In Hereafter devised, we explored how over time we’ve moved from protecting the assets that represent our work product, to our selves becoming an asset that also needs protection. This week we’re seeing what that looks like as we live it now and how that landscape is changing.
As it stands, the market hasn’t waited for the law. It can’t afford to because regulation and legislation is never going to be able to move as fast as the people it needs to protect, nor will it know the specifics of what needs to be guarded against until those boundaries are pushed. The worst outcome of premature policy is something so broad that everything “throughout the universe” is covered, but no one is protected.
What we’re seeing right now are platforms, agencies, and infrastructure companies building frameworks for managing digital identity as an asset. This is a step forward in making rights protections available, but at the moment it is still only serves the people building them and those who have access and can afford it. What protection looks like for everyone else in the gap whose likeness, reputation, and digital identity is just as valuable, if not as marketably lucrative, is still being worked out, mostly by the people most affected.
When ARN Media used the likeness of one of their team members to provide the voice and likeness of ‘Thy’ for their initially undisclosed AI radio host (AFR, 2025), there was no followup coverage to indicate what the agreement with that person looked like. For others who would be put in similar situations, the questions to ask here are: What would informed consent look like? What should fair compensation require? What ongoing rights would the individual have over how their clone is used?
ARN Media used ElevenLabs to create that digital asset for Thy, and their Terms of Service (non-EU and EU versions) that covers both content and user voice models grants ElevenLabs a license that is perpetual and irrevocable, nonexclusive, royalty-free and fully paid, worldwide, and sub-licensable. The ‘sub-licensable’ clause is interesting because that adds a further supply-chain complexity to the rights problem.
ElevenLabs has a feature that allows voice artists to add their voice to a Voice Library that allows others to use their voice and be paid for it. This is covered by the terms clause which states “Notwithstanding the foregoing, we will not commercialize your voice on a standalone basis without your permission to do so.” However, the voice artist does not have full control over how their voice is used, and although ElevenLabs has a reasonably comprehensive Prohibited Use Policy, there are ways a user could skirt around that list. Even the website’s AI agent I asked for clarification on usage flip-flopped a bit on this. At the very least, there is potential for a voice to be used for content against the values of the artist that will be outside of their control, and the way ElevenLabs has described enforcement in that document doesn’t necessarily give voice artists enforceable rights against misuse.
For example, prohibited use includes political campaigning, but there’s nothing stopping someone from creating a persona for an agent with very strong views about reproductive health, immigration, or minority groups and expressing them in a way that amplifies anxieties. They don’t need to name a candidate or political party to convince people to advocate for a group with those policies. We’ve seen similar with comment bots on social media platforms and how hard it is to get even violent content marked as against community standards.
Just as in the case with Google Drive in Who owns the work, rights and ownership of your data does not mean control. This is a pattern the collection has been tracing: ownership, rights, and protection each sounding like stronger guarantees than they are, and each failing to deliver in related but distinct ways. And while the industry is developing in response to market direction with unions, emerging consent standards, and public conversations, knowing the gap exists between what platforms say and what they’re obliged to do is the first form of protection available to everyone.
The cases we hear about likeness protections have been like that of Meta’s now retracted Muse Image feature (Deadline, 2026) where heavy-hitters like CAA were outspoken in their position against a tool that could impact the livelihoods of their talent, including the most well-known actors in the world.
There was also the case where OpenAI released an AI assistant voice remarkably like Scarlett Johansson’s (NPR, 2024) from the film Her (2013). Sam Altman, OpenAI’s CEO, approached Johansson to voice the assistant and she declined, only to hear a facsimile of herself after the demo was released. Despite OpenAI’s statements that the voice actor hired was using their natural speaking voice, the likeness was seemingly intentional because Altman also tweeted the word “her” in connection to the announcement. The voice was later withdrawn. While I haven’t found reports of Johansson trademarking her voice and image, other actors and musicians are already doing this as protection against unauthorised reproduction (Greenspoon Marder LLP, 2026; BBC, 2026; Billboard, 2026).
But the faces and voices that are recognised around the world aren’t the only ones vulnerable to likeness misuse, and may not have the representation or means to be able to attain this type of coverage.
Grandparent scams, deepfakes, and other forms of voice cloning scams are targeting regular people. SecurityBrief reports AUD$25.8 million worth of losses were tied to voice cloning scams in the first half of 2025. All it takes is a few seconds of video or audio to clone someone convincingly, and it doesn’t even have to be something the person recorded of themselves.
This is an everyone problem. While celebrities might be affected by livelihood dilution and reputational damage, the rest of us who fall under the category of “low value targets” have livelihood and reputational risk of a different kind that is outside of our control, and most won’t have the means or access to counter Brandolini’s law:
“The amount of energy needed to refute bullshit is an order of magnitude bigger than that needed to produce it.” — Alberto Brandolini
The EU AI Act and GDPR provide additional protections for those in the European Economic Area (EEA), but platforms like Google, Meta, and ElevenLabs aren’t above creating terms variations to ensure compliance, not across the board so that everyone receives the same protections, but what is need for the region in which it is required. This is why broader global adoption matters.
Japan’s Justice Ministry is drafting a report for “protection of the voices and images of famous individuals” (Japan Times, 2026), Mexico has draft laws for performers in process (FIA, 2026), although these are still focussing on protections of creative artists and those with celebrity and not for private individuals. Broader adoption won’t produce a universal standard, but it would create a common baseline that terms of service couldn’t simply route around by jurisdiction.
In the market, platforms like TrueRights are setting up an end-to-end rights infrastructure platform that covers licensing, monitoring and enforcement, and payment. H&M’s model of helping models create digital twins appears to be a collaborative effort between an AI company and the modelling agencies. Loti AI, who previously only offered their services to public figures, will be opening up their service to the public (Variety, 2025), although at time of writing in July 2026, their public offering page still shows “Join the waitlist” with non-functioning buttons for signing up.
The limitation behind the current offerings still are that they primarily serve public figures who have licensing value and the money to pay for it, but not private individuals who are similarly at risk from different vectors. The solution space and the harm space just don’t overlap. Even if services like Loti AI were to create offerings for the general public, would this new category of consumer-level identity protection reach the most at risk who would need to be covered?
The market has moved faster than the law, but both are still behind what is needed to protect the people who are most vulnerable. And we’re still in a place where what is available has been built on market logic that values reputations by their licensing potential rather than by what they mean to the person who holds them. The question is whether we are able to build protections not around what your likeness is worth, but around who and what you are.
Stay curious,
— Michele
Thanks for reading Life, the Universe, and STEAM! This post is public so feel free to share it.
This article is part of the Original Works collection.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.