180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-137
Consumer AI · United States · 2024 · Use of a likeness without clear consent

OpenAI showed off a chatbot voice that many said sounded like Scarlett Johansson, who had turned the company down

By Ellie Harris · Filed GPT-4o voice demonstrated 13 May 2024; voice paused around 19 May 2024

Alleged: OpenAI developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

OpenAI showed off a chatbot voice that many said sounded like Scarlett Johansson, who had turned the company down

What happened

It was reported that on 13 May 2024 OpenAI demonstrated a new version of ChatGPT that could talk out loud, and that one of its voices, called Sky, struck many listeners as sounding like the actor Scarlett Johansson. Around the same time, the company’s chief executive posted a single word, “her”, a reference to the 2013 film in which Johansson voices an AI assistant.

Johansson then said in a public statement that the chief executive had approached her in 2023 to voice the assistant, that she had declined, and that she was shocked and angered to hear a voice that sounded so like her own. OpenAI said Sky had been voiced by a different professional actor using her own natural voice, that this actor had been cast before the company approached Johansson, and that it had not set out to imitate her. It paused the Sky voice within about a week, saying it did so out of respect for Johansson’s concerns.

A later voice analysis, commissioned by NPR and carried out at Arizona State University, reported that Sky sounded more similar to Johansson’s voice than to hundreds of other voices it compared. Reporting noted that this does not establish that OpenAI copied her voice or set out to, and the company’s account stood.

What an auditable version would have shown

An auditable process would have answered the questions everyone was asking after the launch. It would show who chose the voice actor, whether anyone raised concerns that the voice sounded like a real person, whether that person had been asked for permission, what their response was, and who decided to launch the feature anyway. Instead of arguing about consent after the fact, the company would have had a clear record showing exactly what happened and why.

Where the gap was

The problem was that consent appears to have become something to deal with after the launch instead of before it. Whether or not the voice was actually based on Scarlett Johansson, OpenAI had reportedly approached her, she declined, and the released voice was widely compared to hers. That should have triggered a simple question before release: do we have the right to launch something that could reasonably be seen as using this person’s likeness or voice? That question should have been answered before the product went live, not afterwards.

What governance should have looked like

If a product uses a voice or likeness that could reasonably be associated with a real person, permission shouldn’t be an afterthought. It should be a release requirement. Before launch, there should be a clear record showing who approved the voice, whether consent was needed, whether it had been obtained, and who accepted the decision to proceed. That doesn’t just protect the individual. It protects the company as well. When questions arise later, they can be answered with evidence instead of public arguments.

An AuthorityGate is designed to hold a release until the permission behind a likeness is in place and recorded, so a feature does not ship on the assumption that consent can be sorted out later. A ConductRecord of who was cast, who was asked, and what they answered turns consent from a public argument into a matter of record.

The reference implementation of AuthorityGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed, free for any company to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and OpenAI could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →