Digital Identity and AI: How to Protect Your Brand, Voice, and Likeness from AI-Generated Replicas
- August 20, 2026
- Posted by: allan
- Category: Uncategorized
Artificial intelligence has made it trivially easy to put words in someone else’s mouth — literally. A few minutes of source audio, a commercially available voice-cloning tool, and an attacker can produce a convincing imitation of your CEO instructing the finance team to wire funds to an overseas account. A generative image model can place your brand spokesperson in a competitor’s advertisement. A synthetic media platform can resurrect a deceased founder’s likeness to “endorse” a product the person never touched.
These are not hypothetical risks. A finance worker at a multinational firm wired $25 million in early 2024 after joining a video call that appeared to include the company’s CFO and other executives — every face and voice on the call was AI-generated. In 2025, the CEO of global advertising holding company WPP was targeted when scammers cloned his voice for a fraudulent Teams-style call. Deepfake-based financial fraud losses in the United States reached an estimated $1.1 billion in 2025 — roughly triple the prior year’s figure.
For business owners and executives, this threat operates on two levels. First, your brand, your executives’ voices, and your carefully developed spokespeople can be replicated without consent. Second, your company can inadvertently become a defendant if it deploys AI-generated content that uses a real person’s likeness or voice without proper clearance. Understanding the legal framework — which is developing rapidly at both the state and federal level — is essential for protecting your organization from both directions.
The Right of Publicity: Your Name, Voice, and Face Are Property
The right of publicity is the legal right to control the commercial use of your identity — your name, image, voice, and persona. Unlike privacy rights, which protect you from unwanted exposure, the right of publicity is an intellectual property right. It means that your identity has economic value and that you, not someone else, get to decide how that value is exploited commercially.
The right of publicity is primarily a state law doctrine, and the strength of protection varies significantly by jurisdiction.
California: The Nation’s Most Developed Framework
California’s right of publicity law operates on two tracks. The statutory track, California Civil Code § 3344, prohibits the knowing use of a living person’s name, voice, signature, photograph, or likeness for advertising or commercial purposes without prior consent. The common law track, developed through decades of case law, fills gaps the statute leaves open.
The common law track proved critical in a pair of landmark voice cases. In Midler v. Ford Motor Co., 849 F.2d 460 (9th Cir. 1988), the Ninth Circuit held that Ford Motor Company violated Bette Midler’s common law rights when it hired a singer to imitate her distinctive voice for a television commercial after Midler refused to participate. The court established that when a distinctive voice of a professional singer is widely known and deliberately imitated to sell a product, the imitators have committed a tort in California. Four years later, in Waits v. Frito-Lay, Inc., 978 F.2d 1093 (9th Cir. 1992), a jury awarded Tom Waits $2.375 million — including $2 million in punitive damages — after Frito-Lay used a singer deliberately chosen to sound like Waits in a Doritos radio commercial.
These cases predate AI by decades, but their logic translates directly to voice cloning. If hiring a human to imitate a distinctive voice for commercial purposes constitutes misappropriation, using an AI model trained on that voice to synthesize a commercial performance raises the same — and potentially stronger — legal concerns.
California significantly updated its statutory framework in 2024 and 2025. Governor Newsom signed AB 1836 and AB 2602 in September 2024, creating new requirements for the use of digital replicas of both deceased and living performers. AB 2602, effective January 1, 2025, voids contract provisions that purport to grant rights to a performer’s digital replica unless the performer had independent legal representation or union representation when the provision was negotiated. AB 1836, effective January 1, 2026, prohibits commercial use of a deceased performer’s digital replica in films, television, video games, sound recordings, and similar works without the estate’s consent.
Then, in October 2025, Governor Newsom signed SB 683, which amended § 3344 directly to clarify that “voice” and “likeness” expressly include digital replicas. The amendment also added a right to injunctive relief, requiring a party ordered to cease distribution of an unauthorized digital replica to comply within two business days. The statute provides for $750 in statutory damages or actual damages plus profits, along with punitive damages and attorney’s fees.
California also recognizes a post-mortem right of publicity under § 3344.1, which protects deceased personalities for 70 years after death — recently amended to reach unauthorized digital replicas of deceased individuals’ voices and likenesses.
New York: Expanding to Address the AI Era
New York’s right of publicity statute, Civil Rights Law §§ 50-51, has existed since 1909, making it one of the oldest in the country. Section 50 makes it a misdemeanor to use the name, portrait, picture, or voice of any living person for advertising or trade purposes without written consent. Section 51 provides a private civil right of action for injunctive relief and damages.
