The repurposing of a person’s face, voice, or image in new content without permission. For identity programmes, likeness reuse is a control problem because public media can be copied into misleading contexts long after the original content was created.
What Likeness Reuse Means in Practice
Likeness reuse is not just “using someone’s face or voice.” It is the reuse of recognizable human attributes as a security and governance issue, because the same media asset can be copied, edited, recombined, or placed into new contexts that change what it appears to say or endorse.
That makes likeness reuse different from ordinary content reuse. A legitimate image library or approved brand asset can still become harmful if the reuse breaks consent terms, omits attribution, or creates the impression that a person supported a message they never approved.
Why Likeness Reuse Creates Security and Trust Exposure
The core risk is trust manipulation. A reused face, voice, or image can make synthetic, misleading, or defamatory content look authentic, especially when the audience already associates the likeness with authority, expertise, or familiarity.
This is closely related to identity harm, because the subject being copied is not merely content, it is a person’s recognisable identity signal. In practice, the problem is less about media format and more about whether the use of that likeness can mislead viewers, customers, employees, or the public about endorsement, intent, or origin.
Governance teams should treat likeness reuse as a control question, not only a legal one. Approval, provenance, consent scope, and permitted context matter because a once-authorised asset may become unsafe when repurposed in a different channel, campaign, or AI-generated composition.
Common Failure Modes in Likeness Reuse
Likeness reuse usually goes wrong in a few repeatable ways: consent is absent, consent is too broad, or the original approval does not survive the new context. A portrait approved for an internal profile page, for example, can become misleading when reused in promotional material or an automated persona.
Voice reuse introduces an even sharper trust problem because people often assume recorded speech reflects current intent. When a cloned or archived voice is reused without permission, the result can cross from content misclassification into impersonation, fraud, or reputational damage.
Source control also matters. Once a face, video, or voice sample is widely published, it may be scraped, copied, and redeployed faster than governance processes can track. NIST Privacy Framework is useful here because it frames reuse as a privacy-risk and data-governance problem, not only a publishing issue.
How Likeness Reuse Is Controlled
The most effective controls begin with permission boundaries: what was approved, for which purpose, for how long, and in which media formats. Those boundaries should be explicit enough that a reviewer can tell when a new use is still within scope and when it is a fresh approval decision.
Provenance checks are also important. Content teams should be able to trace where the likeness came from, whether the source is authorised, and whether the transformation preserves the intended context. That is why strong media governance often sits alongside broader control frameworks such as NIST Cybersecurity Framework 2.0 and EU General Data Protection Regulation (GDPR) when biometric or personal data is involved.
For organisations using AI-generated media, the governance bar should be higher, not lower. NIST AI Risk Management Framework and EU AI Act regulatory framework both reinforce the need to manage deceptive output, accountability, and downstream misuse when synthetic media or person-like presentation is part of the system.
Risk and Threat Considerations
Likeness reuse can create fraud, impersonation, defamation, and consent violations when a person’s image or voice is detached from the context that originally made its use legitimate. The same asset may be harmless in one setting and materially misleading in another.
Failure mechanism: An attacker or careless publisher copies a face, voice, or image into a new context that implies endorsement, authority, or speech that never occurred, or uses AI to intensify the deception.
Impact: The result can be reputational damage, social-engineering success, privacy harm, policy breach, or legal exposure, especially where the likeness is trusted because it is recognisable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organisational Context | Defines governance context for how public-facing content is authorised and used. |
| Recommendation — Establish approval boundaries for likeness use and review any new context against them. | ||
| NIST SP 800-53 Rev 5 | AC-3 — Access Enforcement | Supports enforcing who may use approved media assets and in what context. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Supports traceability for who used a likeness asset and when it was repurposed. | |
| IA-5 — Authenticator Management | Applies where voice, face, or image material functions as identity-bearing material needing lifecycle control. | |
| Recommendation — Enforce access and use restrictions for likeness assets and publication workflows. Review publication logs to detect unauthorized or out-of-scope reuse of likeness assets. Manage likeness-derived identity material with the same lifecycle discipline as other sensitive credentials. | ||
| ISO/IEC 27001:2022 | A.5.12 — Classification of information | Supports classifying likeness assets and related consent records by sensitivity and permitted use. |
| Recommendation — Classify likeness assets and consent artifacts so reuse is governed by sensitivity and permitted purpose. | ||
| GDPR | Art. 5 — Principles relating to processing of personal data | Directly governs lawful, purpose-limited use of personal data such as identifiable likenesses. |
| Recommendation — Limit likeness processing to documented purposes, minimised scope, and lawful reuse conditions. | ||
| NIST AI RMF | GOVERN — Govern | Addresses accountability, transparency, and oversight for AI systems that may generate or reuse likenesses. |
| Recommendation — Assign accountability for likeness reuse decisions in AI-enabled content pipelines. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org