Deepfake Fraud and Impersonation Laws: Federal and State (2026)
Independently fact-checked against primary sources (last audited September 24, 2026). · 43 primary sources cited on this page. How we verify our legal content

As of September 2026, using a deepfake (an AI-generated or AI-altered voice, video or image of a real person) to trick someone out of money is a crime everywhere in the United States, because federal and state fraud laws punish the scheme no matter what tool was used to carry it out. On top of that general layer, at least five states have passed crimes aimed at AI impersonation itself, including New Jersey, New Hampshire, Arizona, Washington and Pennsylvania, with Utah adding an AI culpability rule and AI coverage in its fake-endorsement law. No federal statute yet treats AI-assisted fraud as a separate crime; the bills that would do so are pending in Congress.
This article covers deepfakes used for fraud, impersonation and extortion under federal law and the state statutes listed below. It does not cover sexual deepfakes, election deepfakes or right-of-publicity claims, which are covered on the deepfake laws by state hub. For scam phone calls that use a cloned voice, including robocall rules, the FCC's AI voice ruling and where to report a call, see are AI voice scam calls illegal.
Is It Illegal to Use a Deepfake to Scam or Impersonate Someone?
Yes. Fraud laws punish the lie and the loss, not the technology. A scammer who uses a cloned voice of a grandchild, a fake video call from a company executive, or an AI-generated celebrity endorsement to get money is committing fraud in the same way as one who uses a disguise or a forged letter.

The FBI put the distinction plainly in a December 2024 public service announcement: "The creation or distribution of synthetic content is not inherently illegal; however, synthetic content can be used to facilitate crimes, such as fraud and extortion." That is the line this article follows. Making a deepfake is not, by itself, a crime under the federal laws below. Using one to defraud, extort or impersonate someone can be.
What the new state laws add is AI-specific wording. Some make the deepfake itself a separate offense, some grade AI impersonation more severely, and some give the person who was faked a civil claim. Where no such law exists, prosecutors charge the underlying fraud.
The FBI's announcement (Alert Number I-120324-PSA) describes the common patterns: short audio clips of "a loved one's voice to impersonate a close relative in a crisis situation," AI video used "for real time video chats with alleged company executives, law enforcement, or other authority figures," and AI videos used for "fictitious or misleading promotional materials for investment fraud schemes."
The Federal Laws That Reach Deepfake Fraud
Federal prosecutors do not need an AI statute to charge a deepfake scam. The following laws apply to the conduct regardless of how the deception was produced.
| Federal law | What it covers | Maximum penalty |
|---|---|---|
| 18 U.S.C. § 1343 (wire fraud) | A scheme to defraud carried out by wire, radio or television communication in interstate or foreign commerce | Fine, up to 20 years, or both; up to $1,000,000 and 30 years if it affects a financial institution or involves disaster benefits |
| 18 U.S.C. § 1028A (aggravated identity theft) | Using another person's means of identification during a listed felony, including wire fraud | Mandatory 2 years, served consecutively |
| 18 U.S.C. § 875(d) (interstate extortion) | An interstate threat to injure property or reputation, sent with intent to extort | Fine, up to 2 years, or both |
| 18 U.S.C. § 912 (impersonating a federal officer) | Pretending to be a federal officer or employee and acting as one, or demanding or obtaining money or anything of value | Fine, up to 3 years, or both |
| 16 CFR Part 461 (FTC Impersonation Rule) | Materially and falsely posing as a government entity or business, or their officers | Civil enforcement by the FTC |
Wire fraud
Section 1343 reaches anyone who, having devised a scheme to defraud or to obtain money by false pretenses, "transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme." A deepfake video call, voice message or AI-generated image sent across state lines is a picture or sound transmitted by wire. The statute contains no AI-specific language, and it does not need any.
Aggravated identity theft
Section 1028A adds a mandatory 2-year prison term when someone "knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person" during a listed felony, and wire fraud is on the list. The term cannot run concurrently with the fraud sentence.
