In August 2026, the Ministry of Digital Affairs disclosed correspondence with Meta regarding ads reported as fake or used for investment scams on Facebook and Instagram. Meta reported that from July 2025 to June 2026, it removed 380,000 pieces of content violating its policies and 137,000 ads in Poland, 88 percent of which were removed proactively. On the surface, the numbers looked impressive; however, for people whose face, name, or voice was used for example, in a fake ad the statistics alone do not resolve the issue.
A few days later, the dispute moved to the EU level. Poland asked the European Commission to expand its proceedings against Meta and impose a fine of 250 million euros. The materials submitted to Brussels included the results of a test conducted by CERT Polska. Experts reported 122 ads deemed to be fraudulent. In 106 cases, Meta reportedly refused to remove them; it removed 10 ads; and it did not respond to six reports. The government alleged violations of the DSA, including ineffective content reporting procedures, a lack of transparency, and insufficient verification of advertisers.
The European Commission confirmed that it will take into account the materials provided by Poland in the proceedings concerning illegal content and deceptive advertising on Meta’s platforms. An EC spokesperson also noted that the Commission is already investigating Facebook and Instagram and has preliminarily found violations of the DSA as part of that investigation. At the same time, the spokesperson highlighted a problem on Poland’s part: the failure to appoint a national coordinator for digital services.
False investment ads featuring well-known figures do not work solely because of the technology itself. They work because of the trust that the audience associates with the name, face, or voice of the person shown in the material.
If such content is broadcast as an advertisement, its reach does not depend solely on random shares. It is purchased, targeted, and replicated by the advertising system. After one version is removed, it may reappear from a different account, at a different URL, or with slightly altered content. Simply removing a single piece of content often does not solve the problem. If platforms and authorities do not respond quickly, these types of violations will continue to occur, even with existing regulations in place.
Polish law already allows for action against deepfakes. The primary basis for this is the legislation on the protection of personal rights. The Civil Code protects, among other things, honor, reputation, surname, pseudonym, voice, and likeness, and the list of personal rights is not exhaustive. In the event of a violation, one may demand that the violation cease, that its effects be removed, that an appropriate statement be issued, and that compensation or damages be paid. These provisions also apply mutatis mutandis to legal entities, which is important for protecting a company’s reputation and credibility.
We’ve written more about the protection of one’s voice here https://kbiw.com/en/ai-voice-cloning-can-a-voice-be-legally-protected/
The protection of one’s image is of particular importance. In the case of deepfakes, it is not decisive whether an original photo, altered material, or an AI-generated image was used. What matters is whether the viewer can recognize a specific person and whether that person’s likeness was used without consent. If the material additionally suggests that the person endorses a product, participates in an advertisement, or uttered words they never actually said, the infringement may extend not only to their likeness but also to their reputation and professional credibility.
A recent Polish example is the dispute between Rafał Brzoska and Omena Mensah and Meta. The case concerns false advertisements published on Facebook and Instagram. The Personal Data Protection Office (UODO) noted that Rafał Brzoska’s likeness, modified using deepfake technology, was used in advertisements encouraging the use of investment platforms intended to lead viewers to make poor financial decisions. Ads featuring Omena Mensah contained false information about her being beaten, killed, or arrested by the police.
This case, which is currently generating a great deal of public attention, vividly demonstrates that deepfakes can trigger several different liability regimes. From the victim’s perspective, this means the need to pursue the case on multiple levels not only in court but also through communication with the platform itself.
Effective August 2, 2026, these requirements are supplemented by the transparency obligations set forth in Article 50 of the AI Act, which – as we discussed in whether the AI Act applies to U.S. companies – also extends to AI providers based outside the European Union. The European Commission has confirmed that the provisions regarding AI transparency must be applied as of that date. These include, among other things, labeling content generated or manipulated by AI and information obligations toward individuals at risk of deepfakes. The Commission has also published guidelines regarding the obligations of providers and entities using AI systems.
However, the AI Act does not alter the fundamental civil law assessment. Labeling material as AI-generated or AI-modified serves to inform the recipient about the nature of the content itself. It does not replace the consent of the person whose face, voice, name, or likeness has been used by the creator or the model. Material labeled as AI may still violate the law. AI labeling and consent serve two different functions. The former concerns transparency toward the audience, while the latter concerns the right to use another person’s identity, likeness, or voice.
In this context, the announced ScamWatch project is particularly interesting. Rafał Brzoska, together with the co-creator of the Bielik AI model, presented a tool designed to analyze texts, cloned voices, deepfakes, counterfeit company logos, and rapidly changing domain names. According to the project description, its goal is also to gather evidence, including evidence of platforms’ inaction.
This can be a crucial tool in civil litigation. It will become increasingly difficult to base cases involving deepfakes on a screenshot alone. Currently, data showing the entire process of the infringement is becoming more and more important.
Why is this so important? Often, the material disappears, reappears at a different URL, changes its version, leads to another domain, or appears from a new account. Simply stating that an ad was unlawful may not be enough. It is necessary to demonstrate what it looked like, when it was available, where it led, who reported it, and how the platform responded.
For an individual or company affected by a deepfake, the first 48 hours should be focused on securing the material and halting its further distribution. Removing the fake material without securing evidence may later significantly impact the court’s ruling on the case.
Only after securing the evidence can the appropriate litigation strategy be chosen, whether through reporting the issue to the platform and demanding that the violations cease, filing a motion for preservation of evidence, filing a lawsuit to protect personal rights, initiating proceedings before the Personal Data Protection Office (UODO), or notifying law enforcement authorities. In cases of business infringements, issues of unfair competition, misleading advertising, and professional liability may also arise.
Our law firm assists individuals and companies in cases involving deepfakes, false advertisements, and the unlawful use of a person’s image, voice, or a company’s name.