China's Top Court Made Recognisability the Deepfake Test

The Supreme People's Court has told judges that a cloned face or voice is a civil wrong when the real person is recognisable in it. That is an identity question, not a provenance question, and most detection stacks answer the wrong one.
By Sukrit Bhatia
September 8, 2026
l
24
 min read
What are deepfakes — business risk overview article
Table of Content
No items found.

On 7 September 2026 China's Supreme People's Court issued Fa Fa [2026] No. 10, an Opinion in five parts and 24 articles telling judges how to decide civil disputes involving artificial intelligence. Article 4 is the one that matters outside China: using AI to generate a recognisable digital replica of a real person without consent infringes their personality rights, and using someone's voice as training material to imitate their timbre infringes their rights in that voice.

Read the test carefully and it is not the test the detection industry sells against. The court asks whether a natural person is recognisable in the output. A deepfake detector asks whether the output was generated. Those are different questions, answered by different systems, and they disagree in the cases that matter most.

  • It is an Opinion, not a judicial interpretation. Fa Fa [2026] No. 10 guides how Chinese courts adjudicate; it is not itself the binding authority a judgment rests on. Reports calling it a ban are overstating it.
  • No commencement date is stated in the court's announcement or in any wire coverage of it. Plan around the document, not around an assumed in-force date.
  • Article 4 turns on recognisability, not on whether content was generated. That is a face recognition and speaker verification question, not a synthesis detection question.
  • The voice limb reaches the training set. Using a person's voice as training material without consent, to imitate their timbre and intonation, is itself an infringement.
  • Article 7 liability starts at notice, so the audit trail of what you did after being told is the defence. Article 12 lets a court order a developer asserting non-infringement to disclose training data sources and process records.
  • Provenance labels mostly do not survive the trip. Metadata is lost to re-encoding and visible marks are removed by the adversary; intrinsic artefacts are what reach the case file.

China's Supreme People's Court published a document on 7 September 2026 that no other senior court has attempted: it tells judges how to decide when a cloned face or voice is a civil wrong, and hangs the answer on whether an ordinary person would recognise the human being in the output. Not on whether the media was generated. On whether it identifies someone.

That sounds like a lawyer's quibble. It is the whole engineering problem. A deepfake detector answers a question about provenance; the Opinion asks a question about identity. Any organisation expecting its detection stack to answer the court's question is holding the wrong instrument.

What the Supreme People's Court issued

The document is the Opinion of the Supreme People’s Court on Lawfully Adjudicating Cases Involving Artificial Intelligence Disputes, carried on the court's own site as Fa Fa [2026] No. 10, in five parts and 24 articles. Sina Finance sets out the structure: articles 1 and 2 give guiding principles, 3 to 11 cover AI-related infringement, 12 to 16 intellectual property, and the rest evidence, criminal conduct and case management.

Xinhua reported the substance the same day. Article 4 makes it an infringement of personality rights to use AI to process a natural person's name or likeness without consent so as to generate an identifiable virtual digital figure and then use or publish it. It does the same for voice: using a person's voice as training material without consent, to imitate their timbre, intonation and pronunciation style and produce a recognisable synthetic voice, infringes their rights in that voice. Manipulating such a figure or voice to make untrue statements that lower someone's standing is a separate reputation claim, and the protection extends to the digital likeness of the dead on behalf of near relatives.

Article 7 puts generative AI service providers on the hook. Once a rights holder notifies them, a provider that fails to take timely necessary measures, including stopping generation of the infringing content, bears the resulting loss. Users who deliberately steer a model into producing harmful output are liable in their own right. Article 8 allows a personality-rights injunction where waiting would cause irreparable harm, article 10 reaches algorithmic price discrimination, and article 5 covers doxxing.

Tao Kaiyuan, a vice president of the court, framed the document as an attempt to balance development against security, telling AFP that room had been left deliberately for refinement as experience accumulates. Zhou Jiahai, who heads the court's research office, put the rationale more bluntly in remarks carried by The Star: "We cannot expect every consumer to become an expert at spotting deception. The law must step in promptly to protect consumers' legitimate rights and interests."

An Opinion, not an interpretation

Almost every English-language report calls this document rules, guidelines or a framework. Those words do a lot of quiet work, because in the Chinese system the instrument class matters and the class here is an 意见, an Opinion. Sina Finance makes the distinction explicitly: this is adjudication guidance rather than a 司法解释, a judicial interpretation, the instrument that carries binding interpretive force and that courts apply as law.

