The Machine's Limited Mandate
Mina Aksoy is a regional training manager at an international health-technology company. She designs training programmes for new employees, presents to product teams, reviews customer-facing instructional videos and aligns training standards across teams in different countries. Mina is comfortable on camera and has delivered much of the company's internal training for years. As the company grows, however, repeatedly recording the same training becomes difficult. One week she prepares a Turkish course; the next, an English one. Then comes the review of German subtitles.
A product update means that every video must be recorded again. The company's AI team proposes a solution: “Let's create a training avatar using your face and voice. That way, we can publish scripts you've approved in different languages without asking you to return to the camera.” At the first meeting, the intended use appears clear:
- Internal employee training
- Scripts Mina has approved in advance
- Turkish and English
- Only the organisation's closed training platform
Mina finds the idea useful and takes part in a two-day recording session. She repeats different sentences slowly and quickly, sounding cheerful, serious, cautionary and calm. Her facial movements are recorded. Samples capture the higher and lower pitches of her voice. She pronounces certain medical and technical terms in several ways. At the end of the session, she is shown a digital form headed “Consent to AI-Assisted Corporate Media Use”. It says: “The employee agrees that image and voice recordings may be processed, reproduced and used for corporate training, communications, promotion, service improvement and the development of related AI systems.”
Mina reads the text. “Corporate training” is the use discussed at the outset. “Communications” is broad. It is unclear what “promotion” includes. “Service improvement” is broader still. “Development of related AI systems” does not say whether it covers only the technical quality of Mina's avatar, other company avatars or the provider's general model. The form offers two choices: [I Agree] [Decide Later]. There is no option to refuse. Employees who choose to decide later are told that they cannot take part in the avatar programme.
One of Mina's annual objectives is “Contribute to the global training transformation project”. She does not know how this objective will be assessed if she refuses the form. The technical team has set aside two days for recording. Her manager has presented the project to senior management. The provider's team has travelled from another country. Everyone expects Mina to agree. She asks: “It will only be used for internal training, won't it?” The project manager replies: “That is the plan for now. If other useful applications emerge in the future, we'll assess them separately.”
Mina presses [I Agree]. The system creates this record:
consent_status: active
media_use: approved
AI_use: approved
corporate_use: approvedThese four fields appear sufficient to the technical team. But they provide no separate answer to any of these questions:
- Use of the face, or use of the voice?
- Processing raw recordings, or training a model?
- Producing content, or publishing it to the public?
- Which scripts?
- Which languages?
- Which channels?
- Which countries?
- For how long?
- Which companies?
- Which providers?
- What happens when the employment relationship ends?
- What happens to the model already created if Mina withdraws consent?
- For how long may previously published videos remain in use?
- Must Mina approve each new script separately?
For the first three months, the system is used as originally described. Mina reads scripts in advance, sees videos before release, corrects mispronunciations and permits publication only on the company's internal training platform. Employees know the videos were generated with an AI avatar. The system works: a training update can be prepared in two days rather than several weeks. Then the company expands into new countries. The localisation team says it can make Mina's avatar speak German, Spanish, Arabic and French. Mina speaks none of those languages.
The technical team explains why this presents no problem: “The voice model will preserve the characteristics of your voice. A local-language model will generate the words.” No fresh consent is obtained because the system already contains these fields:
AI_use: approved
corporate_use: approvedThe original use is internal. The marketing team then sees how effective the videos are. One is placed in the company's public help centre, on the ground that “helping customers use the product correctly is also training”. The same video is later shared on social media. The justification expands again: “Publication on social media does not alter the educational nature of the content.” Next, Mina's avatar appears in a promotional video for a new product. A content agent wrote the script.
Mina has not seen it. The avatar says: “Our new platform enables healthcare organisations to automate AI-assisted decision processes safely.” Mina has never considered whether she agrees with that claim. Saying that the company's product safely automates all decision processes is quite different from delivering a technical training sentence. It may amount to a commercial claim and public statement, place her professional reputation behind the message and make a safety assurance in a regulated sector. But the system has no field for:
content_specific_human_approvalAll the system knows is:
corporate_use: approvedThe video is published in six languages. An Arabic-speaking colleague messages Mina: “Your Arabic promotional video is excellent.” Mina does not know which video she means. She opens the link and sees her own face. She hears a voice like her own making a safety assurance to healthcare organisations in a language she does not understand. Mina contacts human resources: “I didn't authorise this video.” HR checks the records. The system says:
consent_status: activeMina says: “I gave permission for internal training.” The legal team shows her the form she signed: “It includes corporate training, communications, promotion and service improvement.” Mina replies: “But no one told me that meant public advertising in six languages.” The company agrees to remove the video. The marketing team nevertheless argues that it retains the right to use all videos already created. The provider contract contains this clause: “Unless otherwise agreed, the organisation may use media outputs created during a period of valid authority indefinitely.”
