Compliance

Voice AI and Voice Cloning: Consent and Disclosure Rules

Cloning a voice for an enterprise AI line raises consent and disclosure duties a stock synthetic voice does not. Dilr Voice treats it as a governed decision: whose permission you hold under UK performers' and data protection law, and how you disclose a synthetic voice to callers under the EU AI Act Article 50.

DILR.AI ENGINEERING Voice cloning: consent and disclosure Whose permission you hold, and what you tell the caller CONSENT TO CLONE DUTY TO DISCLOSE EVIDENCE THE DECISION

A cloned brand voice is one of the first things an enterprise asks for once a voice AI line goes into production. Marketing wants the agent to sound like the founder, or a recognisable brand voice, or a named presenter the audience already trusts. It is a reasonable request, and the technology makes it almost trivial: a few minutes of clean audio is enough to build a convincing synthetic replica. The legal and reputational questions it opens are anything but trivial, and most of them are settled before a single line goes live, not after.

Adoption is broad but shallow. McKinsey's State of AI (November 2025) found that around 88% of organisations now use AI somewhere, yet only about 6% capture material earnings impact, and Stanford's AI Index 2026 reports fewer than 10% have fully scaled it in any function. Voice is where that gap gets personal, because a synthetic voice is not an abstract model output. It is a specific human sound, often a real person's, and the moment you reproduce it you inherit that person's rights and the caller's reasonable expectation of honesty about who, or what, they are speaking to.

This guide separates the two questions that get tangled together: whose consent you need to create a cloned or synthetic voice, and what you must disclose to the caller who hears it. The first is largely a UK question of performers', copyright and data protection law. The second is largely an EU AI Act transparency question with a UK fairness overlay. Getting one right does not excuse the other.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.

What does voice cloning mean for an enterprise AI line?

Voice cloning means building a synthetic voice that reproduces the identifiable sound of a specific person, usually from recordings of that person speaking. For an enterprise voice AI line it is distinct from picking a generic, fully synthetic voice from a text-to-speech catalogue, which imitates nobody. It is also distinct from capturing a caller's voiceprint to identify them. Cloning is about the voice your agent speaks with, not the voice it listens to.

That distinction runs through everything that follows. Capturing and matching a caller's voiceprint for authentication is a security and biometric question, covered in our guide to voice biometric data security. Cloning is the opposite direction of travel: you are generating output that sounds like a named human, so the rights you have to worry about belong to the person whose voice you copied, not the person on the phone. A stock synthetic voice sidesteps almost all of it, which is often the quiet right answer.

If the voice belongs to a living, identifiable person, you need that person's permission, and in the UK that permission is assembled from several sources rather than one statute. Performers have rights over recordings of their performances under the Copyright, Designs and Patents Act 1988, the recordings usually carry copyright, and a real person's voice is also their personal data. A signed release covering synthetic reproduction is the instrument that ties those threads together.

The performers'-rights thread is the one most cloning projects overlook, because they assume owning the audio file is enough. It is not. The Act is explicit that copying a recording of a performance needs the performer's consent:

"A performer's rights are infringed by a person who, without his consent, makes a copy of a recording of the whole or any substantial part of a qualifying performance."

Copyright, Designs and Patents Act 1988, section 182A

Whether training a model on those recordings, and generating new speech from it, is itself a "copy" is exactly the boundary the 1988 Act was never written to answer, and it is one reason the government is now looking at reform. What is not in doubt is that reproducing a named person's voice without a clear, documented permission trail leaves you exposed on several fronts at once. The safe operating posture is to treat consent as a written, purpose-specific licence: this person, this use, this duration, this right to withdraw, recorded before the clone is built. Where the source voice belongs to an employee or a founder, the same discipline applies; seniority is not consent.

The table below maps the patchwork so you can see what each instrument does and does not cover. It is why "we have the recordings" is never a complete answer.

Legal routeWhat it protectsWhat it does not settle
Performers' rights (CDPA 1988)Consent to copy recordings of a performanceWhether model training on recordings is a "copy"
Copyright in the recordingReproduction of the sound recording itselfRights of the performer heard on it
Data protection (UK GDPR)The voice as a living person's personal dataA standalone right in your identity or likeness
Passing offMisleading trade use of someone's identityA general image or personality right (none exists yet)
Fraud and defamationImpersonation and false statementsConsented, honestly-disclosed use

For the data protection basis specifically, the source person's voice recordings are their personal data, so you need a lawful basis under UK GDPR Article 6 to process them, most often legitimate interests with a documented balancing test, and a purpose-limitation position if you also want to train on them, which we cover in our note on call recordings and model training. Consent under data protection law and consent under performers' law are not the same consent, and one does not stand in for the other.

Is a cloned voice special category data?

Usually not. Voice is only special category biometric data under UK GDPR when it is processed for the purpose of uniquely identifying someone, which is what a voiceprint authentication system does. Cloning a brand voice to speak on your AI line does not identify anyone; it generates output. The demanding Article 9 conditions that govern a voiceprint therefore do not automatically attach to a clone, and the source person's recordings remain ordinary personal data under Article 6.

