Voice and Likeness in the Age of Deepfake Technology – The Scope of Existing Legal Protection
From AI Content Transparency to the Protection of Identity
The new transparency requirements for AI-generated content, which came into effect on 2 August 2026, mark an important step in the development of the European regulatory framework for artificial intelligence. Article 50 of the AI Act introduces obligations concerning the marking and detection of AI-generated or manipulated content, including specific requirements for deepfake content. These requirements go beyond the technical marking of content and aim to reduce the risks of deception, manipulation, fraud and impersonation.
Of particular significance is the new Code of Practice on Transparency of AI-generated Content (the “Code”), published by the European Commission in June 2026, which sets out practical measures for complying with the transparency obligations laid down in Article 50 of the AI Act. Although adherence to the Code is voluntary, the transparency obligations it seeks to operationalise are legally binding under the AI Act.
We have examined these transparency obligations and their practical implementation in greater detail in our earlier article, “Transparency of AI Content in Focus of New European Regulations”.
The Code provides a practical framework for complying with these binding requirements under the AI Act. It covers, among other things, machine-readable marking of AI-generated content, mechanisms for its detection, and requirements for labelling deepfake content.
For deployers of AI systems, a key obligation is to disclose that image, audio or video content has been artificially generated or manipulated and constitutes a deepfake — content that resembles real people, objects, places, entities or events and could be mistaken for authentic material.
However, the AI Act’s disclosure requirements do not, in themselves, establish whether the use of another person’s likeness, voice or performance is lawful. This raises a broader legal question: does transparency about the AI-generated nature of content make the use of another person’s identity lawful?
Voice, Likeness and Performers’ Identities as an Emerging Legal Issue
Deepfake technology exposes the limitations of traditional copyright and neighbouring rights protection. An AI system can generate new audiovisual content that convincingly imitates a person’s voice, appearance, gestures or manner of performance, even without directly copying an existing recording.
In this context, the legislative reform introduced in Cyprus in 2026 is particularly noteworthy, as it established sui generis protection against certain deepfake imitations of an individual’s physical characteristics and an artist’s performance. According to an analysis published by the Kluwer Copyright Blog, the new provisions cover, among other things, morphology, voice, biometric and behavioural characteristics, as well as the imitation of an artist’s performance without their express consent.
This approach is significant as it seeks to address situations where existing copyright and neighbouring rights may not provide adequate protection. Where AI is used to create a new advertisement featuring a digital replica of a well-known actor or musician, the legal question is no longer simply one of authorship of the newly generated content, but also whether the individual’s identity and distinctive characteristics may lawfully be used to create it.
Is Specific Legal Protection Necessary?
The European regulatory landscape currently reflects two distinct approaches. In relation to deepfake content, the AI Act primarily focuses on transparency, requiring the public to be informed when such content has been artificially generated or manipulated. National legislators, however, are beginning to address the substantive legal protection of identity, including whether the mere disclosure of deepfake content provides sufficient protection for individuals whose voice, likeness or performance has been used.
For companies using generative AI, this raises practical legal questions that extend beyond compliance with the AI Act. Before using digital replicas of a person’s voice, likeness or performance, companies must consider the legal basis for such use, the implications for copyright and neighbouring rights, data protection and personality rights, as well as the terms of any applicable licence or consent.
The commercial exploitation of digital replicas presents particular challenges. A digital replica of an actor, musician or other public figure may have considerable commercial value. However, the commercial value of an individual’s identity does not necessarily mean that its use should be viewed solely in terms of economic rights. It also raises questions concerning human dignity, control over one’s own identity and the limits of consent, particularly where the identity of a deceased person is used or consent is obtained in circumstances of unequal bargaining power.
An important question therefore remains for the European legal framework: will the transparency requirements under the AI Act prove sufficient, or will additional mechanisms emerge to protect voice, likeness and performers’ identities? It will be particularly important for future rules to address not only who is entitled to commercially exploit a digital replica, but also the conditions under which consent is given, its duration and scope, and safeguards against misuse.
From a business perspective, it is therefore important to distinguish between two separate legal issues: the obligation to disclose that content has been generated or manipulated using AI, and the need for a lawful basis to use an individual’s identity in that content. While the former is governed by an established European regulatory framework, the latter is addressed through existing legal protections, alongside emerging national rules specifically targeting deepfake imitations.
Integrating AI solutions into business operations increasingly requires a comprehensive assessment of legal issues relating to artificial intelligence, intellectual property and digital business. Vujinović & Partners assists companies in identifying and assessing the legal risks associated with the development, implementation and use of AI technologies.