Single Blog Title

This is a single blog caption

THE LEGAL ASPECTS OF DEEPFAKE TECHNOLOGY

1. INTRODUCTION

The rapid advancements in artificial intelligence technologies have fundamentally transformed the way digital content is produced, modified, and disseminated. One of the most striking consequences of this transformation is deepfake technology, which allows for the highly realistic imitation or combination of personal facial features, images, voices, and expressions using artificial intelligence algorithms. Initially used as an innovative tool in the film, advertising, education, and entertainment industries, deepfake applications now raise significant legal issues concerning personal rights, privacy, data protection, criminal law, intellectual property law, and the reliability of digital evidence.

The most distinctive feature of deepfake content is that it blurs the line between reality and fiction. The ability to make a person appear to have said something they never said, been in an environment they never attended, or performed an action they never carried out, can seriously impact individuals' honor and reputation, economic well-being, professional standing, and social relationships. Manipulated images and audio recordings, which can reach large audiences quickly, especially through social media platforms, can cause significant harm and make the consequences of the violation irreversible.

Deepfake technology is a phenomenon that must be evaluated not only in terms of individual rights, but also in terms of public order and the democratic order of society. It is possible to use fake images and speeches of political figures to influence election processes, mislead public opinion, create social tension, or spread disinformation. Similarly, payment instructions carried out by imitating the voice of a company executive, fake statements misleading investors, and manipulated content targeting commercial reputation constitute a new form of economic crimes and sophisticated fraud methods.

While Turkish law lacks a comprehensive and independent legal framework regulating all aspects of deepfake technology, actions carried out using this technology can have various legal and criminal consequences under existing legal rules. These include the protection of personal rights under the Turkish Civil Code and the Turkish Code of Obligations, the processing of biometric and personal data under Law No. 6698 on the Protection of Personal Data, and offenses such as violation of privacy, unlawful acquisition or dissemination of personal data, defamation, threat, blackmail, fraud, and obscenity under the Turkish Penal Code. Furthermore, it is possible to resort to methods such as content removal and access blocking under Law No. 5651.

One of the major challenges in the legal assessment of deepfake technology is determining which individuals or entities should be held liable. Different liability regimes may apply to the person who created the content, the platform that developed or distributed the deepfake software, the social media account that published the content, and the service providers that facilitated its dissemination. Furthermore, the technical nature of artificial intelligence systems, the identification of the content creator, the preservation of evidence, the acquisition of information from foreign-based platforms, and the complete removal of illegal content present significant practical difficulties.

Another important issue is the use of deepfake content as evidence in trials. The ease with which audio and video recordings can be altered necessitates stricter scrutiny of the accuracy and integrity of digital evidence. Therefore, the mere fact that an image or audio recording appears realistic is not sufficient for it to be considered legally reliable and conclusive evidence. The file's metadata, creation date, source device, hash values, digital integrity, transmission chain, and expert examination must all be considered together.

This study will outline the technical structure of deepfake technology; examine the problems it poses in terms of personal rights, data protection, criminal law, liability for damages, intellectual property rights, and digital evidence law within the framework of Turkish law. Furthermore, it will assess whether existing regulations are sufficient to prevent deepfake-related violations and compensate victims; and discuss the necessary legal and institutional solutions in the face of technological advancements.

2. THE CONCEPT OF DEEPFAKE TECHNOLOGY

2.1. WHAT IS DEEPFAKE TECHNOLOGY?

Deepfake technology is a general term for technological methods that use artificial intelligence, machine learning, and especially deep learning algorithms to imitate, alter, or combine images, voices, facial expressions, gestures, and movements of individuals in a way that is highly realistic. The term "deepfake" is a combination of the English words "deep learning" and "fake.".

This technology allows a person's face to be superimposed onto another person's image, a person's voice to be imitated to make it appear as if they said things they never actually said, or to make inaccurate alterations to an existing image. The produced content can take the form of video, photographs, audio recordings, or real-time images.

