A Turkish game studio wants its beloved dubbing actor’s voice for a new character, but the actor retired, so the studio trains a voice model on old recordings instead. A marketing agency “features” a celebrity in an ad the celebrity never saw. A fintech’s onboarding call is opened by a cloned executive voice. All three are the same legal problem wearing different clothes: who owns a voice, and what does consent to yesterday’s recording say about tomorrow’s synthesis?
The Turkish stack: three protective layers
Personality rights (Civil Code Arts. 24–25) protect voice and likeness as attributes of the person: unauthorised commercial cloning is an infringement independent of any copyright question, remediable by injunction and damages. Data protection: a voiceprint used to identify a person is biometric data; a special category under KVKK requiring an explicit legal basis, and the KVKK Board’s biometrics line of decisions shows how narrowly “necessity” is read. Copyright (FSEK): the underlying recordings carry performer and producer rights, so training a model on old sessions engages neighbouring rights even where the voice itself is not a “work.” A licence to use a recording in a 2015 commercial is not a licence to synthesise new speech in 2026; purpose limitation cuts across all three layers.
The incoming labelling regime
Two regimes are converging on synthetic voice. The AI Act’s Article 50 (live since 2 August 2026) requires machine-readable marking of AI-generated audio and disclosure of deepfakes. On the Turkish side, the pending TCK amendment bill would require visible “AI-generated” labels on synthetic content with a six-hour takedown for infringing material and platform obligations enforced through BTK. Build voice features with labelling and revocation in the pipeline now; retrofitting provenance into shipped audio is close to impossible.
The contract that makes it lawful
If you commission or use voice cloning, paper it like a rights deal, not a service order: explicit consent naming synthesis as the use; scope by product, term and territory; a revocation mechanism and its consequences; compensation tied to usage; and a warranty chain covering the training recordings’ performer and producer rights. On the vendor side, ask where consent records live and what happens to the model when the licence ends.
Three layers, three remedies
| Layer | Source | What triggers it | Remedy profile |
|---|---|---|---|
| Personality rights | Civil Code Arts. 24–25 | Unauthorised commercial use of voice/likeness | Injunction, material and moral damages, disgorgement |
| Data protection | KVKK (special categories) | Voiceprint used to identify a person | Board fines, processing bans, deletion orders |
| Neighbouring rights | FSEK (performers/producers) | Training or synthesis from protected recordings | Infringement damages up to three-fold, seizure |
The consent clause, sketched
A synthesis consent worth the paper covers seven points: (1) named technology; “training of a voice model and generation of new speech,” not “use of recordings”; (2) scope, which products, which languages, which markets; (3) term and what happens to the model (not just the outputs) at expiry; deletion or escrow; (4) approval rights over sensitive contexts (politics, health, endorsement); (5) compensation structure; flat fee, per-use, or revenue share; (6) revocation mechanics and a wind-down period for shipped content; (7) warranty from whoever supplies the recordings that performer and producer rights are cleared. Put the same seven points, mirrored, into your vendor contract if a platform hosts the cloning for you; the gap between the two documents is where liability pools.
Is a sound-alike (human imitator) safer than a clone?
Not automatically; passing off a voice to suggest endorsement can still infringe personality rights and unfair-competition rules; the technology is not the test, the deception is.
Can we train on our own employees’ voices?
Only with genuinely free, specific consent; employment context makes consent fragile under both KVKK and GDPR, so pay for it separately and allow refusal without consequence.
This week’s homework
If any product feature speaks with a human-derived voice, locate the consent artefact that covers synthesis specifically. If it does not exist, stop expanding that feature until it does; this is the cheapest moment you will ever fix it.
Related: prohibited practices · AI Compliance Hub.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call