How far this reaches a deepfake is an open question. The definition of "means of identification" in 18 U.S.C. § 1028(d)(7) includes a name and "unique biometric data, such as fingerprint, voice print, retina or iris image, or other unique physical representation." A scam that uses the victim's name fits the text. Whether an AI imitation of someone's voice or face is itself a "voice print" or "other unique physical representation" is something the statute does not answer. The AI voice scam calls guide linked above discusses how the Supreme Court has narrowed § 1028A.
Extortion and officer impersonation
Section 875(d) covers a threat, sent in interstate or foreign commerce, "to injure the property or reputation of the addressee or of another" when made "with intent to extort" money or anything of value. A demand for payment backed by a threat to release a fabricated video fits that description. Section 912 covers anyone who "falsely assumes or pretends to be an officer or employee acting under the authority of the United States" and acts as one or, in that pretended role, "demands or obtains any money, paper, document, or thing of value." Neither statute mentions AI, so a deepfaked federal agent is treated like any other impostor. The pending AI Fraud Deterrence Act (H.R. 6306) would add an AI-specific tier to § 912, described below.
The FTC Impersonation Rule
The FTC's Rule on Impersonation of Government and Businesses took effect April 1, 2024. Section 461.2 makes it an unfair or deceptive practice to "materially and falsely pose as, directly or by implication, a government entity or officer thereof," and § 461.3 does the same for "a business or officer thereof." An AI video of a bank officer or a government agent used to sell something or collect money falls within these sections.
The rule does not cover impersonating a private individual. The FTC proposed adding a ban on impersonating individuals in March 2024, and in December 2024 it announced that it would not proceed with the proposal's "means and instrumentalities provision," dropping the part that would have reached providers of tools used in impersonation. As of September 2026, the current rule contains only §§ 461.1 through 461.3, and the individual-impersonation ban remains a proposal. The hub summarizes the rule in its FTC Impersonation Rule section.
What the TAKE IT DOWN Act does not cover
The federal TAKE IT DOWN Act is limited to nonconsensual intimate images, including AI-generated ones. It is not a general deepfake fraud law and does not reach a scam that uses a fake voice or video for money unless the content is also an intimate depiction.
Federal Bills That Would Target AI Fraud Directly (All Pending)
None of the AI fraud bills introduced in the current Congress (the 119th) has become law, and the federal fraud statutes above contain no AI-specific provision. As of September 2026, these bills are pending:

- AI Fraud Deterrence Act (H.R. 6306), pending. Introduced November 25, 2025 and referred to the House Judiciary Committee. It would amend the mail, wire and bank fraud statutes, the money laundering statute (18 U.S.C. § 1956) and § 912. For wire fraud it would add: "If the violation is committed with the assistance of artificial intelligence, such person shall be fined not more than $1,000,000 or imprisoned not more than 20 years, or both." Because ordinary wire fraud already carries up to 20 years, the change for most cases would be the higher fine. For impersonating a federal officer or employee, it would insert "including with the use of artificial intelligence" into § 912 and add a penalty of up to $1,000,000, 3 years, or both when the violation is committed with AI.
- Artificial Intelligence Scam Prevention Act (S. 3495), pending. Introduced December 16, 2025 and referred to the Senate Commerce, Science, and Transportation Committee. It would make it unlawful to "replicate any individual's image or voice, including through the use of artificial intelligence, with the intent to defraud," and to impersonate a government or business, with enforcement by the FTC.
- AI Fraud Accountability Act of 2026 (S. 3982), pending. Introduced March 4, 2026 and referred to the same Senate committee. It would add a federal crime for anyone who, "in interstate or foreign communications," falsely poses as a real or imaginary person in a "digital impersonation" with "intent to defraud a person of any money, paper, document, or thing of value," punishable by up to 3 years.
- Preventing Deep Fake Scams Act (S. 2117 and H.R. 1734), pending. Referred to the Senate Banking and House Financial Services Committees in 2025. It would establish a Treasury-led task force on artificial intelligence in the financial services sector rather than create a new crime.
The NO FAKES Act, a pending bill that would create a federal right over digital replicas of a person's voice and likeness, is a right-of-publicity measure rather than a fraud law. Its status is tracked in the hub's section on pending federal bills and in our NO FAKES Act coverage.
