TwinEthosRequest access

Control

AI-generated voice or likeness of a real person used on products or in advertising without that person's consent

Generated or cloned voice, image, or video of an identifiable real person is used on products or to advertise or sell only with that person's recorded prior consent.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI produces or alters a person's likeness, voice, or intimate imagery without consent · control id cond.ai-likeness-used-commercially-without-consent

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in California (US-CA).

The guard to add

Check a recorded commercial-use consent or talent release for the depicted person before a generated or cloned voice or likeness is published to an ad, product, or storefront.

A consent gate on the path from the likeness generator (face swap, voice clone, identity-preserving image model) to every commercial sink: ad-platform creative uploads, product listings and storefront media, public campaign buckets, merchandise publishing. The gate looks up a consent or talent-release record for the person whose face or voice is reproduced, scoped to commercial use, refuses to publish without a live record, and stamps the asset with the release id so it can be traced and pulled later. A public-figure or celebrity filter runs before generation so references to well-known people are blocked unless a release is on file.

Where it goes: 1 application source code, 2 data models, 6 API calls and integrations, 9 AI output handling.

What reviewers look for: on every path from swapper.get, voices.ivc.create, speaker_wav=, or InstantID/PhotoMaker output to an ad upload, product listing, or public bucket, a check such as consents.require(person_id, scope='commercial') that is read before the upload and fails closed; a talent_release_id stored on the published asset; a public_figure_filter or celebrity_blocklist before generation. A consent field that is collected but never checked does not count.

Example (Python insightface + boto3), before:

def build_ad_creative(person_id, frame, target_face, source_face):
    out = swapper.get(frame, target_face, source_face, paste_back=True)
    cv2.imwrite('/tmp/ad.png', out)
    s3.upload_file('/tmp/ad.png', 'campaign-public', f'ads/{person_id}.png')

After:

def build_ad_creative(person_id, frame, target_face, source_face):
    release = consents.get(person_id=person_id, scope='commercial')
    if release is None or release.revoked_at:
        raise ConsentRequired('no commercial likeness release for this person')
    out = swapper.get(frame, target_face, source_face, paste_back=True)
    cv2.imwrite('/tmp/ad.png', out)
    s3.upload_file('/tmp/ad.png', 'campaign-public', f'ads/{person_id}.png',
                   ExtraArgs={'Metadata': {'talent_release_id': str(release.id)}})

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)