Brazil's national data protection authority published a 163-page technical report on July 29, 2026, mapping how deepfakes are used to defraud consumers, manipulate elections and generate non-consensual intimate imagery, arguing that paid digital advertising has become one of the technology's most active vectors for financial harm. The document, titled "Radar Tecnológico N. 6 - Deepfakes" and issued by the Agência Nacional de Proteção de Dados (ANPD), was written by a six-person team led by Ticianne de Gois Ribeiro Darin under the agency's Superintendência de Inovação Tecnológica, according to the report.

The study carries no binding legal force. According to the report, it is framed as a technical-informative and prospective document that does not constitute normative guidance, an administrative decision or a conclusive institutional position on specific cases. Even so, it compiles enforcement figures, court cases and cross-border comparisons that give advertisers, platforms and compliance teams a working map of where liability is heading, at a moment when the European Union's own AI Act labeling regime becomes legally binding on August 2, 2026, three days after the ANPD's publication date.

A fraud pattern with a familiar shape

The report devotes a full section, numbered 5.6, to what it calls deceptive advertising through deepfakes, describing a three-step operational pattern that recurs across the Brazilian cases it documents. First, criminal groups create synthetic content using the image and voice of a public figure. Second, that content is boosted on social networks as sponsored material targeted by user profile. Third, victims are redirected to fraudulent environments, cloned websites or fake platforms, where they are asked for payments or personal data.

According to the report, one of the most consequential cases involved a criminal organization that used deepfakes of celebrities including Gisele Bundchen, Angelica, Juliette and Sabrina Sato to advertise products that did not exist. In the Bundchen case, the report states, the group sold a supposedly free anti-wrinkle kit for which victims paid only a shipping fee through Brazil's PIX instant-payment system; the product was never delivered. Police investigation found the group had moved more than R$20 million, and its members were arrested, the report says, citing a 2025 news account.

A second advertising-fraud pattern documented in the report involves the repeated manipulation of health professionals' likenesses. Physician Drauzio Varella's image and voice, the report notes, were manipulated on multiple occasions to simulate endorsements of medications and treatments without scientific backing, often presented in a format resembling interviews or news segments to borrow the credibility of journalism. The report includes an illustrative figure contrasting a fabricated account, identified as @dr.mauro_corella_tv, against the physician's genuine, verified account discussing a legitimate public-health topic.

The report characterizes the resulting harm as one defined by scale rather than size: each victim tends to lose a relatively small amount, which reduces the likelihood of a formal complaint while allowing operators to accumulate substantial aggregate profit, citing Romagna's 2025 analysis. Beyond direct financial loss, the report lists four secondary effects: risk to public health where unproven medical products are involved; damage to the credibility of professionals whose likenesses are used without consent; violations of personality rights; and exposure of personal data, since victims often submit information directly to fraudulent websites.

Financial impersonation beyond advertising

A separate section of the report, numbered 5.5, catalogs three additional Brazilian financial-fraud cases involving deepfakes that sit outside conventional advertising but illustrate the same underlying risk. One centers on a video using the image and speech of Pedro Moreira Salles, co-chairman of the board of Banco Itau, shared extensively on Facebook in 2025 and attributing false statements to the executive to promote a supposed miracle investment scheme; Itau subsequently clarified he had no connection to the material, according to the report. Another, the report says, involved a Rio Grande do Sul woman who believed she was in a virtual relationship with actor Brad Pitt, having conducted what she described as video calls with a synthetic version of the actor generated in real time; the same fraud pattern cost a woman in France more than 830,000 euros, prompting the actor's representative to issue a public warning about unauthorized use of his likeness.

A third case concerns Serasa Experian, the Brazilian credit-data company. According to May 2026 data cited in the report, roughly 83.5 million people in Brazil, close to half the adult population, carry negative credit records, while an estimated 57 million consumers hold debts they are unaware of, a population the report calls especially vulnerable to scams exploiting the Serasa name. Fraudulent content promising compensation of up to R$30,000 for a supposed 2021 data leak circulated widely, in some cases using a deepfake video of then-senator Sergio Moro, who later publicly clarified it was false. No court has yet ordered Serasa Experian to pay such compensation, the report notes, though the underlying 2021 leak, which affected roughly 223 million people, is now the subject of a class action in English courts against the Experian group.

To quantify the broader trend, the report cites the Identity Fraud Report 2025-2026 from identity-verification company Sumsub, finding Brazil accounted for approximately 39 percent of detected deepfake cases in Latin America during 2025, alongside a 126 percent increase in deepfake and synthetic-identity attacks between 2024 and 2025.

