OpenAdLibraryOpenAdLibrary
Ad Transparency & Supply Chain

Are Deepfake Ads Illegal? Laws Catching Up With AI Impersonation

There is no single 'deepfake ad law' — but a deepfake ad that fakes an endorsement almost always breaks several existing ones. Here is the actual legal landscape, jurisdiction by jurisdiction, and why enforcement still lags.

Editorial illustration: Are Deepfake Ads Illegal? Laws Catching Up With AI Impersonation

Deepfake ads that fake a real person's endorsement are illegal in most major jurisdictions — not under a single dedicated "deepfake law", but under a patchwork of existing rules they almost inevitably violate: consumer-protection statutes banning deceptive advertising (like Section 5 of the FTC Act in the US), right-of-publicity and likeness laws, false-endorsement provisions in trademark law, and, increasingly, AI-specific transparency rules such as the EU AI Act's requirement that synthetic content be disclosed. The honest complication is not whether these ads are unlawful — it's that enforcement runs years behind production, and the people running the ads are usually anonymous, offshore and judgment-proof.

This is not legal advice; it's a practitioner's map of the terrain as of mid-2026, for advertisers, brand-protection teams and anyone trying to understand why the ads persist if they're so clearly illegal.

The baseline: deception law already covers deepfake ads#

Before any AI-specific statute existed, deepfake endorsement ads were already illegal under general advertising law in most countries:

  • United States. Section 5 of the FTC Act prohibits deceptive acts or practices in commerce — a fabricated celebrity endorsement is a textbook deceptive claim. The FTC's endorsement guidelines separately require that endorsements reflect the honest opinion of a real endorser. The agency has also moved directly against impersonation: its rule on government and business impersonation took effect in 2024, and the FTC has publicly signaled that AI-enabled impersonation of individuals is squarely in its sights (see FTC.gov for current rulemaking status).
  • United Kingdom / EU consumer law. Unfair commercial practice rules ban ads that deceive the average consumer — a synthetic endorsement qualifies regardless of the technology used to make it.
  • Australia. Misleading-or-deceptive-conduct provisions in consumer law have been the basis for regulator action against scam ads using fabricated celebrity endorsements.

The point practitioners miss: the deepfake element is legally almost incidental. A Photoshopped still or a fabricated text quote breaks the same rules. What AI changed is scale and believability, not the underlying illegality — celebrity-bait funnels built on clickbait mechanics and fabricated news pages existed long before generative video.

The person's rights: publicity, likeness and false endorsement#

A second, independent legal layer belongs to the person being faked:

  • Right of publicity. Most US states protect a person's name, image, likeness and (in a growing number of states) voice against unauthorized commercial use. Several states have updated these laws specifically for AI: Tennessee's ELVIS Act (2024) extended protection to AI voice simulation, and California expanded its likeness protections around the same period. A federal proposal (the NO FAKES Act) has been debated in Congress for several sessions; check current status before relying on it.
  • False endorsement under trademark law. In the US, Lanham Act §43(a) lets a person sue over commercial uses that falsely imply their endorsement. For brands, the same statute covers logo and trade-dress misuse — the enforcement path detailed in the trademark infringement in ads guide.
  • Defamation and passing off. Where the deepfake portrays the person saying something damaging ("I was arrested for revealing this secret"), defamation claims stack on top. Common-law countries add passing off.

These private rights matter because they don't wait for a regulator: celebrities and brands can and do sue platforms and operators directly. Their practical weakness is targets — suing a shell company behind a rotating domain yields judgments nobody pays.

The new layer: AI-specific transparency laws#

What has genuinely changed since 2024 is the arrival of AI-specific rules that regulate the synthetic content itself:

Jurisdiction Rule What it requires for ads
European Union AI Act (transparency provisions phasing in through 2025–2026) Deepfakes must be disclosed as artificially generated or manipulated; obligations fall on deployers, with platform-level duties layering on top
European Union Digital Services Act Very large platforms must maintain ad repositories and assess systemic risks — the enforcement hook regulators use against scam-ad distribution
China Deep synthesis and generative-AI regulations Mandatory labeling of synthetic media and real-name verification for services that generate it
United States (federal) FTC impersonation rule; proposed individual-impersonation extension Direct liability for impersonation in commerce, including AI-enabled
US states ELVIS Act (TN), California AI likeness laws, and a fast-growing list of state deepfake statutes Civil (and sometimes criminal) liability for unauthorized AI replicas, with carve-outs varying widely by state

Two caveats belong in any honest summary. First, most deepfake-specific statutes were written with election interference and intimate imagery as the priority; commercial-ad deepfakes are covered but rarely the drafting focus. Second, the disclosure-based rules (label your synthetic content) are aimed at legitimate actors — a scammer already committing fraud does not add an AI-disclosure label. For scam funnels, the AI rules mostly add charges to conduct that was already illegal, and add pressure on the platforms that distribute it.

