Voice cloning and consent: proving you had the right to use a voice
AI Technology

Voice cloning and consent: proving you had the right to use a voice

Voice cloning consent disputes are rarely about whether permission was given. They are usually about whether anyone can prove exactly what was agreed and when. Here is why right-of-publicity law for voice varies by jurisdiction, what EU AI Act Article 50 adds on top of consent, and where a qualified timestamp actually helps, and where it does not.

S
Swiss Trust Layer Editorial Team· Legal Technology Analysis
·July 23, 2026· 6 min read
Voice cloning and consent: proving you had the right to use a voice — Swiss Trust Layer

A voice-AI company clones a voice talent's voice for a product feature. The talent signs a release, or there is a recorded call where they agree to the terms. Eighteen months later the talent, their estate, or a platform disputes what was actually agreed. Was the license for one product or every product the company ships. Did it cover training a new model version. Did it expire. The company has a document or a recording, but nothing that proves it was not altered after the fact, and nothing that proves exactly when it was signed. That gap, not the underlying right-of-publicity question, is where these disputes are actually won or lost.

This post is about that gap: how to make a voice consent record hold up later, not about what right-of-publicity or personality-rights law requires in any specific place, because that varies by jurisdiction and is a question for a lawyer licensed where the voice talent lives and where the product is sold.

Voice rights are real, but there is no single global standard

Several jurisdictions now treat a person's voice as protected property, but the rules differ enough that a consent process built for one place will not automatically cover another.

  • Tennessee, United States. The ELVIS Act, in effect since 1 July 2024, was the first US state law to expressly extend the statutory right of publicity to an individual's voice, and it defines voice broadly enough to cover a simulation, not just a recording of the actual person.
  • Illinois, United States. The Biometric Information Privacy Act treats a voiceprint as a biometric identifier and requires written consent, including the purpose and retention period, before a private company collects or uses one. An electronic signature satisfies the written-consent requirement as of August 2024.
  • Other US states and other countries. Most other jurisdictions rely on a mix of general right-of-publicity, defamation, data-protection, or personality-rights law rather than a voice-specific statute, and the strength of protection, who can enforce it, and what counts as consent all differ. Treating any one jurisdiction's rule as the global default is a common and expensive mistake.

What is consistent across all of these frameworks is the underlying requirement: documented, purpose-specific consent from the person whose voice is being used, obtained before the voice is cloned or trained on, not after.

The EU AI Act adds a disclosure duty on top of consent

Consent from the voice talent and public disclosure to the audience are two separate obligations, and a voice-AI product needs both. From 2 August 2026, Article 50 of the EU AI Act requires deployers of an AI system that generates or manipulates audio content constituting a deepfake to disclose that the content was artificially generated or manipulated. A cloned voice used to portray a real person saying something they did not say, including in public-interest content such as news or commentary, falls squarely inside that obligation. The article carries narrow exceptions: content that is evidently artistic, satirical, or fictional only needs to note that generated content exists, in a way that does not interfere with the work, and use authorised by law for detecting or prosecuting crime is exempted outright.

Having the voice talent's consent does not satisfy the Article 50 disclosure duty, and disclosing to the audience does not substitute for having consent from the person whose voice was cloned. They answer different questions: consent answers whether you were allowed to make the clone, disclosure answers whether the audience was told it is synthetic.

Where these disputes actually happen: not the law, the record

Assume the company did the right thing. A voice talent gave verbal agreement on a recorded call, or signed a release describing the scope of use. In our experience advising on document-evidence questions, this is usually where the real exposure sits, not in whether consent was obtained at all, but in whether anyone can later prove exactly what was agreed and when.

A recorded call sitting in a shared drive can be re-encoded, trimmed, or simply have its file metadata questioned. A signed PDF can be edited after signature if the signature itself was not cryptographically bound to that exact file. A verbal "yes, that's fine" in an email thread has no file-integrity guarantee at all. None of these problems are about whether consent was real. They are about whether the company can prove, to a court or an opposing lawyer two years later, that the consent record in front of them is the same one the voice talent actually agreed to, unaltered, and dated when it says it is dated.

