Face swap: how it works, whose permission you need, and what the law actually says

there are two articles you could write about face swapping. one is a tutorial. the other is the thing almost nobody writes, which is a straight account of what the technology is, who gets to say yes to it, and what happens to you if you do it to somebody who didn't.
this is the second one. it is deliberately not a tutorial, and the reason is at the bottom.
what a face swap actually is
the phrase covers three quite different operations that get lumped together because the result looks similar.
face replacement. you take a target video or photograph and substitute a different person's face onto the existing head, matching pose, lighting and expression frame by frame. the body, the clothes, the room and the performance are all the original person's. only the face is new.
face reenactment. the opposite direction. you keep one person's face and drive it with another person's performance — their head movement, their mouth shapes, their expressions. this is what most "make this photo talk" tools are doing.
full synthesis. no swap at all. a person who does not exist is generated outright, with a face assembled from a model's training distribution rather than lifted from a specific individual. this is where most of the ai-influencer accounts sit.
the distinction matters legally and it matters ethically, and it is almost never made, because from the outside all three produce a video of a face saying something. it is worth holding onto: replacement and reenactment involve a specific real person. synthesis usually doesn't. the questions you have to answer are completely different.
technically, all three are now commodity. what used to require a trained model per identity and hours of gpu time is a hosted api call. that shift is the entire reason this is a subject at all — the constraint stopped being capability and became permission, and most of the writing about it has not caught up.
the only question that decides everything: whose face is it

before anything else, sort your situation into one of four boxes. everything downstream follows from which box you are in.
- your own face. you consented by definition. this is the largest legitimate use and the least discussed.
- someone you have hired, with a signed release. licensed talent. the standard the professional end of the industry already works to.
- someone who has not agreed. a colleague, an ex, a celebrity, a stranger from instagram. this is where the law lives, and where the answer is no.
- nobody — a synthesised person. no consent question, but a disclosure question, and sometimes a "does this resemble a real person by accident" question.
people get into trouble almost exclusively in box three, and they get there by drifting: a face that started as "just a test" ends up in an ad. the useful habit is to decide which box you are in before you generate, not after, because after is when you already have the file.
it is worth noting that the market itself has settled on box two as the professional answer. one of the industry's own pitches puts it plainly:
"AI avatars are built from real consented paid actors"
that is a sales line, but it is a sales line that only works because everyone already understands the alternative is a problem.
what the law actually says
this is not legal advice, it changes fast, and it changes differently in every jurisdiction. what follows is the shape of it as checked on 27 august 2026, so you know which questions to take to somebody qualified. three of the positions below moved in the first half of this year alone, which is the best argument for checking the date on anything you read about this. and the honest state of the field is that people are still asking the basic question out loud:
"Are AI-Generated Ads Legal?"
"I guess there needs to be precedent set cuz what these companies would be worried about would be it coming back to them legal reasons, wouldn't it?"
the UK
there is no general image right in the UK. you do not own your face as property the way a trademark is owned. protection is assembled out of several other things:
- intimate image offences. sharing a sexually explicit deepfake of an adult without their consent is a criminal offence in england and wales, brought in by the online safety act 2023. since 6 february 2026, creating one is a separate offence in its own right — section 138 of the data (use and access) act 2025, which amends the sexual offences act 2003 so that "intimate image" covers digitally altered and ai-generated content. the offence is committed even if the image is never produced or shared: asking someone else to make it is enough. creating carries an unlimited fine, sharing up to two years.
- UK GDPR. a recognisable face is personal data. used to identify someone uniquely it is biometric data and sits in the special-category tier, where the realistic lawful basis is explicit consent. this is the provision most people have never considered and it applies to the ordinary commercial case, not just the malicious one.
- passing off. the route used when a brand implies a celebrity endorsement that never happened — the line of cases running through irvine v talksport and the rihanna/topshop decision. it needs goodwill and a misrepresentation, so it protects the famous far better than it protects you.
- defamation, if the fabricated video puts words or conduct on someone that damages them.
- advertising rules. the CAP code requires ads not to mislead, and misleadingly implying a real person endorses something is a straightforward breach regardless of how it was produced.
the EU
two instruments matter and they do different jobs.
the AI act carries an explicit transparency obligation for deepfakes: where an ai system generates or manipulates image, audio or video content that appreciably resembles real people, places or events and would falsely appear authentic, whoever deploys it has to disclose that the content is artificially generated or manipulated. article 50 applies from 2 august 2026, and the duty bites without any intent to deceive. one carve-out worth knowing: systems already on the market before that date get until 2 december 2026 for the machine-readable marking obligation specifically — the deployer-side duty to disclose a deepfake was not deferred. this is a labelling duty. it does not make an unconsented swap lawful — it makes an undisclosed one separately unlawful. penalties run to €15m or 3% of worldwide turnover.
the GDPR does the consent work. facial data processed to identify a person is special-category data; you need explicit consent and a purpose, and the person retains rights over it afterwards.
and several member states have proper personality rights that the UK lacks: france's droit à l'image under article 9 of the civil code, germany's recht am eigenen Bild, which requires consent to disseminate a person's image with narrow exceptions. in those countries the question is not "is there a law" but "did you get a signature".
somebody put the whole european question in one line:
"Should AI Ads Count As Deep Fake in the EU?"
the answer, once the transparency rules bite, is: if it appreciably resembles a real person and would pass for authentic, yes — and you label it.
the US
fragmented, and moving fastest.
