Regulating AI-Generated Deepfakes In Nigeria: Assessing The Adequacy Of Existing Cybercrime Law And The Case For Legislative Reform

Published On: 7th October 2026

Authored By: Oyelere Promise Mary
Lead City University

Abstract

The rapid advance of generative artificial intelligence has made it possible to fabricate convincingly realistic images, audio and video of real people, a phenomenon widely known as “deepfake” technology. While such tools have legitimate uses in entertainment, education and accessibility, they are increasingly deployed to defame, defraud, sexually exploit and politically manipulate. This article asks to what extent Nigeria’s existing legal framework is adequate to regulate AI-generated deepfakes, and what legislative reforms are necessary to close the gaps that remain. It examines the Cybercrimes (Prohibition, Prevention, etc.) Act 2015, as amended in 2024, the Nigeria Data Protection Act 2023, the Criminal Code Act and the Constitution of the Federal Republic of Nigeria 1999, before drawing lessons from the European Union’s Artificial Intelligence Act, the United States’ federal and state responses, and the United Kingdom’s regulatory posture. It argues that although existing Nigerian law can capture some deepfake-related conduct by analogy, none of it was designed with synthetic media in mind, leaving gaps in definition, liability, evidence and victim remedy that only targeted legislative reform can close.

INTRODUCTION

Artificial intelligence (AI) — broadly, computer systems capable of performing tasks that would ordinarily require human intelligence, such as recognizing patterns, generating language, and synthesizing images or sound — has developed at a pace that has outstripped most regulatory systems’ capacity to respond.[1] Within this fast-moving field, generative AI models trained on large volumes of visual and audio data can now produce a “deepfake”: a synthetic image, video or audio recording that convincingly depicts a real, identifiable person saying or doing something they never said or did.[2] The technology takes its name from the “deep learning” neural-network architectures that make such convincing synthesis possible, and its outputs have moved, within a few years, from crude, easily detectable fabrications to material that can deceive even attentive viewers.

An AI-generated deepfake may therefore be defined as any audio, visual or audio-visual content that has been created or manipulated using AI techniques to represent a person, in whole or in part, in a manner that did not occur, in a way calculated or likely to be mistaken for authentic material. Deepfakes have become a legal and societal concern precisely because the same qualities that make them technically impressive — realism, accessibility and ease of production — also make them a uniquely potent tool for deception. Unlike earlier forms of digital manipulation, deepfakes place a believable simulation of a real person’s voice or likeness in the hands of anyone with a smartphone and freely available software, at a scale and speed the law has not previously had to contend with.

In Nigeria, this concern has a distinct texture. High rates of social media use, endemic online fraud and a volatile political environment make the country fertile ground for the malicious use of synthetic media, while its cybercrime and data-protection statutes were drafted before the technology existed in its present form. Deepfakes generate at least six distinct legal problems in the Nigerian context: they can spread misinformation that undermines public trust; impersonate public officials or private individuals for fraudulent purposes; damage reputations through fabricated statements or footage; defraud individuals and financial institutions through voice-cloned instructions; manipulate political discourse ahead of elections; and violate the privacy and dignity of victims, most severely through non-consensual synthetic intimate imagery. This article’s central argument is that Nigeria’s existing legal framework — principally the Cybercrimes (Prohibition, Prevention, etc.) Act, the Nigeria Data Protection Act, the Criminal Code Act, and relevant constitutional guarantees — does not adequately address the unique legal and evidentiary character of AI-generated deepfakes, and that targeted legislative reform is necessary.

CONCEPTUALISING AI-GENERATED DEEPFAKES

Artificial intelligence, for present purposes, refers to computational systems — most relevantly generative adversarial networks, diffusion models and large multimodal models — that learn statistical patterns from training data and use them to generate new, original outputs.[3] A deepfake results when such a model is trained on images, video or audio of a specific person and then used to generate new content depicting that person’s likeness or voice in situations that never occurred. At a basic technical level, this typically involves feeding the model a large dataset of a target’s face or voice, allowing it to learn the person’s distinguishing features, and then mapping those features onto a source video, audio track or still image, frame by frame or waveform by waveform, so that the output appears seamless to a human observer.

