The risk isn't the deepfake

Deepfakes get the headlines. The larger risk for a campaign is the AI it deploys itself: answering voters, speaking in the candidate's name, at a scale no one reviews.

Not the deepfake, a Fig post on the risks of a campaign's own AI talking to voters.

In shortThirty-one states now regulate election deepfakes, and lawsuits over deceptive ads have begun. But for a campaign using AI, the bigger exposure is quieter: systems that text and talk to voters in the candidate's name, answer questions about voting, and do it thousands of times a day where no one is watching. Independent testing shows general-purpose assistants now get voting facts right yet routinely leave out the official source. The rules that apply are scattered across the FEC, the FCC's robocall rules, state bot-disclosure and deepfake laws. This piece sets out the failure modes, the legal map, the security threats aimed at campaign staff, and the design rules for voter contact a campaign can stand behind.

Every conversation about AI and elections eventually arrives at the deepfake: a fabricated video of a candidate, a cloned voice, an image that never happened. The concern is legitimate. By the National Conference of State Legislatures' count in June 2026, 31 states have laws on deceptive AI in election communications, most of them requiring disclosure and a few banning certain content outright. This fall the first legal threats over AI-generated ads have followed.

But for a campaign deciding how to use AI itself, the deepfake is not the main risk. The main risk is the AI the campaign deploys on purpose, doing ordinary work at extraordinary volume, where nobody is looking.

Where campaign AI actually talks to voters

Political text messaging has quietly become one of the largest deployments of conversational AI in the country. The pattern described by reporting this summer is now common: a person writes and sends the first message, and when the voter replies, an AI system takes over the conversation in the campaign's or candidate's voice, answering questions, asking about priorities and recording what the voter says. Vendors pitch these systems as tireless volunteers who answer within seconds in any language. Phone outreach with synthetic voices, chat on campaign websites and answers inside messaging apps follow the same logic.

Done well, this is a genuine improvement. A voter who asks a question at eleven at night gets an answer. A voter who speaks Spanish or Vietnamese gets one in their language. A campaign with forty organizers can hold a hundred thousand conversations.

Done carelessly, it creates a kind of exposure campaigns have never had before.

Three ways it goes wrong

The wrong answer about voting. The most serious failure is not a fabricated scandal. It is a confident, plausible, incorrect answer about where, when or how to vote, given privately to one voter at a time. The States United Democracy Center tested how general-purpose AI assistants answer voter questions. Factual error rates fell from about 7 to 8 percent in late 2025 to zero on verifiable claims by early 2026, which is real progress. But the answers were frequently incomplete: ChatGPT pointed voters to their state's official election website in only 39 percent of responses, and its answers about gubernatorial candidates were incomplete in 89 percent of cases. If the leading assistants, with enormous resources devoted to election integrity, still leave voters without the official source most of the time, a campaign bot improvising from the open web will do worse.

The position nobody approved. A system speaking in a candidate's name that is asked about a policy the candidate has never addressed will, unless it is built not to, produce an answer. That answer is now, in effect, a campaign statement, made to a voter who may screenshot it.

The error nobody sees. A misleading ad can be found, criticized and withdrawn. An error made in one of a hundred thousand private text conversations is invisible until a voter shares it. As one practitioner put it in Campaigns and Elections this year, these errors are far harder to detect than a bad ad, and far more likely to push someone out of the process.

None of these require bad intent. They are what happens when a system built for open-ended conversation is pointed at voters without the constraints the job needs.

The rules a campaign actually has to follow

There is no single federal AI election law. The rules are scattered, and a national campaign has to satisfy all of them at once.

The scattered rules that apply to campaign AI: the FEC's fraudulent misrepresentation rule, the FCC's ruling on AI voices in calls, state deepfake laws, state bot-disclosure laws, carrier and platform rules.
No single law governs campaign AI. A national campaign answers to all of these at once.

Federal election law. The Federal Election Commission declined to write new AI rules in 2024 and instead adopted an interpretive rule: its existing ban on fraudulent misrepresentation is technology-neutral and applies whether a deception is produced by AI or anything else. With the commission evenly divided, that remains the federal position.

Telephone law. In February 2024 the Federal Communications Commission ruled that AI-generated voices count as "artificial" under the Telephone Consumer Protection Act. Calls using them are subject to the act's consent, identification and opt-out requirements. The commission later fined the consultant behind a 2024 cloned-voice primary robocall six million dollars, even though a state jury acquitted him of criminal charges in 2025. The regulatory exposure is real regardless of how a criminal case ends.

