In March 2022, a video appeared on social media purporting to show Ukrainian President Volodymyr Zelensky calling on Ukrainian soldiers to lay down their arms. This fake garnered millions of views in a matter of hours before it became clear that it was a “deepfake.” But this attack affected more than just heads of state: every year, millions of ordinary people – entrepreneurs, bloggers, teachers, students – find that their faces appear in videos or photos they never took. According to the DeepStrike service, the number of generated deepfakes increased from 500,000 to eight million between 2023 and 2025. The technology, which was only used by film studios five years ago, is now available for free to anyone with a laptop. And it can destroy your reputation, career, or personal life – yours or that of someone close to you – for free.
What is deepfake: technical and legal aspects
Most people understand deepfake intuitively: “fake video.” However, in the context of legal protection, it is important to understand more precisely what exactly we are dealing with, because both the qualification of the offense and the construction of a legal protection strategy depend on it.
How deepfake technology works
Deepfake is content (video, audio, photos, or a combination thereof) created or modified using generative neural networks (AI systems that learn from large data sets and generate new content). The most common technique is face swapping. The algorithm analyzes photos of a real person and then overlays their features onto a video with another person so that the result is perceived by the viewer as real. In parallel, voice synthesis is developing - voice cloning based on a recording allows you to generate any audio on behalf of a specific person.
A key point for understanding legal protection: creating a deepfake does not require the consent of a person, nor even direct communication with them. All that is needed is a few dozen public photos and an accessible online service.
Types of deepfake content: video, audio, photo, text
Depending on the technical method of implementation, there are four main types:
- Video deepfake – replacing a face or entire figure in a video. The most common and dangerous format. Used for disinformation, blackmail, pseudo-advertising.
- Audio deepfake – a synthesized voice of a real person. Used for telephone fraud (e.g., a call from the director), extortion, and targeted manipulation.
- A deepfake photo is a static image with altered features or a face placed in a new context.
Each type can be an independent offense or part of a complex manipulation. They are often combined: a fake video is supplemented with fake quotes and distributed via social networks.
The difference between deepfake and regular photomontage
Traditional photomontage is obvious: unnatural lighting, noticeable edges, quality discrepancies. Deepfake reproduces facial details, micromovements, and voice features – and therefore is perceived as real. It is this plausibility that decisively affects the legal qualification: if a regular montage can be perceived as obvious hyperbole or humor, then a realistic deepfake misleads the audience, which automatically increases the degree of harm caused.
In addition, the quality of deepfakes is constantly improving: if in 2019–2020 they could be detected by blinking eyes or unnatural movements, then in 2025–2026 some videos are practically indistinguishable from the real ones even when viewed carefully.
Importantly. Deepfake is not just a “fake celebrity video.” The threat exists for anyone who posts a photo or video online. All it takes is an open social media account.
The right to one's own image in Ukrainian legislation
Ukrainian legislation protects the image of an individual at several levels – from constitutional guarantees to special laws. Depending on the context, reference may be made to the Constitution of Ukraine, the Civil Code of Ukraine, the Law of Ukraine “On Protection of Personal Data”.
Article 308 of the Civil Code: protection of the image of an individual
Article 308 of the Civil Code of Ukraine is the basic norm of protection against unauthorized use of images. It states: a photograph, video, and any other image of an individual may be used only with their consent. The law provides for three exceptions to this rule:
- The person posed for payment, and the use of the image complies with the terms of the relevant contract.
- The image was taken at open public events (rallies, concerts, exhibitions), and the person is part of the general appearance of the crowd, not an isolated subject of the shooting.
- The person is a public figure and the image is used in a socially significant, not commercial or entertainment context.
Deepfake generally falls under none of these exceptions: it places a person in a context they have never been in and creates the impression of events that never happened.
