Skip to main content

Artificial intelligence has made it possible to create convincing audio, images, and video of people saying and doing things they never said or did. What once required a studio, a skilled editor, and substantial source material can now be produced with widely available AI tools, sometimes from only a short clip of a person’s voice or a handful of public images. For businesses, this is no longer only an entertainment-law issue or a celebrity-rights issue. It is a brand-protection issue, a consumer-protection issue, an employment issue, a cybersecurity issue, and a reputational-risk issue. The U.S. Copyright Office’s report on digital replicas defines the problem in practical terms: digital technology can now realistically replicate a person’s voice or appearance, creating false depictions that may look or sound authentic to the public. ¹

Please note this blog post should be used for learning and illustrative purposes. It is not a substitute for consultation with an attorney with expertise in this area. If you have questions about a specific legal issue, we always recommend that you consult an attorney to discuss the particulars of your case.

The legal system is trying to catch up with that reality. The Copyright Office’s digital replicas report does not treat AI impersonation as a narrow copyright question. Instead, it recognizes that existing law leaves gaps when a fake voice, face, or performance harms a person’s reputation, misleads consumers, or diverts commercial value without copying a protected work in the traditional sense. The Office recommended that Congress consider a new federal law addressing the knowing distribution of unauthorized digital replicas, reflecting concern that state publicity-rights laws, copyright law, trademark law, privacy law, contract law, and platform policies do not always provide a complete or consistent remedy. ²

For brands and business leaders, the practical lesson is that identity has become an attack surface. A company’s trademarks; logos, domain names, and social media handles have long been assets that require monitoring and enforcement. Now, the recognizable voices and faces associated with the company may require the same kind of protection. A founder’s voice, a CEO’s appearance, a spokesperson’s mannerisms, an influencer’s endorsement style, or even an employee’s recorded presentation can become raw material for a fake advertisement, fake investment pitch, fake customer-service message, fake HR announcement, fake political statement, or fake internal instruction. The harm may occur before a lawyer can file a lawsuit, because the public may react immediately to what appears to be an authentic video or audio message.

The risk is especially acute where a person’s identity functions as part of a commercial brand. Consumers often rely on recognizable voices, faces, and personalities as signals of trust. An influencer’s endorsement may move product. A founder’s video may persuade investors. A physician’s image may reassure patients. A lawyer’s name and professional likeness may attract clients. A school administrator’s voice may persuade parents to act. An employee’s familiar voice may convince a finance department to approve a wire transfer. In each of those scenarios, the value lies not only in the words spoken, but in the audience’s belief that the person is real, authorized, and speaking in an official capacity.

That is why recent trademark activity by high-profile figures is important. Trademark law is not a perfect solution for AI impersonation, but it offers a familiar framework when a voice, image, phrase, or visual presentation operates as a source identifier. The U.S. Patent and Trademark Office recognizes sound marks where a sound identifies and distinguishes goods or services and creates an association in the listener’s mind with a commercial source. ³ In the AI context, public figures and businesses are testing whether distinctive voice clips, visual identifiers, catchphrases, and persona-linked branding elements can be registered or enforced as marks when unauthorized digital replicas create consumer confusion or falsely imply endorsement.

The recent reporting on Taylor Swift’s trademark applications illustrates the point. According to reporting on those filings, Swift sought protection for voice phrases and a recognizable image connected to her public persona at a time when AI-generated celebrity deepfakes were being used in scam advertisements.⁵ The broader takeaway is not that every person can simply “trademark their face” or “trademark their voice” in all circumstances. Trademark law generally protects identifiers used in commerce, not personal identity in the abstract. But where a particular sound, phrase, visual image, or presentation has come to identify the source of goods or services, trademark strategy may become one layer in a larger anti-impersonation program.

Publicity rights remain another important part of the analysis. The right of publicity generally protects against unauthorized commercial exploitation of a person’s name, image, likeness, voice, or other identity features, although the scope of protection varies widely by state. That patchwork matters. A brand operating nationally may face a fake endorsement that reaches consumers in every state, but the available remedies may depend on where the plaintiff resides, where the defendant acted, where the harm occurred, and which state’s law applies. The Copyright Office’s recommendation for federal digital-replica legislation reflects that inconsistency and the growing view that AI replicas present nationwide risks that are difficult to manage through state-by-state enforcement alone. ²

Tennessee’s ELVIS Act is one example of state law moving more directly toward AI-specific protection. The law updated Tennessee’s existing personal-rights framework to address voice, image, and likeness concerns, with a particular focus on the misuse of AI in the music industry.⁴ It is significant because it treats voice as a protectable identity interest in a market where vocal sound, style, and recognition can carry enormous commercial value. Although Tennessee’s law is closely associated with musicians and performers, its logic is broader: if AI can convincingly reproduce a person’s voice and use it to mislead audiences, the law must be able to address the misuse even when no traditional copyrighted recording has been copied.

