contemporaneous logs, and document public-interest grounds for publication.
The T6 source-protection tree S2 sub-section fires on Indonesian verification work touching public officials, named police or military, religious actors, and election-mobilisation campaigns. The framing is more permissive than in Thailand, Laos or Sri Lanka on equivalent subjects; the post-April-2025 environment is more accommodating of public-interest reporting on corporate or institutional subjects. The framing remains binding on personal-identity material involving named officials, and on KontraS-style civil-society researcher contact (the March 2026 acid attack on Andrie Yunus is the operational reminder that the threat surface is not only legal). For a Kalimasada-routed political claim where the subject is a public official and the source is a tipline submitter, the S5 (private-group collection) routing applies before the S2 sub-section is engaged.
The wider AI-in-journalism layer matters for newsroom verification disclosure but not for the speech-risk question. The Indonesia Press Council issued Regulation No. 1/2025 on the use of AI in journalistic work, with disclosure expectations around AI-assisted translation, transcription, and summarisation. In August 2025 Komdigi opened public consultation on a White Paper for a National AI Roadmap extending to 2045. Indonesian newsroom workflow on AI-assisted verification now sits under documented disclosure expectations alongside the UU ITE speech-risk environment. The Tempo Assistant and Tempo Detektif Deepfake deployments document the operational form for Tempo specifically.
For cross-border Bahasa–Malay claims, the Indonesian and Malaysian legal-risk environments run in parallel without being identical. A claim that surfaces in Bahasa channels and in Malay channels can attract UU ITE attention on the Indonesian side and CMA 233 attention on the Malaysian side at the same time. The verification work benefits from coordinated handling between MAFINDO–CekFakta and the Malaysian fact-check ecosystem. The Indonesia country page and the Malaysia country page carry the operational handles.
Laos – Decree 327 and the highest-S2 surveillance surface in the toolkit¶
Laos has the most binding legal-risk environment of the six. Decree No. 327/2014 on internet information management is the core instrument, and it criminalises online criticism of the government and the party and the circulation of "false information online." The 2015 cybercrime law sits alongside with vague content offences and investigative powers. The June 2025 draft Law on Cybersecurity, under National Assembly review at the time of writing, would materially extend state capacity if enacted; independent commentary reads it as expansion, not as liberalisation. Decree 327 already criminalises the speech the toolkit's audience produces in the ordinary course of verification work; the draft cybersecurity law would deepen the technical-and-administrative surface around that speech.
The operational consequence is that Lao political content presents the highest-S2 surface in the six focus countries. The T6 S2 sub-section fires by default on Lao political material. The Bee case from March 2024 (a Facebook user reportedly "re-educated" after posting a video exposing checkpoint bribery) and the Bao Mor Khaen / Sisay Luangmonda death in March 2026 (an outspoken government critic found dead after he went missing, with Human Rights Watch calling for an investigation) are the operational anchors. The boundary the state will police is documented, and so is the upper bound of the risk. Anyone documenting corruption, abuse or official falsehoods online in Lao should be treated as exposed.
S5 (private-group infiltration risk and identifying-material caution) sharpens on Lao work because the source pool is small. Diaspora reporters are identifiable by name. Partner-mediated routing means the partner organisation carries part of the exposure. Inside-the-country posters reaching diaspora networks are often already known to the state. The S5 routing on a Lao case looks closer to investigative-journalism source-protection practice than to typical fact-check workflow: strip identifying material from any intermediate file, retain originals in encrypted offline storage, do not retain the chain-of-custody log in cloud services.
S9 (cross-border vendor data retention risk) is operational on Lao work in a way it is not at lower-S2 levels. Cloud-hosted detector tools that ship Lao source files to US-jurisdiction or EU-jurisdiction servers carry data-residency implications that the verifier cannot resolve in-tool. Google Cloud Translation on identifying Lao material is restricted in practice; the InVID-WeVerify deepfake-tab 30-day CERTH retention window is restricted in parallel. Most practical Lao verification work therefore moves to offline tools (Sherloq at 1B.4 is the offline-desktop reference) or to partner-mediated routing that shifts the upload risk onto an organisation in a lower-risk jurisdiction. SEA-LION v4 (March 2026 release, Apache 2.0 in most variants) is the only LLM in the shortlist with documented Lao coverage and is locally deployable, which fits the surveillance-environment routing the Lao stack already assumes.
