Deepfakes and the Future of AI Legislation Ethical and Legal Challenges

Deepfakes and the Future of AI Legislation: Ethical and Legal Challenges

Updated: July 2026

The advent of AI has brought about tools that are reshaping how we interact with technology and information. Among these advancements, deepfakes stand out as one of the most intriguing yet controversial developments. By using machine learning techniques such as deep neural networks, deepfakes enable the creation of highly realistic fake videos, audio, and images that replicate people’s appearances and voices with remarkable precision.

What began as a technological novelty has quickly evolved into a phenomenon with profound implications. While deepfake technology holds real potential in areas such as entertainment, education, and the creative industries, it also poses significant risks. From doctored celebrity videos to fabricated political statements, the misuse of this technology is eroding trust in media and public discourse.

As deepfakes become more sophisticated and accessible, their potential for abuse has sparked debates over ethical considerations and legal accountability. The key challenge lies in drawing on the positive potential of deepfake technology while minimising its harmful impacts.

What are deepfakes?

Deepfakes are synthetic media created using AI, particularly through techniques like deep learning and generative adversarial networks (GANs). They produce highly realistic images, videos, or audio that mimic the appearance and voice of real people.

Originally developed for creative purposes, such as improving film production or creating digital characters, deepfake technology has become increasingly accessible. Today, even basic technical skills and free tools can generate convincing deepfakes.

While this opens doors for creativity and entertainment, it also raises serious concerns about privacy, trust, and the authenticity of information.

How are deepfakes being misused?

While deepfakes hold promise in creative industries, their misuse poses significant challenges. The technology has been weaponised in various ways, threatening individuals, organisations, and societal trust.

How do deepfakes spread misinformation?

Deepfakes have become a powerful tool for spreading misinformation. By creating fake videos of public figures making false statements, they can manipulate public opinion, disrupt elections, or incite conflict. Their realism makes it harder for people to discern truth from fiction, eroding trust in news and media.

How do deepfakes enable harassment and privacy violations?

Deepfakes are often exploited for malicious purposes, such as creating non-consensual explicit content. This has disproportionately targeted women, violating their privacy and causing emotional harm. Deepfakes have also been used in blackmail schemes, impersonation scams, and to defraud businesses.

The accessibility of deepfake tools exacerbates these problems, allowing malicious actors to create and disseminate harmful content with ease. The resulting damage, whether reputational, emotional, or financial, shows the urgent need for ethical and legal safeguards.

Key requirements for AI safety

What ethical challenges do deepfakes create?

Deepfakes present profound ethical challenges that extend beyond their technical capabilities. These issues impact trust, privacy, and societal values, raising questions about how we live in a world where reality can be so easily manipulated.

How do deepfakes undermine trust in media?

Deepfakes erode trust in media by making it increasingly difficult to distinguish between authentic and fabricated content. This undermines the credibility of legitimate news and widens the spread of disinformation. As people become more sceptical of what they see and hear, the broader trust in digital communication and public discourse is at risk.

What is the societal impact of deepfakes on vulnerable groups?

The misuse of deepfake technology often targets vulnerable groups, particularly women and minorities. Non-consensual explicit deepfake content has become a tool for harassment and exploitation, disproportionately affecting women. Similarly, the technology can be used to impersonate or defame individuals, exacerbating existing inequalities and power imbalances.

The ethical dilemma lies in striking a balance between innovation and accountability. While the potential for deepfakes in art, education, and entertainment is undeniable, their misuse demands a good framework of ethical guidelines and public awareness.

What legal challenges and regulatory efforts surround deepfakes?

The rapid proliferation of deepfake technology has outpaced the development of legal frameworks needed to address its misuse. While some countries have begun to introduce regulations, significant gaps remain in efforts to address the global challenges posed by deepfakes.

What existing laws apply to deepfakes, and where do they fall short?

Current legal systems often rely on traditional frameworks, such as:

Defamation/Libel Laws: These can be used if a deepfake makes false statements that damage someone’s reputation. However, proving intent to harm can be difficult.

Copyright Infringement: If a deepfake uses copyrighted material (e.g., footage from a movie), copyright laws may apply. But this doesn’t address the core harm of misrepresentation.

Privacy Laws: These can be relevant if a deepfake uses someone’s likeness without consent, but often don’t fully cover the emotional distress or broader societal impact.

Cybersecurity Laws: These might address the use of deepfakes in phishing scams or other online fraud, but not the broader issue of misinformation.

However, these laws are often insufficient to address the unique challenges posed by deepfakes, such as their anonymity, global reach, and the potential to cause widespread harm before they are identified as fake. They were not specifically designed for deepfakes and often fail to fully address the unique harms they cause. Proving direct, measurable harm from a deepfake can also be difficult, particularly in cases involving misinformation. Enforcement presents another challenge: the internet’s global nature makes it hard to enforce national laws against deepfakes created or hosted in other countries.

How does China regulate deepfakes under the PIPL?

China has taken early steps to regulate deepfake technology under its Personal Information Protection Law (PIPL). The law requires explicit consent before an individual’s image, voice, or personal data can be used in synthetic media. The regulation targets identity theft, privacy violations, and reputational harm caused by deepfakes.

