Mintz Says AI Voice Clones Could Face Existing U.S. Identity-Fraud Law
A new legal analysis argues that the White House’s AI-crime enforcement order may give prosecutors a route to pursue misuse of voiceprints, account credentials and other authentication tools without a new AI-specific statute.
Listen to this story
The audio brief
Story brief
3 key pointsThe practical change is prosecutorial prioritization, not a new AI crime. Executive Order 14,409, issued June 2, directs attention to AI-related cases under three existing statutes, while Mintz highlights 18 U.S.C. §1028 as a possible route for pursuing cloned-voice authentication fraud. The analysis also points to a liability gap when autonomous systems perform unauthorized access: investigators may need evidence...
- 01
Executive Order 14,409 names §§1028, 1030 and 1343 for AI-enabled identity fraud, computer access and wire fraud cases.
- 02
Mintz reads §1028’s “means of identification” language as potentially covering voiceprints and unique electronic identifiers.
- 03
The order prioritizes enforcement; it does not establish a new AI offense or settle how broadly the statutes apply.
A new Mintz legal analysis argues that AI-generated voice clones used to defeat authentication could potentially be prosecuted under an existing federal identity-fraud law. Its significance is less a new crime than a new enforcement emphasis: Executive Order 14,409 tells the attorney general to prioritize cases involving AI-enabled unauthorized computer access and related offenses.
The June 2 order names three existing statutes: identity and authentication fraud under 18 U.S.C. §1028, unauthorized access to protected computers under §1030, and wire fraud under §1343. It expressly covers people who use AI to illegally access or damage computers, as well as AI agents used to obtain data later used for a criminal or unlawful purpose.
That wording does not create a new AI offense. It directs prosecutorial attention to conduct already covered by federal law. Mintz’s analysis, published Tuesday, focuses on §1028 because its definitions reach beyond familiar physical IDs to several forms of digital and biometric identity.
Why authentication is the focal point
Section 1028 covers “means of identification,” which the analysis says include voiceprints and unique electronic identification numbers, addresses and routing codes. That makes a cloned voice more than a generic impersonation problem in the authors’ reading: if it is used as an authentication mechanism to obtain funds through fraud, it could potentially support a §1028 prosecution.
The scenarios Mintz identifies
- A voice-based fraud operation using a real person’s voiceprint as part of its authentication method.
- An autonomous AI system given account credentials or directed with prompts to gain unauthorized access.
- Potentially, fraudulent use of certain internet security credentials, though the analysis says that would require further factual and legal development.
The analysis identifies a practical issue in autonomous attacks: the Computer Fraud and Abuse Act is written around a person accessing a computer without authorization. Where an AI system performs the access, proving the human actor’s role may be harder. Mintz argues that supplying credentials to the system or directing it through prompts could provide a possible §1028 route to the people behind the attack.
The order is a prioritization directive, not a ruling on how far each statute reaches. Mintz’s voice-clone and credential examples are legal interpretations of potential applications, not disclosed prosecutions or settled judicial outcomes. Its discussion of DNSSEC keys issued by ICANN similarly presents a possible §1028 question, contingent on additional facts and legal analysis.
For companies responding to an AI-enabled intrusion, the analysis suggests that a full investigation can do more than establish technical cause. The record may help determine whether stolen credentials, cloned biometric identifiers or instructions to an agent create evidence relevant to law-enforcement cooperation. The unanswered question is how prosecutors and courts will draw the line between an AI tool’s actions and the person who configured or directed it.
Sources
- whitehouse.govPromoting Advanced Artificial Intelligence Innovation and Security
- jdsupra.comAI Authentication Management: Enforcement Prioritization In Executive Order 14,409, “Promoting Advanced Artificial Intelligence and Security” | JD Supra
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.