Dr Felipe Romero-Moreno examines the recent shifts in deepfake technology and asks how legal practitioners can navigate the impending 12-month regulatory vacuum between the AI Act’s functional bans and its high-risk enforcement.
Generative AI, fuelled by advanced multimodal architectures and illicit dark-web variants such as WormGPT and FraudGPT, has precipitated a global digital trust emergency. Deepfake technology has rapidly transitioned from a platform-centric nuisance into a precision financial weapon. The economic fallout is immediate and severe: projections indicate that the global financial ramifications of AI-enabled fraud will reach $58.3 billion by 2030, marking a 153% surge from 2025 baselines.
For technology law practitioners advising on digital security, data protection and platform liability, the legislative response across the UK and the European Union has been ambitious but structurally staggered. The European Parliament and Council’s approval of the Digital Omnibus Regulation in June 2026 represents a watershed intervention. However, it simultaneously creates a critical compliance gap.
Specifically, an immediate 12-month regulatory vacuum now exists between the December 2026 functional bans on deceptive AI systems and the delayed December 2027 application timelines for high-risk AI obligations.
During this 12-month window, practitioners must guide organisations through a period of extreme vulnerability where the technical capacity of threat actors vastly outpaces statutory enforcement. Drawing on my recent peer-reviewed analysis in the Computer Law & Security Review, this article examines the industrialization of deepfake fraud, outlines the legal deadlocks within this impending regulatory gap, and provides practical pointers for advising clients on biometric integrity and risk management.
The Industrialisation of Deepfake Fraud
To understand the severity of the December 2026–2027 regulatory gap, we must first recognise that the technological foundation of deepfake fraud has fundamentally changed.
The Shift from GANs to Agentic Diffusion Models
Deepfakes traditionally relied on Generative Adversarial Networks (GANs). While GANs remain prevalent for live face-swapping, they often fail to replicate the complex motion cues required to circumvent advanced liveness-detection systems. Historically, security frameworks relied on these technical shortcomings, detecting forgeries by analysing frame-by-frame visual inconsistencies.
However, the innovation frontier has shifted toward Diffusion Transformer (DiT) architectures, a paradigm reorientation highlighted by models such as Open-Sora 2.0. By synthesising high-fidelity video through the reversal of a noise-corruption process and processing data as spacetime patches, diffusion models achieve unprecedented physical realism. This evolution effectively neutralises traditional detection methods that rely on visual artifacts.
More alarmingly, this technical evolution heralds a transition into an “agentic” epoch. Unlike previous iterations of deepfakes, which acted as static media masks, agentic AI functions as an autonomous reasoning engine. These models can navigate complex social engineering scenarios and iterate on adversarial prompts in real-time.
The Rise of “Frankenstein” Synthetic Identities
For corporate targets, agentic AI enables highly customised, multi-step execution. Threat actors are now combining stolen real-world data (such as names, national insurance details, and credit histories) with synthetic, AI-generated biometrics to create composite “Frankenstein” synthetic identities. These hybrid personas easily bypass traditional Know Your Customer (KYC) checks because the underlying records are partially genuine.
High-profile corporate heists, such as the 2024 Arup incident where an employee was tricked into transferring $25 million during a multi-person deepfake video conference, and the $18.5 million Hong Kong cryptocurrency heist which utilised highly sophisticated voice cloning, demonstrate how threat actors inject synthetic media into virtual camera and audio feeds to subvert enterprise authentication entirely.
The 12-Month Regulatory Vacuum
The legislative framework designed to combat this threat is currently defined by a temporal misalignment that leaves technology platforms, financial institutions, and their legal counsel in a precarious position.
The Digital Omnibus Regulation, following simplification measures and a “nudifier” app ban approved by the European Parliament and given a final green light by the Council of the European Union in June 2026, explicitly amends the EU AI Act. Alongside expanding the Article 5 list of prohibited practices, the update establishes an uncompromising compliance deadline of 2 December 2026 for strict deepfake transparency and watermarking obligations so effectively outlawing platforms and tools that generate synthetic media without adequate technical safeguards.
However, the rigorous technical resilience, quality management and risk-mitigation obligations mandated for “high-risk” operational domains under Annex III of the AI Act (such as remote biometric identification and financial risk assessment systems) do not take full effect until December 2027.