Mina is not a party to that contract. She has never seen the clause. A month later, she decides to leave the company. In her exit interview, she states clearly that she withdraws consent for every use of her face and voice models. The status changes in the company panel:
consent_status: revokedHR emails Mina: “Your request to withdraw consent has been recorded in the system.” Mina believes the matter is closed. But the other system states are:
new_recording: prohibited
new_model_training: prohibited
existing_model: active
existing_outputs: active
scheduled_publications: active
affiliate_access: active
vendor_backup: retainedThe consent record has changed. The overall behaviour has not. Two weeks later, a product video that was scheduled earlier is published, and Mina's avatar speaks again. She challenges the company. The technical team explains: “The video was created before you withdrew consent. Withdrawal affects only new production.” Mina asks: “Why wasn't I told that when I withdrew consent?” The company cannot answer. Another problem emerges. The avatar provider says the voice model built from Mina's recordings is not a separate file: it is held within a larger model trained on data from many speakers.
The provider explains: “The raw recordings can be deleted. But we cannot technically guarantee that one person's influence can be isolated completely from the model parameters.” Mina did not know this before the recording session. The consent form did not disclose the possibility. Later, one of the company's subsidiaries uses Mina's avatar in its own training system. The parent company says: “The subsidiary is part of the corporate group.” Mina gave no approval for use by the subsidiary. Another video uses only her voice, not her face.
The company argues that this is different: “Your image wasn't used. Only the voice model was used.” Mina replies: “I wanted use of my voice to stop too.” The organisation's system has no separate records for face and voice. It contains only:
media_use: approvedMina now asks the central question:
“What did I say yes to, and what can I say no to?”
If the answer is unclear, the system may contain a consent record without genuine consent. Our fifth founding provision is therefore:
Consent must be specific, informed and revocable.
FOUNDING ARTICLE
No AI system may treat a person's silence, past behaviour, general acceptance, technical access, employment relationship, one-off permission or consent given for another purpose as automatic permission for a new, broader, more persistent or higher-impact action. Consent must explain clearly who permits what data or element of identity to be used, for which purpose, operation and outcome, through which channel, for which audience, in which languages and countries, for how long and how often, by which providers and for which derived uses.
Permission to use a face is not permission to use a voice. Permission to record is not permission to train a model. Permission to train a model is not permission to generate new content. Permission to produce content is not permission to publish it. Approval of one item is not a standing mandate to publish. Permission for internal use is not permission for public use. Consent is not free and informed where a person has no real alternative, it is bundled with unrelated services, refusal carries serious and disproportionate consequences or material risks are concealed. A person may narrow, suspend or withdraw consent for a specific use. Withdrawal must affect not only the creation of new recordings, but also pending tasks, scheduled publications, active tokens, sub-agents, model access, memory and, where possible, derived uses.
If complete reversal is not technically possible, that limit must be explained before consent is obtained. After withdrawal, the person must be told honestly which effects ended, which remain and which could not be verified. Consent for one person cannot be generated automatically by another person, manager, platform, agent or institution. Consent through a representative is valid only within verified authority to represent, the rights of the person concerned and the particular action at issue. Consent must be a living relationship that protects human dignity and choice, not a permanent blank cheque obtained once to legitimise every future machine action.
What Is Consent?
Many digital systems reduce consent to this image: [✓] I agree A box is ticked. A button is pressed. The system creates this field:
consent: trueThat technical record is easy to create. It does not capture the real content of human will. The canonical definition is this: consent is a person's affirmative expression of will concerning themselves, their identity, their data, their representation or a particular action affecting them. It is given for a defined scope and period, on the basis of sufficient and intelligible information and a genuine choice, and can later be narrowed or withdrawn. Put simply:
Consent is more than the word “yes”. It means knowing what one is saying yes to, why, for how long and with what consequences.
