Skip to main content

Generative AI has changed the economics of deception. What once required advanced visual-effects expertise can now be produced with consumer-facing tools, cloud-based inference, and an internet connection. That shift matters most where the harm is both intensely personal and instantly scalable: nonconsensual intimate deepfakes. Michigan’s Protection from Intimate Deep Fakes Act, enacted as Act 11 of 2025 and effective August 26, 2025, is one of the clearest examples of a modern state legislature trying to respond to that reality with a framework that is not limited to criminal punishment alone. Instead, the statute pairs civil remedies with criminal penalties and, just as importantly, draws lines around when technology providers and developers will and will not be exposed to liability. ¹

Please note this blog post should be used for learning and illustrative purposes. It is not a substitute for consultation with an attorney with expertise in this area. If you have questions about a specific legal issue, we always recommend that you consult an attorney to discuss the particulars of your case.

That combination makes Michigan law worth studying closely. Many deep-fake laws focus on a single setting, such as elections, fraud, or explicit images. Michigan’s statute addresses a narrower but especially serious category: deepfakes that realistically depict intimate parts or sexual acts without consent and in circumstances likely to cause harm. In doing so, it does more than prohibit bad acts by bad actors. It also signals how lawmakers increasingly think about accountability in the AI stack. The creator or disseminator remains the primary target, but providers and developers do not receive an unlimited safe harbor. Their protection depends on how the technology is designed, marketed, deployed, and governed through terms of service. ¹ ²

That feature is what makes Michigan act especially instructive for lawyers, platforms, model developers, enterprise adopters, and governance teams. The law does not treat all infrastructure actors alike. It preserves familiar protections for transmission infrastructure and access providers, while giving technology creators a carve-out that is conditional rather than absolute. The condition is not merely formal compliance. It asks whether the product is designed for wrongful use, marketed for wrongful use, deployed for wrongful use, and whether explicit deepfake content is prohibited under the provider’s or developer’s terms of service. In other words, the law tells the market that governance is not a press release. Product decisions, distribution choices, and user rules can all become legally consequential facts. ¹

At a policy level, Michigan’s approach also reflects a broader legal trend. In 2024 and 2025, state and federal policymakers increasingly moved away from treating deepfakes as a novelty problem and toward treating them as a category of concrete, actionable harms. The federal TAKE IT DOWN Act created a national prohibition on certain nonconsensual intimate imagery publication and imposed notice-and-removal duties on covered platforms, while the U.S. Copyright Office separately concluded that unauthorized digital replicas expose genuine legal gaps that likely require targeted legislative responses. Michigan’s statute fits squarely within that movement, but it does so through a distinctly state-law blend of tort remedies, venue rules, confidentiality protections, and criminal exposure. ³ ⁴ ⁵

The statute begins with definitions that are broader and more technologically realistic than casual summaries of “fake porn” would suggest. Michigan defines a “deep fake” to include not only video or images, but also sound recordings and technological representations of speech or conduct that are substantially derivative of an existing recording, film, image, or photograph, provided the result is realistic enough that a reasonable person would believe it depicts the individual and the production depends substantially on technical means rather than mere human impersonation. A “depicted individual” is someone identifiable by face, likeness, or another distinguishing characteristic, and dissemination includes distribution to one or more people other than the depicted person or publication by a publicly available medium. Those definitions matter because they show the legislature was not drafting solely for one app, one format, or one technical workflow. It was drafting for an evolving class of synthetic media that can migrate across modalities and platforms. ¹

The civil cause of action is built around harm, realism, and identifiability. A depicted individual, or someone representing that individual, may sue a person for the nonconsensual creation or dissemination of a deep fake when the defendant knew or reasonably should have known that the creation, distribution, or reproduction would cause physical, emotional, reputational, or economic harm, or when the deepfake was created or disseminated to harass, extort, threaten, or cause such harm. The statute then requires that the deepfake realistically depict the person’s intimate parts or the person engaging in a sexual act, and that the depicted individual be identifiable either from the deepfake itself or from personal information displayed in connection with it. This structure is significant because Michigan did not make mere falsity alone the centerpiece. The statute is targeted to a specific form of intimate synthetic abuse tied to recognizable injury and identifiable victimization. ¹