Meta, Facebook and the platforms named in the report

Several of the fraud cases the report documents were disseminated specifically through Facebook, a detail that places the ANPD's findings alongside enforcement action Meta has already taken in the same market. Meta filed multiple lawsuits on February 26, 2026 against deceptive advertisers operating in Brazil, China and Vietnam, targeting operators who used celebrity impersonation and cloaking techniques nearly identical to the pattern the ANPD report describes: synthetic endorsements paired with redirection to fraudulent sites. Meta removed more than 134 million scam advertisements during 2025, according to disclosures made at a Global Anti-Scam Summit in Washington, and expanded facial-recognition technology for celebrity-impersonation detection, which it said more than doubled fraudulent-ad detection during testing. Internal Meta documents reported by Reuters in November 2025 projected that roughly 10 percent of the company's 2024 revenue, approximately $16 billion, came from advertisements it internally categorized as promoting scams, a characterization Meta has disputed; a Consumer Federation of America class action filed against Meta on April 26, 2026 argued the platform's auction-based pricing rewarded lax fraud enforcement. Separately, the Federal Trade Commission found that social media scams cost Americans $2.1 billion in 2025, and more recent FBI data attributed $893 million in reported 2025 losses specifically to AI-linked fraud.

Other platforms have moved on related enforcement. Google's AI-powered defense suspended 39 million advertiser accounts after assembling a team of more than 100 experts to counter deepfake celebrity-endorsement scams, permanently suspending more than 700,000 offending accounts. Microsoft Advertising revised its policies in October 2024 specifically to address deepfake technology and fraudulent endorsements, later reporting removal or restriction of more than one billion advertisements during 2024.

Brazil's electoral court moves against paid synthetic content

Outside the advertising-fraud context, the ANPD report devotes its longest regulatory discussion to Brazil's Tribunal Superior Eleitoral (TSE), the country's electoral court, which the report credits with taking the most concrete regulatory action against deepfakes of any Brazilian institution to date. Under Resolution 23.732/2024, which amended an earlier 2019 resolution, the TSE prohibited the use of synthetic audio or video content, however generated, to create, replace or alter the image or voice of a living, deceased or fictional person to benefit or harm any candidacy, according to the report. The same resolution requires that synthetic content used in electoral advertising carry an explicit, prominent disclosure identifying it as fabricated and naming the technology used, the report states.

In 2026, the report notes, the TSE went further with Resolution 23.755/2026, which prohibits the publication, republication, even where unpaid, and specifically the paid boosting of new synthetic content depicting a candidate or public figure's image, voice or likeness during the 72 hours preceding and the 24 hours following the close of polling, regardless of whether that content carries a disclosure label. This closes a gap the earlier resolution left open, according to the report: labeling compliance is no longer sufficient to permit paid distribution of synthetic political content in the most electorally sensitive window.

This detail places Brazil's electoral regulator ahead of the transparency-only model that has defined most deepfake-specific advertising regulation elsewhere. The report positions Brazil's approach within three broad international patterns it identifies: transparency mandates requiring disclosure of synthetic content; electoral prohibitions restricting deepfake use around voting; and criminalization of the most damaging categories of abuse, chiefly non-consensual sexual content. South Korea has banned deepfake campaign videos for 90 days before an election under its Public Official Election Act, the report notes, while 28 of 50 US states passed laws between 2019 and 2025 requiring detection and labeling of synthetic election content, led by California and Texas.

The labeling standard the European Union has already chosen

The transparency category the report describes maps closely onto the regime advertisers in the European Union are now confronting directly. According to the report, Article 50 of the EU's AI Act requires providers of generative AI systems to ensure synthetic audio, image, video or text output is marked and detectable as artificially generated, while separately requiring anyone deploying a system that generates deepfake-constituting content to disclose that it was artificially generated or manipulated. The report also notes that Article 50 exempts tools used purely for routine editing that do not alter a piece of content's actual meaning, distinguishing deepfakes from ordinary filters or color correction.

That regime is no longer theoretical for the advertising industry. Google signed the EU's Code of Practice on Transparency of AI-Generated Content as Article 50 obligations became applicable, with non-compliance carrying fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. Meta signed the same code five days before the deadline, with the company's VP of Public Policy for Europe, Markus Reinisch, stating in a newsroom post that signing "reflects our commitment to this principle," referring to giving people tools to identify synthetic media. The European Commission's implementation guidelines, published July 20, 2026, explicitly exclude persuasive commercial content from the lighter disclosure regime reserved for artistic or satirical work, a reading that directly affects marketers using AI-generated spokespeople or avatars in campaigns.

On the advertiser-facing side, Google Ads API version 24.2, released June 24, 2026, introduced developer-facing synthetic-content labeling structures covering two dimensions: whether an asset or ad is AI-generated, and whether it was produced fully automatically or with advertiser review. A separate consumer-facing "How this ad was made" panel followed on July 9, 2026, extending into Google's ad products a disclosure logic already applied on YouTube, where C2PA metadata and SynthID watermarks trigger automatic content labels even when a creator does not select the disclosure option manually during upload.

Detection tools and their limits

The ANPD report devotes its final substantive section to technical mitigation tools, describing four categories in use: automated detection based on algorithms trained to spot manipulated-content patterns; cryptographic signatures verifying content integrity from origin; digital watermarking, using visible or invisible signals identifying AI-produced content; and traceability standards, citing the Coalition for Content Provenance and Authenticity, or C2PA, which the report describes as recording a digital file's origin, authorship and edit history.