Deepfake content is created using artificial neural networks, facial recognition systems, voice synthesis techniques, and generative AI models. These systems analyze a large amount of image or audio data belonging to the target person, learning their facial features, expressions, speech patterns, tone of voice, and movements; they then use these characteristics to create new and realistic content.

Deepfake technology can be used legitimately in the film, advertising, education, art, gaming, and entertainment industries. However, if used without the knowledge and consent of the data subject, it can lead to serious legal problems such as violation of personal rights, violation of privacy, unlawful processing of personal data, fraud, blackmail, reputational damage, disinformation, and the creation of false evidence.

Therefore, deepfake should be defined not merely as a technical method of image or sound alteration, but as a multi-dimensional artificial intelligence technology that makes it difficult to distinguish between real and artificial content and can have implications for individuals' fundamental rights, public order, commercial security, and judicial processes.

2.2. APPLICATION AREAS OF DEEPFAKE TECHNOLOGY

Deepfake technology is not merely a tool used to produce fake images or sounds. This AI-powered technology can be used in many different fields, including cinema, television, advertising, education, healthcare, art, digital communication, and security. However, depending on the purpose of use, the consent of the individual involved, and the resulting outcome, deepfake applications can be either legal or illegal.

2.2.1. Film and Television Industry

One of the most common applications of deepfake technology is in the film and television industry. This technology has made it possible to make actors appear younger or older, to bring deceased actors back to life in specific scenes, to adapt lip movements during dubbing to different languages, and to correct filming errors digitally.

The ability to perform expensive visual effects processes faster and at a lower cost makes deepfake technology a significant tool for production companies. However, the unauthorized use of actors' faces, voices, or body images can create disputes regarding personal rights, copyrights, performing artist rights, and contractual rights.

2.2.2. Advertising and Marketing Activities

Deepfake technology can be used in the advertising and marketing industry to create personalized content. Examples include showing the same person speaking different languages ​​in an advertisement, using digital images of famous people in product promotions, or preparing advertising messages tailored to consumers.

However, using a person's face, voice, or other identifiable features in commercial advertising without their consent may constitute a violation of personal rights. Unauthorized use of images of well-known individuals can also raise legal issues such as unfair competition, unlawful processing of personal data, and unauthorized use of financial gain.

2.2.3. Education and Training Activities

Deepfake technology can be used in education to bring historical figures to life, create realistic speech examples in foreign language teaching, prepare virtual teachers, and adapt lesson content to different languages. These applications can increase student interest in lessons and make educational materials more effective.

For example, portraying a historical figure as if speaking through artificial intelligence can contribute to a more understandable account of events from a particular period. However, in such content, a clear distinction must be made between real events and fictional narratives. Otherwise, the spread of misinformation, the alteration of historical facts, and the misleading of students may occur.

2.2.4. Field of Arts and Culture

Deepfake applications can be used in the production of digital artworks, in enhancing museum and exhibition experiences, and in recreating historical figures or artists. Artists can create new visual or auditory works by combining facial, voice, and motion data from different individuals.

While this form of use may be protected under freedom of expression and artistic freedom, it may face legal limitations regarding the rights of the author, personality rights, trademark rights, and the protection of personal data. Particularly in content where individuals are clearly identifiable, consent, the purpose of use, and the manner in which the content is presented to the public are important considerations.

2.2.5. Gaming and Virtual Reality Applications

In computer games, augmented reality, and virtual reality applications, deepfake technology can be used to create more realistic characters. This includes transferring a player's face onto a game character, simultaneously reflecting facial expressions in a digital environment, and creating personalized virtual characters.

With the development of metaverse applications, the use of people's facial and voice data on digital avatars is becoming widespread. In this context, the processing of biometric data, explicit user consent, data security, and the prevention of misuse of digital identities are gaining importance.

2.2.6. Health and Medical Applications

Deepfake technology can be used in the healthcare field for education, rehabilitation, and communication purposes. Examples of these applications include creating realistic patient simulations for medical students, utilizing digital models in the treatment of diseases affecting speech or facial movements, and supporting communication for individuals with disabilities.

