pt

45.153.101.73

Back
Blogs

Deepfake Laws Explained: Global Regulations and Legal Risks

Deepfake Laws Explained: Global Regulations and Legal Risks
Huma ZahraHuma Zahra MAY 27, 2026 20 minutes read

Deepfake laws create two duties, one to label the AI content you produce and one to detect the AI content sent to you. Here is what each regime requires in 2026.

For as long as there have been documents worth faking, the law has known how to think about forgery. The test was always the artefact itself, a signature whose pressure was wrong, a seal that had been lifted and reapplied, a photograph whose retouching showed under a lens. What generative models changed is not the quality of the fake but the absence of the thing it was faked from.

 A synthetic face lacks the originality to be held against, which is why legislators spent the last three years writing rules that ask a different question. Instead of asking whether media has been altered, the new statutes ask whether anyone told you it was made by a machine, and whether you were in a position to find out for yourself.

This shift carries a price. Shufti’s own fraud-attempt data, drawn from verification traffic across 2025 and early 2026, projects deepfake-powered identity fraud to rise 495% in 2026 over 2025. Regulators reached the same conclusion by a different route, and the instruments they produced are no longer proposals. 

What are deepfake laws, and what do they actually regulate?

Deepfake laws are statutes and regulatory rules governing the creation, distribution, labelling and detection of AI-generated synthetic media that depicts real or realistically plausible people, objects, places or events. They sit across three older bodies of law rather than forming a single field of their own, borrowing from AI regulation, from data protection, and from criminal fraud. Understanding the technical mechanics of how deepfakes work is useful before reading the legal landscape, because most of the drafting choices follow from what the technology can and cannot do.

The two duties every Deepfake Law Creates

Almost every deepfake regime in force today can be reduced to one of two obligations, and the distinction is more useful to a compliance team than any country-by-country list, because the two duties fall on different departments and are evidenced in completely different ways.

  1. The disclosure duty: This governs the AI content your organisation produces. Where you generate or manipulate synthetic media, you must label it so that an ordinary person can tell it was made by a machine. The duty falls on marketing, communications and product teams, and it is evidenced through provenance metadata, visible labels and asset audit trails.
  2. The detection duty: This governs the AI content other people send to you. Where a synthetic face, voice, or document is submitted into your onboarding or authentication flow, you are expected to catch it. The duty falls on compliance and fraud teams, and it is evidenced through control design, model performance, and case records.

The gap between the two is where most organisations currently sit. The disclosure duty is written in plain terms in statute, whereas the detection duty is usually implied by supervisory expectation rather than spelled out, which makes it easier to miss and considerably harder to demonstrate after the fact.

Why “is it a deepfake” became a legal test rather than a technical one

The European Union’s definition is the one most likely to be copied elsewhere, and it is worth reading closely because it is broader than the popular usage. Article 3(60) of the AI Act defines a deepfake as AI-generated or manipulated image, audio or video content “that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.”

The definition reaches objects, places and events, not only human faces. Further, the European Commission’s own guidance frames the third limb of the test as the content’s capacity to mislead a person about its authenticity, rather than as anything turning on what the deployer meant to achieve. A marketing video with a synthetically generated office that never existed is therefore capable of meeting the test, even though nobody involved intended to mislead anyone.

Deepfake laws by country: how the major regimes compare

Deepfake laws by country differ in what they target, who they bind, and how hard they bite. Some jurisdictions have concentrated on criminal liability for harmful content, others on civil disclosure duties for commercial media, and a small group has written technical labelling standards directly into regulation. What they share is direction of travel. The table below sets out the instruments that were in force as of August 2026, and it is deliberately limited to laws that have actually commenced.