Even so, the report is candid about the limitations of currently available detection software. It cites a comparative 2025 study by Moraes and Batista examining three commercial tools, DeepWare Scanner, Attestiv and TrueMedia, which found that none reliably distinguished deepfakes from authentic material, including low-resolution footage or content produced under tightly controlled conditions such as archival television clips. All three tools returned uncertain results for both synthetic and genuine material, leading the study's authors to conclude that combining automated tools with human evaluation remains essential for robust verification. The report frames this as evidence that detection technology alone cannot substitute for a broader governance approach that also includes regulation, digital literacy and traceability infrastructure.

Brazil's own AI decree and enforcement backdrop

The report situates its advertising-fraud findings within Brazil's wider 2026 AI regulatory activity. Decree 12.976, signed May 20, 2026, prohibits internet application providers from generating or modifying intimate content depicting third parties using artificial intelligence, a measure aimed at non-consensual sexual deepfakes rather than commercial fraud, though the report treats it as part of the same regulatory momentum. The ANPD itself expanded its enforcement posture over the same period, having added child protection to its 2026-2027 enforcement priorities on December 22, 2025 and released a draft age-verification guide for public consultation on May 23, 2026, both overlapping with the report's discussion of AI-generated child sexual abuse material as a distinct harm category.Brazil currently has no specific criminal offense covering abusive deepfake use in general, according to the report; non-consensual intimate deepfakes are instead prosecuted under article 218-C of the Penal Code, a 2018 provision whose penalty was increased in 2025. A separate 2025 law, Lei 15.123, amended article 147-B of the Penal Code covering psychological violence against women to increase penalties when AI is used to alter a victim's image or voice, citing UN Women data suggesting around 41 percent of women in public positions report self-censoring to avoid further deepfake-enabled attacks.

Why this matters for advertising and marketing professionals

For marketing and advertising professionals, the ANPD report functions less as a new legal instrument and more as a structured evidence base that will likely inform how Brazilian regulators, courts and platforms treat synthetic-media advertising fraud going forward. PPC Land's own coverage documents a pattern the report independently confirms from the Brazilian side: Meta, Google and Microsoft have each built specific enforcement infrastructure around deepfake-based celebrity endorsement fraud, precisely the mechanism the ANPD identifies as the dominant form of deceptive advertising involving synthetic media in Brazil. That convergence between a national regulator's study and platform-level enforcement action, filed independently and roughly six months earlier by Meta against Brazilian defendants specifically, suggests regulators and platforms are working from a broadly compatible picture of how this fraud operates, even where their remedies differ, one relying on litigation and account suspension, the other on data-protection frameworks that remain largely untested in Brazilian courts.

The report's TSE section carries a distinct implication for political advertising: a disclosure label, sufficient under the AI Act's Article 50 and under most transparency-style state laws in the United States, is not sufficient under Brazil's 2026 electoral rule during the most sensitive pre- and post-election window, where paid boosting of synthetic candidate content is banned outright regardless of labeling. Any advertising or campaign-technology firm operating in Brazilian electoral contexts would need to treat that 72-hour to 24-hour window as an absolute restriction rather than a disclosure obligation. That distinction sits alongside a more uncomfortable finding: none of three commercial detection tools the report tested could consistently distinguish synthetic from authentic media, even as platforms increasingly rely on similar automated detection, paired with C2PA metadata and watermarking, to power the disclosure systems that labeling regimes now require.

Timeline

Summary

Who: Brazil's Agencia Nacional de Protecao de Dados (ANPD), the country's national data protection authority, authored by a team including Gabriela Campos Alkmin, Ingrid David Alves de Carvalho, Roseane Salvio, Roberta Fernandes Mendiondo Nunes, Mariana Luisa da Costa Lage and project lead Ticianne de Gois Ribeiro Darin, under Director-President Waldemar Goncalves Ortunho Junior.

What: A 163-page technical report titled "Radar Tecnologico N. 6 - Deepfakes," documenting how synthetic media is used in deceptive digital advertising, financial fraud, non-consensual intimate imagery and electoral disinformation in Brazil, and comparing Brazilian regulatory responses, including a 2026 electoral-court ban on paid boosting of synthetic candidate content, against international frameworks including the EU AI Act's Article 50 labeling regime.

When: Published July 29, 2026, drawing on source material spanning 2017 through July 2026, three days ahead of the EU AI Act's Article 50 transparency obligations becoming legally applicable on August 2, 2026.

Where: Brasilia, Brazil, with the report's findings and regulatory comparisons extending to the European Union, the United States, South Korea, the United Kingdom, France and Australia.

Why: The report matters to the advertising and marketing industry because it documents, from a Brazilian regulator's perspective, the same deepfake-enabled celebrity-impersonation advertising fraud that Meta, Google and Microsoft have each built platform-level enforcement systems to counter, while also identifying a regulatory gap, Brazil's outright ban on paid synthetic political advertising in the final pre- and post-election hours, that goes further than the disclosure-only requirements most advertisers currently navigate under the EU AI Act and comparable US state laws.