Maat ScanMaat Scan

Explainer

The Ethics of AI-Generated People: Who Owns a Face That Never Existed?

By Maat Scan · July 21, 2026

In October 2024, Hong Kong police arrested 27 people running a romance fraud operation that had extracted more than HKD 360 million (roughly US$46 million) from victims across Asia.1 The perpetrators had used face-swapping software during live video calls to impersonate attractive young professionals — faces that, in many cases, had never belonged to any real person. The victims had been deceived not by stolen identities but by synthetic ones. Nobody whose face was used could file a complaint. Nobody owned what had been taken.

The Synthetic Face Marketplace

Generated Photos offers a library of more than 100,000 AI-generated faces licensed for commercial use — stock imagery of a person who never drew breath.2 Rosebud AI, a Y Combinator graduate, built a service for advertisers that uses generative adversarial networks to synthesize faces and swap them to match target demographic profiles, so that a single ad campaign can show a different "model" to each audience segment.3 ThisPersonDoesNotExist.com, launched in 2019 as a demonstration, put a GAN-generated face in front of anyone with a browser, refreshing on every page load.

Critics of the advertising model have called this "artificial diversity": a company can populate its marketing with algorithmically generated faces spanning every ethnicity and age bracket without hiring a single diverse model, paying residuals, or obtaining releases. The appearance of inclusion is achieved by erasing the people whose inclusion was the point.

The underlying technology for all of these services was trained on scraped real faces. GANs and diffusion models learn the distribution of human appearance from datasets built largely without the knowledge or consent of the people in them. The synthetic faces that emerge are not random inventions — they are statistical recombinations of real ones.

The Accountability Gap

A face that never existed occupies a peculiar legal void. Under US copyright law, works generated entirely by AI without meaningful human creative contribution are not copyrightable — a position the US Copyright Office has maintained consistently since 2023.4 No copyright means no rights holder. Right of publicity laws, which protect real people's likeness from commercial exploitation, have no claimant when the likeness belongs to nobody. There is no model release requirement because there is no model.

This is not an abstract gap. Generative AI-enabled fraud surged 1,100% in 2025 according to identity verification provider Sumsub.5 Deepfake selfies — where a synthetic face is presented as a real person during identity verification — increased 58% in the same period, and roughly one in five biometric fraud attempts now involves a deepfake.10 AI-enabled scams are estimated to be 4.5 times more profitable than traditional fraud methods, partly because synthetic faces leave no victim of identity theft to trigger an investigation.11

The dating and online media sector recorded a 6.3% fraud rate across 2025 and into 2026, the highest among major industry sectors tracked by Sumsub.5 The Hong Kong romance ring was not an isolated incident — it was an early documented example of a method that has since scaled.

What the Law Has Built So Far

The legislative response has accelerated, though unevenly. In the United States, the TAKE IT DOWN Act — signed into law on May 19, 2025 — criminalizes the publication of non-consensual intimate deepfakes and requires platforms to remove flagged content within 48 hours of notice, with criminal penalties of up to two years for adult victims and three for minor victims. Platform removal obligations are enforced by the FTC.6 The law addresses one category of harm clearly. It does not address synthetic faces used in fraud, advertising, or political manipulation.

The NO FAKES Act, reintroduced in April 2025 and revised in May 2026, would create a federal right of publicity specifically covering digital replicas. The Senate Judiciary Committee advanced the bill unanimously by voice vote on June 18, 2026, over First Amendment objections from three Republican senators who voted for it anyway. The bill has broad bipartisan support and backing from SAG-AFTRA, OpenAI, Disney, Adobe, and Google, and would impose platform liability of up to $750,000 per violation.7 It now heads to a full Senate floor vote and, if that passes, House reconciliation; as of this writing it has not become law. Forty-six states had enacted some form of deepfake-specific legislation by spring 2026, but the patchwork is inconsistent on whether fully synthetic faces — those resembling no specific real person — fall within scope.

In the European Union, Article 50 of the EU AI Act requires that deployers disclose deepfakes to audiences, even when the deepfake is lawful. Enforcement begins August 2, 2026, with penalties up to EUR 15 million or 3% of global annual turnover, whichever is greater.8 The regulation mandates machine-readable markers for AI-generated content and proposes a standardized visible "AI" label. A Code of Practice reached its second draft in March 2026.

Japan has moved more slowly. The AI Promotion Act, passed May 28, 2025, is the country's first AI-specific legislation but carries no enforcement penalties.9 Japan's portrait rights — 肖像権 — remain judge-made rather than codified, which means courts apply them case by case without a statutory baseline. The Ministry of Justice announced a study group in April 2026 to examine AI-generated celebrity likeness and voice issues, and the ruling LDP has been pushing to add enforcement mechanisms. For now, Japan has no legal instrument specifically targeting synthetic faces used in fraud or unauthorized commercial contexts. We examined the broader portrait rights landscape in our article on Japan's portrait rights in the age of generative AI.

The Disclosure Problem

The EU AI Act's disclosure requirement points toward what many ethicists consider the minimum viable norm: synthetic faces should always be labeled as such. The practical obstacles are significant. Labels can be removed. Platform pipelines strip metadata. Social sharing compresses and re-encodes images, destroying any embedded markers. The C2PA standard — a cryptographic provenance system backed by Adobe, Microsoft, Google, and the major camera manufacturers — offers a more durable approach, but it requires adoption at every point in the image's lifecycle, which does not yet describe most of the internet.

