If AI Clones Your Face or Voice, What Can You Actually Do?
The good news is that the law is finally catching up to synthetic faces and voices. The bad news is that it is doing so in a dozen overlapping pieces, and most of them were written with famous people, not you, in mind.
The technology to make a convincing fake of your face or voice used to belong to film studios. Now it belongs to anyone with a phone and a few seconds of you talking. That shift has been thoroughly documented; what tends to get skipped is the practical question that follows once it happens to you. Suppose someone has made a deepfake of you — a cloned voice on a scam call, a fabricated video, a fake intimate image. What can you actually do about it? Not in principle, but in law, this year, as the person it happened to?
The honest answer is that you have more protection than you did two years ago and less than you would expect. There is no single, clean “deepfake law” you can point to. Instead there is a patchwork: an older right built for celebrity endorsements, a clutch of new statutes written in a hurry, and privacy and defamation rules pressed into service. Some of it is genuinely useful. Much of it was designed with famous people and paying rightsholders in mind, and an ordinary person copied by an anonymous account in another country still falls through a lot of the gaps. This is a map of the pieces, and of the holes between them.
The old tool: the right of publicity
Before deepfakes had a name, the law already had one instrument aimed at unauthorised uses of a person’s likeness: the right of publicity. It protects your ability to control the commercial use of your name, image and likeness, and it is why a company that runs an advert using a synthetic version of a musician’s voice can be sued. In theory it applies to everyone. In practice it is strongest for people whose likeness has obvious market value, it varies wildly from place to place — a robust statutory right in some US states, a thin common-law patchwork in others — and it was built for the world of endorsements, not for a stranger generating a fake of you for reasons that have nothing to do with selling a product.
So the right of publicity helps most when a deepfake is used to make money by trading on who you are. It helps far less when the fake is used to humiliate, harass or defraud, which is where a great deal of the real harm actually lives. That mismatch — a commercial tool for a mostly non-commercial harm — is exactly the gap the newer laws are trying to fill.
The clearest win: the TAKE IT DOWN Act
For the most acute category of abuse, non-consensual intimate imagery, the United States now has a specific and unusually concrete remedy. The TAKE IT DOWN Act, signed into law in May 2025, makes it a federal crime to knowingly publish non-consensual intimate images — and it explicitly covers AI-generated “digital forgeries”, not just real photographs. Crucially for victims, it does not stop at criminalising the act. It requires “covered platforms” to run a notice-and-removal process and to take reported content down within 48 hours of a valid request, with the Federal Trade Commission enforcing compliance. The platforms were given until May 2026 to have those processes in place.
The significance is that a takedown request now carries legal weight rather than depending on a platform’s goodwill. If a fabricated intimate image of you is posted, reporting it through the platform’s process is no longer a plea; it is a legal obligation with a clock attached. The Act is not perfect — critics have raised real concerns about how the takedown duty could be abused to suppress lawful content, and about the burden on smaller platforms — but as a piece of protection an ordinary person can actually use, it is the strongest single tool on this list.
The one to watch: the NO FAKES Act
The most ambitious US effort is the NO FAKES Act, which would create something the right of publicity only gestures at: a dedicated federal right in your voice and visual likeness, letting you authorise or block AI “digital replicas” of yourself and sue those who make or spread unauthorised ones, with some responsibility placed on the platforms that host them. Reintroduced with bipartisan backing in April 2025, it advanced through the Senate Judiciary Committee in 2026. But advancing through a committee is not the same as becoming law, and as of this writing it had not passed both chambers, with legal scholars still arguing it needs revision to avoid trampling legitimate expression.
If it passes in a workable form, it would be the first genuinely national, general-purpose answer to “someone made an AI replica of me” — not just the intimate-image slice the TAKE IT DOWN Act covers, but voice clones, fabricated performances and synthetic doubles generally. Until then, it is a bill, not a shield, and the working protection outside the intimate-image category sits at state level.