Treating a clone as special category data by reflex is not just belt-and-braces caution; it can send a programme down the wrong compliance path and bury the real obligations. The genuine special category question sits with caller identification and voiceprints, which we handle in the voiceprint and biometric data guide and the wider treatment of special category data on calls. For a clone, the honest analysis is narrower and more manageable: an Article 6 basis for using the person's recordings, a documented licence for the performers' and copyright rights, and a disclosure plan for the caller. Getting that framing right at the AI placement diagnostic stage saves a lot of rework later.

Must you tell callers the voice is AI or synthetic?

Yes, for most enterprise deployments. Under the EU AI Act, the Article 50 transparency obligations began to apply on 2 August 2026 and reach any line people in the EU can call. Article 50(1) requires callers be told they are interacting with an AI system; Article 50(2) requires synthetic audio to be marked as artificially generated in machine-readable form, with a grace period to 2 December 2026 for systems already on the market. A cloned voice removes neither duty.

Those are two separate transparency duties under the EU AI Act, and a synthetic or cloned voice engages both. The general "you are speaking to an AI" disclosure at the top of a call is the Article 50(1) duty, covered in depth in our Article 50 disclosure guide; the marking of the audio as machine-generated is the Article 50(2) duty; and where a voice is a realistic replica of a real, named person, the deepfake disclosure logic of Article 50(4) becomes relevant too. Whether a given duty is technically yours or your platform vendor's turns on whether you are the provider or the deployer under the Act: the Article 50(1) and 50(2) duties fall on providers, while the Article 50(4) deepfake duty falls on deployers. The caller-facing outcome is what a regulator and your customers will judge, so agree in the contract who does what. In the UK, there is no direct equivalent to Article 50, but the ICO's fairness and transparency expectations, reflected in its forthcoming AI code of practice, point the same way: callers should not be misled about whether they are hearing a machine. The decision flow below shows where each check falls.

The voice cloning consent and disclosure decision
01Whose voice is it?Real person or fully synthetic02Get consent to cloneLicence, performers' rights, Article 603Set the disclosureAI Act Article 50(1) and 50(2)04Mark the audioMachine-readable, synthetic output05Log the authorisationPerson, use, duration, withdrawal
Each step is a documented decision recorded before the synthetic voice goes live.

What are the risks of cloning a voice without permission?

The exposure is cumulative rather than confined to one law, which is what makes unpermissioned cloning a poor bet. A cloned voice used without a clear licence can infringe performers' rights and copyright, breach data protection if the recordings were processed without a basis, and support a passing-off claim where it misleads people in trade. If it puts words in someone's mouth, defamation and fraud come into view. A claimant assembles a case from several of these at once.

The government has acknowledged this gap directly. In its Report on Copyright and Artificial Intelligence, published on 18 March 2026, it said it would explore options for addressing the harms of realistic AI impersonation, including whether to introduce a new "digital replica or personality right". Until any such right exists, the patchwork is what you have, and the reputational risk often outruns the legal one: a brand caught using a real person's cloned voice without consent loses trust faster than any tribunal moves. Building the governance now, through an AI operating model that records every voice authorisation, is cheaper than defending its absence. This is the same discipline our execution office applies to any high-exposure AI decision.

What is the best way to use a cloned or synthetic voice in 2026?

The best approach in 2026 is to match the voice to the exposure, not to default to a clone because the tooling allows it. For most enterprise lines, a fully synthetic stock voice with a clear AI disclosure carries the least risk and is sufficient. Reserve a cloned real-person voice for cases where the brand value justifies the consent, licensing and disclosure overhead, and only with a documented trail. The right tool depends on which situation you are in.

For a fully synthetic voice, self-serve platforms such as ElevenLabs make high-quality cloning and stock voices easy to produce, and for low-stakes, clearly-disclosed use with no real-person basis they are often all you need. Where the voice is a real person, or the deployment is regulated, the decision shifts to governance: can the platform record and enforce the licence terms, mark output as synthetic, and evidence the disclosure to an auditor? That is the ground a governed platform such as Dilr Voice is built for, and where our DATS methodology places the controls before deployment. The concession is real: a small business using a plainly synthetic voice, disclosed at call open, with no cloned human behind it, needs none of this apparatus and should not buy it.

How should you document a voice cloning decision?

Treat the authorisation as an evidence pack, not a checkbox. For any cloned real-person voice, keep the signed licence naming the person, the permitted uses, the duration and the withdrawal terms; the data protection basis for their recordings; the record of what callers are told and how the audio is marked; and the date each was decided. If a regulator, a performer or the person asks later, the answer should be a file, not a memory.

Our DATS five-stage methodology treats this as a standard control, and it maps cleanly onto the record-keeping our compliance guides describe for the wider voice programme.

Can you clone a deceased person's voice?

The analysis changes but does not disappear. UK data protection law does not apply to the deceased, so the Article 6 thread falls away, but copyright and performers' rights run for a fixed term from the performance or release, not from death, so a licence may still be needed depending on the recording's age. Family and reputational sensitivities are acute. Cloning a deceased person's voice for an enterprise line is rarely worth the exposure without the rights holder's written agreement.

