The 2026 U.S. midterms are the first stage on which elections in the age of AI face a large-scale test. Over the past few years several states have passed laws targeting election deepfakes (AI-generated video or audio realistic enough to pass as genuine), and this year is the first real test of how those laws work on the campaign trail [source: Pluribus News, 2026]. Public anxiety is high, too. In an NPR/PBS/Marist poll, 85% of Americans said AI-generated political content was likely to spread misleading information during the midterm season [source: AP, 2026].
But this is exactly where care is required. "People are worried" and "the election was actually distorted" belong to entirely different layers of the story. This article keeps them apart. In order, it asks: what does the measured data from the 2024 global elections actually say, what verified harms nonetheless occurred, how far has the law come (introduced and enacted are not the same), where does it collide with free speech, and how effective are defenses like detection, labeling, and media literacy. The short version: the threat is real, but its size sits somewhere between the fear and the data.
One note about how this piece handles evidence. Three kinds of statement get blended together in almost every deepfake story. There is what has been measured: platform tallies, study results, court records, counts of laws actually on the books. There is what has been projected: polling about what people expect, expert warnings, bills introduced but not passed. And there is what has been reported or alleged: a claim about a specific clip, or a candidate's own account of why a race went the way it did. Coverage that drops those markers is where the exaggeration usually enters.
Table of Contents
- Why now — the 2026 midterms put deepfake rules to the test
- The 2024 lesson — big fears, modest measured impact
- Real harms did occur — the verified incidents
- Where the law stands — 31 states, a federal vacuum
- The free-speech counterargument, and the reality of enforcement
- Defenses — detection, labeling, provenance, and media literacy
- Conclusion — what to watch
Why now — the 2026 midterms put deepfake rules to the test
The first field test of a decade of state lawmaking
What makes the 2026 midterms distinctive is not the arrival of the technology but that the laws meant to govern it are being tested in the field for the first time. This year is the first large-scale arena in which the election-deepfake rules passed by many states in recent years meet actual campaign advertising [source: Pluribus News, 2026].
That framing matters because most of these rules have so far been law on paper rather than law in use. By July 2026, 31 states had enacted statutes of this kind, yet experts describe actual enforcement as spotty and note that empirical data for testing whether the statutes work is scarce [source: Pluribus News, 2026]. A law that has never been invoked tells you what a legislature intended, not what a rule does. This cycle is the first chance to observe the second thing.
What the 2026 ads actually look like
Concrete uses have already appeared. The National Republican Senatorial Committee ran an AI-altered ad featuring James Talarico, a Democratic U.S. Senate candidate in Texas, and according to political experts and a Reuters review of public ads, Republicans made comparatively more use of AI this cycle [source: AP, 2026]. The examples pile up at the state level, too. In Michigan, candidates released AI videos targeting opponents (some labeled, some not); in Oregon, unlabeled synthetic videos drew a secretary of state investigation; and in Kentucky, a congressman pointed to an AI ad satirizing him as one reason for his primary loss [source: Pluribus News, 2026].
Those state examples are worth taking one at a time, because they are not the same kind of event. In Michigan, Nesbitt released an AI video featuring Whitmer that carried a label disclosing the manipulation, while Mike Rogers released an unlabeled AI video casting himself as a superhero. In Oregon, an unlabeled synthetic video from Lockwood targeting Rep. Bynum drew the secretary of state's investigation. In Kentucky, the satirical AI ad concerned Rep. Thomas Massie, who afterward named it as part of the reason he lost his primary [source: Pluribus News, 2026]. Labeled differs from unlabeled, and satire from impersonation; only the labeling distinction currently carries much legal weight. The Kentucky item is a candidate's own explanation of a defeat, which is a claim about cause rather than a measurement of one.
Concern measures mood, not harm
The public unease is genuine. The 85% figure above captures that temperature [source: AP, 2026]. Yet that number is "the share of people who feel it could happen," not "a measurement that it did happen." Not placing the size of the worry and the size of the harm on the same scale is the principle running through this entire piece.