The practical consequence is that the Opinion shapes how cases are decided without itself being the authority a judgment rests on. Judges are being told what the senior court thinks the existing Civil Code and consumer statutes already require. That makes it strong evidence of where Chinese litigation is heading and a weak basis for the claim, now circulating widely, that China has "banned" unconsented voice cloning.

A second gap in the record is worth stating plainly. No commencement date appears in the court's own announcement, nor in the Xinhua, AFP, China News Service or Sina coverage, and the announcement does not carry the standard formula 自发布之日起施行, effective from the date of publication.

That blank matters more than it usually would, because articles like this one are increasingly read by machines before they are read by lawyers. Dahl, Magesh, Suzgun and Ho, writing in the Journal of Legal Analysis, measured hallucination rates between 58% and 88% when large language models were asked specific, verifiable questions about federal court cases, and found the models frequently failed to correct a false legal premise supplied by the user. A summary that omits instrument class and commencement date is not neutral. It is an invitation to fill the blanks in.

InstrumentWhat it isIssuedIn forceBinds
Opinion on Lawfully Adjudicating AI Dispute Cases
Fa Fa [2026] No. 10
A judicial policy Opinion, not a judicial interpretation. 24 articles.7 Sep 2026 (SPC)Not stated in the announcement or in any report read hereChinese courts, as adjudication guidance
Measures for Labelling of AI-Generated Synthetic Content
plus GB 45438-2025
Department rules with a mandatory national standard attached.14 Mar 2025 (Loeb & Loeb)1 Sep 2025Generative service providers and app distribution platforms
Provisions on the Administration of Deep Synthesis of Internet-based Information ServicesDepartment rules, 25 articles. The original synthetic-media regime.25 Nov 2022 (China Briefing)10 Jan 2023Deep synthesis service and technical support providers
EU AI Act, Article 50Directly applicable regulation. Transparency obligations.In force 1 Aug 2024 (European Commission)2 Aug 2026Providers and deployers placing systems on the EU market

Table 1: Every legal authority this article relies on, with its instrument class, its dates and who it binds. The blank cell is the point: no commencement date is given in the court's announcement or in the wire coverage.

Article 4 turns on one word

可识别. Identifiable, or recognisable. It appears in both halves of Article 4 and it is the hinge the personality-rights section swings on. The court is not asking whether a model produced the image; it is asking whether the natural person can be picked out of it.

The two limbs are not symmetrical. For likeness, the wrong is generating an identifiable virtual figure and then using or publishing it. For voice, the text reaches back into the training set: using the person's voice as training material, without consent, to imitate their vocal characteristics. The voice limb attaches liability at a stage the likeness limb does not, a detail almost every summary has dropped.

Chinese courts have already been pushing that line outward. In March 2026 the Beijing Internet Court held that an unauthorised AI face swap remains unlawful even where the image has since been modified, as Rest of World reported. That is a refusal to let editing launder identity, and it shows which way the interpretive pressure runs.

Recognition is not detection

Here is where the legal test and the technical stack come apart. A deepfake detector answers one question: does this signal carry the traces a generator leaves behind? Our explainer on the traces generators miss sets out what that residue consists of. Article 4 needs something else: is the person in this clip the specific human being bringing the claim? That is a face recognition or speaker verification question, measured against a reference, with its own false-match and false-non-match rates.

Both are answerable, by different systems that fail in different ways. Proving a clip was generated says nothing about whose face it wears; matching a face says nothing about whether the footage was real.

Fa Fa [2026] No. 10 · Article 4

Two different questions, two different systems

Article 4 hangs liability on whether a natural person is recognisable in the output. A detector asks whether the output was generated. The two tests disagree in half the cases, and one disagreement is where the harm keeps running.

The court's question (Art. 4): is this natural person recognisable?

Recognisable
Not recognisable
SyntheticGenerated or voice-cloned
Both agree

A cloned face that reads as the person

The paradigm case the Opinion describes: name, likeness or voice processed without consent into an identifiable digital figure. Portrait, name, voice and reputation rights all available.

Court: infringement Detector: fires
The seam

A blended identity that still sells

Attributes borrowed from a real person but blended below recognition, with the identity claim carried by the caption, the logo and the setting instead of the face. The persuasion survives; the statutory hook does not attach to a natural person.

Court: Art. 4 does not reach it Detector: fires
AuthenticReal capture, no synthesis
Ordinary law

Real footage, used without consent

Existing portrait and reputation rights already govern this, with or without the Opinion. Nothing in the media itself is generated, so a synthesis detector has nothing to report.

Court: infringement Detector: silent
Out of scope

Nobody in particular

Stock or anonymous imagery. No identifiable person and no synthesis, so neither the personality-rights test nor the detection test has anything to act on.