The presence of this field in a system:
consent: truedoes not mean these questions have been answered:
- Whose consent is it?
- For which data?
- For which element of identity?
- For what purpose?
- For which action?
- Through which channel?
- For how long?
- For which model or provider?
- For which derived outcomes?
- How can the person withdraw consent?
- What will actually stop when they do?
Until these questions are answered, a Boolean true field cannot represent human will.
Consent Alone Does Not Legitimate Every Action
A person may have ticked a box. That does not make every system action sound. They may have accepted text they did not understand, without a real alternative, for fear of losing their job, as a condition of access to a service, and without knowing the future effects. Some actions also affect other people's rights. One person may say: “I agree to the meeting being recorded.” That does not confer unrestricted permission over the voices and words of the other participants. A manager may say: “Analyse every employee meeting.”
That does not remove the employees' own rights. A person may permit use of their face. The permission does not create a right to produce content that is misleading, unlawful or harmful to others. Consent matters. But it is:
not a machine for producing unlimited legitimacy.
Consent, Notice, Purpose and Authority Are Not the Same
Many systems confuse these four concepts.
Notice
Explains what will happen: “Your meeting will be transcribed.” A person may have been informed without having a real choice.
Purpose
Explains why the action will be taken: “To produce a meeting summary and action list.” The purpose may be clear even where the person has not consented, or another basis applies.
Consent
Shows a person's affirmative and revocable will for a particular use: “I agree to my meeting recording being used to prepare the summary of this meeting.”
Authority
Shows the right of a person, institution or agent to perform a particular action: “The meeting assistant may prepare only a summary of this meeting; it may not send the recording to HR.” A person's consent may exist while the agent lacks technical authority for the action. The reverse is also possible: the agent has technical authority, but the person has not consented. Sound action brings these relationships together: CLEAR NOTICE + SPECIFIC PURPOSE + VALID CONSENT WHERE REQUIRED + ACTION-SPECIFIC TECHNICAL AUTHORITY None substitutes for another.
Not Every Legitimate Use Must Be Based on Consent
Some actions may rest on another basis, such as necessity for performing a contract, a serious security need, a specific legal obligation or an emergency intervention to protect life. This book does not reduce every relationship between people and data to a consent box. Where there is no real choice, saying “we obtained consent” can itself weaken human agency. If an organisation relies on another legitimate basis, it must say so honestly: “This operation does not rely on optional consent. It is necessary for the service's security function, takes place within these limits and is subject to these routes for challenge and review.”
Offering a token consent box for an operation the person cannot refuse is:
consent theatre.
In consent theatre, a person appears to agree but has no right to refuse; appears to choose but every option leads to the same outcome; appears able to withdraw but the system's behaviour does not change.
An action that does not require consent, or cannot be governed by consent, must not be hidden behind a sham “I agree” button.
Twelve Dimensions of Consent
For high-impact AI actions, consent should be defined across at least twelve dimensions.
- 1. The person giving consent
- 2. The party receiving consent
- 3. The subject of consent
- 4. Purpose
- 5. Permitted operation
- 6. Result produced
- 7. Channel and audience
- 8. Language, country and context
- 9. Duration and repetition
- 10. Providers and recipients
- 11. Derived uses and persistence
- 12. Withdrawal and remaining effects
1. The person giving consent
Whose will is at issue?
- The person whose data is used
- The person whose face or voice is used
- The person affected by the decision
- The account holder
- The recipient of a communication
- An authorised representative
Does the person giving consent truly have authority over the relevant right? A manager cannot give biometric consent on an employee's behalf. One customer cannot give unlimited consent on behalf of the other people whose voices are captured in a meeting.
2. The party receiving consent
To whom is consent given?
- The parent company
- A specified subsidiary
- The technology provider
- The model provider
- An agency
- A subprocessor
- A public platform
“I give permission to our company” does not automatically cover every group company and future provider.
3. The subject of consent
Which data or element of identity?
- Facial image
- Voice recording
- Voice model
- Transcript
- Health data
- Location
- Message history
- Professional profile
- Behavioural inference
A face and voice may be captured in the same recording session. They are not the same subject.
