LEXAUPDATES
PostAdvertiseAboutContact
LEXAUPDATE — Legal Internships, Moots, Jobs, CFPs & Daily Legal News
← Legal Articles/🇺🇸 United States/Legal Article

Source: Manual

Deepfakes and the Law: Legal Risks of AI-Generated Images, Videos and Audio

LexaUpdate Editorial Team🇺🇸 United StatesLegal Article

← Legal Articles / 🇺🇸 United States / Legal Article

Deepfakes and the Law: Legal Risks of AI-Generated Images, Videos and Audio

Deepfakes can imitate a person's face, voice or actions with remarkable realism. As synthetic media becomes easier to create, existing rules on privacy, defamation, fraud, intellectual property and non-consensual intimate imagery are increasingly being applied alongside new AI-specific regulation. This guide explains the legal risks associated with deepfakes in 2026.

Advertisement
Ad slot — configure in AdSense

Deepfakes and the Law: Legal Risks of AI-Generated Images, Videos and Audio

Quick Answer: Deepfakes can create legal consequences under multiple areas of law, including privacy, defamation, intellectual property, consumer protection, fraud, criminal law and laws governing non-consensual intimate imagery. New AI-specific rules are also emerging. In the European Union, transparency obligations under Article 50 of the AI Act apply from 2 August 2026 to certain AI-generated and manipulated content, including deepfakes. In the United States, the federal TAKE IT DOWN Act became law in May 2025 and addresses the non-consensual publication of intimate visual depictions, including computer-generated depictions.

A politician appears to announce something that never happened.

A company executive appears to authorise a fraudulent payment.

A celebrity's face is inserted into an advertisement without consent.

A person's voice is cloned and used to deceive a family member.

A person's face is placed into an intimate image without consent.

None of these events may have actually occurred.

Yet the digital evidence may appear convincing.

This is the legal problem created by deepfakes.

Deepfake technology allows artificial intelligence and other computational techniques to generate or manipulate images, audio and video so that a person appears to say or do something that they did not actually say or do.

The technology itself is not automatically unlawful.

A synthetic video created for a film may be perfectly legitimate.

A parody may be protected by applicable law.

A digitally altered image may be lawful in one context and unlawful in another.

The legal question therefore is not simply:

“Is this a deepfake?”

The more important questions are:

  • Who created it?
  • Who is depicted?
  • Was consent obtained?
  • What does the content communicate?
  • Who distributed it?
  • Was it intended to deceive?
  • Did it cause harm?
  • Was it commercial?
  • Was it intimate?
  • Does a specific AI transparency law apply?

This article explains the developing legal framework surrounding deepfakes in 2026.

Legal disclaimer: This article provides general educational information and is not legal advice. Deepfake laws differ substantially between jurisdictions and can change rapidly.

Key Takeaways

  • Deepfakes are not automatically illegal.
  • The legality of a deepfake depends heavily on its purpose, content, distribution and consequences.
  • Privacy and publicity laws can apply when a person's likeness or identity is used without permission.
  • Defamation law can become relevant when false statements are attributed to an identifiable person.
  • Fraud laws can apply when deepfakes are used to deceive victims for financial or other unlawful gain.
  • Non-consensual intimate deepfakes present particularly serious legal risks.
  • The United States enacted the TAKE IT DOWN Act in 2025 addressing non-consensual intimate visual depictions, including computer-generated material.
  • The EU AI Act's transparency rules for certain AI-generated and manipulated content apply from 2 August 2026.
  • EU rules require certain deepfakes to be visibly disclosed as artificially generated or manipulated.
  • Machine-readable marking is also relevant to certain AI-generated or manipulated content under the EU framework.
  • Deepfake disputes can involve several areas of law simultaneously.
  • Businesses should establish policies governing the creation, use and distribution of synthetic media.

What Is a Deepfake?

Quick Answer: A deepfake is synthetic or manipulated media generated or altered using artificial intelligence or other computational techniques so that it can realistically depict a person, object, place, event or action.

Deepfakes can involve:

  • Faces.
  • Voices.
  • Video.
  • Images.
  • Audio.
  • Text.

Face-swapping is one of the most recognisable forms.

