Deepfakes are a type of synthetic AI-generated media created by deep learning, which have become increasingly difficult to detect both by the human eye and by existing detection technologies. This has significantly increased privacy, cybersecurity and identity theft risks at an individual, enterprise and state level. This article discusses the key challenges posed by deepfakes to privacy and considers some of the current proposed legislative responses to it in Australia and the European Union (EU). It suggests a possible way forward using a “non-synthetic” model of media authentication and urges that any regulation on the use of these technologies and any consequent deepfakes must be fit for purpose.