top of page

Montana AI Campaign Ad Law Blocked as Court Draws a First Amendment Line

55 minutes ago
14 min read

Montana’s AI campaign ad law faced a major setback after a federal judge blocked enforcement against a political group using digitally altered campaign imagery.

The preliminary injunction protects former Republican legislator Dan Bartel and his Accountability in State Government political action committee, commonly called ASG. It does not erase the law or prevent every future enforcement action.

That distinction matters. The dispute tests whether states can regulate deceptive AI election content without placing unconstitutional burdens on political speech.

In [Accountability in State Government v. Knudsen, No. 6:26-cv-00038-SPW](https://dockets.justia.com/docket/montana/mtdce/6%3A2026cv00038/84819), U.S. District Judge Susan Watters found that the plaintiffs faced a credible enforcement threat and were likely to succeed on their First Amendment claims. The decision arrived as ASG prepared additional mailers for Montana’s 2026 general election.

The conflict reaches beyond one campaign. State lawmakers want voters to recognize synthetic political media, while speakers argue that disclosure rules can stigmatize protected criticism and satire.

A similar dispute already reached a federal court in California. Montana’s ruling strengthens a developing legal warning for states: regulating political deepfakes requires narrower language than regulating other harmful uses of AI.

What the Federal Court Actually Blocked

The court restricted enforcement against two plaintiffs, rather than suspending Montana’s law for every political speaker.

Watters issued the preliminary injunction in September 2026. It prevents Montana’s attorney general and Commissioner of Political Practices from applying the disputed provisions to Bartel and ASG while litigation continues.

The protected communications include proposed campaign materials targeting Democratic state legislator Mary Ann Dunwell. One image portrays Dunwell as a country-western pickpocket removing a wallet from a cowboy’s pants.

According to a Montana Free Press account of the ruling, ASG indicated that it would begin distributing materials after the order. That immediate campaign activity gave the dispute practical consequences beyond a theoretical constitutional challenge.

Montana adopted Senate Bill 25 during its 2025 legislative session. Governor Greg Gianforte signed it on May 8, 2025, after the measure received bipartisan legislative support.

The legislative history shows that the Senate approved its final amended version by a 45-3 vote. The House had previously approved the measure 80-17.

The law regulates election communications containing certain deepfakes. A deepfake is synthetic or digitally altered media that falsely depicts a person’s appearance, speech, or conduct.

Its central restriction applies during the 60 days before voting begins. A sponsor cannot knowingly produce or distribute a covered deepfake involving a candidate or political party without satisfying the statute’s conditions.

The law provides an exception when the communication carries a clear disclosure. That notice must tell viewers that AI significantly edited the content and made something false appear authentic or truthful.

It also exempts satire and parody. That exception became central because state officials had described ASG’s earlier primary-election mailers as protected satire.

Those earlier materials depicted Republican legislative candidates holding pride flags or wearing pronoun buttons. The candidates said the altered images falsely represented their identities and political positions.

Jennifer Carlson, one targeted candidate, filed a complaint with the Commissioner of Political Practices. Other complaints followed, creating the enforcement history that supported the plaintiffs’ claim of a credible threat.

Commissioner Chris Gallus ultimately treated the earlier mailers as satire. Yet the plaintiffs had also received a warning letter, and officials had not categorically disavowed future enforcement.

Watters concluded that those circumstances justified judicial intervention. A speaker generally does not need to risk prosecution before challenging a law that allegedly chills protected expression.

The court did not decide the entire case on the merits. A preliminary injunction preserves the plaintiffs’ position when they show likely success and a risk of irreparable harm.

That procedural posture leaves several questions open. The state can continue defending the statute, seek appellate review, or refine how officials interpret its terms.

The order is also narrower than the article shorthand that Montana’s law was “blocked” might suggest. Other campaign organizations are not automatically covered by relief granted specifically to Bartel and ASG.

That narrow scope reflects an important change in federal remedies. Courts now face tighter limits when extending injunctions beyond the parties who established standing and injury.

Still, the immediate outcome is clear. ASG can proceed with its planned communications without the disputed disclosure while the case moves forward.

Why the Montana AI Campaign Ad Law Failed Its First Test

Montana’s problem was not simply that the statute mentioned AI, but that its categories affected protected political viewpoints unevenly.

