Mintz Says AI Voice Clones Could Face Existing U.S. Identity-Fraud Law

A new legal analysis argues that the White House’s AI-crime enforcement order may give prosecutors a route to pursue misuse of voiceprints, account credentials and other authentication tools without a new AI-specific statute.

By 3 min read
Mintz Says AI Voice Clones Could Face Existing U.S. Identity-Fraud Law
Mintz Says AI Voice Clones Could Face Existing U.S. Identity-Fraud Law

Listen to this story

The audio brief

About 1:34
0:001:34
Read transcript
A cloned voice used to defeat an account check could potentially be pursued under an existing federal identity-fraud law, according to a new analysis from Mintz. The argument is not that Congress has created a new AI crime. The practical change is enforcement priority. Executive Order 14,409, issued June 2, tells the attorney general to focus on AI-enabled cases under three existing statutes: Title 18, Section 1028, covering identity and authentication fraud; Section 1030, covering unauthorized access to protected computers; and Section 1343, the federal wire-fraud law. Mintz focuses on Section 1028 because its definition of a “means of identification” may reach more than physical IDs. The analysis says it could include voiceprints and unique electronic identifiers. So, if a fraud operation uses a clone of someone’s voice as an authentication tool to obtain money, prosecutors might have a path under that statute. That remains a legal theory, not a disclosed prosecution or court ruling. The harder question involves autonomous AI systems. If an agent uses supplied credentials or follows prompts to enter a computer without authorization, investigators may need to show what a person configured, provided, or directed. Company forensic records could become important evidence—not just of what happened technically, but of who enabled it. The key constraint is that the order prioritizes enforcement; it does not settle how broadly these laws apply. The next test is whether prosecutors and courts connect an AI system’s actions to the human behind it.

Story brief

3 key points

The practical change is prosecutorial prioritization, not a new AI crime. Executive Order 14,409, issued June 2, directs attention to AI-related cases under three existing statutes, while Mintz highlights 18 U.S.C. §1028 as a possible route for pursuing cloned-voice authentication fraud. The analysis also points to a liability gap when autonomous systems perform unauthorized access: investigators may need evidence...

  1. 01

    Executive Order 14,409 names §§1028, 1030 and 1343 for AI-enabled identity fraud, computer access and wire fraud cases.

  2. 02

    Mintz reads §1028’s “means of identification” language as potentially covering voiceprints and unique electronic identifiers.

  3. 03

    The order prioritizes enforcement; it does not establish a new AI offense or settle how broadly the statutes apply.

A new Mintz legal analysis argues that AI-generated voice clones used to defeat authentication could potentially be prosecuted under an existing federal identity-fraud law. Its significance is less a new crime than a new enforcement emphasis: Executive Order 14,409 tells the attorney general to prioritize cases involving AI-enabled unauthorized computer access and related offenses.

The June 2 order names three existing statutes: identity and authentication fraud under 18 U.S.C. §1028, unauthorized access to protected computers under §1030, and wire fraud under §1343. It expressly covers people who use AI to illegally access or damage computers, as well as AI agents used to obtain data later used for a criminal or unlawful purpose.

That wording does not create a new AI offense. It directs prosecutorial attention to conduct already covered by federal law. Mintz’s analysis, published Tuesday, focuses on §1028 because its definitions reach beyond familiar physical IDs to several forms of digital and biometric identity.

Why authentication is the focal point

Section 1028 covers “means of identification,” which the analysis says include voiceprints and unique electronic identification numbers, addresses and routing codes. That makes a cloned voice more than a generic impersonation problem in the authors’ reading: if it is used as an authentication mechanism to obtain funds through fraud, it could potentially support a §1028 prosecution.

The scenarios Mintz identifies

  • A voice-based fraud operation using a real person’s voiceprint as part of its authentication method.
  • An autonomous AI system given account credentials or directed with prompts to gain unauthorized access.
  • Potentially, fraudulent use of certain internet security credentials, though the analysis says that would require further factual and legal development.

The analysis identifies a practical issue in autonomous attacks: the Computer Fraud and Abuse Act is written around a person accessing a computer without authorization. Where an AI system performs the access, proving the human actor’s role may be harder. Mintz argues that supplying credentials to the system or directing it through prompts could provide a possible §1028 route to the people behind the attack.

The order is a prioritization directive, not a ruling on how far each statute reaches. Mintz’s voice-clone and credential examples are legal interpretations of potential applications, not disclosed prosecutions or settled judicial outcomes. Its discussion of DNSSEC keys issued by ICANN similarly presents a possible §1028 question, contingent on additional facts and legal analysis.

For companies responding to an AI-enabled intrusion, the analysis suggests that a full investigation can do more than establish technical cause. The record may help determine whether stolen credentials, cloned biometric identifiers or instructions to an agent create evidence relevant to law-enforcement cooperation. The unanswered question is how prosecutors and courts will draw the line between an AI tool’s actions and the person who configured or directed it.

Sources

  1. whitehouse.govPromoting Advanced Artificial Intelligence Innovation and Security
  2. jdsupra.comAI Authentication Management: Enforcement Prioritization In Executive Order 14,409, “Promoting Advanced Artificial Intelligence and Security” | JD Supra

Loading discussion...