Generative AI Scams: Deepfakes, CEO Fraud and Defence in Spain
In this article
Key Takeaways
- Ordinary fraud: Art. 248 CP (6 months to 3 years)
- Computer fraud: Art. 249.1.a) CP, not the repealed 248.2
- Art. 250.1 CP aggravation: 1 to 6 years and a 6 to 12-month fine
- Intent is decisive for money mules and peripheral participants
Scams committed with generative AI are classified as ordinary fraud under Art. 248 CP where the deepfake or synthetic text deceives a person who then makes the patrimonial disposition, carrying 6 months to 3 years in prison, or as computer fraud under Art. 249.1.a) CP, with the same penalty, where what is manipulated is an automated system in order to obtain an unauthorised transfer. If the defrauded amount exceeds 50,000 euros, affects a large number of people, is especially serious or abuses business or professional credibility, the aggravating circumstances of Art. 250.1 CP apply, carrying 1 to 6 years in prison and a 6 to 12-month fine. The defence turns on intent (particularly for peripheral participants and fund recipients), on the technical attribution of the synthetic content and on the lawfulness of the digital evidence.
Need help with your case? Talk to a criminal defense lawyer at Alonso Sala.
Generative AI has made appearances cheap to manufacture. A convincing video of a well-known figure endorsing a financial product, an exact replica of a bank's website or a flawless email written in the victim's own language and register no longer require professional resources. As lawyers specialising in generative AI fraud, we set out which offence actually applies to each modality and how each procedural position is defended.
Types of Generative AI Fraud
Four modalities account for most current litigation. The first is investment fraud using video or image deepfakes: social media advertisements or short videos in which a recognisable face endorses a trading platform or a crypto-asset product, linking to a website built to collect funds. The second is CEO fraud or business email compromise (BEC) supported by fake video: a video call in which an apparently genuine executive orders an urgent, confidential transfer, sometimes preceded by emails drafted with a language model that mirror the company's internal style.
The third is phishing and cloned websites generated with large language models: campaigns without the typos and odd phrasing that once gave the fraud away, personalised with the victim's public data and deployed over visual replicas of legitimate portals. The fourth is romance fraud using synthetic images, where the fictitious profile rests on generated photographs that return no reverse-image match and, at times, on short video calls with an avatar.
Voice cloning deserves separate treatment and we cover it in detail in our article on vishing and cloned-voice fraud. Here we focus on video, image and synthetic text.
Ordinary Fraud and Computer Fraud: Which Article Applies
Art. 248 CP punishes anyone who, for profit, uses sufficient deceit to produce error in another, inducing them to make a disposition to their own or another's detriment. The penalty is 6 months to 3 years in prison, and in fixing it the court considers the amount defrauded, the economic harm caused, the relationship between victim and offender and the means employed. Where the amount defrauded does not exceed 400 euros, the penalty is a fine of one to three months, unless a circumstance of Art. 250 CP applies. Investment deepfakes, CEO fraud by video call and romance fraud all belong here: there is a person whose will is overcome.
Art. 249.1.a) CP describes something different: anyone who, for profit, unduly obstructs or interferes with the operation of an information system, or unduly introduces, alters, deletes, transmits or suppresses computer data, or uses any other computer manipulation or similar artifice, and thereby obtains an unauthorised transfer of any asset to another's detriment. The penalty is likewise 6 months to 3 years in prison. It is the provision that applies where the synthetic content is aimed at a machine: a generated face that defeats automated biometric verification, or a video injected into a remote identification process. It bears stressing from the first pleading that computer fraud now sits in Art. 249.1.a) CP, not in the repealed Art. 248.2 CP.
Art. 249.2.a) CP itself imposes the same penalty on those who manufacture, import, obtain, possess, transport, trade in or otherwise supply to third parties devices, instruments, data or computer programs, or any other means specifically designed or adapted to commit these frauds. That is the natural route for phishing kits and generation tools distributed to others. Many real episodes combine both logics — deceiving a person and then manipulating a system — which opens up concurrence questions that must be analysed case by case rather than stacked automatically.
