Developer guide
Before your AI feature uses a real person's face or voice
Building deepfake, face swap, voice clone or celebrity avatar features with a real person's face, voice or persona? Before you generate, check consent with Rightis, a likeness rights API and public registry of what each person allows under their right of publicity. Not registered is not cleared, and a holder who has said nothing is not a yes either.
Features this applies to
If a real person or character can be recognised in the output, check before you generate. These are the features people build most often.
Avatars and profile images
Avatars that look like a specific person, restyled portraits, and composites that look like a photo with a celebrity.
Face swap
Replacing a face in a photo or video with someone else's. The person whose face goes in is the one you check.
Voice clone and speech synthesis
Reading text, singing or dubbing in a specific person's voice. Ask with voice in asset_types.
Celebrity chatbots and personas
Bots that talk as a real person or character, with their name, manner and personality. It applies even without a face or a voice if the bot presents itself as that person.
User uploads of other people
Nothing guarantees that the person in an uploaded photo is the uploader. Without a check that it is their own photo, treat it as someone else's face.
What checking means
- 01
Decide who it is
A check takes a Rights ID, a code that starts with BR. You can find it by searching the public registry by name. If you cannot tell who it is, you have nothing to check, and that is not permission.
- 02
Describe what you will do
Put the use in plain words in use_type, the assets you need in asset_types (face, voice, style, image), the generation method in ai_methods and country codes in territory. Set for_training separately if you will train. Generation and training are separate rights.
- 03
Read the decision and the next action
decision is one answer for the use you described, and the most restrictive scope wins. Your code follows next_action. Even when decision is allowed, the next step is to request a licence.
- 04
License, then record
Request the licence at the next_action url. An empty url means the holder is not taking requests right now. Once the licence is active, you can record use in the usage ledger and get a signed provenance manifest for each output.
Check it in code
In the SDK, rights.check calls the keyed check when an API key is set and the keyless public resolve when it is not. Both answer in the same shape. Keep the key in a server environment variable, never in browser code.
The keyless public endpoint only answers for real people listed in the public registry. The sandbox sample people are only found with a sandbox key.
npm install @rightis/sdk
npx rightis check BR-XXXX-XXXX-XXXX --use "avatar generation" --asset faceimport { Rightis } from '@rightis/sdk';
// Reads RIGHTIS_SECRET_KEY. Without a key it calls the keyless public resolve.
const rightis = new Rightis();
const result = await rightis.rights.check({
rights_id: 'BR-XXXX-XXXX-XXXX',
use_type: 'avatar generation',
asset_types: ['face'],
ai_methods: ['image_generation'],
});
console.log(result.decision, result.next_action.type, result.next_action.url);curl -X POST https://rightis.org/api/public/v1/rights/resolve \
-H "Content-Type: application/json" \
-d '{
"rights_id": "BR-XV7E-8X7Z-ERB7",
"use_type": "voice clone",
"asset_types": ["voice"],
"ai_methods": ["voice_synthesis"]
}'{
"rights_id": "BR-XXXX-XXXX-XXXX",
"registered": false,
"identity": null,
"decision": null,
"scopes": [],
"unmapped": [],
"training": { "decision": "unspecified", "do_not_train": true },
"next_action": {
"type": "not_registered",
"url": null,
"reason": "No listed registration for this rights_id. Not registered is not permission. Treat the identity as not cleared for AI use."
},
"profile_url": null,
"notes": ["Rightis answers only for identities the holder chose to list."]
}What to do with each decision
A decision is not a licence. Whatever the decision, the one thing that lets you generate is a licence that is active now.
- decision: allowed
- The holder pre-authorised these scopes. It is not free use. next_action is request_license, and the request can be approved without the holder reviewing it. Conditions such as the fee floor are checked when you file the request.
- decision: requires_approval
- The holder decides each request. Request a licence and do not generate while you wait. You also get this when words in unmapped could not be mapped to a scope.
- decision: unspecified
- The holder has never said anything about this use. It is not permission. Request a licence to ask them.
- decision: denied
- The holder refuses at least one scope this use touches. next_action is stop. Do not generate.
- next_action: not_registered
- The Rights ID is not in the registry, and decision is null. Not registered is not cleared. It does not mean the person has no rights, only that Rightis has nothing on record.
- next_action: describe_use
- The person was found but no use was described. Ask again with use_type or asset_types.
Training is answered separately. Read decision and do_not_train under training. Someone who allows generation may still not allow training.