For example, it is possible to create an artificial voice similar to that of a person who has lost the ability to speak, using their past voice recordings. However, since health data and biometric data are special categories of personal data, a high level of data security must be ensured during the processing of this data, and the informed consent of the data subject must be obtained.

2.2.7. News, Media and Journalism Activities

Media organizations can use deepfake technology for documentaries, animations, dubbing, and visual storytelling. Adapting news content into different languages ​​or narrating past events with representative images are among the legitimate uses of the technology in journalism.

However, publishing deepfake content as if it were news footage can mislead the public and lead to the rapid spread of misinformation. Therefore, it is important to clearly label content created using deepfakes and inform the viewer that the image has been artificially produced.

2.2.8. Political Communication and Public Opinion Formation

Deepfake technology can be used in political campaigns, election processes, and public opinion shaping activities. Videos that falsely attribute statements to politicians, spread misinformation that could influence election results, and create fake statements that could disrupt public order are among the most dangerous uses of this technology.

Such content can influence voters' will, damage the reputation of political figures, and increase social polarization. Therefore, political deepfake content should be evaluated in terms of freedom of expression, election security, personal rights, and public order.

2.2.9. Fraud and Social Engineering

One of the illegal uses of deepfake technology is fraud. Examples include imitating the voice of a company executive to solicit money transfers from employees, using the images or voices of family members to request urgent cash, and misleading investors with false statements.

The ability to use voice imitation systems in real time makes fraud methods carried out via telephone and video calls more convincing. In such cases, the victim's free will is compromised by fraudulent behavior, resulting in economic harm.

2.2.10. Blackmail, Threats, and Reputation Damage

Examples of misuse of deepfake technology include superimposing a person's face onto sexually explicit images, making them appear to have committed a criminal act, or presenting them as if they have made statements that could provoke public outrage.

These contents can have serious consequences for the victim's family, work, and social life. Deepfake images with sexual content, in particular, can severely violate a person's privacy, honor, reputation, and psychological integrity. If the content is sent to the victim in exchange for money or other benefits, the crime of blackmail may also be considered.

2.2.11. Identity Impersonation and Creating Fake Accounts

Deepfake technology can be used to mimic a person's image and voice, create fake social media accounts in that person's name, or deceive video authentication systems. This poses significant security risks for banking transactions, electronic contracts, remote customer acquisition, and digital payment systems.

The compromise of a person's digital identity can lead not only to financial losses but also to violations of personal rights and data protection. Therefore, facial and voice recognition systems should not rely solely on a single biometric data point but should be supported by additional verification mechanisms.

2.2.12. Cybersecurity and Security Testing

Deepfake technology can be used in malicious attacks, but it can also be used to test the resilience of security systems. Banks, government agencies, and technology companies can conduct controlled tests to determine how secure their facial recognition or voice verification systems are against deepfake attacks.

These applications contribute to the early detection of attack methods and the development of protective systems. However, personal data used for security testing must be obtained legally, usage limits must be clearly defined, and the data obtained from the test results must be protected.

2.2.13. The Field of Litigation and Digital Evidence

Deepfake technology has a twofold impact on legal processes. On the one hand, it allows for the creation of fake evidence through the manipulation of video and audio recordings, while on the other hand, deepfake detection tools can be used to investigate the authenticity of evidence.

The mere submission of an image or audio recording to court does not automatically prove its accuracy and reliability. The source of the digital content, its creation time, metadata, hash values, chain of custody, and whether it has been altered must be determined through technical expert examination. The development of deepfake technology necessitates a more cautious and technical approach to the evaluation of digital evidence.

Overall Assessment

The applications of deepfake technology are expanding every day. The technology can provide significant benefits in many areas, from education and healthcare to cinema and digital security. However, its use without consent, presenting the content as if it were real, and misleading third parties can lead to serious legal consequences.

