Culture & Media

AI Stole Celebrity Identity at Industrial Scale. The Law Caught up to Version One.

Three separate legal milestones landed within weeks of each other — and together they reveal how thoroughly synthetic-media abuse has outpaced the institutions trying to contain it.

Julian CrossJuly 1, 20268 min read
AI Stole Celebrity Identity at Industrial Scale. The Law Caught Up to Version One.

On June 18, 2026, the U.S. Senate Judiciary Committee did something that almost never happens in the current Congress: it agreed on something. The committee unanimously advanced S. 4591[2], the Nurture Originals, Foster Art, and Keep Entertainment Safe Act of 2026 — the NO FAKES Act — by voice vote. The bill would, for the first time in American law, create a federal property right over a person's voice and visual likeness and establish civil liability for unauthorized AI-generated digital replicas. Senators from both parties called it historic. Advocacy groups called it overdue. And the technology it is meant to constrain had, in the months before the vote, already operated at a scale that makes the bill's notice-and-takedown machinery look like a garden hose aimed at a river.

This is the defining rhythm of AI regulation in 2026: laws arrive, unanimously, to address a problem that has already industrialized. Three events, landing within roughly two months of each other, draw this gap in sharp relief. Sony pulled 135,000 AI-generated deepfake songs from streaming platforms. An Ohio man became the first person convicted under the Take It Down Act, a federal law targeting nonconsensual AI intimate imagery. And the NO FAKES Act cleared committee, moving toward a Senate floor vote that has yet to be scheduled. Taken together, they tell a story less about legislative progress than about the velocity mismatch between a technology that scales instantly and a legal system that deliberates slowly — by design.

135,000 Tracks, One Label, Three Months

In March 2026, at the launch of the IFPI Global Music Report[4], Sony Music said it had requested removal of more than 135,000 AI-generated deepfake tracks[4] impersonating its artists, with roughly 60,000 of those flagged in just the prior year. The affected artists included Beyoncé, Queen, and Harry Styles. Sony said this type of content is causing "direct commercial harm to legitimate recording artists" and is becoming more common as the technology becomes cheaper and easier to use.

The mechanism is fairly simple, and that simplicity is the problem. Deepfakes clone an artist's voice or falsely tag a track as featuring a known name, then upload it to streaming platforms to ride that artist's audience. Sony's digital chief Dennis Kooker describes the problem as demand-driven: fakes are at their worst when they build off the demand an artist has already created, which is why a rising release or a returning catalog act can attract them. In other words, the more successfully an artist promotes their work, the larger the surface area for exploitation. Fame becomes a liability that third-party AI operators can monetize without permission or cost.

Though Sony has removed the 135,000 AI-identified tracks, it's possible this is only a portion of AI-generated content being uploaded across Spotify and Apple Music. That suspicion is shared widely across the industry. Unofficially, the industry believes up to 10% of content across all streaming platforms is fraudulent. And separately, Deezer's AI-music detection tool found that over 60,000 AI-generated tracks were uploaded daily[3] to its platform in 2025, accounting for roughly 39% of daily music deliveries. These are not fringe numbers. They describe a structural condition of how music now circulates — one that Sony's legal team is managing track by track, week by week, using takedown requests that the NO FAKES Act would, if passed, give sharper legal teeth.

“Fame becomes a liability that third-party AI operators can monetize without permission or cost.”

The First Conviction, and What It Cost to Get There

The second data point arrived in April. On April 7, 2026, James Strahler II, 37, of Columbus pleaded guilty to a campaign of cyberstalking and AI-assisted abuse, and prosecutors announced that his conviction on one of the charges makes him the first person in the United States convicted under the Take It Down Act[1] — the landmark federal law signed by President Trump in May 2025 that specifically criminalizes the nonconsensual creation and publication of AI-generated intimate imagery. The case was severe. On his phone, Strahler had 2,400 images and videos depicting nudity, violence, or AI-generated child sexual abuse material, and he had downloaded more than 24 AI platforms and over 100 web-based AI models.

What's instructive is how the case reached federal court at all. Local police in Hilliard, Ohio, initially had almost nothing. The conduct that Strahler was engaged in fell into gaps between misdemeanor dissemination statutes. As investigators uncovered more evidence including AI-generated content, the detective described hitting the limits of local law: "At that time, we didn't have a sextortion law. The charge was dissemination of illicit images, which is a misdemeanor of the first degree. It either falls under menacing-by-stalking or a pandering charge. The federal court system does have artificial intelligence charges, and that's how I was put in contact with the federal prosecutors." A law had to be signed, platforms had to be given a year to build compliance infrastructure, and a federal prosecutor had to be found before the criminal system could engage with behavior that had been happening for over a year.

The conviction matters. But legal experts note that not every federal prosecutor could prosecute every case that comes to them, because this behavior is too pervasive. At least 45 states have now passed local laws related to AI deepfakes, some specifically tailored toward protecting minors, suggesting that the patchwork below the federal level is already thick with jurisdictional friction. One conviction, one law, and a mosaic of 45 state statutes: that is the current architecture for addressing a technology that, as Deezer's numbers show, uploads tens of thousands of new pieces of synthetic content every single day.

What the NO FAKES Act Actually Does — and Doesn't

The NO FAKES Act is more ambitious in scope than the Take It Down Act. It would make online platforms liable for knowingly hosting unauthorized replicas, with penalties of up to $750,000 per work, and set up a notice-and-takedown process modeled on copyright law, with exemptions for news, commentary, and parody. Borrowing from the DMCA framework, the bill creates a streamlined notice-and-takedown process such that if a person finds their voice or likeness has been used without permission, they can demand that the content be promptly removed from online platforms rather than being forced to immediately pursue costly litigation. The legislation gives individuals the right to authorize the use of their voice and likeness in digital replication, and that right does not expire at death — it can be transferred and licensed by heirs, executors, and others, though it terminates no longer than 70 years after an individual's passing.

