Co-Signed by: StoryFile, Lookalike.com, and Authentex
Version 1.0, draft for public comment through September 30, 2026. Documentation CC BY 4.0; schema and code MIT.
Imagine finding a chatbot of one of your family members who has passed away. Someone built it from their public videos. It speaks in their voice, and it says things they never said and never would have. Today, there is a lack of standard procedures to consent to reproductions or to object to unauthorized reproductions. Every platform has a different form, a different bar, and mostly a different silence. Further, the platform has no standard way to evaluate your complaint even if it wants to do the right thing: no definition of who is "family", no way to answer the question, and no timeline. Legal frameworks vary significantly between states and countries.
At Lookalike and StoryFile, we make digital recreations of people, so we have spent a great deal of time on the question of what we owe the people being recreated, the living and the dead alike. This document is our answer, in the form of a standard any platform can adopt: one standard request a person or family can send, one process for how a company answers it, and one clear rule for whose word wins. The rule is simple enough to state in a sentence. When a recreation of a real person is challenged, the only answer that keeps it running is permission from that person or, if they have passed, from their family and estate. Never from the platform, and never from whoever created the profile.
For the living, the standard is simple and immediate. Register a refusal and no adopting platform may host a recreation of you. Find one anyway, and proving you are you is the only paperwork required to start the fourteen-day clock. Death is what makes the question hard, because the person can no longer answer for themselves. That is why most of this document concerns those who have passed, and why the part you fill out while alive matters so much.
Why we hesitated to publish this
We want to name our hesitations before asking you to take the document seriously, because they are the same objections you should be raising.
The first is that we profit from this technology. An ethics standard from a company that sells the thing being regulated invites cynicism, and the cynics have a point. Our answer is design rather than reassurance: the specification is permissively licensed, directives are portable across platforms, the refusal registry is free and requires no relationship with us, the adopter list and dispute outcomes are public, and stewardship moves to a neutral foundation as adoption grows. If we ever run this in a way that serves us rather than the people it protects, everyone else has the means to route around us. We would rather be constrained by architecture than trusted on character.
The second is that standards can normalize what they regulate. The honest state of the evidence is that we do not know what these recreations do to grief over years, and by making the category orderly we may be accelerating its acceptance. People who believe there should be no AI recreations of people who have passed will reasonably see this document as part of the problem. Our view is that the unmanaged status quo is worse, because the recreations are being built either way and today the families have no recourse. But we want to be clear that this is a judgment, not a proof, and the standard commits us to funding independent research and revising as evidence comes in.
Considering all of this, we came to think silence was the worst option of all.
What we owe people who have passed
Every previous generation settled what happens to a person's body, their property, and their words. We have burial law, probate law, copyright. What none of them anticipated is presence: the ability to sit a person's likeness in front of their family and have it respond.
We think one distinction does most of the moral work here. Replaying what a person actually recorded is remembrance; it is a photograph that answers. Generating new speech in their voice and face, words they never said, is something else: it is writing in someone's name after they can no longer object. The first deserves wide latitude. The second requires permission from someone entitled to give it, and it should always be possible for a person to refuse it entirely, in advance, in one sentence: do not recreate me. That refusal should not have to wait for a funeral to mean something. It protects the living first.
Historically, the ability to legally prevent the digital recreation of a person after their death has been severely restricted by the rigid boundary between privacy and publicity rights. Traditional "privacy rights" such as protections against defamation, false light, or the intentional infliction of emotional distress, are strictly personal. They protect an individual’s internal emotional and personal dignity, which means they are legally bound to the living; the moment a person dies, these privacy protections completely evaporate. This leaves families with virtually no privacy-based recourse if a private individual's voice or face is digitally re-engineered by AI for personal, non-commercial, or experimental use.
Conversely, the "right of publicity" treats an individual's likeness as a commercial property right that can successfully pass down to an estate, but it is traditionally limited to public figures and celebrities. To win a right of publicity claim, an estate must prove a strict standard of commercial use, demonstrating that the likeness was exploited to sell a product, drive advertising revenue, or imply a business endorsement. For the average private individual who never commercialized their identity during their lifetime, traditional publicity laws offer no shield. This creates a profound legal gap: ordinary citizens are left unprotected against non-commercial synthetic cloning, while the estates of public figures are forced to clear exceptionally high bars of commercial proof just to protect a decedent's memory.