Therefore, when evaluating the legality of deepfake technology, the purpose for which the content was produced, whether the data subject consented, whether the content was clearly artificially labeled, how it was presented to the public, and whether it caused any harm should all be considered. While the technology itself is not inherently illegal, its manner of use, purpose, and consequences constitute the fundamental criteria in determining legal responsibility.

3. THE LEGAL ASPECTS OF DEEPFAKE TECHNOLOGY

Deepfake technology allows for the imitation or alteration of a person's image, voice, facial expressions, speech patterns, and movements through artificial intelligence. While the technology has legally permissible uses in fields such as cinema, education, art, advertising, and healthcare, its use without the knowledge and consent of the individual can have serious legal consequences.

When determining the legal nature of deepfake content, not only the technology used but also the purpose of its creation, the consent of the individual concerned, the manner in which the content was published, whether the recipients were misled, and the nature of the resulting harm must be considered. Therefore, the mere use of deepfake technology is not illegal. Illegality arises depending on the purpose of the technology's use and the consequences it produces.

Turkish law does not have a specific legal regulation that encompasses all deepfake applications and creates a separate crime or liability type under the name of "deepfake crime." However, deepfake content is subject to existing regulations within the scope of protection of personal rights, tort liability, protection of personal data, criminal law, intellectual property law, unfair competition, and digital evidence law.

3.1. Violation of Personal Rights

One of the most significant legal consequences of deepfake content is the violation of personal rights, encompassing both material and moral integrity. A person's image, voice, name, honor and reputation, private life, professional standing, and social identity are all protected under the right to personality.

According to Article 24 of the Turkish Civil Code No. 4721, a person whose personal rights have been unlawfully violated may request protection from the court against those who committed the violation. A person whose personal rights have been harmed may, within the scope of Article 25 of the Turkish Civil Code;

  • Preventing the anticipated attack,
  • The ongoing attack must stop
  • Determining the illegality of the ongoing attack,
  • Notifying third parties of the correction or decision,
  • He wants the profits obtained from the attack to be given to him

can request.

Superimposing a person's face onto a sexually explicit image, portraying them as having committed a crime, attributing statements to them that they did not make, or presenting them as having engaged in behavior that would provoke a negative reaction in society may constitute an attack on their right to personality.

The fact that an individual has previously given permission for their image or sound to be recorded does not mean they also consent to that data being used in the production of deepfake content. Consent is limited to a specific purpose and scope of use. For example, an actor giving permission for their image to be used in a particular commercial does not legally make it permissible for that image to be subsequently used in another commercial or political content through artificial intelligence.

3.2. Liability for Material and Moral Damages

Deepfake content can lead to tort liability if it infringes on personal rights or causes economic harm to an individual. According to Article 49 of the Turkish Code of Obligations, a person who causes harm to another through a negligent and unlawful act is obligated to compensate for the resulting damage.

Victim due to deepfake content;

  • Having lost their job or customers,
  • Its commercial reputation has been damaged
  • Advertising or sponsorship agreements have expired,
  • Their professional activities have been disrupted,
  • Having suffered financial losses due to fraud,
  • They incurred expenses to remove the content and restore their reputation

This is possible. In this case, in addition to direct damages, lost earnings can also be claimed as part of monetary compensation if the conditions are met.

According to Article 58 of the Turkish Code of Obligations, a person who has suffered damages due to the violation of their personal rights may claim compensation for moral damages. In determining the amount of moral damages, factors such as the nature of the deepfake content, its reach, the number of people it affected, the victim's social and professional status, the duration the content remained online, and the impact of the violation on the victim may be considered.

Deepfake images, especially those with sexual content, can cause significant emotional distress, with severe and long-lasting consequences for the victim's family, work, and social life. The repeated sharing of this content online by different accounts can also exacerbate and worsen the damage.

3.3. Implications Regarding the Protection of Personal Data

Photographs, videos, audio recordings, facial expressions, gestures, and speech characteristics used in the creation of deepfake content may constitute personal data. The collection, recording, modification, transfer to artificial intelligence models, reproduction, and publication of this data may constitute personal data processing activities.

