Generating an ad in someone's face and voice used to take a shoot, a signed release, and a paid performer. AI collapsed all three into a prompt — and with them, the friction that used to make consent automatic. The result is a fast-growing category of unauthorized AI likeness ads that runs a full spectrum: outright deepfake scams that put Tom Hanks or MrBeast behind a fake giveaway, unlicensed endorsements that fabricate a creator recommending a product they've never touched, licensed avatars quietly reused past the scope their owner agreed to, and digital replicas of the dead pressed into campaigns their estates never approved. Every point on that spectrum lands on the same fault line: consent. This guide maps the whole category. It defines what an unauthorized AI likeness ad actually is, sorts the spectrum from fraud to license overreach so you can tell where a given ad sits, breaks 'consent' into the three separate questions it's usually collapsed into — whose identity, what scope, and did the viewer get told — and lays out the 2026 legal map (right of publicity, the ELVIS Act, California's digital-replica statutes, the FTC impersonation rules, the pending NO FAKES Act, and Denmark's copyright-your-face proposal) alongside the platform policies that get you actioned long before any court does. Then it flips the frame: your likeness is not only a liability to defend, it's an asset you can own, license, and monetize — and the producers who build on an identity they control instead of one they borrowed are the ones this whole shift rewards. It closes with the concrete production discipline for making likeness-based ads that survive detection, policy, and law.
An unauthorized AI likeness ad is an advertisement that uses AI to generate a recognizable person's face, voice, or both without valid consent — or beyond the scope of the consent they actually gave. The definition has two halves, and the second half is the one people miss. Everyone understands the first: cloning a celebrity you have no relationship with is unauthorized. The subtler and now more common failure is generating past the bounds of a real agreement — a face you licensed for one product showing up promoting another, a voice cleared for a single campaign reused a year later, an avatar approved for social ads quietly repurposed into a paid endorsement the person never signed off on. Both are unauthorized. Consent is not a switch that flips on once; it is a scope, and stepping outside it is the same category of wrong as never having it.
This matters because AI removed the friction that used to make consent automatic. Producing an ad in someone's face and voice used to require a shoot, a performer, and a signed release — the release happened because you physically could not make the ad without the person in the room. Generative avatars and voice cloning severed that link: now the face and voice can appear without the person, without the room, and without anyone ever asking. The release did not become less necessary; it just stopped being forced by the production process. That is the whole shape of the problem — a legal and ethical requirement that used to be structurally guaranteed is now optional at the point of creation, which is exactly when it gets skipped.
Not every unauthorized likeness ad is a scam, and treating them all as the same thing makes it harder to see where your own production might sit. The category runs along a spectrum. At the criminal end are deepfake fraud ads: a manipulated face and voice selling something the person never endorsed, usually as the front for a scam. This is the version that made headlines — in October 2023 Tom Hanks, MrBeast, and Gayle King all publicly warned that their likenesses were being used without permission in ads, MrBeast's deepfake fronting a fake iPhone giveaway that asked 'winners' to pay a small fee, Hanks's face attached to a dental plan he had nothing to do with. Steve Harvey's cloned voice has pushed Medicare scams. These are unauthorized likeness plus fabricated endorsement plus consumer fraud stacked together, and they are illegal several times over.
The middle of the spectrum is where legitimate businesses actually get caught. It is not fraud; it is overreach. An advertiser licenses a creator's likeness for a defined use, then generates content outside that scope — more platforms, a longer run, a different product, a tone the person would not have agreed to. Or a rights intermediary claims a license it does not clearly hold and sublicenses a face it never truly cleared. The gap between what a likeness deal permits and how an AI campaign ends up using it is a documented and growing dispute, and it is why California passed a law aimed squarely at over-broad digital-replica contract clauses. An in-scope license is a defense; a license stretched past its terms is not, and 'we had a contract' is not the same as 'the contract covered this.'
At the far end sits a quieter case that catches producers off guard: the deceased. A digital replica of a dead public figure feels like fair game to some advertisers because the person cannot object — but the right of publicity survives death in many states, and California's AB 1836, effective January 1, 2026, makes producing or distributing a digital replica of a deceased personality's voice or likeness without prior estate consent grounds for liability. A dead celebrity's likeness is controlled by an estate or rights-holder and requires a license exactly as a living person's does. Assuming otherwise is one of the more expensive mistakes in the category.
The word consent hides three distinct questions, and unauthorized likeness ads usually fail on the two people forget rather than the one they remember. The first question is whose identity — did the actual person, or their estate, agree to be depicted at all? That is the one everyone thinks of. The second is what scope — even with a yes, what exactly did they agree to? Which products, which platforms, which duration, which framing? A yes to a fitness brand's Instagram campaign is not a yes to a supplement company's national TV buy. Scope is where a genuine agreement turns into a genuine violation, and it is invisible unless you read the terms as carefully as you read the technology.
The third question is not about identity at all: was the viewer told? Disclosure is a separate obligation from consent, and the two do not substitute for each other. You can own a likeness completely — your own face, your own voice — and still violate platform policy and spreading synthetic-media rules by failing to label the ad as AI-generated, because a UGC-style spot is designed to read as filmed footage of a real moment, which is exactly what disclosure rules exist to flag. And you can disclose flawlessly while using a face you had no right to. A defensible likeness ad answers all three: a yes from the right person, generation that stays inside the scope of that yes, and an AI-content label on the finished spot. Most producers check the first, assume it covers the second, and forget the third. The consent-versus-disclosure split is worked through in more depth in the AI likeness detection for UGC ads guide; this page's point is narrower — treat them as three boxes, and tick all three.
The foundational protection is the right of publicity — the long-standing rule that a person controls the commercial use of their name, image, and voice — which an unauthorized AI endorsement violates directly and which exists, in some form, in most states. On top of it sits a fast-growing layer of AI-specific statutes. Tennessee's ELVIS Act, signed in March 2024, expanded the state's publicity law to explicitly cover unauthorized AI voice clones and deepfakes. California enacted two aimed at digital replicas: AB 2602, effective January 1, 2025, voids over-broad contract clauses that would let a studio or brand use a performer's digital replica without informed, represented consent; and AB 1836, effective January 1, 2026, extends the protection to deceased personalities. By 2026 a large majority of states have some deepfake-specific legislation, and a meaningful subset address commercial likeness use specifically.
At the federal level the picture is a mix of shipped and pending. The FTC finalized a rule protecting governments and businesses from AI-driven impersonation and proposed extending the same protection to individuals, reflecting its stated view that AI deepfakes threaten to turbocharge impersonation fraud. The federal TAKE IT DOWN Act targets non-consensual intimate imagery, including AI-generated deepfakes. And the NO FAKES Act — reintroduced in a revised form in 2026 and advanced by the Senate Judiciary Committee in June 2026 — would, if it becomes law, create a federal right against unauthorized digital replicas of anyone's voice or likeness, with a notice-and-takedown process. As of this writing it has passed committee but not become law; treat it as the direction of travel, not a rule you can rely on yet. Anyone whose likeness is already being misused should see how to protect your likeness from AI deepfakes and, for a platform claim, how to respond to a YouTube AI likeness claim.
The idea is going global, and one approach is worth watching because it reframes the whole question. In June 2025 Denmark proposed amending its copyright law to give every individual a copyright-style right over their own face, features, and voice — letting people issue takedown notices and claim compensation for unauthorized deepfakes even without proving reputational harm. The European Commission has pushed back on treating likeness as copyright, and the proposal is not settled law, so describe it accurately: a notable signal that jurisdictions are moving to make your likeness something you affirmatively own, not just a fraud you can sue over after the fact. The practical read across the whole map is consistent — the direction is unambiguously toward stronger, more explicit likeness rights, so building on borrowed faces is a bet against every legislative trend at once.
Long before a lawsuit, the platform is the enforcer that actually touches your account. Platform ad policy now treats an unauthorized likeness as a violation you can be actioned for regardless of what the law says in your state, and each major platform has built tooling around it. YouTube shipped a named likeness-detection tool — a creator enrolls a face reference and the system surfaces AI content matching their identity for review or removal — the clearest shipped example of likeness detection as a product. TikTok requires advertisers using a voice clone or digital likeness to upload consent documentation (legal name, permitted use, campaign duration, signed release) and is expanding AI-content detection broadly; it has also been testing an opt-in likeness-detection tool for creators. Meta applies AI-info labels and gives users controls over AI generation of their likeness, covered in the walkthrough on turning off Meta AI image generation of your likeness.
The operational consequence is that the enforcement you will actually feel is faster and lower-threshold than the legal one. A court case takes months; a platform takedown or ad-account suspension takes days, sometimes hours, and it does not wait for a ruling on whether your license was valid — it acts on a match and a policy, and puts the burden on you to produce the consent record. That inverts the usual assumption that you are safe until someone sues. In practice you are exposed the moment a detection system flags an identity you cannot instantly prove you had the right to use. The record — the signed release, the scope, the dates — is not paperwork for a hypothetical trial; it is the thing that resolves a platform review before it becomes a suspension.
The whole conversation so far frames a likeness as something to defend — a thing that can be stolen, faked, and misused. That framing is correct but incomplete, and the incomplete half is where the opportunity is. The same laws that make an unauthorized clone a liability make an authorized one an asset. If your face and voice are legally yours to license, then a digital replica of you is a product you can sell, on terms you set, for scopes you approve — a spokesperson that scales without a shoot, that you own outright, and that no one else can lawfully reproduce. The creator-rights movement behind the ELVIS Act, AB 2602, and NO FAKES is not only defensive; it is establishing the property right that makes owning your synthetic self commercially real.
This is the fork that separates the producers who will thrive from the ones who will keep getting suspended. One group builds campaigns on identities they borrowed — trending faces, scraped voices, over-stretched licenses — and lives one detection match away from a takedown. The other builds on an identity they own end to end: their own face, or a fully-synthetic character that belongs to them and clones no one. The first group's core asset is a legal exposure that compounds as the laws tighten. The second group's core asset appreciates — a consistent, owned, reusable likeness becomes more valuable the more the surrounding rules reward provenance and punish theft. The safest input is also the most valuable one, which is a rare and worth-noticing alignment. The identity-first case for building this way is argued in full in the identity-first AI video guide, and the voice half of the same risk in the AI voice-fraud guide.
The production discipline follows directly from the three consent questions and the enforcement reality. First, the identity must be one of three defensible things and never a fourth: your own face and voice; a real person's with a signed, in-scope release; or a fully-synthetic character that is not a clone of any identifiable real individual. A borrowed public face is never on the list, no matter how good the model. Second, generate only inside the license scope — if the release covers social ads for one product for six months, that is the boundary, and expanding the use means re-licensing first, not generating and asking later. Third, keep the consent record attached to the asset itself, not buried in an inbox, because when a detection match or platform review lands, the release is what turns a suspension into a five-minute clarification.
Fourth, disclose regardless of ownership. Even a fully-owned persona built from your own face needs the platform's AI-generated label, because the format is engineered to read as real footage and disclosure rules and platform policies increasingly demand the label independent of consent — the guidance in AI UGC ads covers the format's mechanics. Fifth, and this is the strategic one: favor a reusable owned identity over one-off clones of whoever is trending. An identity you generate from repeatedly is one you have already cleared once and can defend forever; a fresh clone for every campaign is a fresh liability every time, and it never accrues into an asset. The producers who lose to detection and law are optimizing for the face that converts this week. The ones who win are compounding a face they own — which is the only version of this that gets safer, not riskier, as the rules tighten.
The defensible production model above has a single load-bearing requirement: an identity you own and can prove, that you generate from repeatedly instead of cloning fresh each time. That is a description of an architecture, not a policy — and it is the architecture Kompozy is built around. Kompozy is a content generation and multi-platform publishing engine, and its persona layer is an AI Influencer pool: a set of defined identities you create and control, one designated as primary, each a face and voice you own rather than an arbitrary uploaded likeness. You build the avatar once — your own face via a HeyGen avatar and Gemini face-lock, or a consistent synthetic character that is yours and clones no real person — and every ad after that is generated from that owned cast. The face in the ad is never a borrowed one, because the system has no step where a borrowed one gets uploaded.