The 2024 lesson — big fears, modest measured impact
The largest natural experiment we have
Fortunately, we have recent data to consult. 2024 was a record "global election year." Some 40-plus countries voted, and together they accounted for more than 41% of the world's population and 42% of global GDP [source: TIME, 2024]. That is why warnings that AI would upend democracy filled the early part of that year.
What the post-election assessments found
The post-election assessment, however, was rather different. The U.S. Intelligence Community concluded that while foreign actors did use generative AI, it did not "revolutionize" their influence operations [source: TIME, 2024]. Meta reported that, across its platforms, AI content tied to elections, politics, and social topics amounted to less than 1% of all fact-checked misinformation. It also said it had rejected 590,000 requests to its image generator to create deepfakes of major candidates in the month before Election Day, and that its existing policies and processes were sufficient to reduce the risk [source: Meta, 2024]. A Purdue database logged more than 500 AI-related incidents, but most were not attempts to deceive — they were satire, education, or commentary [source: TIME, 2024].
Those three findings come from three vantage points, and none is complete on its own. The intelligence assessment describes foreign influence operations, one channel among many. Meta's figures describe Meta's own platforms and its own fact-checking pipeline — a self-report by an interested party, with a denominator that can only count what the pipeline caught. The Purdue count captures incidents somebody noticed and recorded, which is not the same as incidents that occurred. What they share is direction rather than precision: three independent looks at the same year all found less than the forecasts had predicted. The 590,000 rejected image requests measure demand that was blocked before it became content, not harm that reached voters.
Why "less than feared" is not "nothing"
None of this means "we are safe going forward." A great deal of AI content moves through hard-to-observe spaces such as encrypted messaging, and detection remains difficult. Indeed, one civil-society figure said they were "pretty worried about what it will look like in 2026 and definitely 2028" [source: TIME, 2024]. The lesson of 2024 is not "the threat was fiction," but "there was a large gap between the scale the fear predicted and the scale that was actually measured."
The people best placed to judge put it in those terms. Betsy Hoover of Higher Ground Labs assessed afterward that AI's effect had not reached the level people expected or feared, and the warning above about 2026 and 2028 came from Sunny Gandhi of Encode Justice [source: TIME, 2024]. Together they describe a finding and its expiry date. The blind spots are the reason to hold it loosely: content moving through encrypted channels appears in no transparency report and no incident database, both of which can only count what is visible to them. "Less than 1% of fact-checked misinformation" is precise about a measured space and silent about an unmeasured one.
Real harms did occur — the verified incidents
The New Hampshire robocall — the clearest verified case
That said, the harm was not zero. The most clearly verified incident happened in New Hampshire in 2024. Two days before the primary, an AI voice cloning President Biden was pushed out in a robocall (an automated recorded call) telling voters not to cast a ballot in the primary. The Federal Communications Commission proposed a $6 million fine against Steve Kramer, the political consultant behind the scheme, and Lingo Telecom, the carrier that actually transmitted the calls, agreed to a $1 million civil settlement [source: FCC, 2024]. Kramer was charged in New Hampshire on 26 criminal counts, including voter intimidation and suppression [source: NPR, 2024].
The charges were not minor ones: of those 26 counts, 13 were felony counts of voter intimidation or suppression [source: NPR, 2024]. What makes this the reference case is its completeness — the artifact, the actor, the distribution path, and the apparent intent were all identified, which is rare, and which is why most alleged deepfake incidents never reach this level of documentation.
Three tracks, one case, three different outcomes
Here, too, the layers must be separated. Kramer was acquitted at his criminal trial [source: Pluribus News, 2026]. In other words, the FCC's administrative penalty held, but criminal guilt did not. The case shows that a regulatory violation and proof of a crime clear different bars.
Set out as tracks, one incident ran on three at once. A federal regulator proposed a $6 million fine against the consultant; the carrier that transmitted the calls settled for $1 million [source: FCC, 2024]; a jury acquitted [source: Pluribus News, 2026]. Different institutions asked different questions under different standards. So the useful habit when reading the next case is to ask which track a headline describes: "fined," "settled," and "convicted" are three distinct outcomes, and only the last is a finding of criminal guilt.
