Every month someone forwards me a statistic about artificial intelligence and identity fraud, and every month the statistic traces back to a company that sells fraud-detection software. So I went and read the primary sources instead — the FBI’s complaint data, the FTC’s Consumer Sentinel Data Book, FinCEN’s Bank Secrecy Act analysis, NIST’s biometric evaluations, and the Federal Register. What I found is more useful than the marketing numbers and considerably less dramatic.
The federal government has documented, in its own reports, that criminals use generative tools across the whole span of fraud. What it has not done is measure how much identity theft those tools cause. Those are different claims, the gap between them is enormous, and anyone quoting a precise percentage is quoting a vendor.
I am writing this for people on the receiving end — the person whose voice was cloned to call their mother, the small business whose controller got a video call from a fake executive, the client who discovers a loan he never applied for. Categories of documented abuse and the defense against each. No methods, no tool names.
What the federal complaint data actually counts
The FBI’s Internet Crime Complaint Center took in 1,008,597 complaints in 2025 reporting $20.877 billion in losses. That report carries a section headed “Artificial Intelligence (AI) Used in Cybercrime,” and it produces the number everyone repeats: 22,364 complaints carrying an AI reference, with adjusted losses of $893,346,472.
Now read the definition IC3 attaches to that number in Appendix B. “AI Related” is a descriptor, and a descriptor “relates to the medium or tool used to facilitate crime and is used by IC3 for tracking purposes only.” The descriptor means precisely this and nothing more:
AI Related: Information reported contains a reference to artificial intelligence (AI).
That is a text-match on what a complainant wrote. It is not a forensic finding. IC3 says so itself, in the same section, about its own investment-fraud figure — $632,041,188 in complaints with an AI nexus against more than $8.6 billion in total investment-fraud losses:
However, overall losses to Investment scams exceeded $8 billion, demonstrating that many victims do not realize the extent AI may be involved in scams.
So the number understates. Fine. But now break it out by crime type, because this is the part nobody quotes. Of the 22,364 AI-referenced complaints, the crime type “Identity Theft” accounts for 460 complaints and $1,643,308 in losses. IC3 logged 31,675 identity theft complaints overall in 2025, with $185,832,657 in losses. The AI descriptor attached to about one and a half percent of them.
The FTC’s data is worse for this purpose, in an instructive way. The Consumer Sentinel Network Data Book 2024 — published March 2025, and still the most recent edition as of this writing — took in over 6.47 million reports, including 1,135,291 identity theft reports. “Credit Card tops the list of identity theft types reported in 2024. The FTC received 449,032 reports from people who said their information was misused with an existing credit card or when applying for a new credit card.” The Data Book runs 92 pages across national, state, and metropolitan breakdowns.
It does not contain the phrase “artificial intelligence.” It does not contain “deepfake.” It does not contain “synthetic identity.” The national identity theft dataset has no field for any of it.
In short, the two federal datasets that count identity theft either do not classify AI involvement at all, or classify it by whether the victim happened to mention it. Anyone who tells you what share of identity theft is now AI-assisted is not working from this data, because this data cannot answer the question.
The four categories the government has actually documented
The absence of a clean number is not the absence of evidence. Two federal publications describe the conduct directly, and between them they map four categories worth a defense.
The FBI issued Public Service Announcement I-120324-PSA, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud,” on December 3, 2024. It says why it exists: “Since it can be difficult to identify when content is AI-generated, the FBI is providing the following examples of how criminals may use generative AI in their fraud schemes to increase public recognition and scrutiny.” It then walks through generated text, images, audio, and video — fictitious profiles at volume, fabricated identification documents, cloned voices used to impersonate a relative in a crisis, and generated video used in live calls to impersonate an executive or an authority figure.
FinCEN issued Alert FIN-2024-Alert004, “FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions,” on November 13, 2024, drawn from its analysis of Bank Secrecy Act filings:
Beginning in 2023 and continuing in 2024, FinCEN has observed an increase in suspicious activity reporting by financial institutions describing the suspected use of deepfake media in fraud schemes targeting their institutions and customers.
Put the two together and the documented categories are these:
- Synthetic identity fraud — a fabricated person assembled from a mix of real and invented information, built to pass an institution’s checks and then used to open accounts.
- Impersonation of a specific known person by cloned voice or generated video — the relative in distress, the executive directing a wire, the public figure endorsing an investment.
