Is Voice Cloning Legal in 2026? What the Law Now Says

Is Voice Cloning Legal in 2026? What the Law Now Says

A voice actor heard himself narrating a podcast he had never recorded. Two years later, four legal systems had answers.

Paul Skye Lehrman was listening to a podcast about artificial intelligence when the guest started speaking in his voice. He had never recorded the episode.

That moment appears in a lawsuit filed in the Southern District of New York. Lehrman and fellow voice actor Linnea Sage allege that recordings they sold through Fiverr in 2019 and 2020, on the stated understanding that the audio was for internal research, were later used to build commercial synthetic voices sold to the public. Lovo, the company they sued, faced sixteen separate claims covering breach of contract, copyright, false endorsement under the Lanham Act and New York right-of-publicity law. In July 2025 a judge let several of those claims proceed.

The case has not concluded. The actors filed a second amended complaint at the end of July 2025 and the parties spent the following year in discovery. What has happened around it is a two-year scramble by lawmakers on three continents to answer a question the technology had already made urgent: when is it lawful to make a machine speak in someone else's voice?

This article starts with what a voice clone actually is, because the legal answers depend on the mechanics. It then works through the rules now in force across the United States, the European Union, India and the United Kingdom, and closes with the consent record that survives a challenge.

A voice clone is a model, not a recording

Voice cloning builds a statistical model of how a specific person speaks, then generates audio of that person saying words they never said. Nothing is spliced together from old tape. The output is new.

The pipeline moves through six stages: collecting voice samples, cleaning the audio, extracting vocal characteristics, training the model, synthesising speech, and deploying the finished clone. The model learns pitch, pace, accent and the small timing habits that make a voice recognisable.

Two shifts explain why this stopped being a research curiosity. Under two minutes of usable audio now produces a working clone. And instant cloning skips training altogether by feeding your sample to the model as a live reference at the moment of generation, which means a clone can exist seconds after the upload finishes.

TechnologyWhat it doesLegal exposure
Text to speechGenerates speech in a synthetic voice built from a licensed or invented voice profileLow. No identifiable person is replicated.
Voice cloningBuilds a model of a named individual's voice from their recordingsHigh. Identity rights attach directly.
Voice conversionTransforms one person's live speech so it comes out sounding like another personHigh. Often used for real-time impersonation.
Speech to speech dubbingCarries a speaker's voice identity into another languageModerate. Depends on whose voice is carried.

Cheap capability created a market. The forecast below tracks where the money went.

A growing market is not what moved legislators. Fraud losses did, and those numbers come next.

The fraud numbers that forced the issue

The US Federal Trade Commission released its 2025 fraud data in June 2026. Consumers reported losing about $15.9 billion to fraud of all kinds, the highest figure the agency has recorded and up from about $12.5 billion in 2024.

Imposter scams, the category that voice cloning feeds directly, generated close to a million reports and $3.5 billion in losses. That made them the most reported fraud category for the fifth consecutive year, accounting for nearly one in three fraud reports. About four in five people who filed an imposter scam report lost no money at all. Among those who did, the median loss was $700, though some individuals lost more than $1 million.

Breaking the category apart shows who scammers chose to impersonate. Business impersonators, led by fake bank fraud departments, accounted for close to $1 billion. Government impersonators accounted for roughly $920 million, up from $789 million a year earlier.

The FTC does not publish a separate line item for AI-cloned audio. Anyone quoting a precise dollar figure for voice cloning fraud is estimating, not reporting.

That caveat matters for anyone writing about this topic. What the data does support is narrower and still serious: the fraud category that cloned audio makes easier is growing faster than fraud overall, and regulators have started treating it that way. The FTC's Impersonation Rule took effect in April 2024. In the two years since, the agency has filed twelve enforcement actions under it and recovered more than $70 million for defrauded consumers.

The short answer, before the detail

Two questions settle most voice cloning disputes. Did the person whose voice was cloned agree? And did that agreement cover this particular use? A third question now applies in the European Union and India, and it is about disclosure rather than permission: did you tell the audience the audio was synthetic?

Run any project through the grid below before running it through a lawyer.