Court: no claim Detector: silent

The seam is narrower than it looks. In March 2026 the Beijing Internet Court held that an unauthorised AI face swap remains unlawful even where the image has been modified, which pushes the recognisability line back towards the attacker. How far back is the open question, and it is a question about perception, not about provenance.

Cell logic derived from Article 4 as published by the Supreme People's Court, 7 September 2026. Beijing ruling per Rest of World. Quadrants describe legal reach and detector behaviour, not accuracy.

The cell that should worry a compliance team is the one where the media is synthetic and the person is not quite recognisable. The persuasive work of a scam advertisement does not all sit in the face. It sits in the caption naming the person, the logo behind them, the studio set, the voice register. Blend a likeness far enough to lose the identification and the advertisement still sells, while the statutory hook loses its grip on any particular person. The architecture we described in the deepfake advertising supply chain is what makes that substitution cheap.

None of which is an argument against the Opinion. It is an argument that the Opinion creates demand for a capability most organisations do not currently buy, and that the capability is identity measurement rather than synthesis detection. The same distinction runs through liveness detection versus deepfake detection: adjacent controls, different questions, not interchangeable.

Article 7 runs at the speed of notice

Provider liability under Article 7 begins when a rights holder gives notice. Before notice, nothing. After it, the clock starts and the standard is whether measures were timely. This is the familiar notice-and-takedown bargain with its familiar failure mode: the defence runs at the speed a human can find, recognise and report a clip, while the offence runs at the speed a model can generate one.

For an individual, that asymmetry is brutal. The person whose face has been cloned has to see the clip to report it, and the clips that damage them most circulate where they will never look. Article 8's injunction helps once litigation is under way and does nothing about the interval between publication and discovery, which is where the money moves. We argued the same point from the other direction in prevention versus reaction.

Meeting Article 7 well is therefore a throughput problem before it is a detection problem: a notice queue that does not silt up, a decision record per item, and a way to catch the near-identical re-uploads that follow every removal.

The takedown arithmetic so far

The scale China already operates at shows what Article 7 is being layered onto. On 2 September 2026, days before the Opinion appeared, the Cyberspace Administration of China reported removing more than 5.61 million pieces of unlawful or rule-violating content and actioning roughly 49,000 accounts across more than 2,400 sites and apps, in a campaign against AI slop, fabricated news and impersonation, per the South China Morning Post. Penalised examples included accounts using AI face and voice swapping to impersonate public figures.

Platforms report their own numbers. ByteDance has removed more than 85,000 videos of unauthorised AI face and voice reproduction since the start of 2026, and the Guangzhou Internet Court has heard roughly 700 AI face-theft cases in three years, both per Rest of World.

FigureWhat it countsPeriodSource
5.61 millionUnlawful or rule-violating content removed in an AI-misuse campaignReported 2 Sep 2026SCMP
49,000Accounts actioned, across more than 2,400 sites and appsReported 2 Sep 2026SCMP
85,000+Videos of unauthorised AI face and voice reproduction removed by ByteDanceSince the start of 2026Rest of World
~700AI face-theft cases heard by the Guangzhou Internet CourtThree years to 2026Rest of World, citing National Business Daily

Table 2: The enforcement volumes the Opinion lands on top of. Each is a count of removals or cases acted on, not a count of content generated.

Millions of removals, hundreds of cases. That gap is not a sign the courts are failing. It is a sign the takedown pipeline does nearly all the work and litigation is the exception. Article 7 formalises the pipeline without shrinking the volume flowing into it.

Where the provenance evidence dies

China has spent three years building the provenance apparatus that ought to make these cases easy. The Deep Synthesis Provisions, in force since 10 January 2023, brought synthetic media under a dedicated regime. The Measures for Labelling of AI-Generated Synthetic Content, in force since 1 September 2025 with the mandatory standard GB 45438-2025 attached, require two marks: an explicit label a viewer can see, and an implicit label in the file's metadata. Articles 17 and 18 then direct courts to examine the authenticity and integrity of electronic data across its generation, collection, storage and transmission.

Coherent on paper, fragile in transit. The fragility is not a Chinese problem. It is a property of how files move.

Articles 17–18 · Authenticity of electronic data

The evidence the rules create, and where it dies

China's labelling regime puts provenance in two places: a visible mark, and an implicit mark in the file's metadata. Articles 17 and 18 then ask courts to weigh the integrity of electronic data across its whole journey. Follow one clip along the route it actually travels, and only one evidence type is still there when the case is filed.

Generatedcompliant tool
Exportedsaved to file
Editedcrop, re-render
Uploadedplatform re-encode
Re-sharedscreen capture
Filedin the case
Visible "AI generated" markExplicit label, burned into the frame

Fails to the adversary. It survives every technical step in the chain and is removed in seconds by the one party with a motive to remove it.

