🎭🤖🗳️
AI Innovation · Apr 30, 2026
C2PA content provenance, state-by-state AI disclosure mandates, and why the technical and legal race is far from settled ahead of November
← All articles

From @deeptomcruise to AI Robocalls: Disclosure Laws Face Their 2026 Midterm Test

AI Innovation Published Apr 30, 2026 · deepfakes · election ai · c2pa · disclosure laws · synthetic media

In March 2021, a TikTok account called @deeptomcruise posted a thirty-second clip of Tom Cruise playing golf and performing a coin trick. The video accumulated two million views in a weekend. Tom Cruise had never touched a camera that week. The footage was fabricated frame-by-frame by Belgian visual effects artist Chris Umé and actor Miles Fisher, using a custom neural face-swap pipeline built atop then-emerging diffusion and GAN architectures. The account now carries more than five million followers. The company Umé and Fisher founded, Metaphysic, raised a $7.5 million Series A in October 2022 and performed a live deepfake segment on America's Got Talent that same year, superimposing Simon Cowell's younger face onto a dancer in real time before a studio audience.

That arc — hobbyist experiment, media company, network prime time — played out in eighteen months. By 2024, the same underlying stack had migrated into electoral politics. The regulatory infrastructure built to manage it was not ready, and a patchwork of state disclosure laws, an untested federal standard, and an ambitious cryptographic provenance specification called C2PA are now being simultaneously stress-tested as 2026 midterm races generate eight-figure budgets and AI-generated content reaches commodity prices.

The Political Deepfake Playbook, 2023–2024

The Republican National Committee released what it described as the first AI-generated political attack ad from a major U.S. party on April 25, 2023 — the same day President Biden formally announced his re-election campaign. The ad depicted a speculative dystopia: AI-synthesised imagery of Chinese military forces advancing on Taiwan, a second COVID-19 wave, and urban unrest. An on-screen disclaimer noted the content was AI-generated. The ad attracted millions of views and injected a disclosure debate into every major political outlet within forty-eight hours — demonstrating that voluntary transparency could coexist with aggressive partisan use of synthetic media.

Six weeks later, the DeSantis War Room account on Twitter circulated fabricated images depicting Donald Trump embracing and kissing Dr. Anthony Fauci — images generated by a commercial image-synthesis model with no basis in any real photograph. They spread virally before fact-checkers flagged them. The episode illustrated a structural gap: platform moderation operates reactively while AI-generated content distributes at publication speed. The June 2023 images were never labelled as synthetic by the account that posted them.

The most consequential incident of the cycle arrived on the evening of January 21, 2024 — the night before the New Hampshire Democratic presidential primary. Thousands of registered Democrats received robocalls carrying a synthesised voice that closely mimicked President Biden's cadence and phrasing, instructing recipients not to vote in the primary. Federal investigators and the New Hampshire Attorney General traced the call to political consultant Steve Kramer, who had been working for Democratic primary challenger Congressman Dean Phillips. Kramer later admitted commissioning the call, characterising it as a deliberate provocation designed to highlight AI's electoral threat rather than to actually suppress votes. The Federal Communications Commission responded on February 8, 2024 with a declaratory ruling: AI-generated voice content meets the statutory definition of artificial voice under the Telephone Consumer Protection Act, making AI-voice robocalls illegal without prior express written consent. Per-call civil penalties under TCPA reach $1,500 for willful violations.

The State-by-State Disclosure Map

Absent a federal election-AI statute, states moved first. The resulting map is genuinely complicated.

The structural limitation is consistent across all these regimes: they require the creator of the content to add a disclosure label. None mandate real-time detection or takedown obligations on platforms. The scheme functions when creators comply voluntarily; it collapses in adversarial cases — which are precisely the cases the laws exist to address.

Federal landscape, April 2026: No comprehensive federal AI political-content disclosure law has passed. The Honest Ads Act and standalone deepfake-in-elections bills have been introduced in multiple consecutive Congresses without reaching a floor vote. The DEFIANCE Act, signed July 30, 2024, addresses only non-consensual intimate deepfakes — a separate category that does not cover political impersonation. FEC rulemaking on AI disclosures in paid political advertising remains in extended comment periods. The absence of a federal floor means enforcement depends entirely on the state in which a voter receives the content.

C2PA: The Cryptographic Provenance Standard

The Coalition for Content Provenance and Authenticity (C2PA) was founded in 2021 by Adobe, Microsoft, Intel, the BBC, and Truepic. Its technical approach is distinct from disclosure law: rather than requiring humans to add labels after content is created, C2PA embeds cryptographically signed provenance manifests at the moment of production.

The mechanism: when an image, video, or audio file is generated — by an AI model or a physical camera — the producing software or device embeds a signed manifest in the file's metadata. The manifest records the tool used, the timestamp, and a cryptographic hash of the original content. Each downstream edit appends to the manifest chain. Any C2PA-aware viewer can validate the chain and inspect the full edit history. The C2PA 2.0 specification, published in 2024, extended the standard to cover audio and text alongside still images and video.

Adoption among major AI providers accelerated sharply through 2024:

The Content Authenticity Initiative (CAI) — the broader industry coalition operating alongside the C2PA technical body — reported more than 2,000 member organisations by mid-2024, including major news publishers, stock photography agencies, and social platforms.

Conjecture, marked clearly: Based on the rate of hardware integrations (Leica M11-P, Nikon Z6 III), adoption by every major AI image generator, and CAI membership growth from launch to mid-2024, we estimate that C2PA-signed content will account for a majority of newly produced commercial photography and AI-generated imagery by late 2026. However, this signed segment will represent a small fraction of total media volume once legacy content and consumer-device output are counted. This is a trend-based inference, not a published industry forecast.

