Film and television production now uses machine learning throughout: de-ageing and face replacement in visual effects, voice cloning for pickup lines and dubbing, crowd generation, previsualisation, and marketing assets cut from footage. Most of that is ordinary tooling. What makes AI in film a security subject is one class of asset: data that can reproduce a specific person. A full-body scan, a few hours of clean studio dialogue, or a fine-tuned voice model is, in the wrong hands, a ready-made deepfake kit for that performer. Inside the production, it is also a contract: every use of it is limited by what the performer agreed to.

This article treats those assets the way a security engineer treats credentials. It summarises the rules that constrain their use, builds a threat model, and then designs a pipeline where consent is attached to the asset itself, every render or dubbing job is authorised against that consent, and retention ends in verified destruction. It is written for production technology, VFX pipeline and studio security teams; it is not legal advice, and the legal summaries below should be checked against the agreements and statutes that apply to your production.

The rules a pipeline must encode

The 2023 SAG-AFTRA TV/Theatrical agreement, which followed that year's strike, set the vocabulary most US productions still use. It distinguishes an employment-based digital replica, made with the performer's participation in connection with their employment on a production, from an independently created digital replica, made without that participation. Use of an employment-based replica requires the performer's clear and conspicuous consent, based on a reasonably specific description of the intended use, with an exception where the photography or soundtrack remains substantially as scripted, performed or recorded. So the common summary, that consent is always required, is not quite right; the exception is narrow, and deciding whether it applies is a legal judgement, not something a pipeline should infer.

A successor agreement was ratified by members on 4 June 2026, effective from 1 July 2026 to 30 June 2030. Press reports describe it as extending the replica protections and further restricting synthetic performers; read the agreement text itself before encoding any of its terms.

Statute adds a second layer. California's AB 2602, effective 1 January 2025, makes a contract provision allowing a digital replica in place of work the person would otherwise perform in person unenforceable when the intended uses are not reasonably specifically described and the person was not represented by counsel or a union whose agreement addresses replicas; all of those conditions must hold. AB 1836, effective the same day, requires consent from the estate for replicas of deceased personalities. A federal NO FAKES Act has been proposed in Congress; check its current status rather than assuming it.

In the EU, Article 50(4) of the AI Act, applicable from 2 August 2026, requires deployers to disclose deepfakes, but where content forms part of an evidently artistic, creative, satirical or fictional work, the duty is limited to disclosing the existence of generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. A credit-roll notice can satisfy that; a marketing clip lifted out of the film may not be read as part of the work.

For engineering, these rules reduce to four checks per use: is there a grant, does the use fall inside its described scope, is the medium and context inside it, and does the output carry the disclosure its destination requires.

Threat model for likeness assets

ThreatExamplePrimary control
Exfiltration of scan or voice dataVendor workstation copies a voice datasetVault encryption, per-job keys, egress monitoring
Scope creepReplica consented for one scene used in the trailerRender-time authorisation against grant scope
Reuse across productionsScan from film one used in the sequelGrants bound to production and asset hash
Unconsented derivative modelsVoice model fine-tuned on dailiesTraining jobs go through the same authorisation
Retention beyond purposeScans kept on a vendor server for yearsDestruction certificates, inventory reconciliation
Leaked replica used for fraudCloned voice used to phone the performer's bankLeak prevention plus the controls in deepfake defence
Deceased performerArchive footage used to synthesise new linesEstate consent recorded as a grant

Two features of this threat model are unusual. First, the asset is irreplaceable: you can rotate a leaked key, but not a leaked face. That shifts weight from detection to prevention. Second, many insiders are legitimate: dozens of artists across several vendors need access during post-production. Controls must therefore make access narrow in time and scope, not merely authenticated.

A replica vault with consent bound to hashes

The design centres on a replica vault. Capture produces raw data; ingest computes a SHA-256 hash of each asset bundle, encrypts it with a key held in a key management service, and records performer, production and capture session. Nothing downstream receives raw assets except through a job that the authorisation service has approved.

Likeness assets: capture, vault, authorised useCapture stagescan, voice sessionIngesthash, encrypt, tagReplica vaultencrypted assets keyed by SHA-256Consent registrygrants bound to asset hashesSigned consentperformer, agentgrantAuthorisation serviceuse, media, language, territory, dateJob requestVFX, dub, marketingNeeds legalambiguous scopeRender or dub jobshort-lived decryption keyallowOutputprovenance, job log
Consent travels with the asset hash. Every VFX, dubbing, marketing or training job is authorised against the grant, receives a short-lived decryption key, and leaves a log entry.

Consent is a record, not a PDF in a shared drive. Each grant names the exact asset hashes it covers and the described uses, and points to the separately signed document that the agreements require. The pattern is the same event-sourced approach described for training data in consent flows for AI data: grants and revocations are appended, never edited.

from dataclasses import dataclass
from datetime import date

@dataclass(frozen=True)
class Grant:
    grant_id: str
    performer_id: str
    production: str
    asset_hashes: frozenset      # the exact scan / voice bundles covered
    uses: frozenset              # e.g. {"de_age_vfx", "pickup_dialogue"}
    media: frozenset             # e.g. {"feature"}; trailers listed explicitly
    languages: frozenset         # for dubbing; empty means original language only
    expires: date
    signed_doc: str              # pointer to the separately signed consent
    revoked: bool = False

Authorising every job

Every job that would decrypt a likeness asset calls the authorisation service with the asset hash, the production, the use, the medium and, for dubbing, the language. The service returns one of three answers, and the third is as important as the first two.

def authorise(job, grants, today):
    candidates = [g for g in grants
                  if job.asset_hash in g.asset_hashes
                  and g.production == job.production and not g.revoked]
    if not candidates:
        return "DENY", "no grant covers this asset for this production"
    for g in candidates:
        if g.expires < today:
            continue
        if (job.use in g.uses and job.medium in g.media
                and (not job.language or job.language in g.languages)):
            return "ALLOW", g.grant_id
    if job.claims_substantially_as_scripted:
        return "NEEDS_LEGAL", "scripted-use exception claimed; legal must decide"
    return "NEEDS_LEGAL", "outside every grant's described scope"

On ALLOW, the service issues a decryption key scoped to that job and valid for hours, not weeks, and writes an append-only log entry with job, grant, operator and output path. The job writes provenance metadata into its output declaring synthetic or altered content, using the approach in C2PA for AI-generated content, so that downstream disclosure decisions have a machine-readable fact to work from.

