“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
As of June 2026, 48 states have laws that make some deepfakes illegal, and the rules change sharply from one state to the next. 45 states criminalize non-consensual intimate deepfakes of adults. Three more (Alaska, Mississippi, and West Virginia) cover only minors. More than 30 states also restrict deepfakes in elections. Only New Mexico and Ohio have no intimate-deepfake law on the books yet.
The map filled in fast. In 2019, only a handful of states had any deepfake law. By June 2026, 48 states restrict non-consensual intimate deepfakes, more than 30 restrict election deepfakes, and Missouri became one of the most recent to add adult protection when it enacted HB 2637 in 2026, according to the Public Citizen intimate deepfakes tracker.
Two numbers matter most:
Deepfakes are illegal, in some form, in 48 states plus a federal law that reaches all 50. The type of deepfake decides which law applies.
So the honest answer to “Is it illegal in my state?” is usually yes, with the details depending on what the deepfake was made to do.
State deepfake laws almost always fall into three buckets, and a single state can sit in one, two, or all three.
This is the most common and the most heavily penalized. These laws criminalize creating or sharing fabricated sexual images of a real person without consent.
When the victim is a minor, the conduct is treated as child sexual abuse material, and the penalties climb. These cases overlap constantly with cyberstalking and online harassment investigations.
These laws restrict AI-generated media that fakes a candidate or misleads voters, usually by requiring a clear disclaimer within a window before an election.
Voice clones used to authorize a wire transfer or impersonate an executive fall under fraud and identity theft investigations.
Some states, including Washington and Pennsylvania, wrote deepfake language directly into their fraud and harassment statutes.
For the full picture of how these categories fit together at the federal and state levels, start with our guide to whether deepfakes are illegal.
The table below shows where each state stands on non-consensual intimate deepfakes, the most common type of deepfake law.
“Yes” means the state protects adults. “Minors only” means the enacted law covers children but not adults. “None yet” means no intimate-deepfake law has passed.
Data reflects the Public Citizen tracker as of June 24, 2026, and this area changes often.
| State | Intimate deepfake law (adults)? |
|---|---|
| Alabama | Yes |
| Alaska | Minors only |
| Arizona | Yes |
| Arkansas | Yes |
| California | Yes |
| Colorado | Yes |
| Connecticut | Yes |
| Delaware | Yes |
| Florida | Yes |
| Georgia | Yes |
| Hawaii | Yes |
| Idaho | Yes |
| Illinois | Yes |
| Indiana | Yes |
| Iowa | Yes |
| Kansas | Yes |
| Kentucky | Yes |
| Louisiana | Yes |
| Maine | Yes |
| Maryland | Yes |
| Massachusetts | Yes |
| Michigan | Yes |
| Minnesota | Yes |
| Mississippi | Minors only |
| Missouri | Yes |
| Montana | Yes |
| Nebraska | Yes |
| Nevada | Yes |
| New Hampshire | Yes |
| New Jersey | Yes |
| New Mexico | None yet |
| New York | Yes |
| North Carolina | Yes |
| North Dakota | Yes |
| Ohio | None yet |
| Oklahoma | Yes |
| Oregon | Yes |
| Pennsylvania | Yes |
| Rhode Island | Yes |
| South Carolina | Yes |
| South Dakota | Yes |
| Tennessee | Yes |
| Texas | Yes |
| Utah | Yes |
| Vermont | Yes |
| Virginia | Yes |
| Washington | Yes |
| West Virginia | Minors only |
| Wisconsin | Yes |
| Wyoming | Yes |
| Washington, D.C. | Pending (introduced) |
More than 30 states now regulate deepfakes in elections, according to the Public Citizen elections tracker, with Maryland becoming the 30th in May 2026 and Maine, Tennessee, and Vermont adding rules during the 2026 sessions.
Most of these laws take a lighter touch than the intimate-image statutes. Rather than banning political deepfakes outright, they require a visible disclaimer on AI-generated political ads, usually within 60 to 90 days of an election.
A few go further and let candidates seek injunctions or damages.
There is a real limit here, and it is worth understanding. California passed the most aggressive version, AB 2839, which tried to prohibit deceptive AI political content near an election. A federal court struck it down in August 2025 as a content-based restriction on speech.
That ruling is a signal to every state: election deepfake laws that reach too far into protected speech can be challenged and lost. Disclosure rules have held up better than outright bans.
Five states stand out for thinner coverage on intimate deepfakes. New Mexico and Ohio have no enacted law yet, though bills have moved through committees in both. Alaska, Mississippi, and West Virginia have laws that protect minors but not adults.