States With AI-Specific Fraud and Impersonation Crimes
The table lists AI-specific state statutes in force as of September 2026 that address AI-generated or digitally forged likenesses used to defraud, extort or harm. It covers the states discussed on this page, not every state: other states may have similar provisions, and a state missing from it still has general fraud and impersonation laws that apply to a deepfake scam.
| State | Statute | Conduct covered | Penalty | Effective |
|---|---|---|---|---|
| New Jersey | N.J.S.A. 2C:21-17.8 | Creating, soliciting, disclosing or using deceptive audio or visual media to commit or further any crime or offense | Third-degree crime, fine up to $30,000, mandatory consecutive sentence with the underlying offense; civil action | 2025 (P.L.2025, c.40) |
| New Hampshire | RSA 638:26-a and RSA 507:8-j | Knowingly creating, distributing or presenting a deepfake of an identifiable person to extort or cause that person financial or reputational harm, among other purposes | Class B felony (up to 7 years); civil action by the person depicted | January 1, 2025 |
| Arizona | A.R.S. § 13-2006(A)(4) | Using a computer-generated voice recording, image or video of another person with intent to defraud other persons | Class 5 felony | September 26, 2025 |
| Washington | RCW 9A.60.045(1)(b) | Knowingly distributing a forged digital likeness of another person as genuine with intent to defraud, harass, threaten or intimidate | Gross misdemeanor (up to 364 days and $5,000) | July 27, 2025 |
| Pennsylvania | 18 Pa.C.S. § 4101.1 | Generating or creating and distributing a forged digital likeness as genuine with intent to defraud or injure | First-degree misdemeanor; third-degree felony in a scheme to defraud, coerce or steal money or property | 60 days after July 7, 2025 |
| Utah | Utah Code § 76-2-107 | Committing any offense with the aid of generative AI, or prompting AI to commit it | The underlying offense's penalty | May 1, 2024 |
| Utah | Utah Code § 76-12-304, with § 45-3-2 as amended in 2026 | Knowingly or intentionally causing publication of an ad that uses a person's identity, including an AI simulation, to imply endorsement without consent | Class B misdemeanor; civil action | Definitions amended effective May 6, 2026 |
New Jersey: a deepfake used for any crime
New Jersey's law is the broadest on this list because it attaches to any underlying crime. Under N.J.S.A. 2C:21-17.8(b), a person commits a third-degree crime by creating "a work of deceptive audio or visual media for the purpose of attempting or furthering the commission of any crime or offense," and the listed examples include offenses under chapters 20 (theft) and 21 (forgery and fraudulent practices) of the criminal code. Subsection (c)(1) makes it a third-degree crime to solicit, disclose or use such media for the same purpose.
"Deceptive audio or visual media" includes a "sound recording," so a cloned voice qualifies, as long as it "appears to a reasonable person to realistically depict" speech or conduct that did not happen and was produced substantially by "technical means" rather than by a human impersonator.
Several features stand out. A fine of up to $30,000 may be added to any prison term. The deepfake conviction does not merge with the underlying fraud, and "the court shall impose consecutive sentences." Subsection (c)(2) adds a fourth-degree crime for knowingly or recklessly disclosing deceptive audio or visual media created for a criminal purpose in violation of subsection (b). A victim, meaning anyone who suffers personal injury or loss of property as a result of the violation, may sue in Superior Court for actual damages, "but not less than liquidated damages computed at the rate of $1,000 for each knowing or reckless violation," plus punitive damages for willful disregard and attorney's fees. The law exempts content a reasonable viewer would understand as satire, parody, commentary or news, and content a reasonable viewer or listener would not believe is authentic. More on New Jersey is on the New Jersey deepfake laws page.
New Hampshire: harm to the person who was faked
New Hampshire codified its deepfake crime in the fraud chapter of its criminal code. RSA 638:26-a makes it a class B felony to knowingly create, distribute or present a deepfake of an identifiable individual "for the purpose of embarrassing, harassing, entrapping, defaming, extorting, or otherwise causing any financial or reputational harm to the identifiable person." If the deepfake leads to that person's arrest, the offender commits a separate class B felony and is liable for the person's defense costs. Under RSA 651:2, a class B felony carries a maximum prison term of 7 years. The companion civil statute, RSA 507:8-j, lets the depicted person sue for damages.
