New Zealand’s Parliament has done something rare: agreed on something. The Deepfake Digital Harm and Exploitation Bill passed its first reading with unanimous support from National, Labour, the Greens, NZ First, ACT, and Te Pāti Māori. The bill criminalises creating, sharing, or selling sexually explicit deepfakes of a person without their consent.
The member’s bill, put forward by ACT MP Laura McClure, was drawn from the ballot in October last year. It amends both the Crimes Act and the Harmful Digital Communications Act by expanding the definition of “intimate visual recording” to include images that are “created, synthesised, or altered” — closing a legal gap where existing law was designed for covert filming, not fabrication.
What the Bill Actually Does
Until now, New Zealand’s law around image-based sexual abuse was built for a world of hidden cameras and stolen recordings. The concept of an “intimate visual recording” dates to the early 2000s, when Parliament was responding to upskirting in bathrooms and changing rooms. The framework hinged on whether someone was secretly recorded.
Deepfakes break that framework. No recording occurred. The image is entirely fabricated. As University of Canterbury law lecturer Cassandra Mudgway explains in The Conversation, current law is “clearer when an intimate image is real than when it is entirely fabricated.”
The bill fixes this by making the definition technology-neutral. Whether the image was a real photo, a manipulated photo, or generated from a text prompt, the offence applies equally. It also targets material that depicts a real, identifiable person — not satire, not art, not legitimate AI use.
Justice Minister Paul Goldsmith told Parliament the government had “zero tolerance for this kind of harassment of individuals, particularly women, who are clearly far more likely to be the victims of this sort of, what will become, a crime.”
The Grok Backdrop
The bill arrives against a specific backdrop. Elon Musk’s Grok AI chatbot on X was used to digitally undress women and girls, generating what prosecutors suspect could be up to three million sexualised images. A widely cited study found 98 per cent of deepfake videos online are pornographic and overwhelmingly target women.
ACT MP Laura McClure said she was moved to act after being approached by two young women who had been deepfaked. “I do think that some of the young guys, when they are deepfaking somebody else in their class, they probably think it’s a bit of a laugh,” she told Parliament. “But it’s actually really serious. And I want to say to them that it’s so serious, that every single party in this Parliament says that it should be illegal.”
Why Criminalisation Alone Probably Won’t Be Enough
Here’s where the consensus gets more complicated. Mudgway’s analysis — and the select committee inquiry into online harm toward young people — both point to the same uncomfortable conclusion: criminal law is reactive, not preventive.
The tools to create deepfakes are cheap, fast, and easy to access. A Tech Transparency Project investigation identified dozens of “nudify” and face-swap apps available through both the Apple and Google app stores, many disguised as image-editing apps despite policies prohibiting sexually explicit content. Criminalising the user who creates a deepfake doesn’t remove the app that made it possible.
The parliamentary inquiry into online harm, which reported earlier this month, recommended a broader package: banning nudify apps entirely, establishing an independent national regulator for online safety, introducing age restrictions for social media platforms, and regulating algorithmic recommendation systems. Labour MP Phil Twyford noted the significance of National and Labour agreeing on “the need for a legislative overhaul of what is currently a patchy, outdated regulatory framework.”
New Zealand is not alone in reaching this point. The UK, Australia, South Korea, and the United States have all introduced or expanded laws to criminalise non-consensual deepfakes. Minnesota became the first US state to ban AI nudification apps outright, with fines up to $500K per violation. The EU’s Article 50 transparency rules, which took effect on August 2, require deepfakes to be labelled as AI-generated. New York has targeted AI deepfakes in school harassment specifically.
What Happens Next
The bill now goes to the Social Services Committee for consideration and public submissions. That process typically takes several months. If it passes its second and third readings, the changes would take effect on a date set by the Governor-General.
The harder question is whether Parliament will go further. The select committee inquiry already recommended banning nudify apps and establishing a regulator — both of which would address the supply side rather than just punishing individuals after the fact. Australia is moving to ban nudification apps. The UK and EU are heading the same direction.
As Mudgway puts it: “If New Zealand wants to meaningfully address image-based sexual abuse in the age of generative AI, criminal law cannot be the end of the conversation.”
The unanimous first reading shows Parliament agrees there’s a problem. What comes next — app bans, a regulator, platform obligations — is where the real debate begins.
📰 Sources
- RNZ — Deepfake bill passes first reading in Parliament
- RNZ — NZ is criminalising sexualised deepfakes
- The Conversation — NZ is criminalising sexualised deepfakes: banning apps that make them should be next
- RNZ — Most parties find common ground against ‘digital robber barons’
- ACT Party — Deepfake Bill passes first reading