Last January, the government announced that it is preparing legislative amendments to crack down on the malicious use of deepfakes by analysing existing laws and drafting proposals to address the use of AI technology for harassment, blackmail or bullying.
This is a long-awaited step in the right direction, and much can be done in this respect. But first, one must keep in mind the recent background that gave rise to this consideration.
Videos, images and audio created using AI to realistically simulate or fabricate content are booming on the internet. They are becoming increasingly accessible, as what previously required powerful tools can now be done with free mobile apps and limited digital skills.
Deep fakes pose greater risks for children than adults, as children's cognitive abilities are still developing, and children have more difficulty identifying deep fakes. Children are also more susceptible to harmful online practices, including grooming, cyberbullying and child sexual abuse material. This highlights the need for legal action and cooperation, including developing the tools and methods needed to tackle these threats at the required scale and pace.
Since 2024, the EU Artificial Intelligence Act (AI Act), enforceable in Malta, has outlawed the worst cases of AI-based identity manipulation and mandated transparency for AI-generated content. This came at a critical time, as 2024 deepfake statistics showed that half of all businesses have experienced fraud involving AI-altered audio and video.
Still, that act doesn't stand alone in its fight against AI identity fraud, as more new anti-deepfake laws are being passed all over the world, from the US to China. Apart from updated, robust legislation, one must also consider what should go hand in hand with legislation to effectively fight against AI identity fraud.
One of the most talked-about laws against AI deepfakes comes from Denmark, which has amended its copyright law to ensure that every person has the right to their own body, facial features and voice. In effect, Denmark is treating a person's unique likeness as intellectual property, a first-of-its-kind approach, at least in Europe.
Under this amendment, any AI-generated realistic imitation of a person (face, voice, or body) shared without consent violates the law. Danish citizens now have a clear legal right to demand the takedown of such content, and platforms that fail to remove it face severe fines. However, the law does make exceptions for parody and satire, as they remain permitted.
In 2025, the US enacted the 'Take It Down' law, marking the first US federal law directly restricting harmful deepfakes. It focuses on non-consensual intimate imagery and impersonations: deepfake pornography, sexual images, or any AI-generated media falsely depicting a real person in a harmful way. The legislation also makes it a crime to knowingly share nude or sexual images of someone without consent, including AI-generated fakes. Penalties include monetary fines and custodial sentences of up to three years; the maximum applies in aggravated circumstances such as prior offences or distribution with intent to harass.
Moreover, the law doesn't only punish the initial perpetrators; it also imposes obligations on platforms to act when such content is flagged. According to the new law, if someone finds an explicit deepfake of themselves, online platforms are now required by federal law to remove it within 48 hours of a report. By May 2026, any platform that hosts user content and could contain intimate images must have a clear notice-and-takedown system in place.
France has amended its Penal Code to criminalise non-consensual sexual deepfakes. It punishes making public, by any means, sexual content generated by algorithms reproducing a person's image or voice without consent. Possible penalties include up to 2 years' imprisonment and a €60,000 fine, with higher thresholds in some specific contexts.
Several countries, among which are the UK, South Korea, Australia, Italy, the UAE, China and Japan, have introduced specific legislation or amended existing laws to criminalise the malicious use of AI deepfakes, often focusing on areas like non-consensual sexual imagery, fraud, and election manipulation.
Criminalising the malicious use of AI deepfakes is one important aspect that our legislators will definitely not ignore.
AI is driving a new era of fraud, one that doesn't just fool machines but people. Local and international proven incidents demonstrate that it is now persuasive enough to trick people into handing over passwords, approving transfers, or sharing credentials. And because many of these scams cross borders, national laws rarely work, and penalties rarely catch the perpetrators. People lose their savings, businesses face losses, and institutions struggle to keep trust intact.
Try as hard as we can, our legislation hasn't always kept pace, either. Laws that outlaw malicious use of deepfakes may look good on paper, but without the tools to detect and prove synthetic content, they're toothless. How would speed limits help if there were no radar guns or police to enforce them? The same logic applies here.
The most effective response will require more than legislation. It demands a universal approach: stronger verification technologies to catch fake identities at critical checkpoints, paired with public education to help people recognise the red flags. Because when deepfakes look real, sound real, and pass basic checks, the only thing standing between a person and fraud is their ability to recognise the red flags and act accordingly.
Technology can detect what humans can't, but humans still need to be equipped to detect what technology misses. One without the other simply won't hold.