However, modern synthetic media extends well beyond simple face replacement.

AI systems can generate an entirely synthetic person.

They can clone a person's voice.

They can modify facial expressions.

They can generate realistic scenes that never occurred.

They can also combine real and synthetic material.

Are Deepfakes Illegal?

Quick Answer: No. Deepfakes are not universally illegal. Their legality depends on the applicable law and the circumstances in which the content is created or distributed.

For example, consider three scenarios.

Scenario 1: Film production.

A production company digitally recreates an actor's younger appearance under a valid agreement.

This may be lawful.

Scenario 2: Political parody.

A creator makes an obviously satirical AI video of a public figure.

The legal analysis may involve constitutional or free-expression protections depending on the jurisdiction.

Scenario 3: Fraud.

A criminal clones a company executive's voice and orders an employee to transfer money.

The circumstances can potentially trigger criminal and civil liability.

The technology is similar.

The legal consequences are not.

Why Are Deepfakes Legally Difficult?

Quick Answer: Deepfakes create legal difficulty because they can combine genuine identity characteristics with fabricated events, making it difficult to distinguish authentic evidence from synthetic content.

Traditional legal rules often assumed that a photograph, recording or video represented an actual event.

That assumption is increasingly unreliable.

A convincing video may be entirely synthetic.

An apparently authentic voice recording may be AI-generated.

A photograph may depict an event that never occurred.

This creates problems for:

  • Courts.
  • Businesses.
  • Journalists.
  • Financial institutions.
  • Law-enforcement agencies.
  • Consumers.

Deepfakes and Privacy Law

Quick Answer: Privacy law can become relevant when deepfake technology uses a person's image, voice, biometric information or other personal information without an appropriate legal basis or consent.

Potentially relevant information can include:

  • Facial images.
  • Voice recordings.
  • Biometric identifiers.
  • Private photographs.
  • Personal information.

The applicable legal framework depends on the jurisdiction.

In the European Union, processing personal data through AI can raise GDPR issues alongside the AI Act.

This creates an important connection between deepfake regulation and the data-protection issues discussed in Article #55.

Deepfakes and Defamation

Quick Answer: Defamation law can potentially apply when a deepfake falsely attributes a damaging statement or conduct to an identifiable person.

Imagine an AI-generated video showing a business executive accepting a bribe.

If viewers reasonably believe that the video is authentic, it could potentially damage the person's reputation.

The legal analysis may depend on:

  • Whether the representation is false.
  • Whether it was communicated to third parties.
  • Whether it caused reputational harm.
  • Whether the applicable legal standard is satisfied.
  • Whether constitutional or other defences apply.

Public figures may face additional requirements under some legal systems, particularly in the United States.

Can a Deepfake Be Defamation?

Quick Answer: Potentially. A fabricated video, audio recording or image can form the basis of a defamation claim if the applicable legal elements are satisfied.

The fact that the content was AI-generated does not automatically remove it from existing defamation law.

However, courts may need to examine additional questions concerning whether a reasonable viewer would understand the content as factual or fictional.

Deepfakes and the Right of Publicity

Quick Answer: In jurisdictions recognising publicity or personality rights, unauthorised commercial use of a person's identity can create legal exposure.

A company might generate an advertisement that makes a celebrity appear to endorse a product.

If no permission exists, the business could face claims depending on the applicable law.

Potentially relevant identity characteristics can include:

  • Name.
  • Face.
  • Voice.
  • Signature characteristics.
  • Other recognisable attributes.

Deepfakes and Copyright

Quick Answer: Deepfakes can create copyright questions when they use copyrighted photographs, videos, recordings, characters or other protected material.

Potential issues include:

  • Copying.
  • Adaptation.
  • Derivative works.
  • Training data.
  • Distribution.
  • Commercial exploitation.

Copyright law does not provide a universal answer to every deepfake.

The legal analysis depends on the source material, transformation, purpose and applicable jurisdiction.

This makes deepfake regulation closely connected to the copyright issues discussed in Article #54.

Deepfakes and Fraud

Quick Answer: Deepfake technology can become a powerful fraud tool when synthetic media is used to deceive victims into transferring money, revealing information or taking other actions.

For example:

An attacker clones the voice of a company's chief executive.

