LikeWard
Academy8 August 20266 min read

The Real Cost of Unlicensed AI Generation

Unlicensed AI generation of real people carries legal, payment and platform risk that compounds quietly. The full breakdown — and the alternative.

By LikeWard Compliance Desk
Legal paperwork spread across a desk, representing the exposure created by unlicensed AI generation of real people

Photo via Unsplash

The economics of unlicensed AI generation look excellent right up until they do not. No licensing costs, no creator negotiations, no supply constraints. The risk sits off the balance sheet, accumulates quietly, and then arrives all at once — usually as an email from an acquirer rather than a letter from a lawyer.

This is a full accounting of that exposure: legal, commercial, platform and reputational. It is written by people with an obvious interest in the licensed alternative, so the reasoning is shown rather than asserted, and the places where the risk is genuinely overstated are marked as such.

Key takeaways

  • Four risk families, and they correlate — one event usually triggers the others.
  • Payment processing loss is faster and more terminal than any legal claim.
  • "We are just a tool" is a defence to authorship, not to a removal duty.
  • The exposure is retroactive: content produced today is judged under tomorrow's rules.
  • You cannot manufacture consent records after the fact. That is the whole argument.

Contents

The four risk families

FamilyTriggerSpeedReversible?
LegalComplaint, claim, prosecutionSlow (months to years)Often, at cost
PaymentAcquirer review, chargeback spikeFast (days)Sometimes; the terminated merchant file is not
PlatformApp store or infrastructure policyFast (days)Sometimes, after remediation
ReputationalPress, creator statementImmediateRarely, fully

Table: the four families of exposure created by unlicensed generation, ordered by how quickly each arrives. Founders typically rank legal first; operators who have been through it rank payment first.

Three distinct routes, often conflated.

Criminal. Intimate imagery of an identifiable person without consent is now criminal in a growing set of jurisdictions, and the UK and several US states have extended their offences to synthetic depictions. The round-up of deepfake laws covers the landscape. This is the tail risk: low probability, catastrophic outcome, no insurance.

Regulatory. The Online Safety Act 2023 creates duties enforced by Ofcom with penalties up to £18m or 10% of qualifying worldwide revenue. The TAKE IT DOWN Act creates a 48-hour removal duty enforced by the FTC. Neither asks whether you generated the content. Both ask what you did about it.

Civil. Right of publicity claims for commercial use of a likeness, plus defamation and misappropriation theories. Brought by private parties, which means no prosecutorial discretion and no prioritisation — the constraint is simply whether someone is annoyed enough to file.

The compounding factor is retroactivity. Content produced in 2024 under 2024's rules is still online in 2026 and is judged under 2026's. A platform's historical output is a growing liability, not a settled one.

Payment and commercial exposure

This is the one that actually kills companies, and it is consistently underrated.

Card networks require documented consent from every identifiable person, verified age, pre-publication review and removal within a stated window for adult content merchants. Acquirers enforce that, and they enforce it on their own timetable.

The sequence is well worn: a chargeback spike or a press story triggers a review, the reviewer picks specific content and asks for consent records, the platform cannot produce them, and a remediation notice arrives with a deadline. Then a rolling reserve. Then termination and a listing on the terminated merchant file, which makes finding a replacement acquirer materially harder for years.

Nothing in that sequence requires anyone to have broken a law. It only requires being unable to demonstrate a control. We walked through the review itself in the card network consent rules guide.

Platform and distribution exposure

App stores, cloud providers, model API vendors, ad networks and domain registrars all have policies here, and all of them move faster than courts.

Model providers are the underrated one. If your generation depends on an upstream API and that provider's terms prohibit unlicensed likeness use, your product's core dependency is a policy decision you do not control. Platforms have woken up one morning to find their model access revoked, with no notice period and no appeal that resolves within a business quarter.

Reputational and talent exposure

Harder to quantify, and it has a specific characteristic: it is asymmetric. A creator publicly stating that a platform generated imagery of them without consent does damage that a correction cannot undo, because the correction reaches a fraction of the original audience.

There is also a supply consequence. Once a platform has that reputation, the creators most worth licensing will not work with it, which means the licensed route closes at the exact moment it would have been most useful.

Why the risks correlate

The critical structural point: these are not four independent bets.

One trigger event — a press story, a creator's complaint, a viral post — sets off a review, which prompts the acquirer, which draws regulatory attention, which the press then covers. A platform running unlicensed does not face four separate small probabilities. It faces one correlated event with four consequences.

"Every operator we have talked to who went through this describes the same thing: it was quiet for two years and then everything happened in the same fortnight. Correlated risk does not feel like risk until it resolves." — LikeWard compliance desk

Where the risk is overstated

In fairness, three things get exaggerated:

Not all generation of real people is unlawful. Satire, commentary, journalism and clearly transformative work have real protection in several jurisdictions. The category is not uniformly illegal, and pretending otherwise damages the credibility of the argument.

Enforcement capacity is finite. Regulators prioritise. A small platform is unlikely to be first in a queue. This is a genuine mitigation — it is just not a strategy, because acquirers and private litigants do not have the same capacity constraint.

The grey area is real. Plenty of use sits in genuine ambiguity today. The problem is that it is narrowing, and narrowing retroactively for content that stays online.

What the licensed route actually costs

Honestly: a revenue share, a smaller catalogue, and more refused requests.

The catalogue point is the real one. Licensed supply is constrained by how many creators have onboarded, and a licensed marketplace with few creators is genuinely less useful than an unlicensed tool with none of those limits. Anyone claiming otherwise is selling.

What you get for it is the ability to answer the question every one of the four risk families eventually asks: was this permitted, by whom, under what rules, and is that permission still in force? On LikeWard that answer is a lookup — a versioned boundary set plus a signed manifest per output, described in content provenance explained.

The asymmetry is what settles it. You can add controls tomorrow. You cannot add consent records to content that already exists.


Further reading: the licensed alternative to AI companion apps, the deepfake law round-up, and how to license your likeness if you are on the other side of this. LikeWard's position is set out on the compliance page.

Frequently asked questions

Is unlicensed AI generation of a real person actually illegal?
It depends on what is generated and where, which is precisely what makes it a poor risk to run. Intimate imagery of an identifiable person without consent is now criminal in a growing number of jurisdictions. Commercial use of someone's likeness without permission triggers publicity rights in many US states. Plenty of other output sits in a genuinely grey area — but the grey area is narrowing every year and it narrows retroactively for content that stays online.
We are just a tool. Is the liability not on our users?
That framing worked better five years ago than it does now. Modern duties attach to the service — did you take reasonable steps to prevent it, did you act swiftly once notified, can you evidence both — rather than turning on who pressed the button. Being a neutral tool is a defence to authorship, not to a removal duty.
What is the single biggest practical risk?
Losing payment processing. Legal claims are slow, arguable and often insurable; an acquirer withdrawing is fast, unilateral and leaves you with no way to take money while you sort it out. Founders consistently rank the legal risk first and then discover the ordering is the other way around.
Does adding a disclaimer help?
Marginally, for transparency obligations. It does nothing for consent, removal duties or publicity rights, because none of those are satisfied by telling the viewer what they are looking at. A disclaimer describes the content; the duties are about permission and responsiveness.
Can we fix this retroactively?
Partially, and it is expensive. You can add controls going forward, build a removal pipeline and start recording authorisation from today. What you cannot do is manufacture consent records for content already produced, which means an acquirer review touching historical output remains a real problem. That asymmetry is the argument for building the record before you need it.