ScenarioGenerally lawful?What decides it
Cloning your own voice for your own contentYesYour own consent. Check whether the tool's terms claim any rights over the voice model.
Cloning an employee's voice for internal training materialUsuallyWritten consent naming the scope and the time limit. Employment does not imply permission.
Cloning a musician or actor for an advertisementNoRight of publicity plus false endorsement. This is the highest-risk category that exists.
Parody or commentary using a public figure's voiceSometimesFree-expression carve-outs exist but are narrower than most creators assume, and they shrink fast once money is involved.
Recreating a deceased relative's voiceDependsPost-mortem rights vary sharply between jurisdictions. Some end at death, others run for decades.
Using any cloned voice to obtain money or accessCriminalFraud and wire fraud statutes apply with or without an AI-specific law on the books.

Four doctrines decide every case

No country has built voice cloning law from scratch. Courts reach for legal machinery that already existed, which is why the same four doctrines appear in filings from Nashville to Mumbai.

Right of publicity and personality rights

The primary vehicle almost everywhere. Most jurisdictions already protect a person's name and likeness against unauthorised commercial use, and courts have shown themselves willing to read voice into that protection without waiting for new statutes. US courts did it twice before the internet went mainstream, for Bette Midler against Ford in 1988 and for Tom Waits against Frito-Lay in 1992, both times over a sound-alike singer in an advertisement.

Fraud and consumer protection

A cloned voice used to extract money is fraud, and prosecutors have not needed AI-specific legislation to charge it. Regulators also hold general deception authority that reaches synthetic audio in advertising.

Copyright, and its limits

Here is the nuance most articles skip. A voice itself is generally not copyrightable. A recording of that voice is. Someone can build a clone that sounds exactly like you without copying any protected work, which leaves a gap copyright cannot close. That gap is precisely why the NO FAKES Act was drafted as a new property right rather than an amendment to copyright law, as the next section explains.

Contract

Where most real disputes actually begin. The Lehrman claims turn substantially on what the voice actors were told the recordings would be used for. Scope language in a session agreement decides more cases than any statute.

United States: a federal gap and a state patchwork

There is still no single federal statute governing voice cloning across all contexts. Legality assembles itself out of state statutes, sector regulation, federal consumer protection powers and the doctrines set out above. The sharpest piece of that sector regulation is the FCC declaratory ruling of 8 February 2024, which held that an AI-generated voice counts as an artificial voice under the Telephone Consumer Protection Act. A cloned voice in a robocall therefore needs the recipient's prior express consent, and state attorneys general can enforce that.

Only a handful of states have written statutes aimed specifically at AI voice cloning or digital replicas. Tennessee, California, Illinois, New York and Pennsylvania are the ones that matter most so far. Everywhere else the question runs through broader publicity, privacy, fraud or impersonation law. That does not make cloning unregulated. General right-of-publicity law reaches it. So do fraud statutes and the FTC's consumer protection authority.

The NO FAKES Act, and where it actually stands

On 18 June 2026 the Senate Judiciary Committee unanimously advanced S.4591, the NO FAKES Act of 2026, sending it to the full Senate. It has not become law. Reporting that describes it as already in force is wrong.

If enacted, S.4591 would create a federal intellectual-property right covering unauthorized digital replicas of a person's voice and visual likeness, covering every individual rather than only celebrities. The right is licensable but not assignable during life, it survives the holder's death, and it comes with a notice-and-takedown mechanism for online platforms modelled on existing copyright practice. It would pre-empt future state digital replica laws while leaving in place those already on the books as of 2 January 2025, so Tennessee's ELVIS Act would survive it.

The state law that already bites

Tennessee's ELVIS Act came into force on 1 July 2024 and remains the sharpest state instrument. It defines voice to include both an actual voice and a simulation of it, which closes the argument that a synthetic imitation is something other than the person's voice. Violations carry civil liability and criminal exposure as a Class A misdemeanour, punishable by up to 11 months and 29 days in jail and fines reaching $2,500.

Two of the six markers on that timeline sit outside the United States. Those are covered below, starting with the rules that went live in Europe on 2 August 2026.

European Union: the labelling rules that went live on 2 August 2026

Article 50 of the EU AI Act began applying on 2 August 2026. It is a transparency regime rather than a permission regime, which makes it different in kind from everything discussed so far. Article 50 does not ask whether you had the right to clone a voice. It asks whether you told people the audio was made by a machine.