The attacker calls an employee.

The employee believes the call is genuine.

The employee transfers money to an account controlled by the attacker.

The underlying technology may be AI.

But the legal issue is fraud.

The AI system becomes the instrument used to commit the unlawful act.

Deepfakes and Identity Theft

Quick Answer: Deepfakes can facilitate identity-related offences by allowing criminals to imitate another person's appearance or voice.

Potential uses include:

  • Fake identity verification.
  • Account takeover.
  • Social engineering.
  • Financial fraud.
  • Impersonation.

Businesses should therefore treat synthetic-identity attacks as part of their broader cybersecurity and fraud risk programmes.

Deepfakes and Non-Consensual Intimate Images

Quick Answer: Non-consensual intimate deepfakes create particularly serious legal risks because they combine synthetic media with privacy, sexual exploitation and reputational harm.

AI can create an apparently intimate image of an identifiable person even where the person never participated in the depicted activity.

This has become a major policy concern internationally.

What Is the U.S. TAKE IT DOWN Act?

Quick Answer: The TAKE IT DOWN Act became federal law in the United States on 19 May 2025 and addresses the publication of non-consensual intimate visual depictions, including computer-generated depictions.

The law is formally titled the Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act.

The statute prohibits the intentional publication of covered non-consensual intimate visual depictions and establishes obligations concerning covered platforms. :contentReference[oaicite:0]{index=0}

The Act expressly includes computer-generated “digital forgeries” within its framework. :contentReference[oaicite:1]{index=1}

Does the TAKE IT DOWN Act Cover AI-Generated Images?

Quick Answer: Yes. The federal statute expressly addresses computer-generated intimate visual depictions and defines digital forgery in terms that include material created, modified, manipulated or altered through software, machine learning, artificial intelligence or other technological means. :contentReference[oaicite:2]{index=2}

This is significant because the law does not limit its protection to authentic photographs or videos.

Synthetic intimate material can also fall within the federal framework.

What Does the TAKE IT DOWN Act Require Platforms to Do?

Quick Answer: The Act establishes a notice-and-removal framework requiring covered platforms to remove qualifying non-consensual intimate visual depictions after receiving a valid notice, subject to the statute's requirements.

The federal law therefore adds a platform-governance dimension to deepfake regulation. :contentReference[oaicite:3]{index=3}

Deepfakes Under the EU AI Act

Quick Answer: The EU AI Act imposes transparency obligations concerning certain AI-generated or manipulated content, including deepfakes.

Article 50 is particularly important.

The European Commission's current guidance states that Article 50 transparency obligations apply from 2 August 2026. :contentReference[oaicite:4]{index=4}

The rules are designed to help individuals recognise when they are interacting with AI or encountering AI-generated or manipulated content. :contentReference[oaicite:5]{index=5}

How Does the EU AI Act Define a Deepfake?

Quick Answer: Under the EU AI Act framework, a deepfake broadly concerns AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

The European Commission's 2026 Code of Practice specifically addresses deepfake labelling and describes the relevant concept in this context. :contentReference[oaicite:6]{index=6}

Do Deepfakes Have to Be Labelled in the EU?

Quick Answer: Certain AI-generated or manipulated deepfake content must be visibly disclosed as artificially generated or manipulated under the EU AI Act's transparency rules.

The European Commission states that from 2 August 2026, deepfakes covered by the relevant provisions must be labelled, while certain AI-generated or manipulated content must also contain machine-readable markings. :contentReference[oaicite:7]{index=7}

This represents an important shift from simply prohibiting harmful uses toward requiring transparency about synthetic media.

What About AI-Generated Text?

Quick Answer: EU transparency rules also address certain AI-generated or manipulated text published on matters of public interest.

Deployers of relevant AI systems must disclose such content where the applicable conditions are met, including where the text has not undergone human review or editorial control. :contentReference[oaicite:8]{index=8}

This is particularly relevant to:

  • News organisations.
  • Political communication.
  • Public-information websites.
  • Social-media publishers.
  • AI content platforms.

What Are Machine-Readable AI Marks?

Quick Answer: Machine-readable marks are technical indicators that can help systems identify AI-generated or manipulated content.

