Superseded. This is version 1.0 of the Consent Standard, kept exactly as published on 10 September 2026. The current version is 1.1.
IMAGORA
Open Standard

The Consent Standard

What must be true before a real person's face and voice are recreated by a machine — and what must remain true afterwards.

Version
1.0
Published
10 September 2026
Status
Open — free to adopt
Patent pending
US 64/153,971

Recreating someone's likeness is now trivial. Establishing that they agreed to it is not, and almost nobody is doing it. This document sets out the minimum an organization should hold itself to. It is published so that others can hold themselves to it, and so that anyone buying this technology has something concrete to ask a vendor for.

It is published by Imagora, which operates the likeness registry this standard describes. Imagora does not make marketing videos and does not compete with the organizations expected to adopt this. That neutrality is the point, and it is why the standard does not live with an operating vendor.

Personæ is its first adopter — it builds AI-generated digital identities for organizations and enforces the standard's core rule in software today: no likeness is generated before a consent record exists. The remaining clauses are being built into its systems.

How to read this. Part One is the short form: five clauses and the exact consent language, written to be copied. Part Two is the complete operating standard — ten Articles covering the full lifecycle of a digital presence, for organizations implementing this at scale. Part One is what you adopt. Part Two is what running it properly actually involves.
Part One

The Consent Standard

Deliberately short. A standard nobody reads protects nobody.

01

Consent precedes creation

No likeness is generated before a consent record exists. This is enforced in software, not in policy: provisioning refuses to run without one. There is no override, and no “we'll collect it later.”

Consent is given by the depicted person, actively — a checkbox that is never pre-ticked, and a typed signature. Consent given by an employer on an employee's behalf is not consent.

The language, verbatim · English · v1.0

I authorize the creation and use of an AI-generated digital likeness of my face and a synthetic version of my voice, from the photograph and voice sample I provide, to generate video and audio messages on my behalf. I confirm I am the person depicted, that I own or control these rights, and I grant permission to produce and deliver these AI-generated messages to prospective and existing customers. I understand these messages are AI-generated. I may revoke this authorization at any time, which stops future generation; revocation does not retroactively affect messages already sent.

Español · v1.0

Autorizo la creación y el uso de una imagen digital generada por inteligencia artificial de mi rostro y una versión sintética de mi voz, a partir de la foto y la muestra de voz que proporciono, para generar mensajes de video y audio en mi nombre. Confirmo que soy la persona representada, que poseo o controlo estos derechos, y otorgo permiso para producir y entregar estos mensajes generados con IA a clientes actuales y potenciales. Entiendo que estos mensajes son generados por IA. Puedo revocar esta autorización en cualquier momento, lo cual detiene la generación futura; la revocación no afecta los mensajes ya enviados.

02

Disclosure travels with the output

Every generated message carries a visible statement that it is AI-generated and that the depicted person consented. Not in a footer nobody reads — on the artifact itself, wherever it is played.

On every output

AI-generated message from [Name] · created with their consent.

Mensaje generado con IA de parte de [Nombre] · creado con su consentimiento.

A recipient who cannot tell they are watching a synthetic person has been deceived, whatever the paperwork says.

03

The record is the asset

Consent that cannot be produced on demand did not happen. Every record is immutable and versioned, so it can be shown years later exactly as it was agreed.

FieldWhy it is captured
signer_nameTyped signature, under the E-SIGN Act
signer_emailIdentifies the depicted person, not the buyer
timestampProves consent preceded creation
ipCorroborates the signing event
consent_versionProves what was agreed, not merely that something was
scopeBounds the permitted use

Versioning is the clause most often skipped and the one that matters most. Without it, an organization can only say a person consented — never to what.

04

Revocation is real, and it is bounded

05

What this is built against

These are the regimes the standard is designed to satisfy. It is not legal advice, and it is not a substitute for counsel in any jurisdiction.

TN
ELVIS Act — voice and likeness protection, including liability for the tools that distribute it.
NY
Synthetic-performer disclosure requirements.
CA
AI Transparency Act, effective 2 August 2026 — manifest disclosure on generated content. Civil Code §3344 for likeness.
IL
BIPA — treats a voiceprint as a biometric identifier, requires consent before collection, and carries a private right of action. Separately, HB 4875 covers unauthorized AI replicas.
PR
Act 139-2011 — written consent is the standard; a single unauthorized commercial use is a violation, regardless of any employment relationship.
BR
LGPD — biometric data as sensitive personal data.

The pattern across all of them is the same. The line between lawful and unlawful runs through consent — obtained first, recorded properly, and disclosed at the point of delivery. Everything in this document follows from that.

06

Adoption

This standard is free to adopt, in whole or in part, with or without attribution. Copy the clauses. Use the field list. Hold your vendors to it.

Patent pending: U.S. provisional applications 64/009,279 and 64/153,971, filed by Imagora's founder. Publication of this standard is not a licence to any patented method; the consent language and record format above are offered freely and separately.
Part Two

Digital Presence Governance Standards

The complete operating standard, in full. Ten Articles covering authorization, creation, deployment, monitoring, suspension, retirement and recordkeeping across the whole life of a digital presence.