Does a standard voice actor contract cover AI cloning?

Usually not. Most legacy voice-over contracts license a specific recording for a specific use; they predate synthetic reproduction and say nothing about training a model or generating new speech in that voice. Relying on an old contract to justify a clone is a common consent gap. To clone a voice actor's voice, the licence has to name synthetic reproduction expressly, and a contract silent on the point should be treated as not granting it.

Do you have to disclose a synthetic voice in the UK if the EU AI Act does not apply?

There is no single UK statute mirroring Article 50, but that does not make silence safe. The ICO's fairness and transparency principles, advertising rules on misleading practices, and general consumer protection all point towards telling people when they are hearing a machine, especially a cloned human voice. Treating EU-facing and UK-facing lines to the same disclosure standard is simpler to operate and lowers the reputational risk of appearing to hide the synthetic nature of the voice from your callers.

Want to get this right before you build? Try Dilr Voice live, book an AI placement diagnostic, see our DATS methodology, or read about our approach to placing AI inside regulated systems.

Guide
EU AI Act Article 50 disclosure
Guide
Voiceprint and biometric data
Product
Dilr Voice
Talk to the operators

Clone with consent, disclose with confidence.

30-min scoping call · No deck · Confidential. We will map the consent trail and the caller disclosure before you build the voice.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI voice cloning consent disclosure enterprisesynthetic voice consent UKAI voice cloning disclosure EU AI Actai voice cloning redditbest ai voice cloning platform 2026voice AI complianceDilr Voice

Questions this article answers

What does voice cloning mean for an enterprise AI line?

Voice cloning means building a synthetic voice that reproduces the identifiable sound of a specific person, usually from recordings of that person speaking. For an enterprise voice AI line it is distinct from picking a generic, fully synthetic voice from a text-to-speech catalogue, which imitates nobody. It is also distinct from capturing a caller's voiceprint to identify them. Cloning is about the voice your agent speaks with, not the voice it listens to.

Whose consent do you need to clone a voice?

If the voice belongs to a living, identifiable person, you need that person's permission, and in the UK that permission is assembled from several sources rather than one statute. Performers have rights over recordings of their performances under the Copyright, Designs and Patents Act 1988, the recordings usually carry copyright, and a real person's voice is also their personal data. A signed release covering synthetic reproduction is the instrument that ties those threads together.

Is a cloned voice special category data?

Usually not. Voice is only special category biometric data under UK GDPR when it is processed for the purpose of uniquely identifying someone, which is what a voiceprint authentication system does. Cloning a brand voice to speak on your AI line does not identify anyone; it generates output. The demanding Article 9 conditions that govern a voiceprint therefore do not automatically attach to a clone, and the source person's recordings remain ordinary personal data under Article 6.

Must you tell callers the voice is AI or synthetic?

Yes, for most enterprise deployments. Under the EU AI Act, the Article 50 transparency obligations began to apply on 2 August 2026 and reach any line people in the EU can call. Article 50(1) requires callers be told they are interacting with an AI system; Article 50(2) requires synthetic audio to be marked as artificially generated in machine-readable form, with a grace period to 2 December 2026 for systems already on the market. A cloned voice removes neither duty.

What are the risks of cloning a voice without permission?

The exposure is cumulative rather than confined to one law, which is what makes unpermissioned cloning a poor bet. A cloned voice used without a clear licence can infringe performers' rights and copyright, breach data protection if the recordings were processed without a basis, and support a passing-off claim where it misleads people in trade. If it puts words in someone's mouth, defamation and fraud come into view. A claimant assembles a case from several of these at once.

What is the best way to use a cloned or synthetic voice in 2026?

The best approach in 2026 is to match the voice to the exposure, not to default to a clone because the tooling allows it. For most enterprise lines, a fully synthetic stock voice with a clear AI disclosure carries the least risk and is sufficient. Reserve a cloned real-person voice for cases where the brand value justifies the consent, licensing and disclosure overhead, and only with a documented trail. The right tool depends on which situation you are in.

How should you document a voice cloning decision?

Treat the authorisation as an evidence pack, not a checkbox. For any cloned real-person voice, keep the signed licence naming the person, the permitted uses, the duration and the withdrawal terms; the data protection basis for their recordings; the record of what callers are told and how the audio is marked; and the date each was decided. If a regulator, a performer or the person asks later, the answer should be a file, not a memory.

Can you clone a deceased person's voice?

The analysis changes but does not disappear. UK data protection law does not apply to the deceased, so the Article 6 thread falls away, but copyright and performers' rights run for a fixed term from the performance or release, not from death, so a licence may still be needed depending on the recording's age. Family and reputational sensitivities are acute. Cloning a deceased person's voice for an enterprise line is rarely worth the exposure without the rights holder's written agreement.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
AI Voice for Hair Salons and Barbers: Booking Guide

One email, once a month. No hype. Just what we learned shipping.