California and Texas both regulate deepfakes. They just do it like they're describing different technologies. The contrast tells you most of what you need to know about the national patchwork.
California moved early and broadly. Nonconsensual intimate deepfakes carry both criminal and civil teeth, and the state has been aggressive on political deepfakes too, with high-profile election-period rules. The approach leans toward explicit AI-specific statutes with detailed definitions. You can feel the lawyers in the drafting.

Texas took its own path, a mix of criminal provisions with a notable focus on election-related deception. The definitions don't line up with California's. The penalties don't either. The enforcement mechanisms don't either. A compliance checklist built for one state does not transfer to the other. New York, Illinois, and Virginia each add their own wrinkles. Illinois leans on its biometric privacy tradition. Virginia moved fast on nonconsensual deepfakes specifically. Nobody is copying anyone's homework.
The practical lesson for anyone operating nationally, and I'll keep saying it: build around the strictest state you touch, not the average. The deepfake law California wrote and the deepfake law Texas wrote answer the same question differently, and a consent practice that satisfies California's detailed statutes will usually clear Texas too. The reverse is not true. Start strict, then relax where the law allows. Never the other way around.
You also cannot learn 'US deepfake law' by reading two states. California vs Texas is just the most vivid example of how differently two big states answer the same question. You have to check each one. An AI compliance monitor SaaS with per-state tracking helps teams watch both, and a mobile app for AI regulation alerts works for solo builders who just need a ping when their state moves.
DeepfakeLaw tracks both states in full detail, requirements, penalties, effective dates, alongside the other 48, federal law, and 40+ countries. Look up your actual jurisdiction instead of extrapolating.
Building something with generated media? I audit AI products for deepfake-law compliance across states and countries, in plain language, at deepfakelaw.fyi.