When facial or voice data is subjected to special technical processes for the purpose of uniquely identifying or verifying an individual, it also becomes considered biometric data. Biometric data is classified as special categories of personal data within the scope of Article 6 of the Law No. 6698 on the Protection of Personal Data.

In order for personal data to be used in deepfake production, a data processing condition stipulated in the KVKK (Turkish Personal Data Protection Law) must be met. Furthermore, the data must:

  • Processing in accordance with the law and principles of fairness,
  • Use for specific, clear and legitimate purposes,
  • It must be relevant to the processing purpose, limited and proportionate
  • It must be kept for the required period of time
  • Protection against unauthorized access and use

It is mandatory.

A photograph or video that a person publicly shares on their social media account does not automatically become data that can be used without limit for any purpose. Whether data is considered public can only be assessed in relation to the uses associated with the individual's intention and purpose of making it public. The fact that a photograph is publicly available does not automatically make it legally permissible to insert a person's face into fake, sexual, political, or commercial content without their consent.

Individuals whose personal data has been processed unlawfully have the right to contact the data controller to inquire whether their data is being processed, to request information about the purpose of the processing, to request the deletion or destruction of the unlawfully processed data, and to claim compensation for the damages suffered. If the data controller fails to fulfill its obligations under the Personal Data Protection Law (KVKK), complaints to the Personal Data Protection Board and administrative sanctions may also be considered.

The Personal Data Protection Authority states that one of the main risks of deepfake technology is the processing and manipulation of personal data; these contents can lead to consequences such as fraud, cyberbullying, and financial harm. The Authority also recommends that artificial intelligence systems should adhere to the principles of legality, transparency, proportionality, data security, and data protection from the design stage.

3.4. Consequences from a Criminal Law Perspective

The Turkish Penal Code does not contain a separate crime that only punishes the creation of deepfake content. Due to the principle of legality in crime and punishment, for an act to be punishable, it must contain the elements of a crime regulated in the Turkish Penal Code or in special penal codes.

Depending on how deepfake content is created and used, different crimes may arise.

3.4.1. Insult

Presenting someone as having committed a concrete act that would damage their honor, reputation, and dignity, or portraying them as having uttered derogatory words, may constitute the crime of defamation as defined in Article 125 of the Turkish Penal Code, provided the conditions for such actions are met.

For example, a fake video that gives the impression that a person has accepted a bribe, admitted to cheating on their spouse, or engaged in socially reprehensible behavior, can target the victim's honor and reputation. The dissemination of the content via the internet or social media may also necessitate an assessment of the public nature of the crime.

3.4.2. Violation of the Right to Privacy

Altering real images related to a person's private life, using intimate images in the production of deepfake content, or creating and publishing false content about a person's sexual life may constitute a violation of the right to privacy under Article 134 of the Turkish Penal Code.

The fact that a deepfake image is entirely artificially produced does not automatically mean that a crime of violating the privacy of private life will occur. However, if the content uses data relating to the victim's real private life, or if the content gives the impression of a real event related to the victim's private life, an assessment should be made based on the specific characteristics of the case.

3.4.3. Crimes Related to Personal Data

The unlawful recording, acquisition, transfer, or dissemination of personal images, voice recordings, and biometric data may constitute crimes related to personal data as defined in Articles 135 and 136 of the Turkish Penal Code.

If the person creating the deepfake content illegally obtains, stores in a database, or transfers to third parties image or audio recordings belonging to the target individual, both the production of the content and the source of the data used must be examined separately. Article 17 of the Personal Data Protection Law also stipulates that the provisions of the Turkish Penal Code shall apply to crimes related to personal data.

3.4.4. Threats and Blackmail

Sending deepfake content to a victim and demanding money, sexual favors, business benefits, or other actions constitutes blackmail. Requests such as "Send money to prevent this image from being published" can exert pressure on the victim, regardless of whether the content is genuinely fake.

