Table of contents
Share Post

A deepfake is synthetic audio, video, or image content generated by AI to make a real person appear to say or do something they never did. AI deepfakes create ethical concerns and impersonation risks that go well beyond celebrity face-swaps: fraud, extortion, nonconsensual sexual imagery, and courtroom evidence tampering. This piece breaks down who gets hurt, why voice cloning may be the bigger threat, what US law now covers, and what actually reduces your exposure.

What a Deepfake Actually Is (And Why 2026’s Version Is Harder to Catch)

A deepfake uses generative adversarial networks or diffusion models to map one person’s face, voice, or mannerisms onto media featuring someone else, and the 2026 generation needs far less source material than the tools from five years ago. Early deepfakes required minutes of footage and a render farm. Now a handful of seconds of audio is enough to clone a voice convincingly.

That drop in the cost of entry is the real story. It’s not that deepfakes got scarier looking. It’s that anyone with a laptop and a free app can make one, which is exactly what turned this from a novelty into an impersonation-fraud category the FBI now tracks by name.

The Real Money Loss: Impersonation Fraud Hit $893 Million in a Year

Deepfake-enabled impersonation is now a measured financial crime category, not a hypothetical risk. According to the Federal Bureau of Investigation, the 2025 Internet Crime Report logged 22,364 AI-related complaints totaling close to $893 million in losses, the first year the FBI broke AI out as its own category in 25 years of reporting.

Voice cloning and video impersonation show up across several fraud types in that report: business email compromise, romance scams, and investment fraud among them. A scammer no longer needs to write a convincing email. They can call an employee, sound exactly like the CFO, and ask for an urgent wire transfer.

Here’s the part that should reframe how you think about this: the FBI itself says the real number is almost certainly higher, because AI is only counted when a victim recognizes it was used. Most people who get fooled by a cloned voice never realize what happened.

Voice Cloning Is the Bigger Risk, Not Video

Video deepfakes get the headlines, but voice cloning is the harder one to defend against because it needs so little source material and hits you somewhere you can’t easily verify in the moment. A convincing face-swap video still has to survive scrutiny of lighting, blinking, and lip sync. A cloned voice on a phone call has none of those tells, and most people trust a familiar voice by instinct.

That’s a structural gap, not a training problem. You can teach an employee to look for deepfake video artifacts. You can’t teach them to distrust their own mother’s voice on the phone, which is exactly the scenario grandparent-scam callers exploit.

Every organization that trains staff to “spot the fake video” while leaving phone verification unchanged is solving last year’s problem.

Who Deepfakes Actually Hurt Most

The loudest deepfake stories involve politicians and celebrities, but the largest and most damaging category of deepfake harm is nonconsensual intimate imagery aimed at ordinary women. Sexualized deepfakes made without consent, and voice-cloned scam calls that target elderly relatives, cause more real, sustained harm per incident than any political deepfake has yet caused in the US.

Nonconsensual Intimate Imagery

Deepfake pornography built from social media photos or old videos has become a tool for harassment, extortion, and control, and it disproportionately targets women who never consented to any of it. Victims often have no idea the images exist until someone sends them a link.

Employees and Executives

Business email compromise scams increasingly pair a spoofed email with a cloned voice call to make the request feel verified. That combination is what makes deepfake-assisted BEC harder to catch than the text-only version security teams trained everyone to spot.

Elderly Family Members

Grandparent scams that once relied on a shaky, generic “it’s me, I’m in trouble” phone call now use a cloned voice built from a few seconds of a public social media video. The emotional pressure plus a genuinely familiar voice is what makes older victims send money fast, before anyone checks.

Where US Law Stands in 2026

Two federal actions now define the baseline for deepfake impersonation in the US: the FTC’s impersonation rule and the TAKE IT DOWN Act. Neither is a complete fix, and both leave real gaps.

The FTC Impersonation Rule

The Federal Trade Commission finalized a rule in February 2024 banning impersonation of government agencies and businesses, and separately proposed extending that protection to individuals in response to a wave of AI-driven deepfake and voice-clone fraud complaints. The individual-impersonation expansion would also let the FTC pursue AI platforms that knowingly let their tools be used for impersonation fraud, not just the scammers themselves.

The TAKE IT DOWN Act

Congress passed the TAKE IT DOWN Act in April 2025, and according to the Library of Congress, the President signed it into law on May 19, 2025, criminalizing the nonconsensual publication of intimate images, including AI-generated “digital forgeries.” Covered platforms had until May 19, 2026, to stand up a notice-and-removal process, and enforcement of that requirement is now active.

The State Patchwork

Roughly 46 states now have at least one deepfake-specific law, but coverage is uneven. Some address only sexual imagery, others only election-related content, and a handful cover neither. That gap means the legality of the exact same deepfake can depend entirely on which state the victim lives in.

Content Credentials Won’t Save You (And That’s the Point)

C2PA Content Credentials cryptographically sign a piece of media to show its origin and edit history, but a valid credential proves a file was signed by a specific device or tool, not that the scene it shows ever happened. According to C2PA, the standard is meant to make tampering evident and the provenance of a file verifiable, built on the same digital-signature model that secures HTTPS connections.

That distinction matters more than it sounds. A camera can sign a photo the instant it’s taken, but nothing stops someone from staging a real scene, in front of a real signed camera, that’s still misleading. Provenance answers “who made this and how,” not “is this true.”

The bigger practical problem is preservation. Screenshots strip the credential. Most messaging apps strip it. Most consumer smartphone cameras still don’t sign natively at capture, which means the vast majority of user-generated video and photos in circulation right now carry no credential at all, real or fake.

None of that makes Content Credentials worthless. It makes them one signal among several, not proof by themselves.