Both statutes focus on harm to the person whose likeness was used. A deepfake of an executive used to extort that executive fits squarely. A voice clone that fools a grandparent into wiring money harms the grandparent, not the grandchild whose voice was copied, so it fits less cleanly, and ordinary theft and fraud charges remain available. Both statutes exempt satire, parody and news reports that flag questions about authenticity. See New Hampshire deepfake laws.
Arizona: AI impersonation graded as a higher felony
Arizona added a fourth form of criminal impersonation in 2025 (Laws 2025, chapter 184): "Using a computer-generated voice recording, image or video of another person with the intent to defraud other persons." For this paragraph, "defraud" means "to make a false representation or material omission to deceive another person to gain a benefit." Comedy, parody, artistic expression, criticism and cases where "it is clear to a reasonable listener or viewer" that the content was digitally manipulated are not fraudulent.
The AI paragraph is a class 5 felony, one class higher than the class 6 felony for the older forms of criminal impersonation. Because the victim is the person deceived, it fits family-emergency scams and fake-executive fraud directly. The chapter was approved May 13, 2025 without an emergency clause, so it took effect on the 2025 general effective date, September 26, 2025. See Arizona deepfake laws.
Washington: distributing a forged digital likeness
Since July 27, 2025, Washington's second-degree criminal impersonation statute has covered anyone who "knowingly distributes a forged digital likeness of another person as a genuine visual representation or audio recording with intent to defraud, harass, threaten, or intimidate another or for any other unlawful purpose," and who knows or reasonably should know it is not genuine. A "forged digital likeness" is an image or voice recording of an actual, identifiable person that has been digitally created or altered to be indistinguishable from the real thing, misrepresents what the person said or did, and is likely to deceive a reasonable person (RCW 9A.60.010(5)).
The offense is a gross misdemeanor, punishable under RCW 9A.20.021 by up to 364 days in jail, a fine of up to $5,000, or both. The statute does not reach newsworthy material, art, commentary, satire or parody, and it does not make platforms, mobile carriers or broadband providers liable for others' content. Washington also gives people a civil property right over their forged digital likeness; our Washington forged digital likeness explainer covers that separate law.
Pennsylvania: digital forgery
Act 35 of 2025, approved July 7, 2025 and effective 60 days later, created the offense of digital forgery in 18 Pa.C.S. § 4101.1. A person commits it if, "with intent to defraud or injure anyone, or with knowledge and intent the person is facilitating a fraud or injury to be perpetrated by anyone," the person "generates or creates and distributes a forged digital likeness as genuine" and knows or reasonably should know it is forged.
The base offense is a first-degree misdemeanor. It becomes a third-degree felony when committed "through involvement in a scheme to defraud, coerce or commit theft of monetary assets or property." A defendant has an affirmative defense by taking reasonable action to put viewers or listeners on notice that the likeness was not genuine. The statute exempts technology providers and developers and internet access services. See Pennsylvania deepfake laws.
Utah: AI is not a loophole, and fake AI endorsements
Utah Code § 76-2-107, effective May 1, 2024, provides that "An actor may be found guilty of an offense if: (a) the actor commits the offense with the aid of a generative artificial intelligence; or (b) the actor intentionally prompts or otherwise causes a generative artificial intelligence to commit the offense." It creates no new crime and carries no penalty of its own. It makes clear that fraud, theft or extortion committed with AI is prosecuted as that offense.
Utah also reaches fake celebrity endorsements. Section 76-12-304 makes it a class B misdemeanor to knowingly or intentionally cause the publication of an advertisement that uses a person's identity to express or imply an endorsement without consent, and it gives the injured person a civil action. That section adopts the definitions in § 45-3-2, which since May 6, 2026 define "personal identity" to include "any simulation, reproduction, or artificial recreation" of a person's picture, likeness or voice, whether created through generative AI, computer animation, digital manipulation or other means. Under the Abuse of Personal Identity Act, as amended in 2026, a person's identity is also abused when it is used without consent for fundraising or "solicitation of donations" (Utah Code § 45-3-3(2)). See Utah deepfake laws.
