Home/Digital Rights/Deepfake & AI Impersonation
Digital Rights & AI

Deepfake and AI Impersonation: What’s Actually Law Right Now

AI likeness law is moving so fast that a lot of coverage blurs "enacted" with "proposed." Here’s what is actually in force today for a fake video, cloned voice, or impersonated identity — and what is still just a bill in Congress or a rule not yet fully applicable.

At a Glance

Enacted
US federal TAKE IT DOWN Act (signed May 2025, platform duty live since May 2026)
Still pending
US federal NO FAKES Act — cleared committee, no final passage confirmed
48 hours
TAKE IT DOWN Act platform takedown deadline for a valid request
Aug 2026
EU AI Act Article 50 deepfake-labeling duty begins applying [verify]

What’s Actually Enacted Today

In the US, the federal TAKE IT DOWN Act was signed into law in May 2025. It criminalizes knowingly publishing non-consensual intimate imagery, including AI-generated or digitally altered ("deepfake") intimate depictions, and requires "covered platforms" (social media, image/video-sharing, messaging, gaming services) to provide a notice-and-removal process that takes down a validly reported image — and known identical copies — within 48 hours of a request. That platform obligation became enforceable by the FTC in May 2026, so as of now it is both enacted and actively being enforced. This is currently the strongest, clearest federal tool for a deepfake intimate-image situation specifically. verify current FTC enforcement activity and any amendments before relying on the exact 48-hour figure

Several US states have also enacted their own right-of-publicity or digital-replica laws that predate and go beyond the federal picture. Tennessee’s ELVIS Act (effective July 2024) was the first state law to add "voice" explicitly to right-of-publicity protection, directly targeting unauthorized AI voice cloning. California enacted AB 1836 (bars unauthorized commercial digital replicas of deceased performers) and AB 2602 (voids certain contract clauses permitting digital-replica use of living performers unless specific conditions are met), both effective January 2025. Separately, roughly 30 US states now have election-specific deepfake disclosure laws — these are narrower, apply only around elections, and do not create a general impersonation remedy; some have even been struck down as unconstitutional (for example, Hawaii’s was permanently enjoined in early 2026).

In the UK, sharing non-consensual intimate images — including deepfakes — has been a criminal offense since the Online Safety Act 2023 inserted new sections into the Sexual Offences Act 2003, in force since January 2024. A separate offense specifically for creating (not just sharing) a sexual deepfake was more recently added via the Data (Use and Access) Act, reported to commence on 6 February 2026 — confirm this has actually taken effect as scheduled before relying on it, since UK commencement dates for this kind of provision can slip. verify current commencement status

What You Can Realistically Pursue

The fastest relief is usually a takedown, not a lawsuit

Platform takedown (fastest route)

A direct platform report, or a formal TAKE IT DOWN Act request for intimate imagery (48-hour statutory deadline for covered platforms), is typically far faster than any court process.

State right-of-publicity/digital-replica claim

Available today in states with enacted laws (e.g., Tennessee’s ELVIS Act, California’s AB 1836/AB 2602) or under general right-of-publicity law in most states, for unauthorized commercial or expressive use of your voice/likeness.

Criminal referral for NCII or large-scale fraud

Non-consensual intimate deepfakes can be referred to local police; AI-enabled scams/impersonation fraud can be reported to the FBI’s IC3 (ic3.gov) or FTC ReportFraud.gov — the FBI’s 2025 data showed a distinct, growing AI-fraud complaint category.

Civil suits are slow and defendants are often hard to reach: Defamation, false-light, and right-of-publicity lawsuits can take months to years, and the person who created or spread a deepfake is frequently anonymous, judgment-proof, or based overseas — a platform takedown or law-enforcement referral is often more practically effective than a civil suit alone.

What’s Still Pending — Don’t Rely on These as Settled Law

The federal NO FAKES Act, which would create a general federal civil right against unauthorized digital voice/visual replicas with statutory damages, remains a bill, not a law, as of this writing — a version cleared the Senate Judiciary Committee in June 2026, but no confirmed full Senate or House passage has occurred. Treat any claim that the NO FAKES Act already gives you a federal right as premature, and check its current status at congress.gov before relying on it.

The EU AI Act’s Article 50 transparency obligation — requiring deployers to disclose that content is artificially generated or manipulated, covering deepfakes — is enacted law (the AI Act entered into force in August 2024), but its application is phased: the deepfake-labeling duty is generally reported to begin applying from 2 August 2026, with some carve-outs for systems already on the market pushed to December 2026. This means the obligation exists on paper but has only just begun (or is about to begin) actually applying as you read this — confirm the current date against the Act’s own application schedule. verify precise application dates, as Commission guidance was still being finalized as of mid-2026

What is already usable today, regardless of AI-specific legislation, are older legal theories: defamation (if the deepfake makes a false, damaging factual claim about you), false light (recognized in many, not all, US states), right of publicity for commercial use of your likeness, and intentional infliction of emotional distress. The EU’s Digital Services Act notice-and-action mechanism (Article 16) is also already in force and lets you flag illegal content — including unlawful deepfakes — to a hosting platform, creating a legal basis for removal or platform liability once the platform has "actual knowledge."

How to Respond, Step by Step

Start with the fastest, most practical route before considering a lawsuit

1

Preserve evidence before requesting removal

Screenshot or save the content, the URL, the account/profile that posted it, and the date you discovered it — platforms and law enforcement will need this even after the content itself comes down.