Deepfakes take several recognizable forms. Face-swapping replaces one person’s face with another’s within an existing video. Voice cloning reproduces a target’s vocal characteristics well enough to generate new speech in their voice. Fully synthetic videos generate an entirely new moving image of a person from scratch rather than manipulating an existing recording. Manipulated images alter still photographs to change context, expression or content. AI-generated audio produces speech or other sounds without any human vocal input at all. These categories often overlap in practice — a fraudulent phone call, for instance, may combine a cloned voice with a script produced by a separate language model.

The technology is not inherently malicious. Legitimate uses include dubbing and de-ageing in film production, synthetic voices for people who have lost the ability to speak, satire and political commentary, and educational simulations. What converts a legitimate technique into a legal wrong is not the technology itself but the absence of consent, the intent to deceive, or the harm that flows from its use — a distinction that, as later sections argue, existing Nigerian law struggles to draw with precision.

THE LEGAL AND SOCIETAL PROBLEMS CREATED BY DEEPFAKES

Defamation and reputational harm

A deepfake may put false words or conduct into a real person’s mouth or body, causing reputational injury that is difficult to correct once the fabricated content circulates, since a retraction rarely reaches everyone who saw the original.

Privacy and personality rights

Every deepfake necessarily uses a real person’s face, voice or likeness without their participation, raising questions about consent and the unauthorized expressive or commercial use of one’s image that traditional privacy law, built around the disclosure of private facts, did not anticipate.

Fraud and impersonation

Cloned voices and synthetic video calls are already used to impersonate executives, relatives or officials in order to induce fraudulent transfers, a threat that exploits the trust ordinarily placed in voice and video as proof of identity.

Sexual exploitation

Non-consensual synthetic intimate imagery, overwhelmingly targeted at women, inflicts harm that is functionally identical to that caused by genuine non-consensual imagery, yet may fall outside statutory definitions drafted around authentic photographs or recordings.

Political manipulation and democratic processes

Fabricated statements or footage of politicians, released close to an election, can distort public understanding of candidates at the precise moment voters most need reliable information, and the difficulty of swiftly authenticating or debunking such material compounds the harm.

Misinformation and public trust

Beyond any single fabricated clip, the mere possibility of deepfakes erodes confidence in genuine audio-visual evidence generally — the so-called “liar’s dividend” — allowing wrongdoers to dismiss authentic recordings as fabricated.

EXISTING NIGERIAN LEGAL FRAMEWORK

The Cybercrimes (Prohibition, Prevention, etc.) Act 2015, as amended by the Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024, is the principal statute of relevance.[4] Section 22 criminalizes identity theft and impersonation carried out through electronic means, while other provisions address computer-related fraud and forgery.[5] The 2024 amendment narrowed the previously contested section 24, which the ECOWAS Community Court of Justice had found incompatible with freedom of expression, replacing broad language such as “annoying” or “grossly offensive” with a threshold tied to threats to life or public order.[6] None of these provisions, however, was drafted with AI-generated synthetic media in mind: impersonation offences generally assume a human actor directly holding themselves out as another person, rather than the more diffuse scenario of a machine-generated likeness circulated by a third party, and the Act contains no definition of “deepfake,” “synthetic media” or “AI-generated content” at all.

The Nigeria Data Protection Act 2023 governs the processing of personal data, defined broadly enough to capture a person’s image and voice, and requires a lawful basis, most commonly consent, for such processing.[7] In principle, the unauthorized use of someone’s face or voice to train or generate a deepfake could constitute unlawful processing of personal data, giving the Data Protection Commission and the data subject a route to enforcement or complaint. In practice, the Act was designed around conventional data-processing relationships between data controllers and data subjects, such as banks or telecommunications operators, not around anonymous or foreign-based individuals generating synthetic content outside any acknowledged processing relationship, which limits its practical utility against the anonymous or judgment-proof deepfake creator.

