---
title: "Likeness, voice rights and deepfakes | Optimize All Academy"
description: "People own their identity A person's face, voice, name and persona are central to their identity and, for public figures and creators, their livelihood…"
url: https://optimizeall.com/learn/responsible-ai-disclosure-and-compliance/likeness-voice-rights-and-deepfakes
updated: 2026-10-05
---

Responsible AI, Disclosure & Compliance · Copyright, likeness and deepfakes · lesson 4 of 11 · 15 min

# Likeness, voice rights and deepfakes

## People own their identity

A person's face, voice, name and persona are central to their identity and, for public figures and creators, their livelihood. AI makes it easy to replicate all of these. Using them without permission can be unlawful, unethical and deeply harmful.

## What counts as a deepfake

A **deepfake** is synthetic or manipulated media that realistically depicts a real person saying or doing something they did not. Not all synthetic media is a deepfake in the harmful sense. Your own consented avatar is synthetic, but used transparently it is not deceptive. The harm comes from **realism combined with lack of consent or deception**.

## The legal landscape, at principle level

Laws vary widely and are changing fast, but several strands apply in many markets:

- **Personality, publicity and image rights:** many jurisdictions protect against unauthorized commercial use of a person's name, image or likeness, and some explicitly cover voice. Several US states have enacted laws on digital replicas and voice. Some European countries have proposed or adopted specific protections against deepfakes of a person's likeness.
- **Passing off, false endorsement and advertising law:** implying someone endorses a product when they do not is misleading under consumer-protection and advertising rules (for example FTC rules in the US and ASA/CAP rules in the UK).
- **Defamation:** synthetic content that damages someone's reputation can be defamatory.
- **Privacy and data protection:** images and voice recordings are personal data; biometric processing attracts stricter rules under GDPR-style laws, including in the UAE and KSA.
- **Cybercrime and criminal law:** impersonation, fraud and non-consensual intimate imagery are criminal offenses in many countries, including under cybercrime laws in Pakistan, the UAE and KSA, and US federal law now specifically addresses non-consensual intimate deepfakes.
- **AI-specific transparency rules:** Article 50(4) of the EU AI Act requires deployers to disclose deepfakes from 2 August 2026, and Saudi Arabia's SDAIA deepfakes guidelines stress consent, labeling and watermarking.
- **Intimate deepfakes:** in the US, the TAKE IT DOWN Act (2025) criminalizes publishing non-consensual intimate images, including AI-generated ones, and requires covered platforms to remove them promptly after a valid request. Many other countries have similar offenses.

## Clear no-go zones

Never create or share:

- Synthetic media of a real person in sexual or intimate contexts without explicit consent. This is illegal in many places and deeply harmful.
- Fake endorsements by celebrities, creators, experts or customers.
- Synthetic political content depicting real candidates or officials saying or doing things they did not.
- Content impersonating a real person to deceive, such as scam calls or fake announcements.
- Parody or satire that a reasonable viewer could mistake for real, especially around politics, religion or public safety.

## When using a real person's likeness is legitimate

With **informed, written consent** covering:

- The specific uses (channels, campaigns, formats, languages).
- Duration and territory.
- Approval rights over scripts and outputs.
- Payment terms.
- Restrictions (no political, adult or unrelated endorsements).
- Revocation and deletion of models and assets.
- For employees: what happens when they leave.

And with **transparent disclosure** to audiences where the content is realistic.

## Your own identity as a creator

- Protect your accounts (two-factor authentication, limited team access) because voice and face models are valuable targets.
- Read brand contracts carefully: watch for clauses granting perpetual or broad rights to create AI replicas of you.
- Consider registering your name or brand as a trademark if relevant.
- Tell your audience how to identify genuine content and what you never do.
- Monitor for impersonation and report quickly.

## Worked example

A Saudi fashion brand wants to "bring back" a popular creator they worked with last year using an AI avatar built from old campaign footage, without contacting her. The agency advises against it: the original contract did not cover AI replicas; using her likeness would imply a current endorsement; and it could breach her image rights, data protection law and advertising rules. Instead they approach the creator for a new deal that includes a clearly scoped, time-limited avatar license with script approval and fair payment. She agrees, and the campaign carries clear disclosure.

## Hands-on: a voice and likeness consent record

Use this as the basis for any AI avatar, voice clone or digital double. Get it reviewed by a lawyer in the relevant market, and keep it with the project files.

```text
AI LIKENESS AND VOICE CONSENT (summary sheet, attach to full contract)

Person:            [full name]            Role: [creator / employee / actor]
Assets captured:   [face video, voice samples, photos], captured on [date]
Model / tool:      [vendor and product], account owner: [company]
Permitted uses:    [channels], [campaigns], [languages], [formats]
Territory:         [countries]            Term: [start] to [end]
Script approval:   Person approves every script before rendering: [yes/no]
Prohibited uses:   political, religious, adult, financial advice, any
                   endorsement outside this agreement, any use after term
Disclosure:        Content will be labeled as AI-generated voice/likeness
Payment:           [fee] plus [per-use fee or royalty], paid [schedule]
Revocation:        Person may withdraw consent with [x] days' notice
Deletion:          On expiry or revocation, voice/face models and source
                   files deleted within [x] days; written confirmation sent
Employees:         Consent is optional, not a condition of employment;
                   models deleted when employment ends unless re-agreed
Signed:            [person]   [company]   Date: [date]
```

And a quick decision check before you create or publish synthetic media of a real person:

```text
1. Is the person real and identifiable (face, voice, name, persona)?      yes -> go on
2. Do we hold written consent covering THIS use, channel and term?        no  -> stop
3. Could anyone reasonably think the person actually said or did this?    yes -> label it
4. Is it political, intimate, financial or health-related?                yes -> do not proceed without legal review
5. Is the consent record and label evidence saved in the project folder?  no  -> fix before publishing
```

## Protecting your own voice and face

- Keep raw voice and face recordings in a restricted folder; they are training data for anyone who gets them.
- When a brand asks for "perpetual, worldwide rights to your likeness in all media now known or later developed", push back: limit term, territory, media and AI use, and add approval and deletion rights.
- Register with your platform's impersonation tools and set up alerts for your name.

## Pitfalls

- "It's just a joke" deepfakes of friends, colleagues or public figures that spread beyond the intended audience.
- Assuming old contracts cover AI uses they never mentioned.
- Using "AI-generated" labels as a license to depict real people however you like.

## Video lecture: Likeness, voice rights and deepfakes

Lecture coming soon · 13 chapters · about 9 minutes. Read the full transcript below.

1. Likeness, voice and deepfakes
2. Why it matters
3. The deepfake test
4. Legal strands
5. No-go zones
6. Legitimate use needs
7. Example 1: Lahore tutoring startup
8. Example 2 (illustrative): Saudi fashion brand
9. Watch me do it: voice clone request
10. Common mistakes
11. Protect your own identity
12. Pushing back: a script
13. Recap + try this now

## Lecture transcript

### Likeness, voice and deepfakes

Imagine opening Instagram and watching yourself recommend a slimming tea you've never tried, in a language you don't speak, to your own followers. The voice is yours. The face is yours. You never said a word of it. For creators, this is no longer science fiction. In this lecture you'll learn what makes synthetic media a harmful deepfake, the legal strands that protect people, the clear no-go zones, how to get consent that actually holds up, and how to protect your own identity.

### Why it matters

Why does this matter so much? Because a person's face, voice, name and persona are part of who they are, and for creators, they're also how they earn a living. AI can now copy all of them from a few minutes of footage. Using someone's identity without permission can be unlawful, unethical and deeply harmful. And for businesses, it's a fast way to lose a partner, a customer base and a reputation. The flip side is that consented, transparent synthetic media can be genuinely useful: dubbing, accessibility, scale.

### The deepfake test

So what exactly is a deepfake? Think of it like a forged signature. Signing someone's name isn't the problem when they asked you to sign on their behalf and everyone knows it. The harm comes when it's realistic, and they didn't agree, or people are deceived. Same with synthetic media. Your own consented AI avatar, clearly labeled, is synthetic but not deceptive. A realistic video of a real person saying things they never said, without consent or disclosure, is the harmful kind. Realism plus lack of consent, or deception. That's the test.

### Legal strands

Several legal strands protect people, and they vary by country. Personality and publicity rights protect against commercial use of someone's name, image, likeness and, in some places, voice; Tennessee's ELVIS Act is one example that explicitly covers voice. False endorsement and advertising law, enforced by bodies like the FTC in the US and the ASA in the UK. Defamation. Data protection, because face and voice are personal data, and biometric processing carries stricter rules, including in the UAE and Saudi Arabia. Criminal law on fraud, impersonation and intimate images. And AI-specific rules, like the EU AI Act's deepfake disclosure duty from August twenty twenty-six, and Saudi Arabia's SDAIA deepfakes guidelines.

### No-go zones

Now, the no-go zones. Never create or share synthetic intimate or sexual imagery of a real person without explicit consent. In the US, the TAKE IT DOWN Act made publishing non-consensual intimate images, including AI-generated ones, a federal crime, and many countries have similar offenses. Never create fake endorsements from celebrities, creators, experts or customers. Never make political content showing real candidates saying things they didn't. Never impersonate someone to deceive, like scam calls. And be careful with parody that people could mistake for real, especially about politics, religion or public safety.