That focus on identifiability deserves special attention. Deepfake disputes can turn on whether the target is “really” the person or just resembles the person. Michigan’s law addresses that problem directly by allowing identifiability to be shown either from the deepfake itself or from contextual personal information displayed with it. For litigators, that means the evidentiary picture is not limited to the pixels or audio file. Captions, usernames, profile tags, surrounding posts, and accompanying metadata may all matter. In practice, many harmful deepfakes are not deployed as free-floating artifacts; they are embedded in a social or platform context that makes the victim obvious to a reasonable viewer. Michigan’s drafting recognizes that reality and reduces the ability of wrongdoers to hide behind the argument that a synthetic depiction was merely suggestive rather than identifiable.¹

The law is also procedurally victim-conscious in ways that should not be overlooked. A cause of action accrues when the depicted individual discovers that the deepfake has been created or disseminated. Venue is available in the county where either party resides or where the deepfake was produced, reproduced, or stored. Most notably, the court must allow confidential filings to protect the plaintiff’s privacy and may grant injunctive relief to maintain confidentiality through the use of a pseudonym. That procedural architecture reflects a basic truth about image-based abuse litigation: forcing victims to expose themselves publicly in order to seek relief can reproduce the very harm the law is meant to address. Michigan’s statute tries to lower that barrier by making privacy protection part of the remedial design rather than an afterthought. ¹

Consent is another area where the act is more precise than many public discussions assume. The statute makes clear that it is not a defense that the depicted individual consented to creation, possession, or even private or public transmission of the deepfake unless the consent appears in a plain-language agreement knowingly and voluntarily signed by the depicted individual, and unless that consent includes a general description of the intimate digital depiction and, where relevant, the audiovisual work into which it will be incorporated. The same approach appears in both the civil and criminal provisions. This is a major drafting choice. Michigan is effectively rejecting vague or implied-consent theories in a context where coercion, confusion, and after-the-fact rationalization are common. It insists on documented, informed, and reasonably specific consent. ¹

That requirement has immediate implications for adult-content platforms, studios, creators, AI tool vendors, and any business experimenting with synthetic likeness workflows. Boilerplate, buried clickwrap, or broad rights language may not carry the day if it does not specifically and plainly address the intimate digital depiction at issue. Nor does the statute appear interested in allowing a defendant to bootstrap consent from a prior lawful image, a prior relationship, or a prior non-intimate digital use. The law’s logic is transactional and contextual: consent must be knowing, voluntary, in writing, in plain language, and descriptive enough to tell the depicted individual what intimate synthetic use is being authorized. Businesses that have historically treated consent as a generic platform function should expect courts and regulators to look more skeptically at that posture in the deepfake setting. ¹

Michigan also includes a set of defenses and exclusions that illustrate the legislature’s effort to separate abusive conduct from legitimate public, legal, and investigative activity. The statute recognizes defenses or non-applicability where the creation or dissemination is for a lawful criminal investigation or prosecution, for reporting unlawful conduct, in the course of seeking or receiving medical or mental health treatment with protection against further dissemination, for certain matters of public interest and lawful public purpose, or for legal proceedings consistent with civil-justice practice or protected by court order. In the civil context, the public-interest defense is narrower than a casual “newsworthiness” label might imply. The statute requires not only lawful public purpose and public-interest subject matter, but also clear identification that the item is a deepfake and good-faith efforts to prevent further dissemination. Michigan thereby tries to preserve legitimate speech without allowing “public interest” to become an all-purpose cloak for sexualized deception. ¹

The damages provision reinforces that the civil action is meant to be practical, not symbolic. A prevailing plaintiff may recover economic and noneconomic damages, including financial losses and damages for mental anguish, embarrassment, and humiliation. The plaintiff may also recover profits made from the creation or dissemination of the deepfake, plus actual court costs, fees, and reasonable attorney fees. On top of that, courts may enter temporary restraining orders or permanent injunctions to prevent further harm and may award a civil fine of up to $1,000 per day for violation of an order. This matters because deepfake harms are not confined to a single snapshot in time. The injury can continue through reposting, monetization, reputational persistence, and algorithmic recirculation. Michigan’s remedial framework responds to that ongoing quality by combining compensatory recovery, disgorgement, fee shifting, and injunctive enforcement. ¹