General Impersonation Laws That Can Reach a Deepfake
Several states have older, technology-neutral impersonation laws. They do not mention AI, but their text can cover a deepfake, usually only when it is used online or in messages rather than a live phone call.

- California (Penal Code § 528.5). Makes it a crime to knowingly and without consent "credibly" impersonate "another actual person through or on an Internet Web site or by other electronic means for purposes of harming, intimidating, threatening, or defrauding another person." It carries a fine of up to $1,000, up to one year in county jail, or both, and a person who suffers damage or loss may sue for compensatory damages and injunctive relief. "Other electronic means" is broad enough on its face to include a voice-clone call or a deepfake video call.
- Texas (Penal Code § 33.07 and Civil Practice and Remedies Code chapter 98C). Section 33.07 makes it a third-degree felony to use another person's name or persona to create a web page or post messages on a social networking site or other website with intent to harm, defraud, intimidate or threaten, and a Class A misdemeanor to send an email, text or similar message using another person's identifying information with intent to harm or defraud. Chapter 98C, effective September 1, 2025, adds a civil claim for "online impersonation," defined as using a person's "name, voice, signature, or likeness in visual material on a social media platform" without consent, when the impersonation is "virtually indistinguishable from an actual person." The claim belongs to a person injured by the impersonation whom the defendant intended to "harm, defraud, intimidate, or threaten." That injured person need not be the one depicted, so someone defrauded through a fake profile may have a claim, while the person whose likeness was used has one only if the scheme was meant to harm them. A prevailing claimant is awarded actual damages and may recover exemplary damages of not less than $500. See Texas deepfake laws.
- Oklahoma (12 O.S. § 1450). A civil claim against anyone who knowingly uses another person's "name, voice, signature, photograph or likeness through social media to create a false identity" without consent "for the purpose of harming, intimidating, threatening or defrauding such person," meaning the person impersonated. Remedies include actual damages, punitive damages of no less than $500 per individual that may be awarded to the injured party, and attorney fees for the prevailing party.
- Louisiana (R.S. 14:73.10). A misdemeanor to impersonate another actual person online, or to send an email, text or "other form of electronic communication" referencing another person's identifying information, with intent to harm, intimidate, threaten or defraud. The penalty is a fine of $250 to $1,000, 10 days to 6 months in jail, or both.
- Rhode Island (R.I. Gen. Laws § 11-52-7.1). A crime to use another person's "name or persona" on a social networking site or in an email, text or similar message with intent to harm, defraud, intimidate or threaten any person. "Identifying information" includes a "voice print." A first offense is a misdemeanor (up to 1 year, a $1,000 fine, or both, plus restitution); a second or later offense is a felony (up to 3 years, a $3,000 fine, or both).
Nebraska takes a different approach aimed at platforms rather than scammers. Its Uniform Deceptive Trade Practices Act, in a version operative January 1, 2027 (Laws 2026, LB838), makes it a deceptive trade practice for a social media platform that sells advertising to fail to establish and implement required safeguards, including identity verification for advertisers, "an unlawful impersonation detection and mitigation program" and fraud detection systems, or to fail to remove an ad it has determined to be fraudulent within five business days (Neb. Rev. Stat. § 87-302(a)(26)). A "fraudulent advertisement" includes one that "unlawfully impersonates another in order to induce a transaction or extract a benefit."
Laws That Did Not Take Effect or Are Still Waiting
Some deepfake fraud laws that appear in trackers and news coverage are not in force.
Virginia: signed, but never effective. In 2025 the General Assembly passed HB 2124 (2025 Acts of Assembly, chapter 398, approved March 24, 2025), which would have added Va. Code § 18.2-213.3, making it a Class 1 misdemeanor "to use any synthetic digital content for the purpose of committing any criminal offense" in the chapter on crimes involving fraud, with a civil action for the person depicted. The act's third enactment clause says: "That the provisions of the first enactment of this act shall not become effective unless reenacted by the 2026 Session of the General Assembly." Section 18.2-213.3 does not appear in the current Code of Virginia, so the crime is not in force. Virginia prosecutes deepfake fraud under its general fraud laws. See Virginia deepfake laws.