Political speech receives the strongest level of First Amendment protection. Laws burdening campaign messages therefore face closer scrutiny than ordinary commercial disclosure rules.

Montana argues that voters deserve notice when manipulated media falsely represents a candidate. That interest becomes more urgent as image generators make convincing alterations inexpensive and widely accessible.

The state’s position has a practical foundation. Carlson told reporters that people in her church and community believed an altered image showing her with a pronoun pin.

One acquaintance reportedly considered removing a Carlson campaign sign. In practice, a voter receiving only the mailer could mistake the fabricated pin for part of the original photograph and infer that Carlson had publicly endorsed a position she said she did not hold.

Media researchers also warn about a broader effect. Repeated exposure to fabricated images can undermine trust in authentic photographs, recordings, and political reporting.

However, an important constitutional gap separates identifying harm from drafting a lawful remedy. A state cannot suppress protected speech merely because officials consider its message misleading or offensive.

The satire exception sharpened that problem. Satire can use obvious exaggeration, but judgments about obviousness often depend on the audience and political context.

If a misleading image qualifies as satire, the statute may permit it. If a similar image appears more realistic, its sponsor may face a disclosure mandate or legal penalties.

That boundary gives government officials substantial authority to classify political expression. Speakers must predict whether regulators will view an image as deception, commentary, or parody.

The plaintiffs argued that this uncertainty chills speech before any formal punishment occurs. Campaigns operating near an election have little time to await a regulator’s decision or complete extended litigation.

Watters also examined the credibility of the enforcement threat. Multiple private complaints, the warning letter, and the absence of a government disavowal supported the plaintiffs’ concerns.

The controversy did not disappear when officials dismissed earlier complaints. ASG intended to create and circulate new materials, while the state retained the legal authority to receive additional complaints.

The plaintiffs therefore challenged more than a hypothetical future. Their intended conduct resembled the conduct that had already attracted complaints and official attention.

The disclosure requirement created another constitutional issue. A mandatory label is compelled speech, meaning the government requires a speaker to carry a particular message.

Courts sometimes uphold factual disclosures in regulated settings. Political advocacy presents a more demanding context because a label can affect how audiences interpret the underlying argument.

Bartel’s attorney, Matthew Monforton, argued that the required notice would discredit the communication. In that view, the warning operates as part of the political debate rather than neutral metadata.

The state sees the same feature differently. Its disclosure tells voters that an apparently authentic depiction was materially altered, allowing them to judge the message with additional information.

Both descriptions contain some truth. A label can inform voters while also weakening the persuasive impact that a campaign hoped to achieve.

That is the core constitutional tradeoff. Montana wants to reduce deception, but its chosen remedy forces speakers to append the state’s characterization to protected political content.

The order indicates that this approach is unlikely to survive in its current application to ASG. It does not establish that every AI disclosure requirement is unconstitutional.

A narrower statute might focus on impersonation, fraudulent voting instructions, or synthetic recordings designed to appear authentic. Each category would still require careful First Amendment analysis.

Montana’s broad concepts also meet an older legal reality. Political campaigns have used retouched photographs, selective editing, cartoons, and misleading juxtapositions long before generative AI arrived.

The technology changes speed and accessibility. It does not automatically create a new category of speech outside established constitutional protections.

Disclosure Rules Collide With Political Satire

The case turns on a difficult line between authentic-looking deception and protected visual rhetoric, not on whether synthetic media can cause harm.

ASG’s images provide an unusually revealing test. They were altered political attacks, yet officials also viewed them as satire protected by the law’s own exception.

That classification creates tension for both sides. The state cannot easily claim that those particular mailers violated the statute after its commissioner described them as exempt.

At the same time, the prior complaints show why the plaintiffs feared future enforcement. Candidates and voters did not necessarily experience the images as harmless jokes.

Carlson called the claims complete lies. She described people asking why she wore a pin that had never appeared in the original photograph.

Those reactions complicate a simple satire defense. A message can contain exaggeration while still persuading some recipients that its fabricated details are genuine.

Political cartoons usually signal their constructed nature through drawing, distortion, or an established format. AI-generated campaign materials can borrow the visual authority of photography.