The law is beginning to rewrite these definitions to protect both the living and the dead, shifting from a narrow commercial framework toward a broader right of identity ownership, though a massive enforcement gap remains. For example, the bipartisan federal NO FAKES Act, which cleared the U.S. Senate Judiciary Committee in June 2026, aims to bridge this chasm by granting every individual, famous or not, a licensable federal property right in their own voice and visual likeness that extends up to 70 years after death. Combined with the European Union's strict synthetic media disclosure rules taking effect on August 2, 2026, and existing estate-consent laws in states like California and New York, the legal system is finally establishing who has the right to sue after an unauthorized AI replica is released. However, these frameworks operate entirely in the realm of post-harm litigation; they fail to provide the immediate connective tissue or real-time verification infrastructure that digital platforms need to enforce a "do not recreate me" directive the moment an unauthorized file is uploaded.
Useful pieces exist elsewhere, and we build on them rather than around them. C2PA credentials prove content is synthetic but not that it was permitted. France proved the directive concept in 2016, for personal data, in one country. RSL Media's new Human Consent Registry lets living people record AI permissions, and our index honors its registrations, but it has no concept of death, no family authority, and no enforcement. The missing piece is the connective tissue between a family's objection and a platform's obligation. That connective tissue is the entire proposal.
The standard, in plain terms
It has two parts.
The first is the Directive: a document you create while you are alive that records what you permit, effective the moment you sign it and continuing after your death. It can be one sentence: do not recreate me. That refusal protects you now, not just later, and it binds your heirs when you are gone. You do not need a Directive for this standard to protect you, but one makes every future dispute trivial, because your own recorded word beats everything. It exists in three layers: one page in plain language your family can read, legal text that fits into a will or trust, and a machine-readable file platforms can check.
Instead of a rigid, hierarchical tier system, your Directive configures a multi-dimensional Consent Matrix. This approach decouples your choices entirely, allowing you to opt into or out of independent variables across six core axes:
- Modalities: Individual opt-in controls for specific outputs (text, voice, video).
- Generation Type: A strict dividing line between Replay (the playback or distribution of historical media you actually recorded) and Generative (allowing AI to synthesize entirely new words, movements, or synthetic performances).
- Audience & Context: Granular targeting for who can interact with the replica, separating private family use from educational research or the general public.
- Commercial Exploitation: Explicit binary switches to permit or completely ban monetization, licensing deals, or commercial appearances.
- Source Material: A strict whitelist defining exactly what data an AI is allowed to ingest to train your digital persona, whether it is restricted to your published books and public interviews, or extended to highly personal data like social media history, private emails, and home videos.
- Topic Guardrails: A definitive whitelist or blacklist governing the conceptual boundaries of your digital avatar’s speech. This allows you to explicitly bar your replica from engaging in sensitive, volatile, or uncharacteristic domains, such as politics, commercial_endorsements, religion, or vulgarity, even within an otherwise permitted audience tier.
Two defaults matter: your Directive is honored on any participating platform, not just the one that captured it, because consent should not be a lock-in mechanism; and your data may not train models beyond your own recreation unless you explicitly say so. You set a term, 25 years by default, renewable only if you allowed it, ending with verified deletion. While you are alive, you are your own steward: you can grant, narrow, or revoke directly, and platforms have thirty days to comply. For afterward, you name a Steward, a person who can pause, narrow, or retire a recreation at any time, but can never expand what you granted.
The machine-readable layer is the part platforms actually check, and it is deliberately plain. Here is what one looks like for a person who chose a Generative Private Replica (text and voice only, strictly for family, using only books and interviews as source material, with a hard ban on commercial use, topic guardrails, and no external model training):
{
"dld_version": "2.0",
"subject": {
"identity_hash": "sha256:8f2a44c1...",
"executed": "2026-09-14T15:30:00Z"
},
"steward": {
"primary": "steward-contact-ref",
"successor": "successor-contact-ref"
},
"consent_matrix": {
"modalities": {
"text": true,
"voice": true,
"video": false
},
"generation_allowance": {
"replay_historical_media": true,
"generative_synthetic_media": true
},
"audience_and_context": {
"private_family_only": true,
"educational_and_research": false,
"general_public": false
},
"commercial_exploitation": {
"allow_commercial_use": false,
"allow_licensing_deals": false
},
"allowed_source_material": {
"public_interviews_and_appearances": true,
"published_written_works": true,
"social_media_history": false,
"private_emails_and_texts": false,
"private_photos_and_home_videos": false
}
},
"guardrails": {
"excluded_topics": ["politics", "endorsements", "religion"],
"portable_across_platforms": true,
"allow_external_model_training": false
},
"term": {
"years_after_death": 25,
"steward_may_renew": false,
"action_on_expiration": "verified_purge"
},
"signature": "ed25519:..."
}
The full schemas, including the ones for challenges and Consent Receipts, live in the public repository. Honoring a Directive requires an index lookup and a signature check. Nothing here is exotic, and that is deliberate: the hard part of this problem was never the engineering.