California: SB 1111 on the governor's desk. SB 1111 would add Penal Code § 540, providing that for any Penal Code provision in which false impersonation is an element, "including, without limitation, Sections 528.5, 529, and 530, false impersonation includes the use of a digital replica with the intent to impersonate another." It would also state that a "voice or likeness" under the Civil Code § 3344 right of publicity includes a digital replica. The bill passed the Legislature on August 28, 2026 and was presented to the governor on September 8, 2026. As of September 24, 2026, the governor had not signed or vetoed it.
Under the California Constitution, article IV, section 10(b)(2), a bill passed before September 1 of the second year of the session and held by the governor on or after that date becomes a statute if it is not returned by September 30. If SB 1111 is signed or becomes law that way, it would take effect January 1, 2027 under the default rule for regular-session statutes in article IV, section 8(c)(1). If it is vetoed, it does not become law unless the Legislature overrides the veto. Until then, California's existing § 528.5 remains the main impersonation statute.
Everywhere Else: General Fraud Law Still Applies
The states named above have AI-specific provisions in force as of September 2026. Other states may have their own, and no state is without a remedy. Every state punishes theft by deception, fraud, forgery and identity theft, and those laws apply when the lie is told with a synthetic voice or face. Federal wire fraud also applies nationwide whenever the scheme uses interstate communications.
Coverage is changing quickly. Bills on AI impersonation are pending in several legislatures, and a state that has none today may have one after its next session. For each state's sexual-deepfake, election and likeness laws, use the state-by-state table on the hub.
What to Do If a Deepfake Was Used Against You
If you were targeted by a deepfake scam, stop any payment you can and contact your bank or payment service right away. Keep the messages, recordings, videos, phone numbers, account names and payment records. The FBI's announcement suggests creating "a secret word or phrase with your family to verify their identity," and checking a caller's identity by hanging up and contacting the person independently.
Report the scam to the FBI's Internet Crime Complaint Center, the FTC and your state consumer protection office. The AI voice scam calls guide linked at the top of this page lists each reporting channel and what it handles.
If someone faked your likeness to scam other people, a civil claim depends on the state and on whom the scheme harmed. New Jersey lets any "victim" of a violation sue, meaning a person who suffers injury or loss of property as a result, with liquidated damages of at least $1,000 per knowing or reckless violation; that can include the person who was defrauded. Utah § 76-12-304 lets a person injured by a fake endorsement ad that uses their identity sue. New Hampshire (RSA 507:8-j) and Oklahoma (12 O.S. § 1450) give the person impersonated a claim only when the deepfake or impersonation was meant to harm or defraud that person, so they fit a scam aimed only at other people poorly. Texas (chapter 98C), which covers online impersonation on social media, gives the claim to the person the impersonation was meant to harm or defraud, which can be the person who was scammed rather than the person depicted. Right-of-publicity claims over an unauthorized voice or likeness are covered in AI voice cloning laws and the ELVIS Act and right of publicity laws by state.
Disclaimer: This article provides general legal information about federal law and selected state statutes on deepfake fraud and impersonation (New Jersey, New Hampshire, Arizona, Washington, Pennsylvania, Utah, California, Texas, Oklahoma, Louisiana, Rhode Island, Nebraska and Virginia), current as of September 24, 2026. It is not a survey of every state and is not legal advice. For advice about your situation, consult a licensed attorney in your state.
Frequently Asked Questions
Is it illegal to make a deepfake of someone?
Making a deepfake is not, by itself, a crime under the federal laws discussed here. The FBI has said that creating or distributing synthetic content is not inherently illegal but can be used to facilitate crimes such as fraud and extortion. Using a deepfake to defraud, extort or impersonate someone is illegal under general fraud law everywhere, and states such as New Jersey, New Hampshire, Arizona, Washington and Pennsylvania have crimes aimed at that use. Separate laws cover sexual and election deepfakes.
