Zum Hauptinhalt springen
← Blog
For companies6 min

How brands can safely use AI-generated people in ads

Most AI-image policies inside agencies are written defensively, "use only when necessary," "get legal review," "avoid recognizable people." These policies are not wrong, but they are not enough. They reduce volume, not risk. To actually de-risk AI campaigns, the workflow has to change.

Replace "fictional" with "licensed"

The first rule of most AI-image policies is "make sure the face is not a real person." This is the wrong rule. You cannot guarantee non-resemblance, the underlying model was trained on real people. The correct rule is: every published face is either licensed (with documented consent and scope) or so abstracted that recognizability is impossible (silhouettes, extreme stylization). There is no middle ground that is safe.

Separate output rights from training rights

These are two different legal questions and should be two different licenses. Output rights govern whether a specific image can be published. Training rights govern whether a face can be used to fine-tune or condition a model. Most brands need only output rights. Paying for training rights you do not use is wasteful; assuming output rights cover training is dangerous.

Configure the smallest sufficient license

A real license has dimensions: duration, geography, medium, industry exclusions, exposure thresholds. Default-everything-allowed licenses are expensive and create unnecessary risk. Configure the smallest license that fits the campaign. DACH, 12 months, print and social only, exclude politics and pharma. Renew or extend if the campaign is extended.

The depicted person is also more comfortable consenting to a bounded license. Consent quality is a defensive asset: a person who clearly understood what they consented to is not a likely plaintiff later.

Build the audit trail at workflow time, not response time

Every campaign asset should map to a license ID. The map should exist before the asset goes live, not after a complaint arrives. Most agencies will tell you they "have records." The test is whether you can produce, in one minute, the chain from a published image to the consent record of the depicted person. If you can't, you do not have an audit trail; you have hope.

What this looks like in a DAM

In your asset management system, every face-bearing asset should carry: the license ID, the depicted person's identifier, the license scope (region, duration, medium, exclusions), and a link to the immutable consent record. When campaigns rotate or extensions are requested, the system should be able to flag scope conflicts (e.g. extending to a region not in the license).

Plan for revocation

GDPR consent is revocable. A license that pretends otherwise is not actually GDPR-compliant. The right pattern is: revocation is always possible, active deployments enter a defined sunset period (so a campaign mid-flight is not yanked off-air), no new uses of the revoked likeness after revocation. The depicted person retains control; the brand has predictable timing.

Treat the AI Act labeling obligation as a checkbox at the end

The EU AI Act will require synthetic-media disclosure for many ad uses. This is a workflow add, a bit of metadata on the asset and a visible label in some contexts, not a strategic question. Build it once into your DAM and your delivery pipelines and it disappears.

The new procurement question

When a vendor pitches an AI-image solution, the question to ask is no longer "can your model produce realistic faces", they all can. The question is: "what is the rights chain, and what evidence do I have when a complaint arrives?" If the answer is "the model is trained on licensed data" or "we provide a license per output," that is a serious vendor. If the answer is "you accept downstream liability per ToS," that is a tool, not a solution.

The vendor sells you a generator. You still need a license layer. They are not the same.

Every AI-generated face is a legal risk. Unless it is licensed.

Request agency access
How brands can safely use AI-generated people in ads · FaceLedger