Legal documents and a laptop on a desk

Why a Single Global Policy Doesn't Work Here

Organisations building voice cloning into their localization or content operations frequently look for one consistent global policy — a single consent form, a single disclosure standard, a single set of usage rules — that can be applied uniformly everywhere they operate. This instinct is understandable and it does not match the actual regulatory reality, which is genuinely fragmented across jurisdictions that are approaching voice cloning through entirely different legal frameworks, moving at different speeds, and in some cases arriving at meaningfully different substantive conclusions about what is permitted at all.

This piece is a starting orientation to that fragmentation, not a substitute for jurisdiction-specific legal advice, and given how actively this area is developing, treat every specific claim here as something to verify against current guidance before relying on it for an actual business decision, in the same spirit as the caution urged elsewhere in this series regarding synthetic voice disclosure requirements generally.

United States: A Patchwork of State Law

There is no single comprehensive federal law governing voice cloning in the United States, and the primary legal frameworks that actually apply are a patchwork of state-level right of publicity laws, which vary considerably in scope, in what they actually protect, and in how they are enforced from one state to another, meaning a use that is clearly permissible under one state's framework may be genuinely contested under another's.

Right of publicity law generally protects an individual's right to control commercial use of their identity, historically covering name, image, and likeness, with voice increasingly recognized as part of that protected identity in several states, particularly following litigation establishing that a sufficiently distinctive and recognizable voice can be protected from unauthorized commercial imitation even without a literal recording of the actual person's own voice being used.

Some states have moved to specifically address AI voice cloning and deepfakes through more recent, purpose-built legislation, distinct from and layered on top of the older general right of publicity framework, reflecting active and ongoing legislative attention specifically responding to the emergence of accessible voice cloning technology, and this is an area where new state-level legislation continues to be introduced and enacted, making it genuinely necessary to check current status rather than relying on an understanding formed even a year or two prior.

Federal law is more directly relevant to specific narrower categories of harm rather than voice cloning generally — fraud statutes for impersonation used in a scam, for instance, or the Federal Trade Commission's authority over deceptive commercial practices — rather than providing one comprehensive federal voice cloning framework comparable to what exists at the EU level, discussed below.

European Union: The AI Act Framework

The EU AI Act includes specific transparency obligations for AI systems that generate synthetic audio, image, video, or text content, requiring that such content be disclosed as artificially generated or manipulated, as covered in more detail in the discussion of synthetic voice disclosure elsewhere in this series, and this framework applies horizontally across the EU rather than varying member state by member state the way US right of publicity law varies state by state, which is a genuinely different regulatory structure from the American patchwork approach.

The AI Act's specific obligations and compliance timelines are phased, with different provisions taking effect at different dates, and an organisation operating in or serving EU markets should verify the current implementation status of the specific provisions relevant to voice cloning and synthetic media disclosure rather than assuming the full framework is already fully in force, since phased implementation is a deliberate feature of how this regulation was designed to take effect.

Separately from the AI Act, existing EU data protection law under the GDPR is relevant to voice cloning to the extent that a voice recording can constitute personal data, and in some interpretations, biometric data warranting heightened protection, which layers an additional, independently applicable legal consideration around consent and data handling on top of the AI Act's more specifically synthetic-media-focused transparency obligations.

Person reviewing dashboards on a monitor

United Kingdom: A Distinct Post-Brexit Path

The United Kingdom is not bound by the EU AI Act following its departure from the European Union, and has pursued its own, generally described as more principles-based and less prescriptively regulatory, approach to AI governance overall, meaning an organisation cannot assume that EU AI Act compliance automatically satisfies UK requirements, or that the UK's approach mirrors the EU's specific transparency and disclosure obligations in the same detailed form.

UK law addresses voice cloning-adjacent harms through a combination of existing frameworks including data protection law, under its own post-Brexit UK GDPR framework, defamation and fraud law for specific harmful uses, and increasing regulatory and parliamentary attention specifically to deepfakes and synthetic media, rather than through one single comprehensive UK voice cloning statute comparable to the EU's AI Act, making the UK's actual current legal position on voice cloning specifically an area that continues to develop and that is worth checking against current guidance rather than assuming settled.