A second strand — AI that is wrong without meaning to be
A different kind of harm came not from malicious manipulation but from AI's own inaccuracy. In 2024, several studies tested chatbots' ability to give voting guidance. When the AI Democracy Projects and Proof News tested five major models, more than half the responses were inaccurate and many were harmful or incomplete. One model wrongly advised that Californians could vote by text message, which is illegal nationwide [source: AI Democracy Projects, 2024]. In a separate analysis, GroundTruthAI reported that chatbots answered 2024 election and voting questions incorrectly 27% of the time [source: GroundTruthAI, 2024], and the Center for Democracy & Technology found incorrect information in more than a third of election-related queries [source: CDT, 2024]. U.S. officials warned voters not to rely on chatbots for voting questions [source: CNBC, 2024]. This is a different strand of the threat, because it stems from system hallucination rather than an intended deepfake. The error rate is a real measurement, but there is no confirmed evidence it changed any actual vote count.
Two details show how ordinary the failures were. In the Proof News test, four of the five models answered incorrectly about same-day voter registration in Nevada [source: AI Democracy Projects, 2024]. The Center for Democracy & Technology's finding came out of a set of 77 election-related queries [source: CDT, 2024]. These were not exotic prompts designed to trip a model up; they were the questions an ordinary voter would type — where, when, and how to vote.
What the error rates do and do not prove
It is tempting to add the two strands into a single figure for "AI harm in elections," and that is exactly what should not be done. The robocall was intentional, had an identifiable author, and aimed at suppressing turnout. The chatbot errors were unintended byproducts of systems never built to be election authorities, and what was measured there is an error rate, not a harm. They do meet the same defense, though: verify procedural facts with an election office rather than a model [source: Brennan Center for Justice, 2024].
Where the law stands — 31 states, a federal vacuum
Counting enacted laws, not headlines
Legislation is moving fast. To read the pace accurately, though, you have to separate "introduced" from "enacted." Measured by enacted law, the number of states regulating election deepfakes rose from five in 2023 to 26 by January 2026 [source: R Street Institute, 2026]; Maryland became the 30th state on May 13 [source: Public Citizen, 2026]; and by July the count reached 31 [source: Pluribus News, 2026].
Read as a curve, that is five states in 2023, 26 at the start of 2026, 30 by mid-May, and 31 by July — most of the growth compressed into 2023 through early 2026, with the pace flattening after. One caveat about the numbers: they do not come from a single tracker. The 2023 and January 2026 figures are R Street Institute's, the 30th-state milestone is Public Citizen's, and the July total is from Pluribus News. All three count enacted law rather than bills filed, which is the property that matters here.
Two designs — disclose, or prohibit
These laws split broadly into two families. One is the disclosure-and-labeling approach, which requires AI use to be marked within a set window before an election and gives a targeted candidate the right to seek a court injunction. This is the more common design. The other is prohibition. Minnesota and Texas bar the distribution of deepfakes within a set number of days before an election, and Maryland bans them year-round [source: Public Citizen, 2026].
The choice between the two designs determines what a court will later be asked to review. A disclosure rule regulates the packaging: it requires a speaker to add information and leaves the message alone. A prohibition regulates the message, so a court must decide which political content is deceptive enough to forbid. Ilana Beller of Public Citizen describes the target narrowly — deceptive, realistic AI content created to harm a candidate [source: Pluribus News, 2026]. That tightness is deliberate, and the next section shows why it is necessary.
The federal vacuum
The federal picture is different. At the federal level, AI political deepfakes are still not illegal. The leading bill to change that is the Protect Elections from Deceptive AI Act (S.1213), introduced on March 31, 2025 by Senator Amy Klobuchar together with Josh Hawley and others. It would prohibit the distribution of materially deceptive AI audio or video relating to federal candidates and give those candidates a civil right of action for injunctive relief or damages. But the bill sits at an early stage, referred to the Senate Rules and Administration Committee — introduced, not enacted [source: U.S. Congress, 2025]. Meanwhile the TAKE IT DOWN Act, signed in May 2025, targets nonconsensual intimate imagery, not elections, and the Federal Election Commission is split along partisan lines and has not set AI-ad guidance. There is even a countervailing force: the Trump administration and some Republican lawmakers are pushing federal preemption that could nullify state AI rules [source: Public Citizen, 2026].