The practical guidance for Laos is direct: use maximum source minimisation, avoid retaining identifying source data unless operationally necessary, separate contributor identities from reporting files, and consider pseudonymous or offshore publication workflows for highly sensitive material. The Laos country page records the diaspora-and-regional-partner routing pattern that is the operational substitute for inside-the-country fact-check infrastructure.
Malaysia – CMA 233, Online Safety Act 2025, and the 3R enforcement frame¶
Malaysia's legal-risk environment runs at three overlapping layers and has been in motion through 2025–2026. The Communications and Multimedia (Amendment) Act 2025 reworked Section 233; offence language moved from "offensive" to "grossly offensive" and penalties rose materially. The August 2025 Court of Appeal ruling in Heidy Quah v Government of Malaysia held the use of Section 233(1) against speech deemed "offensive" or intended to "annoy" to be unconstitutional. In February 2026 the Federal Court reversed, reinstating "offensive" and "annoy" in Section 233(1)(a) and treating the move as a setback for free expression. Legal uncertainty resumed on the same broad offence architecture, available to investigators across 2026.
The Online Safety Act 2025 (Act 866) came into force from 1 January 2026 per MCMC's 1 January 2026 FAQ. ARTICLE 19, CIJ and Sinar Project flagged the draft Online Safety Plan and related codes in their 1 April 2026 consultation submission as relying on vague "harmful content" categories, privatised speech policing, and proactive-monitoring incentives that amount to generalised content surveillance. ONSA sits as the platform-regulation layer; the CMA Section 233 reach sits as the broad offence layer; the 3R enforcement frame (race, religion, royalty) interleaves with both, with the Sedition Act and Penal Code 505© available alongside.
The Malaysiakini January 2025 CMS-access incident is the operational anchor for newsroom-system threat-modelling. CPJ reported on 30 January 2025 that police seized executive editor RK Anand's laptop and that MCMC sought access to Malaysiakini's content-management system. The implication for fact-check operations is direct: regulator action can target the CMS itself. Source-list compartmentalisation, role-based access to drafts and verification files, and secure-export discipline are operational, not precautionary. The auto-archiver cross-jurisdiction route handles the same problem from the storage side, moving high-value verification material outside Malaysian regulator reach.
The practical implication for Malaysia is to assume platform-facing compliance pressure can spill into newsroom systems. Use role-based access for CMS tools, minimise who can access drafts and source files, and keep secure exports off the production CMS in case a regulator seeks backend access. The T6 S2 sub-section fires on Malaysian work touching 3R material, named officials, security forces, or any case the CMA / ONSA / Sedition Act enforcement frame could reach. The Rex Tan January 2026 arrest under Sedition Act, Penal Code 505©, and CMA 233 together is the worked example.
The Murray Hunter cross-border legal-intimidation pattern is documented in IFEX and CIJ reporting from October 2025. The Australian-born commentator was detained in Bangkok on defamation allegations linked to Malaysian authorities and later indicted in Thailand. The implication for regional fact-checking networks is that defamation complaints linked to Malaysian state bodies can spill into neighbouring jurisdictions. Verification work on Malaysia-touching content carries cross-border legal exposure even when the verifier is not in Malaysia. The Thailand country page records the Thai-side handles; the cross-border pattern is the subject of one of the threat-models page's six recurring patterns.
Sebenarnya.my AIFA's operational form sits inside this environment. The chatbot is operated by MCMC, the regulator also documented as the operator behind the device-seizure and CMS-access incidents CIJ has flagged. The Sebenarnya AIFA tool card carries the operator-identity independence caveat. The tension is structural and operational, not rhetorical: the tool reaches a wide public audience civil-society alternatives do not match, and its operator is the same body whose enforcement actions civil society documents as concerning.
