Case Study Analysis
Name: Cipta Surya Ananda
NIM: 2409010020
Case 1 – Deepfakes and AI Ethics
In August 2025, TikTok users were stunned by a viral video featuring a prominent Indonesian public figure making a controversial political statement. However, fact-checkers later revealed that the video was not authentic—it was a deepfake created using AI technology.
This incident highlights significant ethical and digital risks. From an ethical standpoint, deepfakes blur the line between fact and fiction, posing a threat to reputations, spreading misinformation, and undermining public trust. It also underscores the ease with which people share unverified content, especially since social media algorithms prioritize engagement over accuracy.
From an AI ethics perspective, the deepfake issue contradicts UNESCO’s human-centered AI principle, which calls for fairness, accountability, and transparency. Using someone’s likeness without their consent goes against the fundamental value of respecting human dignity.
Several Indonesian laws are relevant in this context:
- The ITE Law (Law No. 1 of 2024, Articles 27A-27B) prohibits the dissemination of false or harmful electronic information, including content that can harm someone’s reputation.
- The Personal Data Protection (PDP) Law No. 27 of 2022 protects biometric data, including facial images and voice recordings. Using this data without consent, even in AI-generated content, is a violation of privacy.
- Copyright Law No. 28 of 2014 applies if a deepfake reuses video materials or recordings without the creator’s permission.
To prevent similar issues, universities could implement a Campus AI Code of Ethics, which would include: - Transparency: Clearly label all AI-generated content with a disclaimer.
- Accountability: Students and staff must take full responsibility for what they publish online.
- Consent: Never use anyone’s likeness, photo, or voice without prior approval.
- Traceability: Disclose which AI tools were used, when, and for what purpose.
- Education: Conduct workshops on digital literacy to help students detect deepfakes.
In summary, this deepfake case highlights the immense potential of technology, but also the dangers it poses when ethical considerations are ignored. Digital literacy must include the ability to question, verify, and act responsibly in the online world.
Case 2 – The Ethics of AI in Academia
A student secretly used ChatGPT and MidJourney to complete their thesis without disclosing it, raising a serious ethical question about academic integrity in the age of AI. The primary ethical concern here is not the use of AI itself, but the lack of transparency and honesty.
From an academic ethics perspective, presenting AI-generated content as one’s own work is still considered plagiarism. It breaches the principle of intellectual honesty, which is essential in education. According to UNESCO’s AI Ethics Principles (2021), the ethical use of AI must adhere to two core values: transparency and accountability. This means users must openly disclose when AI tools have been used and remain responsible for checking the accuracy and originality of the content they generate.
Legally, Copyright Law No. 28 of 2014 (Article 40) states that authorship is linked to creative input. If AI generates content automatically, there is no clear human creator, and submitting AI-generated work under a student’s name misrepresents authorship, which could be deemed academic fraud. The ITE Law (2024) also prohibits manipulating electronic data to mislead others.
To address this issue, universities should establish clear guidelines for ethical AI use in academia. These could include:
- Disclosure Requirement: Students must disclose if and how they used AI tools in their work.
- Verification Responsibility: Even when AI is used, students must ensure the accuracy and originality of their work.
- No Blind Copying: Directly copying AI-generated content without review or modification is prohibited.
- Faculty Oversight: Lecturers can use AI-detection tools, but the focus should be on education rather than punishment.
- AI Literacy Training: Students should be taught how to use AI ethically and avoid over-reliance on it.
Ultimately, AI should be viewed as a co-pilot, not a ghostwriter. It can assist with idea generation, structure, and design, but human creativity and critical thinking should remain central to academic work.
Case 3 – Data Privacy and Cloud Breach
In May 2025, a significant data breach occurred at a university in Indonesia, exposing the personal information of thousands of students, including ID numbers, transcripts, and photos. This incident highlights the critical importance of digital security and data ethics within educational institutions.
The breach may have been caused by phishing emails, weak passwords, or misconfigured cloud storage—common vulnerabilities when data systems are not secured with encryption or multi-factor authentication. This issue also reflects a lack of digital awareness among both staff and students.
Under the Personal Data Protection (PDP) Law No. 27 of 2022, universities are considered data controllers and are responsible for safeguarding all personal data they collect.
- Articles 35–39 mandate that organizations implement stringent security measures and restrict data access to legitimate purposes only.
- Article 46 requires institutions to notify affected individuals immediately after a breach.
Failure to comply could result in legal penalties (Articles 57–58).
The ITE Law (2024) also prohibits unauthorized access to electronic systems, and Kominfo Regulation No. 20/2016 mandates strong encryption for sensitive data.
To enhance digital security, universities should adopt a comprehensive data protection policy that includes: - Two-Factor Authentication for all campus systems.
- Data Encryption during storage and transmission.
- Regular Security Audits and ethical hacking simulations.
- Incident Response Plans, including mandatory 72-hour notifications to users and authorities.
- Digital Literacy Training for staff and students on safe online practices.
This case serves as a reminder that cybersecurity is not just a technical issue—it’s an ethical responsibility. Protecting personal data is integral to maintaining trust. In the digital age, privacy is a fundamental aspect of human dignity, and every institution must treat it as such.

Leave a Reply