Copyright law also has limits in this area. A fake video may use a synthetic voice without copying any particular copyrighted sound recording. A generated image may resemble a person without reproducing a specific protected photograph. A fake endorsement may exploit public trust without copying a company’s logo or written advertising copy. Copyright may help when the AI output copies protected material, but many impersonation harms arise from false identity rather than copied authorship. That distinction is central to understanding why brands should not treat copyright registration alone as sufficient protection against AI fakes.

Trademark law has its own limits. A trademark claim usually depends on use in commerce, likelihood of confusion, false association, dilution, or related theories. It is powerful when a digital replica suggests that a person or company endorsed, sponsored, produced, or approved a product or service. It may be less useful when the fake content is purely personal, political, satirical, or noncommercial. Even in commercial contexts, trademark law does not automatically protect every human feature. A person’s face, voice, or catchphrase must function as a brand identifier, and the claim must be tied to consumer confusion or another recognized trademark harm. That is why trademark protection should be viewed as a targeted tool, not a complete substitute for publicity rights, contracts, platform enforcement, cybersecurity controls, and crisis communications.

For executives, the problem often appears as authority fraud. A convincing fake of a CEO, CFO, managing partner, or department head can be used to instruct an employee to transfer money, disclose confidential information, approve a vendor, change payroll details, or release sensitive documents. These attacks combine deepfake technology with social engineering. The fake does not need to fool the entire public; it only needs to fool one person at the right moment. The more public-facing the executive is, the easier it may be for bad actors to collect training material from interviews, webinars, podcasts, earnings calls, social media, or conference appearances.

For influencers and creators, the harm often appears as false endorsement. A fake video can make it look like a creator recommended a product, investment, diet, app, giveaway, or political cause. Even if the fake is removed later, followers may have already clicked links, entered personal information, purchased goods, or shared the content. The creator then faces reputational harm and may lose trust with sponsors. The brand whose product is falsely promoted may also be harmed, especially if consumers believe the company participated in the deception. Conversely, a scammer may use an influencer’s likeness to promote a fake version of a legitimate product, diverting sales and damaging goodwill.

For employees, the risk is more complex. Many employees are not celebrities and do not think of themselves as having commercially valuable identities. But employees appear in LinkedIn posts, website bios, recruitment videos, Zoom recordings, training materials, conference panels, sales decks, and customer testimonials. A fake employee message can be used to manipulate customers, embarrass the company, impersonate HR, spread false internal information, or create evidence in a dispute. Employers should recognize that digital-replica protection is not only about famous executives. It also concerns ordinary workers whose voices and faces may be misused because they are trusted by customers, vendors, students, patients, or coworkers.

Businesses should begin with an identity-risk audit. That audit should identify which people are publicly associated with the organization and what materials are available online. It should consider executives, owners, sales leaders, recruiters, customer-service representatives, public speakers, brand ambassadors, podcast hosts, physicians, attorneys, financial advisers, athletes, entertainers, and influencers. The company should ask whose voice could move money, whose image could move customers, whose endorsement could move markets, and whose apparent statement could create legal or reputational harm. That question reframes digital replicas as a governance issue rather than a novelty.

The audit should also identify which identity assets are already protected and which are not. A company may have registered its name and logo but ignored a distinctive podcast intro, a founder’s recurring tagline, a recognizable product-demo format, or a spokesperson’s signature phrase. Not every asset will qualify for trademark registration, but the review may reveal opportunities to strengthen protection. Where a voice clip, phrase, visual presentation, or character-like persona functions as a source identifier, trademark counsel can evaluate registrability, use in commerce, specimens, filing bases, and enforcement strategy. The USPTO’s treatment of sound marks shows that audio can serve a trademark function when it identifies commercial source, but the applicant must still satisfy trademark standards. ³

Contracts should be updated as well. Businesses that hire influencers, models, actors, voice talent, employees, contractors, agencies, or production companies should address digital replicas expressly. The agreement should state whether the company may create, train, store, edit, reuse, license, or distribute AI-generated versions of a person’s voice or likeness. It should also define the scope, duration, territory, media, compensation, approval rights, revocation rights, data-security obligations, and post-termination obligations. Silence is dangerous. A contract signed before AI replicas became commercially common may not clearly answer whether a party may synthesize new performances from old recordings.