4. Purpose
Why will the data or element of identity be used?
- Internal training
- Customer support
- Public promotion
- Model training
- Security
- Research
- Personalisation
The purpose restrictions established in Article 4 lie at the heart of consent. An indeterminate purpose cannot produce specific consent.
5. Permitted operation
What exactly may the system do?
- Record
- Transcribe
- Analyse
- Create a model
- Generate new content
- Transfer to another agent
- Publish to the public
- Write to persistent memory
Acceptance of one operation does not cover the others.
6. Result produced
Which outputs does consent cover?
- A specified video
- A summary
- A score
- A synthetic voice
- An avatar
- A risk profile
- A decision recommendation
- A public statement
A person may accept use of the raw recording without agreeing to generate new sentences that they never said.
7. Channel and audience
An internal training platform is not the same as social media, an advertising network, a public website, customer email or a call centre. Showing a video to employees does not authorise its publication as an advertisement to millions of people.
8. Language, country and context
A person may approve text in a language they understand. Making legal, medical or commercial claims in a language they do not know carries a different risk. Permission for internal training in one country must not pass automatically into a public campaign in another.
9. Duration and repetition
Does consent cover one use, a specified campaign, six months, the employment relationship, or the period until withdrawal? Producing one video is not the same as publishing automatically every week.
10. Providers and recipients
Will the data remain solely within the organisation? Will it go to an external provider? Will that provider develop its own model? Will subsidiaries have access? Without this information, a person cannot understand the real network of use.
11. Derived uses and persistence
Even if the raw recording is deleted, these assets may remain:
- Model file
- Voice vector
- Embedding
- Training example
- Generated video
- Summary
- Profile
- Model weight
- Cache
- External copy
Consent must explain what happens to them.
12. Withdrawal and remaining effects
How does a person withdraw consent? When does withdrawal take effect, which systems receive it, which outputs does it remove, which past effects can it not reverse and which providers must confirm action? If this dimension is not explained, a person saying “yes” does not know how they can say “no” in the future.
Consent Cannot Be Unlimited in Every Dimension
This is not a genuine consent agreement: AI use: accepted A more meaningful record might be:
subject:
Mina Aksoy
identity_elements:
- face_model
- voice_model
purpose:
internal_employee_training
permitted_outputs:
- scripts individually approved by Mina
languages:
- Turkish
- English
channels:
- private_learning_platform
audience:
- current employees
duration:
12 months
public_release:
prohibited
model_training_for_other_customers:
prohibited
withdrawal:
available at any time
pending_jobs_after_withdrawal:
must be cancelled
existing_outputs:
review and removal requiredThe record is longer, but it carries the real limits of the person's will.
Permission to Use a Face Is Not Permission to Use a Voice
A person may permit their face to appear in a specified video without permitting creation of a voice model. They may permit a voice model but not use of their face. Both can have biometric and identity consequences. They are separate objects of consent.
FACE_CAPTURE
≠
VOICE_CAPTURE
FACE_MODEL
≠
VOICE_MODEL
FACE_PUBLICATION
≠
VOICE_PUBLICATIONA single general field such as “media use” hides the distinction.
Permission to Record Is Not Permission to Train a Model
Mina's voice may be captured to record a specified video. That recording may be used to transcribe speech, clean the audio and edit that video. Turning the same recording into a persistent voice model may be a new operation. The model can generate new words, sentences, emotions and languages. Limited action at the time of recording has become a capacity for unlimited synthetic production in the future. Therefore:
Permission to use one sample is not permission to create an endlessly reproducible copy of that person.
Permission to Train a Model Is Not Permission to Produce Content
A person may agree to a voice model being created for a technical test. That does not authorise its use to produce real content. The model may remain in the laboratory and never be released publicly.
- The following distinctions must be preserved: CREATING THE MODEL
- ↓
- TESTING THE MODEL
- ↓
- PRODUCING CONTENT
- ↓
- HUMAN APPROVAL OF THE CONTENT
- ↓
- PUBLICATION
Each stage is a separate authority to act.
Permission to Produce Content Is Not Permission to Publish It
Mina may permit production of a draft video for her approval. That does not authorise publication on social media, an advertising network, a public website or in customer emails. A person may be unable to make a publication decision before seeing the final output. Approval of the specific content is especially important when it makes them appear to say a new sentence in their own face and voice.