That difference supports the state’s concern. A fabricated photograph can imply documentary evidence while delivering the same political insult as a traditional cartoon.

However, visual realism alone cannot settle the legal question. Edited photographs have long appeared in campaign advertising, comedy, art, and advocacy.

A technology-specific rule also creates classification problems. Regulators may need to determine whether a campaign used generative AI, conventional editing software, or a combination of both.

That distinction becomes less workable as editing applications incorporate generative features. Removing an object, replacing a background, and extending an image can now involve automated models.

The political meaning does not depend on which software button produced the result. A voter sees the finished message, not the campaign’s technical workflow.

Montana’s law attempts to address the output by defining covered synthetic content. Yet concepts such as falsity, authenticity, and reputational injury remain context dependent.

Consider the Dunwell mailer. Many readers may understand that the legislator did not literally dress as a western pickpocket and steal from a cowboy, but others encountering the image without explanatory text might not immediately know whether it originated from a staged photograph or an alteration.

The image’s intended claim is metaphorical. It apparently communicates an argument about taxes or public spending through a fabricated scene.

A rule treating that image as a deceptive deepfake could reach ordinary political caricature. A rule treating it as satire may leave more convincing fabrications untouched.

That dilemma explains why the case is larger than one label. The law asks officials to separate metaphor from deception during a campaign, when every decision carries political consequences.

The plaintiffs frame that authority as censorship. The state frames it as voter protection through transparency rather than suppression.

The difference between a ban and a disclosure matters, but it is not decisive. Compelled notices can still burden expression when their wording changes a message’s perceived credibility.

The state might eventually defend a shorter, more neutral notice. “AI-generated image” imposes a different message than language declaring that content falsely appears authentic or truthful.

Even that narrower approach would require definitions and enforcement standards. Campaigns could dispute whether an image was generated, merely edited, or altered without changing a material fact.

Platform labels offer another comparison. Social networks can apply private content policies, although their decisions generate separate debates about accuracy and political bias.

A government label carries legal consequences and official authority. That difference triggers constitutional limits that do not apply identically to private moderation.

The strongest policy response may combine several tools. Voluntary provenance standards, newsroom verification, campaign rebuttals, platform context, and targeted fraud laws can address different risks.

No single measure eliminates deceptive political content. Broad disclosure statutes can appear attractive because they promise one visible rule across every medium.

Montana’s case shows the cost of that simplicity. A universal-sounding standard becomes difficult to administer once political parody, metaphor, and authentic-looking fabrication occupy the same advertisement.

Montana Joins a National Fight Over Political Deepfakes

The injunction adds Montana to a wider conflict between state election safeguards and federal constitutional doctrine.

State activity has accelerated because Congress has not created a comprehensive national rule for AI-generated campaign media. Legislatures have instead adopted different definitions, time windows, labels, and enforcement methods.

The state law inventory maintained by the National Conference of State Legislatures shows how varied these approaches have become.

Some states require disclosures on synthetic election communications. Others create removal procedures, candidate lawsuits, criminal penalties, or exceptions for news reporting and parody.

By August 2026, 29 states reportedly had election deepfake laws in effect. California and Hawaii had encountered permanent injunctions affecting their statutes.

Montana’s 60-day window resembles other laws that intensify restrictions close to voting. Lawmakers use these periods because late fabrications leave candidates less time to respond.

The same timing increases the burden on speakers. Campaign messages have their greatest value near an election, and delayed judicial review can function like a final loss.

California offers the clearest comparison. A federal judge blocked most of Assembly Bill 2839 after a creator challenged restrictions on digitally altered election content.

The California dispute involved a parody video featuring altered audio and imagery associated with then-presidential candidate Kamala Harris. The state defended its law as protection against dangerous election misinformation.

In [Kohls v. Bonta, No. 2:24-cv-02527-JAM-CKD, Order Granting Plaintiff’s Motion for Preliminary Injunction](https://cases.justia.com/federal/district-courts/california/caedce/2%3A2024cv02527/453046/14/0.pdf?ts=1727939818), the court acknowledged the dangers of AI and deepfakes. It still concluded that most of the statute likely violated the First Amendment.