Even when disclosure works technically, it does not resolve the more fundamental question: who is responsible for ensuring it happens? A synthetic face used in an advertisement is traceable to the advertiser. A synthetic face used in a romance scam — generated by one of dozens of face-synthesis tools with no user verification — is considerably harder. The EU framework places disclosure obligations on deployers, but the definition of deployer becomes murky when the pipeline involves a consumer-grade tool, an anonymous operator, and a victim in a different jurisdiction.

Synthetic Diversity and What It Erases

The advertising use case presents a different kind of ethical problem — less dramatic than fraud but more structurally embedded. When services like Rosebud AI allow brands to generate photorealistic "models" of any demographic without hiring real people, they remove an economic pathway that has historically served as one mechanism for inclusion in the media industry.

The counterargument from the industry is that AI-generated faces lower the cost of representation, allowing smaller brands to show diversity they could not afford to cast. This is accurate as far as it goes. But it conflates the appearance of diversity with its substance. A synthetic South Asian woman selling a product provides no employment to a real South Asian woman. She requires no accommodation, no pay equity audit, no conversation about representation on set. She is perfect and costs nothing, which is precisely the problem.

The SAG-AFTRA backing for the NO FAKES Act reflects this concern from the talent side. The union has argued that synthetic likenesses — even fully fictional ones modeled on real demographic categories — undercut the market for human performers in commercial work.

Who Is Accountable When Nobody Owns the Face?

The deepest problem with synthetic faces is not technical — it is the structure of accountability they produce, or fail to produce. When a real person's photograph is misused, there is a victim with legal standing. When a real face is deepfaked, there is a person whose likeness was taken without consent. When a fully synthetic face is used in a scam, the harm is real but the liability chain is diffuse: the model that generated the face, the platform that hosted the generation tool, the operator who created the profile, and the network that allowed the profile to circulate all share some portion of causal responsibility without any one party being cleanly liable under current law.

The proposed solutions fall into three categories. Platform liability — the NO FAKES Act model — places financial risk on the entities with the greatest capacity to monitor and remove synthetic content. Mandatory provenance — the C2PA and EU AI Act model — attempts to make the synthetic origin of a face traceable through its lifecycle. Prohibition in specific contexts — the TAKE IT DOWN Act model — criminalizes the most harmful uses without attempting to regulate synthetic faces generally.

None of these approaches fully closes the gap for the fraud use case, because fraud operators are not deterred by civil liability they will never face and are not visible to the platform moderation systems designed to catch them. The Hong Kong ring ran for months before law enforcement intervention. In the interim, victims lost money on the strength of a face that, legally speaking, had never existed.

The Philosophical Dimension

Behind the legal and economic questions is a simpler one that proves harder to answer: what does "authentic" mean when a perfect synthetic face is indistinguishable from a real one? The faces generated by current diffusion models do not look uncanny. They look like people. The only way to know they are not is to have access to information about their origin that is routinely not disclosed.

This matters beyond fraud. When we form a social connection — with a news anchor, a brand spokesperson, a dating profile — part of what we are connecting to is the understanding that a real person made choices and took on risks to appear before us. A synthetic face substitutes the appearance of that commitment without the substance. The connection is parasocial in a new sense: not just one-directional, but directed at something that cannot reciprocate because it does not exist.

The question of who owns a face that never existed may ultimately be the wrong frame. The more tractable question is who is responsible for the consequences when one is used — and whether the legal and technical infrastructure being built now will catch up to the uses already in market.

Sources

  1. "Hong Kong police bust deepfake romance scam ring, arrest 27," South China Morning Post, October 2024. Operation extracted over HKD 360 million from victims across Asia.
  2. Generated Photos, generated.photos. Library of 100,000+ AI-generated faces for commercial licensing.
  3. Rosebud AI, Y Combinator S19. GAN-based face synthesis and demographic swapping for advertising.
  4. US Copyright Office, "Copyright and Artificial Intelligence," Part 1, February 2023; Part 2, July 2024. Establishes that AI-generated works without human authorship are not copyrightable.
  5. Sumsub, Identity Fraud Report 2025. Generative AI-enabled fraud surged 1,100% in 2025; dating/media sector recorded the highest fraud rate among tracked industries at 6.3%.
  6. TAKE IT DOWN Act, Pub. L. No. 119-12, signed May 19, 2025. Criminalizes non-consensual intimate deepfakes; 48-hour removal requirement; platform removal obligations enforced by the FTC; penalties up to 2 years (adults), 3 years (minors).
  7. NO FAKES Act, reintroduced April 2025, revised May 2026. Advanced unanimously out of Senate Judiciary Committee June 18, 2026; awaits full Senate floor vote. $750K platform liability per violation. Supported by SAG-AFTRA, OpenAI, Disney, Adobe, Google.
  8. EU AI Act, Article 50. Deepfake disclosure obligations for deployers. Enforcement date August 2, 2026. Penalties up to EUR 15 million or 3% global turnover, whichever is greater.
  9. AI Promotion Act (AI推進法), Japan, passed May 28, 2025. First AI-specific Japanese legislation; no enforcement penalties. Ministry of Justice study group on celebrity likeness announced April 2026.
  10. Entrust, 2026 Identity Fraud Report. Deepfake selfie attempts up 58% year over year; roughly one in five biometric fraud attempts now involves a deepfake.
  11. INTERPOL, Global Financial Fraud Threat Assessment 2026. AI-enabled scams estimated to be 4.5 times more profitable than traditional fraud methods.