- right of publicity is state law. new york's civil rights law and california's civil code section 3344 are the well-worn ones; california also protects the deceased. tennessee's ELVIS act extended the same protection explicitly to voice and to ai-generated likeness.
- non-consensual intimate imagery. the TAKE IT DOWN act made publishing non-consensual intimate images a federal offence including where the image is ai-generated, and obliges platforms to remove reported material — and known duplicates — within 48 hours of a valid request. the FTC has been enforcing that removal duty since 19 may 2026, and opened by warning twelve of the largest platforms that their processes were inadequate. penalties run past $53,000 per violation.
- election law. a growing set of states restrict synthetic media of candidates inside a window before an election, usually with a disclosure carve-out.
- the FTC. its endorsement guides already treat fabricated endorsers and fake reviewers as deceptive. an ai face delivering a testimonial for a product it never used is an endorsement problem before it is a deepfake problem.
the practical upshot across all three jurisdictions is the same and it is simple: if the face belongs to a real person who did not agree, there is a law that reaches you in every market that matters. the differences are only in which law.
the market has an unresolved argument about licensing

the interesting legal question is not the criminal one, which is settled. it is what happens to the people who do consent. when a creator sells a brand the right to build an avatar from their likeness, what have they sold?
the corpus has people circling this without a name for it:
"What if they're taking the the likeness of the AI image?"
"Does their likeness just become licensed data?"
that second question is the whole thing. a traditional usage licence is bounded — this footage, these channels, this long. an avatar is not footage, it is a capability. the existing vocabulary of the trade already strains at it:
"First things first, what even are usage rights?"
"They want three months of paid usage rights."
three months is a coherent ask about a video. it is close to meaningless about a model trained on someone's face, because the model does not stop existing in month four. if you are licensing a likeness, the release has to say what happens to the derived model, not just to the delivered files. more on that below.
and the tension is not hypothetical — likeness disputes are already happening in public, including complaints that a synthetic persona was built to resemble a specific real performer:
"this is Nia Noir, a 100% AI influencer and she seems to be based on Margot Robbie"
disclosure: when you have to say it out loud
there are three separate sources of obligation and they do not line up.
the law. under the EU AI act, deepfake content gets a disclosure. in the US, election rules and FTC endorsement rules impose their own. in the UK there is no general labelling statute yet, but the CAP code's prohibition on misleading ads gets you to a similar place in most commercial cases.
the platforms. meta, tiktok, youtube and x all require creators to flag realistic ai generated or manipulated media, and all of them apply automated detection on top of what you declare. the automated layer is why "i didn't tick the box" is not a strategy:
"Anyone know how to make this not show up, i’m trying to post lifestyle ai ugc type content but it keeps saying contains ai generated media, anyone know a workaround?"
that is somebody looking for a way around a label. the answer is that the workaround is the violation, and it is also the thing that gets accounts removed rather than posts removed. the same anxiety runs the other way:
"Is YouTube really banning or demonetizing AI videos?"
"Has anyone had an AI UGC ad rejected by Meta or TikTok for being AI-generated?"
labels are also imperfectly applied, which people notice:
"I just noticed, X didn’t add “Made with AI” to my quoted post"
the audience. this is the one that actually determines whether the content works. two lines, asked independently, put the commercial case for disclosure better than any regulation does:
"If a brand paid an AI influencer to recommend a product to you, would you want to know?"
"Would you buy a product after finding out the UGC review that convinced you was AI-generated?"
both are rhetorical, and the answer both expect is the same. the discovery is worse than the disclosure. a labelled synthetic ad is a format. an unlabelled one that gets found out is a betrayal, and the reaction attaches to the brand, not to the tool.
which is why the healthiest version of the disclosure conversation is the one that asks what the label is for:
"But the question is are we disclosing it because we have a problem with AI?"
"Like why why are we disclosing it?"
the useful answer: you disclose so that nobody forms a belief about a real person or a real experience that isn't true. that test tells you when a label is mandatory in spirit even when no rule names it, and it also tells you when a label is pointless — nobody needs "ai generated" on an abstract background plate.
the legitimate uses, in order of how safe they are
1. your own face
the largest honest use and the least written about. it is your likeness, you consent by existing, and the practical questions are craft questions rather than legal ones. people are already doing exactly this deliberately:
"What I want is basically one image with all different sides of my face, my head, so I can feed this into AI and it can refer to me in the best way, okay?"
