Imagine a commercial in which a famous actor promotes a product: we recognize his face, hear his voice, and have no reason to doubt its authenticity. There is, however, one significant detail: that actor never filmed the commercial, never spoke those words, and never authorized the campaign, as the content was created using artificial intelligence.
In all such cases, where digital content (video, photos, or audio) is created using AI systems to realistically mimic the faces, voices, and movements of real people without their consent, the term “deepfake” is used.
This phenomenon, which is becoming increasingly widespread in the digital age, raises a series of legal issues that should not be underestimated; the first is undoubtedly the falsity of the digital content in question and its consequent ability to deceive users regarding its authenticity. The more convincingly the AI system makes the content appear authentic, the greater the risk that the public will be deceived.
There is also a second legal issue concerning the image and identity of the “falsely” depicted individual, specifically, the limits within which that individual has the right to prevent certain unauthorized uses of their image.
In our legal system, as is well known, the right to one’s image derives primarily from Articles 96 and 97 of Law No. 633/1941, which govern the use of portraits and generally provide that their display, reproduction, or commercialization requires the consent of the person depicted, subject to the exceptions provided by law.
This protection is complemented by Article 10 of the Civil Code, which governs the right to one’s image – understood as a personality right – and safeguards the interest in deciding how one is portrayed, allowing the individual concerned to seek the cessation of the misuse of their image and compensation for damages.
With deepfakes, however, a particularly sensitive issue arises. The protection of one’s image no longer concerns only photographs or footage that has actually been taken: today, a system of artificial intelligence can create a scene from scratch that has never existed and, at the same time, make a real person perfectly recognizable.
It is therefore legitimate to ask whether the right to one’s image is also infringed in these cases, that is, when the content or portrait is purely artificial. The answer to this question is by no means straightforward, as there are certain exceptions that will be discussed below; generally speaking, it can be stated that if the photograph or video created by the AI system allows a person to be clearly identified and depicts them in a specific context without their consent, then this would constitute unauthorized use of their identity and, therefore, a violation of their image rights, with all the resulting consequences.
The alleged infringement would be even more evident if the content created by AI were used for commercial purposes; making a well-known figure appear as a spokesperson for a product means exploiting that person’s fame and suggesting to the public the existence of a commercial agreement between the company and the spokesperson, an agreement that, in reality, does not exist.
The harm caused by this practice is not necessarily limited to economic damage. A deepfake can, in fact, attribute to a person statements they never made, actions they never took, or situations they never experienced. In such cases, in addition to the infringement of the right to one’s image, there would also be violations of the reputation and other personality rights of the person involved.
Given the increasingly widespread nature of this phenomenon, the European legislator was compelled to intervene and thus issued EU Regulation 2024/1689 (AI Act), which – as far as is relevant here – introduced specific transparency requirements regarding content generated or manipulated by artificial intelligence systems, including “deepfakes”; in particular, this Regulation imposes a duty to inform the end user that the content has been artificially generated or manipulated. It should be clarified that these obligations fall on so-called “deployers,” that is, the entities or organizations that use an artificial intelligence system under their own authority, including specifically for the purpose of creating deepfakes.
The legislator has thus sought, on the one hand, to protect the end user by preventing them from being deceived by artificial content and, in part, by the subject who is falsely represented where the Regulation prohibits the reproduction of content depicting that subject’s private parts or sexual acts in which the subject is involved; on the other hand, however, the Regulation itself did not go so far as to declare deepfakes unlawful and invalid as such.
Indeed, the aforementioned Regulation, in its preamble, provides that transparency obligations are limited with respect to content that is clearly creative, satirical, artistic, or fictional, provided that the artificial origin is disclosed in a manner that does not hinder the enjoyment of the work. A significant case is the Decision No. 577 of July 23, 2026, issued by the Italian Data Protection Authority, concerning the use of a deepfake featuring Enrico Mentana on the program “Striscia la Notizia”. On that occasion, the Authority clarified that satire falls within the scope of freedom of expression and that the use of artificial intelligence for satirical purposes is not, in and of itself, unlawful.
In the case examined, however, the high degree of realism in the manipulation -achieved through the use of Mentana’s real image and the alteration of his voice – did not make the artificial nature of the content immediately apparent. Therefore, according to the Authority, these characteristics made the manipulation capable of creating a risk of disinformation, and it therefore found that the principles of lawfulness, fairness, and transparency set forth in Article 5 of the GDPR had been violated.
The case analyzed above thus highlights a practical issue: for particularly realistic content, a disclaimer that is barely visible or not sufficiently clear may not be enough to prevent the public from mistaking the artificial representation for an authentic one.
The national legislator has also addressed the phenomenon of deepfakes; specifically, Law No. 132/2025 introduced the new Article 612-quater of the Criminal Code, which punishes with imprisonment of one to five years anyone who, by causing unjust harm to a person, transfers, publishes, or disseminates – without that person’s consent – images, videos, or voices that have been falsified or altered using artificial intelligence systems, when such content is likely to mislead others as to its authenticity.
However, both the Italian and European legislators are entirely silent regarding the civil law aspects of the conduct in question and, therefore, regarding the possible remedies the aggrieved person may pursue to obtain any form of redress, including financial compensation.
In the absence of legislator guidance, it appears reasonable to conclude that the aggrieved party may request the cessation of the unauthorized use of their image and, when the conditions are met, obtain emergency injunctions, in addition to compensation for damages resulting from the infringement of their image, reputation, and other personality rights.
The regulatory framework outlined thus provides only partial protection, given that the European legislator has focused primarily on the transparency of content generated by artificial intelligence and on the need to prevent users from being misled, without, however, establishing under what circumstances the creation and dissemination of a deepfake should be considered, as such, unlawful with respect to the person depicted.
The writes hopes for a more incisive legislative action, aimed not only at ensuring the transparency of content generated by artificial intelligence but also at defining more clearly the limits within which a person’s identity and image may be artificially reconstructed and used. In the absence of more specific regulations, there is indeed a risk that technological advancements will end up unduly restricting an individual’s right to maintain control over their identity and image, as well as preventing the unauthorized dissemination of deepfake content depicting them.