The intuition that "AI-generated" means "no rights questions" is the most expensive mistake in the current generative-content cycle. The opposite is closer to the truth: AI-generated faces aggregate rights questions from multiple legal frameworks, and the failure modes stack rather than cancel.
Personality rights are the floor
Most jurisdictions recognize a personality right (Persönlichkeitsrecht in Germany, droit à l'image in France, right of publicity in the US). The right protects identifiable likeness against unauthorized commercial use. The protection is not contingent on photographic origin, a painted portrait, a sculpted bust, or a generated image all trigger the same analysis. The legal test is recognizability.
Recognizability is a low bar. Plaintiffs do not have to prove that you intended to use their likeness. They have to prove that a reasonable observer would identify them. If a generated face matches their hairline, jaw, eye placement, or skin tone closely enough that someone might mistake it for them, the bar is met.
Image rights add specifics
§ 22 KUG in Germany (and analogous statutes in other EU jurisdictions) requires affirmative consent for the dissemination of a person's image. The statute predates AI but applies to it. Consent must be specific to the use, the context, and (for ongoing relationships) revocable.
There are statutory exceptions: figures of contemporary history, persons who appear only as accessories to a landscape, and a few more. None of these meaningfully cover the use case where a brand wants a "model-like" face for a commercial. The exceptions are narrow; the rule is broad.
GDPR Art. 9 raises the stakes
The General Data Protection Regulation classifies face data as biometric data, a special category under Article 9. Processing biometric data requires explicit consent (Art. 9(2)(a)) or a narrow set of public-interest exceptions. Commercial AI-image generation is not in those exceptions.
This matters even when the depicted face is "synthetic." If the synthesis was learned from real face data, processing that real data was an Art. 9 question, and the brand publishing the output is in the chain of processors. Data Protection Authorities have begun signalling that they will pursue this. Italy's Garante did so against ChatGPT in early 2023, the Norwegian DPA against Clearview AI before that, and the pattern is widening.
The EU AI Act is now stacked on top
The EU AI Act adds transparency and labeling obligations specifically for synthetic media. Deepfakes must be disclosed. AI-generated content used in commercial contexts must be identifiable as such. The AI Act does not replace personality rights or GDPR; it sits on top of them.
For a brand running an AI campaign, this means three independent compliance lines: (1) personality rights to consent on use, (2) GDPR to lawful processing of any underlying biometric data, and (3) AI Act to label the synthetic nature of the output. Failure on any one line creates exposure.
Why model providers are not the answer
It is tempting to think the model vendor handles all of this. They do not. Their terms of service almost universally disclaim downstream liability. They sell tools, not rights chains. When the cease-and-desist arrives, it arrives at the brand. The contractual relationship between the brand and the vendor does not transfer to the depicted person, and the depicted person has no contract with the vendor.
The model vendor sells you tools. The license layer sells you a defensible position.
What the licensed-identity layer does
A licensed identity collapses the three compliance lines into one documented contract. Personality-rights consent is in the license. GDPR Art. 9 explicit consent is in the license. EU AI Act labeling can be hooked into the campaign-asset pipeline because every output maps to a known license. The brand still publishes; the brand also has paperwork.
This does not eliminate every risk. A licensed face still cannot be used in a way the license excludes, politics, pharma, or whatever the depicted person specified. But it converts the risk surface from "did we have any rights" to "did we stay within scope." That is a defensible question.
Every AI-generated face is a legal risk. Unless it is licensed.
Request agency access