TwinEthosRequest access

Control

AI tool whose primary purpose is producing an identifiable person's likeness/voice without authorization

Distributing an algorithm/tool/service whose primary purpose is producing a particular identifiable individual's photograph, voice, or likeness without that individual's authorization creates civil liability.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI produces or alters a person's likeness, voice, or intimate imagery without consent · control id cond.ai-tool-produces-identifiable-likeness-without-authorization

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Tennessee (US-TN).

The guard to add

Gate the clone or swap feature so it reproduces only voices and faces whose owner is verified or licensed, and reject references that target other identifiable people.

An authorization check at the entry point of the likeness tool (the clone, enroll, or swap endpoint), before the reference sample reaches voices.ivc.create, speaker_wav=, inswapper, or a lip-sync or reenactment model. It accepts a reference only when the requester is the verified owner (speaker verification or a spoken voice captcha matched to the sample) or a likeness license or rights-holder record covers that person, and it rejects references that match a celebrity or public-figure blocklist. The authorization id is stored with the created voice or face model so every later generation traces back to it.

Where it goes: 1 application source code, 2 data models, 6 API calls and integrations.

What reviewers look for: in the module that creates a voice or face model, a speaker_verification or voice_captcha step, a likeness_license or rights_holder lookup, or a celebrity_blocklist check that runs before the clone or swap call and rejects on failure; the stored voice or face model carries the authorization id. A terms-of-service checkbox with no check of whose voice or face the sample is does not count.

Example (FastAPI + Coqui XTTS), before:

@app.post('/clone')
async def clone(sample: UploadFile, text: str = Form(...)):
    path = save_upload(sample)
    tts.tts_to_file(text=text, speaker_wav=path, language='en', file_path='out.wav')
    return FileResponse('out.wav')

After:

@app.post('/clone')
async def clone(sample: UploadFile, text: str = Form(...), user=Depends(current_user)):
    path = save_upload(sample)
    if celebrity_blocklist.matches_voice(path):
        raise HTTPException(403, 'reference voice matches a protected public figure')
    owner = voice_ownership.verify(user.id, path)   # spoken captcha + speaker match
    if not owner.verified:
        raise HTTPException(403, 'only your own verified voice can be cloned')
    tts.tts_to_file(text=text, speaker_wav=path, language='en', file_path='out.wav')
    audit.record('voice_clone', user_id=user.id, voice_authorization_id=owner.id)
    return FileResponse('out.wav')

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)