
Nobody signed a release. That’s the uncomfortable fact sitting underneath the excitement around a new wave of AI ad-generation tools, and publishers have already watched this exact scenario play out with a real plaintiff, a real regulator, and a real settlement.
In 2018, UK consumer advocate Martin Lewis sued Facebook after scam ads used his face and name without permission to promote fraudulent investment schemes he had nothing to do with. He didn’t sue whoever built the fake creative — he sued the platform that served it. Facebook settled in 2019 by funding a scam-detection tool through Citizens Advice rather than fight the case per BBC News. That precedent — liability attaching to the distributor, not the unreachable or unidentifiable creator — is exactly the fact pattern publishers running AI-generated ad inventory are now stepping into, at scale, without the paperwork that used to make the question moot.
Higgsfield AI, a generative video platform aimed at marketers, just partnered with Adweek to launch an $85,000 “Adathon” contest challenging brands and creators to build entire ad campaigns using generative AI — no shoots, no casting, no talent contracts. That’s a genuinely useful capability for brands squeezed on production budgets. It’s also a preview of how much programmatic inventory may soon arrive with no clearance trail at all.
The Contract That Isn’t There
Traditional ad production runs on a stack of documents nobody thinks about until something goes wrong: talent releases, likeness clearances, union agreements, E&O insurance covering the specific use case. That paperwork exists because publicity rights — a person’s legal control over the commercial use of their name, face, and voice — are enforceable and violations carry real damages.
Generative platforms don’t produce that paperwork, and the disputes are already piling up. Tom Hanks publicly warned fans in 2023 that a video ad promoting a dental plan used an AI-generated version of his likeness that he had never authorized, telling followers directly to ignore it per The Guardian. Scarlett Johansson’s dispute with OpenAI over a voice she said sounded “eerily similar” to her own, deployed without her consent, drew the same conclusion from a different angle: the company that shipped the product faced the demand letter, not the training data per BBC News. In digital advertising, the equivalent actor isn’t the model vendor — it’s whoever hits “approve” on the ad and serves it to an audience.
Biometric Law’s Track Record
Illinois’ Biometric Information Privacy Act has already produced the litigation blueprint for what synthetic-likeness ads could trigger next. The Illinois Supreme Court’s 2019 ruling in Rosenbach v. Six Flags held that plaintiffs don’t need to show actual injury to sue under BIPA — a bare statutory violation is enough per Justia, which is the ruling that opened the floodgates to the wave of suits that followed. Facebook paid $650 million in 2021 to settle a BIPA class action over facial-recognition tagging per Reuters, and Google settled a similar suit for $100 million the following year. Attorneys who built practices around those cases, including Jay Edelson’s firm, are the same lawyers advertisers and publishers should expect to notice a new category of exposure once AI ad tools start generating faces that map uncomfortably close to real, identifiable people.
The EU adds a second front. GDPR classifies biometric data as a special category requiring explicit consent, and regulators have already shown they’ll enforce it against companies handling facial data without a lawful basis: the UK’s Information Commissioner’s Office fined Clearview AI £7.5 million in 2022 for scraping facial images without consent per the ICO, a penalty a tribunal later overturned on jurisdictional grounds — but French and Italian regulators issued their own fines against the same company under their own GDPR authority around the same period, according to reports. Publishers running programmatic inventory across US and EU audiences are exposed to both frameworks for a single piece of creative whose provenance they can’t verify at serve time.
Why This Lands on Distribution, Not Creation
Ad tech was built around the assumption that creative arrives pre-cleared. Ad servers, SSPs, and publisher ad ops teams have never been positioned to vet whether on-screen talent consented to appear — that verification happened upstream. Generative tools collapse that step entirely. Hollywood’s own talent unions saw this coming: SAG-AFTRA’s 2023 strike produced a landmark agreement specifically governing AI-generated digital replicas of performers per Reuters, because the industry recognized synthetic likeness as a distinct liability category requiring its own contract language, not boilerplate IP indemnification.
What Publishers Should Do Monday Morning
None of this requires rejecting AI-generated creative outright. But ad ops and legal teams need to stop treating “AI-generated” as a production detail and start treating it as a compliance flag. That means asking demand partners directly whether creative was AI-generated, rewriting indemnification clauses to name synthetic-likeness claims specifically rather than relying on generic pre-generative-AI language, and building a fast-pull process for when a claim surfaces — because the Martin Lewis and BIPA cases both prove the same point: regulators and plaintiffs go after the entity that put the content in front of the public, and that’s the publisher, every time.
