RegImpact
ftcproposed· Published 3/1/2024

Trade Regulation Rule on Impersonation of Government and Businesses

The Federal Trade Commission (FTC or Commission) requests public comment on its proposal to amend the trade regulation rule entitled Rule on Impersonation of Government and Businesses (Impersonation Rule or Rule) to revise the title of the Rule, add a prohibition on the impersonation of individuals, and extend liability for violations of the Rule to parties who provide goods and services with knowledge or reason to know that those goods or services will be used in impersonations of the kind that are themselves unlawful under the Rule. The Commission believes these changes are necessary and such impersonation is prevalent, based on all comments it received on the Rule and other information discussed in this document. The Commission now solicits written comment, data, and arguments concerning the utility and scope of the proposed revisions to the Impersonation Rule.

What this rule actually says

The FTC is proposing to ban impersonating government officials, businesses, *and individuals* using AI or other tools. More specifically, it's targeting anyone who *helps* someone else impersonate these entities—like selling a voice cloning API knowing it'll be used to fake someone's voice in a scam call, or providing infrastructure for deepfake impersonation. The rule treats "I didn't know what they'd do with it" as no defense if there was obvious reason to know.

Who it applies to

  • If you're building in these use cases, pay attention:
  • Voice cloning, voice synthesis, or avatar/video generation tools (highest risk)
  • Any tool that mimics how someone communicates (writing style, email templates, chatbots that impersonate specific people)
  • Anything that could generate government seals, official letterhead, or business branding
  • If you're building these, you're probably fine:
  • Medical scribes (documenting real doctor-patient conversations)
  • Generic hiring assistants or support chatbots (they shouldn't pretend to be a specific person or company)
  • Productivity tools that don't involve mimicking identity
  • Jurisdictions: This is FTC, so it applies nationwide in the US. If you have international users, this doesn't directly apply outside the US, but courts in other countries are watching FTC precedent.
  • Data scope: The rule doesn't require you to collect user data or monitor what customers do (yet). It just says if you have "knowledge or reason to know" the tool will be misused for impersonation, you can't provide it.

What founders need to do

  1. Audit your product (2-3 days). Does it create realistic audio, video, text, or images that could convincingly impersonate a real person or official? If yes, it's in scope.
  1. Add terms of service language (1 day). Explicitly prohibit users from impersonating government, businesses, or real individuals. This alone doesn't shield you legally, but it's the baseline.
  1. Think about friction (ongoing). For high-risk tools (voice cloning, video synthesis), consider requiring ID verification or explicit consent from the person being mimicked, especially if they're a public figure or official.
  1. Monitor enforcement signals (ongoing). This is still proposed, not final. Watch for FTC guidance or settlements over the next 12-24 months to see what "reason to know" actually means in practice.
  1. Document your intent (1-2 days). If a user asks you to help them impersonate someone, say no and keep a record. Don't be willfully blind.

Bottom line

Monitor and add basic guardrails now—this rule is coming regardless, and it's broad enough to catch founders building legitimate tools if they ignore obvious red flags.