2

Report directly to the platform first

Most platforms have a direct reporting tool that is faster than any formal legal process. For non-consensual intimate imagery, you can also invoke the federal TAKE IT DOWN Act’s notice-and-removal process, which requires a covered platform to act within 48 hours of a valid request.

3

For intimate-image deepfakes, consider a police report

Non-consensual intimate imagery, including AI-generated depictions, is a federal crime under the TAKE IT DOWN Act and, in the UK, a criminal offense under the Online Safety Act 2023 amendments — a police report can support both takedown and prosecution.

4

For scam/fraud impersonation (voice clones, fake executive/family requests), report to fraud authorities

In the US, report to the FTC at ReportFraud.ftc.gov, and for identity theft specifically, IdentityTheft.gov; larger-scale or financial fraud can go to the FBI’s Internet Crime Complaint Center (ic3.gov).

5

Consider a civil claim only after exhausting faster options, or where money damages matter to you

Defamation, false light, right of publicity, or a state digital-replica statute (where enacted) may support a lawsuit, but expect a slow process and real difficulty if the poster is anonymous or overseas — get advice on whether it’s worth pursuing given your specific facts.

Documents to gather

  • Screenshots/saved copies of the content and its URL
  • The account/profile name and platform where it was posted
  • Any messages, comments, or evidence of who created or shared it
  • A record of when you discovered it and any prior reports you made

Timelines and Limitation Periods

Takedown deadlines are fast; underlying civil claims follow ordinary state/national limitation periods

Platform-facing deadlines (like the TAKE IT DOWN Act’s 48-hour window) are separate from — and much shorter than — the statute of limitations for any civil lawsuit you might later bring over the same content.

JurisdictionLimitation Period
US — TAKE IT DOWN Act platform removal48 hours from a valid removal request to covered platforms
US — defamation/false-light/right-of-publicity claimsVaries by state, commonly 1–3 years verify your specific state
EU — AI Act Article 50 labeling dutyApplication generally begins 2 August 2026, with some obligations delayed to December 2026 verify current status
UK — Online Safety Act NCII sharing offenseCriminal offense, no civil limitation period as such — report to police to trigger prosecution

Realistic Outcomes and Caveats

A platform takedown, especially under the TAKE IT DOWN Act’s 48-hour rule for intimate imagery, is currently the fastest and most reliable relief available — faster than any state or federal civil lawsuit.

Criminal referral can lead to prosecution for non-consensual intimate deepfakes or large-scale fraud, but outcomes depend on whether the perpetrator can be identified and located — many deepfake creators use anonymizing tools or operate from outside your country.

A civil lawsuit can produce money damages under existing defamation/false-light/right-of-publicity theories or a state digital-replica statute, but expect it to be slow, and be realistic that judgment against an anonymous or overseas defendant may be hard to actually collect.

Common Pitfalls

Assuming the NO FAKES Act already protects you

As of this writing it is still a pending federal bill, not enacted law — don’t rely on it for a current claim.

Assuming EU AI Act labeling requirements are already fully in effect everywhere

Article 50’s deepfake-disclosure duty only began applying around August 2026, with some obligations delayed further — check the current application date before assuming full enforcement.

Deleting evidence before reporting

Save screenshots, URLs, and account details before requesting a takedown — once content is removed, you may lose the evidence needed for a later legal or law-enforcement process.

Expecting a fast, cheap civil win against an anonymous poster

Identifying and serving an anonymous or overseas defendant is often the hardest part of a deepfake lawsuit — a platform takedown or law-enforcement referral is frequently more realistic.

Not distinguishing sharing from creating in UK law

The UK criminalized sharing non-consensual intimate deepfakes first (2024); a separate creation offense followed later — confirm which offense applies to your specific facts and its current commencement status.

Organize Your Deepfake Impersonation Case

Use the calculator to document the content, platform, and any reports you’ve already made before deciding on next steps.

Organize Your Deepfake Impersonation Case

Use the calculator to document the content, platform, and any reports you’ve already made before deciding on next steps.

This stays in your private workspace until you choose a next step.

This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.

Official and Legal References

Fragmented Everywhere — Check What’s Actually in Force in Your Country

No country currently has a single, comprehensive "deepfake law." The US has one specific federal law (TAKE IT DOWN Act, intimate imagery only) plus a patchwork of state right-of-publicity statutes, with a broader federal bill (NO FAKES Act) still pending. The EU has a phased-in transparency/labeling duty (AI Act Article 50) plus the already-active DSA notice-and-action mechanism, but no EU-wide compensation right specific to deepfakes. The UK has criminalized sharing (and, very recently, creating) sexual deepfakes, but this doesn’t cover non-sexual impersonation or fraud, which fall back on ordinary criminal and civil law. Check what’s actually enacted and in force in your specific country before assuming a general "deepfake law" protects you.

Frequently Asked Questions

Real edge cases, answered in plain language

Someone made a fake video using my face — is there a federal law against this in the US?

Does the EU AI Act stop people from making deepfakes of me?

I was scammed by a cloned voice pretending to be a family member — what do I do?

This page provides general information about deepfake and AI impersonation law as of July 2026, an area that is changing extremely quickly. It is not legal advice. Some laws described here (particularly the US NO FAKES Act and EU AI Act application dates) may have changed since this was written — confirm current status at congress.gov, eur-lex.europa.eu, or with a qualified professional before relying on anything here.

Organize Your Deepfake Impersonation Case

Use the calculator to document the content, platform, and any reports you’ve already made before deciding on next steps.

Organize My Case