A deepfake is synthetic media, an image, audio clip, or video, created or altered using AI (typically generative adversarial networks, diffusion models, or voice-cloning systems) to depict a real person doing or saying something they did not do or say. The term spans everything from face-swapped video and cloned voices to fully AI-fabricated "photographs" of real people, and it sits at the center of AI governance because the same generative techniques used for legitimate synthetic media (dubbing, avatars, visual effects) can just as easily produce non-consensual intimate imagery, financial fraud, or disinformation at a speed and scale earlier manipulation tools could not match. Regulators have moved unusually fast: the EU, UK, Australia, and US have each enacted or are enacting deepfake-specific rules within roughly the last two years, and 2026 alone brings a wave of new obligations, an EU content-labelling duty, a first-of-its-kind EU ban on "nudifier" apps, and new US platform takedown requirements. For governance and compliance teams, deepfakes are no longer a hypothetical risk on a slide; they are an active compliance surface with criminal, civil, and platform-liability exposure that varies sharply by jurisdiction and by whether the content is sexual, fraudulent, or simply unlabelled.
Run the free AI Health CheckDeepfake, AI-generated or AI-manipulated synthetic content, audio, image, or video, that depicts real people doing or saying things they did not do or say.
Deepfake governance has accelerated sharply. The EU AI Act's Digital Omnibus inserted a new Article 5 prohibition on AI systems designed to generate non-consensual intimate imagery ('nudifier' apps) and CSAM, effective 2 December 2026, a separate rule from Article 50, whose disclosure duties (including flagging deepfake content) are already in force from 2 August 2026, with only a narrow grace period until 2 December 2026 for generative AI providers already on the market to add machine-readable watermarking. In the UK, the Online Safety Act 2023 criminalises sharing or threatening to share intimate images, deepfakes included, while creating one was separately criminalised by the Data (Use and Access) Act 2025. Australia's Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth) criminalises non-consensual creation or sharing of sexually explicit deepfake images and videos of adults (audio-only content is not covered), alongside the US TAKE IT DOWN Act's liability for distributing non-consensual deepfake intimate content.
Source: EU AI Act, Articles 5 and 50, and Digital Omnibus; UK Online Safety Act 2023 and Data (Use and Access) Act 2025; Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth)
Most deepfakes are produced with one of a handful of generative AI techniques: generative adversarial networks (GANs), where two neural networks compete until the output is convincingly realistic; diffusion models, the same family of models behind modern image generators, adapted to face-swap or fully synthesize a person's likeness; and voice-cloning models, which can reproduce someone's voice from a short audio sample. 'Face swap' and lip-sync tools graft one person's face or mouth movements onto another's body or speech, while text-to-video and text-to-image systems can now generate a realistic scene or 'photograph' of a real person from a written prompt alone, with no source footage required.
A specific and heavily regulated subcategory is the consumer 'nudifier' or 'undress' app: tools built specifically to digitally remove clothing from an uploaded photo of a real person without their consent. Because these apps have no legitimate use case and target real, identifiable individuals, they have become the first category of generative AI system that regulators are moving to ban outright, rather than merely require to be labelled.
Non-consensual intimate imagery (NCII)
AI-generated fake nude or sexual images of real people, often produced by 'nudifier' apps, currently the fastest-moving deepfake legal frontier worldwide.
Financial and identity fraud
Cloned executive voices or video used to authorize fraudulent wire transfers ('CEO fraud'), impersonate customers, or defeat voice/video biometric checks.
Political and civic disinformation
Fabricated statements, speeches, or events attributed to public figures, with particular regulatory concern around elections.
Fabricated evidence and the 'liar's dividend'
Deepfakes let fabricated recordings be introduced as if genuine, while also letting genuine evidence be dismissed as 'probably AI', both complicate legal and journalistic fact-finding.
AI-generated CSAM
Child sexual abuse material generated or altered by AI is treated as an outright prohibition in multiple jurisdictions, including under the EU AI Act's Article 5 ban.
Harassment of private individuals
Deepfakes of classmates, colleagues, or ex-partners used to humiliate, intimidate, or bully, many reported cases involve private individuals rather than celebrities or politicians, though comprehensive victim statistics remain limited.
EU AI Act, Article 50 labelling
Deployers of AI systems generating or manipulating deepfake image, audio, or video content must disclose that it is artificially generated or manipulated. Applies from 2 August 2026, unchanged by the Digital Omnibus.
EU Digital Omnibus, nudifier ban
A new Article 5 prohibition bans AI systems designed to generate non-consensual intimate imagery, alongside CSAM-generating systems. Applies from 2 December 2026, a separate rule from, and later than, Article 50 labelling.
EU Digital Omnibus, watermarking grace period
Generative AI systems already on the market before 2 August 2026 get until 2 December 2026 to implement the Article 50(2) machine-readable watermarking duty, a narrow technical grace period, not a delay to labelling generally.
