The tools AI to manipulate faces, voices and bodies multiplied in 2024-2026, Face Swap, kiss generator, voice cloningRealistic avatars. The question everyone asks themselves without always finding a clear answer: Where is the legal limit in France? This guide It responds without unnecessary legal jargon, with the current legislation and what it actually changes for your use.
📌 Essentials
- Private use: generating a deepfake for your personal use ( fun, test, creativity) is legal if you don't broadcast it.
- Publication without consent: broadcasting a deepfake of a real person without his consent is illegal in France since the SREN law of 2024.
- Intimate content not consented: Criminally punished (2 years imprisonment, 60,000 € Since the law of 3 July 2024.
- Political and electoral Deepfakes: framed byAI European Act which came into force in 2025-2026.
- Creative and legal commercial use: possible with the explicit consent of the persons represented and the disclosure of character AI.
Contents: What is a deepfake? • What is legal • What's not • SREEN and AI Act • Tools Responsible • FAQ
What is a deepfake in 2026?
A deepfake is a synthetic, image, video or audio content generated or manipulated by a AI to reveal a real person in a situation that did not occur. The term comes from « deep learning » + « fake ».
In 2026, the term covers several distinct technologies with different legal implications:
- Face swap AI : replacing one person's face with another in an existing image or video. Technology used by tools Like Magic Hour, DeepFaceLab, Reface.
- Kiss generator/hug AI generator : generation of a video featuring two people in intimate interaction from photos. This is the category that poses the most legal problems.
- Voice cloning AI : reproduction of a person's voice from an audio sample. ElevenLabs, Murf and others tools allow this type of generation.
- Avatars AI Realistic: creation of a character that looks like a real person, or of an avatar from his own photos. This is the land of Synthesia, HeyGen, Vidnoz.
These four categories are not treated in the same way by law. The technology is the same or similar, the legal consequences vary radically depending on use and diffusion.
What is legal: authorised uses
1. Your own face, your own voice
Use a tool of the face swap ai in your own photo, clone your voice with ElevenLabs, generate an avatar AI All this is perfectly legal. You own your image and your voice. You can use them, transform them, publish them as you wish.
2. Real persons with explicit consent
Make one Face Swap a friend, generate a video with a colleague, use the voice of a collaborator for a project, all this is legal if the person has given his explicit consent. « Explicit agreement » means: informed of what will be done, the context of use, and the intended dissemination. An oral agreement « to laugh between us » does not cover a public publication.
3. Fictional characters and creative illustrations
Generating scenes with characters that are not real identifiable people, animated characters, invented avatars, fantastic illustrations, is legal. This is what people do tools as Deevid AI or Kling AI to create content video ai creative without involving real people.
4. Satire and parody declared
Political satire and parody are protected by freedom of expression in France. A satirical deepfake of a politician is tolerated if, and only if, the satirical or parody character is clearly displayed and the content cannot be confused with reality. LAI European Act also requires a visible mention « Content generated by AI » on any deepfake broadcast publicly since 2025.
5. Commercial use with agreement and disclosure
Use a ai image generator or tool video have to create advertising content with avatars AIwithout an identifiable real person, is legal and increasingly common. Synthesia and HeyGen do so with actors who have signed contracts transferring their image for commercial avatars. Transparency on generated character is mandatory in regulated commercial contexts (publicity, policy, information).
What's illegal: red lines
Intimate deepfakes not agreed
It's the brightest red line. Generating and broadcasting a sexual or intimate video featuring a real person without his consent is a criminal offence in France since the Law of 3 July 2024 (SREN Law). Maximum penalty: 2 years imprisonment and 60,000 € fine. The penalty is 3 years and 75,000 € if the victim is a minor or if the spread is massive.
This law explicitly covers content generated by AI, not only traditional montages. A Kiss AI Generator used to stage a real person without his consent falls under this definition.
Deepfakes deceptive about real people
Make or make do something to a real person in a video generated by AI, without reference to the synthetic character, may be:
- An infringement of the right to image (Article 9 of the Civil Code).
- Defamation if the contents associate the person with acts or statements that discredit the person.
- Information manipulation if the content is broadcast as real in a current or political context.
Digital Identity Assurpation
Clone a person's voice to make him or her say something that he or she did not make, or create an avatar AI In a deceitful context, it falls within the scope of identity fraud (article 226-4-1 of the Criminal Code). One year's imprisonment and 15,000 € fine.
The legal framework in 2026: SREN and AI Act
Two texts structured the legal framework of deepfakes in France in 2026.
The Siren Act (France, 2024)
The Act of 21 May 2024 (Safeguarding and Regulating the Digital Space) introduced specific sanctions for unauthorised sex deepfakes. It has also reinforced the platform's obligations to quickly remove such content on alert.