Jurisdiction Instrument In force Core duty Maximum exposure
European Union AI Act, Article 50 2 Aug 2026 Deployers disclose deepfake content; providers mark synthetic output machine-readably €15m or 3% of worldwide turnover, whichever is higher
United States TAKE IT DOWN Act (Pub. L. 119-12) 19 May 2025, platform duties 19 May 2026 Platforms remove non-consensual intimate imagery within 48 hours $53,088 per violation
United States FTC Rule on Impersonation of Government and Businesses, 16 CFR Part 461 1 Apr 2024 Do not falsely pose as a business or its officers $53,088 per violation, plus consumer redress
United Kingdom Data (Use and Access) Act 2025, s.138 6 Feb 2026 Criminalises creating a purported intimate image of an adult Summary offence, currently up to 6 months
United Kingdom Online Safety Act 2023 Codes in force 17 Mar 2025 Platforms assess and mitigate illegal content risk £18m or 10% of qualifying worldwide revenue
China Deep Synthesis Provisions 10 Jan 2023 Consent for likeness, conspicuous labelling, real-name verification Administrative penalties, service suspension
China Measures for Labelling AI-Generated Synthetic Content 1 Sep 2025 Explicit user-visible labels plus implicit metadata labels Administrative penalties, service suspension
South Korea AI Framework Act 22 Jan 2026 Notify users where output is difficult to distinguish from reality KRW 30m administrative fine
India IT Amendment Rules 2026, G.S.R. 120(E) 20 Feb 2026 Prominent labelling of synthetic content, tiered takedowns from 2 hours Loss of intermediary safe harbour
Australia Criminal Code Amendment (Deepfake Sexual Material) Act 2024 3 Sep 2024 Criminalises non-consensual transmission of sexual material, including AI-generated 6 years, 7 years aggravated
Singapore Elections (Integrity of Online Advertising) (Amendment) Act 2024 22 Jan 2025 Bans realistic depictions of candidates during the election period Fine, imprisonment, or both

The EU, China and India set the labelling floor

Three regimes now require synthetic content to be labelled as a matter of general application rather than in a single harm category, and between them they cover a very large share of the world’s internet users. China moved first and remains the most prescriptive. Its Deep Synthesis Provisions have required consent before a person’s face or voice is edited, conspicuous labelling where content could mislead the public, and real-name verification of publishing users since January 2023. The Measures for Labelling AI-Generated Synthetic Content then added a two-tier scheme from 1 September 2025, under which an explicit label must be perceivable by the user, and an implicit label must sit in the file metadata carrying the provider’s identifier and a content reference number.

India followed a comparable structure in 2026. The amendments notified as G.S.R. 120(E) create a category of “synthetically generated information” and require it to be labelled with prominent visibility, or through a prefixed audio disclosure where the content is audio, alongside permanent provenance metadata where that is technically feasible. It is worth noting that the takedown timelines run in four tiers, from seven days for general grievances down to two hours for content depicting nudity, impersonation or artificially morphed images, and those duties fall on all intermediaries rather than only the large platforms.

The UK and South Korea criminalise creation, not only sharing

A smaller group of jurisdictions has crossed a line that most have not, which is to attach criminal liability to the act of making synthetic media rather than to the act of publishing it. Section 138 of the Data (Use and Access) Act 2025 came into force on 6 February 2026 and inserted new offences into the Sexual Offences Act 2003 covering the creation of, and requests for the creation of, a purported intimate image of an adult. The statutory language is instructive for anyone drafting policy, because it defines a purported intimate image as one which appears to be a photograph of the person “but is not, or is not only” a photograph of them, which is as close as UK law comes to naming a deepfake outright. Both offences are summary-only and carry a reasonable-excuse defence, so the practical exposure is narrower than the headlines suggested.

South Korea reached a similar position through its 2024 amendments to sexual violence legislation, which removed the requirement to prove an intent to distribute and extended liability to purchasing, saving, possessing or viewing sexually explicit deepfakes. Separately, the Korean National Election Commission has enforced a ban on deepfake campaign material in the ninety days before polling since January 2024.

Where deepfake law is still a bill

Three widely reported initiatives had not become law as of August 2026, and they are worth separating out because they are frequently described as though they had. Denmark’s proposal to extend copyright-style protection to a person’s likeness and voice was notified to the European Commission in October 2025 and was expected to enter into force in July 2026, but the snap general election in March 2026 appears to have delayed the vote, and no adoption has been confirmed. Spain’s organic law on the good use and governance of AI was approved by the Council of Ministers on 26 May 2026, presented to Congress two days later, and remains in parliamentary passage, and its headline €35m ceiling attaches to prohibited practices such as non-consensual sexual deepfakes rather than to labelling failures generally. Brazil’s PL 2338/2023 passed the Senate in December 2024 and is still pending in the Chamber of Deputies, although the electoral rules issued by the Superior Electoral Court in February 2024 are separately in force.

Timeline of deepfake law compliance datesWhat deepfake laws apply to businesses in the United States?

The United States has no general federal deepfake statute, and the single most common mistake in this area is assuming otherwise. What exists instead is one narrow criminal and platform statute, one technology-neutral trade rule that turns out to do most of the work, a supervisory alert aimed at financial institutions, and a large and uneven body of state law.