China: An Explicit and Specific Framework

China has moved comparatively early and specifically to regulate what its regulatory framework refers to as deep synthesis technology, which explicitly includes voice cloning and synthetic voice generation, through dedicated administrative regulations from its cyberspace administration, representing one of the more explicit and specifically targeted regulatory approaches to this technology globally, distinct in structure and philosophy from both the US state-law patchwork and the EU's more general AI Act framework.

China's framework includes specific requirements around labeling synthetically generated content, obtaining consent for using an individual's biometric information including voice for synthesis, and provider-level obligations on companies operating deep synthesis services, reflecting a regulatory approach that places significant specific compliance obligations directly on the technology providers themselves, not only on the end users or businesses deploying the resulting synthetic voice content.

Organisations operating in or serving the Chinese market should treat this as its own distinct, actively enforced compliance framework requiring dedicated attention, rather than assuming that broadly similar-sounding transparency principles developed for the EU or US context translate directly into compliance with China's specific administrative requirements, which have their own particular procedural and documentation expectations.

What to Actually Do Given This Fragmentation

Build your internal consent, disclosure, and voice usage policies to the most stringent applicable standard across every jurisdiction you actually operate in or serve, rather than to the least restrictive one, since this is both the more legally conservative and, in practice, the operationally simpler approach compared with attempting to maintain genuinely different policies and workflows calibrated separately per jurisdiction for what is fundamentally the same underlying voice cloning activity.

Maintain jurisdiction-specific legal awareness as an ongoing function rather than a one-time assessment, given how actively this area continues to develop across every jurisdiction discussed here, connecting to the same "verify current requirements rather than trusting a static understanding" caution that appears throughout the accessibility and disclosure discussions elsewhere in this series — a compliance position that was accurate eighteen months ago is a genuinely risky thing to still be relying on today in an area moving this quickly.

Involve actual legal counsel with specific expertise in the relevant jurisdictions before scaling any voice cloning program with real commercial stakes, since this piece, and general guidance of this kind more broadly, can orient an organisation to the landscape and the categories of consideration that matter, but cannot substitute for jurisdiction-specific legal advice applied to your organisation's actual specific facts, use cases, and risk tolerance.

Track the specific jurisdiction where a voice's owner resides, where the content will be distributed, and where your own organisation is based, separately, since these can each trigger different applicable legal frameworks and are not necessarily the same jurisdiction for any given piece of content, particularly relevant for the kind of genuinely global, multi-market localization content this series is primarily concerned with, where a voice recorded by a speaker in one country can be cloned by a company based in a second country and distributed to audiences in a dozen others simultaneously.

Team reviewing a project plan on a shared screen

Obtain explicit, specific, and well-documented consent for voice cloning use regardless of which specific jurisdiction's law happens to apply to a given instance, since thorough, specific consent is a strong practical foundation across essentially every regulatory framework discussed above, even though the specific legal mechanism through which that consent matters, and the specific additional obligations layered on top of it, vary by jurisdiction.

Specify the actual scope of permitted use explicitly in consent documentation — which languages, which content types, whether use extends to dynamically generated content as covered in the discussion of call center voice cloning elsewhere in this series, what the duration and any renewal terms are — rather than relying on a vague, broadly worded blanket consent, since specific, well-scoped consent is both more legally robust across jurisdictions and clearer for the actual person whose voice is being used to understand and genuinely agree to.

Retain consent documentation for as long as the voice asset itself remains in active use, and for a reasonable period beyond that, since a consent record that has been discarded or lost is functionally equivalent to never having obtained consent at all if a question about the voice's use is ever raised, whether that question comes from a regulator, from the individual themselves, or from an internal audit.