Article 307 of the Civil Code: protection of the right to privacy
Article 307 of the Civil Code prohibits the collection, storage and dissemination of information about a person's private life without their consent. This applies to deepfake scenarios as follows: if a fake video depicts a person in an intimate setting, in a home environment or in situations related to their private or family life, not only the right to an image is violated, but also the right to privacy. The combination of the two grounds significantly strengthens the plaintiff's position in court.
Law "On Personal Data Protection": biometric data
Facial images are biometric personal data within the meaning of the Law of Ukraine “On Personal Data Protection”. Any processing of such data (collection, storage, transfer, publication) requires the explicit consent of the person or a legal basis defined by law. Persons who collect photos for training a neural network or use other people's images in services for deepfake synthesis without permission violate the requirements of this law. The sanction is a fine of up to UAH 34,000 for individuals and up to UAH 170,000 for legal entities.
Constitutional right to honor, dignity and business reputation
Article 28 of the Constitution of Ukraine guarantees everyone the right to respect for their dignity and prohibits any humiliation. Article 32 expressly prohibits the collection, storage and dissemination of confidential information about a person without their consent, and also guarantees the right to refute false information. These constitutional norms form the legal framework within which the entire mechanism of protection operates - from civil lawsuits to criminal proceedings.
What actions with deepfake are considered a crime?
Creating a deepfake without the person's consent
The very fact of creating a deepfake with an image of a real person without their permission may be a violation of Art. 308 of the Civil Code. At the same time, there is an area of legal uncertainty: artistic satire and parody may be permissible if the content clearly does not claim to reflect real events, does not cause reputational damage, and does not mislead the audience about the actions of the person.
But the line is thin. A deepfake, where a public figure “speaks out” in support of a product, party, or idea, is no longer satire, but manipulation. If the goal is to make the audience laugh, the content is clearly fictitious and signed as a parody, the limits of liability are different from a situation where the goal is to mislead.
Spread of fake content on social media
Responsibility lies not only with the author, but also with the one who spreads a deepfake, knowing that it is fictitious. Reposting, sharing, forwarding in messengers - all this can be qualified as intentional dissemination of false information. Ignorance of the fictitiousness of the content is a basis for reducing or excluding liability, but the court will assess whether the spreader had reason to doubt the authenticity of the material.
Using deepfake for commercial purposes
If someone else's image or voice is used for advertising, brand promotion, or any monetized content, this is a direct violation of Article 308 of the Civil Code and, at the same time, unfair competition in accordance with the Law "On Protection against Unfair Competition." The amount of compensation here is higher: in addition to moral damage, illegally obtained commercial benefits are added, which the court may recover in favor of the plaintiff.
Sexually colored deepfake (deepfake porn)
The most serious type of violation. Placing a person in a sexual context without their consent is a gross violation of dignity, which can be classified as a set of criminal offenses - under Art. 182 of the Criminal Code of Ukraine (violation of privacy) and Art. 301 of the Criminal Code of Ukraine (distribution of pornographic materials). The maximum penalty is up to 3 years of imprisonment. If the victim is a minor, the liability increases significantly: up to 6 years of imprisonment under Art. 301-1 of the Criminal Code of Ukraine.
Important detail: Criminal liability arises not only for distribution, but also for storage and transfer of such content to third parties, even in private correspondence. Victims of deepfake porn, within the framework of criminal proceedings, have the right to compensation for moral damage, the amount of which in such cases is traditionally determined by courts to be above average.
Deepfake in political and information manipulation
In the conditions of a full-scale war, this category becomes especially dangerous. Fake video messages from commanders, fake statements from officials, fabricated information about the course of hostilities — all this can lead to criminal liability under Article 114-2 of the Criminal Code (dissemination of false information during martial law, up to 8 years of imprisonment), Article 111 of the Criminal Code (high treason), and in some cases, under the norms on sabotage.
Types of liability for using someone else's image
Civil liability: compensation for moral damage
A civil lawsuit is the most common and flexible tool of protection. It allows you to obtain compensation regardless of whether a criminal offense is involved.
