Skip to content
Responsible AI6 min read

Voice cloning and consent: the rules that apply in 2026

What the EU AI Act, US law, YouTube, payment providers and Pakistan's PECA expect from anyone cloning a voice, and a consent checklist.

Founder, Chief Executive and Director, Ennovaq

Cloning a voice is legal in most places when you have the speaker's consent and you do not use the clone to deceive. Without consent, it can break privacy, publicity, fraud and election laws, and it breaks the rules of every major platform and payment provider. In 2026 the rules have converged on two principles: get documented consent before you clone, and disclose realistic synthetic media when you publish it. Here is what that means in practice.

What counts as voice cloning

Voice cloning means training or prompting an AI system to reproduce a specific person's voice, so that it can say things the person never said. It is different from text-to-speech with a stock voice, which belongs to no identifiable person. Modern systems can produce a convincing clone from a short sample, which is why the rules focus on the person whose voice it is, not on the technology.

The rules, place by place

WhereWhat appliesStatus in October 2026
European UnionAI Act, Article 50: providers of systems that generate synthetic audio, images or video must mark outputs as artificially generated in a machine-readable way; people who use AI professionally to create deepfakes must disclose themIn force since 2 August 2026. Providers whose systems were already on the market have until 2 December 2026 to add machine-readable marking
European UnionGDPR: a voice recording of an identifiable person is personal data; voice used to identify someone is biometric dataIn force
United States, federalFCC ruling of February 2024: AI-generated voices in robocalls count as "artificial" voices under the Telephone Consumer Protection Act, so prior express consent is requiredIn force
United States, federalNO FAKES Act of 2026 (S.4591 and H.R.8915): would create a federal right to control digital replicas of a person's voice and likenessA bill. Approved by the Senate Judiciary Committee in June 2026; not yet law
United States, statesTennessee's ELVIS Act protects voice as part of a person's right of publicity; California restricts contracts for digital replicas of performers; Illinois' biometric privacy law covers voiceprintsIn force
DenmarkA bill giving people rights over realistic digital imitations of their face and voiceIntroduced to parliament on 8 October 2026
ChinaDeep-synthesis rules require consent before editing someone's voice or face, and labelling rules require AI-generated content to be markedIn force since 2023 and 1 September 2025
PakistanNo deepfake-specific law yet; the Prevention of Electronic Crimes Act, 2016, amended in 2025, covers unauthorised use of identity information and fake sexual imageryIn force

What platforms and payment providers require

Laws set the floor; the companies you depend on often set a higher bar.

  • YouTube requires creators to disclose realistic altered or synthetic content, such as a real person appearing to say something they did not, and lets people ask for the removal of AI content that simulates their face or voice.
  • Payment providers restrict the category heavily. Paddle's acceptable use policy, updated in April 2026, prohibits voice impersonation, deepfakes and any content generation that uses a person's likeness without their explicit consent.
  • Voice AI companies, including ours, require consent for cloning another person's voice and can suspend accounts that cannot show it.

The practical consequence: even where a use might be lawful, a voice product without consent controls struggles to take payments, publish on platforms or survive a complaint.

Consent is the difference between a legitimate use and a liability. A short message saying "sure, go ahead" is not enough. Good consent is:

  1. Written and signed, by the person whose voice will be cloned, with the date.
  2. Specific about the voice: whose it is, and which recordings will be used.
  3. Specific about the uses: what content, which channels, which languages, and whether it can be used commercially.
  4. Limited in time, with a clear end date or a review date.
  5. Clear about payment, if any, for the use of the voice.
  6. Revocable: it explains how to withdraw consent, and what happens to the voice model when they do.
  7. Informed: it says plainly that an AI system will learn to reproduce the voice and could make it say new things.

Keep the signed consent with the project files. If a platform, a payment provider or the person themselves asks, you should be able to produce it within days.

This is a starting point, not legal advice. Have it checked for your jurisdiction and your use.

VOICE CLONING CONSENT

I, [full name], consent to [person or company] creating a synthetic
voice model from recordings of my voice, and using it to produce:
[describe the content, e.g. narration for training videos]

Channels and markets: [e.g. YouTube and the company website, worldwide]
Languages: [e.g. English and Urdu]
Period: from [date] until [date]
Payment: [amount, or "none"]

I understand that the model can produce speech I have not recorded.
The model must not be used to imitate me in any other context, for
political content, or in a way that could mislead people into thinking
I said something I did not.

I can withdraw this consent at any time by writing to [contact].
When I do, the voice model will be deleted within 30 days, and no
new content will be made with it.

Signed: ____________________   Date: ____________

Add a short recording in which the person reads part of the statement. It is the simplest proof that the voice and the consent belong to the same person.

Disclosure: when to label AI voices

Label realistic synthetic voices whenever a reasonable listener could believe a real person said the words. That is required for professional deepfakes in the EU, required by YouTube for realistic synthetic content, and good practice everywhere else. Satire and obvious fiction need less, but a clear label still protects you.

Labelling does not replace consent. A clearly labelled clone of someone who never agreed is still a clone of someone who never agreed.

What is never acceptable

Some uses are off-limits under any consent form:

  • cloning the voice of a child;
  • scam calls, fake emergencies and attempts to defeat bank voice checks;
  • sexual content using a real person's voice or likeness without their consent;
  • fabricated statements by candidates or officials, or content that misleads voters; and
  • harassment or impersonation designed to damage someone.

Act quickly, and keep records as you go:

  1. Save the evidence. Download or screen-record the content, and note where you found it, when, and who posted it.
  2. Report it to the platform. YouTube, Meta, TikTok and others have reporting routes for impersonation and for synthetic content that imitates a real person.
  3. Report it to the tool's maker. If you know or suspect which voice product was used, use its abuse or takedown route. Responsible providers can disable the voice model and preserve evidence of who created it.
  4. Report crimes to the authorities. Fraud, extortion, harassment and sexual imagery are crimes in most countries, including under Pakistan's Prevention of Electronic Crimes Act.
  5. Take legal advice if the misuse is damaging your reputation or income. Depending on where you live, privacy, publicity, defamation or data protection law may give you a claim.

How we apply this at Ennovaq

EchoClone and ReVidGen let people clone their own voices, and other voices with documented consent. Our Acceptable Use Policy sets out the consent rules above, bans cloning minors, requires disclosure where the law or a platform demands it, and publishes a takedown route: anyone whose voice has been used without consent can write to info@ennovaq.com, and we investigate within 48 hours.

If you are building a product with voice or avatar features, we can build the same safeguards into yours. See AI product engineering.

Found this useful? Take the next step.

Read our Acceptable Use Policy

Keep reading

Work with us

Tell us what you are building.

Message us on WhatsApp or email a short brief. We reply within one business day with questions, a rough budget range and the next step.