The Practitioner’s Dilemma: Corporate Security vs. Privacy Law
This 12-month gap creates a severe dilemma for technology practitioners. On one hand, the December 2026 bans, operating alongside the systemic risk management requirements of the EU Digital Services Act (DSA) and the UK’s Online Safety Act 2023 (OSA), compel proactive fraud detection. Platforms and intermediaries are under intense regulatory pressure to identify and block synthetic media at the point of ingestion.
Furthermore, in the UK, the Economic Crime and Corporate Transparency Act 2023 (ECCTA) introduces a strict corporate liability offence for “failure to prevent fraud.” Under official Home Office guidance, large organisations must demonstrate “reasonable fraud prevention procedures”. Following high-profile deepfake losses, a deliberate corporate failure to deploy available detection technology, especially where that omission maximises platform ad revenues, likely nullifies a “reasonable procedures” defence.
On the other hand, the legal mechanisms required to achieve proactive fraud detection are strictly constrained by data protection law. Combating deepfakes requires processing biometric data which is classified as special category data under Article 9(1) of the UK and EU GDPR.
The CJEU Grand Chamber’s landmark ruling in X v Russmedia Digital SRL (Case C-492/23) fundamentally shifted the protection burden from reactive moderation to proactive technical intervention, enforcing a “verify-then-publish” directive. The Court essentially pierced the traditional DSA intermediary liability shield, declaring that platforms act as “joint controllers” under Article 26 GDPR when they determine the algorithmic parameters of publication.
Yet, organisations face a conformity deadlock between the GDPR’s data minimisation principle (Article 5(1)(c)) and the AI Act’s requirement for high-accuracy detection models (Article 15). Stockpiling or retaining the vast reservoirs of biometric data necessary to train accurate deepfake detection models directly violates GDPR strict necessity and storage limitation mandates.
Until the December 2027 high-risk AI obligations establish standardised compliance architectures, organisations acting in this 12-month vacuum face severe regulatory exposure from either data protection authorities (for over-collecting sensitive biometric data) or safety and financial regulators (for failing to prevent deepfake fraud).
Cross-Border Enforcement and the Jurisdictional Black Hole
The urgency of navigating this 12-month vacuum is compounded by the breakdown of traditional cross-border enforcement mechanisms. When deepfake fraud originates from non-cooperative jurisdictions, traditional Mutual Legal Assistance Treaties (MLATs) and administrative disclosure orders under the DSA are fundamentally misaligned with the speed of AI crime.
A prime example is the 2025 transnational organised crime syndicate behind the $35 million deepfake-driven celebrity advertisement scam. While European regulators could attempt to issue disclosure orders against platforms under Articles 9 and 10 of the DSA, the administrative process hit a hard jurisdictional wall because the crime ring operated out of Georgia—a third country outside the direct reach of DSA enforcement.
Because Article 10(2)(b) of the DSA restricts platform disclosure to information “already collected” and within their immediate control, platforms maintaining anonymous uploader architectures provided an inadvertent shield for offshore Fraud-as-a-Service (FaaS) syndicates. By the time legal orders cross international borders, stolen assets are laundered through offshore cryptocurrency mixers.
Consequently, legal counsel can no longer rely on ex-post litigation or reactive takedown notices. Effective risk management requires securing the ingestion point through ex-ante architectural controls.
Bridging the Gap: Strategic Advice for Clients
To navigate the 12-month regulatory vacuum, practitioners must advise clients to transition from legacy, post-hoc content moderation toward a “proof of personhood” model that satisfies both corporate security duties and fundamental privacy mandates.
1. Mandate the Shift from PAD to IAD in Vendor Agreements
The primary industry defence against identity fraud has traditionally been Presentation Attack Detection (PAD), which verifies that a biometric input originates from a live human present at the sensor rather than a physical spoof (such as a silicone mask or printed photograph). However, as deepfakes move to the virtual camera level, PAD has become a legacy control.
Threat actors no longer need to hold a physical screen up to a camera; they inject synthetic data directly into the application software stream. Digital injection attacks that bypass physical camera sensors entirely have surged by 2,665% in recent years.
