The Cybercrimes Act and the rise of AI Deepfakes

The rapid advancement of Artificial Intelligence (“AI“) has seen the emergence of quite a number of new cybercrimes such as Deepfakes. These are synthetic media, audio, image and video that are created by AI, significantly for learning purposes to convincingly replace one person’s likeness or voice with another’s. Given their ability to replicate voices, looks, and gestures, these synthetic media outputs pose significant threats to political stability, business integrity, privacy, and dignity. In South Africa, the Cybercrimes Act 19 of 2020 (“the Act”) is the primary legislation that governs cyber misconduct. The crucial question is whether the Act is well equipped to handle the distinct and changing risks presented by deepfakes that are created by AI.
Fundamentally, the Act classifies unlawful access, data interception, cyber fraud, cyber forgery and uttering, and malicious data message distribution illegal. Notably, in the context of deepfakes, the sections that deal with cyber fraud and cyber forgeries are especially relevant. A deepfake that is used to impersonate a person for financial advantage would most likely fall under the category of cyber fraud while AI modified media presented as legitimate could be considered cyber forgery and uttering.
AI generated voice cloning can be used to pose as a business executive and give staff instructions to approve fraudulent payments or divulge private and sensitive information. This happened to a Hong Kong based employee of Arup, a global engineering consultancy, who was deceived into transferring approximately $25 million after participating in a video conference populated entirely by AI-generated deepfakes impersonating senior executives. This instance demonstrates the growing sophistication of synthetic media, where fraud can now imitate an entire organisational relationship rather than just solitary impersonation. The Act’s provisions on fraud and unlawful data interference offer a foundation for prosecution in these situations. In the face of extremely convincing AI-driven fraud, it also highlights the practical difficulties of detection, attribution, and cross-border enforcement.
However, when considering the entire range of dangers associated with deepfakes, the Act has significant shortcomings despite these advantages. On one hand, neither AI nor synthetic media are specifically mentioned in the Act, which is technologically neutral. Despite the flexibility that this guarantees, it also leaves room for interpretation, especially where harm does not cleanly fit into conventional categories like fraud or unlawful disclosure.
On the other hand, deepfakes frequently create psychological, political, or reputational damage and not just financial harm. AI-generated recordings that depict public figures participating deceitfully may undermine some of the democratic processes or incite social unrest. Since the Act does not specifically address misinformation or disinformation, there is a regulatory gap in addressing non-financial damage caused by deepfakes. Furthermore, generative AI techniques can develop deepfakes faster and on a larger scale than traditional regulatory responses. Instead of a preventative or governance-oriented structure, the Act takes a reactive, offence-based strategy.

On the other hand, deepfakes frequently create psychological, political, or reputational damage and not just financial harm. AI-generated recordings that depict public figures participating deceitfully may undermine some of the democratic processes or incite social unrest. Since the Act does not specifically address misinformation or disinformation, there is a regulatory gap in addressing non-financial damage caused by deepfakes. Furthermore, generative AI techniques can develop deepfakes faster and on a larger scale than traditional regulatory responses. Instead of a preventative or governance-oriented structure, the Act takes a reactive, offence-based strategy.
In conclusion, the Act offers a fundamental legal framework that can deal with specific deepfake harm manifestations, but it is not entirely equipped to handle the more complicated and wide-ranging issues brought about by AI-driven deception. It might be necessary to implement a more comprehensive regulatory response that includes aspects of platform accountability, AI governance, and specific offences that deal with the misuse of synthetic media. South Africa’s legal system must change and adapt with deepfake technology to maintain its applicability and efficacy in protecting digital trust.