Aggravating Circumstances Under Article 250 CP
Art. 250.1 CP raises the penalty to 1 to 6 years in prison and a 6 to 12-month fine. In generative AI fraud four circumstances are typically relevant: that the act is especially serious given the extent of the harm and the economic situation in which it leaves the victim or their family (250.1.4); that the value defrauded exceeds 50,000 euros or affects a large number of people (250.1.5), which covers both CEO fraud and mass cloned-website campaigns; that it is committed abusing the personal relationship between victim and offender or taking advantage of the offender's business or professional credibility (250.1.6), which is precisely what impersonating an executive or a known institution seeks; and procedural fraud (250.1.7) where evidence in judicial proceedings is manipulated so as to cause the court to err.
Art. 250.2 CP adds a second tier: where any of circumstances 4, 5, 6 or 7 concurs with circumstance 1, or where the value defrauded exceeds 250,000 euros, the penalty is 4 to 8 years in prison and a 12 to 24-month fine.
The classification drives the limitation period. Under Art. 131 CP, basic fraud — maximum penalty of 3 years — becomes time-barred after 5 years, while aggravated fraud under Art. 250.1 CP — maximum penalty of 6 years — becomes time-barred after 10 years, since it exceeds five without exceeding ten. There is no intermediate three-year bracket for these offences.
Defending the Accused: Intent, Mistake and Peripheral Participants
Many of those investigated in these cases occupy peripheral positions: someone who lent a bank account to receive and forward funds, who registered a domain, who translated texts or who managed advertising without knowing the final destination of the money. The central issue is intent. Art. 301.1 CP punishes with 6 months to 6 years in prison and a fine of one to three times the value of the assets anyone who acquires, possesses, uses, converts or transfers assets knowing that they originate in criminal activity, or performs any other act to conceal or disguise their unlawful origin. Where the acts are committed through gross negligence, Art. 301.3 CP provides for 6 months to 2 years in prison and a fine of one to three times that value. That boundary separates a serious conviction, a mitigated one and an acquittal.
Supreme Court ruling STS 123/2026 of 12 February (appeal 3103/2023) is useful here: the Court upholds a conviction for documentary forgery in medial concurrence with fraud and for money laundering, but clarifies that this last offence requires acts aimed at concealing or disguising the unlawful origin of the assets, and not the mere possession or use of the money. Ordinary transfers are not enough to find laundering where that concealment purpose is missing.
The second line of defence is technical attribution. The fact that content was generated or distributed from a given account, IP address or device does not by itself establish who was behind the keyboard, particularly where accounts are shared or credentials compromised. The third is avoiding forced classification: not every use of a manipulated document amounts to criminally relevant forgery; usurpation of civil status under Art. 401 CP — 6 months to 3 years in prison — requires assuming another's identity in full, not the isolated use of identifying data; and Art. 197.7 CP presupposes a real intimate image, so it cannot be invoked as though it covered entirely synthetic content. Where data belonging to others is deleted or altered with serious results, Art. 264 CP comes into play, carrying 6 months to 3 years in prison.
The Victim's Route: Reporting, Complaint and Tracing Funds
For the injured party the priority is twofold: securing the evidence before it disappears and locating the money while it can still be reached. On the evidential side it is advisable to keep screenshots with date and URL, complete emails with their headers (not forwards), the links and advertisements that led to the fraudulent site, transfer receipts and the full details of the destination accounts. On the asset side, appearing as a private prosecution allows the victim to drive the investigation and request precautionary freezing and attachment measures over identified funds, including those routed through intermediary accounts or crypto-asset service providers.
On platform liability caution is warranted. The European digital services framework provides notice and action mechanisms for unlawful content, so a documented, formal notification is the first step towards removal of the advertisement, video or profile. That duty to act on notice is, however, one thing; the criminal liability of the intermediary is another, requiring proof of its own elements and not following simply from hosting the content.
Evidence: Digital Forensics and Lawfulness
In these proceedings the evidence is essentially digital and its value depends on two cumulative conditions: authenticity and lawfulness. The authenticity of a video or image is no longer presumed. Expert analysis works on the original file and its metadata, the consistency of lighting and shadows, compression and generation artefacts, inconsistencies at edges and transitions, and the traceability of the capture. We develop this methodology in our article on deepfakes as evidence and digital forensic defence.
Lawfulness is examined in parallel. Interception of electronic communications and the search of mass storage devices require the specific judicial authorisation provided for in the Criminal Procedure Act, with reasoning and proportionality. A measure carried out without that cover may render the evidence, and anything derived from it, void. To that is added scrutiny of the chain of custody: integrity of the forensic images, hash functions, documentation of every transfer and correspondence between what was seized and what was analysed.