The court described California’s approach as too blunt for the protected exchange of political ideas. That reasoning gave challengers elsewhere a useful constitutional template.

Montana’s statute differs in wording and structure, so California’s result does not dictate Watters’ decision. The cases nevertheless expose the same drafting problem.

States want to distinguish harmful falsification from parody. Their statutes must describe that distinction before a regulator reviews the message and before a speaker faces penalties.

The First Amendment does not protect every deceptive act. Defamation, fraud, threats, and certain forms of impersonation can create liability under established legal standards.

Yet political falsity alone has not become a broad exception to free speech. Governments cannot generally appoint themselves final arbiters of truth in electoral debate.

That principle frustrates regulators confronting realistic synthetic media. The most harmful content can spread across platforms before fact-checkers identify its origin.

The 2024 robocall that imitated President Joe Biden demonstrates a more targeted category. The recording urged New Hampshire voters not to participate in the presidential primary; the Federal Communications Commission’s official enforcement account described the apparent voice imitation and efforts to trace the calls.

That incident involved apparent impersonation and direct interference with voting behavior. It differs from a visual metaphor attacking a candidate’s legislative record.

Future laws may have stronger prospects when they concentrate on conduct like fraudulent voting instructions. The state interest becomes clearer, while the protected expressive value becomes weaker.

Authentication systems may also shift the policy debate. Content credentials can preserve information about a file’s origin and editing history when tools and platforms support them.

Those systems do not resolve every case. Metadata can disappear, malicious actors can ignore standards, and authentic media can still be presented with false context.

They could nevertheless support less speech-restrictive responses. Campaigns, journalists, and platforms could verify provenance without asking regulators to judge every political image’s meaning.

The national conflict will continue because each side identifies a real risk. Unregulated synthetic media can deceive voters, while poorly drafted laws can suppress criticism.

Montana’s injunction does not settle that conflict. It shows that judicial tolerance decreases when a statute reaches satire, commentary, or compelled statements about truthfulness.

What the Ruling Does Not Settle

The preliminary injunction protects specific speakers while leaving Montana’s statute, the factual dispute, and future enforcement questions unresolved.

The court has not issued a final judgment declaring every provision invalid. Preliminary relief depends on an early assessment made before full merits proceedings conclude.

The state can develop additional arguments and evidence. It can contest standing, defend the disclosure’s neutrality, or argue that the statute targets deceptive conduct rather than viewpoint.

Montana can also appeal the injunction. A higher court could narrow, affirm, or reverse Watters’ reasoning while the underlying case remains active.

The attorney general’s office expressed disappointment with the decision. A spokesperson said Montanans deserve to know when AI manipulates candidate images, audio, or video.

The office was reviewing its next steps, according to Yellowstone Public Radio’s report on the state’s reaction. That leaves both appellate action and legislative revision on the table.

The court also declined to bar all enforcement against everyone. Its restraint followed the Supreme Court’s changing treatment of universal injunctions.

A universal injunction prohibits the government from applying a policy to people who are not parties to the lawsuit. Federal courts once used such orders more freely.

In the Supreme Court’s official opinion in [Trump v. CASA, Inc., 606 U.S. ___ (2025)](https://www.supremecourt.gov/opinions/24pdf/24a884_new_g314.pdf), the Court held that federal courts lack authority under the Judiciary Act to issue universal injunctions beyond relief traditionally available in equity.

Watters therefore focused relief on Bartel and ASG. Another organization planning comparable advertising may need its own legal challenge or another recognized basis for protection.

This fragmented result creates uncertainty during an election. Officials retain a law that a federal judge considers constitutionally vulnerable, but relief does not automatically cover every speaker.

Campaigns may respond in different ways. Some will use disclosures voluntarily, some will avoid synthetic imagery, and others may proceed while preparing constitutional defenses.

For campaign staff, the difference is concrete: a mailer may require legal review before printing, a social-media video may be withheld during the period when it would matter most, and a small organization may abandon a message because it cannot afford rapid litigation.

The ruling also does not establish whether ASG’s planned advertisements are ethical, accurate, or persuasive. Constitutional protection is not an endorsement of a message’s truth or quality.

That separation is essential. Courts can protect offensive or misleading political expression while voters, opponents, and journalists criticize it forcefully.

