AI · Legal

Whose face is that?

A synthetic model with no real template — the third right, the one that has nothing to do with authorship or labeling, and why the doppelgänger question is smaller than it sounds.

A synthetic model for the campaign: no casting, no contract, no shoot — a person who doesn't exist. That sounds like the one case that comes free of any legal entanglement. It can be. But only if you know which line you're standing on.

Because this is about a third right, one that has nothing to do with the first two. Not „is AI involved?" — that was the labeling question. Not „do I own the image?" — that was copyright. But: does a real, identifiable person appear in my image, and are they allowed to?

A third right

§ 22 KUG — the German right to one's own image — and behind it the general right of personality. Neither asks who owns an image, but whether a particular person may be depicted in it. That is something entirely different from authorship, and it runs crosswise to everything on the previous page.

The four-question checklist for LoRA training — own or third-party material, identifiable author, license, distance — tests only copyright in the training material. A photo can be flawless on all four axes: my own image, shot by me, freely exploitable. And still violate § 22 KUG if it shows a person who never consented. The two rights sit side by side; one does not dispose of the other.

What does „deepfake" mean here?

The word is tainted. Most people hear „deepfake" and think immediately of pornographic or otherwise offensive montages — and conclude their harmless campaign image can't be one. That's the first misunderstanding. Technically, a deepfake is any AI-generated likeness of a real person, including the most innocuous portrait in a business suit. The content neither ennobles nor excuses anything.

The second misunderstanding weighs heavier: deepfake does not mean forbidden. Permissibility is decided neither by the content of the image nor by whether it is labeled, but by a single factor — consent. Three things that constantly slide into one another and belong apart here: what the image shows, whether it must be labeled, and whether it was allowed to come into existence at all. A labeled deepfake without consent remains unlawful; the label heals nothing. And a consent-covered AI portrait is permissible, however „fake" it may be technically.

Where the risk sits: the reference image

The critical moment is the training material. If photos of a real person flow into the LoRA, a reference to that specific person is created — and the character carries their likeness from then on, no matter what I later generate with it. That's the core, and it is independent of the output: whether the generated images are harmless or delicate changes nothing about the model resting on a real identity.

One clarification, so the line is right: the actual legal test is not the input method but the recognizability of the result. The reference image is the path that establishes that recognizability — it links the character causally to a particular person. Whoever avoids creating that link in the first place has solved the problem at its root.

Two clean paths

There are two paths to a consistent character that both hold — and one is markedly easier than the other.

  • Path A — prompt only. Build the base character exclusively from a text-based template: a person that emerges from descriptions, not from the face of a real human. From this single synthetic starting image I generate further views, perspectives and variations via img2img — the training material for the LoRA. No real person, no reference, no likeness. This is the cleanest path, and the reason to make it the studio standard.
  • Path B — explicit consent. A named real person who consents — but not with the classic model release. That release predates this use case and does not automatically cover „digitization, training of a model and generation of derivative outputs"; the consent must name these steps explicitly. And even then a thread stays open: consent under § 22 KUG may in some cases be revocable. With an already-trained LoRA that cannot be „unlearned," that's a real business risk — Path A doesn't have it in the first place. Path B isn't forbidden, but it carries a burden the prompt path sets down.

The one moment that decides

Whether a real person is recognizable in the end is decided at a single spot: the selection of the base image. If that one synthetic starting point is free of a recognizable real person, img2img afterward only inherits what was fixed there — the chain stays clean because its beginning was clean. If the starting point tips over, every variation propagates the fault.

That's the control point, and as with copyright it is documentable. The prompt log proving that no reference image and no name went in is, in case of doubt, the evidence that nobody was rebuilt here but something new invented.

And if chance resembles someone?

The obvious worry: with billions of people — doesn't my synthetic face inevitably resemble some real one? And don't I have to rule that out? The reassuring answer is that I neither can nor must, because the law doesn't require it.

§ 22 KUG protects against the portrait of a particular person, and „particular" means: recognizable in the legal sense. Recognizability is judged from the perspective of a circle of acquaintances or the relevant public — people who would say „that's X." A chance resemblance to a nameless stranger among billions doesn't meet that: nobody identifies the image as that person, so there is no portrait of them. What matters is not statistical facial similarity but reference plus identifiability — and my prompt-only character has no reference to any particular real person.

This is the classic doppelgänger constellation. A deliberate look-alike meant to evoke a real — usually prominent — person can infringe rights, because it refers to them. A merely accidental resemblance without reference and without identification does not.

That turns the impossible task into a doable one. Risky and at the same time checkable are only the publicly known faces: celebrities whose face is familiar to the public, so that a strong chance resemblance would be both recognizable and identifiable. Against that manageable set I can meaningfully check — a reverse image search on the finished character as a documentable duty of care. Against private strangers I need not check, because there, without reference, no portrait exists in the first place.

And the labeling?

A synthetic character that resembles no real person is by definition not a deepfake — the AI Act's deepfake labeling hooks onto resembling a real person, and that is precisely absent here. The general AI labeling remains, which applies to photorealistic advertising anyway (see the page on labeling). Only once the character makes a real person recognizable does deepfake labeling come on top — and then labeling is the smaller problem anyway, because without consent the image is already impermissible on personality-rights grounds.

For the studio

Three sentences. First: create no reference to a real person — no reference photos, no real names, no combination of features so specific it points to a particular person. Second: check the finished character against the small set of publicly known faces, via reverse image search, and record the result. Third: document the prompt path, because the log „no reference image, no name" is the evidence that any resemblance is chance. Whoever works this way never let the real person into the image — and doesn't need the consent they can't obtain.

Note

Reasoned opinion, not legal advice. There is as yet no case law on purely AI-generated synthetic faces; the line drawn here follows the established doppelgänger case law as the nearest analogy. As of August 2026. When in doubt, consult a specialist lawyer for copyright and media law.