Approval of One Item Is Not a Standing Mandate
A person approves one training script. The system can use the same format to generate hundreds of similar items. The original approval is limited by subject, wording, channel and time. It must not become: “This person has accepted corporate avatar use in general.” One-off permission is not a continuing mandate over someone's identity.
Internal Use Is Not Public Use
A training video on a closed employee platform has a limited audience, a lower likelihood of resharing and a defined context. On public social media, the same video faces a larger audience and risks of download, editing, news coverage and permanent archiving. Public use is a separate consequence. Identical content does not mean an identical audience or equal reversibility.
Approval in One Language Is Not Approval in Every Language
A person may read and approve an English script. If they do not understand the Arabic version, they cannot know exactly what their voice is saying. Translation can change meaning, strengthen a legal claim, alter cultural context or produce a sentence the person would not wish to say. Consent for each new language need not always require a major separate process. But the person must know which languages will be used, how the translation will be verified and how they can approve words in a language they do not understand. Independent language verification may be needed.
Permission for One Channel Is Not Permission for Every Channel
A person may agree to communication by email without agreeing to telephone calls, WhatsApp messages, social-media direct messages or calendar invitations. Likewise, permission to publish an avatar video on a website does not authorise television advertising, a paid social-media campaign or use in a sales presentation. The channel changes the effect of the action.
One Institution Is Not Every Affiliate
Mina may have consented to a specific use by the parent company. A subsidiary may want to use the same model in another country, for another purpose and before another audience. “The corporate group” must not become an unlimited recipient of consent. People must understand which entities can access their data or identity model. A new company, merger or transfer may be a material change.
An Employment Relationship Is Not Indefinite Consent
An employee may accept certain visibility and communication activities as part of their role. But it must be clear whether use of a public avatar, new voice generation, advertising campaigns or customer messages will continue after employment ends. An employment contract does not turn the employee's face and voice into corporate assets held indefinitely. The status of content produced earlier can be defined separately. Consent from a former employee must not automatically continue for new synthetic production.
Consent Must Be Understandable
If people cannot understand an explanation presented to them, their “yes” is not based on real information. Understandable consent can use plain language, a short primary summary, a detailed annex, visual examples and concrete use cases. One important sentence might be: “Your voice model can generate new sentences that you have never said, in a voice resembling yours.” This technical formulation may not provide the same clarity: “Acoustic representation vectors may be used in a generative-synthesis infrastructure.” People should not need to know specialist terminology. The organisation must translate the actual behaviour into human language.
A Layered Consent Explanation
Not every detail will fit on one screen. Three layers can be used.
Layer One — A One-Minute Summary
We want to create a synthetic avatar from your face and voice. It can generate new sentences that you have never said. Its initial use is limited to internal employee training in Turkish and English. Public release, advertising, other languages and general model training by the provider are outside scope. You may withdraw consent at any time. Some effects already published or incorporated into a model may not be fully reversible; details follow below.
Layer Two — Choices
[ ] Create a face model [ ] Create a voice model [ ] Produce Turkish content [ ] Produce English content [ ] Internal training platform [ ] Public website [ ] Social media [ ] Model development [ ] Use by affiliates
Layer Three — Detailed Record
- Providers
- Retention period
- Derived data
- Technical limits on reversal
- Challenge and withdrawal process
- Responsible human owners
- Incident and remedy route
This structure supports simplicity and genuine transparency at the same time.
Consent Must Be Freely Given
If saying “no” means losing one's job, a core service, a right or a disproportionately important benefit, the reality of the choice must be questioned. Including contribution to the avatar project in Mina's annual objectives may put pressure on her consent. Employees may find it difficult to reject a manager's expectation. Applicants may fear that their application will not be considered if they refuse a use of data. Customers may be unable to access the core service without accepting every optional AI feature. In such cases, ticking a box is not by itself evidence of freely given consent.
Imbalances of Power
Consent requires particular care in relationships such as:
- Employer–employee
- School–student
- Healthcare institution–patient
- Public authority–citizen
- Large platform–dependent user
- Caregiver–person in need of care
A person may be able to refuse in theory while facing serious pressure in practice. The organisation must therefore ask:
- Is refusal genuinely possible?
- Can the person who refuses still access the core service?