Directives are created where identity checks already happen, on platforms by their verified users and through estate lawyers doing ordinary work, and they are published to a shared index. At launch, the index does one thing anyone can do in minutes with a free public tool: register a refusal, effective immediately. Refusals require identity verification, because otherwise anyone could file a fake one in someone else's name. The index stores no photos, no voice data, and no biometrics, only protected identity details like name and date of birth, and it cannot be searched by face or voice. This is deliberate. A consent database that could be searched by face would eventually become the surveillance tool it exists to prevent.
For the majority who leave no Directive, authority goes where the law already puts it. If an estate is open, the executor speaks. If not, the standard uses the same ladder the law uses for decisions about a person's remains: spouse or partner, then a majority of adult children, then parents, then siblings. Society settled long ago who decides what happens to a person's body; the likeness follows the same familiar chain. If family members disagree, an objection from anyone of equal or higher rank freezes the outcome until they resolve it, privately or in court. The platform is never the referee.
The takedown process
This is the operational core, and a platform can stand it up in about a week.
Who can file: first and simplest, the person themselves, alive and holding nothing but government ID; no other paperwork is needed to challenge a recreation of yourself. After death, a Steward, an executor, anyone on the next-of-kin ladder, or a holder of the applicable likeness rights, verified with ordinary documents: government ID, plus a death certificate and executor letters or a sworn family declaration where relevant. Verifying the challenger is what keeps the process from becoming a harassment tool.
Grounds: a recreation comes down if no one with authority ever permitted it; if the person registered a refusal; if it exceeds the scope that was granted, like public video when only private text was allowed; if it fails to disclose that it is synthetic; if it puts invented convictions or endorsements in the person's mouth; if its term has expired; or if a revocation was ignored, whether it came from the person while alive or their Steward after.
The platform's obligation: within fourteen days, show valid authorization or take the recreation down. The platform notifies the creator, who has the same window to substantiate the consent they attested to when they built it. No substantiation, no content. Creators who falsely attest repeatedly lose access, the same way repeat copyright infringers do today. A platform or estate that assembled its authorization up front, as commercial licensing deals naturally do, resolves a challenge in a day by producing that record, which the standard calls a Consent Receipt. Assembling one early is encouraged and never required.
We should explain what this standard deliberately does not do: it does not govern creation. We considered a version that verifies identity before anyone can make a recreation, and we rejected it for three reasons. It would turn every platform into a checkpoint. It would demand government ID from millions of people doing nothing wrong. And it would still miss the actual bad actors, who do not use compliant platforms. Platforms already ask creators to attest they have consent, ours included; what those checkboxes have always lacked is a consequence. Notice and takedown supplies the consequence, and it places the burden of proof at the moment of dispute, on the few, rather than at the moment of creation, on everyone. It is how the internet already governs copyright, defamation, and impersonation. Imperfectly, but workably, and we will take proven and imperfect over elegant and imaginary.
What keeps a voluntary standard honest
People reasonably ask what forces compliance. The honest answer is nothing. That is what voluntary means, and we think it is a strength rather than an evasion. This is an ethical standard that companies adopt because recreating a person against their wishes is wrong, and because being able to say credibly that you will answer a grieving family, or a living person who never consented, in fourteen days is worth something.
Adoption works at the level of the platform, not the product. A company that adopts may say so on its site and appears on the public adopter list maintained alongside the specification. There are no badges stamped on every digital person. The standard's name is protected, so claiming adherence falsely is actionable as false advertising, and a platform that ignores valid challenges comes off the list, publicly.
The rest of the pressure comes from where it always comes from. Families are the detection layer, and the fourteen-day clock is the mechanism they hold. Counterparties multiply it: enterprises writing adherence into vendor contracts, AI providers requiring it of their customers, insurers pricing coverage lower for platforms with a working process. Existing law is the backstop; the standard creates no liability because publicity law already does, and a platform that honored a valid challenge has a documented defense while a platform that ignored one is exposed, now visibly.
And one limit we want to state rather than bury: none of this stops a bad actor with open-source tools, and we do not claim it does. It governs the legitimate market, companies with brands and legal exposure, which is where families can actually get an answer. Payment-card security standards operate on exactly the same scope, and they have done a great deal of good anyway.
Final thoughts
Every previous generation settled what happens to a person's body, their property, and their words. Ours has to settle what happens to their presence. We do not think we get to opt out of that question. We only get to answer it deliberately or by accident, and this standard is our attempt at deliberately.
Comments and adoption inquiries: privacy@lookalike.com.
© 2026 Authentic Interactions Inc.