If you live in one of those states, you are not without options. The federal TAKE IT DOWN Act criminalizes non-consensual intimate deepfakes nationwide and forces platforms to remove them on request, so it fills the gap where state law is silent.
For anything involving fraud, impersonation, or stalking, existing state statutes still apply regardless of whether a deepfake-specific law exists. The federal TAKE IT DOWN Act is the backstop here, and it reaches every state.
A few state laws shaped how the rest of the country writes theirs.
Tennessee’s ELVIS Act was the first to protect a person’s voice and likeness from AI cloning, aimed largely at the music industry but written broadly.
California’s SB 926 made it a crime to create and send realistic intimate images without consent. The state has stacked several related bills on top of it.
New Jersey turned non-consensual deepfakes into a third-degree crime, one of the tougher criminal frameworks in the country.
Washington and Pennsylvania folded deepfakes into fraud and harassment statutes, which lets prosecutors reach cases that a narrow NCII law would miss.
Here is the part most guides skip. A statute makes it illegal to create a deepfake. It does not tell you who created it, and that gap is where cases stall.
In my work at Southern Recon, the legal question almost always becomes an evidence question. Anonymous accounts, spoofed metadata, and content that bounces across platforms make attribution hard.
Winning a claim, whether criminal or civil, usually depends on digital forensics services that trace a file back to a device or an account, plus clean handling of the types of digital evidence a court will accept.
I have watched strong-looking cases fall apart because the evidence was screenshotted and then lost, and weaker ones succeed because the trail was preserved and documented from day one.
If a deepfake targets you, save everything first, then get a forensic examination. If you are pursuing a claim, cyber litigation support services that turn technical findings into something a court can use.
The law gives you the right, but evidence is what lets you act on it.
Deepfakes are illegal in 48 states, with a federal law covering all 50 for non-consensual intimate images. 45 states protect adults, 3 protect only minors, and New Mexico and Ohio have no intimate-deepfake law yet. More than 30 states regulate election deepfakes, mostly through disclosure rules. The harder problem is not the law but proving who made the file, which comes down to forensic evidence.
Southern Recon Agency investigates AI-generated content, identifies its source, and documents findings your attorney can take to court. Request a confidential consultation with a licensed investigator.
Matt Aubin, CDFE, FBCI, is a cyber and counterfeit investigator and the founder of Southern Recon Agency, a Florida-licensed firm specializing in AI-powered investigations, digital forensics, and technical surveillance countermeasures. He is a Certified Digital Forensics Examiner (CDFE) and a Fellow of the Business Continuity Institute (FBCI), and he works with attorneys and brands on cybercrime, deepfake, and counterfeit matters.
Sometimes. There is no blanket federal ban on all deepfakes. Non-consensual intimate deepfakes are illegal nationwide under the TAKE IT DOWN Act, 48 states add their own intimate-image laws, and election, fraud, and defamation deepfakes are covered by a mix of state and existing federal laws.
That refers to the TAKE IT DOWN Act, which President Trump signed on May 19, 2025. It criminalizes publishing or threatening to publish non-consensual intimate images, including AI-generated deepfakes, and requires online platforms to remove them within 48 hours of a valid request.
Nearly all of them. Most states have passed some form of AI or deepfake law, ranging from intimate-image protections to election disclosure rules to broader AI transparency requirements. The specific protections vary widely by state.
The clearest new rules cover intimate images and elections. Creating non-consensual sexual deepfakes is now criminal in most states and under federal law, and AI-generated political ads must carry disclaimers in more than 30 states. Platforms also face removal deadlines under federal law.
Often, yes. Forensic analysts look at compression artifacts, lighting and audio inconsistencies, metadata, and the file’s origin trail. Consumer “detector” apps are unreliable on their own, so serious cases rely on trained examiners rather than a single automated score.
Through three main channels: criminal laws against intimate-image abuse, election laws requiring disclosure of AI content, and platform obligations to remove reported material. Enforcement then depends on identifying who created or shared the deepfake.
Not reliably. General AI chatbots are not built as forensic tools and can miss or misjudge manipulated media. Deepfake detection calls for dedicated forensic analysis of the actual file rather than a chatbot’s opinion of an image.
That usually means the European Union’s AI Act, which requires that AI-generated or manipulated content be clearly labeled as such. It applies in the EU rather than the United States, though it influences how global platforms handle deepfakes.
This article is for general information and is not legal advice. Deepfake laws change quickly at the state and federal level. For guidance on a specific situation, consult a licensed attorney in your state.