Metadata manifestImplicit label in the file header

Fails to the pipeline. No hostile act is required. Re-encoding on upload rewrites the container and the signed manifest goes with it.

Intrinsic artefactsTraces left by the generator itself

Degrades, but arrives. Compression and re-capture weaken the signal and never delete it, because it is a property of the pixels rather than an attachment to them.

This is why the standards bodies added soft bindings. The C2PA specification states plainly that Content Credentials can be removed and that provenance alone cannot tell you whether content is true. A watermark or perceptual fingerprint answers row two. Nothing in either regime answers row one.

Present Degraded Lost at this step Still admissible

Label types per the Measures for Labelling of AI-Generated Synthetic Content, in force 1 September 2025, with standard GB 45438-2025. Evidence duties per Articles 17–18 of Fa Fa [2026] No. 10. Manifest fragility per the C2PA explainer. Row states describe mechanism, not measured survival rates.

The C2PA specification is candid about this in its own explainer. Content Credentials can be removed, which is why the standard added durable credentials backed by invisible watermarks and perceptual fingerprints. Provenance alone, it says, cannot tell you whether content is true, accurate or factual, and no assumption should be drawn from whether an asset carries a manifest at all. Absence of a label is not evidence of synthesis, and presence of one is not evidence of honesty.

What survives the trip is the signal in the pixels and the samples: the intrinsic traces of the generator that made the file. Compression degrades them and re-recording degrades them further, but neither deletes them, because they are a property of the content rather than an attachment to it. For a court applying Articles 17 and 18 that is the difference between evidence that can be argued about and evidence that is gone, which is also why explainable detection output matters more in a legal setting than a confidence score does.

Training data became discoverable

Article 12 should most concern anyone building models rather than moderating them. A developer raising a non-infringement defence can be ordered to produce its training data sources, its training process records and its model operating mode. The defence is available but not free: asserting it opens the training pipeline to the court.

Read that alongside the voice limb of Article 4, which attaches liability to the use of a person's voice as training material in the first place, and the two interlock. A claimant alleges their voice was in the corpus. The developer denies it. The denial triggers disclosure over exactly the records that would settle the question.

These records have to exist before the claim arrives. Provenance logging assembled after a complaint carries little weight and invites an adverse inference, and our note on how much data it takes to clone a face or a voice explains why that is uncomfortable: a single scraped interview can be the whole corpus for one identity.

How this lines up against the EU

European readers now have two live regimes to hold at once. The EU AI Act's Article 50 transparency obligations became applicable on 2 August 2026, per the European Commission, requiring generated content to be marked in machine-readable form and deepfakes to be disclosed. We covered the mechanics in Article 50 and eIDAS 2.

The two are not variants of one idea. Article 50 regulates the act of generation and asks whether the output was marked; Article 4 regulates the depiction of a person and asks whether that person is recognisable. A clip can comply fully with one and infringe the other.

ChinaEuropean Union
Core dutyDo not generate a recognisable replica of a person without consent (Art. 4)Disclose that content is artificially generated or manipulated (Art. 50)
What triggers itIdentifiability of a natural person in the outputThe fact of generation or manipulation, regardless of who is depicted
Who complainsThe person depicted, or a deceased person's near relativesRegulators, through market surveillance
Platform dutyAct on notice, or bear the loss (Art. 7)Mark output in a machine-readable format; label deepfakes
What a defence must showThat no natural person is recognisable, or that consent existsThat the marking and disclosure obligations were met

Table 3: The two regimes ask different questions of the same clip. Sources: Fa Fa [2026] No. 10 as published by the Supreme People's Court; the European Commission's summary of the AI Act's transparency obligations.

For a multinational, a single labelling programme does not cover both. Marking output satisfies Brussels and does nothing for a Chinese personality-rights claim, where the question is who is in the frame. Our survey of what is changing in deepfake regulation this year sets out how quickly this patchwork is thickening.

What to do before a notice arrives

Four capabilities follow from the text, and none is a purchase order for a detector on its own.

Keep a decision record for every notice, not only the ones you action: timeliness under Article 7 is judged on what you did after you were told, so the audit trail is the defence. Know whether you can measure identity as well as synthesis, before a claim asks you to. Hash and log media at ingest, because Articles 17 and 18 make the integrity of the file's journey a live issue and the copy reaching you is already several generations from the original. And if you train models, keep provenance records from the first epoch.