Practitioners reviewing identity verification (IDV) and KYC vendor contracts must ensure that Injection Attack Detection (IAD) is explicitly mandated alongside traditional PAD. Relying solely on legacy PAD controls against a known digital injection vector constitutes a culpable failure to adapt, exposing a company to corporate liability under the UK ECCTA and civil compensation claims under Article 82 GDPR for failing to implement “appropriate” technical measures (Article 32 GDPR).
2. Update DPIAs to Enforce Zero-Retention Biometrics (NIST IAL2)
Relying on ex-post algorithmic detection is legally and technically fragile. AI-driven detection tools frequently fail the GDPR’s accuracy principle (Article 5(1)(d)) due to quantifiable algorithmic bias. Empirical research demonstrates that deepfake detectors can exhibit error rate gaps as high as 10.7% across different racial subgroups, leading to discriminatory false positives.
The only viable pathway to satisfy the CJEU’s Russmedia directive without triggering a prohibited “systematic and generalised” processing of biometric data, as established in Mousse v CNIL (Case C-394/23), is to decouple identity verification from data possession.
Practitioners should advise clients to align their compliance frameworks with the US National Institute of Standards and Technology’s NIST SP 800-63-4 Identity Assurance Level 2 (IAL2) guidelines, adopting zero-retention biometrics.
In a zero-retention architecture, biometric data is processed strictly in local RAM for a single 1:1 match. Once authentication is complete, the raw facial or vocal data is immediately deleted. The system utilises Zero-Knowledge Proofs (ZKP) to generate a cryptographic biometric integrity hash. This hash serves as a self-validating digital seal, providing mathematical proof of a high-assurance verification event without storing the subject’s underlying biometric template.
Lawyers should guide clients to update their Data Protection Impact Assessments (DPIAs) to reflect this transition. Demonstrating zero-retention biometrics in a DPIA fulfils data protection by design and default (Article 25 GDPR), removing the centralised biometric “honey-pot” that hackers target and insulating the business from catastrophic data breach liability.
3. Leverage ISO 20022 Messaging Schemas for Financial Blockades
To address cross-border jurisdictional black holes, lawyers advising financial institutions, fintechs and payment gateways should champion the integration of biometric integrity hashes directly into global payment architectures.
The universal financial messaging standard, ISO 20022, includes extensible metadata fields. By embedding a mandatory biometric integrity hash, generated via zero-retention ZKP protocols, within the SplmtryData (Supplementary Data) schema of an ISO 20022 payment message, financial networks can establish a protocol-level blockade.
If a high-value or cross-border transaction request lacks a valid, real-time biometric integrity hash confirming human authorisation, the transaction is automatically frozen or rejected at the payment gateway.
This mechanism establishes a practical Transatlantic Regulatory and Financial Interoperability Framework. It reconciles the EU’s rights-based verify-then-publish mandate with the UK’s safety-based duties by shifting from reactive content moderation to a structural, automated denial-of-service against non-compliant or anonymous transaction sources.
What to Do Now: Action Plan for Practitioners
To prepare clients for the December 2026 Digital Omnibus deadline and bridge the 12-month regulatory gap, practitioners should take the following immediate steps:
- Audit IDV Vendor Contracts: Review existing contracts with identity verification and KYC providers. Ensure terms explicitly require Injection Attack Detection (IAD) capable of blocking virtual camera injections, alongside traditional Presentation Attack Detection (PAD).
- Update DPIAs for Zero-Retention: Review and update Data Protection Impact Assessments for all biometric processing systems. Document the implementation of zero-retention architectures and Zero-Knowledge Proofs (ZKP) to satisfy GDPR Article 25 (privacy by design) and Article 32 (security of processing).
- Review ECCTA Anti-Fraud Procedures: Assess corporate anti-fraud policies in light of the UK “failure to prevent fraud” offence. Verify that procedures account for agentic AI vishing and virtual camera manipulation during high-value financial transfers.
- Prepare for ISO 20022 Integration: For financial sector clients, evaluate payment processing workflows to support the inclusion of cryptographic biometric hashes within ISO 20022 SplmtryData messaging fields.

Dr. Felipe Romero-Moreno is Associate Professor in Research, Research Lead for Law and Research Degrees Lead at the Hertfordshire School of Law, Education and Society. He serves on the Executive Committee of BILETA and his research focuses on the intersection of generative AI, deepfake regulation, data protection, intellectual property and human rights.
His research and consultancy have directly informed policy for the UK House of Lords, the UK Government and the EU Commission.