Binary Refinery
18 June 2026 Insight

The deepfake gap in New Zealand law - and the bill that closes it

If someone shares a real intimate photo of you, NZ law has your back. If someone fabricates one, the law gets hesitant. A bill closes that gap - submissions due Friday 19th June 2026

By Kat Mac

If someone shares a real intimate photo of you without your consent, New Zealand law has your back. If someone fabricates one - builds a convincing nude of you from the ordinary photos on your public profiles - the law gets unexpectedly hesitant. That gap is the subject of a bill in front of a select committee right now, and the public has until Friday to have a say on it.

Most of my work is about helping New Zealand organisations use AI well, and most of that is about opportunity. This is one of the places where the technology has plainly outrun the law. It is worth a few minutes of your attention, and, if you are willing, a short submission.

What the law does now

Two laws do the heavy lifting on non-consensual intimate imagery. The Harmful Digital Communications Act 2015 (HDCA) set up a civil complaints and takedown system, run through Netsafe, and in 2022 added a specific criminal offence - section 22A - for posting an intimate visual recording without consent. The Crimes Act 1961 (sections 216H to 216N) makes it an offence to create, possess and publish intimate visual recordings.

Both hinge on one defined term: "intimate visual recording". And that definition was written for a world of hidden cameras and real events - someone filmed in a changing room, an image captured without consent. It assumes a recording was made of a real person in a real situation.

A deepfake is not that. Nothing was recorded. The image is generated. Which leaves a determined defendant a genuine argument: "I did not record anything. I created a synthetic image." The protection that clearly covers a leaked real photo does not clearly reach a fabricated one - even though, to the person it happens to, the distinction is meaningless. The humiliation, the loss of control, the damage to reputation and relationships are identical.

Why this matters now

This is not a hypothetical tidied up for a law lecture. Netsafe reported a sharp rise in sextortion - 667 reports in the first quarter of 2025, up 68% on the year before, the youngest victim aged nine. Those figures cover sextortion broadly, not deepfakes alone, but AI tools are increasingly part of the picture, for a simple reason: a perpetrator no longer needs a real intimate image. Any public photo will do. In May 2026, New Zealand saw its first sentencing for creating and sharing deepfake pornography. The tools are free, fast, and require no skill to use.

What the bill does

The Deepfake Digital Harm and Exploitation Bill, a member's bill from ACT's Laura McClure, takes the economical route. Rather than building a new regime, it amends the definition of "intimate visual recording" in both the Crimes Act and the HDCA to include images that have been created, synthesised or altered without consent. The effect is that the offences and protections that already exist apply to deepfakes exactly as they do to real images.

It is a small change with a large reach, and it has broad support - it passed its first reading with every party behind it. Binary Refinery has made a submission backing it, and I would encourage you to as well. Here is what we said, and why.

Where the bill could be stronger

Supporting a bill does not mean staying silent on its detail. The select committee stage is exactly where the wording gets tightened, so a few points are worth raising.

Make "recognisable" clear. The bill turns on whether an image "appears to show the person". That is the right idea, but it raises an obvious question: how recognisable does the person have to be, and to whom? Pin it down - for instance, whether a reasonable person who knows the individual would recognise them - and you avoid two failures: the perpetrator who claims "that is not really her, just a resemblance", and an overly narrow test that lets obvious harm through.

Treat scale as an aggravating factor. Both creating this material and spreading it cause harm. The wider it spreads, the worse the damage. Courts can already weigh that at sentencing, but naming the scale of distribution - mass sharing, sharing for profit, sharing through a commercial "nudify" service - as an express aggravating factor would make sure the worst offending is treated consistently. It targets the most serious behaviour without raising every penalty across the board.

Keep children in the strongest regime. Sexual images of children, including computer-generated ones, are already treated as objectionable publications under the Films, Videos, and Publications Classification Act 1993, which carries far heavier penalties. Prosecutors will charge the most serious offence available, so this is about certainty: confirm that extending the intimate-image definition does not accidentally create a lighter charge for synthetic sexual images of under-18s.

Make takedown faster. Once deepfakes count as intimate visual recordings, the HDCA's existing takedown process applies to them automatically, which is welcome. The catch is speed. A court-based process takes time, and for the person affected, the harm is the material staying up. Victims need a fast way to get this content removed, independent of any prosecution.

Protect the people who report. The person an image is sent to is often the first to know it exists. The law should make clear that someone who receives this material and is worried about it can come forward - to the person depicted, to Netsafe, or to Police - without fear of being treated as an offender. The blame belongs with those who make and spread it, not with someone who flags it.

Support the breadth, but keep any defences narrow. The new definition is deliberately broad. It does not require the person to have been in a private place, and it does not carve out wide exceptions. That is the right call. A non-consensual sexual image of a real, identifiable person is not acceptable because it is labelled satire or art. If defences are added - for legitimate journalism, say, or law enforcement - they need to be drawn tightly, so they do not become a loophole that swallows the offence.

Beyond the bill

A couple of things sit outside this bill but are worth saying, because the law on its own will not solve the problem.

The tools that mass-produce this material - the "nudify" services - sit upstream, and most are run offshore as commercial businesses. No one has a legitimate right to operate a service whose purpose is manufacturing sexual images of real people who never consented. New Zealand already runs a voluntary, ISP-level filter for child sexual abuse material - the Digital Child Exploitation Filtering System, which around 95% of internet users sit behind - and a narrowly targeted version could be pointed at these services. More effective still would be giving an agency the power to require offshore operators to comply or pull out, as Australia has done: a single enforcement action there caused a major nudify operator to block Australian users entirely. That is holding exploitative businesses to account, not policing ordinary speech.

And the most effective protection is preventing the harm in the first place. Pairing the law with education - helping young people, parents and schools understand consent, the reality of synthetic media, and where to get help - will protect more people than any penalty.

Why an AI advisory firm is weighing in

Most of my work is about helping organisations use AI well. But using a technology well also means being honest about where it causes harm, and where the rules have not caught up. This is one of those places. The same capability that drafts a marketing email or summarises a contract can fabricate a convincing nude of a real person from a handful of public photos, and right now the law is not quite sure what to call it. Closing that gap is a small, sensible fix - the kind of clear-eyed governance that should travel alongside every conversation about what AI can do.

How to submit

You do not need to be a lawyer, and you do not need to write much. A few honest sentences about why this matters is a valid submission, and it takes about ten minutes. Submissions close 11:59pm, Friday 19 June 2026. You can make one through the New Zealand Parliament website, and AI Safety Aotearoa has published a plain-English walkthrough if you would like a hand.

The bill is likely to pass. What the committee does with the detail is still open, and that is what submissions shape. If this matters to you, this week is the time to say so.

Sources: the Deepfake Digital Harm and Exploitation Bill and its explanatory note (New Zealand Parliament); Crimes Act 1961 ss 216H-216N and Harmful Digital Communications Act 2015 s 22A (New Zealand Legislation); Netsafe sextortion figures and submission guidance via AI Safety Aotearoa; Department of Internal Affairs Digital Child Exploitation Filtering System; Australian eSafety Commissioner enforcement action against nudify services (2025).

Talk to us

Have a question this raised? Let's talk.

If something here lines up with what you're working on - or pushes back against it - we'd love to hear from you.