If a deepfake video or audio recording is used to harm the victim or their relatives, provisions relating to threats may also come into play.

3.4.5. Fraud

Facilitating money transfers by impersonating the voice or image of a company executive, family member, bank employee, or public official may constitute a crime of fraud.

The provisions regarding aggravated fraud may be considered, particularly when information systems are used as a tool, fake video calls are made, or benefits are obtained through digital platforms. The trust created by the perpetrator using deepfake technology influences the victim's will through fraudulent behavior, resulting in financial loss.

3.4.6. Defamation and Fabrication of Crimes

Submitting deepfake content to authorities that falsely portrays a person as having committed a crime they did not commit, or preparing fake evidence to initiate an investigation against that person, may constitute defamation or fabricating a crime.

For the crime of defamation to occur, merely publishing the content to the public may not be sufficient. There must also be legal requirements, such as reporting or filing a complaint with the competent authorities to initiate administrative or judicial investigations or prosecutions against the person accused of the unlawful act.

3.4.7. Obscenity

Deepfake images with sexual content may trigger the provisions of the Turkish Penal Code regarding obscenity, depending on the nature of the content, the age of the victim, and the method of its production and dissemination. Much harsher penalties and protective measures may apply to content involving images of children or children.

3.4.8. Publicly Disseminating Misleading Information to the Public

If deepfake content contains false information related to the country's internal and external security, public order, or public health, Article 217/A of the Turkish Penal Code may also be considered. For this to apply, the false information must be publicly disseminated solely for the purpose of creating anxiety, fear, or panic among the public, in a manner likely to disrupt public peace.

Not all false or misleading deepfake content constitutes this crime. The perpetrator's motive, the subject matter of the content, and its potential to disrupt public peace must be examined separately within the specific context of the case.

3.5. Implications Regarding Intellectual Property and Portrait Rights

Deepfake production may utilize films, photographs, musical works, sound recordings, acting performances, or other intellectual property. Reproduction, modification, processing, or public dissemination of this content without permission from the copyright holder or author may constitute a copyright infringement under the Law No. 5846 on Intellectual and Artistic Works.

The use of footage from an actor's previous film scenes in a new production, the creation of a new song by artificial intelligence imitating the artist's voice, or the alteration and publication of an artist's performance should be evaluated in terms of copyright and related rights.

The provisions regarding the protection of paintings and portraits regulated in Article 86 of the Law on Intellectual and Artistic Works may also be important in terms of the use of images of real people in deepfake content. In addition, the right to a person's image is also protected as a personality right under the Turkish Civil Code.

3.6. Commercial Reputation and Unfair Competition

Deepfake content can also have legal consequences for companies and businesses. Creating the impression that a company executive has made false statements claiming the company is bankrupt, that its products are unsafe, or that a specific investment decision has been made, can negatively impact the company's commercial reputation and economic operations.

Creating misleading deepfake content about a competing business may be evaluated under the provisions of the Turkish Commercial Code regarding unfair competition. If a competitor's products or commercial activities are slandered through false or misleading statements; if customers are deceived; and if the competitive order in the market is disrupted, the determination, prevention, elimination of the consequences of unfair competition, and claims for compensation may arise.

The use of deepfake content in conjunction with a brand, logo, or trade name may also constitute trademark and trade name infringement if it leads consumers to believe that the content has been endorsed by the rights holder.

3.7. Removal of Content from the Internet

Deepfake content is mostly spread through social media, video sharing platforms, and websites. It is crucial for the protection of victims that the content is removed quickly, as well as being identified as illegal.

Article 9 of Law No. 5651, which regulated the removal of content and blocking access due to violations of personal rights, was annulled by the Constitutional Court's decision numbered E.2020/76, K.2023/172, and the annulment entered into force on October 10, 2024. Therefore, the possibility of applying to the magistrates' court under the old Article 9 based solely on a general violation of personal rights is not valid under current law.

