
Rules
Synthetic media consent problems: scraped likenesses, hidden training use and cloned endorsements
Synthetic media consent problems include scraped likenesses, hidden training, misleading realism, weak disclosure, cloned endorsements, prompts, and regeneration.
What to take away
- Public availability does not answer whether a likeness may be used as model input.
- Tool terms can conflict with the participant's promised limits.
- Realism, context, account design, and captions can mislead even when pixels look imperfect.
- A disclosure that viewers miss does little work.
- A cloned endorsement falsely attributes commercial belief or experience.
- Deleting one output does not stop regeneration from retained sources or models.
Synthetic-media failures often begin before generation. A team uses an unverified source, skips tool terms, or obtains approval for a loose concept rather than the published representation. The fix is a stage-by-stage record and a real stop rule.
Scraped likenesses
A portrait on a public account may be viewable without being licensed for download, model personalization, face swapping, or advertising. A permissive copyright license may also leave subject-level rights unresolved.
Source File Clearance Checklist
- Record source ID for each portrait
- Name the rights owner
- Confirm license covers this process
- Complete depicted-person review
- Log acquisition date
- Block upload if purpose unclear
Hidden training use
A hosted tool may retain inputs, review them, use them to improve services, or grant broad output rights. Those terms can exceed the promise made to a performer. Private mode, enterprise controls, and deletion tools should be verified, not assumed.
Is Training Authorized?
Do the tool terms permit training on inputs?
Record plan and terms version
Select non-training tool and configuration
Record the exact plan and terms version. If training is not authorized, select a tool and configuration that supports that boundary and document the choice.
Misleading realism
Viewers infer authenticity from more than facial detail. A familiar account name, copied set, authentic voice, news-style caption, product link, or urgent call to action can make an imperfect output convincing.
NIST's full report on reducing synthetic-content risks evaluates provenance, watermarking, detection, and labeling while emphasizing context, audience, actor sophistication, and harms such as fraud, nonconsensual intimate imagery, and child exploitation. Detection alone is not a publication clearance.
Missing or weak disclosure
A label hidden after a "more" control, placed only in profile text, delivered after the claim, or removed by cropping may fail its audience. "Creative technology" does not tell viewers that a person's face or voice was generated.
Test the label in the actual feed, ad unit, embed, download, translation, and muted mode. Use visible and audible disclosure where the representation crosses both channels.
Keep the disclosure text with the approved output record. If a distributor changes the file, format, caption, or placement, review the audience experience again before renewed publication.
Cloned endorsements
A generated presenter can falsely imply that a real person tried, approved, or recommended a product. The risk grows when a brand uses the person's name, account style, voice, or familiar phrase.
The FTC's notice proposing protections against individual impersonation discussed AI-generated images, video, and text used to harm consumers through impersonation. It was a proposal, not a final individual-impersonation rule. Confirm current law before making a legal claim.
Unsafe prompts and variants
A permitted base portrait can produce disallowed sexual, political, medical, criminal, or hateful variants. Prompt filters help but are not enough. Restrict who can generate, review every output, keep rejected files from distribution, and log material prompts.
Do not use a real person's likeness for adversarial testing unless the test has a lawful, consented, and secured design. Use purpose-built or licensed test assets where possible.
Repeated generation
Deleting a post leaves the source files, custom model, embeddings, prompts, exports, team access, and distributor copies unless each is addressed. An offboarding plan should identify every reusable component and who can delete or revoke it.
When complete deletion is technically impossible, say so before consent and limit the project. Do not promise that a public model can forget a person on demand.
Common questions
Does a watermark prevent misuse?
No. It can convey or preserve information, but it may be removed, missed, or detached and does not grant rights.
Can a team use public posts for internal testing?
Internal use is still use. Review source rights, personal data, consent, tool terms, security, and retention.
Is low realism always low risk?
No. Context, voice, naming, account presentation, and audience vulnerability can make rough media harmful.
What should happen to rejected outputs?
Restrict and delete them under a defined rule, retaining only the minimum audit information needed without creating a new exposure.