Can you go to jail for using a deepfake in a scam?
Yes. Federal wire fraud (18 U.S.C. § 1343) carries up to 20 years, or up to 30 years if a financial institution is affected, and aggravated identity theft can add a mandatory consecutive 2 years when another person's means of identification is used, although how that statute applies to a synthetic voice or face is not settled. State penalties include a class 5 felony in Arizona, a class B felony (up to 7 years) in New Hampshire, a third-degree crime with a mandatory consecutive sentence in New Jersey, and a third-degree felony in Pennsylvania when the deepfake is part of a scheme to defraud.
Is there a federal law against deepfake fraud?
Not one that names AI. As of September 2026, deepfake fraud is prosecuted under general federal laws such as wire fraud, aggravated identity theft, interstate extortion and impersonating a federal officer. Bills that would target AI-assisted fraud directly, including H.R. 6306, S. 3495 and S. 3982, are pending in Congress and are not law.
What states have deepfake fraud laws?
As of September 2026, at least five states, including New Jersey (N.J.S.A. 2C:21-17.8), New Hampshire (RSA 638:26-a), Arizona (A.R.S. § 13-2006(A)(4)), Washington (RCW 9A.60.045(1)(b)) and Pennsylvania (18 Pa.C.S. § 4101.1), have crimes aimed at AI or digitally forged likenesses used to defraud or harm, and Utah provides that a crime committed with generative AI is still that crime. Virginia passed a similar law in 2025 but it never took effect. Other states may have similar laws, and every state punishes deepfake fraud under its general fraud and theft laws.
Does the FTC Impersonation Rule cover a deepfake of a private person?
No. The rule in effect since April 1, 2024 covers impersonating government agencies and businesses and their officers. A ban on impersonating individuals is still only a proposal as of September 2026, and in December 2024 the FTC dropped its proposal to extend liability to providers of tools used in impersonation.
Can I sue someone who made a deepfake of me to scam other people?
In some states, depending on whom the scheme harmed. New Jersey lets any victim who suffers injury or property loss from a violation sue, with liquidated damages of at least $1,000 per knowing or reckless violation. Utah allows a person injured by an unauthorized endorsement ad using their identity to sue. New Hampshire (RSA 507:8-j) and Oklahoma (12 O.S. § 1450) allow the person impersonated to sue only when the deepfake or impersonation was meant to harm or defraud that person, so a scam aimed only at others usually falls outside them. Texas (chapter 98C) gives the claim to the person the online impersonation was meant to harm or defraud, which can be the person who was scammed rather than the person depicted. Right-of-publicity laws may also apply. Finding and collecting from the scammer is often the practical obstacle.
Is California's deepfake impersonation bill law?
Not as of September 24, 2026. SB 1111, which would treat use of a digital replica to impersonate someone as false impersonation under the Penal Code, was presented to the governor on September 8, 2026 and had not been signed or vetoed. Under the California Constitution, a bill in that position becomes law if the governor does not return it by September 30, 2026; if it becomes law, it would take effect January 1, 2027.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Alert Number I-120324-PSA (Dec. 3, 2024)(ic3.gov).gov
- 18 U.S.C. § 1343 (fraud by wire, radio, or television)(govinfo.gov).gov
- 18 U.S.C. § 1028A (aggravated identity theft)(govinfo.gov).gov
- 18 U.S.C. § 1028(d)(7) (definition of means of identification)(govinfo.gov).gov
