Author: Noémia Bessa Vilela, Andrius Puksas, Karol Bieńkowski
Date: 26-05-2026
There’s a tired joke that technology moves at the speed of light and the law moves at the speed of a committee. AI has stopped making that funny. In a few short years, generative models went from a research curiosity to something anyone can rent for pocket change, and the legal systems meant to govern them are wheezing badly. The gap matters most in illicit trade, because the people abusing AI there don’t sit in committees. They just move.
Three things make this hard. First, timing. Laws are slow on purpose, drafted and argued over and picked apart by courts for years, which is fine until you aim that at a technology that reinvents itself every product cycle. A rule written for last year’s deepfakes is often useless by the time it takes effect. Second, fragmentation. There is no single thing called “AI law,” just a tangle of rules that contradict each other across countries and even across states. Europe went broad and rights focused, China regulates with state priorities in mind, and the United States has lately gone the other way at the federal level while its states keep passing AI bills by the hundred. Agents simply pick whichever jurisdiction asks the fewest questions and live in the cracks. Third, blame. Old fashioned law assumes you can find the person who did it. When a model produces a fraudulent ad, a knockoff design, or a fake identity good enough to fool a bank, who is liable? The user, the company that trained the model, the platform that served it, the reseller? Every link points at the next one, and a harm nobody can pin down is a harm that’s hard to charge.
Illicit trade pulls all of this together. Fraud has gone professional, with operations renting out phishing kits, automation, and fake identities to people with almost no skill for the price of a streaming subscription. AI hands them the one thing they lacked, which is scale. Deepfakes have gone from party trick to working weapon: a cloned voice authorizes a wire transfer, a fake clip pumps a worthless investment, and reported losses now run into the hundreds of millions. Each convincing fake also chips away at the basic assumption that a recording shows something real. Counterfeiters crank out believable fake listings and cloned storefronts faster than enforcement can react. Criminals even use AI to launder money and to feed garbage data to the systems built to catch them.
And almost none of it stays in one country. A scam might be scripted by a model in one place, run from a second, paid through a third, and aimed at victims in a fourth, with the money moving in crypto that ignores borders entirely. Police are stuck inside their own territory, relying on slow treaties and extradition processes. By the time cooperation is arranged, the operation has folded and reopened under a new name.
The awkward twist is that the same technology is also the defenders’ best tool, spotting odd transactions and chewing through huge datasets in minutes. A rule strict enough to cripple the criminals can also blunt the people fighting them. That is what makes this genuinely hard rather than just slow.
None of it means the law is helpless. The better approaches target conduct and outcomes rather than freezing a definition that the next model will outrun, keep responsibility attached all along the chain, and put real weight on cooperation across borders. Perfect rules aren’t coming, and waiting for them quietly favors whoever is already working the gap. The law will never get out in front of AI. The realistic goal is to stop standing still while the illicit economy sprints off into the distance
