Who Owns Your Face? The Legal Fight Over AI-Generated Likeness Rights
Julio Song

Who Owns Your Face? The Legal Fight Over AI-Generated Likeness Rights

AI headshots explained

In August 2024, Tom Hanks posted a warning on Instagram. According to NBC News, he said ads were circulating that used his "name, likeness, and voice promoting miracle cures and wonder drugs," and that they were "created without my consent, fraudulently and through AI." One version, reported by MediaPost, spliced manipulated footage from his "Jimmy Kimmel Live!" appearance into a fake pitch for a diabetes cure. It was not the first time. The previous October, fans had to warn him about a similarly fabricated dental plan ad.

Hanks has a legal team and enough public recognition that the story made national news. Most people whose faces end up in an AI product they never agreed to do not get that kind of attention, especially as AI-generated faces get harder to tell apart from real photos. That gap, between what the law protects and what AI tools can now do to a face, is where a messy and fast-moving legal fight is happening right now.

What does "right of publicity" actually mean?

The right of publicity is a person's legal claim to control commercial use of their own name, image, voice and likeness. It grew out of old lawsuits about companies putting a celebrity's face on a product without asking, and for decades it mostly stayed a celebrity problem, since ordinary people rarely had a likeness worth stealing.

AI image and voice generation changed that math. A face only needs a handful of clear photos to be cloned convincingly, and a voice needs a few seconds of audio. States have responded unevenly. Tennessee, California and New York have all passed new likeness laws since 2024, while Illinois has been enforcing a two-decade-old biometric privacy statute against the same problem from a different angle. Nothing ties these together into one rule.

The United States still has no federal right of publicity, so protection depends entirely on which state you live in, what that state's statute covers, and whether the use in question counts as commercial. That patchwork is exactly what the next few sections walk through.

Why does Tennessee have a law named after Elvis?

Tennessee is home to Nashville's music industry, and Nashville's music industry was among the first to feel what AI voice cloning could do to a working singer's income. In response, the state passed the Ensuring Likeness Voice and Image Security Act, better known as the ELVIS Act, which Governor Bill Lee signed on March 21, 2024; it took effect that July 1.

The ELVIS Act is the first US state law to name a voice specifically as protected property, separate from image or likeness. According to Holland & Knight's analysis of the law, it covers both an actual recorded voice and an AI-generated simulation of it, and it passed the Tennessee legislature by a combined vote of 123 to 0. A violation can lead to a civil suit for damages, and it also carries criminal exposure as a Class A misdemeanor, punishable by up to nearly a year in jail and a fine as high as $2,500.

That combination, a real financial remedy plus criminal teeth, is unusual for publicity law, and other states have been watching. It is also a preview of the tension running through every law in this piece: legislators are trying to write rules for a technology that changes faster than a legislative session.

Illustration of a gavel beside a fragmented, pixelated digital face

Is your face biometric data, legally speaking?

In a lot of places, yes, and that classification carries its own set of rules separate from publicity law entirely. Illinois has required companies to get consent before collecting someone's "faceprint" since 2008, under the Biometric Information Privacy Act (BIPA). Facial recognition company Clearview AI scraped billions of photos from the open internet to build a search tool for that kind of data, and got sued for it.

The case took years to resolve. A federal judge finally approved a settlement in March 2025 that the ACLU had pushed for since filing suit in 2020. Instead of a cash payout, class members received a 23% equity stake in Clearview, valued at an estimated $51.75 million. Clearview is now permanently barred from selling its faceprint database to most private businesses nationwide, and cannot sell to any entity in Illinois, including police departments, for five years.

That case matters beyond Illinois because it shows a second legal track running alongside publicity rights. Under the EU's GDPR, the same logic applies: Article 9 classifies biometric data used to uniquely identify a person as a "special category" that cannot be processed without explicit consent or another narrow legal basis. A photo is not automatically biometric data under either framework. It becomes biometric data the moment a system processes it to identify who you are, which is exactly what a lot of AI face tools do under the hood.

Is the US getting one federal law for this?

Congress is trying. The NO FAKES Act would create the first federal intellectual property right covering a person's voice and visual likeness in a digital replica, with a takedown process modeled on the one that already exists for copyright under the DMCA. The Senate Judiciary Committee unanimously advanced the current version, S. 4591, on June 18, 2026, and it now waits on a vote from the full Senate. A companion bill sits in the House.

The bill would preempt new state laws going forward, but it grandfathers in protections that already existed as of January 2, 2025, so Tennessee's ELVIS Act would survive it. It also carves out exceptions for news reporting, parody, criticism and nonprofit archives, so a documentary or a satire account would not need sign-off from everyone it depicts.

Whether it passes this session or not, its existence tells you something: enough senators from both parties agree the current state-by-state patchwork is not working, even if they still disagree on the details.

Why does the EU force disclosure instead of banning deepfakes outright?