Prevention in the Company
The measure that prevents the most CEO fraud is not technological: it is a dual verification protocol through a separate channel for every payment instruction above a threshold or departing from the usual procedure. Confirmation must be made through a channel initiated by the employee — not the one the instruction arrived through — and against a previously registered contact. To that are added tiered authorisation thresholds, an explicit rule that no executive will ever ask to bypass the process for urgency or confidentiality, and specific training that includes the impersonated video call scenario.
This architecture also carries criminal relevance: an organisation and management model with suitable and effective controls is the backbone of the corporate defence under Art. 31 bis CP. Documenting the protocol, evidencing its actual application and recording detected incidents turns sound financial practice into useful evidentiary material.
⚖️ Do you need a criminal defence lawyer?
A firm dedicated exclusively to criminal law. We assess your case and design the defence strategy.
Frequently asked questions
Is it a crime to use generative AI to create a fake investment advertisement?
Yes, where that advertisement operates as sufficient deceit leading the victim to hand over money. The conduct is fraud under Art. 248 CP, punishable by 6 months to 3 years in prison, and it can be aggravated under Art. 250.1 CP where the amount exceeds 50,000 euros or affects a large number of people, carrying 1 to 6 years in prison and a 6 to 12-month fine.
What is the difference between Art. 248 and Art. 249.1.a) CP?
Art. 248 CP punishes deceiving a person who, acting in error, makes a patrimonial disposition. Art. 249.1.a) CP punishes anyone who, using a computer manipulation or similar artifice, obtains an unauthorised transfer of any asset. Both carry 6 months to 3 years in prison, but the target differs: a person's will as against the operation of a system. The former Art. 248.2 CP has been repealed and citing it is a technical error.
What is the penalty for CEO fraud committed through a fake video call?
The baseline is fraud under Art. 248 CP, 6 months to 3 years in prison. In practice, aggravating circumstances of Art. 250.1 CP usually apply: a defrauded value above 50,000 euros (250.1.5) or abuse of the offender's business or professional credibility (250.1.6), raising the penalty to 1 to 6 years in prison and a 6 to 12-month fine. Where the defrauded value exceeds 250,000 euros, the penalty becomes 4 to 8 years in prison and a 12 to 24-month fine (Art. 250.2 CP).
I received money in my account and forwarded it without knowing its origin: am I liable?
It depends on intent. Intentional money laundering under Art. 301.1 CP carries 6 months to 6 years in prison and a fine of one to three times the value of the assets; where committed through gross negligence, 6 months to 2 years in prison and a fine of one to three times that value (Art. 301.3 CP). Supreme Court ruling STS 123/2026 of 12 February (appeal 3103/2023) recalls that laundering requires acts aimed at concealing or disguising the unlawful origin, not the mere possession or use of the money.
When does a fraud committed with generative AI become time-barred?
Under Art. 131 CP the maximum penalty governs. Basic fraud, with a maximum of 3 years, becomes time-barred after 5 years. Aggravated fraud under Art. 250.1 CP, with a maximum of 6 years, becomes time-barred after 10 years, since it exceeds five without exceeding ten.
Does Art. 197.7 CP cover images generated entirely by AI?
No. Art. 197.7 CP presupposes a real intimate image or recording, obtained with the consent of the person concerned in a private setting, which is later disseminated without permission. Where the content is entirely synthetic that premise is missing, and the conduct must be channelled through other offences depending on the case. Invoking it as though it covered any AI-generated content is a classification error.
What can the victim of an AI-cloned website do?
Report the matter or file a criminal complaint with the fullest possible traceability: screenshots with date and URL, complete emails with headers, transfer receipts and the details of the destination accounts. Appearing as a private prosecution allows the victim to drive the investigation and request precautionary freezing and attachment measures over any funds located.
Can a video submitted by the prosecution be used if it could have been AI-generated?
Only if it passes expert scrutiny. The authenticity of audiovisual material is no longer presumed: the defence can demand the original file with its metadata, the traceability of the capture and a forensic analysis of artefacts and internal consistency. Evidence gathered without the judicial authorisation required by the Criminal Procedure Act may also render the evidence, and anything derived from it, void.
Do you need criminal defense in this area?
We are criminal defense lawyers specializing in generative ai fraud. We act urgently to protect your rights.