The Act defines a deepfake at Article 3(60), and the definition covers image, audio and video rather than text. Content qualifies when it meets every one of the criteria below.

CriterionWhat it means
ResemblanceA high level of similarity between the generated content and the subject it simulates
Existing subjectThe person, place, object, entity or event being simulated actually exists
Apparent authenticityThe content would falsely appear authentic or truthful to someone encountering it

The Commission's guidelines put clearly fantastical content outside the definition, so a dragon or a person flying unaided does not need a label. Duties split by role. Providers of the AI system must apply a machine-readable mark to synthetic output so it can be detected downstream. Deployers who publish a deepfake must disclose that the content is artificially generated.

Four details catch people out. The obligation applies with no intent to deceive, so a labelled parody still needs its label. Open-source systems get no exemption. Businesses established outside the EU are caught if they serve EU users. And penalties reach 15 million euros or 3 percent of worldwide annual turnover, whichever is higher.

One piece of breathing room exists, and it is narrower than most summaries suggest. Under the AI Omnibus amendments, generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2). Nothing else moves. The deployer's duty to disclose a deepfake under Article 50(4) applied from day one and has no grace period at all, so anyone publishing cloned audio to an EU audience is already late if they are not labelling it. Content generated before August 2026 does not need retroactive labelling, though the Commission encourages it.

India: three-hour takedowns and a landmark voice case

India moved before Europe and got less coverage for it. On 10 February 2026 the Ministry of Electronics and Information Technology notified amendments to the IT Intermediary Guidelines and Digital Media Ethics Code Rules. They came into force on 20 February 2026, giving platforms a ten-day runway.

The amendments define synthetically generated information for the first time, as content that appears reasonably authentic but was artificially or algorithmically generated, modified or altered using a computer resource. AI-cloned audio sits squarely inside that definition.

•     Labelling. Visual synthetic content must carry a prominent, easily noticeable label. Synthetic audio must carry a clearly prefixed spoken disclosure.

•     Provenance. Labels must be accompanied by permanent metadata carrying a unique identifier that traces the content back to the tool that made it. Intermediaries cannot permit removal or modification of those markers once applied.

•     Takedown speed. Flagged unlawful content acted on through a court order or authorised government notice must come down within three hours, cut from the earlier 36-hour window. Non-consensual nudity and morphed imagery run on a tighter clock still, two hours instead of 24.

•     Platform duties. Significant social media intermediaries must require uploaders to declare whether content is synthetic, then deploy automated tools to verify those declarations rather than accepting them at face value.

Arijit Singh v Codible Ventures

Indian courts had already acted. On 26 July 2024 the Bombay High Court granted playback singer Arijit Singh an ex-parte ad-interim injunction against AI platforms synthesising his voice. Justice R. I. Chagla observed that the conduct shocked the conscience of the court and noted that it put the performer's livelihood at risk.

The order was unusually broad. It restrained use of Singh's name, voice, vocal style, singing technique, mannerisms, photographs and persona across physical media, digital platforms, advertising, merchandise and the metaverse, reaching generative AI tools, voice conversion technologies, digital avatars and deepfakes. It was framed to operate as a dynamic injunction, meaning it extends to mirror sites and repeat infringement without fresh proceedings.

One limit deserves flagging. Indian courts apply a commercial recognition test, so protection is strongest where a person has built measurable commercial value in their identity. A private individual whose voice is cloned faces a heavier burden establishing actionable harm, which is the gap the February 2026 rules partly fill.

A note on the UK and elsewhere

The United Kingdom has no equivalent statute. Ofcom, the ICO, the FCA and the Advertising Standards Authority each apply existing sector duties to the same conduct, which leaves the obligations scattered across four regulators rather than gathered into one instrument. Any UK business serving EU users is caught by Article 50 regardless.

What this means for the work you are actually doing

If you make content

•     Get written consent naming the specific use, not blanket permission. A release for one campaign does not cover the next one.

•     Label synthetic audio by default. Two jurisdictions now require it and platform policies increasingly do too, so labelling costs you nothing and removes an entire category of risk.

•     Treat celebrity voices as off limits without a signed licence, including for parody, once any commercial element enters the project.

•     Keep the raw consent file with the project assets, not in someone's inbox. If you cannot produce it in under a minute, you effectively do not have it.