The state patchwork
In the absence of a finished federal likeness right, individual US states have moved. Eight — among them Tennessee, whose ELVIS Act updated its old personal-rights law for the AI era, along with California, Illinois, New York, Utah, Arkansas, Montana and Washington — have enacted laws specifically addressing AI-generated digital replicas of a person’s voice or likeness. They differ in scope and strength, which produces the familiar American result: your protection depends heavily on which state’s law applies, and a fake that is clearly unlawful in one state may be in a grey zone in another.
This is the same fragmentation we have written about in other corners of AI policy, where what the rules actually protect you from turns out to depend on an accident of geography. It is better than nothing — a lot better, if you happen to live in a state with a strong statute. It is a poor substitute for a clear national rule.
The everyday tools you already had
It is easy to forget, amid the new statutes, that a deepfake is often just an old wrong committed with a new instrument — and the old laws still apply. A fake that spreads a false, damaging claim about you may be defamation. A fake used to trick someone into handing over money or access is fraud. A synthetic voice pretending to be you to a bank or a colleague can be impersonation. Harassment law can reach a campaign of fabricated images aimed at tormenting a specific person. None of these were written for AI, but all of them can bite a deepfake that does the kind of harm they were designed to punish.
There is also a data-protection angle that is easy to miss. In the United Kingdom and the European Union, your face and voice can count as personal data, which means the rules on how personal data is collected and used — consent, purpose, the right to object — can be brought to bear on someone processing your likeness without a lawful basis. It is not a purpose-built deepfake remedy, and it is clumsy to wield against an anonymous poster, but it is another thread in the net. The practical lesson is that you are rarely choosing a single law; the strongest cases tend to stack several of these together, which is also why they reward getting advice early rather than guessing which one fits.
Europe’s different bet: ownership and labelling
Cross to Europe and the whole framing changes. Rather than extending a commercial publicity right, Denmark proposed something conceptually striking: amending its Copyright Act so that every person holds a copyright-style right over their own body, facial features and voice. Under the proposal, an unauthorised deepfake of you would be treated much like an infringement of a work you own — letting you issue takedown notices, claim compensation even without proving reputational harm, and trigger liability for platforms that fail to act, with protection reportedly lasting decades. It is widely described as the first attempt anywhere to put deepfakes inside copyright law, and other European governments are watching it closely.
Alongside that ownership approach runs a transparency one. The EU’s AI Act requires that deepfakes be labelled as artificially generated or manipulated, with machine-readable markers so the synthetic origin travels with the content. The two ideas attack the same harm from opposite ends: Denmark gives you a property-like claim over your own likeness, while the AI Act tries to make sure a fake is disclosed as a fake in the first place. Neither, on its own, makes you safe. Together they sketch a European model that is less about suing after the fact and more about ownership and disclosure up front.
The gap none of it closes yet
Add all of this up and the protection is real but uneven, and the unevenness is practical rather than theoretical. Four problems recur no matter which law you invoke:
- Speed. A deepfake does its damage in hours; even a 48-hour takedown can be slow, and anything requiring a lawyer or a court is measured in months. The harm is fast and the remedy is slow.
- Jurisdiction. The strongest laws are national, and the internet is not. A fake made and hosted abroad, by an anonymous account, can sit outside the reach of the very statute that would clearly forbid it at home.
- Proof and cost. Many remedies still ask you to show harm, identify who did it, or fund a legal fight. That favours the famous and the well-resourced over an ordinary person, which is the opposite of who is most exposed.
- Detection. You cannot enforce a right against a fake you never find. Labelling rules help only if they are followed, and the people most likely to abuse a deepfake are the least likely to label it.
None of that means the law is useless. It means the law is where the law usually is with a new harm: ahead of where it was, behind where it needs to be, and better at protecting the valuable and the visible than the ordinary and the anonymous.
What you can actually do
If it happens to you, the practical posture is more useful than the theory. For an intimate-image deepfake, the TAKE IT DOWN Act now backs your takedown request with the force of law, so report it through the platform’s non-consensual-image process, preserve the evidence, and consider law enforcement and victim-support organisations. For a commercial misuse — your face or voice selling something — the right of publicity, and any state digital-replica law where you live, are the levers to reach for, ideally with legal advice. For a scam using a cloned voice, the relevant crime is usually fraud or impersonation, and the practical defences are the same ones we set out when we covered AI voice-cloning scams. And whatever the case, document everything early, because every one of these remedies rewards the person who kept the evidence: screenshots with timestamps, the original URL, the account that posted it, and any correspondence. If the fake is spreading, a fast, well-documented platform report will usually do more in the first hour than any lawsuit will do in the first year, and it preserves your options if you later escalate.
