Maryland Just Made a Fake Voice a Felony

Maryland Senate Bill 8 took effect October 1, 2026. The law is narrower than the headlines suggest, and the practical problem it points to is bigger.


Background: How Pikesville Changed the Conversation


Maryland Senate Bill 8, "Artificial Intelligence and Deepfake Representations," amends Maryland Criminal Law section 8-301, sitting under Chapter 445. Governor Wes Moore signed it on May 12, 2026. The vote was unanimous in both chambers, which does not happen often in Annapolis. The reason for that unanimity matters.


If you want to understand why this passed without opposition, the 2024 Pikesville High School case is where to start. Per Stein Sperling analysis, prosecutors pointed to that incident directly: synthetic audio of a school principal, fabricated and distributed to cause harm. A real person voice, made to say something they never said, deployed to damage their reputation. The conduct was harmful. The existing law was a bad fit.


That case illustrated the gap lawmakers were trying to close. It was a local incident, with a local victim, using tools that are now broadly accessible. It was not a sophisticated foreign operation or a corporate espionage scheme.


The technology has crossed a threshold where an "ordinary person" - the test this statute uses - can no longer reliably distinguish a synthetic voice or image from a real one. Once that is true, the legal framework for fraud needs to account for it.


The law sponsor, state Sen. Hester, put the intent plainly: "We are not criminalizing AI." The target is using AI to defraud. That distinction carries a great deal of weight in both the text and the enforcement mechanics.


How the Law Works


The statute defines a "deepfake representation" under section 8-301(a)(3)(i) as a photo, film, video, audio recording, or digital or computer-generated image that is indistinguishable from an actual, identifiable human. The ordinary person test applies: would a typical person, watching or listening, believe this is real?


The definition excludes drawings, cartoons, sculptures, and paintings. The line sits between synthetic media that mimics reality and creative work that does not claim to. That exclusion matters for media companies and artists, and it explains why the Motion Picture Association weighed in during drafting. The intent language in the final statute was narrowed partly in response to those concerns.


What the law prohibits, under section 8-301(f)(2), requires all of the following to be true simultaneously:


Acting knowingly, willfully, and with fraudulent intent

Using AI or a deepfake to impersonate, falsely depict, or claim to represent another person

Doing so to defraud, mislead, or cause harm - or creating and distributing false records to cause harm, obtain personal identifying information, or obtain a benefit, credit, good, service, or thing of value


Three things to hold onto here. First, intent is required at every level. This is not a strict liability statute. Second, the law does not ban AI depiction of real people. It bans using that depiction to defraud or harm. Third, harm is defined broadly enough to include serious emotional distress, not just financial or physical injury. That last point extends the law reach past traditional fraud contexts into territory courts will need to define.


A separate provision makes it a misdemeanor to assume another person identity to harm, harass, intimidate, threaten, or coerce - regardless of whether AI is involved. That tier handles lower-stakes but still harmful conduct that does not rise to the level of financial fraud.


There is also a standalone prohibition on using another person personal identifying information without consent to cause harm. That sits alongside the deepfake provisions rather than inside them.


The Numbers in Context


The criminal penalties for the primary fraud offense are felony-grade:


One victim: up to 5 years imprisonment or a $10,000 fine

Multiple victims: up to 10 years or $15,000

Identity misuse misdemeanor: up to 1 year or $500


There is no minimum dollar threshold anywhere in the statute. A $50 wire transfer obtained through a deepfake voice clone is covered the same as a $500,000 one. That matters for businesses, because the instinct is to frame AI fraud risk in terms of large, dramatic transactions. The law does not share that instinct.


On the civil side, section 8-301(h)(1) gives victims the right to sue directly. Courts can issue injunctions and grant "any other appropriate relief" under section 8-301(h)(2). Whether that language extends to attorney fees is an open question. The statute does not specify, and that ambiguity will get resolved through litigation rather than legislative history.


Stakes: Who Is Actually Exposed


The honest answer is most organizations that authorize payments or transfers based on verbal or visual confirmation.


