October 1st, 2026

Maryland’s New Deepfake Fraud Law Takes Effect October 1: What Businesses Need to Know

Posted in:    Tagged:

On October 1, Maryland’s identity fraud law catches up with a new reality: seeing or hearing someone is no longer necessarily enough to verify their identity.

On May 12, 2026, Governor Wes Moore signed Senate Bill 8 into law. It takes effect on October 1, 2026. Titled “Artificial Intelligence and Deepfake Representations” and located in Maryland’s Criminal Law Article, § 8-301, the new statutory language expands Maryland’s existing identity fraud statute. The purpose of the amendment is to address the use of artificial intelligence and “deepfake representations” to impersonate or falsely depict another person. The legislation passed unanimously in both chambers of the General Assembly, indicating strong bipartisan support for addressing this increasingly serious issue.

For Maryland businesses, the law is particularly relevant, as AI-generated voices, images, and video make very convincing impersonation possible. Businesses dealing with third parties they do not know well can be fooled by scams much more convincing than traditional phone and email scams. Deepfake calls or video appearances can imitate faces, voices, accents, and mannerisms in real time, making it hard to know whether a person is who they say they are.

What Qualifies as a Deepfake?

The law defines a “deepfake representation” as a photograph, film, video, audio recording, digital image, picture or computer-generated image that is indistinguishable from an actual and identifiable human being. § 8-301(a)(3)(i). Drawings, cartoons, sculptures, and paintings are excluded—the standard is whether an ordinary person would conclude that the representation depicts a real, identifiable person.

The definition is broad, such that deepfake fraud does not require an elaborate fabricated video. For example, AI-generated voice cloning can be used to make a caller sound like an executive authorizing a wire transfer, a client changing payment instructions, or a family member asking for emergency funds.

What Does the New Law Prohibit?

The core of the new law is § 8-301(f)(2). It prohibits a person from knowingly, willfully and with fraudulent intent using a deepfake representation to:

The intent requirement is important. The law does not broadly prohibit AI-generated images, audio or video simply because they depict another person. As with other types of fraud, the prohibited conduct requires knowing and willful conduct, fraudulent intent, and harm.

The statute’s definition of harm is notable because it is very expansive. Harm for this crime is broader than financial loss and physical injury—it also includes “serious emotional distress.” Under Maryland law, emotional distress alone often is not actionable. By specifically including emotional distress separately from physical injury, the General Assembly has made it clear that this type of crime is punishable even in circumstances where more “traditional” wrongs might not be.

The statute is also broadly written in its penalties. Unlike many provisions of Maryland’s criminal code (even other types of identity theft in the same statute), the penalties for the new deepfake offense are not based primarily on the dollar value involved.

A violation involving one victim is a felony punishable by up to five years’ imprisonment, a fine of up to $10,000, or both. When the violation involves multiple victims, the maximum penalty increases to 10 years’ imprisonment, a fine of up to $15,000, or both. There is no minimum dollar value of harm that must be established by a prosecutor. Simply engaging in this conduct and causing harm subjects the perpetrator to a felony conviction.

Other Changes to Maryland’s Identity Fraud Law

Chapter 445 makes several other changes to § 8-301.

The law now prohibits using another person’s personal identifying information, without consent and with fraudulent intent, to cause harm. § 8-301(b-2). It also expands the prohibition against assuming another person’s identity to include doing so for the purpose of harming, harassing, intimidating, threatening or coercing that person. Again, the General Assembly is expanding the circumstances in which identify-related misconduct can be prosecuted criminally.

Those offenses are misdemeanors punishable by up to one year of imprisonment, a fine of up to $500, or both.

Victims Can Seek Civil Relief

The law also includes what is known as a private right of action for deepfake fraud. § 8-301(h)(1). Not every law can be enforced by a person or a business. Many laws, especially criminal laws, can only be enforced by a specific governmental authority. By creating a private right of action, the new law allows Marylanders to sue in court when they are harmed by deepfakes, rather than asking a State’s Attorney to pursue criminal charges on their behalf.

The right to sue directly gives Marylanders more control over how deepfake fraud is addressed. It also means that more Marylanders will be accused of deepfake fraud by other private parties and forced to defend themselves in an area of law that is not well understood by most attorneys. When a person sues under this law, the court can issue an injunction (an order that the person stop the behavior or face sanctions from the court up to imprisonment) and grant other relief. That can be particularly important with deepfake content, where stopping continued distribution may be as important to a victim as recovering financial damages.

However, because the statute says that a court can “grant any other appropriate relief,” § 8-301(h)(2), there likely will be disputes over what “other appropriate relief” includes. For example, plaintiffs who successfully sue under the law likely will want to recover attorneys’ fees as “appropriate relief.” Judges will need to decide whether that language overcomes the default rule in Maryland that people pay their own legal fees whether they win or lose.

What Businesses Should Take Away

The new law gives prosecutors and victims additional tools after deepfake fraud occurs. Businesses and individuals who are concerned that they are victims of deepfake fraud or who face accusations of deepfake fraud should consult experienced legal counsel. But the growing ability to convincingly imitate a person’s voice, image or appearance also raises an immediate question for businesses who have not yet dealt with this problem:

Are your existing procedures still adequate when seeing or hearing someone is no longer sufficient verification?

Business owners and controllers should review how they authenticate requests involving payments, changed banking information, confidential information, and other high-risk transactions.

Our companion article, Deepfake Fraud: What Maryland Businesses Should Do Now, outlines practical controls organizations can put in place to reduce that risk.

This article is for informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship.