Discovering an AI-generated image of yourself, used in a context you did not consent to, is disorienting. The first instinct is usually to share it on social media, which is the wrong instinct, because it amplifies the use you are trying to stop. Here is the order of operations that actually helps.
1. Document before you react
Before you contact anyone, capture evidence. Screenshots with visible URL bars and timestamps. Direct links. The platform on which the content appears. The advertiser, if it's an ad. The original image source if you can identify it. Save everything to a folder you control. Cloud-sync it. The content may disappear within hours of you reaching out, and you need a record that survives.
If the image is in a campaign or commercial use, capture the full creative context: the headline, the brand, the product. Personality-rights and right-of-publicity claims are stronger when commercial use is documented.
2. Identify the right legal lever
Your strongest claim depends on jurisdiction.
In Germany / DACH
§ 22 KUG (image rights) and the general personality right under §§ 823, 1004 BGB. Commercial use without consent is per-se actionable. Damages are calibrated to what a license would have cost (lizenzanaloge Schadensberechnung), with a multiplier for unauthorized use. GDPR Art. 9 adds a biometric-data claim if the underlying processing involved your face data.
In the EU more broadly
GDPR Art. 9 (biometric data, requires explicit consent) is the strongest claim. Data Protection Authorities are increasingly active. Each member state's personality-rights or image-rights statute layers on top.
In the US
Right-of-publicity claims, which vary by state. California (Civil Code § 3344), New York (Civil Rights Law § 50-51), and Illinois (BIPA, for biometric data) are the most aggressive jurisdictions. Federal claims are limited; the Lanham Act may apply if the use creates consumer confusion.
3. Send the takedown first
Before legal escalation, most platforms have content-removal processes. Use them. Identify yourself, link the content, cite the personality-rights or image-rights basis. Many takedowns succeed without litigation. Document every step, the request, the response, the timeline.
For commercial uses (ad agencies, brands), a polite cease-and-desist email often works. The legal exposure for them is enough that most will pull the asset rather than fight. If they fight, you escalate.
4. Decide on legal escalation
Hire counsel if: the use is commercial and ongoing, the platform refuses takedown, the financial stakes are meaningful, or the harm is non-financial (reputational, emotional). Most personality-rights claims are handled on contingency or hourly. Consultation fees for an initial assessment are typically modest.
5. Prevent recurrence
After resolving an immediate case, the structural fix is to stop being unprotected. Three layers: reduce involuntary public exposure of your face online (audit your social accounts, delete or restrict legacy photos), opt out of training datasets where signals exist, and license your identity proactively under terms you set.
The first two are defensive and partial. The third is offensive: a documented consent record exists, with industry exclusions you control, and any unauthorized use is now clearly outside a defined contract, which is a much stronger evidentiary position than "I never consented to anything."
Document, takedown, escalate. In that order. And licensing prevents the next case before it happens.
Every AI-generated face is a legal risk. Unless it is licensed.
Protect your identity