Nor does the decision prove that disclosure rules never work. Statutes targeting commercial advertising, campaign sponsorship, or factual funding information operate under different doctrines.

Even political disclaimers can survive when they provide neutral information and meet appropriate constitutional standards. The exact wording and burden remain decisive.

Montana’s current notice appears vulnerable because it does more than identify a production method. It characterizes the communication as falsely appearing authentic or truthful.

For a plainly metaphorical image, that mandated description may misstate how the message functions. For a realistic impersonation, the same description may provide valuable context.

One standard struggles to cover both examples. The court’s skepticism reflects that mismatch between the law’s broad language and the varied forms of synthetic political media.

The dispute also leaves enforcement mechanics unclear. Regulators would need evidence showing who created the content, which tools were used, and what the sponsor knew.

Generative systems can contribute only part of an image. A campaign might start with a photograph, use automated background replacement, and finish the work through manual editing.

Attribution becomes harder when contractors, consultants, and outside groups exchange unfinished assets. Legal responsibility may depend on records unavailable during a short campaign window.

These practical limits do not invalidate regulation by themselves. They increase the importance of precise definitions and predictable procedures.

A speaker needs to know what triggers a label before distributing material. A candidate needs a fast remedy when synthetic impersonation threatens actual voter participation.

Montana’s statute tried to serve both needs through one framework. The injunction suggests that its balance favored regulation too heavily when applied to ASG.

Three Signals Will Decide What Comes Next

The next phase will show whether Montana defends the present law, rewrites it, or becomes another lasting limit on state deepfake regulation.

The first signal is an appeal. State officials can ask the Ninth Circuit to review whether the injunction applied First Amendment standards correctly.

An appeal would test the state’s argument that disclosure offers a narrower alternative to banning speech. It would also clarify how courts should handle satire exceptions and synthetic political imagery.

If the Ninth Circuit affirms the order, other western states will face stronger pressure to review similar statutes. A reversal would give disclosure-based laws more room to operate.

The second signal is the final disposition of Bartel and ASG’s lawsuit. A preliminary finding of likely success is important, but it is not a permanent judgment.

The parties could litigate the merits, settle, or seek a revised enforcement interpretation. A final injunction would create a firmer precedent than the current temporary protection.

Watch whether the court separates particular provisions. A judge might preserve rules aimed at realistic impersonation while rejecting language covering satire or broader reputational harm.

The third signal is Montana’s legislative response. Lawmakers could replace the current notice with a shorter factual label or narrow the law to specific election harms.

A revised statute might target false voting instructions, unauthorized candidate impersonation, or synthetic media that a reasonable person would consider authentic.

Each option involves tradeoffs. A narrow law leaves more misleading content unregulated, while a broad law risks another constitutional defeat.

Campaign behavior will provide an immediate practical test. ASG’s forthcoming materials can show whether the ruling encourages more synthetic images during the general election.

Journalists should examine whether recipients understand those images as metaphor, parody, or documentary evidence. That evidence will shape future arguments about actual voter harm.

Candidates also have nonlegal responses. They can publish original images, document alterations, and address fabrications before they spread through local networks.

News organizations will carry more responsibility when formal enforcement recedes. Verification should identify the underlying source image, material edits, and the message’s sponsor.

Technology providers face a related choice. They can attach provenance records, restrict certain impersonation features, or leave political use primarily to customers.

None of these measures replaces public policy. Together, they reduce pressure on lawmakers to make government officials the primary judges of political truth.

For knowledge workers tracking election technology, the case offers a broader lesson. AI governance turns on definitions, institutional authority, and remedies more than the novelty of the software.

A rule can identify a genuine social harm and still fail because its enforcement mechanism burdens protected activity. Technical accuracy does not resolve that constitutional design problem.

The Montana AI campaign ad law now sits at that boundary. Its goal of informing voters remains understandable, but its application to political satire triggered a serious First Amendment obstacle.

Readers should watch the appeal record, any final injunction, and the next legislative draft. Those three developments will determine whether this ruling stays narrow or reshapes AI election rules.

The harder question will remain even after the litigation ends: who should label a political image as deceptive when its falsity is also the vehicle for criticism?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page