The objective is to make synthetic content detectable by technical systems rather than relying exclusively on a human viewer noticing a visible label.

The European Commission's Article 50 framework specifically addresses machine-readable marking for certain AI-generated or manipulated content. :contentReference[oaicite:9]{index=9}

Is the EU Deepfake Code of Practice Mandatory?

Quick Answer: The Code of Practice on Transparency of AI-Generated Content is voluntary, but it is intended to provide a practical method for demonstrating compliance with the relevant Article 50 obligations.

The European Commission and AI Board assessed the Code as an adequate tool for facilitating compliance, while noting that adherence does not constitute conclusive evidence of compliance. :contentReference[oaicite:10]{index=10}

This distinction is important.

Voluntary code does not mean voluntary compliance with the underlying legal obligation.

What Changed on 2 August 2026?

Quick Answer: 2 August 2026 marked the beginning of the EU AI Act's transparency obligations under Article 50 for relevant AI systems, including rules concerning deepfakes and certain AI-generated content.

The European Commission began enforcing the AI Act from that date and specifically identified new transparency rules concerning AI interaction, AI-generated content and deepfakes. :contentReference[oaicite:11]{index=11}

The Commission also published final guidance on Article 50 shortly before the rules became applicable. :contentReference[oaicite:12]{index=12}

Are All Deepfakes Covered by the EU AI Act?

Quick Answer: No. The Article 50 obligations apply according to their specific legal scope and contain exceptions and conditions.

Businesses should therefore avoid a simplistic rule stating:

“Every AI-generated image must be labelled.”

The precise obligation depends on:

  • The type of AI system.
  • The nature of the content.
  • The role of the organisation.
  • The intended purpose.
  • Whether an exception applies.

What Are the Main Legal Risks of Deepfakes?

Deepfake Use Potential Legal Area
Fake statement attributed to a person Defamation
Celebrity endorsement without permission Publicity / consumer law
Fake intimate image Privacy / criminal law / intimate-image laws
Executive voice clone used for payment fraud Fraud / cybercrime
Copyrighted film manipulated into new content Copyright
Political deepfake Election / media / constitutional law
AI-generated advertisement Consumer protection
Fake identity verification Identity fraud / financial regulation
Unlabelled regulated AI-generated content AI regulation

Deepfakes and Election Law

Quick Answer: Political deepfakes can raise election-law, campaign-finance, constitutional, media and consumer-protection questions depending on the jurisdiction.

A fabricated video of a candidate appearing to make a statement may influence voters.

However, the legal response differs substantially between jurisdictions.

Some systems focus on election-specific restrictions.

Others rely on existing defamation, fraud or media laws.

Businesses publishing political content should therefore conduct jurisdiction-specific reviews.

Deepfakes and Freedom of Expression

Quick Answer: Deepfake regulation must often be balanced against freedom of expression, satire, parody, artistic expression and political speech.

This is particularly important in the United States.

A law restricting malicious impersonation may be treated differently from a law prohibiting political satire.

Courts may therefore need to distinguish between:

  • Fraudulent deception.
  • Defamation.
  • Harassment.
  • Parody.
  • Satire.
  • Artistic expression.
  • Political commentary.

The legal context matters enormously.

Can a Deepfake Be Used as Evidence in Court?

Quick Answer: Yes, but the existence of deepfake technology makes authentication and reliability particularly important when digital media is presented as evidence.

A party may challenge:

  • Authenticity.
  • Integrity.
  • Chain of custody.
  • Source.
  • Metadata.
  • Digital signatures.
  • Editing history.

This issue will become increasingly important as synthetic media becomes easier to create.

What Is the Deepfake Evidence Problem?

Quick Answer: The deepfake evidence problem refers to the difficulty of determining whether apparently authentic digital material is genuine or artificially generated.

This creates two opposite risks.

Risk 1: A fake video is wrongly treated as genuine.

Risk 2: Genuine evidence is dismissed as a deepfake.

The second problem is sometimes called the “liar's dividend”.

If society becomes aware that realistic digital fabrication is easy, a person accused of wrongdoing may claim that genuine evidence is synthetic.

Deepfakes and Businesses

Quick Answer: Businesses should treat deepfake risks as part of their cybersecurity, fraud, compliance and communications programmes.

