The identity layer. Why AI law is moving beyond copyright.
The NO FAKES Act does not merely target fake celebrity songs. It signals a structural transformation in how law treats digital personhood, and the infrastructure to enforce it has not yet been built.
Loading...
Verify on BlockchainThe NO FAKES Act is not just about stopping fake celebrity songs. It signals a larger shift.
https://www.judiciary.senate.gov/committee-activity/hearings/executive-business-meeting-06-18-2026
AI law is moving beyond copyright to address identity, consent, and provenance. Tennessee helped start that shift with the ELVIS Act, which treated voice protection as part of the modern rights framework for artists and performers. Washington is now following suit with its own deepfake and digital likeness protections.
The NO FAKES Act brings the same question to the federal level.
Who controls your identity when AI can replicate it?
That question applies to musicians, actors, athletes, authors, public figures, and ordinary citizens. A song can be copied. A voice can be cloned. A face can be simulated. A performance can be reconstructed. A person's identity can be turned into someone else's product without permission.
That creates a new enforcement problem. It is no longer enough to ask who owns the recording. We also need to ask who authorized the use of the voice and likeness, where the consent record is, whether the platform can verify it, and whether the creator can contest a false takedown.
This is where the next rights infrastructure will be built. Not in slogans. In verifiable records, timestamped claims, consent ledgers, takedown evidence, counter-notice procedures, and audit trails.
The $750,000 headline gets attention. The real story is simpler.
AI has made identity machine-replicable.
Now, identity rights must become machine-verifiable.
Copyright protects the work. Identity rights protect the person.
Copyright law was designed for a world where reproduction required effort. Pressing vinyl, printing books, and distributing film all required physical infrastructure. The rights framework reflected that reality: register the work, own the copy, and pursue infringement through a documented chain of title.
Generative AI breaks that model entirely. It does not reproduce a work. It learns the patterns of a person's voice, face, or style and generates new outputs that were never recorded, never registered, and never consented to. The infringing artifact did not exist before the model produced it. Traditional copyright struggles to address this because the harm is not to a specific work.
The harm is to the identity itself.
The ELVIS Act recognized this distinction in Tennessee. Washington's legislation followed suit. The NO FAKES Act codifies it at the federal level. These laws do not merely extend copyright. They create a new category of right: the right to control the digital replication of your identity.
This is a fundamental expansion.
* Copyright protects expression.
* Identity rights protect existence.
The infrastructure gap nobody talks about
Legislation without an enforcement architecture is a statement of intent, not a solution. Copyright law works because the United States Copyright Office maintains a public registry. You can search it. You can trace the chain of title. You can verify ownership before licensing or distributing a work.
The NO FAKES Act creates a federal right in a person's voice and visual likeness, but provides no government database to check against. There is no registry of authorized vocal likenesses.
No public ledger of consent records.
No searchable index of who controls which digital identity.
This is the infrastructure gap.
It is the single largest structural flaw in the emerging identity rights framework.
Platforms like YouTube and Spotify will be required to verify identity under penalty of up to $750,000 per infringing work. They will have nowhere to verify it against. The government created the obligation but not the means to enforce it.
Private sector infrastructure must fill this void. The solution requires verifiable records, timestamped claims, and audit trails that courts and AI agents can independently check. That infrastructure is being built now.
What machine-verifiable identity looks like
The enforcement layer for identity rights requires three components.
- First, a high-speed query system. Platforms processing millions of uploads per day need to check identity status in milliseconds. This requires a permissioned database optimized for throughput that maintains records of artists, works, consent status, and authorization.
- Second, an immutable anchor. Internal databases are inherently untrustworthy because their operators can modify them. The solution is a cryptographic commitment to a public blockchain. For instance, by hashing every record into a Merkle tree and embedding the root commitment in a confirmed Bitcoin block header, the system creates an unalterable proof that a specific record existed at a specific time. Open timestamping protocols make this cost-effective and independently verifiable. Any auditor, any court, or any AI agent can verify the proof on a public blockchain explorer without trusting the database operator.
- Third, a pre-synthetic baseline. The most defensible proof of human origin is data that existed before generative AI could produce it. An audio archive frozen in early 2022, before the widespread availability of generative audio tools, provides exactly this. Any recording in that archive is immune to AI generation by construction. It establishes an irrefutable historical baseline.
Together, these three layers convert identity claims from heuristic approximations into mathematical certainties.
The deepfake tax is already being collected.
The economic pressure driving this shift is measurable. Deepfake-specific fraud crossed the billion-dollar threshold in 2025. Annual losses are projected to reach $40 billion by 2027.
The $735 billion advertising industry is reacting decisively. Cost-per-mille rates for broad-reach display advertising on the open web have collapsed by 48 percent as advertisers flee bot-poisoned environments. Platforms that offer a human signal are thriving. Advertisers pay a premium for verified human audiences.
This is the deepfake tax.
Every platform that cannot mathematically prove its users are real pays for it. Every platform that can charge a premium for the proof.
The same dynamic will govern the enforcement of identity rights. Platforms that can demonstrate verifiable consent and provenance will navigate the regulatory environment with confidence.
Those who cannot will face escalating statutory exposure.
The next rights infrastructure
The trajectory is clear. AI has made identity replicable at scale. The law is responding by making identity a protected right. Enforcement will demand that identity claims be verifiable at machine speed.
The organizations building this infrastructure today are constructing the rails of the agentic economy. Verifiable records, timestamped commitments, consent ledgers, and audit trails are not optional features. They are the minimum viable architecture for any platform that hosts, distributes, or monetizes human identity.
The $750,000 penalty is the warning shot. The real story is that identity must become as verifiable as it has become replicable.