From a plaintiff-side perspective, that remedial structure makes the law more usable than statutes that offer a theoretical cause of action but no realistic path to prosecute it. Attorney-fee recovery is especially important in cases involving image-based abuse because the harm may be profound even when the plaintiff’s readily measurable economic damages are modest. Fee shifting can therefore change the economics of enforcement and make representation feasible in cases where the principal injuries are emotional, reputational, and dignitary. Disgorgement of profits also matters because many deepfake schemes are commercial, whether through subscriptions, advertising, traffic generation, pay-per-view access, or the sale of tools designed to produce sexualized synthetic outputs. Michigan’s act recognizes that a wrongdoer should not be allowed to keep the proceeds of an abuse economy simply because victim damages are difficult to quantify with precision. ¹

The criminal side of the statute follows a similar logic but introduces aggravating factors that reveal what the legislature regarded as especially culpable. Intentional creation or dissemination of a qualifying deepfake is generally a misdemeanor punishable by up to one year in jail, a fine of up to $3,000, or both. The offense becomes a felony punishable by up to three years’ imprisonment, a fine of up to $5,000, or both where the depicted individual suffers financial loss, where the actor intends to profit, where the actor maintains an online service or application for the purpose of creating or disseminating the deepfake, where the actor posts the deepfake on a website, where the actor acts with intent to harass, extort, threaten, or cause harm, or where the actor has a prior conviction under the section. Michigan is therefore not criminalizing merely at the margin; it is grading the offense according to monetization, platformization, repeated misconduct, and malicious purpose. ¹

The felony triggers tell a broader story about how lawmakers now understand scale. A deepfake created privately and never shared is one thing; a deepfake fed into a website, app, or other online service designed to create or distribute such material is another. By elevating conduct tied to websites, online services, online applications, or mobile applications, Michigan identifies organized or systematized exploitation as more serious than isolated misconduct. That choice has practical importance for founders, marketplace operators, affiliate marketers, and any intermediary whose business model profits from synthetic explicit content involving real people. The statute is not only aimed at the user who uploads a file. It is aimed at the actor who builds or maintains a digital environment for that abuse to occur. ¹

This brings us to the most consequential feature of the statute for the AI and platform ecosystem: the liability carve-outs. In the civil provisions, sections 3 through 6 are not to be construed to impose liability on interactive computer services, public mobile or private radio service providers, telecommunications networks, or broadband providers for providing transmission infrastructure or access to content created by another person. Those entities are familiar categories, and their protection is consistent with long-standing instincts against converting basic communications infrastructure into general publishers or guarantors of user content. But Michigan then adds another category: a provider or developer of technology used in the creation of a deepfake. That is where the statute becomes especially modern. ¹

The provider or developer carve-out, however, is conditional. The technology must not be designed for, marketed for, or deployed for the nonconsensual creation or dissemination of deepfakes that realistically depict intimate parts or sexual acts, and the provider or developer must have prohibited explicit deepfake content in accordance with its terms of service. The criminal section contains parallel language, making clear that the section should not be construed to impose liability on those entities when those conditions are met. The carve-out therefore behaves less like unconditional immunity and more like a conduct-sensitive shield. A company gets the benefit only if its product and governance posture are aligned against the prohibited conduct. ¹

Each of the four conditions in that carve-out deserves separate attention. “Designed for” invites scrutiny of core functionality, default settings, user flows, training objectives, and whether the product is built to facilitate sexualized likeness manipulation of real persons without consent. “Marketed for” turns promotional language, landing pages, affiliate campaigns, app store descriptions, influencer partnerships, and even meme-driven growth tactics into potentially probative evidence. “Deployed for” reaches beyond the abstract features of the tool and into real-world implementation choices, including what customer segments are targeted, what use cases are emphasized, and what friction or safeguards exist at the point of use. Finally, the terms-of-service requirement makes written policy an express part of the liability analysis, but only as one part. Terms alone are not enough if the product is otherwise built, promoted, or rolled out in ways that contradict the statutory conditions. ¹ ²

