Deepfakes Are Not a Copyright Problem. Stop Pretending They Are.
There is a thought experiment in legal philosophy about the drunk man and the lamp post. A man loses his keys in a dark alley but searches for them under the lamp post, because the light is better there. When asked why he is not looking in the alley, he says: “Well, I can see here.”
Several policymakers and legislative drafters, from the Netherlands to the United States, are currently searching for their keys under the lamp post of copyright law. The keys, of course, are somewhere else entirely.
The problem with deepfakes is not that we lack the right intellectual property framework to commodify synthetic likenesses. It is that people are being harmed right now, and enforcers are not using the tools they already have. Reframing a privacy crisis as a market opportunity does not solve the crisis. It does not even look good trying.
There is a thought experiment in legal philosophy about the drunk man and the lamp post. A man loses his keys in a dark alley but searches for them under the lamp post, because the light is better there. When asked why he is not looking in the alley, he says: “Well, I can see here.”
Several policymakers and legislative drafters, from the Netherlands to the United States, are currently searching for their keys under the lamp post of copyright law. The keys, of course, are somewhere else entirely.
The problem with deepfakes is not that we lack the right intellectual property framework to commodify synthetic likenesses. It is that people are being harmed right now, and enforcers are not using the tools they already have. Reframing a privacy crisis as a market opportunity does not solve the crisis. It does not even look good trying.
The Lamp Post: A Dutch Case Study
In October 2025, a Dutch legislative proposal was published that would create a new “neighbouring right” (an intellectual property instrument) giving every natural person an exclusive, licensable right over their own deepfakes. The right would last seventy years after the person’s death. Their children’s children could, in principle, license Grandma’s synthetic likeness to a streaming platform.
The proposal draws direct inspiration from the US NO FAKES Act, and it is not alone in Europe. Denmark has been exploring similar territory. The contrast with Germany is instructive: rather than creating a new IP instrument, the German legislature has proposed straightforward criminalisation of personality rights violations through digital falsification. That approach targets the harm directly, without building a commercial market around it. The legislative impulse behind the Dutch and American proposals is real and, in one narrow sense, understandable: deepfakes are frightening, visible, and politically charged. Politicians want to be seen acting.
But Bernt Hugenholtz, emeritus professor of Information Law at the University of Amsterdam and one of Europe’s foremost copyright scholars, has done something useful: he has read the proposal carefully and explained, in considerable detail, why it does not do what it claims to do.
His analysis, published in the Nederlands Juristenblad this February, makes three arguments that deserve wide circulation beyond Dutch legal circles.
First: Dutch and European law already provides substantial protection against non-consensual deepfakes. Portrait rights, the GDPR, criminal law provisions covering revenge porn, defamation, and non-consensual intimate imagery, the AI Act’s transparency requirements, and the DSA’s platform obligations: together, these form what Hugenholtz calls “a comprehensive arsenal.” This conclusion is not his alone. The 2021/2022 WODC study, commissioned by the Dutch government itself, reached the same finding independently: no urgent gaps exist in existing substantive law. The problem is enforcement, not doctrine.
Second: the proposal does not actually address the harm it claims to target. It defines deepfakes using the AI Act’s formulation, which requires that a reasonable viewer could mistake the content for authentic. This means, as Hugenholtz observes with some dry wit, that a deepfake of a living person in an implausible situation (say, a sexual context) would fall outside the definition. The very content that drives most of the harm would not be covered by the law designed to prevent it.
Third, and most tellingly: the proposal’s real purpose appears to be the creation of a licensable market in synthetic likenesses, not the protection of ordinary people from harm. The 70-year protection term, the explicit licenseability, the provisions mirroring film copyright assignment rules, and the ability to demand disgorgement of profits upon infringement: none of these features make sense if the goal is privacy protection. They make perfect sense if the goal is to build a new revenue stream for the entertainment industry, celebrities, and their estates.
