Get clear, specific permission before using a real person’s face, body, voice, name, or other identifying features in a synthetic intimate, deceptive, commercial, or harmful image. Finding a photo online, taking the photo yourself, or knowing the person does not create that permission.
This guide is practical information, not legal advice. Laws differ by country and state, and they are changing quickly. Consent is the safer standard even when a local law is unclear. Our responsible adult AI generation guide places consent within a broader check for age, privacy, purpose, and likely harm.
The test is not only whether the image started as AI. Ask whether a reasonable viewer could believe the output depicts a real, identifiable person.
What counts as a real-person AI image?
A result can identify someone without copying every detail of one photo.
Real-person signals include:
- A recognizable face
- A distinctive body, tattoo, scar, or birthmark
- A name attached to the image
- A familiar voice or mannerism
- A unique uniform, home, workplace, or event
- A close look-alike presented as the person
- Several details that identify the person when combined
The U.S. Copyright Office uses the term digital replica for an image, video, or audio recording that has been created or changed to realistically but falsely depict an individual. Its Digital Replicas Report explains both useful licensed applications and serious harms from unauthorized replicas.
A fictional character can still create a real-person problem if the output obviously points to a specific person.
What meaningful consent looks like
Consent is not one permanent yes. It should match the actual project.
Permission for a profile picture is not permission for an intimate edit.
They understand the tool, storage, audience, and possible reuse.
Work, money, housing, or relationship pressure can make a yes unreliable.
The agreement states what can be withdrawn before and after release.
Name the project, media, audience, duration, and commercial rights.
Keep a dated record that links to the actual source and planned output.
For intimate synthetic media, verbal permission is weak evidence. Use a written record and confirm again before publication.
Consent should cover
- What source material will be used
- What type of output will be created
- Whether nudity or sexual content is involved
- Whether the output may look photorealistic
- Who can see it
- Where it will be published
- Whether it can be sold or used in ads
- How long it can remain
- Whether edits or new versions are allowed
- How the person can ask for removal
A public photo is not a free pass
A public image can be easy to reach and still protected by copyright, privacy, publicity, platform rules, or social expectations. Access and permission are separate.
“But the person posted it”
Posting a photo lets people view it under the platform’s rules. It does not normally invite strangers to create an intimate digital replica.
“But the person is famous”
Public figures can be discussed, criticized, parodied, and depicted in many lawful contexts. They do not lose every right to identity, endorsement, privacy, or protection from deception. The exact legal balance depends on location and use.
“But the output has a disclaimer”
A label can reduce confusion. It does not create consent for the underlying use or erase harm from a sexual or defamatory image.
“But I never shared it”
Private creation can still expose a person’s source photo to a provider or create a file that may later leak. Non-sharing reduces one risk. It does not turn a non-consensual intimate replica into a responsible project. Before uploading any identifying photo, review the full private AI image generation data path.
Use a fictional adult, a licensed model, or your own consenting likeness when the identity of a specific real person is not required.
A real-person risk ladder
Not every use carries the same risk. Move upward only with stronger permission, documentation, and review.
The Federal Trade Commission has warned that AI-generated deepfakes can increase impersonation fraud. Its 2024 rulemaking announcement focused on tools and services used to harm consumers through impersonation.
Intimate content, minors, and unclear age are hard stops. NSFW Image Generator is planned for fictional adults and will not treat an uploaded face as proof of consent.
Keep a useful permission record
A permission record does not need to be filled with legal jargon. It does need to be specific.
Record:
- The full names or verified identities of the people agreeing
- The date
- The source images covered
- The type of synthetic output
- Whether the result may be intimate or sexual
- The tools or providers used
- Where the result may be stored
- The audience and publication channels
- Commercial use and payment
- The removal and expiration terms
For professional work, use a qualified lawyer and an appropriate model release. Keep source licenses, consent records, prompts, and final exports together.
A checkbox that says “I have permission” can support a process, but it does not verify age, identity, or the scope of consent by itself.
Sharing, labels, and provenance
Before sharing a realistic synthetic image, ask what a viewer may believe.
Use a clear AI label when the image:
- Resembles a real event
- Shows a real person doing something they did not do
- Appears in advertising or fundraising
- Could be mistaken for evidence
- Is published in news, politics, health, finance, or public safety
The C2PA Content Credentials standard can record the source and editing history of a file. C2PA explains that provenance can help people inspect origin and changes. It does not decide whether the content itself is truthful.
Keep labels attached when resizing or reposting. A caption far from the image may be missed.
If a non-consensual image has been shared
Do not blame the person depicted. Save evidence without spreading the file further, use the platform’s report tool, and seek local legal or support help.
StopNCII.org supports adults who are depicted in eligible non-consensual intimate images, including synthetic or generated images. The tool creates a hash on the person’s device. The original image does not leave the device. Participating platforms can compare uploads against that hash.
StopNCII cannot remove an image from the whole internet. Its FAQ explains eligibility, participating services, and limits.
If an image involves a person who was under 18 when it was created, do not upload or resend it as part of an adult removal process. Use the appropriate child-safety reporting service in your country or the reporting route provided by the platform.
Final creator checklist
- Can a reasonable viewer identify a real person?
- Is every subject clearly an adult?
- Does written permission cover this exact type of output?
- Does it cover storage, audience, commercial use, and duration?
- Could the image imply a false event, endorsement, or sexual act?
- Have private details been removed from the source?
- Will a clear AI label or provenance record travel with the file?
- Is there a clear removal contact?
If any answer is unclear, pause. A different fictional subject is often the simplest and most respectful solution.