Corporate risks can include:

  • CEO impersonation.
  • Voice-cloning fraud.
  • Fake customer communications.
  • False announcements.
  • Brand impersonation.
  • Fake employee videos.
  • Reputational attacks.

How Can Businesses Protect Against Deepfake Fraud?

Quick Answer: Businesses should avoid relying on voice or video alone for high-risk authentication or financial instructions.

Controls can include:

  1. Multi-factor authentication.
  2. Independent verification of financial instructions.
  3. Call-back procedures.
  4. Dual approval for major transactions.
  5. Identity verification.
  6. Employee training.
  7. Deepfake awareness.
  8. Incident-response procedures.

Deepfake Incident Response

Quick Answer: Organisations should have a predefined procedure for responding when fake or manipulated media impersonating the organisation or its personnel appears online.

A response plan can include:

  1. Preserve the content.
  2. Record the URL and publication time.
  3. Capture available metadata.
  4. Verify the underlying event.
  5. Identify the impersonated person.
  6. Assess potential legal claims.
  7. Contact the platform where appropriate.
  8. Notify affected parties.
  9. Issue a correction if necessary.
  10. Preserve evidence for potential litigation.

Deepfake Compliance Policy for Businesses

Quick Answer: Businesses using generative AI should adopt internal policies governing the creation, publication and labelling of synthetic media.

A policy can address:

  • Permitted uses.
  • Prohibited uses.
  • Consent.
  • Copyright.
  • Privacy.
  • Labelling.
  • Political content.
  • Impersonation.
  • Employee likeness.
  • Customer likeness.
  • Incident reporting.

Deepfake Compliance Checklist

Question Business Action
Are we creating synthetic media? Inventory the use case
Does it depict an identifiable person? Assess consent and identity rights
Is copyrighted material used? Conduct IP review
Could viewers mistake it for reality? Assess transparency requirements
Is the content commercial? Review publicity and consumer law
Is the content intimate? Assess applicable intimate-image laws
Is it political? Review election and speech rules
Does EU law apply? Assess Article 50 obligations
Could it facilitate fraud? Apply cybersecurity controls
Can authenticity be demonstrated? Maintain provenance and records

Frequently Asked Questions

What is a deepfake?

A deepfake is AI-generated or manipulated media that can realistically depict a person, object, place, event or action in a way that may falsely appear authentic.

Are deepfakes illegal?

Not automatically. The legality depends on the purpose, content, consent, distribution, harm and applicable law.

Can deepfakes be defamatory?

Yes, potentially. A fabricated representation that falsely attributes damaging conduct or statements to an identifiable person can raise defamation issues where the legal requirements are satisfied.

Can someone sue over a deepfake?

Potentially. Depending on the circumstances and jurisdiction, claims may involve defamation, privacy, publicity rights, copyright, consumer protection or other civil causes of action.

Can AI-generated intimate images be illegal?

Yes. Laws increasingly address non-consensual intimate imagery, including computer-generated material. The U.S. federal TAKE IT DOWN Act is one significant example.

What is the TAKE IT DOWN Act?

The TAKE IT DOWN Act is a U.S. federal law enacted in May 2025 addressing the non-consensual publication of intimate visual depictions, including computer-generated digital forgeries.

Are deepfakes regulated in the European Union?

Yes. The EU AI Act includes transparency obligations for certain AI-generated and manipulated content, including deepfakes.

When did EU deepfake labelling rules begin?

The relevant Article 50 transparency obligations began applying on 2 August 2026, subject to the Regulation's specific scope and exceptions.

Do all AI-generated images have to be labelled in the EU?

No. The obligation depends on the specific AI system, content and circumstances covered by Article 50.

What is machine-readable marking?

Machine-readable marking involves technical indicators that can help systems identify AI-generated or manipulated content.

Is the EU AI Act Code of Practice mandatory?

The Code of Practice on Transparency of AI-Generated Content is voluntary. It is designed to provide practical measures that can help providers and deployers demonstrate compliance with the underlying Article 50 obligations.

Can deepfakes be used as evidence?

