AI legal risk
Every AI-generated face is a legal risk.
Unless it is licensed.
Generative models train on billions of images. The provenance of those images is rarely documented, and personality rights apply to AI-generated faces the moment they resemble a real person. The liability lands at the end of the chain: with the brand or agency that publishes the campaign.
Why AI-generated faces create legal exposure
Foundation models are trained on scraped image datasets without per-image consent. When a generated face matches, or even resembles, an identifiable person, the depicted person can assert personality rights (Persönlichkeitsrecht in DACH, right of publicity in the US) and image rights (§ 22 KUG, comparable rules across the EU). The model provider is rarely the defendant. The defendant is whoever published the image: the brand, the agency, the platform. Insurance does not always cover this.
What 'unclear training data' means in practice
If you cannot prove that every depicted likeness was either fictional or licensed, you are exposed to two specific claims. First, similarity claims: a real person recognizes themselves in your campaign. Second, biometric-data claims under GDPR Art. 9, courts increasingly treat face data as a special category requiring explicit, informed consent. Both claims survive even when the generation looks 'random.' The plaintiff doesn't have to prove deliberate use; resemblance is enough.
How licensing closes the gap
A licensed identity comes with a documented consent record and a configurable scope: duration, geography, medium, sensitive-industry exclusions, and a strict separation between training rights and output rights. The license is binding per use, revocable on a defined process, and produces an audit trail you can hand to legal on request. That converts an open-ended liability into a defined contract.
What this looks like at production speed
A creative team filters available identities by demographic, style, and industry permission. A license is configured (e.g. DACH, 12 months, print + social, no politics or pharma). The contract is countersigned in hours, not weeks. The campaign ships with a license ID that maps every output back to a documented consent record. If the depicted person revokes consent, the defined sunset process protects active deployments while preventing new ones.
Every AI-generated face is a legal risk. Unless it is licensed.
FAQ
Frequently asked.
Can AI-generated faces cause legal issues?+
Yes. Personality rights and image rights attach to recognizable faces regardless of how the image was produced. Even if a generated face looks "fictional", a similarity claim from a real person who recognizes themselves is sufficient grounds for action. Liability falls on the publisher, not the model provider.
Can someone sue over an AI-generated image?+
Yes. Personality-rights, image-rights, and biometric-data claims (GDPR Art. 9) all apply. Plaintiffs do not have to prove that you intended to use their likeness, only that a reasonable observer would identify them. Settlements and damages are routine in unauthorized-likeness cases.
How can my agency safely use AI-generated people in ads?+
Use licensed identities with a documented consent chain. The license should specify scope (duration, region, medium), permitted and excluded industries, and a separation between model-training and output rights. Maintain an audit trail per campaign so any claim can be answered with a contract.
Does the EU AI Act change this?+
Yes. The EU AI Act adds transparency and labeling obligations for synthetic media on top of existing personality rights and GDPR. Licensed identity does not exempt you from labeling, but it answers the consent and rights questions that the AI Act assumes are settled.
Ready?
Get early access to FaceLedger for companies. Configure licensed identities directly into your generative-AI workflow.
Request agency access