Basic algorithm:
- Establish the fact of the violation and record the evidence.
- Identify the defendant: the deepfake author, the distributor, or the platform that refused a justified removal.
- Draft a statement of claim with the following requirements: removal of content, public refutation, compensation for moral and material damage (if any).
- File a lawsuit with the general court at the place of residence of the plaintiff or defendant.
The amount of compensation for moral damage in Ukraine is determined by the court individually, based on the severity of the violation, the number of views of the fake content, the duration of its stay on the network and the real consequences for reputation, career and personal life. As a general rule, the amount of compensation is from 30,000 UAH. and higher, depending on the circumstances. The greater the audience reach and the longer the content was available, the higher the amount can be reasonably requested from the court.
To substantiate the amount of moral damage, we recommend:
- record the number of views, likes and reposts;
- save screenshots of comments confirming reputational damage;
- obtain an opinion from a psychologist or psychiatrist regarding experiences and stress;
- Include testimonies from loved ones about changes in their attitude towards you.
If the deepfake has led to real property losses (dismissal, termination of contract, reduction in income), it is advisable to demand compensation for property damage with documentary evidence.
Administrative liability: when applicable
Administrative liability may arise in cases where the violation does not constitute a criminal offense, but is recorded and obvious. Basic norms:
- Article 173-1 of the Code of Administrative Offenses – spreading false rumors that may cause panic among the population or disrupt public order: a fine of UAH 170 to 255 or correctional labor for a term of up to one month with a deduction of twenty percent of earnings.
Criminal liability: when deepfake becomes a crime
Criminal prosecution is possible if one or more elements of the crime are present:
- Article 182 of the Criminal Code – violation of privacy: fine up to UAH 17,000 or up to 3 years of imprisonment.
- Article 190 of the Criminal Code – fraud using deepfake (for example, a call from a manager asking to transfer funds): fine up to UAH 51,000 or up to 3 years of imprisonment.
- Article 129 of the Criminal Code – threat of murder or infliction of grievous bodily harm using deepfake: probationary supervision or restriction of liberty for up to two years.
- Article 163 of the Criminal Code – violation of the secrecy of correspondence or private messages: fine up to 1700 UAH or up to 3 years of imprisonment.
Comparative table of types of liability
| Type of violation | Article | Sanction | Limitation period |
| Publishing a deepfake without consent | Article 308 of the Civil Code | Compensation for damages, removal of content | 3 years |
| Privacy violation | Article 182 of the Criminal Code | Fine up to 17,000 UAH or up to 3 years of imprisonment | 3 years |
| Unlawful processing of personal data | Article 44-1 of the ZPD | Fine up to 170,000 UAH | 1 year |
| Deepfake fraud | Article 190 of the Criminal Code | Up to 12 years in prison | 15 years |
| Threats through deepfake | Article 129 of the Criminal Code | Up to 5 years in prison | 5 years |
| Deepfake in wartime | Article 114-2 of the Criminal Code | Up to 8 years in prison | 10 years |
| Deepfake porn (adult) | Art. 182, Art. 301 of the Criminal Code | Up to 3 years in prison | 3 years |
| Deepfake porn (underage) | Art. 182, Art. 301-1 of the Criminal Code | Up to 10 years in prison | 15 years |
What to do if your image was used in a deepfake
Step 1. Capture evidence: screenshots, specialist review, expert examination
First of all, you need to record the fact that the content existed before it was deleted. A standalone screenshot may be rejected as evidence by the court, as it can be easily forged. More reliable options:
- Website review by a specialist – a specialist reviews the page in real time and creates a report indicating the URL, date, time, and content.
- Police inspection report – if you contact law enforcement immediately, they will record the content themselves in a procedural manner.
- Computer forensics – confirms the fact of forgery and establishes the metadata of the file, including the time and software used for generation.
