Synthetic Identity and the Erosion of Trust: Regulatory Approaches
Digital Dignity Institute Research Team
Abstract
As AI enables the creation of convincing synthetic identities — false personas indistinguishable from real individuals — existing legal frameworks are inadequate. This brief examines regulatory approaches across jurisdictions and proposes minimum standards for synthetic identity disclosure, liability, and enforcement.
The Synthetic Identity Threat
Advances in generative AI have made it possible to create synthetic identities — false personas with convincing photographs, plausible biographical histories, and coherent online presences — at scale and at negligible cost. These capabilities are being deployed for fraud, influence operations, harassment, and the systematic erosion of epistemic trust. Existing legal frameworks, designed to address identity theft and impersonation of real individuals, are structurally inadequate for synthetic identity: there is no victim whose identity has been stolen, no real person who has been impersonated, and no clear locus of harm.
Regulatory Approaches Across Jurisdictions
This brief examines regulatory approaches to synthetic identity across eight jurisdictions, identifying three broad models: disclosure-based regimes that require AI-generated content to be labelled; prohibition-based regimes that restrict synthetic identity creation in specified contexts; and liability-based regimes that assign responsibility for harms caused by synthetic identities to their creators or deployers. We assess the strengths and limitations of each model and identify the conditions under which each is most likely to be effective.
Minimum Standards for Adequate Governance
Drawing on the comparative analysis, we propose minimum standards for synthetic identity governance: mandatory disclosure requirements for AI-generated personas in political, commercial, and journalistic contexts; civil liability for harms caused by synthetic identities, with a rebuttable presumption of liability for creators and deployers; platform obligations to detect and label synthetic identities at scale; and international coordination mechanisms to address the cross-border dimension of synthetic identity operations.
Key Findings
- 01
Existing identity fraud and impersonation laws do not cover synthetic identities — there is no victim whose identity has been stolen.
- 02
Disclosure-based regimes are necessary but insufficient: labelling requirements are easily circumvented and do not address harms already caused.
- 03
Civil liability regimes with rebuttable presumptions offer the most promising path to deterrence.
- 04
Platform-level detection obligations are essential: individual enforcement cannot address synthetic identity at scale.
- 05
International coordination is required: synthetic identity operations are inherently cross-border.
Methodology
Comparative legal analysis across eight jurisdictions; regulatory mapping; structured review of enforcement actions and case law; expert consultation with platform trust and safety teams, law enforcement, and civil society organisations.