What must be true before a real person's face and voice are recreated by a machine — and what must remain true afterwards.
Recreating someone's likeness is now trivial. Establishing that they agreed to it is not, and almost nobody is doing it. This document sets out the minimum an organization should hold itself to. It is published so that others can hold themselves to it, and so that anyone buying this technology has something concrete to ask a vendor for.
It is published by Imagora, which operates the likeness registry this standard describes. Imagora does not make marketing videos and does not compete with the organizations expected to adopt this. That neutrality is the point, and it is why the standard does not live with an operating vendor.
Personæ is its first adopter — it builds AI-generated digital identities for organizations and enforces the standard's core rule in software today: no likeness is generated before a consent record exists. The remaining clauses are being built into its systems.
Deliberately short. A standard nobody reads protects nobody.
No likeness is generated before a consent record exists. This is enforced in software, not in policy: provisioning refuses to run without one. There is no override, and no “we'll collect it later.”
Consent is given by the depicted person, actively — a checkbox that is never pre-ticked, and a typed signature. Consent given by an employer on an employee's behalf is not consent.
The language, verbatim · English · v1.0I authorize the creation and use of an AI-generated digital likeness of my face and a synthetic version of my voice, from the photograph and voice sample I provide, to generate video and audio messages on my behalf. I confirm I am the person depicted, that I own or control these rights, and I grant permission to produce and deliver these AI-generated messages to prospective and existing customers. I understand these messages are AI-generated. I may revoke this authorization at any time, which stops future generation; revocation does not retroactively affect messages already sent.
Español · v1.0Autorizo la creación y el uso de una imagen digital generada por inteligencia artificial de mi rostro y una versión sintética de mi voz, a partir de la foto y la muestra de voz que proporciono, para generar mensajes de video y audio en mi nombre. Confirmo que soy la persona representada, que poseo o controlo estos derechos, y otorgo permiso para producir y entregar estos mensajes generados con IA a clientes actuales y potenciales. Entiendo que estos mensajes son generados por IA. Puedo revocar esta autorización en cualquier momento, lo cual detiene la generación futura; la revocación no afecta los mensajes ya enviados.
Every generated message carries a visible statement that it is AI-generated and that the depicted person consented. Not in a footer nobody reads — on the artifact itself, wherever it is played.
On every outputAI-generated message from [Name] · created with their consent.
Mensaje generado con IA de parte de [Nombre] · creado con su consentimiento.
A recipient who cannot tell they are watching a synthetic person has been deceived, whatever the paperwork says.
Consent that cannot be produced on demand did not happen. Every record is immutable and versioned, so it can be shown years later exactly as it was agreed.
| Field | Why it is captured |
|---|---|
| signer_name | Typed signature, under the E-SIGN Act |
| signer_email | Identifies the depicted person, not the buyer |
| timestamp | Proves consent preceded creation |
| ip | Corroborates the signing event |
| consent_version | Proves what was agreed, not merely that something was |
| scope | Bounds the permitted use |
Versioning is the clause most often skipped and the one that matters most. Without it, an organization can only say a person consented — never to what.
These are the regimes the standard is designed to satisfy. It is not legal advice, and it is not a substitute for counsel in any jurisdiction.
The pattern across all of them is the same. The line between lawful and unlawful runs through consent — obtained first, recorded properly, and disclosed at the point of delivery. Everything in this document follows from that.
This standard is free to adopt, in whole or in part, with or without attribution. Copy the clauses. Use the field list. Hold your vendors to it.
The complete operating standard, in full. Ten Articles covering authorization, creation, deployment, monitoring, suspension, retirement and recordkeeping across the whole life of a digital presence.
These Standards establish the operational framework for authorization, creation, configuration, deployment, administration, monitoring, modification, suspension, retirement, and recordkeeping for Digital Presence operating through a Digital Presence and Orchestration Platform. Where an operator adopts these Standards contractually, they are incorporated by reference into the applicable agreements.
Digital Presence should accurately reflect the approved identity, role, authority, function, or organizational purpose represented.
No Authentic Digital Identity will be activated without the applicable authorization from each Consenting Authorized Individual or Team member required by the Platform Operator.
The Platform Operator administers appropriate disclosure practices consistent with applicable law, Platform configuration, and these Standards.
Each Digital Presence remains subject to documented authorization, approval, deployment, monitoring, modification, suspension, retirement, and Governance Recordkeeping throughout its lifecycle.
The Customer retains authority over its personnel, business decisions, content approvals, and deployment instructions. The Platform Operator administers the Platform and relies on the Customer's authorized chain of command.
Digital Presence may be deployed only through approved Platform Services, configurations, channels, and workflows.
The Platform will evolve to incorporate new technologies, channels, practices, and operational capabilities while preserving Platform integrity and Customer relationships.
Digital Presence must not be used for unauthorized impersonation, material deception, unlawful discrimination, fraud, harassment, defamation, illegal communications, or other prohibited conduct.
Authentic Digital Identities are derived from one or more Consenting Authorized Individuals or Teams through approved Identity Assets and the Platform Operator's authorization procedures.
Synthetic Digital Personas are created independently of a specific individual, serve an approved organizational purpose, and may not intentionally impersonate a real person.
Additional classifications will be introduced as Platform capabilities evolve. Each classification remains subject to appropriate approval, disclosure, lifecycle, and use controls.
A Digital Identity Library may include approved Identity Assets, renderings, voice outputs, message variations, visual outputs, scripts, and other Digital Identity assets associated with one or more Consenting Authorized Individuals or Teams. Library assets may be reused, updated, or expanded only within the authorized Organization scope and subscribed Platform Services.
Confirm required Organization authority and individual authorization.
Develop outputs using approved Identity Assets, roles, messaging, branding, channels, and workflows.
Obtain required approvals before public activation unless an approved automated framework applies.
Monitor available Platform activity and address approved updates, inaccuracies, security concerns, or operational changes.
Suspend Digital Presence where reasonably necessary for law, security, consent, identity, Platform integrity, or risk reasons.
Retire deployment when authorization ends, a subscription terminates, use becomes unlawful, or the Customer issues an authorized instruction. Preserve appropriate governance records as permitted or required.
The Customer must maintain current designated representatives and notify the Platform Operator of material changes affecting Authorized Individuals, Teams, locations, brands, roles, or authority within the time required by the governing agreement. Authorized Individuals submit routine requests through the Customer's designated representative.
The Platform Operator administers disclosure, labeling, provenance, or other transparency practices required by applicable law or selected for Platform integrity. The Customer may not remove or defeat disclosure controls. Platform communications should accurately represent the approved organizational role, purpose, and authority of the Digital Presence.
The Platform Operator may provide Presence Intelligence based on Platform-controlled signals, including Journey Coverage, Response Latency, Engagement Rate, Engagement Quality, Deployment Maturity, Platform Health, delivery, watch duration, completion, replay, clicks, workflow activity, and deployment status. Business results within Customer systems are outside the Presence Index unless separately integrated and authorized.
The Platform Operator may maintain records of authorization, approvals, classification, deployment, material configuration changes, suspension, retirement, disclosures, and related administrative events. Records support Platform administration, security, legal compliance, identity protection, and dispute resolution.
These Standards are reviewed periodically for developments in technology, law, security, customer experience, operational practice, and Platform capabilities. Updates become effective according to the governing agreement and applicable notice requirements.