In parallel, store indirect evidence: messages from third parties with a link to the deepfake, saved copies of pages (web.archive.org), screenshots with visible timestamps and URLs.
Step 2. How to remove a fake video from the platform
Most major platforms have a complaint mechanism for deepfake content:
- Facebook/Instagram: Report → This is misinformation or Report → Nudity/sexual acts. Meta also has a separate form for reporting fake images of your face.
- TikTok: Report → Content spreading misinformation → Deepfake or altered media.
- YouTube: Report → Disinformation → Misleading content.
- Telegram: complaint via @notoscam or direct contact with the channel administrators.
At the same time, send a written request to the account owner to remove the content — by registered mail or email with delivery confirmation. This document confirms to the court that you have exhausted out-of-court settlement options.
Step 3. Contact the police and cyber police
If a deepfake contains signs of a criminal offense (threats, intimate content, fraud, disinformation) - contact the police or directly the Cyberpolice Department (cyberpolice.gov.ua).
The application must contain:
- your personal data and contacts;
- description of the circumstances of the deepfake detection (when, where, under what conditions);
- links to content or printed and certified evidence;
- a specific description of the damage caused;
- request to conduct a pre-trial investigation under the relevant articles of the Criminal Code.
Cyber police are authorized to send official requests to platforms within the framework of international agreements — and to establish IP addresses and personal data of authors much more effectively than private individuals.
Step 4. Filing a civil lawsuit
The statement of claim to the court must contain:
- Plaintiff: your full details and contacts.
- Defendant: The author of the deepfake (if known) or the platform that received a reasoned request to remove the content and refused.
- Subject of the lawsuit: violation of Articles 308, 307 of the Civil Code, the Law "On Personal Data Protection".
- Requirements: removal of content; public refutation; compensation for moral damages (specify the specific amount); compensation for property damage (if any); prohibition on using your image in the future.
- Evidence: notarized inspection, forensic expert opinion, written requirements for the platform, eyewitness testimony.
Court fee: 1% of the claim price, but not less than 0.2 and not more than 10 times the subsistence minimum.
Step 5. Appeal to the Commissioner for Human Rights and other bodies
If law enforcement agencies are inactive or the legal process is delayed, use additional levers:
- The Verkhovna Rada Commissioner for Human Rights (ombudsman.gov.ua) - in case of violation of constitutional rights and/or inaction of state bodies.
- Commissioner for Personal Data Protection (acts as part of the Ombudsman) - if the legislation on the processing of personal data is violated.
- Antimonopoly Committee - in case of commercial use of the image in advertising or a business context.
Example. In 2023, a Ukrainian businesswoman discovered a deepfake advertisement of her alleged "partnership" with an illegal online casino. A notarized protocol + an appeal to the cyber police allowed the author to be identified in 3 months. The court awarded 150,000 UAH in moral damages and ordered the advertisement to be removed from all platforms.
How to identify the author of a deepfake
Anonymity on the Internet is illusory. Even if the perpetrator hides behind a pseudonym, legal and technical tools allow their identity to be established.
Requests to social networks and hosting providers
Through the court or within the framework of criminal proceedings, you can obtain from the platform the IP address, date of account registration, associated phone number or email. Procedure:
- Submit a court order or investigator's resolution on temporary access to things and documents (Articles 159–166 of the Criminal Procedure Code).
- Send a request to the platform through official law enforcement channels or a lawyer's request based on Article 24 of the Law of Ukraine "On the Bar and Legal Activities".
- Platforms are required to respond within the timeframes established by relevant agreements with law enforcement agencies.
Meta, Google, and TikTok publish annual Transparency Reports with data on the fulfillment of requests from different countries. The level of fulfillment of requests from Ukraine has been steadily increasing since 2022.
Involvement of computer technical expertise
A forensic expert in the field of computer technology can:
- set video file metadata (date, time, software, geolocation);
- identify characteristic traces of a particular generative service or model (for example, specific pixelation artifacts characteristic of certain platforms);
- determine the primary source of distribution and chronology of publications;
- to establish whether a specific person is the subject of a forgery, through comparative analysis with original materials.
