
Maintenance
Synthetic media consent checklist: source, person, purpose, disclosure and removal
A synthetic media consent checklist covering source rights, the people depicted, authority, purpose, model records, disclosure, reuse and removal.
What to take away
- Copyright permission and likeness permission are two separate files. Clearing one does not clear the other.
- The production record should name the model, version, account owner, region and the date you read the terms.
- Disclosure belongs where the audience meets the media, not in a footer or a credits page.
- Provenance metadata proves where a file came from. It does not prove the person agreed to this use.
- Someone must hold the pause button, and that name goes in the plan before publication, not after a complaint.
- Separate a test from a release. A closed prototype approval does not clear a public campaign.
- The workflow suits a real project using an adult's likeness. It is not a route for turning scraped material into permission.
Use this before generating, approving or publishing a synthetic depiction of an identifiable person. It is a production review. It does not decide whether a given use is lawful where you are.
Source and person
- List every photo, video, audio file, script and reference going in.
- For each one, record creator, owner, license, release and which adaptations are permitted.
- Identify every person recognizable by face, voice, body, mannerisms, name or context.
- Note age at capture and current legal capacity.
- Keep the copyright file and the likeness, privacy and data file separate.
- Reject scraped or leaked material with no documented basis.
- Note whether each file carries metadata or hidden identifiers, and whether it may enter a hosted model.
- Note any deletion or return requirement attached to the source files.
- Do not upload identity documents, unreleased masters or third-party images just because the tool accepts them.
A performer's release usually covers a defined production, not a synthetic likeness of that performer in a different scene. When the two disagree, the narrower document governs the conversation, and a licensed attorney in your jurisdiction reads it.
Source and person checks
- List each photo, video, audio, script
- Verify creator, owner, license, release
- Identify every recognizable person
- Confirm age and legal capacity
- Separate copyright from likeness and privacy
- Reject scraped or leaked material
Authority and purpose
- Name who is granting each permission and how you verified they can.
- Describe the exact synthetic change in the words a viewer would use.
- Write down the product, message, scene, script, audience, channel, dates and territory.
- Describe the setting, the level of realism, the languages and the channels before any test render.
- Stop before making even a test if that description is broader than the person expects.
- Mark whether this is paid promotion, political communication, fundraising or sales.
- Flag intimate, medical, financial, biometric, criminal, employment, religious, grief, endorsement and child-related contexts.
- Record prohibited uses and prohibited variants.
Those contexts need review by a licensed attorney. A production checklist does not replace legal advice.
Regulatory statements on AI-generated imagery ask for transparency, accessible removal routes and stronger protection for children. Exact duties vary by jurisdiction, so confirm them with a licensed attorney where you operate.
Model and prompt
- Record service, plan, model, version, region and account owner.
- Save the terms and privacy notice you actually read, with the date.
- Check input and output retention, training use, human review, vendor access and deletion.
- Restrict who can open prompt and source files.
- Review negative prompts, reference strength and personalization settings.
- Test outputs for accidental resemblance to people who never consented.
- Refuse instructions that invent sensitive facts or put words in a real person's mouth.
- Record the account controls and the deletion limit on the plan you hold.
- Note any broad license grant over inputs or outputs.
Output approval
- Show the person the final media, the caption, the landing page and the claims beside it.
- Record hashes of approved files and keep rejected versions.
- Confirm edits, crops, languages, aspect ratios and audio substitutions.
- Require fresh approval for new conduct, new words, a new product or a sensitive context.
- Set an approval expiration date.
The current C2PA technical specification describes cryptographically bound manifests, assertions, claims, signatures and provenance for media assets. It also states that the system validates association and tamper evidence rather than judging whether the asserted information is good, bad or true. Keep a human reviewer beside the credential.
Disclosure and audience
- Write a direct label naming the generated or altered element.
- Place it before or with first exposure.
- Test small screens, muted playback, audio-only use, crops, reposts and translations.
- Avoid vague labels such as "enhanced" when a person says or does something synthetic.
- Explain paid or sponsored relationships in their own line.
- Keep the label attached to downloadable files where the format allows.
- Record the exact label wording and its placement for each channel.
Show the rendered placement to someone who did not work on the file. Ask what they think is authentic, what was changed, who approved it, and whether any commercial relationship is clear.
The EU AI Act sets transparency duties for certain generated or manipulated content, including disclosure for deep fakes, with tailored treatment for evidently artistic, satirical and fictional works. Application dates, the role your organization plays, exceptions and national enforcement all need current EU advice.
Provenance, reuse and security
- Keep source IDs, releases, approved prompts, model details, operator, edit log, disclosure and distribution list.
- Minimize location, identity-document and biometric exposure.
- State whether affiliates, licensees or viewers may remix or download.
- Block training or model reuse unless it was separately approved and supported.
- Limit access to reusable voice, face and body assets.
- Rotate keys and revoke vendor access when the project ends.
Removal and correction
- Provide a monitored contact route.
- Name the person who can pause publication and paid media.
- Write the stop and removal route before the first release.
- Keep platform, host, search, licensee and vendor contacts in one place.
- Set response and escalation times.
- Preserve correction and takedown case numbers.
- Delete expired inputs, models, outputs and working files under the retention plan.
Common questions
Is a Content Credential a consent record?
No. It can carry provenance assertions about a file. Permission scope and legal authority need their own records, signed by the people involved.
Must disclosure say which model was used?
Not always. The detail required depends on law, policy, audience need and risk. Your production record should capture it either way.
Can one approval cover unlimited variants?
That is risky. Define a narrow variation range and send material changes back for review. Approval expiration dates close the gap.
What if a distributor strips metadata?
Keep visible disclosure and an external rights record. Test the actual distribution workflow before launch, not after.