LAI European Act (2025-2026)
LAI European Act, whose main provisions apply since 2025-2026, imposes three obligations on deepfakes:
- Mandatory marking: any content generated or substantially modified by AI public dissemination must be identifiable as such (visible marking or C2PA metadata).
- Prohibition of deepfakes: generating deepfakes of political candidates without explicit marking is prohibited within 30 days of a ballot.
- Platform Responsibility: Large platforms must detect and report unmarked deepfake content.
What really changes on August 2, 2026
⚠️ Date to be used: on 2 August 2026Article 50 of the European Regulation onAI enter into force. It is he who bears the obligations of transparency on deepfakes. So far, most of these rules have been announced but not yet due.
The Regulations came into force in August 2024, but their application was phased in. The pure prohibitions took effect in February 2025, a first wave of bonds in August 2025, and the remainder of the text shall apply from 2 August 2026. Article 50 is the rest.
The delay that almost nobody mentions
This is the point that is missing from almost all the articles published on the deadline of 2 August, and it changes the timetable for compliance in practice.
On 7 May 2026, the European institutions reached political agreement on a simplification text, dubbed Omnibus AI, which dates several deadlines of the Regulation. Attention however: this agreement is provisional and was still to be formally adopted. It's not a stabilized right, it's a predicted trajectory.
⚠️ What is postponed, and what is not. Article 50 transparency obligations apply 2 August 2026. On the other hand, systemsAI general already on the market before that date, until 2 December 2026, in order to comply with the sole obligation machine-readable marking.
The distinction is important and often misunderstood. Your obligation to deploy, the obligation to clearly state that a content is generated or manipulated, is not affected by this postponement: it applies to August 2. The deadline relates to the technical part, to be borne by the publishers oftools, which must record a detectable mark in the produced files.
In other words, if you publish, do not count on this deferral. It's none of your business.
What a proper marking looks like
The notion of machine-readable marking remains abstract as long as an example has not been seen. The most common today is that of Google : all videos produced with its Veo model bear SynthIDa signature invisible to the eye, recorded in the data of the file and detectable by tools dedicated. We detail its operation in our article on Veo 3.1 and its conditions of use.
The C2PA standard, mentioned above, pursues the same objective in another way, attaching to the file a history of its creation. The two approaches coexist, and the regulation does not impose any particular technology: it imposes a result, detectability.
For you, the criterion of choice becomes simple. One tool which marks its exits places you on the bright side effortlessly. One tool which produces blank files of any trace lets you bear the burden of transparency alone.
New ban on 2 December 2026
The same package introduces an additional ban, which takes effect on 2 December 2026 and specifically covers undressing applications, tools which generate nudity images from a photograph of a dressed person.
It belongs to a category apart from the regulation, that of purely prohibited practices, where social notation and subliminal manipulation are already found. Contrary to the lack of transparency, these practices are not merely a lack of labelling: they are prohibited, whatever the display that accompanies them.
The signal sent to the area is clear. Transparency becomes the general rule for all content generated, and some uses simply fall outside the scope of the licit.
The calendar at a glance
| Date | What comes into force | Who is concerned |
|---|---|---|
| 2 August 2026 | Article 50 transparency obligations: mention of generated content, information on deepfakes | Everyone, you understand if you publish |
| 2 December 2026 | Machine-readable marking for systems already on the market before August | Publisherstools |
| 2 December 2026 | Prohibition of undressing applications | Publishers and users |
| 2 December 2027 | Obligations of autonomous high-risk systems | Regulated sectors |
Un dernier rappel de méthode, valable pour tout ce dossier : ces dates proviennent d’un accord encore provisoire au moment où nous écrivons. Nous mettrons cette section à jour dès l’adoption formelle du texte, et nous vous recommandons de vérifier l’état du droit avant toute décision engageante.
Two separate obligations, depending on your role
The text does not treat everyone the same way, and that is the point that most articles confuse. Article 50 distinguishes the supplier from the deployer.
- The supplier, it is the publisher who puts ittool available. It must ensure that the content produced is marked in a machine-readable format and detectable as generated or artificially manipulated. In other words, the technical marking is his responsibility, not yours.
- The deployerIt's you if you publish. When you broadcast a deepfake video, audio or image, you must indicate that the contents have been artificially generated or handled. The information must be clear and visible, not later than when the public is exposed to it.
In other words, you don't have to tinker with metadata yourself. Your obligation to you stands in one sentence: to say that it is of theAIand say it to a place the spectator sees.
The artistic exception, and its limitations
The regulation provides for relief when the content falls within the scope of a clearly artistic, creative, satirical or fictional work. In this case, disclosure is done in such a way as not to interfere with the exhibition of the work.
Be careful not to overinterpret this exception. It lightens the shape of the mention, it does not remove it. And the important word is « Clearly » : an assumed parody enters the framework, a realistic false statement attributed to a real person does not enter, even if you qualify it as satire after the fact.