In addition to the PIPL, China has implemented new rules that mandate the labelling of deepfake content, helping users identify manipulated media. These measures serve as an example of how targeted legislation can mitigate the ethical and legal risks associated with deepfakes.

Under the “Deep Synthesis Provisions,” which took effect in January 2023, deepfake service providers are required to identify users and review their content. This added layer of regulation imposes further obligations on those who create and distribute deepfake media, reinforcing China’s commitment to tackling the challenges posed by this technology.

What global trends in AI legislation address deepfakes?

Globally, there is growing recognition of the need for AI-specific legislation, and governments are starting to address the challenges posed by deepfakes, with varying degrees of regulation:

The EU has been a forerunner in AI and digital media regulation with the Artificial Intelligence Act (AI Act) and the Digital Services Act (DSA). The AI Act outlines specific requirements for high-risk AI systems, which may encompass deepfake technology. It also requires disclosure that content is AI-generated. The DSA includes provisions to address harmful content online, though deepfakes are not specifically mentioned. Efforts are underway to add provisions that address the manipulation of media through AI.

The US has a patchwork of state laws addressing specific deepfake harms. There have also been federal bills proposed, such as the DEEP FAKES Accountability Act, but none have yet passed. There is no comprehensive federal legislation specifically targeting deepfakes, and various states, such as California, have implemented laws criminalising the creation and distribution of deepfakes with the intent to harm individuals, especially in cases involving pornography and election interference.

The UK has taken a more cautious approach but has recognised the potential for deepfakes to cause significant harm. The Online Safety Bill includes provisions that require platforms to take responsibility for harmful content, including deepfakes. However, there is still no specific regulation directly addressing deepfakes in the UK.

Australia has incorporated deepfake technology into its Media and Communications Laws, focusing on defamation and privacy. The government has also proposed a broader review of media regulation in the context of emerging technologies, which could lead to more targeted efforts against deepfakes.

Other Countries: Many other countries are in the early stages of developing AI strategies and regulations, with deepfakes being a key concern.

Given the borderless nature of the internet, international cooperation is key in regulating deepfakes. Organisations such as the United Nations and OECD are exploring frameworks for global regulation, though no universally adopted standards currently exist.

While existing laws provide some recourse against the harms of deepfakes, there is a growing trend towards specific AI legislation that directly addresses the unique challenges posed by this technology. The approaches vary across the globe, but common themes include disclosure requirements, focus on harm, and risk-based regulation. Addressing deepfakes requires a balance between encouraging innovation and protecting individuals and society from harm. While some progress has been made, much remains to be done to establish comprehensive, enforceable regulations. Effective regulation will require a combination of legal, technical, and educational efforts.

Why does deepfake regulation matter for companies?

The rise of deepfakes shows the broad potential of AI technologies for both beneficial and harmful applications. For companies, addressing the risks posed by deepfakes is both an ethical and a strategic matter. Businesses must be aware of the potential risks posed by deepfakes, including reputational damage, erosion of consumer trust, and legal liabilities. At the same time, they can responsibly harness the technology’s creative potential to drive competitiveness.

To reduce the risks and capitalise on the opportunities, companies must fulfil several key requirements:

By addressing these requirements, companies protect themselves from potential risks and demonstrate leadership in ethical AI practices. In doing so, they strengthen trust with stakeholders, build a culture of responsible innovation, and contribute to a future where AI serves beneficial ends.

How should deepfake innovation and regulation be balanced?

As deepfake technology evolves, striking a balance between its potential benefits and risks is essential. Achieving this requires coordinated efforts from policymakers, technologists, and the public.

Encouraging ethical innovation involves promoting positive applications in education, healthcare, and entertainment while discouraging malicious uses. Governments must strengthen regulations by mandating the labelling of synthetic media, enforcing consent requirements, and addressing cross-border challenges through international cooperation.

Public awareness and media literacy also matter in combating manipulation, enabling individuals to identify and question suspicious content. Investing in AI-powered detection tools can bolster trust in digital content by helping stay ahead of malicious actors.

Conclusion

Deepfakes offer real creative possibilities, but their potential for harm is serious. Addressing the challenges posed by deepfakes requires integrating ethical considerations, robust legal frameworks, and technological solutions.

With collective action and well-directed measures, a safer approach to AI is within reach. Deepfakes are a reminder that technology is only as beneficial as the values guiding its use.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

Frequently Asked Questions

Do existing laws protect people from deepfake harm?

Only partially. Laws covering defamation, copyright, and privacy can apply in some cases, but they were not designed for deepfakes and often fail to address the full extent of the harm. Proving intent, identifying anonymous creators, and enforcing judgments across borders all present significant obstacles.

Why are women disproportionately affected by deepfakes?

Non-consensual explicit deepfake content targets women far more than any other group, turning the technology into a tool for harassment, blackmail, and reputational damage. The accessibility of free deepfake tools has made this type of abuse easier to carry out and harder to contain once content has been shared.

Does the EU AI Act ban deepfakes?

No, but it does require disclosure. The AI Act mandates that AI-generated or manipulated content be labelled so audiences know it is synthetic. It does not prohibit deepfakes outright, though high-risk uses may face additional scrutiny under its tiered framework for AI systems.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.