If you could not reach Rightis or got an error, do not read it as a yes. Not being able to check is not the same as being cleared.
import { Rightis, RightisError } from '@rightis/sdk';
const rightis = new Rightis(); // server side only
type Gate = { generate: boolean; reason: string; url?: string | null };
export async function mayGenerate(rightsId: string, licenseCode?: string): Promise<Gate> {
// 1. An active licence for this use is what lets you generate.
if (licenseCode) {
const v = await rightis.licenses.verify({ license_public_code: licenseCode });
// Also compare v.rights_categories, v.media_types and v.territory with your use.
if (v.valid) return { generate: true, reason: 'active licence' };
}
// 2. No licence yet: ask what to do next.
let r;
try {
r = await rightis.rights.check({
rights_id: rightsId,
use_type: 'face swap video',
asset_types: ['face'],
ai_methods: ['video_generation'],
});
} catch (e) {
// Could not ask. Unknown is not cleared.
return { generate: false, reason: e instanceof RightisError ? e.code : 'unreachable' };
}
switch (r.next_action.type) {
case 'stop':
return { generate: false, reason: 'denied by the rights holder' };
case 'not_registered':
return { generate: false, reason: 'not registered is not cleared' };
case 'describe_use':
return { generate: false, reason: 'describe the use and ask again' };
case 'request_license':
// allowed, requires_approval and unspecified all land here. None is a licence yet.
return { generate: false, reason: r.decision ?? 'request a licence', url: r.next_action.url };
}
}Recording what you generated
These exist today. All three need an API key and are tied to a licence.
Usage ledger
Send uses such as generation, exposure or voice synthesis against a licence code, up to 500 at a time, deduplicated by event_id. In the SDK this is usage.log.
Provenance manifest
Send the SHA-256 hash of an output with the licence code and get a signed manifest back. It is not issued unless the licence is active now. The generation tool name is your declaration, not something Rightis verified. Not in the SDK yet; call the provenance path in the OpenAPI document.
Licence verify
Check whether a licence is valid now, by licence code or output hash. In the SDK this is licenses.verify.
await rightis.usage.log([
{
event_id: 'gen_01J9Z3K7', // your id, resends are reported as duplicate
license_public_code: 'L-XXXXXXXX', // usage is recorded only against a licence
occurred_at: new Date().toISOString(),
use_type: 'generation',
decision: 'allow',
content_hash: outputSha256Hex, // optional, hex SHA-256 of what you generated
},
]);Where the law stands
Laws in force and bills that are not law yet are listed separately. No law requires a Rightis check. A check tells you what the holder has set; it does not replace a legal assessment.
US federal
- In force
TAKE IT DOWN Act
Enacted May 2025; platform duties from 19 May 2026Covered platforms must provide a removal request process for non-consensual intimate imagery and take the image, plus known identical copies, down within 48 hours of a valid request. AI-generated and AI-altered images are covered. The FTC has begun enforcement.
Source: FTC - Bill
NO FAKES Act
Advanced by the Senate Judiciary Committee on 22 June 2026; not lawA bill that would create a federal right in digital replicas of voice and likeness, with a notice-and-takedown process. If it passes, the current state-by-state patchwork consolidates.
Source: Congress.gov
US state
- In force
ELVIS Act (Tennessee)
In force since 1 July 2024The first US state law to protect voice as a property right, aimed squarely at AI tools that clone a person's voice without consent. Signed 21 March 2024; 2024 Tenn. Pub. Acts ch. 588.
Source: Tennessee 주정부 - In force
AB 2602, AB 1836 (California)
AB 2602 from 1 January 2025; AB 1836 from 1 January 2026A contract that lets someone create a digital replica of a performer's voice or likeness must state specifically what will be made and obtain consent. Digital replicas of deceased personalities require the estate's permission.
Source: California Legislative Information
Korea
- In force
AI Framework Act (Korea)
In force since 22 January 2026Providers of generative AI must label output as AI-generated. Deepfake output requires a label a viewer can actually see. Fines are held back during an initial grace period.
Source: 국가법령정보센터 - In force
Unfair Competition Prevention Act (Korea)
In force since 8 June 2022Using a well-known person's name, likeness or voice for your own business, against fair commercial practice and to their economic detriment, is an act of unfair competition. This is the practical basis for commercial likeness and voice claims in Korea.
Source: 국가법령정보센터 - In force
Sexual Violence Punishment Act art. 14-2 (Korea)
Amendment in force since 16 October 2024Editing or synthesising a person's face or body into sexual material and distributing it is a crime; a 2024 amendment extended punishment to knowingly possessing, buying, storing or viewing such material.
Source: 국가법령정보센터
A summary of published statutes and government material, not legal advice. Talk to a lawyer about your own case. As of 10 September 2026.
Frequently asked questions
- Is there an API to check likeness rights and the right of publicity?
- Yes. Rightis has a keyless public decision API, a keyed check API, and an SDK and CLI on npm. Send a Rights ID and a described use, and it returns one of allowed, requires approval, unspecified or denied, plus a next action.
- How do I check consent in a deepfake or voice clone feature?
- Before you call the model, send the person's Rights ID, the use and the assets you will use (face, voice) and read the decision. Generate only under an active licence, and without one follow the next action in the answer.
- If the decision is allowed, can I generate right away?
- No. Allowed means a licence can be signed without the holder reviewing it, not that you may use the likeness without a licence. The next action is still a licence request.
- Can I use someone who is not registered with Rightis?
- No. Likeness rights and the right of publicity exist without registration. Not registered means Rightis has no record, not that you have permission. Treat a failed check the same way.