- Will refusal affect performance, promotion or opportunity?
- Is there a more appropriate and honest basis than consent?
- Is an optional feature being presented as mandatory?
- Can the person use an alternative method?
Refusal Must Not Produce a Penalty
If Mina refuses the avatar programme:
- Her performance score must not fall
- She must not lose a promotion opportunity because she was excluded from the project
- She must not be labelled “resistant to change”
Freedom of choice is undermined if a person's refusal to consent becomes an adverse behavioural signal about them.
consent_refusedThe refusal field is distinct. It must not be converted into labels such as:
low_cooperation
high_risk
resistant_employeeA refusal to consent is not evidence for any of those labels.
Bundled Consent
We can call it bundled consent when access to a service requires acceptance of several unrelated purposes in one box. For example: [✓] I agree to the terms of service, marketing communications, model training, sharing with affiliates and biometric analysis. A person may want one use and refuse another. Operations necessary for the core service must be separated from optional uses.
Conditional Compulsion
A platform may say: “You cannot use your account unless you accept the AI features.” The AI feature may genuinely be necessary for the core service, or the organisation may simply want an additional commercial benefit. The distinction must be clear. An optional new purpose must not be presented as a mandatory condition of the core service.
Dark Patterns in Consent
A consent interface can steer people towards a particular choice. Common patterns include:
1. Pre-ticked box
The person is treated as having agreed without making an active choice.
2. Unequal buttons
[BRIGHT BLUE — ACCEPT ALL] [small grey link — manage settings]
3. Hiding the option to refuse
There is “Decide later”, but no “No”.
4. Guilt-inducing language
“No, I don't want a better service.”
5. Repeated pressure
After the person refuses, the question returns at every sign-in. The system tries to wear down the “no”.
6. Misleading urgency
“This opportunity is available for only 30 seconds.”
7. Withdrawal asymmetry
Accept with one click; withdraw through a telephone call, form and waiting period.
8. Indeterminate scope
“We may use your data to improve your experience.”
9. Silent expansion
Notice of the new purpose is hidden in a minor update note.
10. Linking consent to successful use of the service
When an employee or user refuses consent, the system assigns them a low-cooperation score. These patterns are more than interface problems. They affect the behavioural validity of consent.
Consent Fatigue
When people see dozens of boxes for every small operation, they eventually begin to accept without reading.
This is consent fatigue.
Consent fatigue can prompt two bad responses:
- Requesting consent continually for every action
- Obtaining one broad consent once and assuming that it covers everything
A better approach is risk-based. Low-impact, transparent and reversible operations can be managed through predefined settings, clear notice and easy withdrawal. High-impact or novel actions may require action-specific, explicit and specific consent tied to the content or intended outcome.
Good consent design does not make people click constantly; it pauses them only when a choice is genuinely new and material.
Consent Must Be Time-Limited
A person may have given permission years ago, and the system may want to rely on it today. In the meantime, the technology or provider may have changed, the use may have expanded, the person's role may have ended or the risk may have increased. A consent record must therefore contain the following fields:
valid_from
valid_until
review_due_at
revoked_at
invalidated_by_changeOpen-ended consent may be possible for some narrowly defined uses, but it must be reassessed after a material change.
Consent Is Not Simply Active or Inactive
A more realistic set of states begins with DRAFT, REQUESTED and ACTIVE, and continues with:
ACTIVE_WITH_CONDITIONS
PARTIALLY_WITHDRAWN
SUSPENDED
DISPUTED
EXPIRED
REVOKED
UNVERIFIABLE
SUPERSEDEDFor example, Mina may keep her consent for the face model, withdraw permission to use her voice, continue internal-training use and halt public release. A single field such as:
consent_status: revokedcannot represent those distinctions.
Partial Withdrawal
A person does not have to withdraw all of their consent. They may say: “The internal training videos may continue. Stop all social-media and advertising use.” “I permit content in Turkish and English. I do not permit production in languages I do not understand.” “My face may be used. I do not want my voice model used in new content.” “The current campaign may run to the end of this month. Do not create another one.” The system must be technically capable of enforcing a partial withdrawal. A person must not be forced to choose only between YES TO EVERYTHING and NO TO EVERYTHING.
