180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-169
Consumer AI · United States · 2025 · Generation of a real person's likeness without consent

OpenAI paused Sora depictions of a civil rights leader at his estate's request, and offered estates an opt-out while living people's likenesses were already opt-in

By Ellie Harris · Filed Sora app launched 30 September 2025; depictions reported through October 2025

Alleged: OpenAI developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

OpenAI paused Sora depictions of a civil rights leader at his estate's request, and offered estates an opt-out while living people's likenesses were already opt-in

What happened

It was reported that within about a week of the Sora app launching at the end of September 2025, users were generating videos of deceased public figures, and their families were asking publicly for it to stop. In October OpenAI and the estate of a civil rights leader said generations depicting him had been paused at the estate’s request while guardrails for historical figures were strengthened, and that estates could ask for a likeness not to be used.

OpenAI, a performers’ union, an actor whose voice and likeness had been generated without his consent, and three talent bodies issued a joint statement later that month. It recorded that opt-in for voice and likeness had been OpenAI’s policy from launch, and that the company regretted the generations and had strengthened its guardrails. The route offered to the estates of the dead is an opt-out, which is the reverse of the arrangement for the living.

What an auditable version would have shown

The cases described in the sources reviewed entered the public record through external reporting, family advocacy or union escalation. A daughter asked publicly and then contacted the company. A performer noticed and told his union. No figure for how many generations claimed a real person’s likeness, how many were tested against a consent record, or how many were refused was identified in the sources reviewed.

Each generation could leave a record showing whose likeness was used, whether consent was on file, what the check found and what happened next. Put those records together and the company could see how many attempts were refused before publication and how many reached an audience. It could then show whether its policy was actually being enforced.

Where the gap was

It was reported that consent for a living person’s voice and likeness was required by policy from launch, and that a performer’s voice and likeness were nonetheless generated in some outputs without it. A PersonaGuard is designed to test whether a generated persona matches an identity the operator has authorised, at generation and again at output, and to record whether a likeness without a consent record was refused before publication. A ConstraintGate runs the standing rule as a check before publication, including where the person depicted is dead and the operator has undertaken to honour an estate’s request. A ConductRecord preserves the request, the likeness claimed, the consent record tested and the output. None of these decides who should be depictable. What they change is that a policy stated in public becomes something the operator can demonstrate it applied.

What governance should have looked like

OpenAI’s stated position is that opt-in for voice and likeness was its policy from the start, and that it strengthened its guardrails after outputs were generated without consent. The reporting reviewed here records that each case surfaced because the person depicted, a family member or a union raised it.

Where an organisation generates a real person’s voice or likeness, best practice would be to test a consent record before the generation is produced rather than after a complaint, to provide a documented estate or authorised representative route for declaring likeness preferences before generation rather than relying on a request after release, and to record what was checked so the organisation can state how much of its enforcement is its own.

Failure Pattern: a generative video product produced likenesses of real people without consent, and each case entered the record because the person depicted, a family member or a union raised it rather than because a check at generation refused it.

Governance Principle: when an organisation generates a real person’s voice or likeness, it should be able to show whose likeness was used, whether consent was given, and what happened when that consent was checked.

The reference implementation of PersonaGuard, ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and OpenAI could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed August 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →