// HOW-TO · COMPLIANCE

How to make an AI ad using someone's likeness — legally, with consent (2026)

Make an AI likeness ad you can defend: pick an identity you're allowed to use, get an in-scope written release, generate inside it, and disclose it correctly.

Last verified · 2026-09-27 · by Moe Ameen

AI collapsed a face-and-voice ad from a shoot, a performer, and a signed release into a single prompt — and quietly removed the friction that used to make consent automatic. The face can now appear without the person ever being in the room, which is exactly when the release gets skipped. This walkthrough is the production discipline for making a likeness-based ad you can actually defend: one that survives a platform's likeness-detection scan, its ad policy, and the fast-growing stack of 2026 likeness laws.

The task is not "can I generate this face" — the models will happily generate almost anyone. The task is "can I prove I was allowed to." That splits into three separate boxes most producers collapse into one: whose identity you used, what scope they agreed to, and whether the viewer was told it's AI. Own all three and the ad is defensible; miss any one and it isn't, no matter how good the render looks. This is a practitioner checklist, not legal advice — for a big spend, a regulated category, or anyone's likeness but your own, confirm current rules and, where warranted, with counsel.

The steps

  1. Decide whose face you are allowed to use — and it must be one of three. A defensible likeness ad is built on exactly one of three identities: your own face and voice; a real person's, with a signed and in-scope release; or a fully-synthetic character that is not a clone of any identifiable real individual. A borrowed public face — a celebrity, a trending creator, a scraped likeness — is never on the list, however convincing the model is. Pick the identity before you write the ad, because it determines every step after it.
  2. Get the release in writing before you generate anything. If the identity is a real person other than you, get their consent in writing first — a release that names them, the permitted use, and a signed authorization. Generating first and papering it later is how a genuine agreement turns into a genuine violation. For a deceased person, the likeness is almost always controlled by an estate or rights-holder and requires their consent exactly as a living person's does; do not treat 'they can't object' as permission.
  3. Write the scope down explicitly — a license is not a blank check. Consent is a scope, not a switch. Pin down, in the release, which products the likeness can promote, which platforms it runs on, how long it runs, and what tone or claims it may make. A yes to one brand's Instagram campaign is not a yes to a different product's national buy. California's AB 2602 (effective January 1, 2025) exists precisely because over-broad digital-replica clauses were claiming more than performers intended — it voids provisions that lack a reasonably specific description of the uses. Vague scope is not more permission; it's less.
  4. Generate strictly inside that scope. Produce only the ad the release actually covers. If the scope is social ads for one product for six months, that is the wall — a different product, a longer run, or a tone the person would not have agreed to is a breach, not a covered use. When you want to expand, re-license first and generate second. 'We had a contract' is not the same as 'the contract covered this,' and the gap is where legitimate businesses get caught.
  5. Disclose it as AI — and upload consent docs where the platform demands them. Consent and disclosure are two different obligations; satisfying one does not satisfy the other. Even a fully-owned persona built from your own face needs the platform's AI-generated label, because a UGC-style spot is engineered to read as filmed footage. Apply each platform's label (Meta's 'AI info', TikTok's AIGC label, YouTube's altered-content disclosure). TikTok's ad policy separately bars using a real person's likeness or voice without their permission, so keep the signed release on hand — if TikTok's review flags the ad, you'll need to produce it.
  6. Attach the consent record to the asset, not your inbox. Store the signed release, the scope, and the dates with the creative itself so anyone who touches the ad can find them. Platform enforcement moves faster and at a lower threshold than any court: a detection match or ad-account review can suspend you in hours, and it puts the burden on you to produce proof you had the right to the face. A release you can surface in five minutes turns a suspension into a clarification; one buried in an email thread turns it into downtime.
  7. Gate every ad on a human review, and reuse one owned identity. Before anything ships, run a two-box check: is the identity one you can prove in scope, and is the AI label applied? At volume this cannot be ad-hoc, so bake it into an approval step. Then make the strategic choice: favor one reusable, already-cleared identity over a fresh clone of whoever is trending each week. An owned identity is cleared once and defended forever; a new clone per campaign is a new liability every time and never accrues into an asset.

Common gotchas

  • Treating consent and disclosure as one thing. You can own a face completely and still break policy by not labeling the ad; you can label perfectly and still use a face you had no right to. They are separate boxes — tick both.
  • Assuming a signed license is a blank check. It grants specific uses; generating outside the scope (new product, new platform, longer run) is a breach, not a covered use.
  • Thinking a deceased person's likeness is fair game because they can't object. The right of publicity survives death in many states, and California's AB 1836 (effective January 1, 2026) makes an unauthorized digital replica of a deceased personality grounds for liability.
  • Using a borrowed public face because the model renders it well. Render quality is irrelevant to whether you were allowed to use the identity — likeness detection and the new laws are built to catch borrowed faces specifically.
  • Scrubbing C2PA/provenance metadata to dodge a platform's AI label. Detection keeps improving, and for regulated ad categories non-disclosure is itself the violation.
  • Running a rotating cast of anonymous 'real customers.' Each disposable synthetic stranger staged as an unpaid customer is a separate fake-testimonial exposure; a single declared, consented persona is not.
Legal note

