Your Face, Their Crime: A State-by-State Look at Where Deepfake Laws Actually Stand Right Now
Photo by Photo by Jonathan Phillips on Unsplash on Unsplash
Imagine discovering that someone has used your face — your actual face — in explicit content you never consented to, never filmed, and never knew existed until someone sent you a link. This isn't a hypothetical. It's happening to thousands of people across the US every year, and the legal system's ability to respond to it depends enormously on what state you happen to live in.
Deepfake intimate imagery — sometimes called synthetic CSAM when it involves minors, or non-consensual synthetic pornography when it targets adults — has exploded in availability as AI image and video tools have become cheap and accessible. The technology that used to require serious computing resources and technical skill now lives in apps that anyone can download on a Tuesday afternoon.
The law is trying to catch up. In some places, it's getting close. In others, victims are still largely on their own.
What We're Actually Talking About
Before getting into the legal landscape, it's worth being precise about terminology, because the conversation tends to get muddled.
Deepfakes in the context of intimate imagery refers to AI-generated or AI-manipulated content that realistically depicts a real person in a sexual context they never participated in. This includes face-swapping onto existing adult content, fully synthetic generation using someone's likeness, and voice cloning used in audio sexual content.
This is distinct from — though related to — non-consensual pornography (sometimes called revenge porn), which involves real footage shared without consent. Many states have laws covering the latter that have been extended or amended to address synthetic imagery. Others are starting from scratch.
The Federal Picture (Or Lack Thereof)
At the federal level, the legal framework is still catching up. The DEFIANCE Act, signed into law in 2024, was a significant step — it created a federal civil cause of action for victims of non-consensual intimate deepfakes, meaning individuals can now sue in federal court regardless of where the content was created or distributed.
But federal civil action is different from criminal prosecution. For criminal charges, you're still largely dependent on state law, and that's where the patchwork gets complicated.
States Leading the Charge
Texas was among the earliest movers, criminalizing the disclosure of synthetic intimate visual material back in 2023. The law is broad enough to cover AI-generated content and carries real criminal penalties.
California has multiple overlapping laws addressing both non-consensual pornography and deepfakes specifically. AB 602 and AB 730 (the latter focused on election deepfakes) laid groundwork that subsequent legislation has built on. California also gives victims civil remedies independent of criminal prosecution.
Virginia updated its existing revenge porn statute to explicitly include deepfakes, making it a Class 1 misdemeanor with felony escalations for repeat offenses or cases involving minors.
Georgia, Illinois, and Minnesota have all passed or significantly strengthened synthetic imagery laws in recent cycles, with Illinois in particular taking an aggressive approach that includes provisions around AI-generated content in commercial contexts.
New York passed legislation in 2023 that covers both the creation and distribution of non-consensual intimate deepfakes, with civil penalties that can be substantial.
States Still Playing Catch-Up
Not every state has moved with the same urgency. As of mid-2025, a number of states either lack specific deepfake legislation entirely or have laws so narrowly written that they don't clearly apply to synthetic content.
States like Wyoming, Montana, and Mississippi have limited or no specific statutory coverage for synthetic intimate imagery. Victims in these states may have recourse through broader harassment, defamation, or existing revenge porn statutes — but those paths are less direct and often harder to prosecute.
Florida has revenge porn laws on the books but has been slower to explicitly address the synthetic dimension, leaving prosecutors to work with tools that weren't designed for AI-generated content.
The practical implication: if you're a creator or a private individual who's been targeted, your legal options vary dramatically based on geography — which is a real problem when the internet doesn't respect state lines.
Landmark Cases Worth Knowing
Legal wins in this space are still relatively rare, but they're starting to happen.
In 2024, a Georgia woman successfully pursued a civil judgment against an ex-partner who had created and distributed AI-generated intimate images of her. The case was notable because it relied on a combination of the state's computer fraud statute and harassment law in the absence of a specific deepfake statute — a workaround that advocates have flagged as unsustainable long-term.
On the criminal side, a Texas case resulted in a conviction under that state's synthetic imagery law, with the defendant receiving a jail sentence and a permanent restraining order. It was one of the first criminal deepfake convictions in the country and has been cited in legislative debates in other states.
Not all cases have gone well for victims. In several states, prosecutors have declined to pursue cases citing evidentiary challenges — proving who created the content, establishing that a specific person's likeness was used without consent, and meeting the intent standards required for criminal conviction are all genuinely difficult in synthetic imagery cases.
Practical Steps If You're Targeted
Regardless of where you live, the immediate steps are the same:
- Document everything. Screenshot URLs, preserve metadata if possible, note dates and platforms. Evidence degrades fast online.
- Report to the platform. Most major platforms now have specific intake processes for non-consensual intimate imagery, including synthetic content. Use them — it creates a paper trail and can result in faster takedowns.
- Contact StopNCII.org or the Cyber Civil Rights Initiative. Both organizations have resources specifically for victims and can help with hash-matching technology that prevents content from being re-uploaded.
- Consult an attorney familiar with your state's laws. Given how variable the legal landscape is, generic legal advice only goes so far. Find someone who knows the specific statutes in your jurisdiction.
- File with local law enforcement even if you're uncertain. A police report creates an official record that can matter later, even if the immediate investigation goes nowhere.
What Creators Specifically Need to Know
For people who make adult content professionally, the deepfake threat has an additional dimension: your likeness is already public, which some bad actors treat as implicit permission. It isn't. Consent to view content is not consent to have your face used in synthetic material.
Some creators have begun watermarking content with digital signatures and using services that actively scan for unauthorized use of their likeness. It's not a perfect solution, but it creates documentation that can support legal action.
The legal landscape here is moving fast — faster than most areas of tech law — because the harm is concrete, the victims are vocal, and the political will to act exists across party lines. That's actually unusual. Watch for continued legislative movement through 2025 and 2026, particularly at the federal level where a comprehensive criminal statute is increasingly likely.
Your face is yours. The law is getting there. Know where your state stands.