AI impersonation exposes gaps in South African law

Posted on Leave a comment

Artificial intelligence is reshaping social media at a pace that South African law was never designed to match. Deepfake videos, voice cloning, and AI-generated impersonations are no longer hypothetical threats – they are already causing real harm locally.

A deepfake is AI-generated or manipulated media designed to make it appear as though a person said or did something they never did. The dangers are threefold: deepfakes deceive audiences into believing false content, they enable cybercrimes and reputational harm, and they can be created and published by anyone, including anonymous social media users.

South Africa has already experienced this first-hand. In 2024, broadcast journalist Leanne Manas had her image used in fake endorsements for weight-loss products and online trading platforms on Facebook and TikTok. In 2025, Professor Salim Abdool Karim appeared in a deepfake video making anti-vaccination statements while endorsing counterfeit heart medication. Deepfake videos of Elon Musk induced South Africans to invest in fraudulent financial schemes.

Voice cloning poses an equally serious threat. With just a few seconds of audio, AI can now replicate a person’s voice with natural intonation, rhythm, and emotion. The risk extends beyond public figures: anyone with an online presence, including a LinkedIn or WhatsApp profile, is a potential target.

The South African legal framework

South Africa has no single law dedicated to AI or deepfakes. Instead, individuals must rely on a combination of existing statutes and common law principles that were not drafted with this technology in mind. Despite this, several laws can offer meaningful protection:

  • The Cybercrimes Act criminalises the electronic disclosure of intimate images without consent under section 16, and the definition extends to simulated images, meaning a deepfake does not escape liability simply because it is artificially generated.
  • The Protection of Personal Information Act (POPIA) prohibits the processing of personal information without a lawful basis, and section 99 allows victims to claim damages, often the most straightforward civil route where harm is reputational or emotional.
  • The Electoral Act prohibits publishing false information intended to influence elections.
  • The Films and Publications Act prohibits distributing private sexual photographs or films without consent to cause harm, although its focus on whether the original image was “private” can be limiting where deepfakes use publicly available photos.
  • The Protection from Harassment Act enables victims to obtain protection orders to stop ongoing online harassment.

South African common law also provides recourse through the actio iniuriarum.

  • The Supreme Court of Appeal confirmed in Grütter v Lombard and Another (2007) that a person’s identity is protected from unauthorised exploitation, supported by the constitutional guarantee of human dignity.
  • In Kumalo v Cycle Lab (Pty) Ltd (2011), the High Court held that using someone’s likeness for false endorsements infringes identity and privacy rights. These precedents can apply to deepfake misuse.

International developments

International jurisdictions are moving rapidly, signalling the direction South Africa’s framework may take. In the United States, the TAKE IT DOWN Act, 2025 became the first federal law to criminalise non-consensual intimate deepfakes, requiring platforms to remove such content within 48 hours. Tennessee’s ELVIS Act, 2024 was the first to extend publicity rights expressly to AI-generated voice clones.

In the European Union, the AI Act requires mandatory disclosure when content is AI-generated and imposes fines of up to 6% of a company’s global turnover for non-compliance.

The United Kingdom’s Online Safety Act, 2023 and Data (Use and Access) Act, 2025 have criminalised both the sharing and the creation of non-consensual intimate deepfakes, and regulators have launched investigations into AI tools generating such content.

South Africa is yet to announce specific AI regulation proposals but has released a National AI Policy Framework through the Department of Communications and Digital Technologies, signalling a future risk-based regulatory model. This framework draws inspiration from global standards and may form the basis for a future AI Act.

Recommendations

The primary challenge in South Africa is enforcement rather than the absence of prohibitions. Courts face capacity constraints, litigation remains time consuming and costly, perpetrators hide behind anonymous profiles, and global platforms respond slowly to local court orders.

Organisations should map all AI use across their operations, update policies to address synthetic media, implement deepfake-aware incident response plans, and ensure contracts explicitly address AI-generated content.

Individuals should preserve evidence immediately (screenshots, URLs and timestamps), report content through platform tools and seek urgent relief through takedown notices citing the Cybercrimes Act, POPIA, or common law iniuria.

South African law clearly prohibits the misuse of identity through deepfakes, but the enforcement gaps leave victims exposed. Parliament must update social media laws so that platforms are directly accountable, mandate the watermarking of AI-generated content, and ensure takedown systems actually work.

Until dedicated legislation arrives, the combination of existing statutes, constitutional protections, and practical vigilance remains the strongest safeguard available.

This article was written by Tayyibah Suliman, a director and head of the technology and communications sector at Cliffe Dekker Hofmeyr, and Sadia Rizvi, a senior associate in that sector.

Disclaimer: The views expressed in this article are those of the writer and are not necessarily shared by Moonstone Information Refinery or its sister companies. The information in this article is provided for general purposes only and does not constitute legal advice.


Leave a Reply

Your email address will not be published. Required fields are marked *