The Criminal Code Act supplies general offences of fraud, false pretenses, forgery and related conduct that can, in principle, be applied wherever a deepfake is used to deceive a victim into parting with money or property.[8] These provisions are technologically neutral in the sense that they focus on the deceptive act rather than its medium, but they were not designed to address the distinctive evidentiary and attributional problems that synthetic media creates, such as establishing who trained the model, who deployed it, and whether the resulting content was reasonably capable of deceiving its audience.

Finally, the Constitution of the Federal Republic of Nigeria 1999, as amended, guarantees the right to privacy in section 37 and freedom of expression in section 39.[9] These provisions cut in different directions in the deepfake context: section 37 supports a victim’s claim against unauthorized use of their likeness, while section 39 protects legitimate uses of synthetic media such as satire, parody and political commentary, meaning that any future deepfake-specific offence will need to be drafted narrowly enough to survive constitutional scrutiny without becoming so broad that it chills protected speech, in the manner that the pre-2024 section 24 of the Cybercrimes Act was found to do.

IS THE EXISTING LEGAL FRAMEWORK ADEQUATE?

The preceding survey suggests that existing Nigerian law can, at best, address deepfake-related conduct by analogy rather than by design. None of the four instruments examined expressly defines or regulates deepfakes, synthetic media or AI-generated content, which creates genuine legal uncertainty: a prosecutor relying on the impersonation or forgery provisions of the Cybercrimes Act must persuade a court that a wholly synthetic, machine-generated likeness falls within language drafted for human impersonation, an argument that is plausible but untested in Nigerian courts.

Liability is a further unresolved question. A deepfake typically passes through several hands — the developer of the underlying AI model, the person who trains or prompts it to produce a specific output, the platform on which it is hosted, and the individuals who further distribute it — and existing law offers no clear rule for allocating responsibility among these actors, most of whom bear little resemblance to the traditional forger or fraudster the Criminal Code and Cybercrimes Act contemplate. Related to this is the problem of establishing authorship and intent: because generative AI tools can be prompted anonymously and models can be run without leaving the kind of trail traditional forgery leaves, proving who created a given deepfake, and with what state of mind, is considerably harder than in analogue cases of fraud or defamation.

Courts will also face acute evidentiary problems. As synthetic media becomes harder to distinguish from genuine recordings, the traditional presumption that audio-visual evidence is authentic unless shown otherwise becomes less safe, requiring new rules on authentication, expert testimony and the burden of proving that content is, or is not, AI-generated — none of which the Evidence Act currently supplies in deepfake-specific terms.

Victims, meanwhile, have limited practical remedies: a defamation or privacy action can take years to resolve in Nigerian courts, offers no mechanism for rapid takedown of viral synthetic content, and does little to help a victim whose fabricated intimate images have already been widely shared.

Taken together, these problems support the conclusion that although existing Nigerian laws can potentially address some conduct involving deepfakes, they were not specifically designed to address the distinctive legal and evidentiary challenges created by AI-generated synthetic media, leaving the technology to be regulated, unevenly and unpredictably, through statutes drafted for a different kind of wrongdoing.

COMPARATIVE/INTERNATIONAL PERSPECTIVE

Other jurisdictions have begun to legislate for deepfakes directly, offering lessons rather than templates for Nigeria. The European Union’s Artificial Intelligence Act imposes, from August 2026, a transparency obligation under Article 50 requiring any deployer of an AI system that generates or manipulates image, audio or video content amounting to a deepfake to disclose that the content is artificially generated, with a narrower disclosure duty for content that is evidently artistic, satirical or fictional.[10] The EU’s approach illustrates a workable middle path: rather than banning deepfakes outright, it targets the absence of disclosure, which most directly causes the deception-related harms identified above, while leaving room for legitimate creative and commercial uses.

