Introduction
Beyond their potential to facilitate human life and business processes, advancing artificial intelligence technologies have also provided the criminal underworld with an unprecedented tool: synthetic media—commonly known as “deepfakes”—and voice cloning. AI algorithms capable of mimicking a person’s facial features, expressions, body language, or tone of voice—using just a few seconds of audio and video—to a degree indistinguishable from reality have become devastating weapons for fraudsters, cybercriminals, and blackmailers.
The United Arab Emirates (UAE), Saudi Arabia, Qatar, Kuwait, Bahrain, and Oman—members of the Gulf Cooperation Council (GCC)—have become direct targets of these next-generation cyber threats due to their high per capita income, rapidly digitizing public and financial infrastructures, smart city visions, and high rates of high-tech adoption. Incidents such as AI-enabled impersonation, “CEO fraud” (where a CEO’s voice is cloned to authorize fraudulent multi-million dollar transfers), and reputational attacks involving fabricated videos of public officials or celebrities are on the rise in the region.
In response, Gulf states have launched a rigorous, uncompromising legal campaign to combat these issues, utilizing Cybercrime Laws and Personal Data Protection Laws (PDPL) alongside traditional penal codes.
In this comprehensive analysis… We examine the legal status, penalties, evidentiary processes, integrity of evidence, and avenues for protection regarding AI-enabled crimes—such as impersonation, fraud, reputational assassination, and blackmail—in GCC countries, using clear, accessible, and original language free from a clutter of technical jargon.
- How Are Deepfake and Voice Cloning Technologies Defined Legally?
For an act to constitute a crime within the legal system, its legal definition and material elements must first be clearly established.
Deepfake: The production of fake content in which an individual appears to say words they did not speak or perform actions they did not carry out, achieved by processing existing visual and audio data belonging to that person using deep learning algorithms—all without their explicit consent.
Voice Cloning: The process of analyzing an individual’s voice frequencies, inflections, and intonations via artificial intelligence software, and subsequently using the cloned voice to articulate desired text—either in real-time or through a recording.
Under Gulf law, the mere act of creating a deepfake or cloning a voice—if it involves the unauthorized processing of another person’s personal data—is considered a violation of rights; however, if these technologies are used as an instrument of a crime, cybercrime legislation comes into play.
Judicial authorities in GCC countries generally penalize acts committed using deepfake and voice cloning technology under the following four main categories:
Unauthorized Processing of Visual and Audio Data / Violation of Personality Rights
Cyber Fraud and Forgery (Aggravated Fraud)
Character Assassination, Defamation, and Slander
Blackmail, Threats, and Violation of Privacy
- Cybercrime Legislation and Penalties in GCC Countries,
As Gulf countries view cyberspace as an integral part of national security and public order, penalties for crimes committed in the digital realm are far more severe than in many other countries worldwide. In addition to imprisonment, sanctions include astronomical fines and deportation for foreign nationals.
A. United Arab Emirates (UAE)
With Federal Decree-Law No. 34 of 2021 on Combating Cybercrimes and Rumors (which entered into force in 2021), the UAE has drafted one of the most comprehensive legal frameworks addressing AI-related violations.
Impersonation and Identity Theft: Pursuant to Article 44 of the Law, individuals who assume another person’s identity or act on their behalf by manipulating or copying that person’s voice, image, or personal data without consent are subject to a minimum of one year in prison and a fine ranging from AED 250,000 to AED 500,000 (approximately USD 68,000 – 136,000).
Violation of Reputation and Privacy via Deepfakes: Individuals who disseminate a person’s private images online—or damage their reputation—by creating deepfake montages face penalties of one to three years in prison and a fine of up to AED 500,000.
Cyber Fraud: Those who obtain financial gain by deceiving banks, companies, or individuals through the use of cloned voices or deepfake videos are subject to prosecution involving a minimum prison sentence of one year and heavy fines reaching up to AED 1,000,000.
B. Kingdom of Saudi Arabia
Saudi Arabia imposes penalties within the framework of the Anti-Cybercrime Law of 2007, as updated by subsequent decrees. Violation of Privacy and Character Assassination: Pursuant to Article 3 of the Law, individuals who violate the privacy of others—or produce and disseminate fabricated images that damage their reputation—using camera-equipped mobile phones or information technology tools are subject to imprisonment for up to one year and a fine of SAR 500,000 (approximately USD 133,000).