New York’s protections historically applied only to living individuals. In 2021, the state enacted § 50-f, creating a post-mortem right of publicity applicable specifically to digital replicas of deceased performers. In December 2025, Governor Hochul signed amendments that broadened § 50-f’s reach by removing the prior “likelihood of deception” requirement — now a plaintiff need only show the digital replica was used without authorization. The amendments also expanded the actionable conduct to cover audiovisual works, sound recordings, and live musical performances.
New York also enacted a synthetic performer disclosure law in 2025, requiring advertisements that use AI-generated synthetic performers to include a conspicuous disclosure of that fact.
Tennessee: The ELVIS Act Puts Voice First
Tennessee became the first state in the nation to explicitly address AI voice cloning when Governor Bill Lee signed the Ensuring Likeness Voice and Image Security Act — the ELVIS Act — on March 21, 2024. The law took effect on July 1, 2024.
The ELVIS Act amends Tennessee’s Personal Rights Protection Act to add an individual’s voice as an expressly protected property right. Before the Act, the statute, in place since 1984, protected only a person’s name, photograph, and likeness. The expansion to cover voice is particularly significant in the context of AI.
The Act prohibits using an AI voice-cloning tool to create an unauthorized replica of a person’s voice for commercial purposes. Critically, it goes one step further than most state statutes: it creates direct liability for any person who “makes available an algorithm, software, tool, or other technology, service, or device” whose “primary purpose or function” is producing unauthorized voice recordings of an individual. This means the liability chain can reach the platform enabling the cloning, not just the end user who deploys the fake voice.
Violations can result in civil liability and, in some circumstances, criminal prosecution as a Class A misdemeanor. The ELVIS Act applies to all individuals — not just performers or public figures — making it relevant to any business owner or executive whose voice could be replicated.
Other States Worth Knowing
Indiana has one of the broadest right of publicity statutes in the country, protecting not just name, image, and voice but also distinctive appearance, mannerisms, and gestures. Indiana’s post-mortem right of publicity lasts 100 years — the longest in any state.
Illinois has long protected individuals under its Right of Publicity Act and revised the statute in 2025 to address digital replicas in the context of AI. The Illinois Biometric Information Privacy Act (BIPA) provides an independent layer of protection by regulating the collection and use of biometric data, including voice prints and facial geometry.
Texas protects name, voice, signature, photograph, and likeness, with a 50-year post-mortem right. Texas law also addresses biometric identifiers including voiceprints under the Texas Capture or Use of Biometric Identifier Act.
Florida recognizes both statutory and common law rights of publicity, with post-mortem protection extending 40 years after death.
As of 2026, more than 35 states have some form of right of publicity protection, and the trend in recent legislation — across California, New York, Tennessee, and Illinois in particular — is unmistakably toward explicit coverage of AI-generated synthetic media.
Federal Law: The Lanham Act’s False Endorsement Theory
While no federal right of publicity statute exists, the Lanham Act, 15 U.S.C. § 1125(a), provides a powerful federal cause of action for false endorsement and false association. Section 43(a) prohibits the use of any word, term, name, symbol, or device — or any false or misleading representation of fact — that is likely to cause confusion about a person’s affiliation with, connection to, or sponsorship or approval of a product or service.
The Ninth Circuit’s Waits decision cited above arose in part under this theory. Tom Waits prevailed on his Lanham Act claim because Frito-Lay’s use of a Waits impersonator created consumer confusion about whether Waits had endorsed Doritos — he had a well-documented public persona of refusing commercial endorsements, making the association particularly damaging.
In the AI context, false endorsement under the Lanham Act is directly applicable whenever a synthetic reproduction of a person’s voice, image, or likeness is used in connection with goods or services in a way that is likely to make consumers believe the person endorsed, sponsored, or approved those goods or services. The plaintiff must show: (1) use of an identifying characteristic in commerce; (2) likely consumer confusion about affiliation or endorsement.
AI-generated advertisements featuring a recognizable voice clone of a celebrity, a deepfake image of an executive praising a competitor’s product, or a synthetic audio track that sounds like a well-known brand spokesperson all fit squarely within the false endorsement framework. The Lanham Act’s reach extends to any commercial use in interstate commerce, making it available regardless of which state the injured party or the defendant is located in.
Remedies under the Lanham Act include injunctive relief, actual damages, disgorgement of the defendant’s profits, and — in willful infringement cases — enhanced damages and attorney’s fees.
The Take It Down Act: New Federal Law on Deepfakes
On May 19, 2025, President Trump signed the Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act — the TAKE IT DOWN Act — into federal law. The bill passed both chambers of Congress by near-unanimous votes.