When this landsWhat you have to be able to produceWhich control produces itWhere it breaks
A notice naming your platform under Art. 7A decision on the clip, fast enough to count as timelyAutomated triage plus human reviewVolume. Notice arrives at human speed; generation does not
A defence that no natural person is recognisableA measurement of identity similarity to the named personFace recognition or speaker verification against a referenceThere is often no clean reference recording of the speaker
A challenge to your evidence under Arts. 17-18An unbroken account of the file from receipt to filingHashing and chain-of-custody logging at ingestThe copy you receive is already a re-encode of a re-encode
A non-infringement defence as a model developer (Art. 12)Training data sources, training process records, model operating modeProvenance records kept from the start of trainingRecords assembled after a claim is filed are worth little

Table 4: Four moments the Opinion creates, and the capability each assumes you already have. Derived from the article text as published by the Supreme People's Court.

The teams that will find this easiest already treat detection output as evidence rather than as a score, the posture we argued for in where detection fits in an identity verification stack.

What the Opinion does not settle

Three questions stay open. How recognisable is recognisable? The text supplies a standard and no threshold, normal for a personality-rights provision and unhelpful for anyone building a control. The Beijing Internet Court's March position suggests modification is no defence; where the line sits for a blended identity is unanswered.

What weight does an Opinion carry against a judicial interpretation? Courts will apply it as guidance. How it fares against a contrary reading of the Civil Code is a question for the first appellate judgment.

And when does it commence? The public record does not say. Treat that blank as a blank rather than assuming publication and commencement are the same date.

Frequently Asked Questions

Has China made deepfakes illegal?
No. The Opinion tells courts how to handle civil disputes over AI-generated content. Creating a recognisable digital replica of a real person without consent infringes their personality rights and gives them a civil claim. That is not a criminal prohibition, and the Opinion is adjudication guidance rather than a judicial interpretation with binding force.

Does the Opinion apply outside China?
It governs how Chinese courts decide cases before them, so its practical reach covers any platform or model provider available in China that receives a notice from a Chinese rights holder. The final part also addresses international judicial cooperation.

What counts as a recognisable digital replica?
The Article 4 test is whether the output identifies the natural person. Not whether it was AI-generated, and not a similarity percentage. The Beijing Internet Court held in March 2026 that modifying an AI face swap does not cure the infringement, so cosmetic editing is unlikely to help a defendant.

Is voice cloning treated the same as face swapping?
Not quite. The voice limb reaches the training stage, treating the unconsented use of someone's voice as training material to imitate their timbre as an infringement of their voice rights. The likeness limb attaches at generation and publication. The voice provision is the broader of the two.

Will provenance labels prove a case?
Rarely on their own. Visible labels are removable by anyone motivated to remove them, and metadata is commonly lost when a file is re-encoded on upload. The C2PA specification says provenance cannot establish whether content is true and that no inference should be drawn from a missing manifest. Intrinsic artefact analysis is what survives the distribution chain.

Methodology

Primary sourcing for the Opinion is the Supreme People's Court's own announcement at court.gov.cn, including the document number, structure and article text. Wire reporting from Xinhua, AFP and China News Service was read directly to corroborate it, and Sina Finance supplied the part-by-part structure and the instrument classification. Enforcement figures come from the South China Morning Post and Rest of World, not from the court. Standards and comparative material come from the primary bodies: the C2PA specification, and the European Commission for the AI Act timeline. Where the public record is silent, notably on commencement, this article says so instead of inferring.

Sources

  1. Supreme People’s Court: Opinion on AI Dispute Cases, Fa Fa [2026] No. 10
  2. Xinhua: China’s top court sets rules for AI deepfakes
  3. AFP via TechXplore: Top court posts guidelines on deepfakes
  4. The Star: Fake AI-generated content now liable
  5. China News Service: 最高法发文明确AI换脸拟声等案件裁判规则
  6. Sina Finance: 最高法发布我国首部涉人工智能司法裁判规则文件
  7. South China Morning Post: China cracks down on AI deepfakes
  8. Rest of World: A new marketplace to rent human faces
  9. C2PA: Content Credentials Explainer, specification 2.4
  10. Loeb & Loeb: China’s AI labelling measures
  11. China Briefing: Deep Synthesis Provisions, in force January 2023
  12. European Commission: Regulatory framework for AI
  13. Dahl et al.: Large Legal Fictions, Journal of Legal Analysis 16(1)
By Sukrit Bhatia
DuckDuckGoose AI

About the author

By Sukrit Bhatia
DuckDuckGoose AI

Discover the Power of Explainable AI (XAI) Deepfake Detection

Schedule a free demo today to experience how our solutions can safeguard your organization from fraud, identity theft, misinformation & more