“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
Deepfakes are not automatically illegal in the United States. They become criminal based on how they are used. Federal law now bans non-consensual intimate deepfakes under the TAKE IT DOWN Act, signed May 19, 2025, and roughly 30 states criminalize deepfakes built to deceive voters or defame people. Use, intent, and harm decide whether a given deepfake breaks the law.
A deepfake becomes illegal when its use causes a specific harm the law already recognizes. The technology itself is legal. Making a face-swap video of yourself, a parody clip that everyone understands is fake, or a visual effect for a film breaks no law.
Three things decide the outcome:
A funny voice clone shared with friends sits in a very different place than a fabricated nude image of a classmate or a fake video of a candidate the night before an election. Same technology, completely different legal exposure.
In my work running cyber investigation services for attorneys and brands, the legal question almost always turns into an evidence question. A law can criminalize a deepfake, but someone still has to prove who created it and where it came from. That is where most cases are won or lost.
Federal law reaches deepfakes mainly through two statutes: the TAKE IT DOWN Act and the pending DEFIANCE Act.
The TAKE IT DOWN Act was signed into law on May 19, 2025. It criminalizes publishing, or threatening to publish, non-consensual intimate images, and it covers AI-generated deepfakes alongside real photos.
It also forces “covered platforms” to build a notice-and-removal process, so a victim can demand takedown and the platform has 48 hours to comply. Platforms were given until May 19, 2026, to set those systems up, and the Federal Trade Commission now enforces that requirement.
The DEFIANCE Act covers the other half of the problem: money. It creates a federal civil right of action, so a victim can sue the person who made or spread an intimate deepfake and recover damages. The Senate passed it by unanimous consent in January 2026, and it is now with the House. If it becomes law, victims will have a federal path to sue, on top of whatever their state already allows.
Beyond intimate imagery, there is no single federal law that bans political or fraudulent deepfakes outright. Bills like the DEEPFAKES Accountability Act have been introduced and stalled.
For now, election and fraud deepfakes are handled by existing laws on fraud, defamation, and election interference, plus the growing list of state statutes.
Illegal deepfakes usually fall into four categories of harm, and each maps to a type of case my team investigates.
This is the most heavily regulated category by far. Fabricated nude or sexual images of a real person are now criminal under federal law and in most states.
When the victim is a minor, it is treated as child sexual abuse material, and the penalties climb sharply.
These cases often overlap with cyberstalking and online harassment investigations, because the same person is frequently behind both.
A deepfake made to trick voters, fake a candidate’s words, or interfere with a vote is illegal in roughly 30 states. Many of these laws require a disclaimer within a set window before an election.
A deepfake that presents a false statement of fact and harms someone’s reputation can trigger a civil defamation claim, whether the target is a private person or a business.
Voice clones and face swaps used to authorize a wire transfer, impersonate an executive, or open accounts fall under existing fraud and identity theft investigations.
This is one of the fastest-growing threats we see, and it is a core focus of our AI threat investigations and protection work.
Roughly 30 states have passed deepfake laws, and the details differ sharply from one to the next. Some focus only on intimate imagery. Others add election protections. A handful cover both.
The National Conference of State Legislatures deepfake tracker keeps a running list of what has passed.
Here is how a few of the most active states compare:
| State | Main focus | Type of law |
|---|---|---|
| Florida | Non-consensual intimate images and altered sexual depictions | Criminal (felony) and civil |
| California | Intimate images and election deepfakes | Criminal and civil |
| Texas | Election deepfakes and intimate images | Criminal |
| ~26 more states | Elections, intimate images, or both | Varies |
Florida sits on the stricter end. Its longstanding statute, Florida Statute 836.13, already made it a third-degree felony to maliciously promote an “altered sexual depiction” of an identifiable person. It gives victims a civil claim worth at least $10,000 plus attorney’s fees.
Then House Bill 757, effective October 1, 2025, went further and criminalized the act of generating that image in the first place. Creating a non-consensual altered sexual depiction is now a third-degree felony carrying up to five years in prison, and possession with intent to distribute is a second-degree felony carrying up to 15 years.
If you want the full breakdown for a specific state, our state guides cover Florida, California, and Texas in detail.
A deepfake is generally legal when it does not harm a real person or deceive an audience in a way the law restricts. Consent is the clearest line. If the person depicted agreed, most concerns fall away.
Clearly labeled satire, parody, and artistic work are usually protected too, since they carry real First Amendment value and no reasonable viewer treats them as true.
Educational demos, research, film effects, and consensual entertainment all sit on the legal side. The trouble starts when a deepfake is passed off as real to cause harm, whether that harm is sexual, financial, political, or reputational.
If a deepfake is used against you, your first move is to preserve the evidence before it disappears:
Do not delete anything, and do not confront the poster in a way that tips them off to scrub the trail.
From there, a forensic examination can pull metadata, trace how the file was made, and work toward attribution.
I have seen strong cases collapse because the evidence was never captured properly, and weak-looking cases turn around once digital forensics services surfaced the source. Understanding the types of digital evidence involved helps you and your attorney know what is realistic to recover.
Report the content to the platform under the TAKE IT DOWN Act’s notice-and-removal process, which now legally requires covered platforms to act.
If a crime occurred, file a police report. If you are pursuing a civil claim, documented forensic findings and cyber litigation support services give your lawyer something a court can actually use.
The law gives you rights, but evidence is what lets you use them.
Deepfakes are legal to create, but illegal to weaponize. Federal law now criminalizes non-consensual intimate deepfakes through the TAKE IT DOWN Act, a federal civil remedy is moving through Congress, and roughly 30 states restrict election or intimate-image deepfakes, with Florida among the strictest. Satire, parody, art, and consensual uses stay protected. If you are targeted, the law is on your side, and forensic evidence is what turns that right into a result.
Southern Recon Agency investigates AI-generated content, traces its source, and documents findings your attorney can take to court. Request a confidential consultation with a licensed investigator.
Matt Aubin, CDFE, FBCI, is a cyber and counterfeit investigator and the founder of Southern Recon Agency, a Florida-licensed firm specializing in AI-powered investigations, digital forensics, and technical surveillance countermeasures. He is a Certified Digital Forensics Examiner (CDFE) and a Fellow of the Business Continuity Institute (FBCI), and he works with attorneys and brands on cybercrime, deepfake, and counterfeit matters.
It depends on the content and your intent. Making a harmless or clearly labeled deepfake is legal. Creating a non-consensual intimate image, a fraudulent impersonation, or a deceptive election video can be a crime under federal or state law.
Yes. Non-consensual intimate deepfakes carry prison time under federal law and many state laws. In Florida, generating an altered sexual depiction without consent is a third-degree felony punishable by up to five years, and distribution-related offenses can reach 15 years.
Private, consensual, or clearly satirical deepfakes are generally legal. The moment a deepfake depicts a real person in a sexual, fraudulent, or defamatory way without consent, personal use is no longer a defense.
Yes, in specific situations. Florida makes it a felony to generate, possess with intent to distribute, or maliciously promote non-consensual altered sexual depictions, and it gives victims a civil claim starting at $10,000.
Attribution usually relies on digital forensics: metadata, file provenance, account records, device analysis, and the trail left when the file was uploaded or shared. Capturing that evidence early, before it is deleted, is the single biggest factor in a successful case.
This article is for general information and is not legal advice. Deepfake laws are changing quickly at the federal and state level. For guidance on a specific situation, consult a licensed attorney in your state.