That inverts the risk the rest of this guide describes into leverage. Because the persona is a defined, reusable asset rather than a per-campaign clone, the consent question is answered once, at the source, and then compounds — you are scaling a likeness you hold, the exact asset the creator-rights laws are busy making valuable, not manufacturing a fresh liability for each spot. The Persona Brief governs voice and framing so the avatar stays on-brand across everything it appears in, which also keeps generation inside the scope you intend rather than drifting into tones or claims the identity was never meant to make. And because Kompozy is the publishing layer, the disclosure half rides the ship step: one source expands across 18 output formats — Persona Shorts and avatar video, images, carousels, quote graphics, blogs, newsletters — and fans to the eight social platforms plus blog and email, where you apply each platform's AI-generated label as part of publishing instead of remembering it ad by ad.
The governance is the part that keeps volume from outrunning the discipline the category now demands. A per-post review gate on Autopilot keeps a human on the approve step, so the ad an owned avatar generates still passes a set of eyes before it ships — the difference between scaling a defensible identity and mass-producing exposure. The taxonomy at the top of this page splits producers into two futures: one borrows faces and lives a detection match away from a takedown, the other builds on a face it owns and watches that asset appreciate as the laws tighten. Kompozy is built for the second future by construction — an owned persona pool, brand-governed generation, per-platform disclosure, and a review gate — which is why the safe input and the valuable one turn out to be the same input. For the detection-technology side of the same problem, the AI likeness detection for UGC ads guide covers what the platforms are scanning for and why an owned identity is exactly what they are built to leave alone.
It's any advertisement that uses AI to generate a recognizable person's face, voice, or both without their consent — or beyond the scope they actually agreed to. It covers a spectrum: outright deepfake scams that put a celebrity behind a fake giveaway, fabricated endorsements of a product a creator never touched, licensed avatars reused past their contract terms, and digital replicas of deceased people used without estate permission. The common thread is that the identity in the ad was used without valid, in-scope consent.
In most commercial cases, yes. Unauthorized use of a person's face or voice to sell something violates the right of publicity in most states, and a growing stack of AI-specific laws adds to it: Tennessee's ELVIS Act and California's AB 2602 and AB 1836 protect voice and likeness against unauthorized digital-replica use, the FTC's impersonation rules target AI-driven impersonation fraud, and the pending federal NO FAKES Act would create a nationwide likeness right. Platform ad policies also treat it as a violation independent of the law.
They're two separate obligations and satisfying one does not satisfy the other. Consent is about whose identity you used and on what terms — did the person (or estate) agree, and does what you made fall inside that agreement's scope. Disclosure is about telling the viewer the content is AI-generated. You can have full consent for a likeness and still break disclosure rules by not labeling the ad, and you can label an ad perfectly while still using a face you never had the right to.
Only within its scope. A license is not a blank check — it grants specific uses (which products, which platforms, how long, what tone), and generating outside those bounds is a breach, not a covered use. California's AB 2602 exists precisely because over-broad digital-replica clauses were being used to claim far more than performers intended. Read the scope, generate inside it, keep the signed record with the asset, and re-license before you expand the use. An in-scope license plus the right AI-content disclosure is the defensible position.
Generally not without permission from their estate. California's AB 1836, effective January 1, 2026, makes producing or distributing a digital replica of a deceased personality's voice or likeness without prior estate consent grounds for liability, and several states protect a post-mortem right of publicity. The safe assumption is that a dead public figure's likeness is controlled by their estate or rights-holder and requires a license exactly as a living person's would.
Build on an identity you can defend. Use your own face and voice, a real person's with a documented in-scope release, or a fully-synthetic character that is not a clone of any real individual — never a borrowed public face. Keep the consent record attached to the asset, generate only inside the license scope, apply each platform's AI-generated label, and prefer a reusable owned identity over one-off clones. Likeness detection and the new laws are built to catch borrowed identities, not owned ones.
An unauthorized AI likeness ad is any ad that uses AI to generate a recognizable person's face or voice without valid, in-scope consent — spanning outright deepfake scams, fabricated endorsements, licensed avatars reused beyond their terms, and digital replicas of the dead. In 2026 it collides with the right of publicity, AI-specific laws like Tennessee's ELVIS Act and California's AB 2602 and AB 1836, the FTC's impersonation rules, and the pending NO FAKES Act, plus platform policies that act first. The defensible production move is to build on a likeness you own or have licensed in scope, keep the consent record, and disclose.
Get started → · ← All guides · Compare Kompozy vs other tools