- Forged or altered identity documents, including face-morphed photographs submitted into document issuance and verification workflows.
- Social engineering at volume — the same phishing and confidence schemes as before, written faster, in more languages, without the spelling errors that used to give them away.
Notice what is common to all four. None of them is a new crime. Every one of them is an old crime with the unit cost driven down. That is what actually changed, and it is why the defense is mostly not technological.
Why synthetic identities are the hard category — and who eats the loss
FinCEN’s Financial Trend Analysis on identity-related suspicious activity, published January 9, 2024 and covering calendar year 2021, is the closest thing to a measurement that exists. Roughly 1.6 million identity-related BSA reports — 42% of about 3.8 million total filings — reported $212 billion in suspicious activity. FinCEN sorted them into fourteen typologies. Its definition of the one that matters here:
perpetrators of “Synthetic Identity” use a combination of real and fake PII to fabricate a person or entity to pass validation processes
And the count for that typology, out of 1.6 million identity-related reports: approximately 3,000 reports, reporting $182 million. For comparison, in the same table, “General Fraud” carried 1.2 million reports and $149 billion, “False Records” about 423,000 reports and $45 billion, and “Identity Theft” about 222,000 reports and $36 billion.
Three thousand. I do not read that as proof that synthetic identity fraud is rare. I read it as proof that it is invisible, which is the entire design objective. Every other typology on that list has a human being who notices something and complains. A synthetic identity has no one.
Work it through the Fair Credit Reporting Act and the problem becomes concrete. The federal block at 15 U.S.C. § 1681c-2(a) requires a consumer reporting agency to block information “that the consumer identifies as information that resulted from an alleged identity theft,” and it conditions the block on four inputs from that consumer, including “a statement by the consumer that the information is not information relating to any transaction by the consumer.” A fabricated person files no dispute, submits no statement, and triggers no reinvestigation. The tradeline sits there, ages, builds a file, and is eventually charged off by the lender.
So who bears that loss? The public federal data does not tell us. I looked for it in the Sentinel Data Book, in the IC3 report, and in FinCEN’s analysis, and none of them allocates synthetic-identity losses among lender, merchant, and consumer. I would rather say that plainly than repeat a figure I cannot source. The one thing the statutes do establish is that the FCRA’s victim machinery — the block, the fraud alert, the reinvestigation — is built around a real consumer who shows up and objects. Where there is no such consumer, it does nothing at all.
Face morphing is the one place the government has measured the defense
NIST published Interagency Report 8584, Face Analysis Technology Evaluation (FATE) MORPH Part 4B: Considerations for Implementing Morph Detection in Operations, in August 2025. It is the most rigorously grounded document in this entire subject area, because NIST tests detection algorithms against data the developers have never seen.
Three findings carry directly into the defensive posture of any organization that accepts a submitted photograph.
First, on how much of this is actually happening: “The prevalence of morphs is unknown and difficult to quantify without technical means for detection.” NIST, testing this for years with federal funding, will not put a number on it. That should settle how much weight to give a vendor who will.
Second, on the single most effective control: “The threat can be reduced significantly if photo capture is trusted.” Not better detection software — control of the camera. An organization that captures the photograph itself, in its own environment, has removed most of the exposure. One that accepts uploads has kept it.
Third, on the limits of detection, and this is the finding that should make anyone relying on a detection product uncomfortable. NIST splits the field in two. Single-image detection — an algorithm handed one photograph — is effective against morphs from a generator it was trained on, and NIST’s assessment of the rest is blunt: “For not-previously-seen morph types, morph detection accuracy is often very poor.” Differential detection, which compares the submitted photograph against a live image of the person, NIST found more generalizable, because it leans on identity information across the two images rather than on artifacts in one. Read that as an instruction. Single-image detection decays the moment the technique changes; what survives is holding a second, trusted image to compare against.
What NIST now requires of anyone verifying identity remotely
NIST finalized Special Publication 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment, in July 2025. Section 3.14 is titled “Digital Injection Prevention and Forged Media Detection,” and it exists because remote identity proofing can be fed media that never came from the applicant’s camera.
I am not going to catalog how. The controls are the useful part. Credential service providers shall implement technical controls giving confidence that media is being produced by a genuine sensor; shall analyze all submitted media for artifacts and indicators of potential modification, manipulation, tampering, or forgery, with those analysis algorithms tested against known attack artifacts and genuine media so the false-positive and false-negative rates are actually known and documented; shall use authenticated protected channels; and should add passive forged-media detection, sensor authentication or device attestation, and manual review layered on top of automated decisioning. For processes with a human on the other end, NIST requires that proofing agents be trained to spot indications of manipulated media, and that random human-in-the-loop cues be built into capture.