The Act was primarily designed to address nonconsensual intimate imagery, including AI-generated deepfake pornography. It criminalizes the knowing publication of intimate visual depictions of individuals without their consent, whether the content is authentic or AI-generated. Criminal penalties range from two to three years imprisonment depending on whether the victim is an adult or a minor.
The Act also requires online platforms to implement a notice-and-removal process: upon receiving a qualifying notice from a depicted individual, covered platforms must remove the content within 48 hours. Platforms have until May 19, 2026, to establish compliant removal processes.
For business owners, the Take It Down Act has a narrower scope than it might initially appear. It is focused on intimate and sexual imagery — it does not provide a general federal cause of action for commercial deepfakes, AI-generated fake endorsements, or synthetic business impersonation outside the intimate imagery context. Those scenarios remain governed primarily by state right of publicity laws and the Lanham Act.
That said, the Act’s passage signals a meaningful shift in congressional appetite for federal deepfake regulation, and further legislation specifically addressing commercial AI impersonation remains an active area of legislative discussion.
FTC Enforcement: AI-Generated Fake Endorsements
The Federal Trade Commission has moved aggressively to address AI-generated deception in commercial contexts, using its authority under Section 5 of the FTC Act to prohibit unfair or deceptive acts or practices.
On August 14, 2024, the FTC finalized its rule on fake reviews and testimonials, which took effect on October 21, 2024. The rule explicitly prohibits AI-generated consumer reviews and testimonials — including reviews that misrepresent that they were written by a real person who had actual experience with the business or product. The FTC brought an early enforcement action against Rytr, an AI writing service that enabled paid subscribers to generate unlimited fake testimonials with fabricated specifics that bore no relation to any actual consumer experience.
Separately, in March 2024, the FTC finalized a Trade Regulation Rule on Impersonation of Government and Businesses, effective April 1, 2024. This rule makes it an unfair or deceptive act or practice to falsely pose as, or materially misrepresent affiliation with, a government entity, government officer, business, or business officer. AI-generated content impersonating a company’s executives or brand personnel directly implicates this rule.
The FTC also proposed, in February 2024, extending these protections to cover AI-powered impersonation of private individuals — recognizing that deepfake technology had created a new category of fraud risk. The agency expressly noted that proposed extensions of liability could reach companies that provide AI tools knowing (or having reason to know) that the tools would be used for impersonation fraud.
Civil penalty exposure under current FTC rules can reach over $53,000 per violation, with each non-compliant piece of content potentially counted separately. A single AI-generated fake endorsement campaign could therefore generate millions of dollars in exposure.
Voice Cloning and AI Audio Fraud: The Business Threat
The most immediately dangerous AI replication threat for most businesses is not a trademark lawsuit — it is financial fraud. Voice cloning technology has made it possible to generate convincing audio of any person with a relatively small sample of that person’s speech. Publicly available audio from earnings calls, conference presentations, podcast interviews, or even voicemail greetings can provide sufficient source material.
The documented cases are instructive. In early 2024, an engineering firm lost $25 million when a finance worker was deceived by a video call populated with AI-generated replicas of the CFO and other executives, all indistinguishable from the real people. In 2025, the CEO of a major advertising firm was targeted with a cloned-voice scheme over a messaging platform. A UK energy company lost the equivalent of roughly $240,000 after an employee received a call from a perfect-sounding replica of the company’s CEO authorizing a wire transfer.
These attacks — known in cybersecurity as AI-enabled business email compromise or deepfake CEO fraud — exploit the trust that employees naturally place in a recognized executive voice. They work precisely because voice has historically been reliable as an authentication factor.
The legal remedies available after such an attack are meaningful but limited. Wire fraud and computer fraud statutes apply to the perpetrators, but recovery depends on identifying and prosecuting the attacker — which is difficult when the fraud originates overseas. Prevention is therefore a legal and operational priority.
From a legal standpoint, businesses should also be aware that deploying AI-generated voice agents for customer service without adequate disclosure creates its own liability exposure. If a customer believes they are speaking with a human representative and is misled in a way that causes harm — for example, receiving incorrect information about a financial product — the FTC’s deception standards and relevant state consumer protection laws may apply.
When Your Business Creates AI Avatars: Rights Clearance Requirements
The other side of this legal landscape is the risk businesses face when they are the ones deploying AI-generated content. Using an AI tool to generate a synthetic voice, likeness, or persona for marketing, customer service, or internal communications requires careful attention to what — and whose — the AI was trained on and what consents exist.