Potentially, but authenticity and integrity become critical evidentiary questions. Courts may need to consider provenance, metadata, chain of custody and expert analysis.

Can a company use an employee's face in an AI-generated video?

Businesses should obtain appropriate permissions and assess applicable employment, privacy, publicity, intellectual-property and data-protection rules before using identifiable employees in synthetic media.

Can a celebrity's face be used in an AI advertisement?

Unauthorised commercial use of a celebrity's identity can create legal risks, including publicity-rights, consumer-protection and potentially other claims depending on the jurisdiction.

Can deepfakes be used for fraud?

Yes. Voice cloning, video impersonation and synthetic identities can be used to deceive victims and facilitate financial or other forms of fraud.

How can businesses detect deepfake fraud?

Businesses should combine technical detection with strong identity verification and transaction controls rather than relying exclusively on whether a voice or video appears authentic.

What should someone do if they become the victim of a deepfake?

The victim should preserve evidence, document where the content appears, assess the applicable legal framework and consider appropriate platform, civil or law-enforcement remedies.

Conclusion

Deepfakes have changed the relationship between digital identity and evidence.

A person's face can be reproduced.

A person's voice can be cloned.

A fictional event can be made to appear real.

And content that never existed can circulate globally within minutes.

The law is therefore moving beyond the question of whether synthetic media is technically possible.

The more important question is:

What legal consequences should follow when synthetic media causes harm?

There is no single answer.

Defamation law can address false statements.

Privacy law can address misuse of personal information.

Publicity rights can protect commercial use of identity.

Copyright law can address protected source material.

Criminal law can address fraud, harassment and other unlawful conduct.

Consumer-protection law can address deceptive commercial practices.

And AI-specific regulation is increasingly imposing transparency requirements.

The European Union's approach is particularly significant in this respect.

From 2 August 2026, Article 50 of the EU AI Act introduced transparency obligations for certain AI systems and content. The European Commission specifically identifies deepfakes as requiring disclosure under the applicable framework and also addresses machine-readable marking of certain synthetic content. :contentReference[oaicite:13]{index=13}

The EU's 2026 Code of Practice provides practical measures for providers and deployers to help demonstrate compliance with those obligations. The Commission and AI Board have assessed the Code as an adequate voluntary compliance instrument, while clarifying that signing it is not conclusive evidence of compliance. :contentReference[oaicite:14]{index=14}

The United States has also moved toward targeted federal regulation of harmful deepfakes.

The TAKE IT DOWN Act, enacted on 19 May 2025, specifically addresses the non-consensual publication of intimate visual depictions, including computer-generated digital forgeries. :contentReference[oaicite:15]{index=15}

These developments demonstrate an important trend.

Deepfake regulation is unlikely to develop through one universal “deepfake law”.

Instead, legal protection will increasingly come from multiple overlapping frameworks.

  • AI regulation.
  • Privacy law.
  • Defamation.
  • Intellectual property.
  • Criminal law.
  • Consumer protection.
  • Cybersecurity law.
  • Platform regulation.

For businesses, the practical response should therefore be broader than simply installing a deepfake detector.

Organisations should establish rules for synthetic media creation, identity use, consent, copyright, disclosure, security and incident response.

They should also assume that audio and video can no longer be treated as automatically authentic merely because they appear convincing.

The central legal challenge of the deepfake era is not simply proving that something is fake. It is determining who is responsible when synthetic content becomes indistinguishable from reality and causes real-world harm.

Legal Disclaimer

This article is provided for general educational and informational purposes only. It is not legal, regulatory, privacy, intellectual-property, cybersecurity or litigation advice and does not create an attorney-client relationship. Deepfake laws differ significantly between jurisdictions and continue to develop. Readers should obtain jurisdiction-specific legal advice before relying on this information.

Advertisement
Ad slot — configure in AdSense
Sponsored Content

Topics

deepfake lawdeepfakes and the lawdeepfake legal issuesdeepfake laws 2026AI deepfake lawsdeepfake regulationdeepfake legal consequencesAI-generated images lawAI-generated videos lawdeepfake liabilitydeepfake legislationnon-consensual deepfakesdeepfake privacy law
Advertisement
Ad slot — configure in AdSense
Advertisement
Ad slot — configure in AdSense