State deepfake laws. Thirty-one states now regulate deceptive AI in election content. Most require a disclosure when AI is used to depict a real person doing or saying something they did not; Maryland, Minnesota and Texas prohibit certain content even with a disclosure. Definitions, timing windows and penalties differ from state to state.

State bot-disclosure laws. California has required since 2019 that anyone using a bot online to influence a vote disclose that it is a bot, if the bot is used to mislead about its artificial identity. A campaign whose AI texts or chats as if it were a person, or as the candidate, needs to know where rules like this apply.

Carriers and platforms. Mobile carriers require registration and consent for political text programs, and major advertising platforms require disclosure of synthetic content in political ads. These are contractual rather than statutory, but losing access to a channel in October is its own kind of penalty.

The threat aimed at the campaign itself

AI has also changed what campaigns have to defend against. Security researchers and federal agencies tracking the 2026 midterms have consistently found that the main targets are not voting machines but people: phishing and credential theft aimed at campaign staff, impersonation of trusted organizations, and attacks on fundraising platforms. In 2024, federal agencies attributed a hack-and-leak operation against a presidential campaign to a foreign government.

Generative AI makes every one of these cheaper and more convincing. A phishing email in flawless, personalized English costs nothing to produce. A cloned voice of a campaign manager asking a junior staffer to approve a payment or share a password takes minutes. Campaigns grow so fast that half the staff have never heard the real voice.

The practical defenses are not exotic: single sign-on and hardware keys for every account, no shared credentials, a verification rule for any request involving money or access, and an AI system that lives inside the campaign's security perimeter rather than in a dozen personal accounts.

Design rules for voter contact

A campaign that wants the benefits of AI voter contact without the exposure can build to a short list of rules. They are not burdensome; they are what a careful campaign would expect of a human volunteer.

The loop for governed voter contact: approved sources, an answer with the official link for voting logistics, escalation to a person for anything sensitive, and a complete record reviewed by staff.
Every answer comes from approved material, every voting question points to the official source, and every conversation leaves a record.

Answer only from approved material. Positions, biography, events and volunteer logistics, from a knowledge base the campaign maintains and owns. Never from the open internet.

Send voting logistics to the official source. Registration, deadlines, polling places and identification are questions for election officials. The system should always provide the official state or county link rather than its own summary.

Never invent a position. If the approved material does not cover a question, the answer is that the campaign will follow up, and the question goes to a person.

Escalate the sensitive. Questions about legal issues, threats, accessibility needs or anything the system is not certain about go to a named staff member, quickly.

Disclose where required, and arguably everywhere. A voter who later learns they were talking to a system that presented itself as a person, or as the candidate, will not distinguish between a legal requirement and a breach of trust.

Get consent right. Calls with synthetic voices and automated texts carry consent requirements. Build them into the system, not the training deck.

Keep a complete record. Every message, the source it drew on and the person who approved the underlying material, reviewable by staff and available to counsel. It is the difference between answering a reporter's question in an hour and not being able to answer it at all.

These rules map directly onto how we build governed agents: grounded in approved knowledge, with approval gates before anything consequential and an audit record of everything that happened.

What the campaign keeps

There is one more risk, and it arrives after election day. A campaign is a temporary organization. When it ends, its people disperse, and much of what it built, the knowledge base, the record of what voters asked and the operating playbooks, ends up scattered across departed staffers' accounts and vendors' systems, or simply lost.

The data and knowledge a campaign creates should belong to the committee that created it, held in systems it controls and can hand on lawfully to whatever comes next, rather than living inside a vendor's product on terms nobody read. That is the same principle we argue for every organization in the sovereign frontier enterprise, and it matters most for an organization designed to end. How to build that operation from the start is in the AI campaign playbook.

Key takeaways

  • The bigger risk in campaign AI is not other people's deepfakes but the campaign's own systems speaking to voters at scale, privately and unreviewed.
  • Leading AI assistants now get voting facts right but usually omit the official source. A campaign bot should always point voters to election officials for anything about voting itself.
  • The rules are scattered: the FEC's technology-neutral fraud rule, the FCC's treatment of AI voices as artificial, 31 state deepfake laws, bot-disclosure laws, and carrier and platform requirements.
  • The main security threat is phishing and impersonation aimed at staff, which AI has made cheap. Verification rules and a single secured system matter more than any detection tool.
  • Govern voter contact the way you would a volunteer: approved material only, official sources for voting, escalation for anything sensitive, disclosure, consent and a complete record.

The deepfake is someone else's problem to solve. What a campaign's own AI says to voters is entirely the campaign's.

Build a Frontier Enterprise

Platform, people, and strategy, brought together to change how your enterprise works, measured in results you can see.

Be the next big thing

Dream big, build fast, and grow far with Fig

Fig Desktop Coming Soon!