/
Unauthorized AI Deepfakes of an Influencer: What Legal Recourse Exists Under EU and Danish Law
Guide
Strategy
Both
An unauthorized AI deepfake of an influencer — a fake video or audio clip that makes it look like they're endorsing a product or saying something they never said — isn't itself banned under the EU AI Act; the Act only requires whoever uses the deepfake to disclose that it's artificial. The real legal recourse sits in GDPR, Danish marketing law and, for the worst cases, criminal law, while a broader Danish shield against unauthorized imitations of appearance and voice (a new § 73a in the Copyright Act) is still awaiting final passage. The fastest practical route is usually the platform's own reporting tools, not the courts.
An unauthorized AI deepfake is a synthetic video or audio clip in which a real, named influencer's face or voice is used to make them appear to say or do something they never actually said or did — without their consent. The typical scenario is a scammer, a competitor, or a bad-faith advertiser using a cloned version of a well-known creator to endorse a product, an investment, or a "secret" discount code the creator was never involved with.
That's different from the two closely related topics already covered on the Academy. AI voice cloning and dubbing of creator content covers a brand that has lawfully hired a creator and cloned their voice with consent to dub content into other languages — the rights question there is already settled, and the article is about the disclosure duty to the viewer. AI and virtual influencers vs human creators covers a fully synthetic persona with no real person behind it, and that article itself states that an unauthorized deepfake of a named, real person "sits outside the scope of this article." This article is exactly that topic: a real person's identity, used by a third party, without consent.
When an influencer or a brand discovers an unauthorized deepfake, there are really three separate questions in play, and each is answered by a different set of rules:
The most common misconception is that the EU AI Act bans unauthorized deepfakes of a person outright. It doesn't, unless the deepfake falls under one of the Act's eight specifically prohibited AI practices in Article 5 (among them subliminal manipulation, exploiting vulnerabilities, and biometric categorisation to infer race, religion or trade union membership) — an ordinary commercial deepfake of an influencer typically doesn't meet that bar.
What Article 50(4) actually requires is a disclosure duty: whoever deploys an AI system to create a deepfake must inform the public that the content is artificially generated. That's a transparency obligation, not a ban on making the deepfake in the first place — and a scammer who deliberately passes off a fake endorsement as genuine is, naturally, violating that disclosure duty just as deliberately as they created the deepfake itself. Article 50 is rarely the effective hammer here; a genuinely fraudulent deepfake typically also breaches Danish marketing law and often criminal law, both of which carry sharper enforcement tools.
Creating a deepfake requires an AI system to process image or audio material of an identifiable, real person — that's personal data under GDPR, regardless of purpose. The processing needs a lawful basis under Article 6, and a scammer using an influencer's likeness without consent and without any other valid basis generally doesn't have one.
Whether the material also counts as biometric data in GDPR's sense (Article 9, special category data) is less certain: the definition in Article 4(14) requires "specific technical processing" that allows unique identification of the person — an ordinary photo isn't automatically that, but the technical process behind building a convincing deepfake of someone's specific facial features sits closer to that line. We haven't found a clarifying Danish or EU ruling that addresses this exact question for deepfakes specifically — treat this as unsettled, not as a firm conclusion.
Regardless of that question, GDPR offers a real, practical route: the affected person can file a complaint with Datatilsynet (the Danish Data Protection Agency) over the unlawful processing of their own data, and can in theory also bring a compensation claim under Article 82 if the processing has caused financial or non-financial harm. That requires being able to identify and pursue whoever actually created the deepfake — often the hardest part in practice, when the sender is anonymous or based outside the EU.
Here, Danish law is actually already clear, and it's often the strongest angle in a commercial case. Using an influencer's face or voice in an advertisement, without the person actually standing behind the recommendation, is a misleading commercial practice under markedsføringsloven and the underlying UCPD directive — the consumer is misled into believing an endorsement is genuine when it isn't. That holds regardless of whether the sender calls it AI or not. It's the same underlying deception logic behind the ordinary rules on influencer marketing disclosure in Denmark and the EU — except the problem runs the other way: instead of a genuine endorsement missing its disclosure label, this is a fabricated endorsement that never happened at all.
Forbrugerombudsmanden (the Danish Consumer Ombudsman) can act against whoever advertises using the fake content — typically whoever is selling the product, not necessarily the anonymous party who technically produced the deepfake. That makes this route particularly useful when you can identify the advertiser behind a campaign, even if you can't identify who technically made the video.
What many people assume exists but actually doesn't: a general, statutory Danish right to control your own image and voice, outside the narrow situations criminal law and copyright law already cover. That's precisely the gap the incoming § 73a of the Danish Copyright Act (next section) is written to close.
| Rule set | Does it cover an unauthorized commercial deepfake of an influencer? | Why / why not |
|---|---|---|
| Straffeloven (Criminal Code) § 264d | No, as a rule | Covers unauthorized disclosure of images/information about a person's private affairs — not a public, commercial product endorsement |
| Ophavsretsloven (Copyright Act) § 60 | No | Only protects commissioned portrait photographs — a photo the person themselves commissioned from a photographer, not an AI-generated fabrication made by a third party |
| Markedsføringsloven (Marketing Practices Act) | Yes, if it's a commercial ad | Misleading marketing is already prohibited, and Forbrugerombudsmanden can act against the advertiser |
| GDPR | Partially | Unlawful processing of personal data gives a complaint and compensation route, but requires identifying who is responsible |
| EU AI Act, Article 50(4) | Disclosure only | Requires the deepfake to be labelled as artificial — doesn't ban making it |
| Incoming § 73a, Copyright Act | Yes, once/if it enters into force | Will give every person a standalone right to refuse digital imitations of their appearance and voice — see status below |
A bill, built on a political agreement reached by eight parties in June 2025, would add a new § 73a to the Danish Copyright Act. It would give every natural person — not just public figures — a copyright-like right to refuse having realistic, digitally generated imitations of their appearance, voice or movements made available to the public without consent, with an exception for satire, parody and genuine social criticism.
