Deepfake videos, voice cloning, and other AI-generated impersonations are causing demonstrable harm in South Africa. These tactics involve AI-generated or manipulated media designed to falsely depict individuals saying or doing things they never did. The proliferation of such content poses significant threats to personal reputations, financial security, and democratic processes. Despite the growing threat, South Africa currently lacks a dedicated law specifically addressing AI or deepfakes. The primary challenge in the country is focused on the enforcement of existing regulations rather than an absence of prohibitions against such harmful activities. These AI-driven impersonations are causing real harm locally, affecting individuals from public figures to ordinary citizens, and undermining trust in digital information.
Harmful Impersonations Surface
The impact of AI impersonations is being felt across various sectors. In 2024, broadcast journalist Leanne Manas had her image used in fake endorsements for weight-loss products and online trading platforms. These fraudulent promotions, which falsely claimed Manas supported the products, appeared prominently on social media platforms Facebook and TikTok, reaching a wide audience and misleading users. The unauthorized use of her likeness created a deceptive impression of her endorsement, potentially leading consumers to invest in or purchase unverified products.
In a separate and equally concerning incident in 2025, Professor Salim Abdool Karim, a globally recognized epidemiologist, was featured in a deepfake video that depicted him making anti-vaccination statements. This video went further, showing him endorsing counterfeit heart medication, thereby creating a false impression of his medical views and product recommendations. Such sophisticated manipulation of a public health figure could have severe consequences for public trust in medical advice and legitimate pharmaceutical products.
Beyond individual figures, deepfake videos featuring prominent personalities like Elon Musk have circulated widely, specifically manipulating South Africans into investing in fraudulent financial schemes. These deepfakes are meticulously designed to appear as if Musk is personally promoting the illicit investments, leveraging his public image and credibility to gain trust from potential victims. The sophisticated nature of these AI impersonations notes a broader technological capability that makes them highly convincing. With just a few seconds of audio, artificial intelligence can replicate a person’s voice with remarkable accuracy. This technology allows for the reproduction of natural intonation, rhythm, and emotion, making it extraordinarily difficult to distinguish an AI-generated voice from a genuine one. These capabilities contribute significantly to the effectiveness of the impersonations, allowing for convincing audio elements to accompany visual deepfakes or to be used independently in phishing scams and other forms of deception. The ease with which such compelling fake content can be produced shows the urgency of addressing these technological threats.
Existing Legal Protections Tested
South Africa's existing legal framework contains several provisions that may apply to AI-generated impersonations, despite the lack of specific deepfake legislation. While there is no single law dedicated exclusively to AI or deepfakes, various statutes offer avenues for recourse. The Cybercrimes Act, for instance, criminalises the electronic disclosure of intimate images without consent under section 16, a definition that explicitly extends to simulated images. This provision provides a legal basis to prosecute those who create or disseminate non-consensual deepfake pornography.
The Protection of Personal Information Act (POPIA) is another key piece of legislation. It prohibits the processing of personal information without a lawful basis, which would include the unauthorized use of an individual's image or voice for deepfake creation. Section 99 of this Act specifically allows victims to claim damages for violations of their personal information rights, offering a civil remedy for those harmed by AI impersonations.
For situations involving political manipulation, the Electoral Act prohibits publishing false information intended to influence elections. This could potentially be invoked if deepfakes are used to spread disinformation about political candidates or parties. The Films and Publications Act also addresses content distribution by prohibiting the distribution of private sexual photographs or films without consent, particularly when intended to cause harm, further strengthening protections against certain types of deepfakes. The Protection from Harassment Act allows victims to obtain protection orders, which can be used to stop ongoing online harassment, including that perpetrated through AI-generated content.
Beyond statutory law, South African common law offers recourse through the actio iniuriarum, a legal action protecting personal rights including dignity, reputation, and privacy. This common law principle has been reinforced by significant judicial rulings. The Supreme Court of Appeal confirmed in Grütter v Lombard and Another (2007) that a person’s identity is protected from unauthorised exploitation, establishing a precedent for cases involving the misuse of an individual's likeness. Similarly, in Kumalo v Cycle Lab (Pty) Ltd (2011), the High Court held that using someone’s likeness for false endorsements infringes upon both identity and privacy rights, directly addressing the kind of fraudulent activities seen with figures like Leanne Manas. These common law precedents, while not specifically mentioning AI, provide a foundational legal framework that can be adapted to address new forms of digital harm.
Global Responses and Local Challenges
The international community has begun to enact specific legislation to combat the rising tide of AI-generated impersonations. The United States enacted the TAKE IT DOWN Act in 2025, which criminalised non-consensual intimate deepfakes and mandated that platforms remove such content within 48 hours of notification. This legislation provides a clear legal pathway for victims and places responsibility on online platforms. In the state of Tennessee, the ELVIS Act of 2024 became the first legislation to specifically extend publicity rights to include AI-generated voice clones, offering a new layer of protection for artists and public figures against unauthorized vocal impersonations.
The European Union's AI Act, a landmark piece of legislation, introduced requirements for mandatory disclosure when content is AI-generated, alongside stringent penalties for non-compliance that can reach up to 6% of a company’s global turnover. This full approach aims to ensure transparency and accountability in the use of AI. Similarly, the United Kingdom has addressed the issue through its Online Safety Act of 2023 and the Data (Use and Access) Act of 2025, both of which have criminalised the sharing and creation of non-consensual intimate deepfakes, demonstrating a unified approach to protecting individuals from digital harm.
In South Africa, the Department of Communications and Digital Technologies has released a National AI Policy Framework, indicating a recognition of the importance of AI governance. Despite these policy efforts, South African courts face significant capacity constraints, and litigation often proves time-consuming and costly for victims. A persistent challenge is that perpetrators frequently operate behind anonymous online profiles, making identification and prosecution difficult. Global platforms are often slow to respond to local court orders, complicating enforcement efforts and allowing harmful content to remain accessible for extended periods. These operational hurdles exacerbate the difficulties faced by individuals seeking redress for AI-driven harms.
Path Forward for Parliament
Given the evolving nature of AI threats and the limitations of existing legal and enforcement mechanisms, South Africa's Parliament must update social media laws to ensure platforms are directly accountable for content, according to legal experts. This legislative action should also mandate the watermarking of AI-generated content to clearly identify its synthetic origin, providing users with key information about the authenticity of what they consume online. The updated framework needs to ensure that content takedown systems are genuinely effective and responsive, capable of swiftly removing harmful deepfakes and other AI-impersonations.
These proposed measures aim to address the proliferation of harmful deepfakes and AI impersonations by placing greater responsibility on the platforms where they circulate. By holding platforms accountable, mandating transparency through watermarking, and ensuring efficient content removal, South Africa can create a more strong regulatory environment. This environment would be better equipped to combat digital misinformation and protect individuals from the multifaceted forms of AI-driven exploitation, safeguarding both personal rights and the integrity of public discourse. Urgent legislative intervention is needed to close the existing gaps and provide clear, enforceable protections against these sophisticated digital threats.