Voice & avatars

Source/event record · Guide · prepared 19 September 2026

Every borrowed face and voice needs a consent ledger

Creators need evidence of who authorized an identity, for which uses, for how long, and what happens when permission ends.

Prepared for local review · Site publication: not set · 481 words

A creator may have permission to record a voice without permission to clone it, or permission to use an avatar in one story without permission to turn it into an endlessly improvising companion. “The actor agreed” is not an operational record. A consent ledger makes scope and expiry inspectable before identity becomes a product dependency.

Record the grant, not the vibe

For every human-derived face, body, motion performance or voice, record the rights holder, asset, allowed media, character, territories, term, training permission, synthesis permission, sublicensing, moderation limits, revocation process and evidence location. Link to the signed agreement without placing private contracts in a public repository. Separate ownership from consent: owning an audio file does not necessarily authorize new speech in the performer’s identity.

Track transformations

A ledger entry should follow the asset into fine-tuning, voice conversion, promotional clips and user-generated remixes. C2PA’s Content Credentials specification provides a way to bind provenance assertions and edits to media. It does not decide whether a use was ethically or legally authorized; even C2PA’s explainer stresses that provenance is not a value judgment. Use credentials as one technical signal alongside contracts and release controls.

Design withdrawal before launch

Write down what happens if consent expires: stop new generation, remove discovery listings, preserve records needed for disputes, notify licensees, and decide whether old user conversations remain playable. A system that cannot locate downstream uses cannot honor a scoped withdrawal reliably. The FTC’s Voice Cloning Challenge likewise framed protection as a combination of products, policies and procedures rather than a single detector.

Try a hypothetical release gate

A studio proposes a companion voiced by a performer for a six-month event. The ledger shows promotional video and interactive dialogue are allowed, but training a reusable base voice and adult content are not. The build uses an approved bounded model, adds a visible synthetic-voice disclosure, disables user export of raw voice assets, and schedules generation shutdown before the licence ends. Legal review remains separate.

Audit for absence too

Include a “no human likeness” declaration for fully fictional assets, with notes on source material. Unknown should block release, not be converted into presumed permission. Recheck whenever the character, distribution channel or monetization changes.

Make the ledger a build dependency

Give every approved identity asset a stable identifier and require that identifier in the build manifest. Automated checks can reject an expired asset or one missing synthesis permission before packaging. Human review still decides ambiguous scope. If a marketing team requests a new trailer, the ledger should answer whether promotional use is covered without reopening private contracts casually. This turns consent from a launch-time promise into a condition that survives handoffs, staff changes and derivative assets.

The ledger cannot settle every jurisdiction’s publicity, copyright or labor rules. It can make the project’s evidence legible. Read it alongside the avatar standards record and the creator regression suite before a character reaches users.

Sources & reading trail