Where the two parts differ. Part One is what a person is owed. Part Two is what an organization must operate to deliver it. Written for a platform operator implementing this at scale; a single practitioner needs only Part One.
§

Foundational principle

Art. 1

Purpose and application

These Standards establish the operational framework for authorization, creation, configuration, deployment, administration, monitoring, modification, suspension, retirement, and recordkeeping for Digital Presence operating through a Digital Presence and Orchestration Platform. Where an operator adopts these Standards contractually, they are incorporated by reference into the applicable agreements.

Art. 2

Governing principles

2.1Authenticity

Digital Presence should accurately reflect the approved identity, role, authority, function, or organizational purpose represented.

2.2Authorization

No Authentic Digital Identity will be activated without the applicable authorization from each Consenting Authorized Individual or Team member required by the Platform Operator.

2.3Transparency

The Platform Operator administers appropriate disclosure practices consistent with applicable law, Platform configuration, and these Standards.

2.4Lifecycle administration

Each Digital Presence remains subject to documented authorization, approval, deployment, monitoring, modification, suspension, retirement, and Governance Recordkeeping throughout its lifecycle.

2.5Organizational authority

The Customer retains authority over its personnel, business decisions, content approvals, and deployment instructions. The Platform Operator administers the Platform and relies on the Customer's authorized chain of command.

2.6Platform integrity

Digital Presence may be deployed only through approved Platform Services, configurations, channels, and workflows.

2.7Continuous evolution

The Platform will evolve to incorporate new technologies, channels, practices, and operational capabilities while preserving Platform integrity and Customer relationships.

2.8Responsible use

Digital Presence must not be used for unauthorized impersonation, material deception, unlawful discrimination, fraud, harassment, defamation, illegal communications, or other prohibited conduct.

Art. 3

Digital presence classifications

3.1Authentic Digital Identities

Authentic Digital Identities are derived from one or more Consenting Authorized Individuals or Teams through approved Identity Assets and the Platform Operator's authorization procedures.

3.2Synthetic Digital Personas

Synthetic Digital Personas are created independently of a specific individual, serve an approved organizational purpose, and may not intentionally impersonate a real person.

3.3Future classifications

Additional classifications will be introduced as Platform capabilities evolve. Each classification remains subject to appropriate approval, disclosure, lifecycle, and use controls.

Art. 4

Digital identity library

A Digital Identity Library may include approved Identity Assets, renderings, voice outputs, message variations, visual outputs, scripts, and other Digital Identity assets associated with one or more Consenting Authorized Individuals or Teams. Library assets may be reused, updated, or expanded only within the authorized Organization scope and subscribed Platform Services.

Art. 5

Lifecycle standards

5.1Authorization

Confirm required Organization authority and individual authorization.

5.2Creation and configuration

Develop outputs using approved Identity Assets, roles, messaging, branding, channels, and workflows.

5.3Approval and activation

Obtain required approvals before public activation unless an approved automated framework applies.

5.4Monitoring and modification

Monitor available Platform activity and address approved updates, inaccuracies, security concerns, or operational changes.

5.5Suspension

Suspend Digital Presence where reasonably necessary for law, security, consent, identity, Platform integrity, or risk reasons.

5.6Retirement and archival

Retire deployment when authorization ends, a subscription terminates, use becomes unlawful, or the Customer issues an authorized instruction. Preserve appropriate governance records as permitted or required.

Art. 6

Organizational administration

The Customer must maintain current designated representatives and notify the Platform Operator of material changes affecting Authorized Individuals, Teams, locations, brands, roles, or authority within the time required by the governing agreement. Authorized Individuals submit routine requests through the Customer's designated representative.

Art. 7

Disclosure and customer communication

The Platform Operator administers disclosure, labeling, provenance, or other transparency practices required by applicable law or selected for Platform integrity. The Customer may not remove or defeat disclosure controls. Platform communications should accurately represent the approved organizational role, purpose, and authority of the Digital Presence.

Art. 8

Presence intelligence

The Platform Operator may provide Presence Intelligence based on Platform-controlled signals, including Journey Coverage, Response Latency, Engagement Rate, Engagement Quality, Deployment Maturity, Platform Health, delivery, watch duration, completion, replay, clicks, workflow activity, and deployment status. Business results within Customer systems are outside the Presence Index unless separately integrated and authorized.

Art. 9

Governance records

The Platform Operator may maintain records of authorization, approvals, classification, deployment, material configuration changes, suspension, retirement, disclosures, and related administrative events. Records support Platform administration, security, legal compliance, identity protection, and dispute resolution.

Art. 10

Standards review and updates

These Standards are reviewed periodically for developments in technology, law, security, customer experience, operational practice, and Platform capabilities. Updates become effective according to the governing agreement and applicable notice requirements.