Conversely, if internet content directly violates the right to privacy, the procedure outlined in Article 9/A of Law No. 5651 can be applied. Furthermore, it is possible to contact the content provider, hosting provider, or social network provider; to file a lawsuit to stop the violation under the Turkish Civil Code; and to request a preliminary injunction under the Code of Civil Procedure. The 9/A mechanism concerning the right to privacy remains in effect in the current legal text.

Sharing content simultaneously on platforms in different countries can make enforcing removal orders more difficult. Therefore, URLs, usernames, sharing dates, and screenshots of the content should be identified without delay; and if possible, evidence should be secured through notarization, timestamps, or digital forensics methods.

3.8. Evidential Value of Deepfake Content

One of the most significant consequences of deepfake technology from a legal perspective is that it raises doubts about the reliability of audio and video recordings.

According to Article 199 of the Code of Civil Procedure, photographs, films, images, sound recordings, and data in electronic format are considered documents. However, the acceptance of digital content as a document does not necessarily mean that its accuracy and preservation from alteration are definitively accepted.

In criminal proceedings, a judge may base their decision on legally obtained evidence presented and discussed in court. While evidence may be freely evaluated, the conviction must be based on conclusive and convincing evidence, free from any doubt.

In evaluating an audio or video recording that is alleged to be a deepfake;

  • Whether the original file exists or not,
  • The creation and modification dates of the file,
  • Metadata information,
  • The hash value of the file,
  • The device from which the recording was obtained,
  • The file retention and transfer chain,
  • The light, shadows, and facial movements in the image,
  • Voice frequency and speech characteristics,
  • Whether the file contains cuts, merges, or re-encodes

It should be examined.

The mere fact that a video looks realistic or sounds like the person's voice does not prove the evidence is genuine. Similarly, a party's abstract assertion that "this content might be a deepfake" is not sufficient to dismiss the evidence entirely. The claim must be evaluated in conjunction with a technical expert examination and other evidence.

3.9. Identifying Responsible Persons

In deepfake content, responsibility may not be limited solely to the person who originally created the video. Depending on the specifics of the case;

  • The person who created the content,
  • The person who gives the production instructions,
  • The person who provides personal data,
  • The person who first published the content,
  • Individuals who knowingly repost illegal content,
  • Businesses that use the content for advertising or commercial gain,
  • Companies that act as data controllers,
  • Content and location providers

Different types of responsibility may arise in this regard.

In some cases, simply sharing content can contribute to the continuation of the violation of personal rights and the escalation of harm. However, when determining the responsibility of the person sharing the content, factors such as whether they were aware of the illegality of the content, the purpose of the sharing, the comments added to the content, and the audience reached should be considered.

The company that developed the artificial intelligence tool cannot be automatically held responsible. Whether the company defined the purpose of the system's use, its role in processing personal data, the measures it took to prevent risks, whether it was aware of unlawful use, and its response to requests for content removal must all be considered together.

3.10. Deepfake in the Context of the European Union Artificial Intelligence Regulation

The European Union's Artificial Intelligence Regulation (Regulation 2024/1689) imposes specific transparency obligations for deepfake content. Article 50 of the Regulation requires those who produce or use deepfake image, audio, or video content to disclose that the content has been artificially produced or altered.

For works of artistic, creative, satirical or fictional nature, the obligation to provide explanations is considered to be fulfilled in a manner that does not hinder the exhibition or use of the work. While some provisions of the regulation came into effect earlier, it will generally apply from August 2, 2026

The transparency approach introduced in the EU is based not on completely banning deepfake content, but on clearly stating that the content is artificial and preventing users from being misled. For Turkey, clearly labeling artificially produced content, developing technical tagging systems, and imposing rapid response obligations on platforms are among the methods that could be considered in future regulations.

Overall Assessment

Deepfake technology is a multi-faceted technology that combines different areas of existing legal rules within a single event. The creation and dissemination of a single deepfake content can simultaneously give rise to violations of privacy rights, unlawful processing of personal data, torts, intellectual property rights infringement, and criminal liability.

