LEGAL INSIGHTS

Deepfakes and AI Voice Cloning: What Are the Legal Risks in Indonesia?

Article Language:

Samuel Sihombing

Associate

INTELLECTUAL PROPERTY & TECHNOLOGY

Developments in artificial intelligence have made synthetic images, video, and audio considerably easier to produce. Technology can now create recordings that appear to show a person saying or doing something even though the event never occurred.

This is commonly referred to as deepfake technology. In audio, similar technology can clone a person's voice from recorded samples.

Such technologies may be legitimately used in entertainment, filmmaking, dubbing, education, and other creative activities. Legal concerns arise, however, where AI is used to impersonate someone without consent, make fabricated information appear authentic, deceive another party, exploit a person's identity commercially, or cause harm.

The risk is no longer theoretical. In June 2026, Indonesia's Ministry of Communication and Digital Affairs specifically warned that AI could imitate a person's face and voice and generate highly convincing deepfake videos. In August, the Ministry again highlighted scams involving synthetic voices that impersonate relatives and well-known individuals.

A Deepfake Is Not Automatically Unlawful

The technology itself needs to be distinguished from its use.

Creating synthetic media does not automatically constitute a criminal offence. Legal analysis depends on factors such as consent, purpose, the information used, whether the content is presented as authentic, whether a benefit is obtained, and whether another person suffers harm.

A clearly labelled AI parody, for example, differs significantly from a fabricated video of a company director used to instruct employees to transfer money.

The same distinction applies to voice cloning. A synthetic voice used with a voice actor's consent for a film is different from cloning a director's voice without authorization to issue payment instructions.

The relevant legal question is therefore not merely whether AI was used, but how and why it was used.

Manipulation of Electronic Information

Article 35 of Indonesia's Electronic Information and Transactions Law prohibits intentional and unauthorized or unlawful manipulation, creation, alteration, deletion, or destruction of Electronic Information or Electronic Documents with the purpose of causing them to be regarded as authentic data.

This provision can be particularly relevant to deepfakes.

For example, an individual may fabricate a video appearing to show a director approving a transaction or generate an audio recording that sounds as though a company officer has issued payment instructions.

Not every edited or synthetic piece of content automatically satisfies Article 35. The statutory elements, including the purpose of having the information regarded as authentic, remain important.

Context is therefore critical.

Deepfakes as a Tool for Fraud

The risks become substantially more serious where synthetic identities are used to obtain money or assets.

Examples include cloning a CEO's voice to request a transfer, creating a synthetic video call purporting to involve an executive, impersonating a customer to alter bank details, or producing false endorsements to promote investments.

Indonesia's new Criminal Code under Law No. 1 of 2023 has been in force since 2 January 2026. Article 492 regulates fraud and identifies methods including the use of a false name or position, deceit, and a series of false statements to induce another person to surrender property, create a debt, or extinguish a receivable.

In this context, the deepfake itself may simply be the instrument through which the underlying fraudulent conduct is carried out.

Personal Data Risks

Deepfakes ordinarily require information relating to the person being imitated.

Synthetic video may involve processing facial images, while voice cloning typically relies on audio samples.

Indonesia's Personal Data Protection Law recognizes biometric data as a category of specific personal data. Its explanation describes biometric data as information concerning physical, physiological, or behavioural characteristics that allow unique identification, expressly giving facial images as an example.

Voice information may also engage personal data requirements where it relates to an identified or identifiable individual and can raise biometric considerations where it is used as a unique identifier.

Companies developing or deploying facial or voice-cloning systems should therefore understand the origin of their datasets, the lawful basis and purpose for processing, retention periods, and access arrangements.

Fabricating Personal Data

The PDP Law also contains provisions particularly relevant to synthetic identities.

Article 66 prohibits creating false Personal Data or falsifying Personal Data with the intention of obtaining a benefit for oneself or another person where the conduct may cause loss to another person.

Article 68 provides criminal consequences where the statutory elements are satisfied.

Accordingly, generating an artificial identity through AI may become considerably more than an ethical concern where it is used to obtain an advantage and harm another person.

Commercial Use of a Person's Face

The use of a person's appearance can also raise copyright-related issues.

Indonesia's Copyright Law regulates the commercial use of portraits and requires consent in circumstances covered by Article 12.

This becomes relevant where, for example, a business generates a synthetic advertisement making a public figure appear to endorse a product that the person never agreed to promote.

Businesses should therefore address not only the right to use existing photographs but also rights relating to synthetic modifications, digital replicas, AI-generated derivatives, media, duration, and commercial purposes in their contractual arrangements.

Does Copyright Protect a Person's Voice?

Voice cloning requires a more nuanced analysis.

A person's vocal quality should not automatically be treated as a copyrighted work merely because the voice is distinctive.

However, recordings used to create a clone may themselves consist of protected recordings, musical works, films, performances, or phonograms.

Indonesia's Copyright Law also provides Related Rights to performers and phonogram producers. Performers have economic rights concerning, among other matters, broadcasting, fixation, reproduction, distribution, and making recorded performances available to the public.

The legal analysis should therefore consider which recordings were used, who owns the relevant rights, how the materials were obtained, what licences were granted, and how the synthetic voice will ultimately be exploited.

Reputation and Civil Liability

Deepfakes may also be used to portray someone as having made a statement or engaged in conduct that never occurred.

The resulting harm may include damage to personal reputation, customer trust, investor relationships, or business relationships.

Depending on the circumstances, civil claims may arise under Article 1365 of the Indonesian Civil Code, which provides the general basis for liability for unlawful acts resulting in harm.

The relevant remedy will depend on the conduct, evidence, harm, and causal relationship involved.

Authenticity of Digital Evidence

Synthetic media is also changing how electronic evidence may need to be assessed.

In August 2026, Komdigi specifically highlighted the ability of generative AI to create synthetic photos, video, and audio that resemble real events, noting the resulting challenge for authentication of evidence in court proceedings.

Businesses should therefore avoid assuming that a voice note, video recording, screenshot, or virtual meeting recording is authentic merely because it appears convincing.

Metadata, original files, audit logs, chain of custody, source devices, and corroborating evidence are likely to become increasingly important.

AI Disclosure Rules Are Beginning to Appear

Indonesia is also beginning to introduce sector-specific rules concerning AI-generated content.

Minister of Trade Regulation No. 19 of 2026 regulates AI use in electronic commerce. Among other obligations, businesses must provide information or labels so consumers know when goods or services generated, displayed, recommended, or promoted involve AI.

This may be relevant where synthetic faces or voices are used for advertising, endorsements, recommendations, or other electronic-commerce content.

It does not mean, however, that every deepfake in Indonesia is currently subject to a universal labelling obligation. Businesses must examine the particular regulations applying to their sector and activity.

Indonesia's AI Framework Is Still Developing

Indonesia has not yet enacted a single comprehensive statute specifically addressing deepfakes or voice cloning.

The Government continues to prepare the National AI Roadmap 2026–2029 and an AI ethics regulation. As of 17 September 2026, Komdigi continued to describe both as components of the national AI governance framework being prepared.

The existing 2023 Ministerial Circular on Artificial Intelligence Ethics nevertheless provides guidance concerning security, transparency, accountability, personal data protection, intellectual property, and risk management.

Companies therefore should not wait for a dedicated "deepfake law" before developing appropriate safeguards.

What Should Companies Do?

Deepfakes are not only a risk for technology companies. Any organization can become a target.

Companies should consider secondary verification for material financial instructions. A phone call or video call that appears to originate from an executive should no longer automatically be treated as sufficient authentication.

High-risk payments can instead require multiple approvals, callbacks to previously registered numbers, or verification through internal systems.

Companies should also establish rules governing the use of employee, executive, customer, and talent faces and voices in AI systems.

Agreements with performers, brand ambassadors, or voice actors can specifically address whether recordings may be used for AI training, digital replicas, synthetic voices, automated dubbing, and future content generation.

For externally published AI content, review procedures should cover consent, personal data, intellectual property, accuracy, and whether the presentation could mislead the public.

Conclusion

Deepfakes and voice cloning demonstrate how artificial intelligence can transform the risks associated with identity in digital environments.

The absence of a dedicated Indonesian deepfake statute does not place the technology outside the law.

Electronic information manipulation, personal data processing, identity falsification, fraud, commercial use of portraits, rights in recordings and performances, and reputational harm may each engage different legal regimes.

The central question is therefore not simply whether content was created using AI.

The more important questions are whose identity was used, what information was processed, whether consent existed, how the content was represented, why it was created, and what harm resulted.

Summary

Deepfake and voice-cloning technology can reproduce a person's face, voice, and apparent conduct with increasingly convincing realism. Although Indonesia does not yet have a dedicated deepfake statute, its use may trigger liability under the Electronic Information and Transactions Law, Personal Data Protection Law, Criminal Code, Copyright Law, and civil law depending on the purpose, circumstances, and resulting harm.

Legal Basis & References

  1. Law No. 11 of 2008 on Electronic Information and Transactions, as amended by Law No. 19 of 2016 and Law No. 1 of 2024. Article 35 addresses unlawful manipulation, creation, alteration, deletion, or destruction of Electronic Information or Electronic Documents for the purpose of having them regarded as authentic data.


  2. Law No. 27 of 2022 on Personal Data Protection. The law regulates personal data processing, including biometric data, and prohibits certain unlawful acquisition, disclosure, use, creation, and falsification of Personal Data.


  3. Law No. 1 of 2023 on the Criminal Code, as adjusted by Law No. 1 of 2026 on Criminal Adjustment. The Criminal Code has been in force since 2 January 2026. Article 492 on fraud may become relevant where synthetic identity or voice cloning is used as deceit to induce another person to surrender property or create or extinguish a financial obligation.


  4. Law No. 28 of 2014 on Copyright. Its provisions concerning commercial use of portraits and Related Rights of performers and phonogram producers may be relevant to the use of facial likenesses, sound recordings, and recorded performances in synthetic media.


  5. Article 1365 of the Indonesian Civil Code concerning unlawful acts may provide a basis for civil liability where the relevant conduct, fault, damage, and causal connection can be established.


  6. Minister of Communication and Informatics Circular Letter No. 9 of 2023 on Artificial Intelligence Ethics, which addresses principles including security, transparency, accountability, personal data protection, intellectual property, and risk management.


  7. Minister of Trade Regulation No. 19 of 2026 on Electronic Commerce, particularly Article 47 concerning responsibility for AI use, disclosure or labelling, internal AI governance, complaint mechanisms, personal data, consumer protection, and intellectual property.

Tags

Deepfake

Voice Cloning

Artificial Intelligence

Personal Data Protection

Electronic Information Law

Intellectual Property

Digital Fraud

AI Governance

Need Legal Advice?

Our team is ready to assist you with practical solution

All inquiries are treated with strict confidentiality and attorney-client privilege. Your information will never be shared with third parties.