A Working Checklist

  • Treat US voice cloning regulation as a fragmented state-level right of publicity patchwork, not a single federal standard.
  • Check for state-specific AI voice and deepfake legislation, which continues to be actively introduced.
  • Verify current EU AI Act implementation status and phased compliance timelines for synthetic voice disclosure obligations.
  • Consider GDPR's data protection implications for voice recordings as biometric data, separate from AI Act obligations.
  • Treat UK requirements as genuinely distinct from EU AI Act compliance, following its own post-Brexit regulatory path.
  • Treat China's deep synthesis regulations as a distinct, actively enforced framework with specific labeling and consent requirements.
  • Build internal policy to the most stringent applicable jurisdiction rather than the least restrictive.
  • Maintain jurisdiction-specific legal awareness as an ongoing function, not a one-time assessment.
  • Involve jurisdiction-specific legal counsel before scaling any commercially significant voice cloning program.
  • Track the voice owner's jurisdiction, the distribution jurisdiction, and your own organisation's jurisdiction separately per use case.
  • Obtain explicit, specifically scoped consent regardless of which jurisdiction's law applies to a given instance.
  • Retain consent documentation for the full active life of a voice asset and beyond.

Frequently Asked Questions

Is there one global law that covers voice cloning?

No. The regulatory landscape is genuinely fragmented: the US relies primarily on a patchwork of state-level right of publicity laws with no single comprehensive federal framework, the EU addresses it through the AI Act's synthetic media transparency obligations layered alongside existing data protection law, the UK follows its own distinct post-Brexit approach not bound by the EU framework, and China has its own specific and comparatively early deep synthesis regulations. Building to one uniform global policy means building to the most stringent applicable standard across all of these.

Does US law protect someone's voice from being cloned without permission?

Increasingly, through state-level right of publicity law, which historically protected name, image, and likeness and has been extended in several states to cover a sufficiently distinctive and recognizable voice, even without using an actual recording of the person's own voice. This protection varies meaningfully by state rather than existing as one uniform federal standard, and some states have also introduced newer, more specifically AI-focused legislation addressing voice cloning and deepfakes directly.

Does complying with the EU AI Act mean I'm compliant in the UK too?

No. The UK left the EU and is not bound by the AI Act, pursuing its own generally more principles-based approach to AI governance instead. UK law addresses voice cloning-adjacent harms through a combination of its own data protection framework, existing defamation and fraud law, and evolving parliamentary attention to deepfakes specifically, rather than one comprehensive statute comparable to the EU's AI Act. Compliance needs to be assessed separately for each jurisdiction.

Why does China's approach to voice cloning regulation look different from the US and EU?

China has moved comparatively early with an explicit, purpose-built regulatory framework specifically covering what it calls deep synthesis technology, including voice cloning, administered through dedicated cyberspace administration regulations. This framework places specific compliance obligations directly on technology providers, not only on end users, and includes explicit labeling and consent requirements, representing a more centralized and specifically targeted regulatory philosophy than either the US state-law patchwork or the EU's broader AI Act.

What should a company do given this level of legal fragmentation?

Build internal consent, disclosure, and usage policies to the most stringent applicable standard across every jurisdiction actually relevant to your operations and audience, since this is both the more conservative and, in practice, the operationally simpler approach compared with maintaining genuinely separate policies per jurisdiction. Treat legal awareness in this area as an ongoing function given how quickly it is evolving, and involve jurisdiction-specific legal counsel before scaling any commercially significant program.

Is well-documented consent enough to cover me regardless of jurisdiction?

Explicit, specifically scoped, well-documented consent is a strong practical foundation across essentially every framework discussed here, but the specific legal mechanism through which it matters, and the additional obligations layered on top of it, vary by jurisdiction. Consent alone does not substitute for understanding and complying with jurisdiction-specific disclosure, labeling, or data protection requirements that may apply independently of whether consent was obtained.


Related reading: Synthetic Voice Disclosure | Ethical Voice Cloning | Video Translation Security and Privacy