Guide · Updated 2026-06-26
Are Deepfakes Illegal?
A 2026 guide to US, EU and UK deepfake law — plus how to spot one and what to do if you are targeted.
The short answer: sometimes. There is no global ban on deepfakes, but most major jurisdictions have made specific uses criminal — non-consensual intimate imagery, election interference, impersonation fraud — and the list of regulated contexts is growing every year.
United States
The TAKE IT DOWN Act (Public Law 119-12), signed on 19 May 2025, is the first federal statute squarely aimed at deepfakes. It criminalises publishing non-consensual intimate visual depictions — explicitly including AI-generated ones — and forces covered platforms to remove flagged content within 48 hours of a valid notice.
Beyond that, deepfake law is state-level and moving fast: 68 state deepfake bills were signed into law in 2025 alone, on top of more than 100 enacted since 2022. Texas, California, Virginia, New York, Minnesota, Georgia and Florida have laws against non-consensual sexual deepfakes. California, Texas, Michigan and Washington restrict political deepfakes in the days leading up to an election. Tennessee's ELVIS Act extends protection to AI voice clones. Penalties range from misdemeanours to multi-year felonies depending on the state and the harm caused.
European Union
The EU AI Act (Regulation 2024/1689) entered into force in August 2024, but the deepfake-specific transparency obligations in Article 50 apply from 2 August 2026. From that date, anyone publishing synthetic image, audio or video content depicting real people, events or places must clearly label it as artificial. Penalties for non-compliance with transparency obligations can reach up to EUR 15 million or 3% of global annual turnover, whichever is higher.
GDPR applies in parallel: a deepfake of an identifiable person is personal data processing, which usually requires a lawful basis. Several member states (France, Germany, Spain, Denmark) have added national criminal provisions on top.
United Kingdom
Section 138 of the Data (Use and Access) Act 2025 inserts a new offence (s.66E of the Sexual Offences Act 2003) making it a crime to create, or request the creation of, a purported intimate image of an adult without consent. The maximum penalty is two years in prison. Deepfakes used for fraud, harassment or blackmail continue to be prosecuted under existing fraud, malicious-communications and stalking laws.
How to spot a deepfake
Most deepfakes you will encounter in the wild — romance scams, fake crypto endorsements, edited political clips — are not state-of-the-art. They leak the same handful of tells:
- Mismatched lighting between the face and the neck or hair
- Teeth that merge into one block, or shift shape between frames
- Ears, earrings and glasses that warp when the head turns
- Eyes with inconsistent reflections, or that blink in a uniform pattern
- A face that stays unnaturally sharp while the background softens
- Audio that is flat, with no breath sounds and no room reverb
Signs of a low-end deepfake
Cheap deepfakes — the kind shipped by free apps — make several mistakes a forensic detector catches instantly: visible seams at the jawline, lip-sync that is a quarter-second out, flickering when the head turns past 30 degrees, and identical micro-expressions looped every few seconds. If you can see any of these, a tool like TrueFace will return a very high probability of manipulation.
What to do if someone made a deepfake of you
Document first, then report. Save the URL, screenshots with visible timestamps, and (if possible) the original file — platforms move fast and evidence vanishes. In the US, use the TAKE IT DOWN takedown flow on the hosting platform and file a NCMEC CyberTipline report for sexual content. In the EU and UK, report through the platform's illegal-content channel and to local police. A forensic report from TrueFace quantifying the probability that the image is synthetic can support your case — it does not replace legal advice, but it anchors the conversation.
Verify any image in seconds
Upload a photo to the TrueFace scanner for a per-face breakdown of the signals above — frequency artefacts, GAN-inversion error, filter and retouching traces — with a colour-coded verdict. Open the scanner.
Frequently asked questions
Are deepfakes illegal in the United States?
There is no single federal law banning all deepfakes. The TAKE IT DOWN Act (Public Law 119-12), signed on 19 May 2025, criminalises the publication of non-consensual intimate visual depictions — including AI-generated ones — and requires covered platforms to remove flagged content within 48 hours of a valid notice. Outside that category, deepfakes are regulated state by state.
What US states have made deepfakes illegal?
Deepfake legislation is moving fast: 68 state deepfake bills were signed into law in 2025 alone, on top of more than 100 enacted since 2022. Most criminalise non-consensual sexual deepfakes (Texas, California, Virginia, New York, Minnesota, Georgia, Florida and others) or restrict political deepfakes near an election (California, Texas, Michigan, Washington and more). Tennessee's ELVIS Act covers AI voice clones. Penalties range from misdemeanours to felonies with multi-year prison terms.
Are deepfakes illegal in the EU?
The EU AI Act (Regulation 2024/1689) entered into force in August 2024, but the deepfake-specific transparency obligations in Article 50 apply from 2 August 2026. From that date, anyone publishing AI-generated or manipulated image, audio or video content depicting real people, events or places must clearly disclose it as artificial. GDPR also applies — a deepfake of an identifiable person is personal data processing and usually requires a lawful basis.
Are deepfakes illegal in the UK?
Section 138 of the Data (Use and Access) Act 2025 inserts a new offence (s.66E of the Sexual Offences Act 2003) making it a crime to create, or request the creation of, a purported intimate image of an adult without consent — punishable by up to two years in prison. Deepfakes used for fraud, harassment or blackmail continue to be prosecuted under existing fraud, malicious-communications and stalking statutes.
How do you spot a deepfake?
Look for mismatched lighting between the face and the neck, blurry or shifting teeth and ears, inconsistent reflections in the eyes, and a face that stays unnaturally still while the head moves. Audio deepfakes often have flat prosody and no breath sounds. Forensic detectors like TrueFace measure signals the eye cannot — frequency artefacts, GAN-inversion error, compression mismatches inside vs outside the face region.
What are the signs of a low-end deepfake?
Cheap deepfakes show visible seams at the jawline, a face that stays sharp while the background blurs, flickering when the head turns past 30 degrees, teeth that merge into one block, and earrings or glasses that warp between frames. Lip-sync is often a quarter-second out. These are the easiest cases to flag automatically.
What can I do if someone made a deepfake of me?
Document the content (URL, screenshots with timestamps) before reporting. In the US, use the platform's TAKE IT DOWN takedown flow and file a report with NCMEC's CyberTipline for sexual content. In the EU and UK, report to the platform under their illegal-content policies and to local police. Forensic analysis from a tool like TrueFace can support the report by quantifying the probability the image is synthetic.