In legal assessment, it is as important whether the content creates the impression of being real in the viewer as it is whether it is artificially produced. Clearly stating that the content is a parody, fiction, or a product of artificial intelligence can affect the assessment of illegality. Conversely, presenting the content as real, targeting a specific person, or aiming to cause harm or gain benefit are factors that can aggravate liability.

One of the biggest problems with deepfake-related breaches is that the content reaches a wide audience very quickly and is difficult to completely remove. Therefore, in addition to legal applications, it may be necessary to simultaneously consider avenues such as rapid evidence gathering, removal requests from platforms, preliminary injunctions, criminal investigations, and applications related to the protection of personal data.

In conclusion, deepfake technology itself is not illegal or prohibited. However, its use without consent, presenting false content as if it were true, deceiving third parties, or targeting individuals' honor, reputation, privacy, and property leads to serious legal and criminal liabilities. While current regulations are applicable to many violations, the speed and spread of the technology highlight the need for clearer and more specific regulations for identifying, labeling, removing deepfake content, and determining those responsible.

4. REGULATIONS REGARDING DEEPFAKE IN TURKISH LAW

There is no specific law in Turkish law that directly and comprehensively regulates deepfake technology. However, the creation, use, and dissemination of deepfake content may be subject to existing legislation under the scope of personal rights, data protection, criminal law, intellectual property, and internet law.

According to Articles 24 and 25 of the Turkish Civil Code, the unlawful use of a person's image, voice, honor, and reputation may constitute a violation of personal rights. The victim may request the prevention or cessation of the attack, the determination of the unlawfulness, and, if necessary, the removal of the content. Furthermore, it is possible to claim material and moral damages under the Turkish Code of Obligations.

Face, voice, photograph, and video recordings used in deepfake production may constitute personal data. The unlawful collection, processing, or dissemination of this data may be subject to the provisions of Law No. 6698 on the Protection of Personal Data. In particular, biometric data provisions may come into play when face and voice data are processed for identity verification purposes.

While the Turkish Penal Code does not contain a separate deepfake crime, depending on the nature of the specific case, offenses such as defamation, violation of privacy, unlawful acquisition or dissemination of personal data, threat, blackmail, fraud, and slander may occur.

If deepfake content is created using original works, photographs, films, audio recordings, or artist performances, the Law on Intellectual and Artistic Works may also apply. Misleading content targeting commercial businesses or brands may constitute unfair competition under the Turkish Commercial Code.

Against deepfake content published on the internet, requests can be made to platforms for its removal, preliminary injunctions can be requested from civil courts, and in cases of violation of privacy, the remedies provided for in Law No. 5651 can be utilized.

In conclusion, while there is no single regulation specific to deepfake technology in Turkish law, existing legal rules can be applied together according to the specific circumstances of the case to protect the victim and ensure the legal or criminal liability of those responsible.

5. CONCLUSION

Deepfake technology, with the advancement of artificial intelligence, has made it possible to alter image and sound content to a highly realistic level. While this technology can be used beneficially in education, art, and entertainment, it also poses serious legal risks such as violation of personal rights, breach of privacy, fraud, blackmail, reputational damage, and the creation of false evidence.

While Turkish law does not contain specific regulations regarding deepfake technology, existing legislation can be applied to specific cases. Legal and criminal liability may arise under the Turkish Civil Code, the Turkish Code of Obligations, the Turkish Penal Code, the Law on the Protection of Personal Data, and other relevant regulations.

However, the rapid advancement of technology and the ability of deepfake content to reach large audiences quickly make it difficult for existing regulations to always be sufficient and effective. Therefore, it is necessary to clearly identify deepfake content, ensure the swift removal of illegal content, and create specific regulations to provide victims with effective legal protection.

In conclusion, rather than banning deepfake technology, ensuring its lawful, transparent, and auditable use is crucial for protecting individuals' fundamental rights and public trust in information.

Leave a Reply

Call Now Button