🏛️ State deepfake rules
1. Key Themes
Theme 1: AI Deepfake Regulation is a Patchwork — States Are Outpacing Congress
The absence of a federal baseline has created a fragmented legal landscape, leaving voter protections highly uneven depending on geography.
"Proposals to tackle AI in elections have been floated in Congress for years, but states have moved faster — creating different realities for voters depending on where they live."
Twenty-nine states have laws in effect, but the approaches vary dramatically — from outright bans (Maryland's is year-round; Minnesota and Texas restrict deepfakes only in windows before elections) to disclosure-only regimes with varying granularity.
Theme 2: First Amendment Is the Critical Battleground for Deepfake Laws
Two of the most prominent state-level efforts have already been struck down, signaling legal fragility across the entire regulatory category.
"California's and Hawaii's AI deepfakes laws were struck down in court on First Amendment grounds."
Both states are now pivoting to disclosure-based approaches rather than outright bans, which may become the template for legally durable regulation.
Theme 3: The Trump AI Framework Has a China-Sized Blind Spot
The White House's voluntary, cooperation-based model for AI oversight is structurally inapplicable to Chinese AI labs, creating a significant national security gap.
"This was never going to be the right tool for Kimi K3 or Qwen... The covered-model framework is a pre-release cooperation mechanism. Restricting Chinese model use is an access and procurement fight that's still being negotiated separately." — Joseph Hoefer, Monument Advocacy
The framework relies on companies wanting to be in the U.S. government's "good graces" — a mechanism that simply does not apply to adversarial-nation developers: "China doesn't care about that."
Theme 4: Data Center Infrastructure Is Becoming a Legislative and Tax Flashpoint
AI infrastructure is triggering simultaneous legislative action at federal and state levels around taxation, community impact, and electricity costs.
"American communities are rightfully questioning whether the rapid buildout of data centers across the nation will benefit them." — Sen. Ron Wyden
Kentucky's governor signed an executive order requiring data center developers to show they "won't increase electricity costs for existing customers, harm the environment or avoid local taxes" and must commit to building "a meaningful relationship with the community."
2. Contrarian Perspectives
Perspective 1: The Trump AI Framework Is Not Actually an AI Governance Framework — It's a Pre-Release Review Mechanism for Friendly Actors
The conventional framing is that the White House has released an AI governance framework. The more accurate read: it's a voluntary, narrow pre-release cooperation tool that explicitly excludes open models and has no teeth for adversarial actors.
"The covered-model framework is a pre-release cooperation mechanism. Restricting Chinese model use is an access and procurement fight that's still being negotiated separately." — Joseph Hoefer
The framework "explicitly says nothing in it should be interpreted as restricting open models once they've been released." This means the most widely accessible and potentially dangerous models — open-source releases from Chinese labs like Kimi K3 (Moonshot) and Qwen (Alibaba) — are entirely outside its scope.
Perspective 2: Banning Deepfakes May Be the Wrong Legal Strategy — Disclosure Is More Durable
The instinct for legislators is to ban harmful AI-generated content. But the First Amendment has already neutralized California's and Hawaii's bans, suggesting prohibition-first approaches are legally vulnerable.
"Both states are pressing ahead with alternative approaches that don't specifically regulate election AI deepfakes."
California's pivot to the AI Transparency Act (requiring disclosure of AI-generated images) and Hawaii's consent-based approach for deepfakes in ads may prove more legally resilient — and become the national model.
Perspective 3: The Take It Down Act — Passed but Not Yet Effective
Congress passing its first AI deepfakes law (on nonconsensual intimate imagery) is widely cited as a milestone. But advocates warn the implementation reality is far weaker than the headline.
"Passing the law was one thing. Implementing it effectively is another, advocates say, citing inconsistent removal processes of posts and predicting litigation will be needed to secure strong enforcement."
3. Companies Identified
| Company | Description | Why Mentioned | Quote |
|---|---|---|---|
| Moonshot AI | Chinese AI lab | Developer of Kimi K3, an advanced open model outside the scope of the Trump AI framework | "This was never going to be the right tool for Kimi K3 or Qwen" |
| Alibaba | Chinese tech conglomerate | Developer of Qwen, an advanced open model similarly outside the framework's reach | Same quote as above |
4. People Identified
| Person | Description | Why Mentioned | Quote |
|---|---|---|---|
| Joseph Hoefer | AI Principal, Monument Advocacy | Provided key analytical framing on the Trump AI framework's limitations regarding Chinese models | "The covered-model framework is a pre-release cooperation mechanism. Restricting Chinese model use is an access and procurement fight that's still being negotiated separately." |
| Sen. Ron Wyden (D-OR) | U.S. Senator, ranking member Senate Finance Committee | Introduced draft proposal to end existing data center tax incentives and create a new excise tax on data center investments | "American communities are rightfully questioning whether the rapid buildout of data centers across the nation will benefit them." |
| Gov. Andy Beshear (D-KY) | Kentucky Governor | Signed executive order establishing new community-protective standards for data center development | Ordered developers to show they won't "increase electricity costs for existing customers, harm the environment or avoid local taxes" |
| Sen. Richard Blumenthal (D-CT) & Sen. Marsha Blackburn (R-TN) | U.S. Senators | Champions of the Kids Online Safety Act, which passed Senate Commerce Committee unanimously | "The Senate has repeatedly shown that there is broad, bipartisan support for a version of KOSA that creates a duty of care to protect kids from online predators, addictive algorithms, and harmful product design." |
5. Operating Insights
Insight 1: If You're Building AI Tools for Political Campaigns, Operate State-by-State — the Legal Exposure Varies Dramatically
There is no federal baseline. Operators in political AI (ad generation, candidate content, voter outreach) face 29 different state regimes. Some require disclosure of the creator's identity, creation date, and edit history (Colorado, Utah). Others ban deepfakes outright during election windows. Building compliance infrastructure that is state-aware is now a table-stakes requirement.
Insight 2: Data Center Developers Must Now Budget for Community Relations as a Core Approval Requirement
Kentucky's executive order explicitly requires developers to commit to building "a meaningful relationship with the community" before projects move forward — alongside financial and environmental requirements. As community backlash grows (fueled by electricity cost and land use concerns), community engagement is shifting from a soft ESG consideration to a hard regulatory gate.
Insight 3: Voluntary Cooperation Frameworks Only Work When the Counterparty Has Reputational Incentives
The Trump AI framework's reliance on companies wanting to be in the government's "good graces" is a useful design principle — but only for actors who value that standing. For companies outside U.S. jurisdiction or without U.S. commercial interests, the mechanism has zero leverage. Operators and investors should not model geopolitical AI risk based on this framework's scope.
6. Overlooked Insights
Insight 1: The NSF Is Quietly Building a Distributed AI Infrastructure Network
Briefly mentioned but potentially significant: the National Science Foundation announced a $100 million program to establish up to 10 state and regional AI infrastructure hubs, aimed at expanding access to compute and data. This could meaningfully decentralize AI capability beyond major tech centers — creating new geographic vectors for AI startups, academic research commercialization, and regional government AI adoption that investors focused on coastal tech ecosystems may be underweighting.
Insight 2: The EU AI Act's Transparency Rules Are Now Being Actively Enforced
The article notes in passing that "the European Union has now begun enforcing AI Act transparency rules, including disclosure requirements for certain AI systems and labeling requirements for AI-generated content." For any company operating in or selling into Europe, this is no longer a future compliance risk — it is a current one, with labeling and disclosure obligations already in effect as of this publication date.