So why do deepfake ads still run?#

Because illegality and enforceability are different problems. The operators behind deepfake endorsement ads — overwhelmingly scam affiliates pushing crypto schemes and miracle-cure offers — are structured to be unenforceable against: anonymous accounts, offshore entities, daily domain rotation and cloaking that shows reviewers a clean page while users get the fake. The legal system moves against named defendants and fixed evidence; the scam ecosystem provides neither voluntarily.

That makes evidence infrastructure the practical bottleneck. Regulators, platforms and litigators all need the same thing: proof of what ad ran, where, when, and what it resolved to. This is exactly what independent ad-transparency capture provides. OpenAdLibrary's index — 725,000+ live native creatives across 49 networks, with 1.3 million+ captured landing pages as of June 2026 — preserves timestamped records of creatives, the publishers that carried them and the redirect chains behind them, the raw material for documenting and reporting a scam ad properly. Brand and legal teams can monitor for impersonation of their own executives or spokespeople through the ad intelligence platform rather than waiting for customer complaints.

What this means in practice#

If you're a legitimate advertiser using AI in creatives: synthetic media itself is legal almost everywhere. The lines you cannot cross are (1) implying a real, identifiable person endorses you without consent, (2) deceiving consumers about material facts, and (3) failing AI-disclosure duties where they apply — the EU AI Act being the one with real extraterritorial pull. AI-generated fictional spokespeople, product renders and voiceovers are fine; cloned real voices and faces without written consent are not. Disclosure norms for paid content still apply on top — the FTC's advertorial disclosure rules don't have an AI exemption.

If you or your brand is being deepfaked: move on three tracks at once. Preserve evidence (independent capture beats screenshots, which platforms may treat as unverifiable); file platform takedowns citing impersonation policies alongside regulator reports; and evaluate civil claims — right of publicity and false endorsement for people, trademark for brands, with the brand-protection playbook for native advertising covering the operational side. Speed matters more than perfection: these campaigns burn domains fast, and unpreserved evidence disappears with them.

If you're assessing risk as a publisher or network: the DSA-era trend is unambiguous — liability and accountability are migrating up the ad supply chain toward the platforms and intermediaries that profit from distribution. "We reviewed the creative and it looked clean" is a weakening defense when cloaking is a known, detectable technique.

The direct answer to the question, then: yes, deepfake ads that fake real people are illegal essentially everywhere that matters — under deception law today, under likeness law where the person sues, and increasingly under AI-transparency law as it phases in. What's still catching up isn't the legality. It's the enforcement plumbing: verification, capture and accountability across an ad supply chain that was built to move fast and ask few questions.

Frequently asked questions

Are deepfake ads illegal in the United States?
Almost always, yes — via a patchwork rather than one statute. A deepfake endorsement ad typically violates the FTC Act's ban on deceptive practices, state right-of-publicity laws protecting a person's likeness and voice, and the Lanham Act's false-endorsement provision. Several states have added AI-specific likeness laws, and the FTC has an impersonation rule with AI-enabled impersonation in scope.
Does the EU AI Act ban deepfake ads?
It doesn't ban them outright — it requires that deepfakes be clearly disclosed as artificially generated or manipulated, with obligations phasing in through 2025–2026. A deepfake ad faking a real endorsement would separately violate EU unfair commercial practice rules regardless of labeling. The Digital Services Act adds platform-level duties, including ad repositories on very large platforms.
Can a celebrity sue over a deepfake ad?
Yes, on several grounds: right of publicity (unauthorized commercial use of likeness or voice), false endorsement under trademark law, and often defamation when the fake portrays them saying something damaging. The practical obstacle is not the legal theory but the defendant — operators hide behind shell entities and rotating domains, so suits increasingly target the platforms and intermediaries that distributed the ads.
Is it legal to use AI-generated people in ads?
Generally yes. Fictional AI-generated spokespeople, product renders and synthetic voiceovers are lawful in most jurisdictions, provided the ad isn't otherwise deceptive and any applicable AI-disclosure rules are met — the EU AI Act being the most significant. The bright line is identifiability: once a synthetic character resembles a real, recognizable person without their written consent, publicity and endorsement law comes into play.
Why do deepfake scam ads still run if they're illegal?
Because enforcement requires named defendants and preserved evidence, and scam operations are engineered to deny both — anonymous accounts, offshore entities, daily domain rotation and cloaking that shows ad reviewers a clean page. The ads are illegal several times over; the bottleneck is attribution and evidence, which is why independent ad capture and stricter advertiser verification matter more than new statutes.
The OpenAdLibrary Team
Written byThe OpenAdLibrary Team
Ad intelligence & native advertising research

We build OpenAdLibrary, the open ad-transparency platform. Every day our systems capture live native ads across Taboola, Outbrain, MGID, Revcontent, Teads, Yahoo and MSN, identify the real advertiser behind each one, and follow the click to its landing page. These guides distill what we see in that data so you can research the market faster.