A bounded primary-source review of the rules, proposals, contracts and technical standards shaping how a real person’s face or voice can be authorized, generated and verified in 2026.
Original research with a defined limit. This report codes 14 primary sources reviewed through September 5, 2026. It is not a global law census, legal advice or evidence that every source applies to every campaign.
AI identity licensing is not becoming one rule. It is becoming an operating stack. Rights and contracts answer whether a person authorized a use. Advertising and synthetic-media rules answer what an audience must be told. Provenance standards answer what can be checked about a file and its history.
SocialGravity’s inference from this review: a buyer needs permission, disclosure and provenance as separate connected records. A synthetic label cannot supply consent. A licence cannot prove which output was generated. A valid provenance claim cannot decide whether the depicted person agreed.
This update adds the enacted TAKE IT DOWN Act as a narrowly scoped removal and remedy signal, adds SAG-AFTRA interactive-media guidance on written consent, intended use, compensation and suspension of new generation, and updates the technical standard to C2PA 2.4. The authority class and limits of each source remain explicit in the dataset.
These counts show topic coverage inside this dataset. They are not legal requirements, maturity ratings or performance scores.
Binding law, a proposed bill, collective bargaining, government guidance and a technical standard do not carry the same legal weight. The dataset keeps them separate so a reader can see whether a statement is a rule, proposal, contract pattern or implementation mechanism.
9 of 14 sources address permission or a right to control use. 6 address contract form or specific scope. The pattern is strongest in the California contract rule, the proposed NO FAKES Act and SAG-AFTRA agreements, but the legal effect differs between them.
Only 2 sources in this bounded review directly address access, security, storage, transfer or destruction. That makes asset custody an easy operational gap even where the permission language is detailed.
4 sources address compensation or a paid relationship. 3 address audience disclosure. Paying the person does not make an endorsement truthful, and labeling an output does not establish that the person was paid or agreed.
3 sources address technical origin, marking or provenance. C2PA and NIST describe ways to bind, label or recover information about content. They do not convert a missing licence into permission.
7 sources address duration, additional uses, termination, expiry, destruction or credential status. A buyer still needs an explicit rule for future generation and a separate rule for outputs already produced.
These are SocialGravity’s operational definitions for this report. They do not replace a statute, collective agreement or signed contract.
| Term | Working definition |
|---|---|
| Digital replica | A computer-generated representation readily identifiable as a real person’s voice or visual likeness. |
| AI identity licence | Scoped permission for a named party to use defined identity elements for an agreed AI use, term and production route. |
| Consent of record | Evidence that the identified person agreed to participate and to the reviewed version of the proposed use. |
| Intended use | The buyer, campaign, script or claims, channels, territory, languages, formats and dates the permission covers. |
| Asset custody | The controls governing who can access, copy, transfer, use or destroy captured face, voice and model assets. |
| Permitted generation | A generation event allowed by the current licence, covered asset version and agreed production constraints. |
| Content provenance | Verifiable information about an asset’s origin and history. Provenance is not automatically proof of personal permission. |
| Output receipt | A signed record connecting a released file to its generation event, licence references and content credential. |
| Lifecycle control | The rules and technical actions for additional use, expiry, termination, revocation and existing outputs. |
A defensible transaction needs more than one document or label. The practical chain is identity verification, reviewed consent, a signed licence, secured payment, terms-locked generation, a verifiable receipt and revocation control.
Inspect the evidence chainBring a licensing brief
This report is informational research. Applicability depends on the person, work, agreement, jurisdiction and use. Obtain qualified legal advice for a real transaction.
The reviewed sources show separate movement around permission, use-specific contracts, compensation, disclosure, provenance and lifecycle controls. No source in this bounded dataset covers the complete operating chain.
No. Disclosure tells an audience that content is synthetic or sponsored. Permission requires its own evidence from the person or authorized right holder.
No. Content Credentials can provide signed provenance assertions. They do not decide whether the depicted person granted the required rights.
No. It is a transparent, reproducible review of 14 selected primary sources through September 5, 2026. The methodology states what was included and excluded.