The deeper point is that a person’s likeness is becoming something the law has to actively protect rather than something it could safely take for granted. That is a shift with the same shape as the fight over who owns the words that trained your AI and the difficulty of getting a system to forget you once it has learned you: a right you assumed was yours turns out to need a statute to defend it. The laws are coming, unevenly and in pieces. Until they settle, the most reliable protection is knowing which piece applies to your situation before you need it — and not assuming that because a fake of you is obviously wrong, it is automatically, usefully, illegal.
Frequently asked questions
Is it illegal to make a deepfake of someone?
Not in itself, in most places. The legality turns on what the deepfake is and what it is used for. A non-consensual intimate (sexual) deepfake is now criminal in the United States under the TAKE IT DOWN Act and in a growing number of other countries. A deepfake used to defraud, defame, impersonate for commercial gain, or interfere in an election can fall foul of fraud, defamation, right-of-publicity or specific deepfake statutes. But a labelled parody, or a synthetic image that is clearly satire, may be lawful. There is no blanket ban on synthetic likenesses; there is a thickening web of rules about harmful uses of them.
What is the “right of publicity” and does it help me?
The right of publicity is the older legal tool for this problem: it protects your ability to control the commercial use of your name, image and likeness. It is what lets a celebrity sue when an advert uses a lookalike or a synthetic version of their voice without permission. It can apply to anyone, not only the famous, but in practice it is strongest for people whose likeness has clear commercial value, it varies enormously by jurisdiction, and it was built for endorsements and advertising rather than for a stranger generating a fake of you. It helps most when a deepfake is used to sell something.
Someone made a fake intimate image of me. What can I do right now?
In the United States you have a specific, recent remedy. The TAKE IT DOWN Act makes it a federal crime to knowingly publish non-consensual intimate images, including AI-generated “digital forgeries”, and requires covered platforms to operate a notice-and-removal process and take the content down within 48 hours of a valid request. In practice that means: document and report it to the platform using its non-consensual-intimate-image process, which now carries legal weight; preserve evidence; and consider contacting law enforcement and organisations that help victims of image abuse. Other countries have their own, differing, criminal routes.
Will the NO FAKES Act fix this?
It would help, but it is not yet law. The NO FAKES Act would create a federal intellectual-property right in your voice and visual likeness, letting you authorise or block AI “digital replicas” and giving you a route to sue those who make or distribute unauthorised ones, with some responsibility on platforms. It advanced through the Senate Judiciary Committee in 2026, but had not passed both chambers, and critics argue it still needs work to balance free expression. Until it becomes law, protection in the US is a mix of the TAKE IT DOWN Act for intimate images and a patchwork of state digital-replica laws for everything else.
Is the law different in Europe?
Yes, and the philosophy is different. Rather than a US-style publicity right, Denmark proposed amending its Copyright Act to give every person a copyright-style right over their own body, facial features and voice, letting them demand takedowns and compensation and putting liability on platforms that fail to act — reportedly the first country to treat likeness as a copyright matter. Across the EU, the AI Act takes a transparency approach: providers must label deepfakes as artificially generated or manipulated, using machine-readable markers. Ownership in one case, disclosure in the other; both aim at the same harm from different directions.
Sources
- S.146 — TAKE IT DOWN Act, 119th Congress (signed into law 19 May 2025) — US Congress
- President Trump Signs TAKE IT DOWN Act Into Law — Latham & Watkins
- S.1367 — NO FAKES Act of 2025, 119th Congress — US Congress
- A Federal Shift in AI and the Right of Publicity? NO FAKES Act Advances in Congress — Byte Back (Womble Bond Dickinson)
- Deepfake legislation: Denmark takes action — World Economic Forum
- Personal identity meets copyright: Denmark moves to regulate deepfakes in the Copyright Act — Plesner