The approximate cost of a private examination is from 8,000 UAH. State (appointed by the investigator in criminal proceedings) is free of charge for the victim. The term for the performance of a private examination is from 2 to 6 weeks, depending on the complexity of the material. Please note: the list of forensic experts in the field of computer technologies can be found in the register of the Ministry of Justice of Ukraine.
Global practice of regulating deepfake
Ukraine is not alone in facing this problem. Understanding how other countries are addressing it is useful from both a practical and strategic perspective.
USA: state laws against deepfake
There is currently no federal law against deepfakes in the US, but several states have passed their own legislation:
- California (AB 602, AB 730, 2019) – prohibits deepfakes in pornographic contexts and for the purpose of political influence on elections. AB 602 explicitly allows civil lawsuits against deepfake porn creators for damages of at least $150,000.
- Texas (HB 4337, 2023) – criminalized deepfakes in election manipulation and certain types of financial fraud.
- Virginia is one of the first states to criminalize the distribution of deepfake porn without a person's consent (up to 12 months in prison and a fine of up to $2,500).
At the federal level, the DEFIANCE Act (Disrupt Explicit Forged Images and Non-Consensual Edits Act) was actively discussed in 2024–2025, aimed at criminalizing sexual deepfakes nationwide. American experience shows that the absence of a federal law does not prevent effective protection if there is a will to enforce it and case law.
EU: Digital Services Act and AI Act
The Digital Services Act (DSA), which comes into full force in 2024, obliges major platforms to label AI-generated content and remove it upon reasonable request. The AI Act (coming into force in stages from 2025–2026) establishes: mandatory labeling of synthetic content and a ban on systems that generate material with the aim of deception. Violations can result in fines of up to €35 million or up to 7% of annual turnover.
For Ukraine, as a candidate for EU membership, these norms are a direct reference point for adapting its own legislation.
United Kingdom: Online Safety Act 2023
The UK's Online Safety Act 2023 is one of the world's toughest regulations on deepfakes. It criminalises the distribution of sexual deepfakes without consent - even with the intention of distributing such content without actually distributing it. The penalty is an unlimited fine and/or imprisonment for up to 2 years. Platforms that fail to remove content upon request face fines of up to 10% of annual turnover.
Prospects of Ukrainian legislation
As of April 2026, there is no separate law regulating deepfake in Ukraine. However, the Verkhovna Rada has registered several draft laws in the field of artificial intelligence regulation that directly address this topic.
Bill No. 11264 “On the Principles of the Development of Artificial Intelligence in Ukraine” passed its first reading in 2024. It provides for the labeling of AI-generated content and the liability of AI system developers for harm caused to third parties. Amendments to the Criminal Code regarding the direct criminalization of deepfake porn are at the stage of interdepartmental discussion.
In parallel, as part of the adaptation to EU legislation, Ukraine is obliged to implement the Digital Services Act and AI Act as part of the membership agreement. This means that in the next 2–3 years, the legislative framework in the field of deepfake will change significantly - in particular, there will be requirements for mandatory labeling of synthetic content and direct penalties for platforms.
Until a special law is adopted, protection is provided through the existing legal framework: the Civil Code, the Criminal Code, and the Law on Personal Data Protection. Case law confirms that this framework is generally sufficient for effective protection of rights, provided it is properly applied and provided with qualified legal support.
How to protect yourself from the use of your image
It is impossible to completely eliminate the risk, but it is possible to significantly reduce it today.
Privacy settings on social networks
Specific steps for major platforms:
- Instagram: Settings → Privacy → Private account. Additionally: disable the ability for third parties to download your Stories, limit viewing of tags.
- Facebook: Settings → Privacy → Who can see your posts: Friends only. Turn off facial recognition in your profile settings.