Amount of sanctions
The regulation organizes fines in three levels. Failures to comply with Article 50's transparency obligations are the responsibility of the intermediate level: up to EUR 15 million or 3% of the world's annual turnover, whichever is greater. By comparison, purely prohibited practices amount to 35 million or 7 per cent.
These ceilings are primarily for businesses, and a reduction is foreseen for SMEs and startups. An individual creator is obviously not the priority target of the authorities. But the logic of the text is clear: transparency is no longer a good practice, it is a binding obligation.
What it really changes for you
- MentionAI when the content is generated. A line in description, a box at the beginning of the video, or the native label of the platform suffice. The whole thing is that it is visible effortlessly.
- Use platform labels rather than bypass them. They fulfill your obligation as a deployer and avoid making a make-up.
- Keep written consent Whenever an identifiable face or voice belongs to someone else. It is the right to image and voice that then applies, regardless of the European regulation.
- Choose tools which mark their exits. Serious publishers already incorporate C2PA metadata. One tool which produces files without any trace lets you bear the burden of transparency alone.
💡 Note: the platforms did not wait until the deadline. TikTok automatically labels some of the content detected as generated, and tests a tool detection of facial usurpations for creators. We detail these mechanisms in our guide on on AI Tools for TikTok and what the platform allows.
Last point, often forgotten: this regulation is European, it does not replace French law. The Siren Act, the right to image and the articles of the Criminal Code on editing continue to apply in parallel. A properly labelled deepfake remains illegal if it harms a person. The mention « generated by AI » Never been a pass.
Tools AI video responsible: how to use them in nails
The tools of the face swap and video generation AI are not illegal in themselves. What it is is is the use it is made on real people without consent. The following are the practices that make it possible to use these tools in full legality.
- Face swap on yourself: Magic Hour, DeepFaceLab, Reface, perfectly legal for personal creative use or TikTok content where you are the subject. See our comparison face swap AI 2026.
- Avatars AI For professional videos: HeyGen, Synthesia, DeeVid AI use actors who have signed image transfer contracts for their commercial avatars. Legal use in business. Our AI guide video 2026 details the options.
- Voice cloning with his own voice: ElevenLabs can clone your own voice for voice-over, podcasts, multilingual content. Complete Guide in our tuto voice cloning ElevenLabs.
- Systematic marking: on all content AI publicized, including a mention « Content generated by AI » is now a European legal obligation and good editorial practice.
💡 The simple rule: If you do not have the explicit consent of the person represented, do not publish. If you publish, mention the character AI. These two reflexes cover 95% of legal situations in 2026.
FAQ: AI Deepfakes and legality in France
Is it legal to take a deepfake in France?
Yes for private use without dissemination, and for content with consent of the persons represented. No to broadcast a deepfake of a real person without his consent, including any content of an intimate or sexual nature, sanctioned since the law TREN of July 2024 (2 years in prison, 60,000 € (d) fine.
A Kiss AI Generator Is it legal?
On oneself or with the consent of the persons represented: Yeah. On real people without their consent and broadcast: no. The SREN Act explicitly covers content generated by AI, not just traditional installation. The intention does not matter, it is the unconsented broadcast that is sanctioned.
Does it have to be said that a video is generated by AI ?
Since the entry into force ofAI European Act in 2025-2026, yes, for any publicly broadcast content. The reference may be textual (« Content generated by AI ») or integrated into metadata via C2PA. For advertisements and political content, it is a strict obligation with sanctions.
Can we clone someone's voice without his consent?
No. Closing a person's voice without his or her consent to make statements that he or she has not made constitutes an identity usurpation (Article 226-4-1 of the Criminal Code). To clone your own voice or that of a consenting collaborator, tools as ElevenLabs are perfectly suited.
Can platforms delete a deepfake about me?
Yes, and they must do so quickly under the TREN Act. You can report any deepfake representing you without your consent directly on the relevant platform (YouTube, TikTok, Instagram, etc.) or via the LCEN procedure with the host. For unconsented intimate content, a criminal complaint is possible.
What is the real risk if I publish an unconsented deepfake?
In France: up to 2 years imprisonment and 60,000 € fine for an unconsented intimate deepfake (SREN 2024). For a non-intimate deepfake: risk of civil action for infringement of the right to image, defamation or the usurpation of identity depending on the content. The platforms now transmit the identification data on judicial requisition in 24 to 72 hours.
🎯 In summary
The tools of the Face Swap, video generation and voice cloning are legitimate technologies with creative, professional and personal uses perfectly legal. What is illegal is to use them to represent real people without their consent, and especially in any content of an intimate or misleading nature.
The golden rule remains simple: your image, your voice, your fictional characters = free. The face, voice or image of someone else = explicit agreement required before publication.
Avant même de trancher la question du droit, encore faut-il repérer un deepfake. On détaille comment faire, avec les nouveaux outils de détection, dans notre guide sur le détecteur de vidéo AI.