The federal layer is narrower than it looks

The TAKE IT DOWN Act is the only enacted federal deepfake statute. Signed on 19 May 2025, its criminal provisions applied immediately, and its platform obligations commenced exactly one year later on 19 May 2026. Covered platforms must operate a notice-and-removal process and take down reported non-consensual intimate imagery, whether real or AI-generated, within 48 hours, along with known identical copies. The Federal Trade Commission enforces it, treating a breach as a violation of a rule defining an unfair or deceptive practice, which carries civil penalties of $53,088 per violation. The Commission sent warning letters to fifteen major platforms days before enforcement opened.

Everything else aimed at commercial deepfake fraud remains a bill, although one of them is now moving. The NO FAKES Act of 2026 was advanced to the full Senate by the Judiciary Committee on a unanimous voice vote on 18 June 2026, and it would create a federal property right in a person’s voice and visual likeness, with platform liability for knowingly hosting unauthorised replicas. It has not passed the Senate, and the House has not acted. The Preventing Deep Fake Scams Act, the AI Fraud Deterrence Act and the QUIET Act are all still sitting in committee. Therefore, any statement that federal law now addresses deepfake fraud against businesses is, as of August 2026, incorrect, although the position on likeness rights may change within this Congress.

Deepfake laws by state, and what they actually protect

State legislatures have moved considerably faster than Congress. According to Ballotpedia’s August 2026 tracking, 48 states now have laws addressing sexually explicit deepfakes, 33 have laws addressing political deepfakes, and 244 deepfake bills have been enacted nationwide since 2019. The important qualification for a business audience is that deepfake laws by state overwhelmingly protect identifiable individuals. Very few of them protect institutions, and none of them creates a corporate cause of action for being impersonated as an entity.

State Instrument In force What it protects
Tennessee ELVIS Act, Tenn. Code Ann. §§ 47-25-1101 to 1108 1 Jul 2024 Property right in name, photograph, voice and likeness, and reaches the tools built to clone them
California Civ. Code § 1708.86, as amended by AB 621 1 Jan 2026 Civil claim for non-consensual sexually explicit altered depictions, with public-prosecutor standing
California AI Transparency Act, Bus. & Prof. Code §§ 22757 et seq., as amended by AB 853 2 Aug 2026 Latent provenance disclosures and a free public AI detection tool for large generative AI providers
Texas Penal Code § 21.165 and Civ. Prac. & Rem. Code ch. 98B, both via SB 441 1 Sep 2025 Criminalises deepfake sexual media, and separately imposes a 72-hour civil takedown duty on website operators
Washington RCW 9A.60.045, as amended by SHB 1205 27 Jul 2025 Gross misdemeanour to distribute a “forged digital likeness” with intent to defraud, harass, threaten or intimidate
Pennsylvania Act 35 of 2025 5 Sep 2025 First-degree misdemeanour for forged digital likenesses, rising to a third-degree felony where used to defraud, coerce or steal

The three California statutes people keep getting wrong

California generates most of the confusion in this area, and three corrections are worth making because they circulate widely. AB 2839, the broad election deepfake prohibition, was held facially unconstitutional in Kohls v. Bonta on 29 August 2025 and permanently enjoined as against the plaintiffs, and the court expressly found that no part of it was severable. AB 2655, the platform-facing companion, was separately enjoined in August 2025 on Section 230 preemption grounds rather than on the First Amendment. Both judgments are under a single consolidated appeal to the Ninth Circuit, which was fully briefed by May 2026 and remains undecided, so neither ruling should be treated as final. AB 853, by contrast, is live and unchallenged. It moved the operative date of the California AI Transparency Act to 2 August 2026, so the latent-disclosure and detection-tool duties on large generative AI deepfake providers took effect this month, with platform and device duties following in 2027 and 2028.

What deepfake laws apply to businesses operating in the European Union?

The European Union has the broadest deepfake framework currently in force, and it is the one most likely to reach a business that has no European establishment, because the AI Act applies where output is used in the Union.

What Article 50 requires of you, and from when

Article 50 of the AI Act applies from 2 August 2026 and splits its duties between two roles. If you deploy an AI system to generate or manipulate image, audio or video content that constitutes a deepfake, you must disclose that the content was artificially generated or manipulated, and the European Commission has been explicit that the label must be perceivable by a person without any specialist tool. A hidden watermark or a metadata tag does not discharge the deployer duty. If you provide such a system, Article 50(2) separately requires you to mark its output in a machine-readable format so that it is detectable as synthetic.