Cyber-enabled Fraud: Article 4 of the Law penalizes the creation of fake identities using artificial intelligence or computer systems, or the act of deceiving others via fabricated audio or visual content to misappropriate their financial resources, with up to five years of severe imprisonment and a fine of SAR 3,000,000 (approximately USD 800,000).
C. Qatar, Kuwait, Bahrain, and Oman
Qatar:
Under Cybercrime Law No. 14 of 2014, individuals who create a false identity by altering another person’s digital data, or who engage in blackmail using artificial intelligence-generated materials, are subject to a prison sentence of up to three years and a fine of 100,000 QAR.
Kuwait: Under Cybercrime Law No. 63 of 2015, those who produce content that is immoral or damaging to reputation via deepfakes face prison sentences ranging from two to five years.
Bahrain and Oman: Through updates to their respective cybercrime laws, both countries have classified AI-generated fake audio and video under the scope of “forgery of documents and digital data,” prescribing prison sentences ranging from one to seven years.
- Typical Deepfake Crime Scenarios and Legal Classification
AI-based identity impersonation crimes manifest in various ways in practice, and each is penalized under different legal provisions:
A. “CEO Fraud” and Corporate Financial Theft
In this scenario, attackers upload audio recordings—sourced from previous media appearances or interviews of a senior executive (such as a CEO, CFO, or Chairman of the Board)—into an AI system. Subsequently, they call an employee in the company’s finance department and, using the cloned voice, request the transfer of millions of dollars or riyals to a specific account for an urgent purchase or a confidential investment.
Legal Classification: This act is not merely a simple case of fraud. Under GCC law, this crime… It is classified as a combination of the offenses of fraud involving digital systems, identity theft, and aggravated bank fraud. Penalties are imposed at the maximum statutory limit, and full restitution—including interest—is required for all financial losses suffered by the company.
B. Blackmail and Revenge
The perpetrator takes ordinary photos that the victim has shared publicly on social media and uses artificial intelligence tools to edit them into obscene videos. Subsequently, the perpetrator sends these videos to the victim to demand money or threatens to disseminate them to the victim’s family and professional circle if their demands are not met.
Legal Classification: Since Gulf countries place great importance on social morality, family privacy, and public order, this type of offense is subject to some of the harshest cyber-related sanctions. It involves a combination of crimes: blackmail, threats, violation of privacy, and the production of digital material contrary to public morals. The perpetrator faces both a severe prison sentence and an obligation to pay substantial non-pecuniary damages to the victim.
C. Political Character Assassination and Disinformation
This involves the creation of AI-generated fake videos of public officials, ministers, or prominent figures, portraying them as making statements intended to incite the public, manipulate exchange rates, or disrupt the state’s foreign relations.
Legal Classification: In GCC countries, this conduct is classified as a crime against public order, public peace, and state security. Going beyond ordinary fraud, it leads to prosecution in much stricter criminal courts under statutes concerning the violation of national security and the dissemination of fake news.
- Burden of Proof in Court, Digital Forensics, and Evidence Integrity
The greatest legal challenge facing the judiciary in deepfake and voice cloning cases is distinguishing the fake from the real and presenting evidence to the court in a valid manner. Courts in the Gulf have moved away from traditional concepts of evidence and adopted high-tech forensic examination methods.
A. Cyber Forensics Examination
To determine whether a video or audio recording is a deepfake, investigative bodies (such as the UAE Cybercrime Department or the Saudi Arabian Cybersecurity Authority) refer the file to cyber forensics experts.
Experts submit a forensic report to the court after examining the following technical parameters:
Pixel and Light Analysis: Examination of shadows, light reflections, blinking frequency (blinking reflexes often appear artificial in deepfake videos), and facial boundaries within the video.
Spectrum and Frequency Analysis: Detection of micro-differences between the natural frequency fluctuations of the human voice and the monotonous frequency patterns generated by artificial intelligence in voice cloning.
Metadata Examination: Tracking the digital file’s creation date, the software used to process it, and source IP addresses.
B. Preservation of the Chain of Custody
Under Gulf law, for digital evidence to serve as the basis for a court judgment, the “chain of custody” must remain unbroken. Simply taking a screenshot or photographing a phone screen with another phone may not be considered sufficient evidence on its own.
When submitting a message or audio recording involving blackmail or fraud to judicial authorities, the victim is required to preserve the data in its original form and have the submission formally recorded by authorized law enforcement agencies.
- The Role of Personal Data Protection Laws (PDPL)
The raw material for deepfake and voice cloning crimes consists of individuals’ personal data (photographs, audio recordings, videos). Consequently, these AI-perpetrated crimes also constitute direct violations of the Personal Data Protection Laws (PDPL) in the UAE, Saudi Arabia, and Qatar.
Legal Status of Biometric Data
Under the PDPL legislation in GCC countries, a person’s facial map, retinal data, and voice analysis fall into the category of “Sensitive Personal Data.”
Processing a person’s voice or face—without their “Explicit Consent”—to train an AI model or generate fake content constitutes, in itself, a major data violation offense.
AI companies or third-party data processors face heavy administrative fines for data protection violations if they fail to secure the voice and image data they collect and allow it to be leaked.
- Step-by-Step Legal Recourse for Victimized Individuals and Companies
Individuals and institutions in Gulf countries that fall victim to a deepfake or voice cloning attack (suffering financial loss or reputational damage) should take the following legal steps:
Step 1: Immediate Preservation of Evidence
The fake video, audio recording, or incoming threat messages must be secured on the original device before they are deleted or lost. Details such as the platform where the messages originated, usernames, URL links, and any money transfer receipts must be documented.
Step 2: Reporting via Official Cybercrime Portals
GCC countries have established highly practical digital reporting channels for victims:
UAE: Online cybercrime reports can be filed via the Ministry of Interior’s “MOI UAE” app, Dubai Police’s “eCrime.ae” portal, or Abu Dhabi Police’s “Aman” service.
Saudi Arabia: Complaints are filed via the Ministry of Interior’s Law Enforcement Portal (“Absher”) or Law Enforcement App (“Kulluna Amn”).
Qatar & Other Countries: Official reports are submitted to the Cybercrime Departments within the respective Ministries of Interior.
Step 3: Removal of Content from the Internet and Blocking Access
Following the formal complaint, cyber authorities (such as the UAE’s TDRA or Saudi Arabia’s CITC) are contacted to block access to the social media platforms and websites hosting the deepfake content and to ensure the content is taken down (issuance of a “Take-down Notice”).
Step 4: Criminal and Civil Litigation
Once the investigation is concluded and the perpetrator is identified (mechanisms for international judicial assistance and Interpol Red Notices are utilized even if the perpetrator is abroad):
In Criminal Court: Proceedings are initiated to ensure the perpetrator receives a prison sentence and a fine.
In Civil Court: Lawsuits are filed seeking pecuniary damages for actual financial losses incurred (e.g., funds lost to fraud, loss of employment) and non-pecuniary damages for the psychological distress and reputational damage suffered.
- Recommendations for Protection Against Deepfake Crimes and Cyber Hygiene
Just as legal protections against AI-driven fraud are important, preventive measures taken at both individual and corporate levels—known as “cyber hygiene”—are vital:
Voice Verification Protocol (For Companies): A “secondary verification” mechanism should be established between senior executives who issue financial transfer instructions and the employees executing them. Money transfers should not be made based solely on voice instructions received via phone; instead, pre-determined code words or secure internal messaging channels should be used.
Family Password System (For Individuals): There has been a recent rise in cases where families are called by someone using a cloned child’s voice, claiming the child has been kidnapped or involved in an accident. Establishing a secret “family password” to be used between family members during emergencies can instantly thwart such scams.
Social Media Privacy: Publicly sharing high-quality, long-duration videos featuring your face and voice makes it easier for AI models to be trained using your data. It is recommended to tighten account privacy settings.
Biometric Banking and Two-Step Verification: One should not rely solely on voice or facial recognition systems to access bank accounts; multi-factor authentication (MFA) methods—such as SMS, mobile app approval, or physical security keys—should be enabled.
General Assessment and Conclusion
Artificial intelligence, deepfake, and voice cloning technologies represent a highly complex phase of threats to the security of the digital world and the personal rights of individuals. However, the states of the Gulf Cooperation Council (GCC) are among the jurisdictions that have responded most swiftly and rigorously to this threat, thanks to their advanced technological infrastructure and strict cybercrime legislation.
In the GCC region, perpetrators who use artificial intelligence as a tool to impersonate others, commit fraud, or engage in character assassination face extremely severe prison sentences, fines amounting to billions of riyals or dirhams, and inevitable legal sanctions. The most essential steps for individuals and institutions to take in the face of this new type of crime are to maintain a high level of digital awareness, implement cybersecurity protocols, and immediately report any violations to the judicial authorities.
No Responses