Deepfake Statistics 2026
By Axis Intelligence Research
Co-author: Marcus Chen | Last updated: August 17, 2026 | License: CC BY 4.0
The FBI logged 22,364 AI-related cybercrime complaints in 2025 carrying $893,346,472 in adjusted losses — the first year artificial intelligence appeared as a formal descriptor in the Internet Crime Report. That is 2.2% of all complaints producing 4.3% of all losses. Synthetic media is not yet common. It is already expensive.
Quick Answer
Deepfake and synthetic-media crime is measured in the United States through the FBI’s AI descriptor, which recorded 22,364 complaints and $893.3 million in losses in 2025. According to Axis Intelligence Research, the average AI-related complaint cost $39,946 against an all-complaint average of $20,699 — an AI Fraud Amplification (AIFA) of 1.93. Victims aged 60 and over filed 14.1% of those complaints and absorbed 39.5% of the losses.
Key Findings
- According to Axis Intelligence Research, AI-related complaints reported to the FBI in 2025 carried 1.93 times the average loss of the complaint population as a whole ($39,946 versus $20,699), computed from the Internet Crime Complaint Center’s own crime-type tables.
- Axis Intelligence Research finds that 83.0% of all AI-related fraud losses reported to the FBI in 2025 moved over cryptocurrency rails — $741,639,787 of $893,346,472 — while crypto-nexus complaints made up only 39.0% of AI-related complaint volume.
- Complainants aged 60 and over accounted for 3,143 AI-related complaints and $352,496,231 in losses in 2025, meaning elder victims carried 2.81 times their proportional share of synthetic-media fraud losses, per Axis Intelligence Research calculations on FBI data.
- The National Center for Missing & Exploited Children received more than 400,000 CyberTipline reports with a generative-AI nexus in 2025, of which more than 182,000 involved offenders possessing, generating, or attempting to generate AI child sexual abuse material.
- The Federal Trade Commission began enforcing the TAKE IT DOWN Act on May 19, 2026, and issued warning letters to 12 “nudify” services the following day, with civil penalties of up to $53,088 per violation; the European Union’s synthetic-content labelling duties under Article 50 of the AI Act applied from August 2, 2026.
The Axis Metric: AI Fraud Amplification (AIFA)
AIFA — AI Fraud Amplification. The ratio of the average reported loss on complaints flagged with an AI nexus to the average reported loss across all complaints, computed inside a single reporting system, for a single year, within the same crime type.
Most published deepfake numbers compare a vendor’s telemetry to a survey to a projection, and the result means nothing. AIFA avoids that. Every input comes from one document — the FBI’s 2025 Internet Crime Report — so the denominator, the collection method, the reporting population, and the loss definition are identical on both sides of the ratio.
Formula
AIFA(crime type) = (AI-related loss ÷ AI-related complaints)
÷ (total loss ÷ total complaints)
Headline reading: $893,346,472 ÷ 22,364 = $39,946. $20,877,000,000 ÷ 1,008,597 = $20,699. AIFA = 1.93 (as of the 2025 reporting year, published April 2026).
An AIFA above 1.00 means a criminal who reached for a synthetic-media or generative tool extracted more money per successful complaint than the field average. Below 1.00 means the tool added reach but not yield.
AIFA by crime type, 2025
| Crime type | AI complaints | AI losses | Avg loss, AI | Avg loss, all | AIFA | Source |
|---|---|---|---|---|---|---|
| IPR / Copyright & Counterfeit | 63 | $10,103,789 | $160,378 | $11,176 | 14.35 | FBI IC3 2025 |
| Phishing / Spoofing | 803 | $10,283,732 | $12,807 | $1,127 | 11.37 | FBI IC3 2025 |
| Lottery / Sweepstakes / Inheritance | 54 | $4,486,965 | $83,092 | $34,527 | 2.41 | FBI IC3 2025 |
| Business Email Compromise | 135 | $30,256,592 | $224,123 | $123,005 | 1.82 | FBI IC3 2025 |
| Harassment / Stalking | 763 | $1,445,378 | $1,894 | $1,285 | 1.47 | FBI IC3 2025 |
| Employment | 691 | $12,550,185 | $18,162 | $14,701 | 1.24 | FBI IC3 2025 |
| Investment | 4,356 | $632,041,188 | $145,097 | $118,500 | 1.22 | FBI IC3 2025 |
| Extortion | 1,764 | $2,940,642 | $1,667 | $1,374 | 1.21 | FBI IC3 2025 |
| Government Impersonation | 260 | $7,061,628 | $27,160 | $24,610 | 1.10 | FBI IC3 2025 |
| Real Estate | 115 | $2,699,085 | $23,470 | $22,244 | 1.06 | FBI IC3 2025 |
| Credit Card / Check Fraud | 139 | $1,836,105 | $13,209 | $15,056 | 0.88 | FBI IC3 2025 |
| Personal Data Breach | 1,204 | $18,767,964 | $15,588 | $19,493 | 0.80 | FBI IC3 2025 |
| Tech / Customer Support | 574 | $19,457,078 | $33,897 | $44,664 | 0.76 | FBI IC3 2025 |
| Confidence / Romance | 626 | $19,041,653 | $30,418 | $40,126 | 0.76 | FBI IC3 2025 |
| Identity Theft | 460 | $1,643,308 | $3,572 | $5,867 | 0.61 | FBI IC3 2025 |
The table above shows 15 of the 26 crime types the FBI reports. All 26 ship in the CSV, including the six with fewer than 50 AI-flagged complaints, which are marked NA rather than scored, and ransomware, whose AI-flagged loss is zero.