Then NIST says the thing a vendor never will:
However, even these mechanisms are not sufficient to address all possible cases of these kinds of attacks.
FinCEN reaches the same place from the compliance side. Its alert “identified certain best practices that may help financial institutions reduce their vulnerability to deepfake identity documents” — multifactor authentication, phishing-resistant where available, and live verification — while listing red flags that mostly turn on inconsistency rather than on any single tell: identity documents that conflict with each other, a photograph inconsistent with the customer’s stated age, a customer who declines multifactor authentication, geographic or device data that does not match the documents, and account behavior that does not match the profile.
Every one of those is a process control. None of them is a detector. That is the lesson: the institutions that hold up are the ones whose verification does not depend on any single artifact being genuine.
What federal law gives a victim, and what it withholds
Two FCRA provisions do the real work, and the second one has a hole in it that most people never learn about until they need it.
The block, 15 U.S.C. § 1681c-2. A consumer reporting agency “shall block the reporting of any information in the file of a consumer that the consumer identifies as information that resulted from an alleged identity theft, not later than 4 business days after the date of receipt by such agency” of four things: proof of identity, a copy of an identity theft report, identification of the information, and the consumer’s statement that it is not his. Four business days is a hard deadline, and it is far faster than the reinvestigation timeline. The agency may decline or rescind a block under subsection (c), including where the consumer got the goods or money.
Everything turns on the identity theft report. The Bureau’s definition at 12 CFR 1022.3(i) requires, at a minimum, a report alleging identity theft with as much specificity as the consumer can provide, and one “that is a copy of an official, valid report filed by the consumer with a Federal, state, or local law enforcement agency, including the United States Postal Inspection Service, the filing of which subjects the person filing the report to criminal penalties relating to the filing of false information, if, in fact, the information in the report is false.” Minnesota law is unusually good on exactly this point, and I have written the sequence out in full in the identity theft victim’s guide. What a reinvestigation has to look like once you dispute is covered here.
The business records, 15 U.S.C. § 1681g(e). This is the provision nobody uses and everybody should. A business that extended credit to, or transacted with, the person who misused your identity must, within 30 days of a proper written request, hand over “a copy of application and business transaction records in the control of the business entity” evidencing the transaction — the application itself, the signature, the documents submitted. Without charge. Paragraph (5) lets the business decline in good faith on four narrow grounds, one of which is a request for Internet navigational data, so ask for the application file and not a browsing history. That is how you find out whether the “identity” that opened the account was a forged document, a stolen file, or a fabrication. It is the single most valuable discovery tool a victim has, and it operates before any lawsuit.
Now the hole. Section 1681g(e)(6): “Except as provided in section 1681s of this title, sections 1681n and 1681o of this title do not apply to any violation of this subsection.” Congress gave victims the right to those records and simultaneously stripped the private damages remedies that enforce the rest of the statute. If a business ignores your § 1681g(e) request, you cannot sue it for willful or negligent noncompliance. Enforcement runs through the regulators. I still send the requests, and most institutions comply, but I tell clients the truth about what backs the demand.
Minnesota wrote forged likenesses into the identity theft statute in 2026
This is the development that has not filtered out yet, and it changes the Minnesota answer.
The 2026 Legislature passed Laws 2026, ch. 97 — S.F. No. 4760 — whose Article 3 is captioned “IDENTITY THEFT; FINANCIAL CRIMES.” Section 3 of that article amends Minn. Stat. § 609.527, subd. 1, to add a new definition:
“Forged digital likeness” means any video recording, motion-picture film, sound recording, electronic image, or photograph, or any technological representation of speech or conduct substantially derivative thereof that: (1) was created, adapted, altered, or modified in a manner that was substantially dependent upon technical means; (2) misrepresents the appearance, speech, or conduct of the individual; and (3) is so realistic that a reasonable person would believe it depicts the image or speech of an actual individual.