- TikTok: Settings → Privacy → Private Account. Turn off Duet and Stitching – they allow other users to use snippets of your videos.
General advice: Avoid posting high-quality videos from different angles and with neutral backgrounds — this is the material that is most suitable for training a deepfake model. If you are a public figure or content creator, consider registering your own image as a copyrighted object — this is an additional legal tool for protection.
Important. No technical solution provides 100% protection. The most effective weapon is a combination of caution in publications + prompt legal action when a violation is detected.
Why you should watermark photos
A visible watermark will not technically protect against deepfake, but it has two practical effects:
- Evidential value: If a deepfake contains traces of your watermark or the removed watermark is visible in the metadata, this confirms that the image was yours and was used without permission.
- Deterrence effect. Deepfakes are usually looking for “clean” images. A watermark increases their risk of being identified and can divert attention to easier targets.
For additional protection, consider a steganographic watermark – a special code embedded directly into the image pixels and invisible to the eye but readable by software.
Conclusions and recommendations
Deepfake is not a threat of the future. It is already here, already being used against real people, and Ukrainian law already contains protection tools – even without a special law.
The main thing to remember:
- Your image is protected by law regardless of whether you are a public figure.
- Any use of your image without consent is grounds for civil action, administrative or criminal liability of the violator.
- Anonymity on the Internet does not guarantee impunity: deepfake authors are identified and held accountable through requests to platforms and cyber police.
- The most important thing is to capture evidence immediately, before deleting the content.
At the same time, it is worth remembering about prevention: privacy settings on social networks, watermarks on photos, and caution in publications significantly reduce the risk of becoming a victim. But if this has already happened, the legal system has an answer for every level of violation: from a complaint to the platform to criminal charges and millions in compensation.
If you discover a deepfake with your image, don't delay. Contact a lawyer to protect your rights to your image and bring the perpetrators to justice. The sooner you start taking action, the better your chances are of identifying the author, preserving evidence, and receiving fair compensation.
FAQ
Is it possible to make a deepfake of a public figure (meme, satire)?
A satirical deepfake of a public figure may be permissible if it clearly does not claim to reflect real events, does not harm the reputation beyond the limits of permissible criticism, and is clearly labeled as a parody. But even then, the line is very thin. If a “satirical” deepfake contains defamatory statements, intimate subtext, or is used for commercial purposes, legal protection disappears regardless of genre framing.
What to do if the deepfake was created by an anonymous person?
Record the content in a notary public and immediately contact the cyber police. Law enforcement officers can send an official request to the platform to obtain the IP address and other account registration data. In parallel, you can file a civil lawsuit against an unidentified person – “to the person to be identified” – and after identification, clarify the requirements. This mechanism is directly provided for by procedural legislation. Remember that your actions can protect other persons from such abuses and contribute to the prompt identification of the offender.
How long does the legal process take in such cases?
A civil case in the court of first instance usually takes from 3 to 12 months. Criminal proceedings take much longer – from 6 months to several years. Please note: civil and criminal proceedings can be conducted simultaneously – they do not exclude each other, but on the contrary, strengthen the position of the victim. The quality of the evidence collected at the start directly affects the timing.
Can I claim compensation if the deepfake was quickly removed?
Yes, and in full. The fact of removal does not eliminate liability: the violation occurred at the time of publication. For a successful claim, it is necessary to prove the fact of publication itself and the damage caused. This is why it is critical to record evidence before removal - with a notarized inspection or police report.
How to protect a child from deepfake?
First, limit the number of photos of your child in public access and set privacy on all social networks where there are children's images. Second, explain to your teenager that you should not share photos with strangers on the Internet, and generally respond to requests; check the content that the child distributes. Second, if a deepfake with a child's image has already been detected, immediately contact the police or immediately consult a lawyer about the algorithm of actions, as this is a criminal offense with severe sanctions (up to 10 years of imprisonment). Do not try to resolve this on your own or through negotiations with the offender.