Artificial intelligence is creating an entirely new category of defamation risk. Large language models (LLMs) like ChatGPT, Google Gemini, and Meta AI routinely generate convincing but entirely fabricated statements about real people — a phenomenon known as "hallucination." Meanwhile, deepfake technology enables the creation of realistic but fake images, audio, and video that can devastate reputations. This guide examines how UK defamation law applies to AI-generated falsehoods and what remedies are available.
The Scale of the Problem
AI hallucination is not a rare glitch — it is an inherent feature of how large language models work. LLMs predict the most statistically likely next word in a sequence. They do not verify facts. They do not distinguish between truth and fiction. When asked about a real person, they may confidently assert that the person has been convicted of fraud, struck off a professional register, or engaged in misconduct — none of which is true.
Documented cases of AI-generated defamation include:
- False criminal records: LLMs stating that named individuals have been convicted of crimes they never committed
- Fabricated professional misconduct: AI systems claiming that lawyers, doctors, or academics have been disciplined or disbarred
- Invented scandals: Chatbots generating detailed but entirely fictional accounts of sexual misconduct, fraud, or corruption
- False business information: AI attributing negative reviews, lawsuits, or regulatory actions to businesses that have a clean record
The problem is compounded by the sheer scale of AI usage. Hundreds of millions of people interact with LLMs daily. A single hallucinated falsehood can be viewed, copied, and republished countless times.
Does UK Defamation Law Apply to AI Outputs?
The Defamation Act 2013 was drafted before the AI revolution, but its core principles are technology-neutral. The critical questions are:
Is There a "Statement"?
An AI-generated response about a real person containing a false factual assertion is capable of being a defamatory statement. It does not matter that no human wrote the words. What matters is that the words were published — communicated to at least one person other than the claimant.
Is There "Publication"?
Every time an AI system displays a defamatory response to a user, that constitutes publication. Unlike a static webpage, AI outputs are generated dynamically — the same prompt may produce different results on different occasions. This creates a novel challenge: the defamatory statement may not be consistently reproducible, making evidence preservation critical.
Who Is the "Publisher"?
This is the most complex question. Potential defendants include:
- The AI company (e.g., OpenAI, Google, Meta) — as the developer and operator of the system that generated the statement
- The user — if they republished the AI's output, for example by sharing it on social media or incorporating it into a report
- A website operator — if they integrated the AI into their platform and displayed the output to users
Under common law, anyone who participates in the chain of publication may be liable. The AI company has the strongest case to answer as the primary publisher, though it may argue that it is merely a platform or processor and seek to rely on the section 5 website operator defence or analogous defences.
Need Expert Legal Advice?
Our specialist defamation solicitors offer free, confidential case evaluations. Get clarity on your legal position today.
The Serious Harm Threshold
Under section 1 of the Defamation Act 2013, a statement is not defamatory unless it has caused, or is likely to cause, serious harm to the claimant's reputation. For AI-generated defamation, this requires evidence that:
- The output was actually seen by third parties (not just the person who prompted it)
- The content was believable — AI outputs carry an air of authority that makes them particularly persuasive
- The claimant suffered, or is likely to suffer, actual reputational harm — such as lost business, damaged professional standing, or social stigma
For businesses, the threshold is higher: "serious financial loss" must be demonstrated or shown to be likely.
Deepfakes and Synthetic Media
Deepfakes — AI-generated images, audio, or video that realistically depict someone doing or saying something they never did — present a distinct but related challenge. Common scenarios include:
- Face-swap pornography: Non-consensual intimate images created using someone's likeness. This is now a specific criminal offence under the Online Safety Act 2023.
- Fabricated video statements: Deepfake videos showing a person making statements they never made — for example, admitting to misconduct or expressing extremist views.
- Fake audio recordings: AI-generated voice clones used to create fabricated conversations or admissions.
- Manipulated images: Photos altered to place someone in compromising situations.
Deepfakes that portray someone doing or saying something defamatory are actionable under both defamation law and, where applicable, the criminal law provisions of the Online Safety Act 2023 and the Malicious Communications Act 1988.
Available Legal Remedies
1. Defamation Claims Against AI Companies
A defamation claim can be brought against the AI company responsible for generating the false output. The claim would seek:
- Damages: Compensation for reputational harm and any financial losses
- An injunction: Requiring the company to implement measures preventing the system from generating the defamatory output in future
- A correction: Though the nature of dynamic AI outputs makes traditional corrections difficult, a court could order the company to implement guardrails or fine-tuning to prevent repetition
2. GDPR and Data Protection Claims
Under UK GDPR, individuals have the right to have inaccurate personal data rectified or erased. If an AI system processes and outputs false personal data, the data controller (the AI company) may be obliged to:
- Correct the training data to remove false information
- Implement output filters to prevent the false statement being generated
- Respond to a subject access request disclosing what data it holds about the individual
The Information Commissioner's Office (ICO) has indicated that AI outputs containing personal data fall within the scope of UK GDPR, and that the accuracy principle (Article 5(1)(d)) applies.
3. Online Safety Act 2023
The Online Safety Act imposes duties on platforms to protect users from illegal content, including defamatory content and non-consensual intimate images. AI-generated deepfake pornography is specifically criminalised. Platforms that integrate AI systems are subject to these duties with respect to the content their systems generate.
4. Misuse of Private Information
Where AI outputs disclose private information — whether real or fabricated but believed to be real — a claim for misuse of private information may lie alongside or instead of a defamation claim.
5. Criminal Remedies
Creating and sharing deepfake intimate images is a criminal offence. The Online Safety Act 2023 also criminalises the sharing of deepfake intimate images (even without intent to cause distress), and the Malicious Communications Act 1988 applies where content is sent with intent to cause anxiety or distress.
Practical Steps if You're a Victim
- Preserve evidence immediately. Screenshot the AI output including the prompt, timestamp, and platform. AI outputs are ephemeral — the same prompt may not reproduce the same result.
- Report to the platform. All major AI providers have content reporting mechanisms. Google, OpenAI, and Meta have specific processes for reporting factual inaccuracies about named individuals.
- Submit a GDPR correction request. Write to the AI company's data protection officer requesting rectification of inaccurate personal data under Article 16 of UK GDPR.
- Seek legal advice. AI defamation is a rapidly evolving area. Specialist legal advice is essential to navigate the intersection of defamation, data protection, and online safety law.
- Consider urgency. If the defamatory output is actively being generated and seen by users, an interim injunction may be required to compel the platform to implement immediate output filters.
The Emerging Legal Landscape
UK law is evolving rapidly to address AI-generated harms:
- The EU AI Act (which the UK is monitoring closely) imposes transparency and accuracy obligations on AI systems, particularly those classified as high-risk.
- The UK Government's AI Safety Institute is developing frameworks for evaluating AI harms, including reputational harms.
- Courts are expected to hear the first major AI defamation cases in 2026–2027, which will establish important precedents on liability, the publication requirement, and the serious harm threshold in the AI context.
- The Law Commission has been invited to consider whether existing defamation law adequately addresses AI-generated content, with a potential consultation expected in 2027.
In the meantime, the existing framework of defamation law, data protection law, and the Online Safety Act provides a robust — if imperfect — set of tools for those harmed by AI-generated falsehoods.
Related Reading
Anonymous online defamation | How to remove defamatory content | The Online Safety Act 2023 | Tech defamation hub
Free Confidential Consultation
Has online content damaged your reputation?
- No-obligation free case assessment
- UK's 1-year limitation period — act now
- Referral to specialist defamation solicitors