Scope note. The AI descriptor is applied when a complaint references artificial intelligence. It captures what victims and analysts noticed, not everything that happened — and it does not separate a cloned voice from a chatbot-written email. AIFA measures the money attached to a noticed AI nexus, which is a floor, not a ceiling.
Marcus Chen: The two runaway ratios are the interesting ones, and they run in opposite directions from the story most vendors tell. Phishing at 11.37 does not mean AI made phishing eleven times more dangerous in general — phishing’s all-complaint average loss is $1,127 because the category is stuffed with 191,561 near-zero-loss reports. What AI did was pull a small number of phishing attempts into wire-transfer territory. Confidence and romance fraud, meanwhile, sits at 0.76. The category with the most breathless deepfake coverage is the one where the synthetic tool did not raise the take. Attribution has a cost, and the cheapest attacks do not need it.
How Much Money Do Deepfakes and AI-Enabled Fraud Actually Cost?
The honest answer is that no institution measures deepfake losses as a line item. What exists is the FBI’s AI descriptor, and reading it carefully is more useful than any projection.
| Measure | 2025 value | Source |
|---|---|---|
| AI-related complaints | 22,364 | FBI IC3 2025 |
| AI-related adjusted losses | $893,346,472 | FBI IC3 2025 |
| Total IC3 complaints | 1,008,597 | FBI IC3 2025 |
| Total IC3 losses | $20,877,000,000 | FBI IC3 2025 |
| AI share of complaints | 2.22% | Axis Intelligence Research calculation |
| AI share of losses | 4.28% | Axis Intelligence Research calculation |
| AI-related complaints per day | 61.3 | Axis Intelligence Research calculation |
| AI-related losses per day | $2,447,525 | Axis Intelligence Research calculation |
According to Axis Intelligence Research, the single largest concentration of AI-related loss sits in investment fraud: $632,041,188, or 70.7% of all AI-flagged losses. The FBI’s own commentary on this is the most quotable line in the report — investment losses overall exceeded $8 billion, and the bureau notes that many victims never realize AI was involved at all. The descriptor is a self-report.
Where the money goes
Axis Intelligence Research finds that AI-flagged complaints with a cryptocurrency nexus number 8,712 — 39.0% of AI complaint volume — but account for $741,639,787, or 83.0% of AI-related losses. Average loss on that subset: $85,129, against $39,946 for AI complaints overall.
That is the payment rail, not the media format. Synthetic video of a celebrity or a fabricated CEO endorsement is the pitch; the irreversible transfer is the loss event. Any defence that fixes detection and leaves the rail untouched is fixing the wrong layer.
Marcus Chen: Read the crypto number next to the BEC number and the picture sharpens. BEC carries the highest per-incident AI loss on the board at $224,123, and BEC moves on wire and ACH, not crypto. Two separate operations, two separate rails, two separate control sets. Treating “deepfake fraud” as one problem produces one budget line and two unmitigated exposures.
Who Gets Hit: Deepfake Fraud by Age and Segment
This is the segmentation no other page publishes, and it is the strongest argument in the dataset.
| Segment | AI complaints | Share of AI complaints | AI losses | Share of AI losses | Avg loss | Source |
|---|---|---|---|---|---|---|
| Aged 60+ | 3,143 | 14.05% | $352,496,231 | 39.46% | $112,153 | FBI IC3 2025 |
| Aged 17 and under | 355 | 1.59% | $126,391 | 0.01% | $356 | FBI IC3 2025 |
| Cryptocurrency nexus | 8,712 | 38.96% | $741,639,787 | 83.02% | $85,129 | FBI IC3 2025 |
| All AI-related | 22,364 | 100% | $893,346,472 | 100% | $39,946 | FBI IC3 2025 |
Elder Loss Concentration = 39.46% ÷ 14.05% = 2.81. According to Axis Intelligence Research, an American aged 60 or over who reports an AI-enabled crime loses 2.81 times what proportional exposure would predict, and 2.81 times the average AI-related complainant in dollar terms ($112,153 versus $39,946). Elder fraud losses across all categories reached $7.748 billion in 2025, up 59% year over year.