Training is a job like any other. Fine-tuning a voice model on session recordings requires a grant listing that use, and the resulting model weights are themselves ingested into the vault with a new hash and a lineage pointer to the assets they came from. A model derived from a performer's data inherits that performer's grants and nothing more; when the grant is revoked or expires, the model is destroyed with the source data.

Vendors, retention and destruction

Most likeness data leaves the studio, because VFX and localisation are outsourced. Contractual controls matter, but technical ones decide what actually happens. Vendors should work inside a studio-controlled environment, such as a virtual workstation with no local download, wherever their tools allow it. Where data must travel, it travels encrypted with keys the studio holds, and the vendor's access is tied to job authorisations rather than standing credentials. Egress monitoring on that environment watches for bulk reads of asset bundles that no active job explains.

Retention needs an end state. At wrap, the vault inventory lists every asset and every derived model for the production. Each one is either kept under a grant that explicitly allows retention, or destroyed, and destruction at a vendor is evidenced by a signed certificate naming the hashes. Reconciliation compares the inventory with certificates; any hash with neither a retention grant nor a certificate is an open finding.

Worked example: a pickup line and a dubbed trailer

A feature film in post-production needs two things from one lead performer. In an illustrative case, a line of dialogue in a recorded scene must change after a test screening, and the distributor wants a German dub of the trailer using a voice model so the performer's own voice carries the line.

The performer's grant covers the feature, uses pickup_dialogue and de_age_vfx, original language, and the session bundle hashes from the voice capture. Its pickup_dialogue entry is not a blanket tag: it points to a rider, signed with the contract, that describes the permitted scope as alternate takes of listed lines in named scenes, each identified by script reference. The editorial request names one of those lines and its replacement. Because the new wording is not among the described alternates, the service cannot match it and returns NEEDS_LEGAL. Business affairs obtains a short, specific amendment describing the new line, records it as a grant event, and the resubmitted job is allowed with a six-hour key. Consent specificity has to exist before the job runs; a log written afterwards cannot supply it.

The trailer request fails twice over: medium trailer is not in the grant, and language de is not either. Again the answer is NEEDS_LEGAL, and again an amendment negotiated with the performer's representatives is recorded before the job is resubmitted and allowed. Because the trailer will be released as a standalone marketing asset in the EU, the marketing team also adds an on-screen notice that the voice was synthesised, rather than relying on the film's end credits.

Without the pipeline, the most likely outcome is that a localisation vendor, holding a voice model from the dubbing work, produces the trailer line on request, and the gap is discovered when the performer hears it.

Failure modes

  • Consent stored as documents. Nobody can check a job against a PDF at render time. Encode grants as data bound to hashes.
  • Hashes on the wrong object. Hashing the delivery archive but not the extracted assets lets a re-packed copy escape. Hash bundles at ingest, after normalisation.
  • Standing vendor access. Long-lived credentials outlast jobs and productions. Issue keys per job.
  • Derived models outside inventory. A fine-tuned voice model is not a "file" anyone tracks. Ingest weights into the vault with lineage.
  • Automating the exception. A pipeline that decides a change is substantially as scripted is making a legal call. Route it to people.
  • Disclosure lost in reuse. A clip cut from the film loses its credits context. Attach provenance to the asset and re-check disclosure per destination; see AI-generated media labelling.

Trade-offs

Controlled environments slow artists down and some specialist tools will not run in them; the practical compromise is to allow local work on low-resolution proxies and keep full-resolution likeness assets in the controlled environment. Narrow grants protect performers but generate more legal requests; templated grant amendments for common cases, such as additional dub languages, cut that cost. Strict destruction at wrap protects the performer but rules out reshoots and sequels without fresh capture, which is exactly the trade the performer should get to make, through a retention grant. And every control here assumes the vault is the only path. If productions can bypass it by emailing a scan, none of the rest matters, so the first metric to watch is the share of likeness assets in the vault versus the share found in periodic storage scans.

What to do next

  1. Inventory every likeness asset and derived model on current productions, including at vendors.
  2. Stand up a vault: hash at ingest, encrypt with studio-held keys, record performer and production.
  3. Convert signed consents into grant records bound to asset hashes, with uses, media, languages and expiry.
  4. Put an authorisation check in front of every render, dubbing, marketing and training job.
  5. Issue short-lived per-job keys and log every decryption to an append-only store.
  6. Route out-of-scope and scripted-exception claims to legal; never auto-approve them.
  7. Write provenance into outputs and decide disclosure per destination, including the EU.
  8. At wrap, reconcile inventory against retention grants and destruction certificates.
Key takeaway: Treat performer scans, voice recordings and models derived from them as irreplaceable credentials. Bind each consent grant to the exact asset hashes it covers, authorise every render, dub, marketing and training job against the grant's described scope, send ambiguous cases to legal rather than deciding them in code, and end every production by reconciling the vault against retention grants and destruction certificates.