Be precise about status: the bill was sent for consultation in July 2025, and its expected entry-into-force date has moved at least twice — first 31 March 2026, then 1 July 2026 — and a snap general election called in March 2026 further delayed its parliamentary treatment. The most recently confirmed status in this Academy's own research (23 August 2026, for the AI voice cloning article) was that the bill remained under parliamentary treatment, not enacted law. Treat § 73a as an incoming, not a current, right until it's actually passed and in force — and check the Danish Ministry of Culture's own updates for the current status if you're dealing with a live case.
Regardless of how a case eventually resolves legally, the fastest real route to getting content removed is almost always the platform's own reporting mechanism, not the courts. The major platforms each have their own policy against AI-generated impersonation used for fraud:
Note: the platforms' own, current policy pages could not be fetched directly for this article (they require JavaScript rendering); the summary above is therefore drawn from a secondary, dated trade source and shouldn't be quoted as the platform's own wording.
There's also a formal EU route alongside a platform's own policy: the Digital Services Act (DSA), Article 16, requires platforms (including TikTok, Meta and YouTube as major providers) to operate a notice mechanism for illegal content — and a deepfake that violates Danish marketing law or GDPR qualifies as illegal content in the DSA's sense. A formal DSA notice can therefore carry more weight than an ordinary user report if a platform's own handling stalls.
The situation is somewhat different when it isn't the influencer themselves but a brand that discovers its contracted ambassador is being deepfaked by a third party — for example, a competitor using a fake version of the ambassador to disparage the brand, or a scammer exploiting the ambassador's credibility to sell an entirely different product.
Here, the contract's morality clause doesn't help — it governs the relationship between brand and influencer, not a third party's conduct. A brand's own route runs instead through trademark law (if the brand's own name or logo also appears in the deepfake), the same marketing-law deception angle covered above, and — the fastest in practice — the same platform reporting route. A brand should also keep its ambassador informed and coordinate the report with the influencer directly, since it's often the influencer's own identity that a platform reacts fastest to protect. This sits naturally alongside the ongoing vetting the brand safety checklist describes — just pointed outward at a third party, rather than inward at the ambassador's own conduct.
IF the content is still live and it's urgent → report it to the platform immediately, under the impersonation/fraud/manipulated-media category, regardless of whether the legal questions below are resolved yet. That's the fastest lever available to you.
IF the content is being used in a paid ad or to sell a product → document the ad (a dated screenshot and URL) and consider a parallel complaint to Forbrugerombudsmanden alongside the platform report — that targets the advertiser, not just the technical content.
IF you can identify who's behind it → seek legal advice on a compensation claim under GDPR Article 82 or Denmark's general culpa-based tort rule; the realistic outcome here depends entirely on whether the person or company can actually be found and pursued.
IF none of the above gives fast traction → keep the case documented and wait for § 73a to enter into force, if your situation would fall within its scope — but don't treat waiting as your only strategy while the platform-report route is available right now.
The figures and sequence below are invented, for illustration only — not a real Make Influence customer case.
A Danish micro-influencer with 40,000 followers discovers a TikTok video in which a cloned version of her voice and face endorses a "secret investment tip" linking to a scam platform. The video reaches 60,000 views over three days. She reports it to TikTok under the fraud category the same day (removed after roughly 36 hours, per the platform's own handling time in this specific case), documents the video with dated screenshots and the URL, and files a parallel complaint with Datatilsynet over the unlawful data processing. Because she can't identify the actual sender, a formal compensation claim stays out of reach in this specific case — the fast, real win is the removal of the content itself, not a court judgment or a payout.
In our experience, the most common mistake we see from both brands and creators is waiting for the "proper" legal fix — usually the incoming § 73a — instead of using the channels that already work today. A platform report doesn't resolve the underlying legal question, but it often resolves the urgent problem faster than any court system can. Our recommendation to brands with contracted ambassadors: build a short, written procedure for who reports what, and how fast, before you need it — not as a reaction once a case has already happened.
There's currently no general, statutory Danish rule that directly bans making a deepfake of a person outright. It typically becomes illegal the moment it's used commercially to mislead consumers (markedsføringsloven), processes the person's data without a lawful basis (GDPR), or meets criminal law's narrower rules on private affairs. The incoming § 73a would close the broader gap, but it isn't in force yet.
Possibly, under GDPR Article 82 or Denmark's general culpa-based tort rule — but only if you can identify and pursue whoever is responsible, which is often the genuinely hardest part of the case when the sender is anonymous or based outside the EU.
Report the content to the platform immediately under the impersonation/fraud category, and document it with dated screenshots and the URL, before considering the legal steps — see the decision framework above.
Only partially. It requires whoever uses the deepfake to disclose that it's artificial — it doesn't ban making it in the first place, unless it meets one of the eight specifically prohibited practices in Article 5, which an ordinary commercial deepfake typically doesn't.
Not settled as of this article's research. The expected date has moved several times and was further delayed by the March 2026 general election — check the Danish Ministry of Culture's own updates for the current status.
Yes, the same rule sets apply to a cloned voice as to a cloned face. If the voice cloning instead happens with your consent, by a brand you're actually working with, that's a different topic — see AI voice cloning and dubbing of creator content.
Make Influence
Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.
Book a demoCreate accountMake Influence
Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.
Create creator profileMore creator guidesMake Influence
Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.
See how it worksBrowse the Academy