Bangladesh is on course to regulate deepfakes without passing a deepfake law. On September 17, 2026, 19 Bangladeshi and international organisations, including Transparency International Bangladesh, BLAST, Ain o Salish Kendra and ARTICLE 19, called for withdrawal of the draft Cyber Protection (Amendment) Act, 2026. The draft would broaden defamation and add offences for 'rumours' and 'disinformation'. Penalties run up to 10 years' imprisonment and fines of up to Tk 40 lakh.
The result is a general speech-offence regime that happens to reach AI content. It is not a targeted synthetic-media statute.
The case for acting
The government's concern is real. Synthetic audio, video and images can put invented words in a real person's mouth, and the harm lands fastest on women and minors. Prothom Alo reports that officials cited fake videos, audio and images generated with AI as a reason for stricter penalties. The same report says the amendments set enhanced penalties where defamatory content targets women or minors. A country with fast-spreading messaging, high political temperature and thin platform trust-and-safety capacity has good reason to want a faster remedy than a years-long civil suit.
The Oversight Board's September 17 decision on a video of a Scottish councillor shows the problem exists everywhere. The video used the councillor's likeness to say something they never said, and the Board ordered it removed. As MediaNama reports, it also found Meta's 'High Risk AI' labels had 'barely been applied at any meaningful scale'.
What the draft does instead
The Board's response was narrow. It ordered one removal and asked for lower thresholds on labelling manipulated media. It also asked for click-through screens and penalties for repeat sharers. None of that involves prison.
Bangladesh's draft goes the other way. According to the ICNL analysis dated September 18, as reported by Daily Waadaa, the draft reaches content prepared or modified using artificial intelligence. But it does so through the same vague categories it applies to all speech. Three features stand out:
- Undefined harm categories. Article 25 criminalises content that is 'defamatory or humiliating or bullying'. ICNL warns that a journalist publishing a video of someone accepting a bribe could fall within it.
- 'Rumour' defined as unconfirmed information. ICNL says Article 26(A) could effectively criminalise breaking news, because emerging reports are usually unverified at first. The same definition would catch an AI-generated clip, a satirical edit and a first-day news report alike.
- Warrantless arrest. ICNL says the offences are cognizable, so police can arrest based on an officer's judgment of an online post.
The joint statement adds concerns about pre-trial detention, prosecution under the Mobile Courts Act, and an expanded executive power to order content removal without clear procedures or appeals. It also objects to the Ministry of Information and Broadcasting leading the process, when cyber legislation has usually sat with the Posts, Telecommunications and IT ministry.
Why a targeted law would work better
A law aimed at deepfakes would ask what makes synthetic media distinctive. That is deception about authenticity, the use of a real person's likeness, and speed of spread. The tools that fit those features are proportionate ones:
- Disclosure and labelling duties for realistic synthetic media.
- Fast, court-supervised takedown for non-consensual intimate imagery and impersonation.
- Penalties tied to demonstrable intent to deceive and to concrete harm.
The draft leaves out the intent-and-harm limits that would separate a malicious fake from satire or reporting. Instead it puts the burden of proof on the speaker. Anyone who posts something 'unverified' risks a decade in prison. The likely effect is self-censorship among journalists and ordinary users, while a determined bad actor simply moves to an offshore account.
The legislative history adds to the concern. The Cyber Security Act 2023 replaced the Digital Security Act 2018. ICNL's handbook notes it kept much of the earlier regulatory structure with reduced penalties, and critics feared it would still restrict online expression. Rights groups now say the new draft is 'in many respects, more regressive' than the 2018 law.
The process problem
According to ICNL, the government published the draft on September 13 and set September 23 as the comment deadline. That gives the public ten days and nothing in the way of a consultation on how the text was drafted. A rule that can put people in prison for what they post should be tested against evidence. That means a real look at how many deepfake harms existing defamation and harassment law already covers, and at what remedies victims actually need.
What proportionate regulation would look like
Bangladesh is entitled to protect people from synthetic falsehoods. Article 19 of the International Covenant on Civil and Political Rights, which Bangladesh has ratified, permits restrictions on expression only where they are provided by law and necessary and proportionate. ICNL says several provisions of the draft fail that test.
The better path is straightforward. Withdraw the draft, run a real consultation, and legislate narrowly on synthetic media with intent and harm thresholds, judicial oversight and clear definitions. Decriminalise 'rumour' altogether. The draft as written would give Bangladesh a broad tool for policing speech and no meaningful protection specific to deepfakes.