Voices, faces, and trade secrets
Lesson 5 of 5 in AI and Intellectual Property: Training Data, Outputs, and the Litigation Wave.
Copyright protects works. It does nothing for the thing generative AI clones most convincingly: a person — their voice, face, and persona. That protection comes from the right of publicity, a patchwork of US state laws with a case-law spine built long before AI: Midler v. Ford (9th Cir. 1988) — hiring a sound-alike to imitate Bette Midler’s voice in an ad was actionable; White v. Samsung (1992) — even a robot evoking Vanna White crossed the line.
Voice-cloning AI turned that quaint doctrine urgent, and Tennessee moved first. The ELVIS Act (Ensuring Likeness, Voice, and Image Security Act, signed March 2024, effective July 2024) rebuilt the state’s publicity statute for the AI era: it added voice — including simulations of a voice — as an explicitly protected property right, extended liability beyond advertising to any unauthorised commercial use, and, most consequentially, created liability for distributing tools whose primary purpose is producing unauthorised replicas of someone’s voice or likeness. Music-industry-backed and aimed straight at voice-clone apps, it became the template other states studied.
California layered on in September 2024: AB 2602 voids contract terms that let studios use a performer’s digital replica without specific consent and professional representation, and AB 1836 requires estate consent for digital replicas of deceased performers. At the federal level, the NO FAKES Act — a bipartisan bill to create a national digital-replica right with platform takedown duties — has been repeatedly introduced but, as of this writing, not enacted; the US Copyright Office’s 2024 digital-replicas report endorsed exactly such a federal right. Check its current status: this is the likeliest next federal IP statute.
Now the quietest IP regime in the stack — and for AI companies, arguably the most valuable one. Trade secrecy protects information that derives value from not being generally known and that its holder reasonably guards (US Defend Trade Secrets Act 2016; EU Trade Secrets Directive 2016). No registration, no term limit, no novelty requirement — which is why model weights, architectures, training-data recipes, RLHF pipelines, evaluation suites, and system prompts are guarded as trade secrets rather than patented or published.
The strategic collision is with everything else you have studied on this site: transparency mandates keep demanding disclosure of exactly what secrecy protects. The EU AI Act wants Annex IV technical documentation, Article 53’s public training-content summary, and deep documentation for systemic-risk models. GDPR access rights want "meaningful information about the logic" — and the CJEU’s Dun & Bradstreet Austria ruling (2025) held trade secrets cannot ground a blanket refusal: contested material goes to the court or authority, which balances. Litigation discovery pries further — the NYT case produced orders around model inspection and output logs under protective orders. And frontier-safety laws like California’s SB 53 compel publication of safety frameworks companies once called proprietary.
The professional skill is knowing the resolution pattern, because the law rarely picks one side outright: disclosure flows to regulators and courts under confidentiality, while the public gets summaries, model cards, and redacted templates. The EU AI Act says so expressly — Article 78 binds authorities to protect confidential information they receive. When a client says "we can’t disclose, it’s a trade secret", the correct answer is usually: you can’t refuse — you can channel.
Interactive sorting exercise: For each artifact, decide which force wins by default: trade-secret protection, or a disclosure mandate.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.