The lines not worth crossing: likeness, consent and synthetic media
Most risk in this business is commercial: an account gets restricted, a channel stops converting, a platform changes its terms. A small number of categories are different in kind, and confusing the two is the most expensive mistake available in this niche.
What you get from this page
- The difference between policy risk and legal exposure, and why operators conflate them
- The three content categories that are never worth the upside
- Why 'it is only AI' is not a defence anyone should rely on
- What to put in writing before anyone else touches your accounts
On this page
Policy risk versus legal exposure
Operators in this niche tend to treat all risk as the same kind of risk: something that might get an account banned. That framing is fine for most decisions and catastrophically wrong for a few.
- Policy risk
- A platform may restrict or remove your account. Painful, survivable, and largely a business-continuity problem. You mitigate it with diversification, documentation and compliance.
- Legal exposure
- Consequences that follow you personally regardless of what any platform does. Not mitigated by having a backup account, by operating through a company, or by the platform never noticing. There is no continuity plan for this category.
Almost everything in this business sits in the first category. The rest of this page is about the small set that does not.
The three categories
1. Any identifiable real person, without consent
This is the central one, and it covers more ground than people assume. Face swaps onto a real person. Training an adapter on photographs of a real person. Generating a synthetic character deliberately built to resemble a specific individual. So-called nudify or undress tooling applied to a real photograph.
Platform position is unambiguous: this category is described as zero tolerance with immediate permanent bans across the platforms in this space. Legislators in multiple jurisdictions have been moving the same way, treating distribution of non-consensual intimate synthetic imagery as a criminal matter and not a terms dispute. We have not summarised specific statutes here, for the reason given in the provenance note at the foot of the page; get advice for the jurisdiction you actually operate in.
The practical rule is simple and has no edge cases worth exploring: generate synthetic identities, train only on your own synthetic output, and never reference a real individual anywhere in the pipeline. Our consistency methods guide covers how to build an identity from scratch, which is the only defensible route.
2. Anything with ambiguous age presentation
This is the category with the least tolerance for error anywhere in the stack: platforms, payment processors, hosting providers and law enforcement all treat it as absolute. Policy language across the major platforms covers content whether real, fictional, simulated, cartoon, AI-generated or edited.
The operational implication is that this cannot be handled by intent. A generation pipeline does not know what you meant. It has to be handled by a review gate that rejects anything ambiguous instead of assessing whether it is probably fine.
3. Misrepresenting a synthetic persona as a real person
Weaker than the first two in legal terms but it belongs on the list, because it is the one operators walk into gradually rather than deliberately.
It typically starts with a slightly vague bio, continues through chat scripts that imply a physical person, and ends somewhere that looks like inducing payments through a false representation. The platform framing is misleading fans. The consumer-protection framing, in some jurisdictions, is less forgiving than that.
The mitigation is proper disclosure, and specifically extending it to everyone with account access, not treating it as a profile-settings task.
Things that are risk but not this kind of risk
For balance, because treating everything as existential is its own failure mode and it leads people to ignore the real lines.
| Concern | Actual category | Proportionate response |
|---|---|---|
| Platform changes its commission | Commercial | Model it, diversify revenue, move on. |
| Account restricted for a policy breach | Policy risk | Read the policy, fix it, appeal. Keep the content library off-platform so it survives. |
| A social channel stops converting | Commercial | Expected. Run more than one channel. |
| AI content in search results being demoted | Commercial | Relevant if you publish a website. Not a legal matter. |
| Real person's likeness in any output | Legal exposure | Do not do it. There is no proportionate version. |
| Ambiguous age presentation | Legal exposure | Hard reject gate. No judgement calls. |
A framework and not a dataset. The platform positions cited come from the published guidelines linked in Sources; the risk categorisation is our own editorial judgement and is labelled as such throughout this page.
What to put in writing before delegating
The moment a chatter, manager, editor or agency touches your accounts, your compliance position becomes whatever the least-briefed person believes. Written rules are the only version of this that survives contact with a real team.
Minimum written policy before anyone gets access
No real person's likeness, in generation, training or reference, ever
Stated as an absolute with no approval path, because an approval path is how it happens.
Ambiguous age presentation is a hard reject, not a judgement call
No representation that the persona is a physical person
With example phrasings of what is and is not acceptable in chat. Vague guidance produces vague compliance.
Named individual responsible for the review gate
Name one person. Shared responsibility for a compliance step reliably means nobody performs it.
Access log: who has credentials, to what, since when
Revocable individually. Shared logins make this impossible.
An escalation route for anything uncertain
Cheaper than a chatter making a judgement call at 2am to save a sale.
Is a synthetic character that happens to resemble a celebrity a problem?
If the resemblance is deliberate, yes, treat it as the first category. If it is coincidental, the practical answer is still to change the character, because you will not enjoy arguing about intent and the cost of a different face is a training run.
Does operating through a company protect me?
It may affect commercial liability. Do not assume it insulates an individual from the categories described here. This is exactly the question to put to a lawyer, not to a guide.
The platform has not noticed. Does that mean it is fine?
No. Detection and legality are unrelated. The first two categories carry consequences that arrive independently of whether a platform's moderation queue got to you, and they do not expire.
Why does this page not cite specific statutes?
Because we have not verified the legislation in detail, and because the specifics vary by jurisdiction in ways a single page cannot honestly cover. The purpose here is to be clear about which risks warrant professional advice. These three do.
Where these numbers come from
This page describes platform policy, which is published and linkable, and refers in general terms to the direction of legislation on non-consensual synthetic imagery in several jurisdictions. We have deliberately not cited specific statutes or summarised their provisions, because a misstated provision in this area could cost a reader far more than a missing one. Treat the legal framing here as a prompt to get advice, not as a substitute for it.
Sources
Who wrote this
AIOF Editorial DeskResearch & editorial
AIOF is an editorial desk that works from primary sources: platform terms, vendor pricing pages and published company data, read and dated rather than repeated from other write-ups. Where a figure comes from someone else we cite it and grade it. Where we have not measured something ourselves we say so, which today is most of the places you might expect a first-hand number.
- Works from primary platform documents, with the date each page was last checked published on the page itself
- Grades every figure as sourced, third-party estimate, modelled or measured, and labels which
- Publishes no first-party measured benchmarks yet, and says so on the methodology page rather than implying otherwise
- Corrections are made in place with a dated changelog entry, listed on the updates page
Rules and pricing here change often. This page was last touched on . Found something out of date? Tell us and we will fix it in place with a dated note.
Read next
AI disclosure by platform
What each major platform requires you to disclose about AI-generated content, how prominent it has to be, and what happens when it is missing.
PolicyReference5 minPolicyReference5 minCharacter consistency methods
The practical methods for keeping an AI character's face and body consistent across a content library, with the failure mode of each.
ProductionAnalysis6 minProductionAnalysis6 minOnlyNudes quick start
What a hosted AI studio costs per render, the sequence to follow, and the three signals that mean you have outgrown it. Worked from published credit prices.
ProductionTutorial6 minProductionTutorial6 min