That is the exact fact pattern a qualified timestamp is built to close.

What a qualified, sealed timestamp adds, and what it does not

Sealing the consent recording or the signed release with a qualified timestamp, of the kind recognised under ZertES in Switzerland or eIDAS in the EU, establishes two specific, narrow facts: that a specific file, in a specific state, existed at a specific time, and that the file has not been altered since. Applied to a voice consent record, that means the company can show exactly what document or audio file the talent agreed to, and exactly when the agreement was captured, without relying on a shared drive's modification date or an email server's word.

It is important to be precise about what that does not do. A sealed timestamp does not establish that the scope of consent described in the document covers a specific later use, that the person signing had the legal authority to grant the rights described, or that the underlying right-of-publicity or personality-rights question was correctly assessed for the relevant jurisdiction. Those are legal questions that depend on the document's actual wording and the applicable law, not on the timestamp. A timestamp strengthens the evidentiary weight of a consent record that is otherwise sound; it does not fix a consent record that was too narrow, too vague, or obtained from the wrong person in the first place, and Swiss Trust Layer is not a substitute for legal review of that scope.

A practical checklist for voice-AI teams

  • Get consent in writing or on a recording before cloning or training, not after a product ships.
  • Write the scope in plain terms: which products, which model versions, how long, and whether it covers derivative or future training runs.
  • Seal the signed release or the consent recording with a qualified timestamp at the moment it is finalised, not months later.
  • Keep the disclosure obligation separate from the consent question. Confirm with counsel whether Article 50 or an equivalent local disclosure rule applies to the specific output before it ships.
  • Re-confirm and re-seal consent when the scope of use changes, rather than assuming an old release stretches to cover it.

Companies building on provenance for AI training and content data face the same underlying evidence problem across training data, model documentation, and consent records: the value is rarely in the fact that something was agreed, it is in being able to prove exactly what was agreed and when, months or years after the conversation is over.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

C2PA content credentials aren't enough on their own
AI & Technology

C2PA content credentials aren't enough on their own

C2PA Content Credentials give AI-generated content a signed history, but the metadata is routinely stripped by re-uploads, screenshots, and platform recompression. Here is what the standard actually verifies, where it breaks down in practice, and why an independent, qualified timestamp is worth adding alongside it.

July 21, 2026Read more →
The EU AI Act, Article 50: what 'AI content transparency' means from August 2026
AI & Technology

The EU AI Act, Article 50: what 'AI content transparency' means from August 2026

Article 50 of the EU AI Act becomes applicable on 2 August 2026. It requires AI providers to disclose direct interaction, mark synthetic content as machine-readable and detectable, and flag deepfakes and AI-written public-interest text. Here is what the article requires and where content provenance fits, and where it does not.

July 20, 2026Read more →
For UAE company-formation firms: sealed, verifiable corporate documents
Country Markets

For UAE company-formation firms: sealed, verifiable corporate documents

UAE company formation runs through a chain of documents, from the Memorandum of Association to shareholder resolutions and powers of attorney, that pass through several parties before a license is issued. Here is what a sealed, timestamped record adds for corporate-services firms handling multi-jurisdiction incorporations, and where it fits alongside UAE notarization and attestation requirements.

July 26, 2026Read more →
Signing legally in the UAE with UAE Pass: a simple guide
Country Markets

Signing legally in the UAE with UAE Pass: a simple guide

UAE Pass is the UAE's national digital identity and e-signature platform, backed by Federal Decree-Law No. 46 of 2021. Here is when UAE Pass is enough on its own, and when a document needs a signature built for recognition outside the UAE too.

July 24, 2026Read more →
How AI companies prove training-data provenance and defend copyright claims
AI & Technology

How AI companies prove training-data provenance and defend copyright claims

AI companies face two distinct exposures when training models: EU AI Act Article 10's data governance requirements, and civil copyright claims over training data. Here is what a defensible dataset provenance record actually needs, and what a qualified timestamp on a dataset hash can and cannot prove.

July 22, 2026Read more →