The assumption that causes the problem
Because generation feels like production rather than casting, the rights questions that would be obvious with a human on set get skipped. Nobody would film a person without a release; the equivalent step for synthetic talent is routinely missed because there is no moment that prompts it.
Real likeness
Generating a recognisable likeness of a real, identifiable person requires that person's documented written consent for the specific use. Not for AI generally, and not for a previous campaign — for this use.
This includes the awkward internal cases: a founder, an employee, a customer. Being enthusiastic in a meeting is not a release, and the person who agreed may not be there when the campaign is still running.
Voice
Voice is treated as a distinct right and needs its own consent. Cloning a voice from existing recordings without permission is not made acceptable by the recordings having been public.
Scope matters here too: consent for one campaign is not consent for a library the voice can be pulled from indefinitely. Say what it covers and for how long.
Fully synthetic people
A presenter who depicts no real individual avoids the likeness problem and still requires disclosure — and under EU rules, content that looks or sounds like a real person can require labelling even where no specific person is depicted.
It also inherits the claim boundary: a synthetic person must not deliver first-person experience claims, because there is no person who had the experience.
The record
Every campaign should leave behind a provenance record: source assets and their licensing basis, tools used, consents obtained with scope and duration, disclosure text supplied, and approvals.
The purpose is to be able to answer a question in eighteen months, when the campaign is still running, the freelancer has moved on, and someone asks where a particular asset came from. Assembling that after the fact is expensive; capturing it during production costs almost nothing.