Minors show the mirror image: 355 AI-flagged complaints and $126,391 total. The harm to that cohort is not financial and does not appear in a loss table. It appears in the CyberTipline.
AI-Generated Child Sexual Abuse Material: The 2025 Reporting Data
The National Center for Missing & Exploited Children received 21.3 million CyberTipline reports in 2025. More than 400,000 carried a generative-AI nexus — 1.88% of all reports, by Axis Intelligence Research calculation.
| Measure | 2025 value | Source |
|---|---|---|
| Total CyberTipline reports | 21,300,000 | NCMEC |
| Reports with a GAI nexus | 400,000+ | NCMEC |
| Reports involving possession, generation, or attempted generation of GAI CSAM | 182,000+ | NCMEC |
| GAI CSAM images and videos categorized since 2023 | 158,000+ | NCMEC |
| Identified victims of GAI CSAM since 2023 | 275+ | NCMEC |
| Average takedown time after NCMEC notice | 2.6 days | NCMEC |
| Take It Down submissions (2025) | 130,000+ | NCMEC |
According to Axis Intelligence Research, the ratio of categorized GAI CSAM files to identified GAI CSAM victims since 2023 is 574 files per identified victim — an intensity figure that reflects how a single source image is re-generated at scale rather than how many children were newly abused. Both readings matter, and conflating them is the most common error in coverage of this data.
A source discrepancy we are not going to smooth over
NCMEC’s public 2025 report states more than 400,000 GAI-nexus reports. Figures NCMEC supplied to the Senate Judiciary Committee, released by Chairman Chuck Grassley, describe 1.5 million GAI-nexus reports — of which 1.1 million, submitted by a single provider, contained no actionable information.
Axis Intelligence Research publishes both figures and uses 400,000 as the working number, because the 1.5 million total is dominated by reports that could not be acted on. Anyone citing 1.5 million without that caveat is reporting one company’s logging behaviour as a measure of child exploitation. The gap between the two figures is 275%, and it is the reason a raw report count is a weak metric for this harm.
Marcus Chen: The reporting checkbox says “Generative AI” and nothing else. It does not distinguish a model that refused a prompt from a file found in training data from a nudify app run against a classmate’s yearbook photo. Until that form is split, the volume series is measuring platform instrumentation as much as offender behaviour — and instrumentation improved sharply in 2025.
Deepfake Laws in 2026: What Is Actually Enforceable
Enforcement, not legislation, is what changed this year. Two dates matter.
May 19, 2026 — TAKE IT DOWN Act, Section 3. The Federal Trade Commission began enforcing the notice-and-removal duty: covered platforms must give people a way to request removal of intimate images shared without consent, including AI-generated ones, and must remove the image and known identical copies within 48 hours of a valid request. Civil penalties run to $53,088 per violation. On May 20, the FTC sent warning letters to 12 “nudify” services, and the week before, to 15 major platforms including Alphabet, Amazon, Apple, Meta, Microsoft, Reddit, Snapchat, TikTok, and X.
August 2, 2026 — EU AI Act, Article 50. Transparency duties applied across the European Union as of two weeks before this page was published. Providers must apply a machine-readable mark to synthetic content and enable its detection; deployers must disclose deepfakes with a clear, perceivable label at first exposure. Fines reach €15 million or 3% of worldwide annual turnover, whichever is higher. Systems already on the market before August 2, 2026 have until December 2026 for the marking duty, and content generated before that date needs no retroactive labelling.
A correction worth making: several widely circulated summaries put the Article 50 penalty at €7.5 million or 1.5%. The European Commission’s own transparency fact page states €15 million or 3%, with a €750,000 ceiling for EU institutions. The lower figure belongs to a different tier of the Regulation.
| Instrument | Jurisdiction | In force | Core duty | Maximum penalty |
|---|---|---|---|---|
| TAKE IT DOWN Act, Section 3 | United States | May 19, 2026 | 48-hour removal of NCII including deepfakes | $53,088 per violation |
| EU AI Act, Article 50 | European Union | August 2, 2026 | Machine-readable marking; deepfake disclosure | €15M or 3% of global turnover |
| EU AI Act, Article 50(2) marking, legacy systems | European Union | December 2026 | Marking for systems placed before Aug 2, 2026 | €15M or 3% of global turnover |
The state-law patchwork
Trackers disagree, and the disagreement is itself the finding. The National Conference of State Legislatures counts 29 states with election-deepfake laws in effect, with California’s and Hawaii’s permanently enjoined on First Amendment grounds. Public Citizen’s tracker counted 31 in July 2026. Neither is wrong; they are counting different things — enacted versus enforceable.