Europe took a different approach than either the US publicity-law model or the US biometric-privacy model: instead of asking who owns a likeness, the EU AI Act asks whether the audience knows what they are looking at. Article 50 of the AI Act, which applies from August 2, 2026, requires anyone who publishes a deepfake to clearly label it as AI-generated or manipulated.

The rule applies even when nobody intended to deceive anyone and even when the depicted person does not exist. A silly AI video of a coworker for an office party still needs a label under a strict reading of the text. Penalties for skipping the disclosure can reach 15 million euros or 3% of a company's global revenue, whichever number is bigger.

This is a genuinely different philosophy from ownership-based US law. It does not ask whether you had the right to make the content. It asks whether you told people what it was.

Illustration of a screen showing an AI-generated face with a disclosure label icon

What should you check before you upload your face to an AI tool?

Start with what happens to the photo after you hit generate. Under GDPR, a company processing your face to uniquely identify or recreate you is handling special category data, which means it needs your explicit consent and a real basis for processing it, not just a line buried in a terms-of-service page you scrolled past. A reasonable privacy policy should tell you plainly whether your photos are deleted after your images are generated, whether they are used to train a general model that other users benefit from, and how long they are retained if you do nothing.

Reputable AI headshot generators, Starkie AI included, spell this out because customers increasingly ask before they upload anything. Look for a stated deletion window, a clear answer on model training, and a way to request your data be removed. If a tool cannot answer those three questions in plain language, that itself is useful information. It also helps to pick a source photo that actually gives the model something usable, since a blurry or badly lit upload gets reprocessed and stored the same way a good one does.

None of this is unique to headshot tools. The same questions apply to any app asking for a selfie, a voice memo or a full-body photo, from filters that age your face to apps that turn a photo into a cartoon avatar. Whatever the tool, that one photo is usually the seed for dozens of generated variations, so it is worth knowing what happens to it before you send it.

Where does this leave performers and everyday users?

The entertainment industry got here first because it had the most to lose. SAG-AFTRA's 2023 TV and theatrical contract, ratified by 78% of voting members, now requires a studio to get informed, signed consent and give a "reasonably specific description of the intended use" before creating a digital replica of a performer, and bars studios from using replicas to avoid hiring background actors altogether.

State legislatures followed with rules aimed at performers specifically. California's AB 1836, signed in September 2024, protects deceased performers' digital replicas for 70 years after death and requires estate consent, with damages set at the greater of $10,000 or actual losses. New York went further in December 2025, when Governor Kathy Hochul signed a pair of bills that require disclosure of AI "synthetic performers" in ads and extend the state's postmortem publicity protections to digital replicas for 40 years after death, dropping the old requirement that the use be commercial.

None of these laws were written with an ordinary LinkedIn photo or a headshot generator in mind. They were written for actors, musicians and public figures whose faces are worth money to someone else. But the legal reasoning underneath them, that a face and a voice are property you did not automatically sign away, applies just as much to anyone whose photo ends up somewhere they did not expect, which is also why trust in AI-generated professional images has become its own topic of debate.

Tom Hanks had the reach and the resources to fight back in public. The direction of travel in Tennessee, Illinois, California, New York, Brussels and Washington suggests the rest of us are getting some of the same protection, just later, and mostly one state at a time.

Share this article

Frequently asked questions

Is it illegal to use someone's photo to create an AI image of them without permission?
It depends on where you and the other person live and what the image is used for. States like Tennessee, California and Illinois have specific likeness or biometric privacy laws, but the US has no single federal rule yet, and most existing laws focus on commercial use rather than private, personal use.
What is the ELVIS Act?
The ELVIS Act is a Tennessee law, signed in March 2024, that makes a person's voice a protected property right, covering both a real recording and an AI-generated simulation of it. Violations can lead to civil damages and, in some cases, a criminal misdemeanor charge.
What is the NO FAKES Act?
The NO FAKES Act is a proposed federal law that would give people a legal right over AI-generated digital replicas of their voice and likeness, with a takedown process similar to copyright law's. The Senate Judiciary Committee advanced it in June 2026, but it has not yet passed the full Congress.
Does uploading my photo to an AI headshot generator give the company ownership of my face?
No law works that way. What matters is the company's stated policy, including whether it deletes your photos after generating results, whether it uses them to train other models, and how long it keeps them. Check the privacy policy for direct answers before uploading anything.
Is my face considered biometric data?
Only when a system processes it to identify who you specifically are. Under GDPR and laws like Illinois' BIPA, a photo becomes biometric data the moment it is run through facial recognition or matching software, which then requires explicit consent before that processing can happen.
Does the EU ban AI deepfakes?
No, the EU AI Act does not ban deepfakes outright. Instead, Article 50, which applies from August 2026, requires anyone who publishes AI-generated or manipulated image, audio or video content resembling a real person to clearly disclose that it was artificially created.

More on ai headshots explained

See all