A voice-AI company clones a voice talent's voice for a product feature. The talent signs a release, or there is a recorded call where they agree to the terms. Eighteen months later the talent, their estate, or a platform disputes what was actually agreed. Was the license for one product or every product the company ships. Did it cover training a new model version. Did it expire. The company has a document or a recording, but nothing that proves it was not altered after the fact, and nothing that proves exactly when it was signed. That gap, not the underlying right-of-publicity question, is where these disputes are actually won or lost.
This post is about that gap: how to make a voice consent record hold up later, not about what right-of-publicity or personality-rights law requires in any specific place, because that varies by jurisdiction and is a question for a lawyer licensed where the voice talent lives and where the product is sold.
Voice rights are real, but there is no single global standard
Several jurisdictions now treat a person's voice as protected property, but the rules differ enough that a consent process built for one place will not automatically cover another.
- Tennessee, United States. The ELVIS Act, in effect since 1 July 2024, was the first US state law to expressly extend the statutory right of publicity to an individual's voice, and it defines voice broadly enough to cover a simulation, not just a recording of the actual person.
- Illinois, United States. The Biometric Information Privacy Act treats a voiceprint as a biometric identifier and requires written consent, including the purpose and retention period, before a private company collects or uses one. An electronic signature satisfies the written-consent requirement as of August 2024.
- Other US states and other countries. Most other jurisdictions rely on a mix of general right-of-publicity, defamation, data-protection, or personality-rights law rather than a voice-specific statute, and the strength of protection, who can enforce it, and what counts as consent all differ. Treating any one jurisdiction's rule as the global default is a common and expensive mistake.
What is consistent across all of these frameworks is the underlying requirement: documented, purpose-specific consent from the person whose voice is being used, obtained before the voice is cloned or trained on, not after.
The EU AI Act adds a disclosure duty on top of consent
Consent from the voice talent and public disclosure to the audience are two separate obligations, and a voice-AI product needs both. From 2 August 2026, Article 50 of the EU AI Act requires deployers of an AI system that generates or manipulates audio content constituting a deepfake to disclose that the content was artificially generated or manipulated. A cloned voice used to portray a real person saying something they did not say, including in public-interest content such as news or commentary, falls squarely inside that obligation. The article carries narrow exceptions: content that is evidently artistic, satirical, or fictional only needs to note that generated content exists, in a way that does not interfere with the work, and use authorised by law for detecting or prosecuting crime is exempted outright.
Having the voice talent's consent does not satisfy the Article 50 disclosure duty, and disclosing to the audience does not substitute for having consent from the person whose voice was cloned. They answer different questions: consent answers whether you were allowed to make the clone, disclosure answers whether the audience was told it is synthetic.
Where these disputes actually happen: not the law, the record
Assume the company did the right thing. A voice talent gave verbal agreement on a recorded call, or signed a release describing the scope of use. In our experience advising on document-evidence questions, this is usually where the real exposure sits, not in whether consent was obtained at all, but in whether anyone can later prove exactly what was agreed and when.
A recorded call sitting in a shared drive can be re-encoded, trimmed, or simply have its file metadata questioned. A signed PDF can be edited after signature if the signature itself was not cryptographically bound to that exact file. A verbal "yes, that's fine" in an email thread has no file-integrity guarantee at all. None of these problems are about whether consent was real. They are about whether the company can prove, to a court or an opposing lawyer two years later, that the consent record in front of them is the same one the voice talent actually agreed to, unaltered, and dated when it says it is dated.
That is the exact fact pattern a qualified timestamp is built to close.
What a qualified, sealed timestamp adds, and what it does not
Sealing the consent recording or the signed release with a qualified timestamp, of the kind recognised under ZertES in Switzerland or eIDAS in the EU, establishes two specific, narrow facts: that a specific file, in a specific state, existed at a specific time, and that the file has not been altered since. Applied to a voice consent record, that means the company can show exactly what document or audio file the talent agreed to, and exactly when the agreement was captured, without relying on a shared drive's modification date or an email server's word.
It is important to be precise about what that does not do. A sealed timestamp does not establish that the scope of consent described in the document covers a specific later use, that the person signing had the legal authority to grant the rights described, or that the underlying right-of-publicity or personality-rights question was correctly assessed for the relevant jurisdiction. Those are legal questions that depend on the document's actual wording and the applicable law, not on the timestamp. A timestamp strengthens the evidentiary weight of a consent record that is otherwise sound; it does not fix a consent record that was too narrow, too vague, or obtained from the wrong person in the first place, and Swiss Trust Layer is not a substitute for legal review of that scope.
A practical checklist for voice-AI teams
- Get consent in writing or on a recording before cloning or training, not after a product ships.
- Write the scope in plain terms: which products, which model versions, how long, and whether it covers derivative or future training runs.
- Seal the signed release or the consent recording with a qualified timestamp at the moment it is finalised, not months later.
- Keep the disclosure obligation separate from the consent question. Confirm with counsel whether Article 50 or an equivalent local disclosure rule applies to the specific output before it ships.
- Re-confirm and re-seal consent when the scope of use changes, rather than assuming an old release stretches to cover it.
Companies building on provenance for AI training and content data face the same underlying evidence problem across training data, model documentation, and consent records: the value is rarely in the fact that something was agreed, it is in being able to prove exactly what was agreed and when, months or years after the conversation is over.