If your business wants to create a digital replica of a living spokesperson, employee, or performer, the consent requirements depend on jurisdiction and context:
For union performers, SAG-AFTRA agreements are now explicit. Since 2024, SAG-AFTRA has established that creating a digital voice replica of a union member requires the performer’s informed consent, separate compensation, and the right to opt out of continued use in new works. The 2025 Commercials Contract established detailed provisions for synthetic performer consent. Companies that use AI voice tools without confirming the underlying training data was appropriately licensed are operating at risk even if they did not intend to replicate any specific performer.
For non-union employees and contractors, any agreement to use an individual’s voice or likeness for an AI digital replica should be in writing, with explicit scope and compensation terms. California’s AB 2602 makes this a legal requirement for entertainment industry contexts: a contract clause purporting to grant AI digital replica rights is void unless the performer had legal or union representation when it was signed. Even outside California, vague language in a standard employment agreement is unlikely to cover AI-generated replica use.
For AI-generated brand characters, the risk is inadvertent resemblance. Generative AI models trained on existing content can produce outputs that resemble real people. Before deploying an AI-generated spokesperson, avatar, or voice, a business should conduct a reasonable clearance review to confirm the output does not closely resemble a known individual whose rights might be asserted.
Practical Steps to Protect Your Business
Monitor Your Brand and Executive Identities
Proactive monitoring is the first line of defense. Set up alerts for mentions of executive names in combination with audio, video, or impersonation. Several commercial services now specifically scan for AI-generated synthetic media. The faster a fake is identified, the faster it can be addressed — including takedown requests to the hosting platform and, under the TAKE IT DOWN Act, expedited removal of qualifying intimate deepfakes.
Register Your Trademarks
Your brand name, logo, and distinctive brand persona are protectable as trademarks. A registered trademark gives you standing to pursue Lanham Act claims and provides leverage in platform-level takedown processes. If a core element of your brand involves a particular person’s name or likeness — a founder, a mascot associated with a real individual — consider whether the persona itself warrants registration.
Train Your Finance and Operations Teams
The CEO fraud threat is operational as much as it is legal. Implement verification protocols that require out-of-band confirmation for any wire transfer or financial authorization, regardless of how convincing the request sounds or looks. A brief callback on a known number — not a number provided in the suspicious communication — costs seconds and can prevent a seven-figure loss. Brief your team that voice alone is no longer a reliable authentication factor.
Contractual Protections
For any arrangement involving performers, voice actors, spokespeople, or creative professionals, ensure your contracts address AI digital replicas explicitly: what uses are permitted, what consent is required for new uses, what happens if the relationship terminates. Silence in a contract on this point does not mean the right is granted — in California, it means the opposite. If you are a business licensing AI-generated voice or avatar technology from a vendor, require representations that the underlying training data was properly licensed and that the vendor carries appropriate insurance for intellectual property claims.
If You Are a Public Figure or Executive
Consider recording a brief inventory of your distinctive vocal characteristics and publicly available audio samples with your legal counsel, so you have baseline documentation if you ever need to demonstrate what constitutes your authentic voice versus a replica. Some jurisdictions allow pre-registration of publicity rights; consult counsel about what options exist in your state.
Conclusion
The law governing AI-generated replicas is moving faster than most technology law has moved in a generation, and it is doing so in a business owner’s favor. State right of publicity laws in California, New York, Tennessee, and elsewhere have been explicitly updated to cover digital replicas and AI voice clones. The Lanham Act’s false endorsement theory provides a federal remedy for commercial impersonation that misleads consumers. The FTC’s rules against fake endorsements apply with full force to AI-generated testimonials and synthetic spokespeople. And while the Take It Down Act is narrowly focused on intimate imagery, it signals that Congress is paying attention.
What has not changed is the fundamental principle at stake: your identity, and your executives’ identities, are property with commercial value. Allowing that value to be appropriated — whether by a fraudster cloning a CEO’s voice or by a competitor deploying a synthetic spokesperson that sounds like your brand — is a cognizable legal wrong with growing remedies.
The practical message is straightforward. Treat digital identity protection the way you would treat trade secret protection: assume the threat is real, build procedures to detect it early, and ensure your contracts and registrations give you the standing to act quickly when it occurs. The businesses that will be least prepared are those that treat this as a future problem. The cases and regulatory actions described in this post make clear it is very much a present one.
This post is provided for general informational and educational purposes only and does not constitute legal advice. Laws in this area are evolving rapidly and vary by jurisdiction. Consult qualified legal counsel regarding the specific facts and circumstances of your situation.