UK, Online Safety Act 2023 + Data (Use and Access) Act 2025
The OSA criminalizes sharing or threatening to share intimate images that merely 'appear to show' a person, covering deepfakes; the DUA Act 2025 (s.138) separately criminalizes creating a non-consensual deepfake intimate image of an adult.
Australia, Criminal Code Amendment (Deepfake Sexual Material) Act 2024
Federal offence for non-consensually creating or sharing sexually explicit deepfake images or videos of an adult (audio not covered); commenced 3 September 2024.
US, TAKE IT DOWN Act
Signed 19 May 2025. Criminal ban on publishing non-consensual intimate imagery, real or AI-generated, took effect immediately; platform 48-hour notice-and-takedown duties took effect 19 May 2026, with FTC enforcement now underway.
US, NO FAKES Act (pending)
Would create a federal civil right against unauthorized AI replicas of a person's voice or likeness. The Senate Judiciary Committee unanimously advanced the bill (S. 4591) by voice vote on 18 June 2026, sending it toward a full Senate vote; it had not passed as of mid-2026, worth tracking, not yet law.
Track the split EU dates
Calendar 2 August 2026 (Article 50 labelling/disclosure) and 2 December 2026 (nudifier ban plus the watermarking grace-period deadline) as two separate compliance events, not one.
Push vendors on provenance
Ask generative AI vendors whether outputs carry C2PA-style content credentials or comparable machine-readable provenance ahead of the EU watermarking deadlines.
Harden finance and executive workflows
Add out-of-band verification (callback to a known number, code-word protocols) for any payment or credential change requested by voice or video alone, given rising voice-cloning fraud.
Build jurisdiction-aware NCII takedown procedures
Response timelines and legal triggers differ by country, e.g., the US 48-hour platform window under the TAKE IT DOWN Act, so a single global takedown SLA may under- or over-shoot local law.
Is it illegal to make a deepfake?
It depends on the content and the country, there is no blanket ban on deepfake technology itself. Liability attaches mainly where a deepfake is sexual/intimate and non-consensual (already a criminal offence in the UK and Australia, and under the US TAKE IT DOWN Act), used for fraud, or fails a jurisdiction's content-labelling rule. Within the EU, the AI Act's Article 5 'nudifier' ban is a product-level prohibition enforced against system providers (market surveillance, fines) rather than a harmonized criminal offence for an individual's act of creating NCII, that individual criminal liability is being harmonized separately via the 2024 EU directive on combating violence against women (Directive (EU) 2024/1385), which requires member states to criminalize non-consensual sexual deepfakes in national law by 14 June 2027. A consensual deepfake (e.g., a dubbed film performance or an approved digital avatar) is generally lawful.
Does the EU AI Act require deepfakes to be labelled, and from when?
Yes. Article 50(4) of the EU AI Act requires deployers of AI systems that generate or manipulate image, audio, or video deepfakes to disclose that the content is artificially generated or manipulated. This obligation applies from 2 August 2026 and was not delayed by the 2026 Digital Omnibus amendments, though narrow exceptions exist for law enforcement use and clearly-flagged artistic/satirical work.
What is the EU's 'nudifier app' ban and when does it start?
The Digital Omnibus on AI, finalized in mid-2026, inserted a new prohibition into Article 5 of the AI Act banning AI systems specifically designed to generate non-consensual intimate imagery of real people (so-called 'nudifier' or 'undress' apps), alongside a parallel ban on systems generating child sexual abuse material. This prohibition applies from 2 December 2026, separately from Article 50's labelling duties.
What does the US TAKE IT DOWN Act require online platforms to do?
Signed into law on 19 May 2025, the Act made it a federal crime to knowingly publish non-consensual intimate imagery, real or AI-generated, effective immediately. Its Section 3 platform duties, which took effect 19 May 2026 and are now enforced by the FTC, require covered platforms to offer a takedown-request process and remove reported images (and known copies) within 48 hours.
What's the difference between a deepfake and a 'cheapfake'?
A deepfake is produced or altered with AI models (e.g., GANs, diffusion models, or voice-cloning networks) that synthesize new realistic content. A 'cheapfake' (or 'shallowfake') uses simple, non-AI editing, slowing footage down, re-captioning, splicing, or cropping context, to mislead. Both can deceive, but only deepfakes rely on generative AI, which is why AI-specific laws like the EU AI Act target the former.
How can you tell if an image or video is a deepfake?
There is no universally reliable detector: visual artifacts (unnatural blinking, lighting mismatches, lip-sync drift) can be spotted in low-quality fakes but are increasingly absent in state-of-the-art ones. The more durable approach favored by regulators and standards bodies is content provenance, cryptographic labelling of media at the point of capture or generation (e.g., the C2PA standard), rather than after-the-fact detection.
Last reviewed July 2026