- 18 U.S.C. § 875(d) (interstate communications with intent to extort)(govinfo.gov).gov
- 18 U.S.C. § 912 (impersonating an officer or employee of the United States)(govinfo.gov).gov
- 16 CFR Part 461 (FTC Rule on Impersonation of Government and Businesses)(ecfr.gov).gov
- FTC, Trade Regulation Rule on Impersonation of Government and Businesses, final rule, 89 FR 15017 (Mar. 1, 2024), effective April 1, 2024(federalregister.gov).gov
- FTC, Trade Regulation Rule on Impersonation of Government and Businesses, notice of informal hearing, 89 FR 104905 (Dec. 26, 2024)(federalregister.gov).gov
- H.R. 6306, AI Fraud Deterrence Act, 119th Congress (introduced text)(govinfo.gov).gov
- H.R. 6306, AI Fraud Deterrence Act, 119th Congress (bill status)(congress.gov).gov
- S. 3495, Artificial Intelligence Scam Prevention Act, 119th Congress (introduced text)(govinfo.gov).gov
- S. 3982, AI Fraud Accountability Act of 2026, 119th Congress (introduced text)(govinfo.gov).gov
- S. 2117, Preventing Deep Fake Scams Act, 119th Congress (introduced text)(govinfo.gov).gov
- N.J.S.A. 2C:21-17.7 and 2C:21-17.8 (P.L.2025, c.40, deceptive audio or visual media)(pub.njleg.gov).gov
- N.H. RSA 638:26-a (Fraudulent Use of Deepfakes)(gc.nh.gov).gov
- N.H. RSA 651:2 (sentences and limitations)(gc.nh.gov).gov
- N.H. RSA 507:8-j (Civil Actions for Fraudulent Use of Deepfakes)(gc.nh.gov).gov
- Ariz. Rev. Stat. § 13-2006 (criminal impersonation; classification)(azleg.gov).gov
- Arizona Laws 2025, Chapter 184 (SB 1295)(azleg.gov).gov
- Arizona Legislature, General Effective Dates(azleg.gov).gov
- Rev. Code Wash. § 9A.60.045 (criminal impersonation in the second degree)(app.leg.wa.gov).gov
- Rev. Code Wash. § 9A.60.010 (definitions, forged digital likeness)(app.leg.wa.gov).gov
- Rev. Code Wash. § 9A.20.021 (maximum sentences for crimes)(app.leg.wa.gov).gov
- Washington HB 1205 (2025), Chapter 51, Laws of 2025, bill summary(app.leg.wa.gov).gov
- Pennsylvania Act 35 of 2025 (SB 649), 18 Pa.C.S. § 4101.1 (digital forgery)(palegis.us).gov
- Utah Code § 76-2-107 (commission of offense with aid of generative artificial intelligence)(le.utah.gov).gov
- Utah Code § 76-12-304 (unlawful use of another's personal identity in an advertisement)(le.utah.gov).gov
- Utah Code § 45-3-2 (Abuse of Personal Identity Act definitions, as amended 2026)(le.utah.gov).gov
- Utah Code § 45-3-3 (acts constituting abuse of personal identity, as amended 2026)(le.utah.gov).gov
- Cal. Penal Code § 528.5 (impersonation through an internet website or other electronic means)(leginfo.legislature.ca.gov).gov
- Tex. Penal Code § 33.07 (online impersonation)(tcss.legis.texas.gov).gov
- Tex. Civ. Prac. & Rem. Code ch. 98C (liability for online impersonation)(tcss.legis.texas.gov).gov
- Okla. Stat. tit. 12, § 1450 (online impersonation; liability; remedies)(oklegislature.gov).gov
- La. R.S. 14:73.10 (online impersonation)(legis.la.gov).gov
- R.I. Gen. Laws § 11-52-7.1 (online impersonation)(webserver.rilegislature.gov).gov
- Neb. Rev. Stat. § 87-302 (deceptive trade practices; social media fraudulent advertisements)(nebraskalegislature.gov).gov
- 2025 Va. Acts ch. 398 (HB 2124), synthetic digital content(lis.virginia.gov).gov
- Code of Virginia, Title 18.2, Chapter 6 (Crimes Involving Fraud), section list(law.lis.virginia.gov).gov
- California SB 1111 (2025-2026), Digital replicas, bill text(leginfo.legislature.ca.gov).gov
- California SB 1111 (2025-2026), bill history(leginfo.legislature.ca.gov).gov
- California Constitution, article IV, section 10 (governor's action on bills)(leginfo.legislature.ca.gov).gov
- California Constitution, article IV, section 8 (effective date of statutes)(leginfo.legislature.ca.gov).gov