Philippines – cyber-libel, anti-terror, COMELEC Resolution 11064¶
The Philippine legal-risk environment is the most legally specific on AI-election material in the six-country set, and one of the most operationally severe on community-reporting work. The Cybercrime Prevention Act of 2012 carries the cyber-libel provision that has shaped the press environment through the Maria Ressa arc. The Ressa cyber-libel case remained pending against Ressa and Reynaldo Santos through 2024–2026, with the June 2025 Rappler acquittal in the anti-dummy case leaving cyber-libel under final appeal. In June 2024, CPJ, RSF and ICFJ filed an amicus brief urging the Supreme Court to close the case. Cyber-libel is the central legal-risk instrument on the press environment side.
The anti-terror legal frame is the operationally sharper instrument on community-reporting work. The Deo Montesclaros terrorism-financing charges (January 2025), the Frenchie Mae Cumpio terrorism-financing conviction (January 2026), and the broader CMFR / NUJP attacks-on-press documentation through April 2025 show that anti-terror provisions remain usable against journalists. Red-tagging is the term Filipino civil society uses for labelling journalists and activists as communist or terrorist sympathisers; CMFR / NUJP data identifies 48 red-tagging cases and 19 surveillance incidents in the broader attacks-on-press dataset. Red-tagging converts online monitoring into offline danger. The SIM Registration Act adds attribution risk on phone-routed source contact. On Filipino verification work touching security forces, communities in Mindanao, land or labour rights, or environmental defenders, the threat-model framing is anti-terror frame first.
COMELEC Resolution 11064 (adopted 17 September 2024, effective 25 September 2024, amended through Resolution 11064-A) regulates the misuse of social media, AI and internet technology for digital campaigning, disinformation and misinformation in the 2025 national, local and BARMM parliamentary elections. The resolution is the clearest worked AI-election rule set in the region, with prohibitions on deepfakes and manipulated AI-generated campaign content, disclosure obligations for AI-generated materials, and registration requirements for campaign platforms.
For working fact-checkers, COMELEC 11064 changes the verification workflow on election-cycle content in two ways. First, the disclosure question becomes documentary: AI-generated campaign material not disclosed as AI-generated falls inside the resolution's prohibition, adding a regulatory dimension on top of authenticity verification. Second, provenance preservation matters: campaign material verified during the cycle should be archived with a clear chain of custody, because regulatory complaints can rely on verification evidence in ways authenticity-only cases do not. T4 provenance triage carries a heavier operational load during Filipino election cycles than in most regional contexts. Content Credentials Verify at 1A.4 sits in the front-line pass on campaign artefacts. auto-archiver at 2A.3 handles the archive workflow regulatory complaints depend on.
Senate Bills 191 and 241 (anti-fake-news bills filed July 2025) and Senate Bill 758 (Deepfake Regulation and Digital Identity Protection Act, filed July 2025) entered the legislative pipeline through 2025. None had been enacted by May 2026 in the reviewed materials, but the legislative interest signals further AI-specific statute work may follow the COMELEC framework.
The surveillance picture in the Philippines includes documented Predator spyware infrastructure with "Philippines-based" attribution in 2024 public reporting, though the reviewed materials do not tie that infrastructure to a verified domestic victim list. The practical implication is to treat the spyware infrastructure as a watchpoint, not a confirmed targeting dataset, and to route any case where surveillance compromise becomes a working hypothesis through the institutional CSIRT layer at 1C.1 and through the T6 source-protection tree. The S5 sub-section sharpens on Filipino work because the cybertroop and coordinated-amplification environment includes documented infiltration patterns.
Sri Lanka – Online Safety Act 2024, PTA legacy, and the airport-detention pattern¶
The Online Safety Act No. 9 of 2024 (OSA) is the central legal instrument. The Act was certified 1 February 2024 and establishes an Online Safety Commission with broad powers over "prohibited statements," online accounts and "online locations" used for prohibited purposes. The first arrest under the OSA was made in February 2024, and the Online Safety Commission was not appointed at the time. The Cabinet approved an amendment-committee process in February 2025; the law remained in force through 2025–2026 with the amendment process described as ongoing in September 2025 reporting. Access Now, CPJ and fifty-plus organisations called in January 2024 for the bill to be withdrawn. GNI's March 2025 year-in-review characterised the OSA as one of the most sweeping threats to freedom of expression and privacy in any jurisdiction.