Employee policies require a careful balance. Employers may need permission to use employee images and recordings for legitimate business purposes, such as training, marketing, or internal communications. But employees should not unknowingly grant broad rights to create synthetic versions of themselves for unrelated future uses. Clear policies can protect both sides. The company can preserve necessary rights for ordinary business materials, while employees receive transparency about whether AI tools will be used to alter, simulate, or extend their voice or likeness. In sensitive industries, such as law, medicine, finance, education, and government contracting, policies should also address authentication of official communications.

A strong approval process is essential for marketing content. No AI-generated voice, face, testimonial, endorsement, or spokesperson-style content should be released without written confirmation that the company has the necessary rights. Marketing teams should understand that a vendor’s platform capability does not equal legal permission. The fact that software can generate a realistic voice does not mean the company may use that voice. The fact that an AI image resembles a real employee or celebrity does not mean the image is safe. Legal review should occur before launch, not after a takedown demand or public complaint.

Vendor agreements should also be examined. Many companies use outside agencies for advertising, video production, social media, recruiting content, voiceovers, chatbots, and customer-service automation. Those vendors may use AI tools in ways the company does not see. Contracts should require vendors to disclose AI use, obtain necessary permissions, avoid unauthorized voice or likeness replication, indemnify the company for misuse, maintain records of consent, and remove disputed content promptly. If vendors use synthetic media libraries, the company should require proof that the underlying voices and likenesses were lawfully licensed.

Monitoring is another critical layer. AI impersonation often spreads through social platforms, ad networks, domain registrations, app stores, marketplaces, and messaging channels. A company should monitor not only its name and logo, but also key executives, brand ambassadors, product names, recurring phrases, and known scam patterns. Monitoring should include paid advertisements because deepfake scams may appear as sponsored content before they appear in ordinary search results. The WIRED reporting on celebrity deepfake scam ads shows how sponsored social content can use realistic-looking manipulated interviews and fake reward programs to collect personal information.⁵ That same technique can be adapted to business leaders, professional-service firms, financial products, franchisors, schools, nonprofits, and local employers.

When a fake appears, speed matters. The first response should preserve evidence before the content disappears. Screenshots, screen recordings, URLs, account names, ad identifiers, timestamps, payment-page information, platform notices, and consumer complaints may all matter later. The company should then assess the harm. Is the content falsely endorsing a product? Is it collecting personal information? Is it impersonating an executive for fraud? Is it defamatory? Is it using a registered mark? Is it targeting employees? Is it intimate or harassing content involving an individual? The answer determines whether the best response is a platform takedown, trademark complaint, cease-and-desist letter, law-enforcement referral, consumer warning, litigation hold, insurance notice, or public statement.

Public communications should be disciplined. A company responding to a digital replica should not accidentally amplify the fake more than necessary. In some cases, a short statement confirming that the content is unauthorized and directing consumers to official channels may be enough. In other cases, especially where money, safety, privacy, or regulated services are involved, the company may need a more detailed warning. The message should be consistent across the website, social media, customer-service teams, sales staff, and internal communications. Employees should know what to say and what not to say.

Businesses should also create authentication habits before a crisis. Executives and employees should not rely solely on voice, video, or caller ID for sensitive instructions. Internal controls should require secondary verification for wire transfers, bank-account changes, credential resets, confidential document releases, urgent procurement requests, and unusual executive instructions. A deepfake policy should be integrated with cybersecurity training because AI impersonation often succeeds through process failure, not technological perfection. The best defense may be a culture where employees are rewarded for verifying unusual requests rather than punished for slowing them down.

For brands that use real people in advertising, consent records should be organized and searchable. A company should be able to answer quickly whether it has permission to use a particular person’s image, voice, testimonial, performance, or AI-generated variation. The records should identify the source file, the date of consent, the permitted uses, any restrictions, and any expiration date. This is especially important for companies with large content libraries, legacy campaigns, franchise systems, influencer programs, or decentralized marketing teams. Without records, a company may be unable to distinguish authorized synthetic content from unauthorized impersonation.

Insurance and incident-response plans should be revisited. Cyber policies, media-liability policies, errors-and-omissions policies, employment-practices policies, and directors-and-officers policies may respond differently to AI impersonation events. Some may cover social-engineering losses only under limited circumstances. Some may exclude intellectual-property disputes. Some may require prompt notice. Legal, finance, HR, IT, marketing, and risk-management teams should understand in advance who owns the response. AI impersonation does not fit neatly into one department.