A few details sharpen the picture of that bill. Klobuchar's cosponsors include Hawley, Coons, Collins, and Bennet, and the text carries exceptions — for broadcasters' news programming, among others — so that ordinary journalism showing a manipulated clip is not swept in. A companion measure under the same name, H.R.5272, was introduced in the House [source: U.S. Congress, 2025]. Referral to committee is the routine first stop for any bill and signals neither momentum nor its absence.
One clarification heads off a common conflation. The TAKE IT DOWN Act, signed in May 2025, does address deepfakes — but the deepfakes it addresses are nonconsensual intimate images, not political content [source: U.S. Congress, 2025]. It is often cited as proof that Congress has acted on deepfakes. Congress has, on a different problem.
The counter-current — preemption
The push for federal preemption runs in the opposite direction from everything above. Preemption is the principle under which federal law displaces conflicting state law; applied to AI, it could nullify state-level rules, and Public Citizen flags the effort by the Trump administration and some Republican lawmakers as a live risk [source: Public Citizen, 2026]. The scenario matters because of where the substantive law currently sits: with Congress holding no election-deepfake statute of its own, the entire operative layer is the 31 states — exactly the layer preemption would reach.
The free-speech counterargument, and the reality of enforcement
Why prohibition-style laws keep losing in court
These laws have not settled in smoothly. The biggest wall is free speech. California's 2024 prohibition-style deepfake law was struck down in federal court as a First Amendment violation, though the same state's labeling requirement survived [source: R Street Institute, 2026]. Hawaii's law was likewise blocked as unconstitutional, and Montana's is currently in litigation [source: Pluribus News, 2026]. Political speech is the category the Constitution protects most heavily, so what counts as "deception" that may be banned is perpetually contested. So is how to carve out satire and parody — as the Kentucky case shows, the line between a satirical ad and malicious manipulation is often blurry [source: Pluribus News, 2026].
The pattern across those rulings tracks the design distinction from the previous section. A rule that says "you must disclose" asks a speaker to add a line of information; a rule that says "you may not publish" asks a court to decide which political messages are false enough to forbid, in a system where political speech sits at the center of constitutional protection.
Satire is the hardest edge
The Kentucky episode shows why the line is so hard to draw in statute. The ad was satirical, its subject was Rep. Thomas Massie, and Massie afterward named it as part of the reason for his primary loss [source: Pluribus News, 2026]. Nothing in that establishes deception: satire works by being recognized as satire, and being mocked in an ad is not being impersonated in one. A statute that catches the impersonation while exempting the satire must draw its line on the maker's intent or on what a reasonable viewer would conclude — both contestable, which is to say both invite litigation.
Enforcement is spotty, and largely unmeasured
The reality of enforcement is no simpler. Experts note that actual enforcement is spotty and that empirical data to test effectiveness is scarce. A researcher at NYU's Center on Technology Policy questions whether labeling really reduces deception and suggests that name, image, and likeness (NIL) protections may work better for AI depictions of politicians [source: Pluribus News, 2026]. That Kramer absorbed a large FCC fine in the New Hampshire robocall case yet was acquitted at his criminal trial illustrates the same gap between rule-breaking and punishment [source: Pluribus News, 2026]. In short, the laws are multiplying quickly, but there is still distance between "law on the books" and "law that works."
The researcher raising that doubt is Scott Babwah Brennen of NYU's Center on Technology Policy [source: Pluribus News, 2026]. His alternative changes the question a court has to answer. NIL protections govern the use of a person's name, image, and likeness, so a claim brought under them asks whether permission was given to use a likeness — not whether a piece of political content was deceptive. That question is narrower, more factual, and less entangled with the content of political speech.