### Legitimate use needs

When is using a real person's likeness legitimate? With informed, written consent that covers the specific uses, channels, languages, territory and duration. Script approval rights. Payment. Prohibited uses, like political or adult content. How to withdraw consent. What happens to the voice and face models afterwards, including deletion. For employees, it must be a genuine choice, not a condition of the job, with a clear answer for what happens when they leave. And where content is realistic, you still disclose to audiences. Consent and disclosure are two separate things. You need both.

### Example 1: Lahore tutoring startup

First example. A Lahore tutoring startup wants its founder's voice to narrate lessons in Urdu, English and Punjabi. The founder is happy, but they still do it properly. She signs a consent record covering the three languages, education content only, two years, with her approval on every script and deletion if she leaves. Each lesson says the narration is AI-generated from her voice. When a parent asks whether the founder really recorded everything, the answer is on screen. No awkwardness.

### Example 2 (illustrative): Saudi fashion brand

Second example, a realistic business scenario with illustrative details. A Saudi fashion brand wants to bring back a creator it worked with last year by building an AI avatar from old campaign footage, without contacting her. The agency says no, and explains why. The original contract never mentioned AI replicas. Using her face now implies a current endorsement. And it risks her image rights, data protection law, advertising rules, and SDAIA's deepfake guidance on consent. Instead, they approach her for a new deal: a twelve-month avatar license, script approval, a clear AI label, and a fee. Illustratively, she agreed, promoted the campaign on her own channels too, and the brand got more reach than the avatar alone would ever have delivered.

### Watch me do it: voice clone request

Watch me do it. A client asks: can we clone our sales director's voice for WhatsApp voice notes to customers? I run the five-question check. One, is she real and identifiable? Yes. Two, do we have written consent for this use, channel and term? Not yet. So I stop and draft a consent record: WhatsApp customer updates only, English and Arabic, one year, she approves every script, deletion if she leaves, and it's optional, not part of her job. Three, could customers think she personally recorded each note? Yes. So every note starts with: this is an AI-generated voice message from our team. Four, is it political, intimate, financial or health-related? No. Five, is the record saved? Now it is.

### Common mistakes

Common mistakes. Just a joke deepfakes of friends, colleagues or public figures that escape the group chat. Assuming old contracts cover AI uses they never mentioned. Treating an AI-generated label as a license to depict real people however you like. A label tells people it's synthetic. It doesn't give you permission. Getting a casual verbal OK from an employee. And forgetting deletion, so voice models sit in a vendor account for years after someone leaves.

### Protect your own identity

Finally, protect yourself. Your raw voice and face recordings are training data for anyone who gets them, so keep them in a restricted folder and turn on two-factor authentication everywhere. Read brand contracts carefully. If you see perpetual, worldwide rights to your likeness in all media now known or later developed, push back. Limit term, territory and AI uses, and add approval and deletion rights. Tell your audience how to spot genuine content from you. And report impersonation quickly using platform tools.

### Pushing back: a script

What does pushing back sound like in practice? Here's a simple script. Thanks for the contract. I'm happy with the usage for this campaign. The likeness clause is broader than the project needs, so I'd like to limit it to the named campaign, the agreed channels and twelve months. Any AI replica of my face or voice needs a separate agreement with script approval, a fee and a deletion date. Most brands accept this, because their legal team drafted a wide clause by default, not because they plan to clone you. And if a brand refuses to limit AI rights at all, that tells you something important about the partnership.

### Recap + try this now

Recap. A harmful deepfake is realistic and lacks consent, or deceives. Publicity rights, advertising law, defamation, data protection, criminal law and AI-specific rules can all apply. Some uses are simply off limits. Legitimate uses need specific, written, revocable consent plus disclosure. Try this now: open one brand or creator contract template you use and add an AI likeness and voice section using the consent record in the lesson: scope, term, approval, payment and deletion. Next module, we move to labeling AI content on platforms.

## Key takeaways

- Deepfakes are realistic synthetic depictions of real people without consent or with deception.
- Publicity rights, advertising law, defamation, data protection and criminal law can all apply.
- Never create fake endorsements, intimate deepfakes, deceptive political content or impersonations.
- Legitimate use needs specific, written consent and transparent disclosure; creators should protect their own likeness.

## Try it

Review one brand or creator contract template and add clauses covering AI replicas of likeness and voice: scope, duration, approval, payment and deletion.

- [Previous: Copyright, AI outputs and training-data questions](https://optimizeall.com/learn/responsible-ai-disclosure-and-compliance/copyright-and-training-data)
- [Next: Labeling AI-generated content on social platforms](https://optimizeall.com/learn/responsible-ai-disclosure-and-compliance/labelling-ai-content-on-platforms)
- [All lessons of Responsible AI, Disclosure & Compliance](https://optimizeall.com/learn/responsible-ai-disclosure-and-compliance)