The Prevention of Terrorism Act (PTA) legacy sits alongside the OSA. RSF in September 2024 called for repeal of both. In April 2025, the Centre for Policy Alternatives warned that the government continued to use the PTA for conduct with no apparent connection to terrorism, including arresting a youth over anti-Israel stickers. Human Rights Watch in January 2026 warned that the proposed Protection of the State from Terrorism Act risked reproducing PTA abuses. Groundviews described the December 2025 draft as retaining wide executive powers and strong overlap between ordinary offences and terrorism. The legal-risk question runs through PTA-replacement framing as well as PTA enforcement.
The 2024–2026 prosecutions pattern affects both Sinhala-language and Tamil-language journalism, and falls disproportionately on Tamil journalists. CPJ reported in August 2025 that counter-terrorism police summoned Tamil photojournalist Kanapathipillai Kumanan, who had been documenting mass graves in the north. In March 2026, authorities detained Lanka-e-News editor Sandaruwan Senadheera after he arrived at Colombo airport. The airport-detention pattern matters operationally. The threat surface includes border control on returning journalists, not only inland investigation.
For working Sri Lankan verification, the operational implication is layered. The T6 S2 sub-section fires on Sri Lankan work touching the OSA enforcement pattern, the PTA legacy, north-and-east community reporting, or any case where counter-terrorism framing is plausible. The S5 sub-section sharpens on Tamil community sources in the north and east, where the documented physical-and-digital surveillance pattern (per RSF UN reporting September 2024, Tamil Guardian February 2025) interleaves with OSA centralised authority over accounts, content and "online locations." The practical implication is that staff travelling to the north and east should use travel-clean devices where possible, keep sensitive archives off-device, and set up immediate check-in procedures.
The surveillance environment drives the choice of forensics tooling. Sherloq at 1B.4 is the offline forensics route when the source file cannot leave the verifier's machine. The toolkit treats this offline-desktop pattern as mandatory mitigation for Sri Lanka's surveillance-environment threat model under Decision 7 paired honest-gap policy. The auto-archiver cross-jurisdiction archive route at 2A.3 handles retention outside Sri Lankan jurisdiction.
The Meta Content Library access barrier is structural. No Sri Lankan operator currently holds active IFCN signatory status, which closes Meta Content Library access to most Sri Lankan fact-check operators. The toolkit treats Meta Content Library as a Graphika-pattern access-barrier tool with the "cite as external source" Quickstart redirect. The route around the gap runs through Fact Crescendo Sri Lanka's network-level connection or through a partner organisation outside Sri Lanka holding the IFCN signatory status Sri Lankan operators do not currently carry.
Thailand – Article 112, the April 2025 Emergency Decree amendments, and Pegasus¶
Thailand carries the sharpest S2 surface in the toolkit on royalty-adjacent material and the only surveillance environment in the focus set where mercenary-spyware threat sits central in the background risk picture. Article 112 of the Criminal Code (lèse-majesté) is the central instrument on monarchy-adjacent verification work. RSF's current Thailand profile describes lèse-majesté as a permanent threat hanging over media. The 112 Watch 2024 report and ARTICLE 19's 2024 defamation report both record continued enforcement through 2024–2026. The Constitutional Court dissolved the Move Forward Party in August 2024 in a case rooted in its Section 112 reform campaign. The legal-risk surface on any verification work touching the monarchy, royal family or royal-symbol material is binding.
The April 2025 amendments to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes expanded enforcement powers and added obligations for relevant businesses. The July 2025 social-media safe-harbour rules require platforms to remove specified content within 24 hours of government notification. Manushya Foundation and allied groups have warned that the new decree effectively replaced the 2017 content-removal framework and required intermediaries to remove content within 24 hours where users or the public alleged a violation of Section 14 of the Computer Crime Act. For fact-checkers, the practical change is that platform complaints can cascade quickly into removal pressure, with weak oversight and strong incentives for intermediary over-compliance. Verification work that produces public-facing debunks can attract the same takedown pressure as the original misleading content where the complaint frame is plausible.
The criminal-defamation framework remains active alongside, and Thailand became a venue for transnational legal intimidation through the Murray Hunter case (Australian-born commentator indicted in Thailand on criminal-defamation charges at Malaysia's request over his Substack articles about MCMC). The June 2025 NACC-linked anti-SLAPP amendment slightly improved protection for good-faith complainants and whistleblowers dealing with official misconduct. The ICJ welcomed the 2025 anti-SLAPP reform as progress but stressed that Thailand still lacks a comprehensive anti-SLAPP framework beyond the NACC setting.