The same section rewrites the definition of “identity” to mean “any name, voice or likeness, number, or data transmission that may be used, alone or in conjunction with any other information, to identify a specific individual or entity,” and adds “a forged digital likeness” to the enumerated list. Article 3, section 3 carries no effective-date clause of its own — only section 4 of that article does, and section 4 sets August 1, 2026 — so section 3 runs on the default in Minn. Stat. § 645.02. That section supplies two defaults. An ordinary act “takes effect on August 1 next following its final enactment, unless a different date is specified in the act.” But “[a]n appropriation act or an act having appropriation items enacted finally at any session of the legislature takes effect at the beginning of the first day of July next following its final enactment.” Chapter 97 contains an article of grant extensions that reprints appropriation items, which puts it in reach of the second default. The outside date is August 1, 2026, and it may have run from July 1. Either way the new definition was law well before I wrote this.
The consequence is direct. Cloning a person’s voice and using it to induce a wire transfer is now, in Minnesota, use of “an identity that is not the person’s own” under § 609.527, subd. 2. The Revisor’s website still displays the pre-amendment text of subdivision 1 with a currency banner; the session law is the operative language.
Now, what this does and does NOT do.
It is a criminal statute. It creates no civil cause of action. On conviction the court must order restitution of not less than $1,000 to each direct victim under subdivision 4, and subdivision 5 requires the law enforcement agency where you live to take your report and give you a copy — which is the report the federal block requires. That is real, and it is more than most states give. It is not a lawsuit.
Two Minnesota statutes do give a civil remedy over a forged likeness, and both are narrow. Section 604.32 creates a cause of action for the nonconsensual dissemination of a deep fake, and subdivision 2 confines it to a deep fake that realistically depicts intimate parts or a sexual act. Section 609.771 — the election deep fake statute — is mostly criminal, but subdivision 4 is not. It provides that “[a] cause of action for injunctive or equitable relief may be maintained against any person who is reasonably believed to be about to violate or who is in the course of violating this section,” and the list of who may maintain it runs: the attorney general, a county or city attorney, “the depicted individual,” and an injured candidate. That is a private action, and the person whose face or voice was fabricated holds it in his own right. It is also a narrow one — injunctive or equitable relief only, no damages, and only against conduct meeting subdivision 2’s elements, which require an intent to injure a candidate or influence an election and dissemination either within 90 days before a nominating convention or after absentee voting opens. Section 617.262 criminalizes the nonconsensual sexual variety and creates no civil action of its own. Outside those lanes there is no Minnesota statutory claim for having your face or voice fabricated — and there is no Minnesota biometric privacy act at all, which I have worked through separately, including the common-law appropriation tort that is the nearest available vehicle. If the fabrication rides on a data breach, Minn. Stat. § 325E.61 governs notice and is enforced by the attorney general under § 8.31; the three overlapping Minnesota privacy regimes and which of them a company actually falls under are set out here. Whether a Social Security number was exposed pulls in § 325E.59, and whether the company owed notice at all is treated here.
Where federal law is not — and where it retreated
The FTC finalized its Impersonation Rule on March 1, 2024, effective April 1, 2024. It is a genuine tool: 16 CFR 461.3 makes it a violation to “materially and falsely pose as, directly or by implication, a business or officer thereof, in or affecting commerce . . .” with a parallel prohibition for government at § 461.2. Civil penalties and redress follow.
Read the two operative sections again and notice who is missing. The rule reaches impersonation of a government entity and impersonation of a business. It does not reach impersonation of you.
The Commission knew that when it issued the rule. On the very same day, at 89 FR 15072, it published a supplemental notice of proposed rulemaking to “add a prohibition on the impersonation of individuals,” citing its own numbers: “Consumers have reported 152,696 instances of family and friend impersonation and associated total losses of approximately $339 million from 2019 through 2023.” Comments closed April 30, 2024, and the Commission noticed an informal hearing on the proposal for January 17, 2025, at 89 FR 104905 (Dec. 26, 2024). As of this writing — nearly two and a half years later — 16 CFR Part 461 still reads exactly as it did in March 2024, sourced to 89 FR 15030, with no individual-impersonation provision and no final rule on the Federal Register docket.
And in one respect the federal posture moved backwards. On May 12, 2025, at 90 FR 20084, the CFPB published a withdrawal notice stating that the Bureau “is withdrawing many guidance documents issued since the CFPB assumed its functions in 2011.” Item 13 on the list is “Consumer Financial Protection Circular 2022-04: Insufficient data protection or security for sensitive consumer information, 87 FR 54346 (Sept. 6, 2022)” — the circular that had told covered entities that inadequate authentication and weak data security can themselves be an unfair practice under 12 U.S.C. § 5536(a)(1)(B), breach or no breach. The statute did not change. The guidance interpreting it is gone.