The United States has developed its response in a fragmented, sector-specific manner. At the federal level, the TAKE IT DOWN Act, signed into law in May 2025, criminalizes the publication of non-consensual intimate imagery, expressly including AI-generated “digital forgeries,” and compels covered platforms to establish a notice-and-removal process for victims within a fixed statutory deadline.[11] Separately, dozens of individual states have enacted their own laws addressing election-related deepfakes and unauthorized digital replicas of a person’s voice or likeness, producing a patchwork that is more protective in some states than in others.[12] The lesson for Nigeria lies less in the substance of any single American statute than in the value of separating the sexual-exploitation, election and general-fraud strands of the deepfake problem into distinct, purpose-built provisions, rather than relying on one general impersonation offence to do all the work.

The United Kingdom, by contrast, has so far relied on existing sectoral regulators, applying the Online Safety Act’s content-moderation duties and general data-protection and harassment law to deepfake-related harms rather than adopting a horizontal deepfake statute.[13] This model shows that a purpose-built AI statute is not strictly indispensable, but it also illustrates the gap that persists without one: victims and regulators must stretch instruments not designed for synthetic media — precisely the criticism levelled at Nigeria’s own framework in the preceding Part. The overall lesson for Nigeria is that transparency obligations, victim-centered takedown mechanisms and offence-specific drafting for intimate imagery and election interference are more effective than reliance on general-purpose cybercrime or fraud provisions alone.

THE CASE FOR LEGISLATIVE REFORM

Nigeria should adopt a clear statutory definition of “deepfake” or “synthetic media” that captures AI-generated or AI-manipulated audio, image and video content depicting a real, identifiable person, to remove the interpretive uncertainty identified in Part V. Building on that definition, the law should create specific offences for the malicious creation and distribution of deepfakes intended to deceive, defraud, defame or harass, distinct from and additional to the general impersonation and forgery offences in the Cybercrimes Act. Non-consensual synthetic intimate imagery deserves particularly strong protection, following the approach of the federal American statute, including criminal liability for creation as well as distribution, and a mandatory, time-bound takedown obligation on hosting platforms operating in Nigeria.

Reform should also clarify rules on impersonation and identity misuse to expressly cover synthetic likenesses, and should give victims accessible civil remedies, including expedited injunctive relief, that do not depend on the slow pace of ordinary civil litigation. Because deepfakes typically pass through platforms before causing harm, the law should impose graduated obligations on those platforms, proportionate to their scale and Nigerian user base, to detect, label and act on reported synthetic content, in the spirit of the EU’s transparency-based approach. Nigeria’s Evidence Act should be updated with evidentiary mechanisms for authenticating digital content, such as recognized technical standards for detecting AI generation and clear rules on the burden of proof once a party alleges that contested content is synthetic.

Any reform must, however, be drafted narrowly enough to protect legitimate uses such as satire, journalism, education and artistic expression, and to avoid the vagueness that made the pre-2024 section 24 of the Cybercrimes Act vulnerable to misuse against government critics. A disclosure-based obligation, modelled on the EU’s approach, is generally preferable to outright prohibition because it addresses the deception at the heart of the harm without unduly restricting expression, and it should be paired with proportionate, clearly defined penalties so that enforcement does not become another avenue for the arbitrary application the 2024 amendment was itself meant to correct.

CONCLUSION

Nigeria’s existing legal framework — comprising the Cybercrimes Act, the Nigeria Data Protection Act, the Criminal Code Act and relevant constitutional guarantees — provides some mechanisms capable of addressing conduct associated with deepfakes, but significant regulatory gaps remain in definition, liability, evidentiary practice and victim remedy. The rapid development of generative AI, and its ready availability to ordinary users, means these gaps are unlikely to close on their own. Targeted legislative reform, drawing selectively on the European Union’s disclosure-based model, the United States’ offence-specific approach to intimate imagery, and lessons from the United Kingdom’s reliance on general regulators, is necessary to protect individuals, public institutions and Nigeria’s democratic processes, while preserving legitimate technological innovation and the freedom of expression that section 39 of the Constitution guarantees.

