“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
Yes. Many deepfakes are illegal in the United States, though the technology itself is not banned. Federal law criminalizes non-consensual intimate deepfakes under the TAKE IT DOWN Act, and 48 states add their own rules. Enforcement is no longer theoretical. The Federal Trade Commission can fine platforms up to $53,088 per violation, and the first federal criminal conviction landed in April 2026.
Deepfakes are legal to make and illegal to weaponize. That single line holds true across the whole country. What changes is which law applies once a deepfake causes harm.
The United States regulates deepfakes through a layered system.
A deepfake that is legal to create for a parody video can become a federal crime the moment it turns into non-consensual sexual content, and a state crime the moment it targets a voter or defrauds a business.
For the plain-language version of when a deepfake crosses that line, our guide to whether deepfakes are illegal breaks down each category.
Four federal levers do most of the work.
The TAKE IT DOWN Act is the headline law. Signed in May 2025, it makes it a federal crime to publish, or threaten to publish, non-consensual intimate images. It treats AI deepfakes the same as real photos. It also created a notice-and-removal duty for platforms, covered in more detail below.
The DEFIANCE Act handles the money side. It gives victims of intimate deepfakes a federal civil claim worth up to $250,000 in damages. The Senate passed it by unanimous consent in January 2026, and it is now waiting on the House.
Existing fraud and identity theft statutes cover the rest. A voice clone used to trigger a wire transfer or a fake video used to impersonate an executive gets prosecuted under federal wire fraud and identity theft law, the same statutes that predate AI. These cases overlap heavily with identity theft investigations.
Child protection law is the strictest layer. Federal law treats a computer-generated image that is indistinguishable from a real minor as child sexual abuse material, which carries some of the harshest penalties in the code.
One bill people ask about, the DEEPFAKES Accountability Act, would require a visible watermark on all AI content. It was introduced back in 2023, never advanced to a vote, and has not been reintroduced in the current Congress.
For most adult deepfakes, watching is not a crime. Federal and state intimate-image laws target creation, publication, and sharing, so passive viewing generally sits outside them. Downloading or re-sharing is a different story, because that can count as distribution or possession with intent.
There is one hard exception. If a deepfake depicts a minor, federal law treats it as child sexual abuse material, and knowingly viewing or possessing it is a serious federal crime on its own. The AI origin of the image offers no protection there.
A deepfake made and kept for genuinely private, consensual, or clearly satirical use is usually legal. Consent is the clean line. If the person depicted agreed, or the content is obvious parody that no one would mistake for real, the law rarely reaches it.
Personal use stops being a defense the instant the content is non-consensual and sexual, deceptive in an election, or used to defraud. Intent and harm matter more than where the file is stored.
This is where 2026 changed the picture. For years, deepfake laws existed mostly on paper. Now three sets of enforcers are active.
The Federal Trade Commission polices platforms. Since May 19, 2026, the FTC has enforced the TAKE IT DOWN Act’s removal requirement, treating violations as unfair or deceptive practices with civil penalties up to $53,088 per violation. Ahead of the deadline, the agency sent formal warning letters to more than a dozen major platforms, including Meta, Apple, Microsoft, TikTok, Reddit, Snapchat, and X.
The Department of Justice handles the criminal side. It secured the first federal conviction under the TAKE IT DOWN Act’s criminal provision in April 2026, against a man who used AI to create non-consensual imagery of his neighbors and shared it online.
State attorneys general enforce the state laws, using the growing set of criminal and civil statutes on the books.
Under the platform rule, a covered site that receives a valid takedown request has 48 hours to remove the content and must make reasonable efforts to scrub known copies.
The federal floor covers everyone, and state law fills in the rest. That two-layer design is why the same deepfake can trigger different consequences depending on where it lands.
Take a fabricated intimate image. The TAKE IT DOWN Act applies nationwide, so the victim can force a takedown and refer a criminal case anywhere.
If that victim lives in a state with its own intimate-deepfake statute, they may also have a state criminal charge and a civil claim on top.
If they live in one of the two states without such a law, the federal statute is their main tool. Which protections you get still depends heavily on your state.
Every law above shares one blind spot. It punishes a person, but only after someone identifies that person. In my work at Southern Recon, that identification is the hard part. Deepfakes travel through anonymous accounts, stripped metadata, and re-uploads that bury the trail.
Closing a case, criminal or civil, usually depends on digital forensics services that trace a file back to its source and on careful handling of the types of digital evidence a court will accept. A strong federal law and a preserved evidence trail are what turn a violation into a result.
Deepfakes are legal to create but illegal to use for harm in the United States. The federal TAKE IT DOWN Act criminalizes non-consensual intimate deepfakes and forces platforms to remove them, the DEFIANCE Act would add civil damages, and 48 states layer on their own rules. Enforcement is now active through the FTC and DOJ. Watching an adult deepfake is generally legal, while sharing one, or possessing a deepfake of a minor, is not.
Southern Recon Agency investigates AI-generated content, identifies its source, and documents findings your attorney or law enforcement can use. Request a confidential consultation with a licensed investigator.
Matt Aubin, CDFE, FBCI, is a cyber and counterfeit investigator and the founder of Southern Recon Agency, a Florida-licensed firm specializing in AI-powered investigations, digital forensics, and technical surveillance countermeasures. He is a Certified Digital Forensics Examiner (CDFE) and a Fellow of the Business Continuity Institute (FBCI), and he works with attorneys and brands on cybercrime, deepfake, and counterfeit matters.
Private, consensual, or clearly satirical deepfakes are generally legal. The protection ends when the content is non-consensual and sexual, deceptive in an election, or used to defraud someone. Intent and harm are what decide it, rather than where the file is stored.
Usually not, for adult content. Federal and state laws target creating and sharing intimate deepfakes, so passive viewing typically falls outside them. Downloading or re-sharing can create liability, and any deepfake depicting a minor is illegal to view or possess under federal child protection law.
It is the main federal deepfake law, signed in May 2025. It criminalizes publishing or threatening to publish non-consensual intimate images, including AI deepfakes, and requires platforms to remove reported content within 48 hours. The FTC began enforcing the platform rule in May 2026.
It is a proposed federal bill that would require AI-generated content to carry a watermark or disclosure. It was introduced in 2023, never reached a vote, and has not been reintroduced in the current Congress, so it remains a proposal rather than law.
They vary by law. The TAKE IT DOWN Act carries federal prison time for criminal violations and FTC fines up to $53,088 per violation for non-compliant platforms. The DEFIANCE Act would allow civil damages up to $250,000. State penalties range from misdemeanors to multi-year felonies.
This article is for general information and is not legal advice. Deepfake laws change quickly at the federal and state level. For guidance on a specific situation, consult a licensed attorney in your state.