This is a practitioner checklist, not legal advice, and the law is moving fast — verify current rules and consult counsel for a large spend, a regulated category, or anyone's likeness but your own. The foundation is the right of publicity, which in most states lets a person control the commercial use of their name, image, and voice; an unauthorized AI endorsement violates it directly. On top of it: Tennessee's ELVIS Act (signed March 2024) explicitly covers unauthorized AI voice clones and deepfakes; California's AB 2602 (effective January 1, 2025) voids over-broad digital-replica contract clauses, and AB 1836 (effective January 1, 2026) extends protection to deceased personalities. Federally, the FTC finalized an impersonation rule and proposed extending it to individuals, and the NO FAKES Act — advanced by the Senate Judiciary Committee in 2026 — would create a national likeness right if enacted, but as of this writing is not law. Platforms enforce their own likeness and disclosure policies independent of all of it, usually first.

Where Kompozy fits

The failure mode this checklist is built to prevent is a scattered pile of one-off clones — a fresh face uploaded for every campaign, each one its own unproven paperwork and its own liability. [Kompozy](/) removes that mode by construction: it doesn't have an "upload a face for this ad" step. Its persona layer is an AI Influencer pool — a small set of defined identities you create and control, one designated primary — so the identity in step one is settled once, at the source, and every ad after that is generated from that owned, already-cleared cast. You clear the consent box a single time for the persona, not once per creative, which is the operational difference between scaling a defensible identity and mass-producing exposure.

Scope enforcement lives in the [Persona Brief](/glossary/persona-brief). It governs the persona's voice, claim boundaries, and banned-word rules on every generation, so the ad stays inside the tone and claims you intended rather than drifting into a product or framing the release never covered — step four's discipline, applied automatically instead of remembered ad by ad. And because Kompozy is also the publishing layer, disclosure rides the ship step: one consented persona expands across [18 output formats](/glossary/output-buckets) — [Persona Shorts](/glossary/persona-shorts) and [avatar video](/glossary/avatar-video), images, carousels, quote graphics, blogs, newsletters — and fans to the eight social platforms plus blog and email, where you apply each platform's AI label as part of publishing. A per-post review gate on [Autopilot](/glossary/autopilot) keeps a human on the approve step, which is the natural place to run the two-box check and confirm the label before anything goes out.

Be clear on the boundary: Kompozy produces and distributes the on-brand creative, but the signed release, the TikTok consent upload, and the final call on scope are your actions, not the engine's — it can't grant you rights to a face you don't hold. What it does is make the safe input the default one: an identity you own, cleared once, generated from repeatedly, with disclosure built into the publish. That is exactly the identity [likeness detection](/glossary/likeness-detection) is built to leave alone, and the [unauthorized AI likeness ads](/guides/unauthorized-ai-likeness-ads) guide argues the fuller case for why an owned face appreciates while a borrowed one compounds risk. Pricing is credit-based: Starter ($99/mo, 5,500 credits) fits a solo advertiser running a persona or two, Pro ($299/mo, 18,000 credits) suits an agency producing likeness ads across many brands, and Enterprise is custom.

Frequently asked questions

Can I legally use someone's likeness in an AI ad?

Yes, if you have their valid, in-scope consent. Using a real person's face or voice to sell something requires permission — a signed release in the case of an ad — because unauthorized commercial use violates the right of publicity in most states. The permission has to cover the actual use: the products, platforms, duration, and framing you generate. Consent for one campaign does not extend to a different one.

What's the difference between consent and disclosure for a likeness ad?

They're two separate obligations. Consent is about whose identity you used and on what terms — did the person or estate agree, and does your ad fall inside that agreement. Disclosure is about telling the viewer the content is AI-generated via the platform's label. You can have full consent and still break disclosure rules by not labeling, and you can label perfectly while using a face you never had the right to. Clear both.

Do I need a release if I use my own face and voice?

You don't need a release from anyone else, but you still have to disclose. A UGC-style ad built from your own AI avatar is engineered to read as real filmed footage, which is exactly what platform AI-label rules exist to flag — so apply the platform's AI-generated label even when the identity is entirely your own. Owning the likeness settles the consent box; it does not settle the disclosure box.

Does a signed likeness license make the ad safe?

Only within its scope. A license grants specific uses — which products, which platforms, how long, what tone — and generating outside those bounds is a breach, not a covered use. Read the scope, generate inside it, keep the signed record attached to the asset, and re-license before you expand the use. An in-scope license plus the platform's AI label is the defensible position.

Can I use a deceased celebrity's likeness in an AI ad?

Generally not without permission from their estate. The right of publicity survives death in many states, and California's AB 1836, effective January 1, 2026, makes producing or distributing a digital replica of a deceased personality's voice or likeness without prior estate consent grounds for liability. Assume a dead public figure's likeness is controlled by a rights-holder and requires a license exactly as a living person's would.

What happens if a platform flags my likeness ad?

Enforcement moves faster than any court. A likeness-detection match or an ad-account review can restrict or suspend you within hours, and it puts the burden on you to produce proof you had the right to the identity. That's why the signed release, the scope, and the dates need to live with the asset — a record you can surface immediately turns a review into a quick clarification instead of a takedown.

Related tutorials

← All how-to guides · Get Started