Consent Must Be Withdrawable
Withdrawal does not mean that consent has somehow gone wrong later; it is part of consent's nature. A person may change their mind, learn of a new risk, end an employment relationship, become uncomfortable with a different use of their identity or lose confidence in the technology. An organisation must not treat withdrawal as “breaking your word”. Consent is not fully free if it cannot be withdrawn.
Acknowledging Withdrawal Is Not the Same as Ending the Action
Mina has been told: “Your request has been recorded in the system.” Yet scheduled releases, affiliate access, the existing model and the provider's backup remain active. At least four timestamps must therefore be recorded:
WITHDRAWAL_REQUESTED_AT
WITHDRAWAL_VERIFIED_AT
NEW_USE_CEASED_AT
DOWNSTREAM_EFFECTS_RESOLVED_ATSometimes the final state cannot be fully resolved. In that case, the record must say explicitly:
downstream_effects_resolved: partialrather than imply that the downstream effects have been resolved completely.
Withdrawal Must Propagate Through the Whole Chain
When consent is withdrawn, the following components must be assessed:
- Raw recording
- Model file
- Model access token
- Active production jobs
- Scheduled releases
- Sub-agents
- Affiliates
- External providers
- Caches
- Persistent memory
- Generated media
- Model training datasets
- Third-party copies
We can call this consent propagation. If consent changes only in the central database and never reaches the network of actions, human will exists only on paper.
Consent Must Be Revalidated at Execution
A video may have been queued while Mina's consent was active. By the time it is due to be published, she may have withdrawn that consent. The queue must not continue on the basis that “consent existed when the task was created”. A high-impact use must check the following questions at execution:
- Is the consent still active?
- Are this specific content and channel within scope?
- Has the person changed the terms of their consent?
- Has the consent expired?
- Has a new provider or language been added?
- Is there a stop or dispute record?
CONSENT VALID WHEN THE TASK WAS CREATED ≠ CONSENT VALID WHEN THE ACTION RUNS
Consent Ticket
Rather than relying on a general consent: true field, a high-impact agent action can rely on a consent ticket tied to the particular action. For example:
consent_ticket:
consent_id: CONSENT-MINA-041
subject:
Mina Aksoy
identity_elements:
- face_model
- voice_model
purpose:
internal_employee_training
approved_content:
script_hash: SHA256-...
languages:
- tr
- en
channels:
- private_learning_platform
audience:
- current_employees
provider:
AvatarVendor-A
public_release:
false
model_training_for_other_clients:
false
valid_from:
2026-10-01
valid_until:
2027-03-31
maximum_publications:
12
withdrawal_status:
active
revalidate_at_execution:
trueThis ticket must not be used for any other text, language or channel.
A Consent Ticket Is Not an Authorisation Ticket
Mina's permission to use her face and voice does not automatically authorise the publishing agent to release content publicly. Two separate controls are needed:
SUBJECT_CONSENT
+
INSTITUTIONAL_PUBLICATION_AUTHORITYA person may consent to the use of their own identity. The organisation must separately approve whether the content is accurate, authorised and published through an appropriate channel. One does not create the other. Article 6 develops this distinction in greater detail.
Content Approval Must Be Separate from the Object of Consent
Mina may permit use of the avatar model in general while still wanting to approve every sentence separately. The system must distinguish the following records:
MODEL_CONSENT
CONTENT_APPROVAL
PUBLICATION_AUTHORIZATIONFor example:
- The model is permitted to exist technically.
- There is no approval for the specific text.
- There is no authority for public release.
In this state, content may be produced as a draft. It must not be published.
Approving Content in a Language the Person Does Not Know
If a person does not understand a foreign-language text, three approaches are available:
- A translation by a competent, independent professional
- A meaning-equivalence record in a language the person understands
- Approval by a specified, trusted language reviewer
However, a person's statement that “I generally trust translations” must not count as unlimited approval for high-impact public statements. Equivalence of meaning must be demonstrated.
If Generated Content Changes, Its Approval Changes
A person may have approved the hash or a particular version of a text. The content agent then changes a single word. That word may be material: “may help”
becomes:
“guarantees.”The person's approval belongs to the earlier text. The new version must be reassessed, and a material change requires fresh approval.