The standard's central limitation deserves equal emphasis: C2PA establishes provenance only for content signed at the moment of creation. It provides no retrospective verification for the vast existing corpus of unsigned media. Critically, absence of a C2PA manifest does not mean a piece of content was manipulated — it means only that its origin is undocumented. Security researchers have warned that the asymmetry risks conditioning audiences to treat signed content as automatically authentic and unsigned content as automatically suspect, which would be false in both directions and exploitable by sophisticated actors who selectively leak signed fakes.

The 2026 Midterm Stress Test

With competitive House and Senate races already drawing eight-figure budgets, AI-generated content has moved from experiment to routine production tool in political communications. Voice cloning that cost thousands of dollars per hour in 2021 now runs via commercial APIs at fractions of a cent per second. Image generation that required days of model fine-tuning in 2022 executes in under ten seconds on consumer hardware today.

For synthetic celebrity personas in entertainment — the Metaphysic lineage — a parallel legal framework is maturing faster than the political equivalent. SAG-AFTRA negotiated AI replica protections in its November 2023 contract with major studios after a 118-day strike, requiring informed consent and negotiated compensation for any digital replica of a union member's likeness, voice, or performance. Individual states are advancing right-of-publicity statutes that would extend comparable protections to non-union performers. The commercial harm is easier to quantify and litigate than democratic harm; plaintiffs and attorneys have followed the money, and the resulting case law is accumulating faster than comparable election-law precedent.

The political domain lacks equivalent clarity. Proponents of C2PA argue that mandatory provenance-signing requirements built into campaign-finance disclosure law could close the enforcement gap: a political ad with a valid C2PA manifest tracing to a real licensed photograph is qualitatively different from one carrying no provenance chain. Bipartisan interest in that approach exists in Congress; legislation has not materialised.

The speed differential defines the current moment. Generative AI capabilities advance in quarters; regulation advances in congressional sessions. The 2026 midterms are the first major U.S. cycle conducted after C2PA 2.0, after the DEFIANCE Act, and after every leading AI image generator ships provenance metadata by default. Whether that infrastructure meaningfully constrains synthetic electoral content — or becomes a technical checkbox that adversarial actors route around entirely — will be one of the defining empirical questions of the next six months.

Frequently asked

Who created the @deeptomcruise TikTok account?
The account was created by Belgian VFX artist Chris Umé in collaboration with actor and Tom Cruise lookalike Miles Fisher. They launched it in March 2021 and subsequently co-founded the AI video company Metaphysic, which raised a $7.5 million Series A in October 2022 and performed a live deepfake segment on America's Got Talent the same year. The account has grown to more than five million followers.
Are AI-generated robocalls using cloned voices legal in the United States?
No. On February 8, 2024, the FCC issued a declaratory ruling that AI-generated voice content meets the definition of 'artificial voice' under the Telephone Consumer Protection Act (TCPA), making such robocalls illegal without prior express written consent. Willful violations carry civil penalties up to $1,500 per call. The ruling followed the January 2024 New Hampshire primary incident in which thousands of Democratic voters received a fabricated Biden voice recording urging them not to vote.
What is C2PA and how does it verify content provenance?
C2PA — the Coalition for Content Provenance and Authenticity — is an open technical standard founded in 2021 by Adobe, Microsoft, Intel, the BBC, and Truepic. It embeds cryptographically signed manifests in media files at the moment of creation, recording the producing tool, timestamp, and a hash of the content. Downstream edits append to the manifest chain, creating an auditable history. OpenAI's DALL-E 3, Adobe Firefly, Google Imagen, and camera makers including Leica and Nikon all support the standard.
Which U.S. states have enacted AI deepfake disclosure laws for elections?
As of April 2026, Texas (HB 4337, 2023), Michigan (SB 1056, 2023), California (AB 2839, 2024 — currently under a preliminary First Amendment injunction), Minnesota, Washington, and Indiana have all enacted AI election disclosure requirements of varying scope. No comparable federal law exists; FEC rulemaking on AI in paid political advertising remains in extended comment periods.
Why did a federal court block California's AB 2839?
In October 2024, a federal court issued a preliminary injunction against AB 2839 in Kohls v. Bonta, finding that the law's requirement to label AI-generated political content within 120 days of an election raised serious First Amendment concerns — particularly because the statute's broad definition could encompass clearly satirical or parodic content protected under the First Amendment. The injunction is being appealed; the law remains unenforced as of April 2026.
Does a missing C2PA manifest mean a piece of content is a deepfake?
No. The absence of a C2PA manifest means only that a file's provenance is undocumented — not that it was manipulated. The overwhelming majority of existing media, including legitimate photos and videos, predate the standard or were produced by devices that do not yet support it. Security researchers warn that conflating 'unsigned' with 'fake' is a false inference that sophisticated bad actors could themselves exploit by selectively signing fabricated content.

Sources & further reading

  1. C2PA — Coalition for Content Provenance and Authenticity (Technical Specification)
  2. Content Authenticity Initiative — Industry Adoption Coalition for C2PA
  3. FCC Declaratory Ruling: AI-Generated Voice Robocalls Under TCPA (February 2024)
  4. California AB 2839 — Political AI Deepfake Disclosure Act (2023–2024 Legislative Session)
  5. Metaphysic — AI Video Technology (DeepTomCruise parent company)
  6. OpenAI — Transparency and Content Credentials

Last reviewed Apr 30, 2026. AI Pulled News is editorial; corrections welcome at /news/about.html.