
Maryland’s New Deepfake Fraud Law
Effective October 1, 2026, Maryland has amended its identity fraud law to address fraudulent uses of artificial intelligence (AI). The identity fraud statute now provides imposition of criminal and civil penalties for individuals who use AI for “deepfakes.” When a bad actor deploys a convincing imitation of a business owner’s voice or of an employee’s image, real damage can be done, and this can put a small business at risk of financial loss.
What Qualifies as a Deepfake Representation?
The new law addresses specific misconduct involving AI. A “deepfake representation” is defined as “a photograph, a film, a video, an audio recording, a digital image, a picture, or a computer or computer-generated image or picture, whether made, produced, or generated by electronic, mechanical, or other means, that is indistinguishable from an actual and identifiable human being.” Drawings, cartoons, sculptures, and paintings are excluded. This law protects small businesses from fraudsters who impersonate an owner, employee, customer, or vendor by punishing fraudulent conduct. For a small business that is a victim of deepfake misrepresentations, the damage can be very costly.
What Conduct Does the Law Prohibit?
A person may not knowingly, willfully, and with fraudulent intent use AI or a deepfake representation to cause harm to another person by impersonating, falsely depicting, or claiming to represent that person or someone else. The statute defines “harm” to include physical injury, serious emotional distress, and economic damages. It also prohibits using AI or a deepfake representation to create or distribute false records with the intent to cause harm, induce someone to provide personal identifying information, or obtain a benefit, credit, good, service, or other thing of value. The intent of the fraudster matters. Ordinary business use of AI is not prohibited.
Criminal Penalties and Civil Remedies
The criminal penalties for engaging willfully in deepfake representations can carry up to five years in prison, a fine up to $10,000, or both if there is one victim, or up to 10 years in prison, a fine up to $15,000, or both, if there are two or more victims. The statute also provides a victim of deepfake representation with a civil cause of action against the fraudster. The legislature granted the courts broad authority to issue any other appropriate relief to the victim, in addition to an injunction, if necessary. In certain situations, a court may award reasonable attorney’s fees to the victim.
How Businesses Can Reduce the Risk of Deepfake Fraud
One of the drawbacks for businesses of AI in the marketplace is its ability to impersonate humans. To avoid being a victim of deepfake representation, business owners should establish systems to verify a person’s identification and authorization before engaging with others in marketing and communications. Examples include confirming payment changes, wire instructions, and requests for sensitive information through a phone number rather than through an online request. A business should also require more than one method of approval for any suspicious transfers. Owners should train employees to verify an individual’s identity and not rely solely on one’s voice or image. Employees should also save any suspicious messages or recordings. Regular business practices can thwart a fraudster’s plan, even with a sophisticated AI deepfake.
Seeking Legal Advice After a Loss
A business that suffers a loss should seek advice about which remedies are available to it. None of the information provided in this article constitutes legal advice. Every situation is different and should be thoroughly reviewed by and discussed with your legal advisors. Please do not rely on the contents of this article as a basis for making decisions regarding your situation. Please call us to schedule a consultation at (410) 489-1996.