Two timing points are routinely missed. The deployer disclosure duty under Article 50(4) has no transition period at all and bites on 2 August 2026. The provider marking duty under Article 50(2) carries a limited grace period, but only for AI systems placed on the market before 2 August 2026, and those providers have until 2 December 2026 to comply. New systems get nothing. Content generated before 2 August 2026 does not have to be labelled retroactively. The Digital Omnibus on AI, which became Regulation (EU) 2026/1744 and entered into force on 27 July 2026, delayed parts of the high-risk regime but left the Article 50 date untouched.

Two carve-outs are narrower than they appear. Where the content forms part of an evidently artistic, creative, satirical or fictional work, the duty is reduced to disclosing the existence of the synthetic content in a manner that does not spoil the work, which is a limitation on how you disclose rather than a licence not to. The law-enforcement exemption applies only where the use is authorised by law to detect, prevent, investigate or prosecute a criminal offence.

What it costs to get this wrong

Article 99(4)(g) of the AI Act names the Article 50 transparency obligations expressly, and sets administrative fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. However, Article 99(6) reverses that calculation for SMEs, start-ups and small mid-cap companies, for whom the applicable figure is whichever is lower. Enforcement sits primarily with national market surveillance authorities rather than with the Commission, which means the practical experience of Article 50 is likely to vary by member state for some time.

The GDPR and DSA layer sitting underneath

Article 50 is not the whole of the European position. A deepfake of a real person will normally involve the processing of personal data, and the European Data Protection Board has confirmed that a generative model fine-tuned on an individual’s voice recordings to mimic that voice involves the processing of personal data. Where the output is used to identify a person uniquely, Article 9 GDPR and its closed list of derogations come into play as well. Separately, the Digital Services Act lists prominent marking of manipulated media among the risk-mitigation measures very large platforms may need to adopt under Article 35(1)(k), with penalties reaching 6% of worldwide turnover, although that provision is an illustrative menu rather than a freestanding labelling mandate.

What laws apply when a deepfake impersonates a company or its employees?

This is the question compliance teams actually ask, and it is the one the deepfake statutes answer least well. Almost every dedicated deepfake law protects natural persons. When a cloned executive voice authorises a payment, or a synthetic support agent collects credentials under your brand, the applicable law is usually older, broader and technology-neutral.

In the United States, a 2024 rule with no AI in it

The operative federal instrument is the FTC’s Rule on Impersonation of Government and Businesses, in force since 1 April 2024. Section 461.3 makes it an unfair or deceptive act to materially and falsely pose, directly or by implication, as a business or an officer of one. The definitional section is what makes it bite, because § 461.1 defines “officer” to include executives, officials, employees, and agents. A synthetic video of a named executive and a fake branded agent therefore both fall inside a rule that never mentions artificial intelligence. Civil penalties run to $53,088 per violation. It is worth noting that the proposed extension of the rule to impersonation of individuals was consulted on but has not been finalised, and that the FTC has no jurisdiction over banks and federal credit unions under section 5(a)(2) of the FTC Act.

Where money moves, the general fraud statutes do the heavier work. Wire fraud under 18 U.S.C. § 1343 is medium-agnostic on its face, reaching any writings, signs, signals, pictures, or sounds, and it already carries an enhancement of up to $1,000,000 and thirty years where the violation affects a financial institution. That existing reach is a large part of why no deepfake-specific fraud statute has been enacted.

In the United Kingdom, the Fraud Act on the face of the statute

A deepfake used to impersonate a company officer falls within section 2 of the Fraud Act 2006 on a straightforward reading. Impersonation is an implied representation under section 2(4), a claim about another person’s state of mind under section 2(3), and section 2(5) makes clear that a representation still counts when submitted to any system or device designed to receive communications, with or without human intervention. The maximum sentence on indictment is ten years. No reported UK case has yet tested that application to synthetic media, and Crown Prosecution Service guidance on the Fraud Act does not address AI-generated content, so the position is best described as statutory analysis rather than settled law.

What none of this does for you

The uncomfortable conclusion is that these instruments punish the attacker after the event and give the impersonated business very little. There is no statutory duty on anyone to detect the impersonation before the payment leaves, and no regime treats the impersonated company as a protected party in its own right. The exposure that follows a successful impersonation attack is therefore commercial and reputational long before it is legal.

