Skip to content
Alonso Sala
CRIMINAL LAWYERS
Legal Analysis

AI and Criminal Law in Spain: Deepfakes, Fraud and New Risks

February 26, 2026Updated: 

AI creates no impunity: Spanish courts apply the existing offences to crimes committed with it. A single deepfake can constitute several offences at once — identity theft (Art. 401 CP), defamation or insults (Arts. 205-208 CP), an offence against moral integrity (Art. 173.1 CP) and, if used to deceive, fraud (Arts. 248-251 CP). Art. 197.7 CP should not be assumed to apply: that offence requires a genuine intimate image obtained with the subject's consent and later shared without her authorisation, so extending it to wholly synthetic imagery is contested, and there are legislative proposals to create a specific offence. The technological novelty grants no impunity, but it complicates proof of authorship and intent, which is where the defence opportunities lie.

Need help with your case? Talk to a criminal defense lawyer at Alonso Sala.

Artificial intelligence has transformed the landscape of criminal conduct at extraordinary speed. Deepfakes, AI-generated fraud schemes, automated phishing, voice cloning for identity theft, and AI-assisted market manipulation are no longer theoretical risks — they are active criminal cases in Spain's courts today.

Deepfakes and Criminal Law

A deepfake — a hyper-realistic video or audio fabricated by AI — can constitute multiple simultaneous offences under Spanish law: identity theft (Art. 401 CP), defamation or insults against honor (Arts. 205-208 CP), an offence against moral integrity where the content is humiliating or degrading (Art. 173.1 CP), and if used for fraud, criminal deception (Art. 249 CP). The challenge for prosecutors is proving authorship and intent. Each of these offences has its own elements, so the same video may support some charges and not others: an effective defence forces the prosecution to analyse them separately instead of charging in bulk.

One point is frequently misunderstood. Article 197.7 CP punishes anyone who, without the authorisation of the person concerned, shares, discloses or transfers to third parties images or audiovisual recordings of that person which he had obtained with her consent in a dwelling or any other place beyond the sight of third parties. The offence therefore presupposes a genuine recording obtained with consent and subsequently circulated without it. Where the intimate image is generated entirely by AI there is no such prior consented recording, so fitting the conduct within Art. 197.7 CP is contested and cannot be taken for granted.

For sexual deepfakes the routes actually used are insults (Art. 208 CP), the offence against moral integrity (Art. 173.1 CP) and, where the composite starts from real images of the victim, the privacy offences of Article 197 CP. This is an area of open academic debate, with legislative proposals aimed at creating a specific offence for non-consensual synthetic sexual imagery, so the correct legal characterisation depends on the facts of each case and is open to argument — which is precisely why the prosecution's chosen charge should not be accepted without scrutiny.

AI-Enhanced Fraud

Fraudsters now use AI to clone voices (impersonating bank managers), generate convincing correspondence, and automate phishing at industrial scale. Spanish courts are applying existing fraud provisions (Arts. 248-251 CP) to these new methods, but the technical complexity of proving the AI element creates significant defence opportunities.

Digital Evidence and Attribution

These cases stand or fall on digital evidence: device forensics, account records, metadata and the analysis of the manipulated files themselves. Two problems dominate. The first is attribution: proving that a specific person — and not simply a device, an account or someone with access to them — created or used the AI-generated content. The second is integrity: digital files are easy to alter, so the chain of custody and the way the evidence was collected and preserved must withstand scrutiny. Forensic expert reports are usually the decisive piece for both questions.

Defence Strategies in AI Cases

The defence lines follow from those weaknesses: challenging authorship when several people had access to the device or account; auditing how the digital evidence was obtained and whether its integrity can be guaranteed; commissioning an independent technical expert report to confront the prosecution's conclusions; and disputing intent, since using or sharing content is not the same as having fabricated it knowing it was false. The technical complexity that makes these schemes effective also makes them genuinely difficult to prove. None of this is theoretical: prosecutions often rest on the inference that the account holder must be the author, and dismantling that inference — shared devices, compromised credentials, remote access — is frequently where these cases are won or lost.

Practical Steps for Victims

If you have been targeted by a deepfake or an AI-driven scam, preserve everything before it disappears: screenshots, original files, URLs, account names and transfer receipts. Do not delete conversations, and have the material secured by a forensic expert where possible, because properly preserved evidence is what later allows both the criminal complaint and the recovery of losses within the same proceedings. The sooner a specialist lawyer reviews the preserved material, the more procedural options remain open — both for the criminal case and for any recovery.

Spain and the EU are actively working to regulate AI-related criminal conduct. The EU AI Act (2024) establishes obligations for high-risk AI systems, and breaches of these obligations may create criminal liability through referral to national penal codes. Spanish criminal lawyers must stay ahead of this rapidly evolving landscape. For businesses deploying AI systems, this means that documenting how a system was designed, tested and supervised is becoming part of criminal-risk prevention, much like classic corporate compliance.

Need a criminal defence lawyer?

If you are facing a criminal matter, our team of specialist defence lawyers can help. Contact us for a case assessment.

Frequently asked questions

What offences can a deepfake amount to?

A single deepfake can fit several offences at once: identity theft (Art. 401 CP), defamation or insults (Arts. 205-208 CP), an offence against moral integrity (Art. 173.1 CP) where the content is humiliating or degrading and, if used to defraud, fraud (Arts. 248-251 CP). Art. 197.7 CP, by contrast, is designed for genuine intimate images obtained with the subject's consent and later shared without her authorisation, so applying it to a wholly synthetic deepfake is not settled law.

Does using AI make these offences go unpunished?

No. Someone who defrauds using a cloned voice is liable like any other fraudster, and someone who shares a fake video is liable for the relevant offences against honour or privacy. The technological novelty creates no impunity, but it does complicate the evidence.

Why is it difficult to prove authorship in AI-related offences?

A fabricated video or a cloned voice can be generated from anywhere and rarely leaves an obvious signature. Attribution requires reconstructing the full technical chain: accounts, IP addresses, devices, payments and metadata; each link is also a defence opportunity.

What defence strategies exist against AI-generated evidence?

An independent technical expert report to verify whether the material is synthetic, scrutiny of the digital chain of custody, challenging the subjective element (deception and intent to profit in fraud) and disputing the correct legal characterisation.

What should I do if I am a victim of a deepfake or an AI-driven scam?

Preserve the evidence immediately (links, files, dated screenshots), ask the platforms to take down the content, file a criminal complaint so authorship can be investigated, and consider the available criminal actions. Speed is critical: both the content and the money disappear quickly.

Do you need criminal defense in this area?

We are criminal defense lawyers specializing in cybercrime and technological criminal law. We act urgently to protect your rights.

View expertise

Related Articles

View all

Before you act, speak to a criminal defence lawyer.

What you read here is just the beginning. Transform information into active defence by contacting our team of experts.