Deepfake Rules, Likeness Rights and Consent From People Shown

Video: Deepfake Rules, Likeness Rights and Consent From People Shown

Deepfakes are synthetic media (images, audio, or video) that depict a real person without their consent or in a false context. The term deepfake originally referred to face-swapping technology but now encompasses any synthetic media of a person’s likeness, including synthetic speech, synthetic video, or AI-modified video of a person’s face or body. In marketing contexts, deepfakes pose significant legal and ethical risks. For example, a deepfake of a well-known sports star endorsing a fitness supplement without their permission could damage their reputation and lead to costly legal disputes. Similarly, a deepfake of a company’s CEO appearing to make controversial statements could severely harm the company’s brand and public trust.

Legal liability for deepfakes of real people arises from multiple sources. First, intellectual property law recognises a person’s right of publicity or right of likeness. In many jurisdictions, using a person’s image, voice, or likeness in commercial speech (advertising) requires explicit consent. The United Kingdom does not have a codified right of publicity statute, but English common law recognises passing off, defamation, and breach of confidence as grounds to challenge misuse of a person’s likeness. If you create a deepfake of a real person (a celebrity, a public figure, an employee, a competitor) and use it in marketing without consent, that person can sue for damages. For instance, a marketing agency that created a deepfake of an employee using a company product without their consent could face a lawsuit under passing off or breach of confidence. This was highlighted in a case where a deepfake of a well-known actress was used in a commercial, resulting in a court ruling that the unauthorized use of her likeness was a breach of her rights.

Deepfake Rules, Likeness Rights and Consent From People Shown Concept Diagram
Figure: Conceptual architecture and workflow for Deepfake Rules, Likeness Rights and Consent From People Shown

Second, if the deepfake misrepresents the person (suggesting they endorse your product when they do not, or placing them in a false or damaging context), defamation law provides grounds for suit. A deepfake of a competitor’s CEO saying the competitor’s product is unsafe could be defamatory. A deepfake of a celebrity appearing to use your product when they never agreed to do so violates their publicity rights. A real-world example occurred when a deepfake of a well-known actor was used in a fake advertisement for a rival brand. The actor successfully sued for defamation and damages, as the deepfake implied an endorsement that never happened. This case reinforced the importance of verifying consent before using any deepfake in marketing.

Third, data protection law may apply in certain circumstances. If creating the deepfake required processing someone’s biometric data (their face, voice, or behavioural patterns), UK GDPR Article 9 restricts processing of biometric data to narrow circumstances. Using someone’s face to train a model or create a deepfake without consent may violate data protection law and trigger enforcement by the Information Commissioner. For example, a company that used employees’ facial data to create deepfakes for internal training purposes was investigated by the ICO for violating GDPR. Although the data was anonymised, the ICO ruled that consent was still required for biometric processing. This case illustrates that even internal deepfake projects must comply with data privacy laws.

Fourth, the Online Safety Act 2023 creates a statutory offence of distributing intimate sexual images without consent. Deepfakes of a person in sexual or intimate scenarios can trigger criminal liability under this Act, with potential imprisonment. A notable case involved a deepfake of a public figure created and distributed online, which led to criminal charges under the Act. This demonstrates that deepfakes are not only a civil matter but can also lead to criminal prosecution. Companies must be especially cautious when using deepfakes in any context that could be perceived as sexual or inappropriate, even if the intent was not malicious.

For marketing purposes, the safest approach is to obtain explicit written consent from any real person depicted or impersonated in synthetic media. The consent should specify the exact use (the platform, the campaign, the geographic scope, duration) and should be in writing. Pay attention to geography: if you are using a deepfake of a person in advertising targeted at the EU, Article 50 requires labelling, but the consent requirement remains independent. A marketing team launching a deepfake campaign in multiple EU countries must ensure that each deepfake used complies with local consent laws. For example, a deepfake of a European celebrity used in a campaign targeting France and Germany must have specific consent forms tailored to each jurisdiction. This level of detail is essential to avoid legal disputes and protect brand reputation.

If you use real people in deepfakes, disclose that the person is depicted synthetically. If you are using the likeness of a celebrity or public figure, assume you need consent even if a particular regulation does not explicitly require it, because the person can sue you under common law. A marketing campaign that used a deepfake of a well-known singer without consent was later challenged in court. Although the singer had not explicitly stated a right of publicity, the court ruled that the deepfake was a violation of their reputation and likeness. This case reinforced the importance of assuming consent is required, even when not legally mandated. A practical step is to include a clear disclaimer on all deepfake content, such as “This is a synthetic representation of [Name] and not an endorsement.”

For AI-generated people (faces that do not belong to any real person), no consent is required from anyone, but you still must disclose that the image is AI-generated under Article 50. This is particularly important in marketing contexts where consumers may be misled into thinking a deepfake is real. A company that created deepfake characters for a video game and failed to label them as synthetic was criticized for deceptive marketing. The label must be visible and clear, such as “AI-generated character” or “Synthetic representation.” This transparency helps build consumer trust and avoids potential legal issues. A marketing team working on deepfake content should always include a disclosure statement in all promotional materials and on all platforms where the deepfake is distributed. This simple step can prevent disputes and ensure compliance with transparency laws.