To what extent, then, is Nigeria’s existing legal framework adequate for regulating AI-generated deepfakes?

The honest answer is: only partially — and reform grounded in clear definitions, allocated liability and workable evidentiary rules is the necessary next step.

REFERENCES

  • Legislation
  1. Constitution of the Federal Republic of Nigeria 1999 (as amended).
  2. Cybercrimes (Prohibition, Prevention, etc.) Act 2015.
  3. Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024.
  4. Nigeria Data Protection Act 2023.
  5. Criminal Code Act, Cap C38, Laws of the Federation of Nigeria 2004.
  • Foreign and International Instruments
  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 1689, art 50.
  2. TAKE IT DOWN Act, Public Law No 119-12, 139 Stat 218 (2025) (US).
  3. Online Safety Act 2023 (UK).
  • Cases

Incorporated Trustees of Laws and Rights Awareness Initiative v Federal Republic of Nigeria, ECOWAS Community Court of Justice, Suit No ECW/CCJ/APP/53/18, Judgment No ECW/CCJ/JUD/16/20 (10 July 2020).

  • Official and Secondary Sources
  1. European Commission, ‘Transparency obligations under Article 50 of the AI Act’ (Shaping Europe’s Digital Future) <https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act> accessed 18 August 2026.
  2. International Association of Privacy Professionals, ‘Nigeria moves toward comprehensive AI regulation’ (IAPP, 28 May 2026) <https://iapp.org/news/a/nigeria-moves-toward-comprehensive-ai-regulation> accessed 18 August 2026.
  3. Recording Law, ‘Deepfake & AI Voice Cloning Laws by State (2026)’ <https://www.recordinglaw.com/us-laws/deepfake-laws/> accessed 18 August 2026.
  4. Olumide Babalola LP, ‘Amendment of Section 24 of the Cybercrimes (Prohibition, Prevention etc) Act 2015: A Fruit of Strategic Litigation’ <https://oblp.org/amendment-of-section-24-of-the-cybercrimes-prohibition-prevention-etc-act-2015-a-fruit-of-strategic-litigation/> accessed 18 August 2026.

[1]Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 1689, art 3(1).

[2]Artificial Intelligence Act (n 1) art 3(60), defining a ‘deep fake’ as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful.

[3]European Commission, ‘Transparency obligations under Article 50 of the AI Act’ (Shaping Europe’s Digital Future) <https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act> accessed 18 August 2026.

[4]Cybercrimes (Prohibition, Prevention, etc.) Act 2015, as amended by the Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024.

[5]Cybercrimes Act 2015 (n 4) s 22 (identity theft and impersonation); ss 13–14 (computer-related fraud and forgery).

[6]Cybercrimes (Amendment) Act 2024 (n 4) s 24; Incorporated Trustees of Laws and Rights Awareness Initiative v Federal Republic of Nigeria, ECOWAS Community Court of Justice, Judgment No ECW/CCJ/JUD/16/20 (10 July 2020).

[7]Nigeria Data Protection Act 2023, ss 2, 24–26 (lawful bases for processing, including consent).

[8]Criminal Code Act, Cap C38, Laws of the Federation of Nigeria 2004, ss 419, 465–468.

[9]Constitution of the Federal Republic of Nigeria 1999 (as amended) ss 37, 39.

[10]Artificial Intelligence Act (n 1) art 50(4).

[11]TAKE IT DOWN Act, Public Law No 119-12, 139 Stat 218 (2025) (US).

[12]Recording Law, ‘Deepfake & AI Voice Cloning Laws by State (2026)’ <https://www.recordinglaw.com/us-laws/deepfake-laws/> accessed 18 August 2026.

[13]Online Safety Act 2023 (UK); Bradby Law, ‘AI Act Article 50: Chatbot and Deepfake Rules for UK Firms’ <https://bratby.law/ai-act-transparency-obligations-2026/> accessed 18 August 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top