That is the state of it. The technology is compounding, NIST is writing controls, Minnesota criminalized forged likenesses weeks before I wrote this, and the federal consumer-protection rule that would let a person recover for being personally impersonated has been sitting as a proposal since March 2024. The law is behind, and I would rather say so than pretend the toolkit is fuller than it is.
What I tell a person to do
Do these, in this order, and do not wait for a loss.
Freeze all three credit files. Under 15 U.S.C. § 1681c-1(i)(2)(A) a nationwide agency must place the freeze “free of charge” within 1 business day of an electronic or toll-free request, and under paragraph (3)(C) must lift it, again free of charge, within 1 hour on the same channel. That one-hour lift is the answer to every objection about inconvenience. A freeze stops a new account from opening; monitoring only tells you it already did.
Agree on a verification phrase with your family and use it. This is the FBI’s own first recommendation in PSA I-120324-PSA — “Create a secret word or phrase with your family to verify their identity” — and it is the only defense that does not degrade as the audio gets better. A cloned voice cannot produce a fact it was never given.
Hang up and call back on a number you already had. Not a number the caller gave you, not a number in the email. This defeats the entire impersonation category regardless of how convincing the voice or the video was.
Cut the raw material. Long public recordings of your voice, and public video of your face, are the inputs. The FBI’s guidance is to limit them and to keep social accounts private. That advice reads as quaint. It is still correct.
If it has already happened: file the police report Minnesota requires, get your copy, use it to place blocks under § 1681c-2, and send § 1681g(e) requests to every business that opened an account. Get the application records before anyone’s retention schedule runs.
What I tell a small business to do
Control the capture. NIST’s finding is unambiguous — a trusted capture beats a detector. Wherever your process accepts an uploaded photograph or document that you could instead capture yourself, change it.
Put a callback rule on money movement and write it down. Any change to payment instructions, any wire above a threshold you set, any urgent request from an executive: verified by a call to a number in your own records, by someone other than the requester, every time, with no exception for the CEO. The executive-impersonation category exists because exceptions exist. This one policy defeats it.
Do not let one artifact decide. Three of FinCEN’s nine red flags are inconsistencies — a document that conflicts with another document, device data that conflicts with the identity documents, a photograph that conflicts with the rest of the profile. Three more are behavioral. The last three depend on detection software, which is the part that ages. Build the process so no single genuine-looking item clears an account.
Multifactor authentication everywhere, phishing-resistant where you can get it. It is the first item on FinCEN’s best-practices list and it is cheap.
Know your notice duty before you need it. Minnesota’s § 325E.61 runs on a definition of “personal information” narrower than most people assume, and the clock is “the most expedient time possible and without unreasonable delay.” Decide now who makes that call.
If you take a claim of identity theft from a customer, treat § 1681g(e) as a compliance obligation. Thirty days, no charge, and the affirmative defense in paragraph (10) only protects you if you actually made “a reasonably diligent search of its available business records.”
Madgett Law, LLC represents Minnesota consumers in Fair Credit Reporting Act matters — disputes, blocks, reinvestigation failures, and suits against furnishers and consumer reporting agencies — and advises small businesses on data-security incidents, breach-notification obligations, and privacy compliance. If a fraudulent account, a forged signature, or a fabricated identity has landed on your credit file or in your company’s systems, send us a message or call 612-470-6529.
Sources: Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report (2025 totals of 1,008,597 complaints and $20.877 billion in losses at p. 4; AI section at pp. 39–40 for 22,364 complaints and $893,346,472; AI references by complaint count at p. 41 and by loss at p. 42 for the 460 identity theft complaints and $1,643,308; 2025 crime types at pp. 7–8 for 31,675 identity theft complaints and $185,832,657; descriptor definitions at p. 61; data caveats at p. 62). FBI IC3 Public Service Announcement I-120324-PSA, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud” (Dec. 3, 2024) (categories of AI-generated text, images, audio, and video; verification-phrase and call-back recommendations). Federal Trade Commission, Consumer Sentinel Network Data Book 2024 (March 2025) (executive summary at p. 4 for 6.47 million reports and the 449,032 credit card identity theft reports; p. 16 for the 1,135,291 total identity theft reports; no artificial intelligence, deepfake, or synthetic identity classification anywhere in the 92-page volume). Financial Crimes Enforcement Network, Alert FIN-2024-Alert004, “FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions” (Nov. 13, 2024) (increase in deepfake-related SAR filings at p. 1; best practices and red flag indicators at pp. 4–6). FinCEN, “Financial Trend Analysis: Identity-Related Suspicious Activity: 2021 Threats and Trends” (Jan. 9, 2024) (executive summary at p. 1 for 1.6 million identity-related reports, 42%, and $212 billion; synthetic identity definition at p. 6; typology table at Appendix 1, pp. 13–14, for approximately 3,000 synthetic identity reports and $182 million). National Institute of Standards and Technology, NISTIR 8584, Ngan & Grother, “Face Analysis Technology Evaluation (FATE) MORPH Part 4B: Considerations for Implementing Morph Detection in Operations” (Aug. 2025) (executive summary for trusted capture; § 1 for unknown prevalence; § 3 for single-image versus differential morph-detection generalization). NIST Special Publication 800-63A-4, “Digital Identity Guidelines: Identity Proofing and Enrollment” (July 2025), § 3.14 (digital injection prevention and forged media detection requirements; limitation of those mechanisms); glossary (synthetic identity fraud). 15 U.S.C. § 1681c-1(i)(2)(A), (i)(3)(C) (national security freeze placed free of charge within 1 business day and removed within 1 hour on an electronic or toll-free request); 15 U.S.C. § 1681c-2(a), (c) (identity theft block, four business days, four required inputs, authority to decline or rescind); 15 U.S.C. § 1681g(e)(1), (3), (4), (5), (6), (10) (business transaction records, 30 days, written request, no charge, good-faith grounds to decline, limitation on liability, affirmative defense); 15 U.S.C. § 1681a(q)(3), (4) (definitions of identity theft and identity theft report), all from uscode.house.gov. 12 C.F.R. § 1022.3(h), (i) (Bureau definitions of identity theft and identity theft report), from eCFR. 16 C.F.R. §§ 461.1, 461.2, 461.3 (Impersonation Rule definitions and prohibitions), from eCFR, sourced to 89 Fed. Reg. 15030 (Mar. 1, 2024); Trade Regulation Rule on Impersonation of Government and Businesses, final rule, 89 Fed. Reg. 15017 (Mar. 1, 2024) (effective April 1, 2024); supplemental notice of proposed rulemaking, 89 Fed. Reg. 15072 (Mar. 1, 2024) (proposal to prohibit impersonation of individuals; comment deadline April 30, 2024; 152,696 family and friend impersonation reports and approximately $339 million in losses, 2019–2023); informal hearing notice, 89 Fed. Reg. 104905 (Dec. 26, 2024) (hearing on the individual-impersonation proposal noticed for January 17, 2025). Consumer Financial Protection Bureau, “Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal,” 90 Fed. Reg. 20084 (May 12, 2025) (withdrawal applicable May 12, 2025; item 13, Consumer Financial Protection Circular 2022-04, 87 Fed. Reg. 54346 (Sept. 6, 2022)). Laws 2026, ch. 97 (S.F. No. 4760), art. 3, § 3 (amending Minn. Stat. § 609.527, subd. 1, to add “forged digital likeness” and to include voice or likeness within “identity”); Minn. Stat. § 645.02 (default effective dates — August 1 for an ordinary act, the first day of July for an appropriation act or an act having appropriation items; art. 3, § 3 carries no effective-date clause, and ch. 97, art. 11 reprints appropriation items); Minn. Stat. § 609.527, subds. 2, 4, 5 (identity theft crime, $1,000 restitution floor, mandatory police report); Minn. Stat. § 604.32, subd. 2 (civil action limited to a deep fake realistically depicting intimate parts or a sexual act); Minn. Stat. § 609.771, subds. 2, 3, 4 (election deep fake crime and its 90-day and absentee-period windows; penalties; subdivision 4, which creates a cause of action for injunctive or equitable relief maintainable by the attorney general, a county or city attorney, the depicted individual, or an injured candidate — injunctive and equitable relief only, no damages); Minn. Stat. § 617.262 (nonconsensual sexual deep fake crime; no civil action); Minn. Stat. § 325E.61, subds. 1, 6 (breach notification and attorney general enforcement under § 8.31), all from revisor.mn.gov.
This article is general legal information about Minnesota and federal law, not legal advice. Reading it does not create an attorney–client relationship with Madgett Law, LLC. No outcome is promised or implied.