Deepfakes in Law: Defamation, Evidence, and Emerging Regulation
AI-generated synthetic media — commonly called deepfakes — have moved from technical curiosity to a genuine legal problem in courts, legislative chambers, and regulatory agencies around the world. The legal system is scrambling to adapt existing doctrines and craft new ones to address the harms these technologies enable.
Defamation and Right of Publicity
Deepfakes depicting real people in false situations raise immediate defamation questions. Traditional defamation law requires proving a false statement of fact that damages reputation — AI-generated video of a public figure saying something they never said fits squarely within this framework. The challenge is often identification and service of process: deepfake creators frequently operate anonymously or from jurisdictions that don't cooperate with civil discovery.
Non-Consensual Intimate Images
AI-generated intimate images of real people have prompted the most rapid legislative response. As of mid-2024, over 40 U.S. states have enacted laws specifically criminalizing non-consensual deepfake intimate images, and the federal DEFIANCE Act created a private right of action in federal court. The UK's Online Safety Act similarly addresses the issue.
Deepfakes as Evidence
Courts are grappling with how to authenticate digital evidence in a world where any video can potentially be fabricated. Federal and state rules of evidence already require authentication as a foundation for admission, but current standards were not designed with AI-generated media in mind. Courts and evidentiary scholars are considering whether specific deepfake authentication standards — including requirements for forensic analysis — are needed.
Defamation Law Applied to Deepfakes
Traditional defamation doctrine applies when a deepfake depicts a real person making statements or engaging in conduct they never did. The plaintiff must establish that the content constitutes a false statement of fact (not opinion), that the defendant published it to third parties, that it damaged the plaintiff's reputation, and — for public figures — that the defendant acted with actual malice (knowledge of falsity or reckless disregard for truth). AI-generated video is not categorically exempt from defamation law; courts in the US, UK, and EU have all applied defamation principles to digitally manipulated media. The practical challenge is often identifying the creator: deepfakes frequently originate anonymously, requiring subpoenas to platforms, hosting providers, or internet service providers to unmask defendants.
Right of Publicity and Personality Rights
Beyond defamation, deepfakes implicate right-of-publicity statutes in US states and personality rights under civil law systems in Europe. Right of publicity protects individuals' control over the commercial use of their name, likeness, and identity. A deepfake that places a celebrity in an advertisement they never agreed to participate in, or a political figure in propaganda they did not create, may give rise to right-of-publicity claims independent of any defamation analysis. Several US states have enacted legislation specifically addressing AI-generated likeness: California's AB 2602 requires consent before an AI-generated digital replica of a performer can be used in creative work.
Authentication Challenges in Evidence Law
The proliferation of deepfakes creates acute challenges for evidence authentication. Federal Rule of Evidence 901 requires a proponent to produce evidence sufficient to support a finding that the item is what the proponent claims. Video evidence has historically been authenticated by testimony from someone with personal knowledge of the recording's accuracy. Courts and commentators are now grappling with whether additional authentication requirements — such as mandatory technical analysis by a qualified expert — are needed for digital video in a deepfake era. The National Institute of Standards and Technology (NIST) is developing evaluation frameworks for deepfake detection tools, and several federal courts have begun allowing expert testimony specifically on deepfake detection methodologies.
EU Regulation: The AI Act and Transparency Obligations
The EU AI Act imposes specific obligations relevant to deepfakes. Article 50 requires deployers of AI systems that generate synthetic audio, image, video, or text content to label outputs as artificially generated in a machine-readable format, and to implement technical solutions enabling the content to be identified as AI-generated. For deepfakes specifically — realistic AI-generated images, audio, or video of real people — disclosure is mandatory unless the content is clearly satirical or artistic in nature. Providers of general-purpose AI models with systemic risk (those trained with over 10^25 FLOPs) face additional obligations, including adversarial testing for disinformation risks.
Criminal Dimensions: Non-Consensual Intimate Imagery
The intersection of deepfake technology and non-consensual intimate imagery has generated the most immediate legislative response. As of mid-2026, the majority of US states have enacted criminal statutes targeting AI-generated intimate deepfakes, and the federal DEFIANCE Act created a private civil right of action for victims. The UK's Online Safety Act 2023 criminalises the sharing of intimate deepfakes without consent, and further criminalisation of creation (not just sharing) is under active consideration in Parliament. These laws typically apply regardless of whether the images depict an actual sexual act — computer-generated images that would appear to a reasonable observer as depicting the victim in a sexual context are covered.
Related reading: AI, Defamation, and Chatbot False Information · EU AI Act Prohibited Practices