A Practical Defense Checklist

You don’t need a forensics lab to cut your exposure to deepfake impersonation. Most of the highest-value defenses are procedural, not technical.

For Individuals

Set a verbal code word with close family members that a scam caller could never guess, and agree to use it for any request involving money or an emergency. Refuse to authorize a wire transfer, gift card purchase, or password reset based on a phone call alone, no matter how familiar the voice sounds. Search your name periodically alongside terms tied to intimate content, since most nonconsensual deepfake victims find out from a third party, not a monitoring service.

For Organizations

Require a second verification channel, not just a callback, before any financial request tied to a voice or video call: a ticket in an existing system, a message on a separate platform, or in-person confirmation for large transfers. Train finance and HR staff specifically on voice-cloning scenarios, since generic phishing training doesn’t cover a convincing phone call. Log which vendors and executives are public enough (interviews, earnings calls, conference talks) to give an attacker enough clean audio to clone, and treat those individuals as higher-risk targets for verification policy.

That last point is the one most security teams miss entirely, and it’s the one deepfake attackers are already using against you.

People Also Ask

Is it illegal to make a deepfake of someone without their consent?

It depends on the content, the platform, and the state. Sexual deepfakes made without consent are now illegal in most US states and, since May 2025, under the federal TAKE IT DOWN Act. Non-sexual impersonation for fraud or defamation can violate existing FTC, publicity-rights, or state impersonation laws even without a deepfake-specific statute.

Can you sue someone for making a deepfake of you?

Yes, in many cases. Depending on your state, you may have claims under right-of-publicity law, defamation, false light invasion of privacy, or a state-specific deepfake statute. Sexual and intimate deepfakes made without consent also carry federal criminal exposure for the creator under the TAKE IT DOWN Act, separate from any civil claim you bring.

How can you tell if a video or voice call is a deepfake?

Look for unnatural blinking, mismatched lighting between a face and its background, and audio that doesn’t quite sync with lip movement in video. For voice calls, there’s often no reliable visual tell at all, which is why verification through a second channel matters more than trying to “spot” a cloned voice in the moment.

Is voice cloning illegal?

Voice cloning itself isn’t banned nationally, but using a cloned voice to defraud, impersonate, or extort someone is illegal under existing wire fraud, impersonation, and state deepfake laws. The FTC’s impersonation rule and proposed individual-impersonation expansion both target this use case directly.

What is the punishment for creating a deepfake?

Penalties vary widely by state and by what the deepfake depicts. Sexual deepfakes of minors carry the harshest penalties, including decades in prison in some states. Nonconsensual sexual deepfakes of adults now carry federal criminal exposure under the TAKE IT DOWN Act, and fraud-related deepfake use can add wire fraud and impersonation charges on top of any state deepfake statute.

FAQs

What’s the difference between a deepfake and a regular edited photo or video?

A regular edit changes existing footage, cropping, filtering, or splicing real clips together. A deepfake uses AI models trained on a person’s face or voice to generate entirely new frames or audio that never existed, making them say or do something with no original footage of that action at all. That’s what makes deepfakes harder to disprove than a traditional edit: there’s no “original, unedited version” to compare against, because the fake content was generated, not modified.

Why do deepfakes disproportionately target women?

The overwhelming majority of nonconsensual deepfake content is sexual imagery of women, built from photos pulled off social media without consent. Researchers tracking this pattern since the earliest deepfake tools in 2017 have found the same skew every year since: women, including private individuals with no public profile, make up most victims. This isn’t an incidental side effect of the technology. It reflects who existing image-based abuse and harassment already targeted before AI made it easier to produce.

Can deepfakes be used as evidence in court?

Courts increasingly face what legal professionals call the “deepfake defense,” where a party challenges authentic video or audio evidence by claiming it could be AI-generated, whether or not it actually is. This cuts both ways: fabricated deepfake evidence can mislead a jury, and the mere existence of deepfake technology gives attorneys a new argument to cast doubt on real footage. Courts are increasingly relying on forensic analysis and content provenance tools to settle these disputes, though no method is universally accepted yet.

Do AI companies bear any legal responsibility for deepfakes made with their tools?

That’s actively being decided. The FTC’s proposed expansion of its impersonation rule would extend liability to AI platforms that knowingly provide tools used for impersonation fraud, not just the individuals who use them. Most major AI image and video generators already restrict impersonation of real people in their terms of service, but enforcement is inconsistent, and open-source tools with no terms of service at all sit outside any platform’s control.

How is C2PA different from AI-generated content detection?

C2PA Content Credentials record where a file came from and what happened to it, cryptographically signed at creation or edit. AI detection tools instead analyze a file after the fact, looking for statistical artifacts that suggest generation. The two approaches solve different problems: provenance tells you who made a file and how, while detection tries to guess whether a file was AI-generated at all, often without any cooperation from the tool that made it. Neither is complete alone, which is why some newsrooms now use both together.

Ahmed UA

A technology journalist with over 13 years of industry experience covering AI, cybersecurity, mobile technology, gadgets, and global tech trends. He founded iCONIFERz in 2019 as a platform dedicated to making technology accessible to everyone — without the jargon. Follow Website, Facebook & LinkedIn.

Stay in the loop

Subscribe to our free newsletter.

You can unsubscribe anytime.

  • The rapid growth of solar and wind power—now accounting for over 15% of global electricity—underscores the urgency of reliable buffering systems. Energy storage technology for renewable sources transforms intermittent generation into dispatchable energy, smoothing out peaks and valleys to stabilize grids, cut costs, and pave the way to a carbon-free future. Yet, with dozens of competing chemistries, mechanical options, and system architectures, choosing the right solution can feel overwhelming. Why Energy Storage Is the Keystone of a 100% Renewable Grid [...]

KEEP READING

Latest Post