The legal strategy should be layered. Copyright may help if protected content was copied. Trademark may help if consumers are confused about source, sponsorship, affiliation, or endorsement. Publicity rights may help if a person’s identity is commercially exploited without permission. Privacy, defamation, unfair competition, false advertising, contract, employment, and computer-crime laws may also apply depending on the facts. Platform policies may offer faster relief than court action, but platform action may be temporary or incomplete. Federal and state laws are evolving, and businesses should not assume that a remedy available in one jurisdiction will apply everywhere.

The Copyright Office’s report is important because it frames unauthorized digital replicas as a problem affecting both public figures and private individuals. ² That point should matter to employers. The law may eventually develop in a way that protects all individuals, not only celebrities, from knowing distribution of unauthorized digital replicas. Businesses should prepare for that future by treating employee identity rights with seriousness now. Using AI to simulate a worker, spokesperson, or customer without clear permission may create legal and cultural risk even before a specific statute addresses every scenario.

At the same time, the First Amendment and legitimate expression remain important. Not every imitation should be unlawful. News reporting, commentary, parody, satire, documentary uses, historical works, and other expressive contexts may receive legal protection depending on the circumstances. A digital-replica framework must distinguish between harmful deception and protected expression. Businesses should be careful not to overclaim. Aggressive enforcement against criticism, parody, or commentary can backfire legally and publicly. The strongest cases usually involve deception, commercial exploitation, false endorsement, fraud, privacy invasion, or clear reputational harm.

A practical brand-protection program should therefore focus on clarity, consent, and consumer confusion. Clarity means the public should know when a communication is official and when content is synthetic. Consent means people whose voices and likenesses are used should understand and approve the use. Consumer confusion means the company should act quickly when fake content misleads the public about endorsement, affiliation, sponsorship, employment, or authority. These principles align with the existing logic of trademark, publicity, and consumer-protection law while anticipating new federal digital-replica rules.

The businesses most prepared for AI impersonation will not be the ones that rely on one legal theory. They will be the ones that combine intellectual-property registration, contractual consent, employee training, platform monitoring, cybersecurity controls, vendor oversight, and rapid communications. They will know which people are most likely to be impersonated and what harm could result. They will have a protocol for evidence preservation and takedown demands. They will have already reviewed whether distinctive voice or visual assets function as trademarks. They will have updated contracts to address synthetic media. And they will have trained employees to verify high-risk instructions even when the voice on the phone sounds familiar.

AI digital replicas are not merely fake content. They are false signals of trust. They can borrow credibility from a person, authority from an executive, intimacy from an influencer, and goodwill from a brand. That is why protection must be both legal and operational. The law is moving toward stronger remedies, as shown by the Copyright Office’s federal recommendations, the USPTO’s attention to identity-related value, state laws such as Tennessee’s ELVIS Act, and public figures’ experiments with trademark filings. ¹ ² ³ ⁴ ⁵ But businesses should not wait for perfect legislation. The most effective response begins now, with a clear understanding that voice, likeness, and digital replicas have become part of modern brand security.

Contact Tishkoff

Tishkoff PLC specializes in business law and litigation. For inquiries, contact us at www.tish.law/contact/. & check out Tishkoff PLC’s Website (www.Tish.Law/), eBooks (www.Tish.Law/e-books), Blogs (www.Tish.Law/blog) and References (www.Tish.Law/resources).

References

  1.  U.S. Copyright Office, Copyright and Artificial Intelligence, Part 1: Digital Replicas, July 2024. https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-1-Digital-Replicas-Report.pdf
  2.  Library of Congress Newsroom, Copyright Office Releases Part 1 of Artificial Intelligence Report, Recommends Federal Digital Replica Law, July 31, 2024.  https://newsroom.loc.gov/news/copyright-office-releases-part-1-of-artificial-intelligence-report–recommends-federal-digital-repli/s/33eeaa40-8847-4668-9c58-8a45c3ac9e01
  3.  U.S. Patent and Trademark Office, Trademark Manual of Examining Procedure, Section 1202.15, Sound Marks. https://www.uspto.gov/sites/default/files/documents/TM-TMEP-8th-edition.pdf
  4.  Office of Tennessee Governor Bill Lee, Tennessee First in the Nation to Address AI Impact on Music Industry, January 10, 2024. https://www.tn.gov/governor/news/2024/1/10/tennessee-first-in-the-nation-to-address-ai-impact-on-music-industry.html?utm_source=chatgpt.com
  5.  WIRED, Taylor Swift Wants to Trademark Her Likeness. These TikTok Deepfake Ads Show Why, April 29, 2026. https://www.wired.com/story/taylor-swift-rihanna-tiktok-deepfake-ads/

This publication is for general informational purposes and does not constitute legal advice. Reading it does not create an attorney-client relationship. You should consult counsel for advice on your specific circumstances.