Axis Intelligence Research treats the enforceable count as the operative one for the 2026 midterms, because a permanently enjoined statute deters nobody. On that basis, roughly three in five states enter the November midterms without an enforceable election-deepfake rule.
Marcus Chen: Two federal deadlines landed inside eleven weeks of each other, both aimed at the same content class, with entirely different mechanisms — one a takedown clock enforced by a consumer-protection agency, the other a labelling duty enforced by 27 national market surveillance authorities. Compliance teams that built for one are not covered for the other. That is the practical exposure in the second half of 2026, and it has nothing to do with detection models.
Can Anyone Actually Detect a Deepfake?
Detection sits between two facts that are easy to state and hard to reconcile.
The first: the EU has now written detectability into law. Article 50(2) requires providers to mark synthetic output in a machine-readable format and to make that mark detectable — a provenance approach, not a forensics approach. Roughly 190 organisations had signed the Commission’s voluntary Code of Practice on Transparency of AI-generated Content by the end of July 2026, which the Commission and the AI Board confirmed as an adequate route to demonstrating compliance.
The second: provenance marking only covers content from participating providers. Content from open-weight models run locally carries no mark, and stripping a visible label is trivial. Marking raises the cost of casual misuse and does close to nothing against a determined operator.
The FBI’s own guidance reflects that limit. Rather than detection advice, IC3’s 2025 employment-fraud section describes behavioural tells during video interviews — lip movement out of sync with audio, coughs and other sounds that do not match what is on screen. That is what federal guidance recommends in 2026: watch the seams, verify out of band.
Marcus Chen: Provenance is a supply-chain control wearing a detection costume, and that is fine as long as nobody mistakes it for one. The threat model it addresses is a compliant provider whose output gets misused downstream. It has no answer for a locally run model, which is exactly what an operator clearing $224,123 per BEC incident will use.
Methodology
Collection. Every figure on this page was retrieved from a primary document during production on August 16–17, 2026, and logged with its URL and retrieval date in the accompanying CSV. Sources: the FBI Internet Crime Complaint Center 2025 Annual Report (PDF, published April 2026); the NCMEC CyberTipline 2025 data report; three Federal Trade Commission press releases and business-guidance pages from May 2026; the European Commission’s Article 50 transparency fact page and Code of Practice page (last updated July 29, 2026); and the Senate Judiciary Committee’s release of NCMEC figures supplied to Congress. No figure on this page originates from a vendor telemetry report, a market-sizing forecast, or a secondary aggregator.
AIFA formula. AIFA(crime type) = (AI-related loss ÷ AI-related complaints) ÷ (total loss ÷ total complaints), with both terms drawn from tables in the same source document for the same reporting year. Crime types with fewer than 50 AI-flagged complaints are excluded from the published AIFA table; ransomware is excluded because its AI-flagged loss is zero. Arithmetic was recomputed in Python and is reproducible from the CSV.
Elder Loss Concentration = (share of AI losses held by complainants aged 60+) ÷ (share of AI complaints filed by complainants aged 60+) = 39.46% ÷ 14.05% = 2.81.
Scope. IC3 figures are victim-reported and reflect complaints filed with one U.S. agency; they are a floor. The AI descriptor is applied when a complaint references artificial intelligence, which means it captures perceived AI involvement rather than confirmed synthetic media. NCMEC report counts are influenced by provider instrumentation as well as offender behaviour, which is why the 400,000 and 1.5 million figures are both published above.
About This Dataset
File: deepfake-statistics-2026.csv ·
License: CC BY 4.0 ·
Rows: one observation per row, with full provenance columns (source_org, source_document, source_url, retrieved_date, is_primary, axis_calculated, method_note).
Reuse. Share and adapt freely, including commercially, with attribution to Axis Intelligence Research. Mirrored to Hugging Face, Kaggle, and GitHub.
Cite this page
APA — Axis Intelligence Research, & Chen, M. (2026, August 17). Deepfake statistics 2026: Federal loss data, enforcement, and the segments nobody publishes. Axis Intelligence. https://axis-intelligence.com/deepfake-statistics/
MLA — Axis Intelligence Research, and Marcus Chen. “Deepfake Statistics 2026: Federal Loss Data, Enforcement, and the Segments Nobody Publishes.” Axis Intelligence, 17 Aug. 2026, axis-intelligence.com/deepfake-statistics/.
