How close does the deep fake need to be to the original? What we saw with DALLE2 was that each person whose face was restricted made a hole in the latent space of all faces. After enough celebrities faces were restricted, there were so many latent space holes that the algorithm couldn't make faces at all since every producable face was a certain "distance" away from a restriction.
Sure, you can make lora training on unconsenting people illegal and also make particular prompts illegal, but there is enough raw data and vague prompts to mold a generation into something that looks like it was done the illegal way without breaking either of those two restrictions.
There are billions of people. Find the right one, and a "reasonable person" could not tell the difference.
Image a law that said you cannot name your baby a name if someone else's name starts with the same letter. After 26 names, all future names would be illegal. The law essentially would make naming babies illegal.
The "alphabet" in this case is the distict visual depiction of all people. As long as the visual innumeration of "reasonable people" is small enough, it essentially makes any generation illegal. Conversely, if "reasonable people" granulated fine enough, it makes avoiding prosecution trivial by adding minor conflicting details.