The Short Answer: Yes, Consent Is Now a Legal Requirement in Several U.S. Jurisdictions
AI-generated likenesses, voices, and synthetic performances cannot be used in commercial product advertising without explicit consent from the person whose data was used to train or clone the model. Since New York's two statutes took effect on May 20, 2025, the Empire State has led the U.S. in codifying this rule, and other states are following with similar language. Even outside regulated jurisdictions, contract law, right-of-publicity doctrine, and platform-level enforcement (notably Amazon's September 2025 seller crackdown) make consent operationally unavoidable. Brands that skip this step face civil penalties ranging from $1,000 to $10,000 per violation under New York law, plus platform suspension and class-action exposure.
Also worth reading: How does synthetic fashion model licensing work for AI product images and digital doubles? · How can I take an eye-catching image of a model holding a product for my online store? · How do I integrate a C2PA verification API for AI product images in my workflow?
What New York Actually Prohibits
Two distinct bills, S.5028A/A.5689A and S.5873A/A.6054A, were signed by Governor Kathy Hochul in May 2025 and became enforceable twenty days later. The first statute targets synthetic performers: it requires written, notarized consent from any individual whose voice, likeness, or visual representation is digitally replicated in advertising content distributed within New York. The second law, the New York NIL Act, addresses name, image, and likeness rights for athletes and adds artificial-intelligence-specific provisions. Violations are treated as deceptive trade practices under Executive Law § 63(12) and General Business Law § 349, with statutory damages starting at $1,000 for a first offense and reaching $10,000 for repeat or knowing violations. The rules apply retroactively to contracts signed after the effective date and to any ad impression delivered to a New York IP address, regardless of where the brand or seller is located.
Why Amazon Cracked Down in September 2025
On September 2, 2025, Amazon issued a formal update to its Selling Partner Policies prohibiting the use of AI-generated images that "depict a real person, including their likeness, voice, or persona, without their express written permission." CNBC reported that the policy shift was directly tied to the New York disclosure law and the surge in AI-product listings on the marketplace. According to Amazon's third-party Brand Protection Report, more than 1.4 million suspected infringing listings were blocked or removed in the first half of 2025, with AI-generated imagery accounting for a growing share of takedowns. Sellers who ignore the rule now risk account deactivation within 24 hours of detection. The Amazon move effectively nationalized the New York standard: it is simpler for a marketplace to enforce one rule across the country than to geofence a single state.
The Federal and Industry Gap
There is no comprehensive federal law that governs synthetic likeness in advertising as of September 2026, although the NO FAKES Act has been reintroduced in successive Congresses and the FTC has signaled interest through its 2024 enforcement sweep of AI marketing claims. Industry self-regulation is uneven: the Interactive Advertising Bureau (IAB) released its AI in Advertising Disclosure Framework in late 2024, but adoption remains voluntary. The result is a patchwork: Tennessee's ELVIS Act (2024) protects voice; California's AB 2602 and AB 1836 (2024) protect digital replicas of deceased performers; and roughly fourteen additional states have pending bills. Brands operating nationally should treat the strictest standard (New York's notarized-consent rule) as the baseline because it produces the lowest residual legal risk across the board.
How to Obtain Compliant Consent
The consent document should be a stand-alone agreement, not a clause buried in a larger contract, and it must specify the scope of permitted use: which product, which channels, which time horizon, and which territories. A properly drafted release identifies the synthetic or AI model used, the source data (or the trained model file hash), the exact advertising format (still image, video, voiceover, virtual try-on), and any renewal or revocation mechanics. New York requires notarization for voice and visual likeness; a remote online notarization (RON) session is acceptable and avoids scheduling friction. Brands should retain a copy of the model's training data summary or a signed disclosure of synthetic origin. Storage must comply with GDPR and CCPA retention rules, and the data subject has a right to revoke consent, after which all ad flights must sunset within thirty days.