Professors Jane Ginsburg and Graeme Austin reached the same conclusion about the NO FAKES Act: its true purpose is not to protect individuals but to give licensee right-holders, “especially motion picture and record producers, rights exclusively to exploit digital replicas.” The Dutch proposal follows the same logic. As Hugenholtz puts it: if this law were already on the books, there would be serious money to be made in synthetic Charlie Chaplin and Elvis Presley content. That tells you something about what the law is actually for.
Wrapping the Village in Leather, Again
We have been here before. The instinct to reach for an intellectual property instrument when facing a technology-driven harm is not new. It tends to happen when the harms are real but diffuse, when enforcement is politically inconvenient, and when there are well-resourced industries waiting to monetise the resulting rights regime.
The copyright framing does something specific and damaging: it converts a public harm into a private asset. It takes the question “how do we stop people from being abused?” and replaces it with “who gets to profit from synthetic likenesses?” These are not the same question. Treating them as equivalent does not protect the person whose face has been pasted onto non-consensual pornography. It protects the heir who stands to license the family resemblance to a tech company in 2061.
This is not a small distinction. Intellectual property rights are designed to promote and reward creative performance. They are tradeable, heritable, and subject to market logic. Privacy rights are not, and for very good reason. Privacy is personal. It cannot be assigned away in a studio production contract and retained simultaneously. The Dutch proposal, by routing a privacy protection through a neighbouring rights framework, ends up undermining the very protections it claims to extend.
Hugenholtz’s conclusion on this point is worth dwelling on. The proposal “does not contribute to combating deepfakes, but to their exploitation, and thus to their normalisation.” That is a precise diagnosis of what happens when you legislate with the wrong framework. And it connects directly to the accountability failure the IP approach cannot remedy. IP law gives you a damages calculation after the fact: it tells you what a licence would have cost and lets you sue for the difference. It does not require platforms to build safeguards before harm occurs. It does not impose systemic obligations on the companies that designed and deployed these tools. It compensates the rare victim with the resources and emotional bandwidth to litigate, and leaves everyone else where they started. Creating a licensable market in synthetic likenesses treats the production of deepfakes as a legitimate commercial activity to be taxed, not a harmful practice to be curtailed. It sends the message to tech companies and the public that the question is not “should this content exist?” but “who gets paid?”
Hugenholtz cites the American actors’ strike of 2023, in which performers fought precisely to prevent studios from replacing them with digital replicas. The Dutch proposal takes a step toward legitimating exactly what the strike was against. There is something troubling about a law that presents itself as protecting actors while building the legal infrastructure for their replacement.
Where the Keys Actually Are
While some legislatures are drafting new IP regimes, 61 data protection and privacy authorities across four continents have done something rather different. In a joint statement coordinated through the Global Privacy Assembly’s International Enforcement Cooperation Working Group, published on 23 February 2026, they have collectively pointed to where the keys are.
Non-consensual intimate imagery is a privacy violation. AI content generation systems must comply with existing data protection laws. The creation of such imagery “can constitute a criminal offence in many jurisdictions.” No need for new rights: just use the ones we have.
The statement is not legally binding. It creates no international enforcement mechanism. But it does something important: it establishes a shared enforcement priority among regulators who do have legal teeth in their own jurisdictions. Canada expanded its investigation into X Corp and launched a new probe into xAI. The UK Information Commissioner opened investigations into both X Internet Unlimited Company and X.AI LLC over the processing of personal data in relation to Grok. Ireland, as the EU lead authority for X, is already engaged. The Clearview AI cases showed that coordinated voluntary enforcement, even without a binding international mechanism, can produce meaningful compliance results, including market exit.
Owen Bennett, who specialises in international platform regulation, put it well in his analysis in a Techpolicy.press article. When 61 data protection regulators from every continent issue a joint statement, “it sends a warning that regulators intend to use the mechanisms available to them to share supervisory insights and intelligence when companies don’t play ball on this issue.” He also noted that, compared to online safety regulators, data protection authorities “have the advantage of having rulebooks that are more mature, and of having greater experience in flexing their enforcement muscles.” We are not starting from zero. We are starting from underuse.
