Regulatory Spotlight 2024–2026: New US, EU & INTERPOL Guidance on Deepfakes and National Anti‑Scam Centers
Introduction — Why 2024–2026 Matters for Consumers
Between 2024 and 2026 regulators and international policing bodies issued a wave of guidance, rulemaking and operational toolkits targeting AI‑enabled impersonation (deepfakes and voice cloning), mass robocalls and coordinated scam networks. These developments aim to reduce upstream abuse (blocking supply), require platform and industry transparency, and help governments stand up national anti‑scam centers to coordinate response and victim support.
Key takeaways in this article: what regulators have done, how enforcement and platform rules are changing, what national anti‑scam centers are, and concrete steps consumers should take today to reduce risk and report incidents.
Regulatory & Law‑Enforcement Developments (US, EU, INTERPOL)
United States — FCC, FTC and rulemaking to curb AI voices and robocalls
The Federal Communications Commission moved to make certain uses of AI‑generated voices in robocalls illegal, reflecting a tougher posture toward synthetic‑voice scams.
The Federal Trade Commission has prioritized upstream, tech‑driven approaches for voice cloning and synthetic‑media scams, running challenges and publishing recommendations on detection and prevention while continuing civil enforcement of deceptive telemarketing and impersonation practices.
European Union — AI Act, Digital Services Act and transparency rules
The EU’s package of AI and platform rules (notably the AI Act and the Digital Services Act) explicitly addresses AI‑generated or manipulated audio, image and video that can mislead users and includes transparency obligations and measures to help platforms identify and act on synthetic media. The AI Act defines deepfakes and establishes disclosure and risk‑management duties for providers and deployers of relevant systems.
INTERPOL — operational guidance and national anti‑scam center playbooks
INTERPOL has published analysis and operational materials on synthetic media, issued alerts (including Purple Notices on impersonation risks), and in 2024–2026 expanded programs (e.g., Project SynthWave and SynthWave PLUS) to help member countries detect, investigate and respond to deepfake‑enabled crimes. INTERPOL and the UN/global forums have also promoted guidance for establishing national anti‑scam centers to centralize reporting, intelligence sharing and victim support.
What this combination means in practice
- Regulators are focusing on upstream controls (blocking or labeling synthetic media at the source) and on making platforms and service providers take more responsibility for detection and remediation.
- Law enforcement is investing in tooling and cross‑border operations to trace fraud rings that use AI to scale vishing, smishing and spoofing.
- National anti‑scam centers are being recommended as best practice to consolidate victim reporting, triage fraud, and feed intelligence back to carriers, platforms and international partners.
Practical consumer guidance — What you must know and do now
Regulatory momentum does not eliminate risk overnight. While governments and platforms build defenses, consumers should take simple, high‑impact steps to reduce vulnerability to deepfake vishing/robocalls, smishing and caller‑ID spoofing:
- Assume caution with unexpected requests for money or data. Never transfer funds or provide login codes after an unsolicited call or text, even if the voice sounds like a known person.
- Verify independently. Hang up and call a trusted number (from your contact list or the organization’s official website) — do not use numbers provided in the suspect message.
- Enable stronger authentication and carrier protections. Use passkeys or authenticator apps where possible, and ask your mobile carrier for port‑freeze / SIM‑transfer locks to reduce SIM‑swap risk.
- Preserve evidence. Keep call‑recordings, screenshots of text messages, timestamps and any transaction details to help investigators and banks/markets reverse fraud.
- Report quickly and to the right places. In the US, report robocalls and caller‑ID spoofing to the FTC (DoNotCall.gov) and, when applicable, to the FBI’s Internet Crime Complaint Center (IC3); follow your national anti‑scam center’s reporting guidance where available.
If you encounter AI‑generated audio or a convincing impersonation, preserve the file and metadata (where possible) and report it to platform support and to authorities — this helps platforms improve detection and supports cross‑border investigations.
Reporting pathways, what to expect, and realistic timelines
Where you report matters. Platforms can remove content, banks can freeze scams in some cases, and regulators may use reports to build cases and policy. Expect these timelines:
| Action | Who to contact | Typical outcome/timeline |
|---|---|---|
| Immediate financial loss | Your bank + local police (+ IC3 in the US) | Bank may freeze/rollback within days; law enforcement investigations vary (weeks–months) |
| Robocall or spoofed number | FTC complaint (DoNotCall.gov) and carrier | FTC uses reports for enforcement and industry initiatives; carriers may block or trace calls (days–weeks). |
| Deepfake audio/video used for extortion or impersonation | Platform takedown request + national anti‑scam center or police | Platforms may remove content quickly; cross‑border policing coordination and forensic analysis can take longer (weeks–months). |
Governments are building centralized reporting through national anti‑scam centers to shorten triage and speed feedback to carriers and platforms; check whether your country has announced such a center and use it as the primary reporting hub.
Looking ahead — what to expect from regulators and platforms
- Expect more upstream obligations on AI providers and platform transparency (labels, provenance metadata, and requirements to disclose synthetic content). The EU’s framework already mandates disclosure rules for certain high‑risk AI systems and the DSA is increasing platform accountability.
- Carriers and VoIP providers will face stronger pressure (and rulemaking) to adopt call‑authenticity measures and new branding/labeling proposals have been under consultation to help consumers know if a call originates abroad.
- International policing cooperation (INTERPOL) will keep expanding toolkits, exercises and operational projects to trace and disrupt cross‑border fraud networks that use synthetic media at scale.
For consumers: updates in regulation are promising but slow — the best defense remains skepticism, strong account hygiene and quick reporting.
If you want a short checklist to share:
- Stop: don’t act on an unsolicited request for money or authentication codes.
- Verify: call a known number, not the one in the message.
- Lock: enable passkeys/authenticator and carrier transfer locks.
- Report: file complaints with the platform, your carrier, and national reporting centers (FTC/DoNotCall.gov in the US; use local anti‑scam centers elsewhere).
Questions about specifics in your country? Check your national anti‑scam center page (if one exists) and your telecommunications regulator for STIR/SHAKEN or call‑authenticity updates.
Sources referenced in this article include FCC and US regulatory notices on AI voices and robocalls, FTC research and enforcement summaries, the EU AI and DSA framework materials, and INTERPOL operational reports and guidance (2024–2026).