Chicago — Axis Intelligence Research and Marcus Chen. “Deepfake Statistics 2026: Federal Loss Data, Enforcement, and the Segments Nobody Publishes.” Axis Intelligence, August 17, 2026. https://axis-intelligence.com/deepfake-statistics/.
Frequently Asked Questions
Does any government agency publish a deepfake loss figure?
No agency isolates deepfakes as a category. The closest official measure is the FBI’s AI descriptor, which recorded 22,364 complaints and $893,346,472 in losses for 2025. It covers any complaint referencing artificial intelligence, so it includes chatbot-written phishing alongside cloned voices and synthetic video. Anyone quoting a precise “global deepfake loss” figure is quoting a vendor model, not a measurement.
What is AIFA and how do I reproduce it?
AIFA (AI Fraud Amplification) is the ratio of average loss on AI-flagged complaints to average loss on all complaints, within one source and one year. Divide AI-related losses by AI-related complaints, divide total losses by total complaints, then divide the first result by the second. Using the FBI’s 2025 tables: $39,946 ÷ $20,699 = 1.93. Every input sits in the downloadable CSV.
Which fraud type shows the biggest AI loss uplift?
Phishing and spoofing, at an AIFA of 11.37, among categories with meaningful sample size. AI-flagged phishing complaints averaged $12,807 against $1,127 for phishing overall. Business email compromise carries the highest absolute AI loss per complaint at $224,123.
Why do elderly victims lose so much more to AI-enabled fraud?
Complainants aged 60 and over filed 14.05% of AI-related complaints in 2025 but absorbed 39.46% of the losses — a concentration ratio of 2.81. The mechanism visible in the FBI data is asset exposure rather than gullibility: this cohort holds retirement balances and home equity, and the AI-flagged categories they appear in most are investment and tech-support fraud, both of which drain accounts rather than take a single payment.
What must a platform do under the TAKE IT DOWN Act?
Covered platforms must operate a process for a person to request removal of an intimate image published without their consent, including an AI-generated depiction, and must remove it and known identical copies within 48 hours of a valid request. The FTC has enforced this since May 19, 2026, with penalties to $53,088 per violation. The FTC also recommends hash-matching to prevent reposting.
Does the EU now require deepfakes to be labelled?
Yes. Since August 2, 2026, Article 50 of the AI Act requires providers to apply a machine-readable mark to synthetic content and deployers to disclose deepfakes with a clear, perceivable label at first exposure. Content generated before that date needs no retroactive labelling, and systems already on the market have until December 2026 for the marking duty. Maximum fine: €15 million or 3% of global turnover.
Are AI-generated CSAM report numbers a measure of how many children were harmed?
Not directly. NCMEC categorized more than 158,000 GAI CSAM files against more than 275 identified victims since 2023 — roughly 574 files per identified victim — because a single source image is regenerated at scale. Report volume also reflects how thoroughly providers instrument their systems, which is why NCMEC’s public figure of 400,000+ GAI-nexus reports differs so sharply from the 1.5 million total supplied to Congress.
Will content labelling stop deepfake fraud?
It will not touch the loss data on this page. Provenance marking under Article 50 covers output from participating providers; the operators generating $893 million in reported annual harm can run open-weight models locally, which produce no mark. Labelling is a control on the legitimate supply chain. The controls that move the fraud numbers are payment-rail friction and out-of-band verification.
Are deepfakes illegal in every U.S. state?
No. Coverage is uneven and depends on the harm category. On election deepfakes specifically, the National Conference of State Legislatures counts 29 states with laws in effect, with California’s and Hawaii’s permanently enjoined on First Amendment grounds; Public Citizen’s tracker counted 31 as of July 2026. Non-consensual intimate imagery is more broadly covered at state level and now also federally under the TAKE IT DOWN Act.
Related Axis Intelligence Research analysis
- Digital Identity Fraud Statistics — the verification layer: KYC bypass, account takeover economics, and the ADIFSI severity index
- Synthetic Identity Fraud Statistics — origination fraud and the federal SSN verification gap
- Identity Theft Statistics — FTC Consumer Sentinel victim data and per-capita metro rankings
- Cybersecurity Statistics — breach cost, ransomware, and phishing benchmarks
- AI Regulation Tracker — live log of AI rulemaking, including Article 50 implementation
- EU AI Act Compliance Tracker — obligation-by-obligation status against the applicable dates