What AI deepfake laws expect operationally: the detection duty

The detection duty is the half of the picture that no legislature has written down cleanly, and it is emerging instead through supervisory expectation. For regulated firms, it is already the more demanding of the two.

The supervisory expectations already in force

Four instruments matter more than any statute here. FinCEN’s alert FIN-2024-Alert004, issued on 13 November 2024, sets out nine red flags for deepfake media in customer onboarding, including the use of third-party webcam plugins during live verification and identity photographs inconsistent with other customer data, and asks institutions to tag relevant filings with the key term FIN-2024-DEEPFAKEFRAUD. The alert is advisory rather than binding, which is exactly why it is used as an examination reference. In the United Kingdom, JMLSG Guidance Part I at paragraph 5.3.89 expects firms verifying identity electronically or without physical presence to apply an additional check, and names biometric data, including facial recognition and liveness checks, among the options. The Monetary Authority of Singapore published an information paper on cyber risks associated with deepfakes in September 2025. The Financial Action Task Force published its Horizon Scan on AI and deepfakes on 22 December 2025, tying deepfake circumvention of customer due diligence to Recommendations 10 and 22, and treating Recommendation 15 separately as the risk-assessment obligation that attaches to new technologies.

One correction is worth making here, because it circulates widely in vendor content. The frequently quoted projection that generative AI could push fraud losses to $40 billion by 2027, up from $12.3 billion in 2023, does not come from FATF. It comes from Deloitte’s Center for Financial Services, it covers the United States only, and it sits at the upper end of a modelled range whose conservative path is closer to $22 billion.

Why the control has to survive compression, not only inspection

The composition of the threat explains why generic detection underperforms. In Shufti’s 2025 verification data, synthetic identity accounted for 42.3% of AI-enabled fraud incidents, live video deepfakes 28.1%, face swaps 17.6%, and document deepfakes 11.9%. That spread matters operationally, because a control tuned for one category will not see the others, and the fastest-moving category is the one most firms check least. Document deepfakes are projected to rise nearly 3,892% year over year in 2026, which is roughly a fortyfold increase in a single year and the sharpest movement anywhere in the dataset.

There is a second reason detection fails in production. Media that reaches a verification flow has usually been compressed, re-encoded, screenshotted, or re-uploaded, and each of those steps strips the pixel-level cues that visual-only checks depend on. A control validated on clean laboratory media may therefore perform very differently on the traffic an examiner will eventually ask about.

How Shufti helps compliance teams evidence deepfake controls

Compliance teams are being asked to prove something the statutes never define, which is that their onboarding flow can distinguish a real face from a generated one and can show its working afterwards. The difficulty is that most detection degrades under ordinary media handling, because a file that has been compressed, screenshotted, and re-uploaded loses the surface cues that visual-only checks rely on.

Shufti’s deepfake detection runs standard visual analysis and frequency-domain analysis in parallel, so the generative artefacts that survive compression and re-encoding stay visible to the model even when image quality has degraded. Capture-integrity signals sit alongside that analysis to surface the stream-substitution patterns typical of virtual cameras and emulators, and high-risk attempts route to review with evidence outputs an examiner can read. Shufti holds iBeta Level 3 conformance for passive face liveness, the highest test level iBeta runs under ISO/IEC 30107-3.

See how Shufti evidences a deepfake decision on your own onboarding traffic, then book a 20-minute demo.

Frequently Asked Questions

Q: What are deepfake laws?

Deepfake laws are statutes and regulatory rules governing the creation, distribution, labelling, and detection of AI-generated media depicting real or realistically plausible people and events. They create two duties, one to label synthetic content you produce and one to detect synthetic content submitted to you.

Q: Which countries have specific laws regulating deepfakes?

China, the European Union, the United Kingdom, South Korea, India, Australia, Singapore, and the United States all have deepfake rules in force as of August 2026. Denmark, Spain and Brazil have bills pending. China and the EU impose the broadest general labelling duties.

Q: What legal protection do businesses have against deepfake impersonation?

In the United States, the FTC's impersonation rule at 16 CFR Part 461 applies, because it defines "officer" to include employees and agents. Wire fraud under 18 U.S.C. § 1343 also applies. In the United Kingdom, section 2 of the Fraud Act 2006 covers it on a plain reading.

Disclaimer: The information provided here is for general informational purposes only and should not be treated as legal, regulatory, or business advice. Shufti Pro Limited accepts no liability for decisions or actions taken in reliance on this information.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.