"So close to just making my own content and putting my face in the videos"
that first line is also just good practice. a multi-angle reference sheet of your own face is what makes a consistent result possible, and it is the same technique whether you are doing this for a talking-head ad or for a film.
two cautions even here. first, read the terms of whatever service you upload to: you are handing a third party biometric data about yourself, and what they may do with it afterwards is a real question. the vendors know it is a question, which is why they answer it in public:
"For paid users, we don’t train on your content nor use it promotionally without explicit permission."
second, your own face plus a fabricated claim is still a fabricated claim. consent covers the likeness, not the testimonial.
2. licensed talent with a signed release
the professional standard, and the one commercial work should default to. what the release has to cover is more than a normal shoot release, because the deliverable outlives the session:
- scope of use — which products, which markets, which channels, paid or organic
- term, and what happens at the end of it
- the derived asset — whether a model, embedding or avatar may be built from the likeness, whether it may be used to generate new material the performer never performed, and whether it must be deleted on expiry
- script approval or a category exclusion list — the performer's protection against being made to say something they would have refused. this is the clause most often missing and the one that causes the disputes
- no training on the material beyond the agreed purpose
- fair renewal terms, because a perpetual licence bought at a one-video rate is how this goes wrong reputationally even when it is legally clean
pay the release rate rather than the footage rate. an avatar licence is not a usage licence with a longer number in it.
3. clearly-labelled fiction and satire
synthesis, parody, obviously-unreal composites. the tests are whether a reasonable viewer could take it as real, whether a specific identifiable person is depicted, and whether anything defamatory is being put in their mouth. satire has genuine protection in most jurisdictions and it is narrower than people assume: the protection is for the commentary, not for the realism.
if it is fiction, make it legible as fiction. this also happens to be the thing that works — the failure zone for synthetic content is the middle, where it is realistic enough to be mistaken and rough enough to be caught.
4. archival, dubbing, and continuity work
visual-effects face replacement has been a legitimate craft for two decades: de-aging, stunt-double face restoration, multilingual dubbing with matched mouth shapes. all of it is consented, contracted and disclosed in the credits. the technology is not new here. only the price is.
the boring problem underneath all of it
the reason people end up on the wrong side of this is rarely malice. it is that the record falls apart. the reference image, the release, the prompt and the output live in four different places, and six weeks later nobody can answer "which agreement covers this file".
the same complaint shows up around ai production generally:
"Deepfakes still exist, IP infrigement is still happening and people that want to create original content are left to frankenstein clips together from different models"
"But now here's where most creators struggle, finding high-quality voices, sound effects, and visuals that actually legal to use."
and it is exactly what makes the difference between a clean project and an incident. if you take one operational thing from this: keep the permission attached to the asset. whatever you use — a folder convention, a spreadsheet column, embedded content credentials — the release, the reference and the output should be one object, not three. that is a filing discipline, not a technology, and it is the whole of compliance in practice.
there is also a version of this that is somebody else's face being used by someone with no right to it, and it is not rare:
"That video on the top left is OUR video The first 20 seconds are real and he deepfaked our creator to promote his shitty AI UGC course"
that is the entire subject in one complaint: a real creator's face, taken from a real video, attached to a claim she never made, used to sell something.
what this article deliberately does not contain
there is no walkthrough here for putting a face onto a person who has not agreed to it, and that is not squeamishness about naming tools. it is that a step-by-step for the unconsented case has no legitimate reader. every honest use — your own face, licensed talent, disclosed fiction — needs a release and a workflow, not a bypass. the mechanics that a "how to swap anyone's face" guide adds on top of that are only the mechanics of doing it to someone who said no, or was never asked.
the search data makes the point without any interpretation: sitting in the same keyword cluster as face swap and ai face swap, with several thousand searches a month of its own, is the explicitly non-consensual pornographic variant. that is a meaningful share of what the demand behind these terms actually is. it is not a reason to refuse to explain the technology. it is a very good reason not to write the tutorial.
the summary
- three different operations get called face swapping. replacement and reenactment involve a specific real person; synthesis usually doesn't. sort yours first.
- the whole question is whose face it is. your own, licensed talent, someone who didn't agree, or nobody. decide before you generate.
- there is a law that reaches you in every major market if the face belongs to someone who didn't consent — UK intimate-image offences and UK GDPR, the EU AI act plus national personality rights, US state publicity law plus TAKE IT DOWN and the FTC.
- the EU AI act's deepfake transparency duty is a labelling obligation, not a permission. disclosure does not cure a consent problem.
- disclose because discovery is worse than disclosure. the platforms will label you anyway, the audience punishes the reveal, and the useful test is whether someone would otherwise form a false belief about a real person.
- a likeness release is not a usage licence. it has to say what happens to the derived model, not just to the delivered files, or you have sold something without a term.
- keep the permission attached to the asset. most incidents are filing failures, not intentions.