Criminal Law - Identity Fraud - Artificial Intelligence and Deepfake Representations
SB8 expands Maryland’s identity fraud law to address misuse of personal identifying information, online impersonation, and emerging AI-generated deception. The bill makes it unlawful to knowingly and willfully use another person’s personal identifying information without consent to cause harm, and it adds a new prohibition on using artificial intelligence or deepfake representations to impersonate, falsely depict, or claim to represent another person with fraudulent intent. It also prohibits using AI or deepfakes to create or distribute false records to harm someone, induce disclosure of personal information, or obtain money, credit, services, or other value.
The bill also broadens existing identity-fraud provisions involving assuming another identity, re-encoder devices, skimming devices, and malicious disclosure of sensitive information through interactive computer services. It creates a private right of action for victims of certain AI/deepfake conduct, allowing them to seek injunctions and other relief in court. The bill retains and updates criminal penalties, including misdemeanor and felony classifications based on the value involved or the number of victims, and it authorizes restitution for costs tied to repairing credit, clearing health records, and related proceedings.
SB8 amends Criminal Law § 8-301 and updates the State Finance and Procurement definition of artificial intelligence in § 3.5-801. In practical terms, it extends Maryland’s identity fraud framework to cover AI-generated impersonation and deepfake-based fraud, while preserving existing rules on identity theft, credit card skimming, and unauthorized use of personal information. It also expands enforcement and venue provisions, keeps statewide investigative authority for certain law enforcement agencies, and allows the Attorney General and State’s Attorneys to prosecute violations. The bill affects individuals whose identities are misused, victims of online harassment or fraud, and entities handling health information or personal data.
The recorded voting history suggests strong bipartisan support and little visible opposition: the bill passed the Senate 45-0 and the House 127-0. The committee report was favorable with amendments, indicating the measure was broadly acceptable while still receiving some technical or policy refinement. No committee transcript was provided, so the available record points to a consensus view that the bill addresses a timely and serious problem involving identity fraud and AI misuse.
The main policy issue reflected in the text is how far to extend criminal liability for AI and deepfake use without sweeping in legitimate speech, art, or ordinary digital editing. The bill narrows its deepfake definition by excluding drawings, cartoons, sculptures, and paintings, and it requires knowing, willful, and fraudulent intent for the new AI-related offenses. Another point of potential concern is the creation of a civil cause of action and the expansion of penalties for conduct involving digital impersonation, which could raise questions about proof, scope, and enforcement. However, the unanimous votes suggest these issues were not politically divisive in the final version.