Spotted a fake account or AI misuse? Report it — we’ll investigate.
Beta
Signals

Who's Liable When an AI Clone or Deepfake Goes Viral?

March 25, 2026

Quick answer: Liability currently splits three ways, the platform, the creator of the clone, and the person whose likeness was used, and the law hasn't fully caught up to assign a clean answer. In practice, the burden of monitoring and enforcement usually falls on the affected person.

An AI clone of someone's voice or face appears online, spreads fast, and causes real harm. The obvious question is whose fault that is. The honest answer: it depends, and the law hasn't fully caught up.

Three parties, three different levels of responsibility

All three parties share some part of the responsibility.

The platform — where the content was posted or distributed. Platforms have historically been shielded from liability for user-generated content under Section 230, a law written in the 1990s, long before generative AI existed.

The creator — whoever made or deployed the clone. If they used someone's likeness without authorization, they may have direct liability under right of publicity or biometric privacy law, but tracking down an anonymous creator across borders is often practically impossible. Many of the most damaging clones originate from anonymous accounts, offshore hosting, or throwaway profiles specifically designed to make the creator untraceable.

The rights holder — the person whose voice or face was used. In most cases, they bear the burden of monitoring, detecting, and enforcing against unauthorized use themselves, since no single party is automatically responsible for policing it on their behalf. For public figures with a large public footprint, this can mean fighting the same battle across dozens of platforms simultaneously, often faster than any single takedown request can be processed.

Why Section 230 is a live question again

A recent German case where courts held Google liable for its AI's false claims about a company is a useful marker here, a ruling widely seen as straightforwardly correct. Section 230 protects platforms from liability for content posted by users. What's newly contested is whether that protection extends to content a platform's own AI system generates, a meaningfully different legal question courts are actively working through, including in high-profile cases involving AI-generated claims about real people.

The distinction matters because it changes who has the incentive to prevent harm in the first place. If a platform's own AI system is treated as the platform's own speech, the platform has a direct legal reason to build in safeguards. If it's treated the same as any other user post, that incentive weakens considerably.

The enforcement gap

Even when liability is clear on paper, enforcement is the harder problem. Detecting an unauthorized clone across dozens of platforms, filing takedowns, and pursuing legal action all fall, in practice, on the affected individual, a significant burden, especially for creators and public figures who are frequent targets. By the time a takedown request is processed on one platform, the same clone has often already been re-uploaded, mirrored, or repackaged elsewhere.

What's changing

Regulation is starting to catch up, state by state, particularly around right of publicity and biometric privacy. But coverage is inconsistent, and there's still no comprehensive federal standard addressing AI-generated likeness. Until that changes, most of the practical protection available to an individual comes from proactive registration, monitoring, and licensing infrastructure rather than after-the-fact litigation.

FAQ

Can I sue a platform for hosting a deepfake of me? It depends on the platform, the jurisdiction, and whether the content was user-generated or produced by the platform's own AI. Section 230 protections generally cover the former but are increasingly contested for the latter.

Who is responsible for taking down an AI clone once it's posted? In most cases, the burden falls on the affected individual to detect it and file a takedown request. There's no default obligation for platforms to proactively monitor for unauthorized AI likeness.

Does right of publicity law cover AI-generated content? In many states, yes, though the laws were largely written before AI existed and enforcement varies significantly by jurisdiction.

onwards,
The Royall team