Stein Sperling analysis frames the business risk around three scenarios worth sitting with:


A voice clone of a senior executive calls the finance team to authorize a wire transfer. The team hears the CEO voice and complies.

A client calls to change payment instructions. The account manager recognizes the voice and makes the update.

A family member calls about an emergency and needs funds wired immediately.


In each case, the question is not only whether the impersonator broke the law. It is whether your organization verification controls were reasonable given what the technology can now do - and whether your compliance posture reflects that reality.


Stein Sperling frames it this way: "Are your existing procedures still adequate when seeing or hearing someone is no longer sufficient verification?"


That is the operative question for every compliance team, and the honest answer for most organizations is probably no.


Limits and Counterpoints


This law solves a specific problem and leaves several others intact. Before treating it as a comprehensive answer to AI-enabled fraud, a few caveats.


Intent is hard to prove. The statute requires knowing, willful, fraudulent intent at every element. That is a meaningful prosecutorial bar. Sophisticated actors know how to create distance between themselves and the AI-generated content they deploy - by passing it through intermediaries, by using offshore tools, by constructing plausible deniability. Proving that a specific defendant knowingly used a deepfake with fraudulent intent, rather than merely distributing content they received, is a real challenge in court.


The emotional distress standard is untested here. Including serious emotional distress as qualifying harm extends the law reach beyond financial fraud. That is intentional. It also invites litigation over what "serious" means in a deepfake context specifically. Courts will need to work that out, and the answers are unlikely to arrive quickly.


Attorney fees remain unresolved. Victims can sue under section 8-301(h), but the statute "any other appropriate relief" language is genuinely ambiguous on fees. For individual victims - particularly those whose harm is primarily emotional rather than financial - that uncertainty affects the practical calculus of whether civil litigation is worth pursuing, especially against out-of-state or anonymous defendants.


The state patchwork problem. Maryland joins a growing list of states with deepfake-specific fraud provisions, but the patchwork is exactly that. Conduct that is a felony in Maryland may be addressed differently, or not at all, under the law of a neighboring state. For national businesses, compliance complexity accumulates without a federal floor to rationalize it. That is not an argument against Maryland law. It is an argument for a federal framework that has not materialized.


The Practical Takeaway: Callback Verification and Nothing Less


The law criminalizes a specific category of conduct that was already harmful. It cannot update your verification procedures on your behalf.


The practical answer - consistent with what fraud prevention professionals have been recommending since voice cloning became reliable - is callback verification through an independent channel. If someone calls to authorize a transfer or change payment instructions:


End the call.

Call back on a number you already have on file, not one the caller provided.

Confirm the request through a second, independent channel before acting.


That protocol applies whether the caller sounds like your CFO, your largest client, or a family member in distress.


Out-of-band verification is not a new concept. What is new is that it is now the minimum reasonable standard rather than a belt-and-suspenders addition. The same technology that makes deepfakes indistinguishable to an ordinary person makes "I recognized the voice" an insufficient basis for a $10,000 wire transfer, let alone a larger one.


Maryland has named the conduct, set penalties, and given victims a civil cause of action. The law is well-constructed for what it is designed to do. The rest - the operational question of whether your organization verification controls are adequate for a world where audio and video can be fabricated at low cost - that part is yours to solve.


Sources: Stein Sperling analysis of Maryland Senate Bill 8; Maryland Chapter 445 statutory text; Maryland Senate Bill 8 fiscal note.

Stein Sperling: https://steinsperling.com/marylands-new-deepfake-fraud-law-takes-effect-october-1-what-businesses-need-to-know/

Chapter 445: https://mgaleg.maryland.gov/2026RS/chapters_noln/Ch_445_sb0008T.pdf

Fiscal note: https://mgaleg.maryland.gov/2026RS/fnotes/bil_0008/sb0008.pdf

Mara Quinn

Mara Quinn is Reporting from the Uncanny Valley's resident expert on media and the business of technology. She covers platforms, deals, incentives, and the money moving underneath new machines. She lives in Beacon.

Previous
Previous

Google Put Four AI Chips in Orbit. They Can Only Think for 15 Minutes at a Time.

Next
Next

The Detector That Uses Light to Catch a Fake