Someone generates a birthday video of a colleague giving a heartfelt speech they never gave. A parent uses an AI tool to “improve” a family photo by swapping in a better smile from a different shot. A creator turns a friend’s holiday snapshot into a stylized illustration and posts it. None of these examples are malicious. All of them raise the same two questions, and most people only think to ask one of them, if any: did the person in the image agree to this, and does anyone who sees it know AI was involved.
This article is a practical way to answer both questions before you post, not after someone asks why they were not told.
Two questions, not one
It is tempting to collapse “is this okay to post” into a single gut check, but consent and disclosure are genuinely separate failure modes.
Consent is about the person depicted. Did they agree to being generated, edited, or synthesized in this way, for this purpose, in this context? A person can be completely fine with a fun filter for a private chat and genuinely upset about the same technique used in a public post, a dating profile, or a work presentation. Consent is contextual, not a one-time checkbox.
Disclosure is about the audience. Does a reasonable viewer understand that what they are looking at was AI-generated or AI-edited in a way that changes its meaning? A viewer can be fully aware that filters exist in general and still be misled by a specific piece of content that does not say so.
You can satisfy one and fail the other. A fully consented AI video of a real person can still mislead an audience if it looks like an unedited recording and nothing marks it otherwise. A clearly labeled “AI-generated” image can still violate someone’s consent if they never agreed to be depicted that way at all.
Consent for the original photo is not consent for a synthetic transformation of it. Someone who let you take their picture at a party did not automatically agree to appear in an AI-generated video, a stylized deepfake, or an edited version depicting them somewhere they never were.
What “identifiable” means here
The checklist in this article applies whenever a real, identifiable person could be recognized in the result - by face, voice, name, distinctive setting, or context that narrows it to one person even without a clear face. It does not apply to fully synthetic people, generic illustrations, or your own likeness used with your own consent. When in doubt about whether someone is identifiable, assume they are; the cost of asking is a short message, and the cost of skipping the question is a much harder conversation later.
The consent check
Before generating or posting synthetic media of someone else, work through these in order:
- Does the person know this content exists? Not “would they probably be fine with it” - do they actually know.
- Did they agree to this specific use? A person consenting to an internal team photo did not consent to a public marketing video built from it.
- Would the context surprise them? A humorous private-chat edit and the same edit posted publicly are different requests, even with identical output.
- Can they ask you to take it down? If the honest answer is “not really, once it’s posted,” that is a signal to slow down before posting, not after.
If any answer is no or unclear, ask the person directly before you generate or share anything - a short message (“I want to make a fun AI video with your photo for the team chat, is that okay?”) costs seconds and prevents most of the actual harm.
The disclosure check
Separately, before anything goes anywhere a stranger might see it:
- Would a reasonable viewer assume this is an unedited photo or recording, without a label? If yes, and it is not, label it.
- Does the platform’s own AI-content label apply, and is it turned on? Most major platforms now have a way to mark content as AI-generated or AI-modified - use it rather than relying on viewers to guess.
- Is there a human-readable disclosure near the content, not just embedded metadata? Metadata can be stripped by re-uploads, screenshots, and format conversions; a caption or on-image label survives those better.
- Does the disclosure describe what actually changed? “AI-enhanced” covers a lot of ground; if the change is material - a different setting, words the person never said, an edited expression - say so specifically.
The EU AI Act’s transparency rules for AI systems include obligations that take effect from 2 August 2026, including Article 50 duties that distinguish machine-readable marking by providers from clear, perceivable labelling by deployers of certain deepfake and synthetic content (European Commission, transparency rules overview). Timing, grace periods, and who counts as a provider versus a deployer depend on the specific use - this article is practical guidance, not legal advice. Check the current regulation text and your platform’s rules before treating any label as optional or complete.
Provenance signals help, but do not replace either check
Tools like Content Credentials (the C2PA standard) can attach a cryptographically signed record of an asset’s creation and editing history, which is a genuine improvement over an unlabeled file (C2PA technical explainer). But a signed credential answers “what tool made this and what did it assert,” not “did the depicted person agree” or “does the viewer actually see the disclosure.” A perfectly signed, fully provenance-tracked video can still be posted without the subject’s consent, and a credential can be stripped by an ordinary screenshot or re-upload before it ever reaches your audience. For the deeper technical and organizational version of this - what provenance can and cannot prove, and how to build a publishing policy around it - see Content Credentials and watermark basics for the individual-reader version, or provenance, watermarking, and Content Credentials for the organizational one.
If you are the one generating the media, keep your own record of what you made, from what source, with whose agreement, and when - even a one-line note. If a question comes up later, “here is what I generated and here is the message where they agreed” resolves it in a way that memory alone will not.
What this does not cover
This checklist is for content you are creating or sharing about someone else with generally good intent. It is not the process for what to do if you discover a deepfake made of you without your consent - that is a different, harder situation, covered in the adult first-response plan. It also is not the general privacy checklist for uploading someone’s photo to an AI tool in the first place, which sharing images with AI covers. And if the concern is specifically about whether an image or video looks real versus AI-made, rather than about consent, AI image limits, not detectors covers what you can and cannot reliably tell.
Common pitfalls
- Assuming a private, funny intent excuses skipping consent. Private intent does not control what happens after a screenshot leaves the private chat.
- Treating “everyone does this now” as consent. Normalization of a technique is not agreement from the specific person depicted.
- Labeling once and assuming it survives. A caption on your original post does not travel with a screenshot or re-upload; consider an on-image or on-video label for anything likely to be reshared.
- Confusing a Content Credential with a consent record. They answer different questions - keep both if you can, but do not substitute one for the other.
- Skipping the check for low-stakes content. A silly filtered video of a friend for a group chat still deserves the thirty-second question “is this okay to post here.”
Try it this week
The next time you generate or edit an image or video that includes a real, identifiable person other than yourself, run both checks before it goes anywhere: get their explicit agreement for this specific use, and label the result so viewers know AI was involved. Use the synthetic media provenance and consent checklist to make both checks automatic rather than something you remember only after a problem.



