
What is the new law in Washington State regarding deepfakes?
Key Facts
- Washington's SHB 1205 is the first U.S. law to broadly criminalize all malicious deepfakes, effective July 27, 2025 according to BakerHostetler.
- Distributing a malicious deepfake in Washington carries up to 364 days in jail and a $5,000 fine per Crowell & Moring.
- Washington's SSB 5886 doubles civil deepfake penalties from $1,500 to $3,000 and adds noneconomic damages according to Cooley.
- SHB 1205 uses a 'should have known' standard, so ignorance of a forged likeness is no defense per legal analysis.
- The FCC ruled in February 2024 that AI-generated voices count as artificial voices under the TCPA, requiring prior express consent per the FCC ruling.
- TCPA violations cost $500–$1,500 per call, and FCC fines can reach $23,727 per violation per compliance guidance.
- Cooley warns existing contract consent language may not cover AI-generated likenesses under Washington's new statutory definition per its client alert.
Washington's Two New Deepfake Laws, Explained
Washington did not pass one deepfake law — it passed two, and together they create both criminal and civil exposure for anyone who distributes deceptive synthetic media. Here is what each law does and why the details matter for any business using AI-generated voices or likenesses.
SHB 1205, effective July 27, 2025, is the first U.S. law to broadly criminalize all malicious deepfakes — not just sexual or political ones. Signed April 16, 2025, it amends Washington's second-degree criminal impersonation statute, according to a BakerHostetler analysis.
The law prohibits knowingly distributing a forged digital likeness of another person as genuine, with intent to defraud, harass, threaten, intimidate, or for any other unlawful purpose. Violations are a gross misdemeanor carrying up to 364 days in jail and a $5,000 fine, with enhanced penalties for fraud and identity theft.
SSB 5886, effective June 11, 2026, adds the civil layer by expanding Washington's Personality Rights Law to cover AI-generated likenesses of living and certain deceased individuals. Per a Cooley client alert, it doubles the civil penalty from $1,500 to $3,000 and adds noneconomic damages for reputational injury, humiliation, and mental or physical pain and suffering.
Both laws share the same three-part definition of a "forged digital likeness":
- Content digitally created or altered to be indistinguishable from genuine content of an identifiable individual
- Content that misrepresents the person's appearance, speech, or conduct
- Content likely to deceive a reasonable person
The most consequential detail for businesses is the "should have known" liability standard. SHB 1205 does not require actual knowledge — liability extends to conduct a party reasonably should have known involved a forged likeness, as Crowell & Moring's analysis explains. Ignorance is no longer a defense; process is.
SHB 1205 does carve out exemptions for cultural, historical, political, religious, educational, and newsworthy content, and it grants platform-style immunity to interactive computer services and telecom providers that respond promptly to takedown requests. Courts have yet to resolve how "likely to deceive a reasonable person" interacts with First Amendment protections for satire and parody.
For organizations using AI voice technology legitimately, the practical takeaway aligns with federal rules: the FCC's February 2024 Declaratory Ruling treats AI-generated voices as "artificial" under the TCPA, requiring prior express consent, clear identification, and opt-out ability, according to the National Law Review. Cooley also warns that existing consent language in contracts may not cover AI-generated likenesses under the new definition.
This is why disclosure-first operations matter. My AI Call Center builds AI disclosure into every call, verifies list source and consent records before any campaign launches, and honors opt-outs immediately — the structural opposite of the deceptive impersonation these laws target. When liability attaches to what you "should have known," documented consent and transparent disclosure are the compliance posture that holds up.
Why AI Voice Calls Sit at the Center of the Risk
A voice that sounds exactly like a real person — but isn't — is precisely what Washington's deepfake laws were written to stop. And when that voice picks up the phone, a separate layer of federal law kicks in, one that every organization running outbound calls needs to understand.
In February 2024, the FCC unanimously ruled that AI-generated voices count as "artificial" voices under the TCPA, making AI-voice robocalls illegal without proper consent (FCC declaratory ruling). The ruling covers "any AI technology that initiates any outbound telephone call using an artificial or prerecorded voice," including voice cloning.
That matters here because Washington's laws and the FCC's rule target the same core problem: a synthetic voice that misrepresents a person's speech and could deceive a reasonable listener. Both SHB 1205 and SSB 5886 define a "forged digital likeness" as content indistinguishable from genuine content that misrepresents appearance, speech, or conduct (legal analysis). A cloned voice on a call fits that definition almost perfectly.
The FCC ruling produces three compliance requirements for any AI-driven calling:
- Prior express consent before placing an AI-voice call to a consumer.
- Caller identification and AI disclosure — the responsible party must identify itself, and the artificial nature of the voice must be disclosed.
- Immediate opt-out ability, consistent with FCC consent revocation rules.
The stakes are real. TCPA violations run $500–$1,500 per call, and FCC fines can reach $23,727 per violation (compliance guidance). Washington adds its own exposure: SHB 1205 carries up to 364 days in jail and a $5,000 fine, with liability extending to what a party "should have known" (Crowell & Moring).
Cooley LLP warns that existing consent language in contracts "may not be sufficient to cover AI-generated digital likenesses" under the new statutory definition (Cooley client alert). That's why consent verification has to happen before a campaign launches, not after.
This is exactly how My AI Call Center structures its managed campaigns: list source and consent records are reviewed before any calls go out, AI disclosure is delivered on every call, and opt-outs are logged and honored immediately. The safest AI voice call is the one that never pretends to be something it isn't.
The Four Compliance Practices That Keep You Safe
Knowing the law matters less than building habits that satisfy it. Law firms analyzing Washington's new deepfake statutes converge on the same practical advice — and it maps cleanly onto four safeguards any organization running AI-powered calls should treat as non-negotiable.
1. Verify consent records before launch. Cooley warns that existing consent language in contracts and terms of service may not cover AI-generated likenesses under the new statutory definition. Separately, the FCC requires prior express consent for AI-voice calls under the TCPA. This is why My AI Call Center runs a list-and-consent review before any campaign launches — checking list source, consent records, and calling windows, and plainly telling clients when a list won't support the campaign.
2. Disclose AI on every call. The FCC's February 2024 Declaratory Ruling treats AI-generated voices as "artificial" voices, which carries three obligations: prior express consent, identification of the responsible party, and a working opt-out mechanism, per the National Law Review's regulatory analysis. Disclosure isn't a courtesy — it's the structural opposite of the deception both Washington statutes target. Every My AI Call Center campaign opens with AI disclosure, and recipients can ask whether the call is AI-assisted, request a human, or opt out at any point.
3. Honor opt-outs immediately — and document them. Crowell & Moring recommends that businesses in higher-risk sectors adopt disclaimer language, consent documentation, and prompt response procedures to mitigate exposure. In practice, that means:
- Keyword opt-outs (STOP and REVOKE) processed the moment they arrive
- DNC requests respected across all campaigns, not just the active one
- Opt-out and DNC logs delivered back into client records as campaign deliverables
- Disposition codes on every call, so the record shows exactly what happened
- Never clone a real voice without permission. Both SHB 1205 and SSB 5886 target "forged digital likenesses" that misrepresent a person's speech or conduct and could deceive a reasonable listener. The criminal side carries up to 364 days in jail and a $5,000 fine, while the civil side doubles penalties to $3,000 plus noneconomic damages. A disclosed, clearly synthetic voice used with consent sits outside that definition; an undisclosed clone of a real person sits squarely inside it.
The through-line is the "should have known" standard — liability attaches to organizations that reasonably should have caught the problem. Managed campaigns that bake consent review, disclosure, opt-out logging, and script approval into the launch process remove that ambiguity by design, rather than relying on after-the-fact good intentions.
How to Run Compliant AI Calls in Washington
Running AI-powered outbound calls in Washington means building disclosure and consent into every step — not bolting them on after the fact. The FCC's February 2024 ruling confirms that AI-generated voices are "artificial" under the TCPA, requiring prior express consent, clear identification of the responsible party, and a working opt-out mechanism on every call FCC declaratory ruling. At the same time, Washington's SHB 1205 (effective July 27, 2025) criminalizes distributing a "forged digital likeness" with intent to defraud, harass, or for any unlawful purpose — and liability extends to conduct a party reasonably should have known was deceptive Crowell & Moring analysis. A managed campaign process that verifies consent before launch and discloses the AI voice on every call is the practical response to both regimes.
- Campaign review — one clear goal, quoted before launch
- List and consent review — source, permission records, and calling windows checked before any dialing begins
- Script and disclosure approval — AI disclosure, opt-out language, and escalation path signed off by the client before going live
- Launch and monitor — calls run in approved windows with real-time outcome tracking
- Disposition reporting — named outcome codes, per-call notes, routed follow-ups, and opt-out/DNC logs delivered at close
My AI Call Center runs this process on approved, permissioned, or reviewed lists only — never indiscriminate cold calling. Keyword opt-outs (STOP, REVOKE) are honored immediately and carried into the client's DNC records across all campaigns. The FCC also requires that callers identify the business and disclose the AI-generated nature of the voice National Law Review on TCPA compliance, which is baked into every script we approve. Campaign requirements vary by location, industry, contact type, consent status, and technology; clients are responsible for obtaining appropriate legal guidance before launch.
Frequently Asked Questions
What exactly does Washington's new deepfake law make illegal?
Can I get in trouble under the law even if I didn't know the content was a deepfake?
Are there any exemptions, like for satire or news content?
Does the second Washington law add anything beyond criminal penalties?
Do these deepfake laws apply to AI voice calls, like the ones my business runs?
Is the consent language in my existing contracts enough to cover AI-generated voices and likenesses?
The Safest AI Voice Call Is the One That Never Pretends
Washington's two new laws — SHB 1205's criminal penalties and SSB 5886's expanded civil liability — send one clear message: deceptive synthetic media now carries real consequences, including up to 364 days in jail and a $5,000 fine under the criminal statute, per Crowell & Moring's analysis. And because liability attaches to what your organization "should have known," good intentions aren't a defense — documented process is. The practical path forward is straightforward: verify consent records before any campaign launches, disclose AI on every call, honor opt-outs immediately, and never clone a real voice without permission. That disclosure-first structure is exactly how My AI Call Center runs its managed campaigns — consent reviewed before launch, AI identified on every call, opt-outs logged and carried into your DNC records. If you're planning AI-powered outbound calling and want the compliance built in rather than bolted on, the first campaign review is free — and you'll know the full number before you approve anything.