This is the enforcement gap that actually matters. Not a doctrinal gap, but a political will gap. And that is precisely the gap that a new neighbouring right for deepfakes does nothing to close.
The Accountability Question the IP Frame Cannot Answer
There is a deeper problem with routing deepfake harms through intellectual property law. IP law gives you a damages calculation. It tells you what a licence would have cost and lets you sue for the difference. It is not designed to answer the question: how do we stop platforms from hosting millions of non-consensual intimate images? How do we hold the companies that built and deployed these tools accountable for the harms they enabled?
These are fundamentally accountability questions. They require regulatory frameworks that can impose systemic obligations, mandate prior safeguards, and sanction failure: not just award compensation after the fact to the rare victim with the resources and emotional bandwidth to litigate.
Privacy law, at its best, does all of this. The GDPR imposes obligations on processors of personal data before harm occurs. The AI Act requires transparency and risk mitigation from operators of high-risk systems. The DSA removes safe harbour protections from platforms that fail to act on illegal content once notified. The criminal law provisions in many EU member states impose direct liability on creators and distributors. None of this requires a new neighbouring right for Charlie Chaplin’s estate.
The technology-neutral principle that information labs consistently defends in other contexts is directly applicable here. We do not need a law for “deepfakes.” We need effective enforcement of laws against non-consensual intimate imagery, fraud, defamation, and data protection violations, regardless of the technological means used to commit them.
The Normalisation Risk
There is one argument in Hugenholtz’s analysis that gets insufficient attention in the broader policy debate, and it is the one most worth elevating.
The Dutch proposal does not just fail to protect people. In a meaningful sense, it normalises the phenomenon it claims to address. Creating a licensable market in synthetic likenesses treats the production of deepfakes as a legitimate commercial activity that needs to be regulated and taxed, not a harmful practice that needs to be curtailed. It sends the message to the entertainment industry, to tech companies, and to the public that the question is not “should this content exist?” but “who gets paid?”
That framing will haunt us. Once you establish a market in synthetic likenesses, the pressure to exploit that market is enormous. Hugenholtz cites the American actors’ strike of 2023, in which performers fought precisely to prevent studios from replacing them with digital replicas. The Dutch proposal takes a step toward legitimating exactly what the strike was against. There is something troubling about a law that presents itself as protecting actors while building the legal infrastructure for their replacement.
The person whose deepfake has no commercial value (the ordinary woman whose face ends up in non-consensual pornography, the teenager targeted for cyber-bullying) gets nothing useful from this framework. What she needs is prompt removal, effective enforcement, and accountability for the platform that hosted the content. None of that follows from a neighbouring right. It follows from a data protection authority that actually uses the powers it has.
What We Should Be Calling For
The lesson from Hugenholtz’s analysis and from the joint statement of 61 privacy regulators is not that nothing should be done. It is that we should be precise about what needs doing.
We should be calling for effective enforcement of existing privacy, data protection, and criminal law frameworks against non-consensual deepfakes. We should be supporting international regulatory cooperation through bodies like the Global Privacy Assembly, and pushing for the US to develop federal data protection law so that it can participate in that cooperation rather than serving as a regulatory black hole for companies like xAI. We should be demanding that platforms implement robust safeguards before harm occurs, not minimum-effort content moderation after it scales. And we should be scrutinising any proposal that wraps a privacy harm in an IP jacket and asks us to admire the tailoring.
The keys are not under the lamp post. They never were.
Get the article’s core concepts in a unique auditory summary—listen to the AI-generated track below!
This song was created entirely using artificial intelligence tools. If you enjoy this experiment, keep an eye out for each song illustrating our December articles.
Written by Caroline De Cock, LL.M., Head of Research