If you run a business deploying cloned voices

•     Build an internal review step before any cloned-voice asset ships, and keep an audit trail that demonstrates compliance if you are challenged later.

•     Check whether your vendor applies machine-readable marking. Under Article 50 that duty sits with the provider, but your reputation travels with the output.

•     Map which jurisdictions your audience sits in before you ship, because the EU and Indian rules follow the audience rather than your registered office.

•     Give employees a genuine opt-out. Consent extracted as a condition of employment is fragile, because the imbalance of power between employer and employee undercuts any argument that it was freely given.

If you are a voice actor

•     Strike or narrow any clause permitting use of your recordings for machine learning, model training, dataset licensing or synthetic voice development.

•     Watch for research-purpose framing. The Lehrman claims describe exactly that framing preceding commercial deployment.

•     Set an expiry date on every licence you grant. Perpetual rights over a voice model are worth far more than session fees compensate for.

•     Register your work and keep dated records of what you recorded and for whom.

If someone cloned your voice

•     Preserve evidence first. Save the audio, the URL, timestamps and any account details before filing a report, because content disappears once a complaint lands.

•     Use the platform's synthetic media reporting route, which in India now runs on statutory deadlines rather than goodwill.

•     If money changed hands, report it as fraud rather than as a content complaint. The remedies are stronger and faster.

•     Get legal advice before publicising it, since a public accusation can complicate the claim you might bring.

Consent is the pivot on which the entire question turns, as the scenario grid above showed. A signature on a one-line release will not carry the weight. Eight elements make a consent record defensible.

•     Identity. Full legal name of the person whose voice is being cloned, and confirmation they hold the rights to grant this.

•     Purpose. The specific use cases permitted, written narrowly enough that a new campaign requires a new conversation.

•     Media and channels. Where the output may appear, covering owned channels, paid placement, syndication and third-party distribution.

•     Territory. Which countries, which matters more now that EU and Indian duties attach to audience location.

•     Duration. A fixed end date. Perpetual grants invite challenge and price poorly for the person granting them.

•     Compensation. What is paid, on what basis, and whether usage beyond the agreed scope triggers additional payment.

•     Sublicensing. Whether the voice model may be passed to vendors, agencies, affiliates or acquirers, stated explicitly either way.

•     Revocation and deletion. How consent is withdrawn, and the commitment to delete the trained model rather than only the output files.

That last element is the one most templates miss. Deleting generated audio while keeping the voice model means the capability to impersonate someone survives their withdrawal of consent.

What lands next

Four dates are worth marking, because each changes what this article says.

•     A full Senate vote on the NO FAKES Act, which would replace the state patchwork described above with a single federal right.

•     2 December 2026, when the EU marking obligation reaches generative systems that were already on the market in August, and when new EU prohibitions on AI-generated child sexual abuse material and non-consensual intimate imagery start to apply.

•     Further rulings in Lehrman v Lovo, which will produce the first substantive US case law on training data consent for voice models.

•     The first enforcement actions under India's February 2026 rules, which will show whether three-hour takedown deadlines survive contact with real platform operations.

Until those land, the practical position holds: consent decides whether you may clone a voice, and disclosure decides whether you may publish the result without a label.

Discussion

Comments 0

Join the discussion and share your perspective.

Join the conversation

Sign in to post a comment and reply to other readers.

Sign in

No comments yet

Be the first to share your perspective on this article.

Related

More from the blog.

Is Voice Cloning Legal in 2026? What the Law Now Says

Is Voice Cloning Legal in 2026? What the Law Now Says

Is voice cloning legal in 2026? Learn the latest voice cloning laws in the US, EU and India, including consent, AI disclosure and legal risk...

Harish Kumar Aug 27, 2026
AI Agent vs Chatbot: What's Actually Different in 2026

AI Agent vs Chatbot: What's Actually Different in 2026

Chatbots answer questions. AI agents take action. Learn the seven key differences, real-world examples, risks, and when your business should...

Vaibhav Srivastava Aug 26, 2026
Nvidia in Talks to Back Perplexity at Over $30 Billion as Revenue Triples

Nvidia in Talks to Back Perplexity at Over $30 Billion as Revenue Triples

Nvidia is reportedly in talks to invest in Perplexity at a valuation above $30 billion as the AI search startup’s annualized revenue tops $7...

Swati Gupta Aug 24, 2026