That is the central lesson of the Michigan statute: governance must be legible in product behavior, not just legal drafting. A provider that says “misuse is prohibited” while simultaneously advertising face-swap pornography, one-click nudification, celebrity-sex simulations, or “revenge” use cases would face obvious difficulty arguing that its technology was not marketed for or deployed for nonconsensual intimate deepfakes. Likewise, a provider that nominally bans explicit deepfake content but makes no operational effort to detect, deter, or respond to such use may find that its terms of service look more ornamental than substantive. Michigan’s act does not expressly spell out a compliance checklist, but its language points toward one. Product governance, trust-and-safety enforcement, content policy, moderation escalation, abuse reporting, and vendor diligence all become part of the liability story. ¹

For enterprises purchasing or integrating generative tools, the statute also reshapes procurement and risk allocation. A company using third-party image, video, or audio generation technology in a consumer-facing environment should not assume that upstream AI branding is enough. It will matter whether the vendor’s tool is architected to resist abusive sexualized use, whether its public positioning invites misuse, whether its deployment controls are meaningful, and whether its terms clearly prohibit explicit deepfake content. Contracting parties may increasingly insist on representations about model safeguards, prohibited-use enforcement, complaint handling, logging, and rapid response procedures for synthetic intimate imagery. Michigan’s law does not govern every procurement clause, but it makes those clauses easier to justify because the statutory language itself links liability protection to operational posture. ¹

The act also avoids a common drafting mistake by preserving other remedies. Section 7 states that liability under sections 3 through 6 does not affect any other remedy available under law, and section 9 confirms that the act does not affect the ability to bring a civil action under any other law or to prosecute under any other law. That means the Michigan statute should be read as additive, not exclusive. Plaintiffs may still explore claims arising under other privacy, harassment, defamation, consumer protection, employment, or tort theories where the facts support them, and prosecutors may look to other criminal statutes as well. This is another sign that Michigan treats intimate deepfake abuse as a serious category of harm that intersects with, rather than replaces, traditional legal doctrines. ¹

In that sense, the Michigan law is not just a cause of action; it is a legal framing device. It tells courts and litigants that intimate deepfakes are neither harmless parody nor an exotic species of speech immune from ordinary legal consequence. They are a form of technologically mediated abuse that can inflict reputational, emotional, physical, and economic injury. By naming the harms and building procedural privacy protections around them, the statute gives victims and courts a vocabulary for dealing with a problem that has too often outpaced older categories. It also gives defendants less room to argue that synthetic falsity makes the injury less real. Under Michigan’s statute, the falsity is part of the wrong, not a reason to discount it. ¹

Michigan’s approach also shows how state law can complement federal developments without waiting for a full national AI liability code. The federal TAKE IT DOWN Act addresses nonconsensual intimate imagery through a national prohibition and a platform notice-and-removal mechanism enforced by the FTC, including AI-generated imagery. Michigan, by contrast, offers a state-level private right of action, fee shifting, venue provisions, confidentiality measures, and criminal penalties tailored to specific aggravating factors. The two approaches are different, but they are not in tension. They reflect a layered compliance environment in which a platform or developer may face overlapping obligations from federal takedown rules, state civil claims, and state criminal law. ³

For organizations, the practical takeaway is straightforward. If a product can generate or materially facilitate synthetic likeness content, especially sexualized content involving real persons, Michigan’s act is a warning against passive compliance. Leaders should ask whether the product design affirmatively discourages abusive outputs, whether marketing language could be read as inviting nonconsensual intimate use, whether deployment choices create foreseeable misuse channels, whether terms of service clearly prohibit explicit deepfake content, and whether those terms are actually enforced. Those questions are no longer merely reputational or ethical. In Michigan, they may shape whether a provider or developer can claim the benefit of the statute’s carve-out at all. ¹