Common Mistakes That Get Brands Sued
The most expensive error is conflating model release with talent release. A model release grants permission to photograph a person; it does not authorize a brand to feed those images into a generative AI model and synthesize new poses, expressions, or products that the original model never performed. The second mistake is assuming open-source model licenses cover commercial advertising. Most open-source image models (Stable Diffusion, FLUX, SDXL variants) forbid the generation of identifiable likenesses of real people without additional rights clearance, and the license is between the developer and the user, not the user and the depicted individual. A third pitfall is relying on stock-image metadata that mentions "editorial use only"; editorial rights do not transfer to commercial advertising, and the licensing chain typically does not authorize downstream model training. Finally, brands frequently misclassify synthetic influencers as fictional characters. Courts have applied right-of-publicity analysis to AI personas when the digital double is based on a real person's training data, regardless of whether the output name is changed.
Comparing the Main Paths for AI Product Imagery
| Approach | Consent Requirement | Disclosure Burden | Cost Range (per asset) | Best For |
|---|---|---|---|---|
| AI-cloned model of a real person | Notarized release, full NIL scope | High — must label as synthetic | $500–$5,000 | Celebrity or athlete campaigns |
| Fully synthetic virtual influencer | None for likeness, but trademark check required | Medium — voluntary AI label | $150–$800 | Always-on brand persona content |
| AI product on AI background | No person depicted | Low — no person to label | $5–$40 per image | Catalog and e-commerce at volume |
| Real model photographed + AI upscaled | Standard model release covers source photos | Medium — if faces regenerated | $80–$300 | Hybrid fashion and beauty |
| User-generated-content-style AI | Inherited consent from UGC plus platform terms | Variable | $10–$60 | Social and creator partnerships |
When to Act and What to Budget
If you are running product advertising today that uses any AI-generated image containing a recognizable human face, voice, or body, the safe move is to assume you need consent and to obtain it before the next creative flight refresh, which is usually a 60–90 day cycle. Budget $300–$1,500 for a properly drafted and notarized release if a real person's likeness is involved, plus $0.50–$2.00 per impression for synthetic-content disclosure if you choose to add a visible "AI-generated" label, which is not currently required federally but is mandatory under New York law for certain synthetic performer content. Brands that operate in apparel, cosmetics, sportswear, and footwear should treat compliance as a hard launch blocker because these verticals concentrate the highest volume of right-of-publicity claims. If your ad spend is below $10,000 per month, in-house legal review is usually sufficient; above that threshold, expect to spend 0.1–0.3 percent of media spend on AI-rights clearance and documentation.
Practical Steps for the Next 30 Days
Begin by auditing every active creative asset for identifiable human likeness. Tag each asset as "real person depicted," "synthetic but based on real person," or "fully synthetic." For category one, confirm a signed release covers the current channel and format. For category two, obtain retroactive notarized consent or retire the asset. For category three, ensure your generative AI vendor's terms-of-service permit commercial advertising use, and keep a record of the model version, prompt, and seed used to generate the asset so that you can prove non-infringement if challenged. Update your creative brief template to require an AI-rights disclosure line, and train your agency partners on the new gating questions. Finally, if you sell on Amazon, re-read the September 2025 policy update and remove any listing image that depicts a real person without documented permission.
Where the Law Is Heading Through 2027
Expect at least six additional states to enact AI-disclosure laws by mid-2027, with California and Texas the most likely next movers. Federal momentum behind the NO FAKES Act is building, and the FTC has signaled that AI deception in advertising will be an enforcement priority in its 2026–2027 strategic plan. Synthetic-content labeling standards, including the C2PA content-credentials specification, are being integrated into Adobe, Microsoft, and Google tools, which will make provenance tracking automatic rather than manual. Brands that build consent and provenance into their workflow now will avoid a costly retrofit in eighteen to twenty-four months when the patchwork becomes a single federal floor.
The Bottom Line
Consent is not optional, and it is not a single checkbox. It is a documented chain of permissions covering training data, generation, distribution, and renewal, and it must be enforceable in every state where your ad runs. The cheapest, fastest, and lowest-risk path for most product advertisers is to keep real humans out of generative AI product imagery entirely. When a human must appear, treat the consent process with the same rigor you would apply to a celebrity endorsement deal, because the law now treats it as functionally identical.