Defenses — detection, labeling, provenance, and media literacy
Provenance — a receipt, not a lie detector
Technical defense rests on roughly three pillars. The first is provenance. C2PA Content Credentials (a standard led by the likes of Adobe and Microsoft, with the BBC, The New York Times, and Sony taking part) and Google DeepMind's SynthID watermarking try to attach a tag recording how a piece of content was made. The second is labeling. Many state laws require language along the lines of "this image, video, or audio has been manipulated" [source: Brennan Center for Justice, 2024]. The third is automated detection tools.
Provenance deserves a precise description, because it is often discussed as though it were detection. Content Credentials and SynthID do not inspect an unknown file and rule on whether it is fake; they attach a record of how content was made, at the point where it is made, and camera makers such as Leica take part alongside the publishers and platforms. The consequence is asymmetry: a valid credential is informative, while a missing one is close to meaningless — the file may be authentic footage from a device that never supported the standard, or a marker may have been stripped along the way [source: Brennan Center for Justice, 2024].
Labeling — what the statutes actually ask for
Labeling is the pillar with legal force behind it in a growing number of states, and what it asks for is plain: wording to the effect that "this image, video, or audio has been manipulated" [source: Brennan Center for Justice, 2024]. The Michigan and Oregon examples show the divide this creates in practice — some AI ads carry the disclosure and some do not, and it is the unlabeled ones that draw investigations [source: Pluribus News, 2026].
Detection tools — the warning that comes attached
The trouble is that none of these is a silver bullet. The Brennan Center for Justice advises voters not to rely on deepfake detection tools, because they have limited accuracy and will grow less effective as generation technology improves. Provenance information should not be over-trusted either — markers are easy to remove and adoption is uneven. If a platform has not clearly labeled content as "made by AI," their guidance is not to jump to conclusions about authenticity, but to verify using proven practices such as authoritative, independent fact-checkers [source: Brennan Center for Justice, 2024]. Checking voting procedures at official election-office websites rather than a chatbot follows the same logic.
A verification routine that does not depend on tools
What the Brennan Center recommends instead is a sequence rather than a gadget, and it comes to four steps. Check whether the platform itself has explicitly labeled the content as AI-made. If it has not, treat that as absence of evidence rather than evidence of authenticity. Take the claim to an authoritative, independent fact-checker rather than a detection app [source: Brennan Center for Justice, 2024]. And for anything procedural — where to vote, when, how to register — go to the election office's own website rather than a chatbot [source: CNBC, 2024]. None of these steps requires technical expertise, which is the point.
Media literacy as the load-bearing layer
That leaves media literacy. The Brennan Center names voter education, verification tools, and open-source resources as central to defense [source: Brennan Center for Justice, 2024]. If no single technology can stop deception on its own, what remains is to pair layered defenses with the social work of building a habit of not being fooled.
Conclusion — what to watch
The 2026 picture resists a one-sentence summary. Public anxiety is high (85% of Americans), real campaign use of AI has grown, and the state laws governing it have spread to 31. Yet the measured data from 2024 show AI's electoral impact was smaller than the fear, federal law remains stuck at the introduced stage, and the state laws must pass two tests at once — free speech and enforcement. The threat is real, but its size sits somewhere between overstatement and reassurance.
Put back in the terms this piece opened with: the 85% is projected concern; the 31 enacted state laws and the 2024 platform tallies are measured; and every claim that a particular clip changed a particular outcome remains reported rather than established. Sorting coverage into those three bins is most of the work of reading it accurately — and it has to be redone each cycle, because the measured column is the one that changes.
So the points to watch are clear. First, whether the deepfake laws in 31 states are actually enforced and prove effective in these midterms. Second, whether the federal S.1213 crosses from introduced to enacted, or whether the preemption push to nullify state rules wins out. Third, how courts reconcile labeling requirements with free speech. Fourth, whether detection and provenance technology is shown, in data, to actually reduce deception. And fifth — perhaps most important — that the real harm of deepfakes may lie less in any single fake fooling the many than in a rising, pervasive distrust in which even genuine evidence can be dismissed as "fake" (the so-called "liar's dividend") [source: Brennan Center for Justice, 2024]. What is needed now is neither to inflate the threat nor to wave it away, but to keep measuring its real size with data.