For litigators, the statute suggests new discovery fronts. Expect disputes over product roadmaps, content moderation data, internal abuse reports, investor decks, prompt libraries, promotional copy, creator partnerships, community forums, demo environments, and archived versions of terms of service. Expect plaintiffs to argue that “design,” “marketing,” and “deployment” are fact-rich concepts that cannot be resolved by a defendant’s self-description alone. Expect defendants to emphasize their general-purpose architecture, their explicit prohibitions, and their abuse-mitigation systems. Michigan has effectively written product-governance facts into the liability analysis, and that means the courtroom battle may start well before the content at issue itself. ¹ ²

For judges and policymakers outside Michigan, the statute offers a valuable model because it avoids two extremes. It does not place all blame on end users while ignoring product incentives and distribution choices. But it also does not treat every infrastructure or AI actor as strictly liable whenever harmful user content appears. Instead, it calibrates responsibility by role and by conduct. Transmission and access providers remain protected for basic infrastructure functions. Providers and developers of relevant technology can also be protected, but only when the technology is not built, sold, or rolled out for the forbidden conduct and when explicit deepfake content is prohibited by terms of service. That may prove to be one of the most durable contributions of the statute: it translates abstract debates about “AI accountability” into concrete legal questions about how a product is made, presented, launched, and governed. ¹

The deeper lesson is that intimate deepfakes are forcing the law to confront a more general truth about generative systems. Capability and misuse cannot always be separated after the fact. Sometimes the misuse is foreseeable because it is embedded in the product’s architecture, messaging, or deployment context. Michigan’s Protection from Intimate Deep Fakes Act recognizes that without collapsing into a blanket anti-innovation rule. It leaves room for general-purpose tools, legitimate public-interest uses, lawful proceedings, and core infrastructure services. But it also sends a clear signal that the companies seeking legal distance from abusive conduct must earn that distance through the choices they make before harm occurs. ¹ ⁴

As the synthetic-media regulatory map continues to develop, Michigan’s 2025 statute will likely matter beyond its borders. It is concise, targeted, and operationally revealing. For victims, it supplies a more usable pathway to relief. For wrongdoers, it raises the cost of creation, dissemination, and monetization. For providers and developers, it underscores that liability analysis may increasingly turn on design, marketing, deployment, and enforceable platform rules rather than on abstract claims of neutrality. And for everyone else working in AI governance, the act offers a durable proposition: in the age of deepfakes, responsibility is no longer just about what content exists, but about who made it possible, how they made it possible, and what they did to prevent the most foreseeable forms of abuse. ¹ ² ³ ⁴ ⁵

Contact Tishkoff

Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).

Sources

1- Michigan Compiled Laws, Act 11 of 2025, Protection from Intimate Deep Fakes Act, Sections 752.382 through 752.389; effective August 26, 2025. https://www.legislature.mi.gov/documents/mcl/archive/2025/September/mcl-Act-11-of-2025.pdf

2 -Michigan Senate Fiscal Agency, Bill Analysis for House Bill 4047, Protection from Intimate Deep Fakes Act, 2025. https://www.legislature.mi.gov/documents/2025-2026/billanalysis/Senate/pdf/2025-SFA-4047-S.pdf

3- Federal Trade Commission, Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act, summary of the TAKE IT DOWN Act. https://www.ftc.gov/legal-library/browse/statutes/tools-address-known-exploitation-immobilizing-technological-deepfakes-websites-networks-act-take-it

4- U.S. Copyright Office, Copyright and Artificial Intelligence, Part 1: Digital Replicas, published July 31, 2024; Copyright Office AI initiative materials. https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-1-Digital-Replicas-Report.pdf

5- National Conference of State Legislatures, Deceptive Audio or Visual Media (Deepfakes) 2024 Legislation.  https://www.ncsl.org/technology-and-communication/deceptive-audio-or-visual-media-deepfakes-2024-legislation

This publication is for general informational purposes and does not constitute legal advice. Reading it does not create an attorney-client relationship. You should consult counsel for advice on your specific circumstances.