The DMCA comparison is worth sitting with, because it is both the bill's strength and its warning. The DMCA's notice-and-takedown regime has been operative for nearly three decades, and it is widely understood to function as an industrial whack-a-mole: content removed from one URL reappears under another, platforms process millions of takedown requests and still host vast quantities of infringing material, and rights holders with legal teams — like Sony — manage it as an ongoing operation rather than a solved problem. Applying that same logic to AI-generated voice and likeness replicas at current upload velocity suggests that the NO FAKES Act, if passed, will be a meaningful legal floor but not a ceiling. That is the takedown volume from one major label with a full legal team. For ordinary people — voice actors, local journalists, private individuals — the notice-and-takedown process requires awareness, resources, and persistence that most people do not have.

There are also structural ambiguities the bill has not yet resolved. Legal scholar and right-of-publicity expert Professor Jennifer Rothman has cautioned that even with the 2026 revisions, the bill's preemption clause remains legally ambiguous and may be constitutionally vulnerable in certain applications — and that the bill's interaction with surviving state right-of-publicity and privacy laws could create what she has called an "identity thicket," a layered and potentially conflicting set of claims over who controls a person's digital replica in a given context. Three Republican senators — Mike Lee, Ted Cruz, and Eric Schmitt — voted with the unanimous committee but raised First Amendment concerns, signaling that the floor debate, whenever it arrives, will be substantive. It's unclear when or if the legislation will make it to the Senate floor, and a House companion bill has yet to be taken up in committee.

“The law will be a meaningful legal floor but not a ceiling — and for ordinary people, notice-and-takedown requires awareness, resources, and persistence that most people do not have.”

The Speed Problem Is the Real Problem

What unites these three events — the Sony takedowns, the Strahler conviction, the NO FAKES committee vote — is a common temporal structure. In each case, the harm preceded the remedy by a meaningful margin. AI voice-cloning tools capable of producing convincing artist impersonations have been commercially available for years. The streaming fraud they enable had already, by Sony's own accounting, produced more than 135,000 actionable fakes from a single label's roster before any federal law was in place to address them. Strahler's abuse began in December 2024 and continued for six months before charges were filed — in part because local law enforcement had no legal category that fit the conduct. The NO FAKES Act was first circulated as a discussion draft in 2023. When it was first introduced in 2024, it never got out of committee.

This is not a critique of the legislators involved — the bill has genuine bipartisan support, real industry backing, and thoughtful provisions. It is an observation about the structural mismatch between how fast generative AI has industrialized the theft of identity and how slowly democratic legislatures can translate that harm into enforceable law. As we've seen elsewhere with algorithmic systems, by the time a legal framework is built around a technology's behavior, the behavior has already become a condition — woven into platforms, business models, and daily experience in ways that a single federal statute can only partially reverse.

The NO FAKES Act, if it becomes law, will matter. It will give individuals a federal cause of action. It will impose platform liability that currently does not exist. It will establish a right that currently has no federal anchor. But as AI tools become more accessible and affordable, Sony warns that the volume of unauthorized AI music is expected to keep rising, posing ongoing challenges to the integrity of the music industry and artists' rights. A law modeled on the DMCA, operating on notice-and-takedown, enforced against a technology producing 60,000 new fraudulent tracks a month from a single label's roster alone, is not a solution that scales to the problem. It is a foundation that still needs walls. What the liar's dividend makes clear is that the credibility damage from synthetic media often precedes any remedy — and sometimes survives the correction. The unanimous committee vote is a genuine milestone. It just lands three years into a problem that has already normalized.

References

  1. Columbus Man Pleads Guilty Cyberstalking Exes Creating Ai Generated Obscene Material (justice.gov)
    Documents James Strahler II's guilty plea as the first U.S. conviction under the Take It Down Act for AI-generated intimate imagery.
  2. unanimously advanced S. 4591 (congress.gov)
    Confirms the Senate Judiciary Committee's unanimous advancement of S. 4591, the NO FAKES Act, by voice vote.
  3. 60,000 AI tracks hit Deezer daily as platform moves to license detection tech to wider music industry (musicbusinessworldwide.com)
    Provides Deezer's data showing over 60,000 AI-generated tracks uploaded daily, accounting for 39% of daily music deliveries.
  4. Sony Music has targeted 135,000+ deepfakes of its artists’ music for removal from streaming platforms (musicbusinessworldwide.com)
    Reports Sony Music's removal request for 135,000 AI-generated deepfake songs impersonating artists including Beyoncé, Queen, and Harry Styles.

About Julian Cross

Julian Cross writes about AI, automation, surveillance, digital identity, labor, human relationships with each other and automation, complex systems and attention — less about what new tools, studies and observations can do in theory than what they're already doing to how we work, spend, relate, and get measured. His work follows leads to the point where it stops being a product and starts being a condition.

More like this

To Fix a Deepfake, YouTube Wants Your Face. That's the Trap.

To Fix a Deepfake, YouTube Wants Your Face. That's the Trap.

Julian Cross 9 min
Deepfakes Didn't Break Trust. They Broke the Act of Verifying.

Deepfakes Didn't Break Trust. They Broke the Act of Verifying.

Julian Cross 8 min
Trump's DNA, Carroll's Dress, and the Machinery of Institutional Revenge

Trump's DNA, Carroll's Dress, and the Machinery of Institutional Revenge

Paul Wardell 10 min