For working Thai verification, the T6 S2 sub-section fires by default on work touching the monarchy, royal symbols, protest movements, or corruption involving elites. The practical implication is to use special escalation procedures: mirror and timestamp contested content outside local platforms; combine auto-archiver at 2A.3 cross-jurisdiction retention with Sherloq at 1B.4 offline forensics for the highest-risk source files.
The Pegasus history makes phone-compromise threat-modelling operational on sensitive Thai verification work. Citizen Lab's earlier "GeckoSpy" findings established Pegasus targeting against Thailand's pro-democracy movement. Amnesty reported in November 2024 that a Bangkok civil court dismissed Jatupat Boonpattararaksa's lawsuit against NSO Group; Manushya described the case as one chapter in an ongoing fight over spyware abuse in Thailand. Privacy International's January 2025 work on protest surveillance warns that information gathered through blanket monitoring of protests is used in criminal proceedings against activists and defenders. Manushya's December 2024 reporting on facial recognition and predictive-policing deployment in the Southern Border Provinces records AI-enhanced surveillance as part of the threat landscape. The S5 sub-section sharpens on Thai work because protest-surveillance and Pegasus history can turn metadata into evidence.
Cofact Thailand's LINE-native operational form sits inside this environment. The platform-of-origin protection considerations on LINE-routed material differ from WhatsApp-routed material. The LINE codec compression gap on audio and video material remains untested in any public audit; verification of LINE-routed audio operationally combines human review with the detector pass. The 24-hour-takedown rules apply to verified debunks Cofact publishes back through LINE; the cross-jurisdiction archive route is operational on the highest-risk debunk material.
How this section routes back into in-case work¶
The six country sections above sit behind the operational tools the toolkit ships. When a current case reaches the desk, the routing layer is the T6 source-protection tree and the country page for the jurisdiction. T6 routes the case to the S-class that fires; the country page anchors the operational case work in regional grounded reads of the environment; this page is the comparative layer that lets a regional coalition plan workflow across jurisdictions and identifies the cross-border patterns the threat-models page expands on.
Three operational handles travel across all six jurisdictions. The first is to archive material to controlled cross-jurisdiction locations early; the auto-archiver cross-jurisdiction route at 2A.3 is the standard option. The second is to separate factual verification from legal-risk review in the publication workflow; content can be accurate and still trigger exposure under defamation, public-order, "harmful content" or anti-terror provisions. The third is to prepare a regulator and police response protocol so staff know what to do if approached by police, MCMC-or-equivalent digital regulators, or counter-terror units. Cross-country synthesis names all three as binding across the six jurisdictions.
Cross-references¶
- T6 source-protection tree – S2 sub-section is the in-case routing for this page
- Source-protection aggregation – the pedagogical layer on S2 sits inside the wider S1–S10 system
- Threat models – the surveillance-state, election-cycle, scam-economy, red-tagging, communal-memory, and cross-border patterns this page anchors
- Operational checklists – pre-publication and pre-platform-report checklists carry the legal-risk-review step
- Country pages: Indonesia, Laos, Malaysia, Philippines, Sri Lanka, Thailand
- Tool cards: auto-archiver, Sherloq, Sebenarnya AIFA, Cofact Thailand, MAFINDO Kalimasada, Meedan Check, Content Credentials Verify, SEA-LION, Google Cloud Translation, InVID-WeVerify, Meta Content Library
Sources¶
- Human Rights Watch. World Report 2026. HRW, 2026. hrw.org.
- ARTICLE 19. Southeast Asia: Digital Rights and Free Expression. ARTICLE 19, 2025. article19.org.
- Reporters Without Borders (RSF). Press Freedom Index 2025. RSF, 2025. rsf.org/en/index.
- Committee to Protect Journalists. Digital Safety. CPJ, 2025. cpj.org/digital-safety.
- Country pages (Indonesia, Laos, Malaysia, Philippines, Sri Lanka, Thailand) – the regional-grounded legal-context sections this page expands
- Architectural Anchors – Architectural Anchor 1 (provenance-first workflow)