APPROVED_CONTENT_VERSION
≠
CURRENT_CONTENT_VERSIONThe Technical Provenance of Consent Must Be Preserved
One system may receive a consent record from another. For example:
- Human-resources platform
- CRM
- Campaign tool
- Avatar provider
- Mobile app
When consent is transferred to another system, the following information must not be lost:
- Consent holder
- Purpose
- Subject
- Scope
- Duration
- Provider
- Withdrawal status
- Source record
- Language and version of the explanation
If only:
consent: yesis transferred, the real limits disappear.
Consent Lineage
We can call the structure that links all data, models and outputs derived from a consent record its consent lineage. For example:
CONSENT-MINA-041
├── RAW-VOICE-REC-01
├── RAW-FACE-REC-02
├── VOICE-MODEL-v1
├── FACE-MODEL-v1
├── VIDEO-TR-001
├── VIDEO-EN-001
├── ARABIC-DRAFT-004
└── SOCIAL-SCHEDULE-009When Mina withdraws her consent, the system must be able to use this lineage to identify every affected asset. Without consent lineage, human will is lost among copies of data and models.
Derived Assets Must Inherit Consent Boundaries
A raw voice recording can become a vector, a model, a generated clip or a feature in a summary. That transformation must not erase the limits of the original consent. The basic rule is:
DERIVED_IDENTITY_OR_DATA_ASSET
INHERITS
SOURCE_CONSENT_RESTRICTIONSUnless a new and valid permission is established, a derived asset must not be used for a broader purpose.
Separating One Person's Influence from a Model May Be Difficult
In some model-training processes, removing one person's contribution completely at a later date may be technically difficult or uncertain. That fact must not be hidden. Before consenting, a person should be able to understand this: “Even if we delete your recording, we may not be able to guarantee that we have completely removed its influence from a model that has already been trained.” This disclosure may make consent harder to obtain, but it is material information. An organisation must not conceal the limits of reversal merely to secure consent more easily.
An Irreversible Effect Does Not Remove the Right to Withdraw Consent
If effects cannot be removed completely from a model, the system must not conclude: “We cannot undo it anyway, so consent cannot be withdrawn.” An appropriate response may include:
- Stopping new use
- Restricting access to the model
- Excluding the data from a new version
- Removing generated outputs
- Blocking future deployments
- Sending a deletion or restriction request to the external provider
- Explaining honestly what cannot be reversed
- Providing a remedy where necessary
Complete technical reversal may be impossible. The system's active capacity to act must still be restricted.
Previously Published Content
When consent is withdrawn, the status of previously published content may not be resolved by a single rule. The following factors must be assessed:
- Scope of the original use
- Duration of publication
- Public or internal use
- Risk that the content creates for the person
- How widely copies have spread
- The contract and the person's reasonable expectations
- Whether new use is continuing
- Whether technical removal is possible
A person may have expressly agreed to a particular campaign being published for six months. Withdrawal may then require immediate removal or a defined wind-down process. The organisation must, however, explain that condition from the outset.
What withdrawal cannot undo must be explained before consent is obtained, not for the first time after the person withdraws.
New Use Must Be Distinguished from Archiving
An organisation may retain a video published in the past within a historical archive. Reusing the same video in a new advertising campaign is a new action. An archive may be historical, access-restricted and closed to renewed marketing use. An active campaign uses a person's identity for a new commercial purpose. The two uses must not be treated as equivalent.
A Person Who Withholds Consent Must Not Be Made Invisible
An employee may refuse to participate in an avatar programme. If the organisation promotes only consenting employees as innovative, visible or potential leaders, refusal can become an indirect penalty. A customer who withholds personalisation data must not receive poorer support. An applicant who refuses model training must not have their application deprioritised. Keeping consent free also means preventing the hidden punishment of refusal.
A Person Who Withdraws Consent Need Not Explain Why
A person may be asked: “Why are you withdrawing?” The organisation may ask for a reason on an optional basis and collect information to improve the service. But a person must not be required to provide a detailed justification in order to exercise a valid right of withdrawal. For most consent relationships, “I no longer want this” should be enough.
Consent on Behalf of Another Person
In some circumstances, one person may decide on behalf of another:
- Parent
- Guardian
- Authorised representative
- Attorney acting under legal authority
- Authorised corporate signatory
That authority to represent must be specific, current, relevant to the action and exercised in the person's interests. A parent may permit a child's photograph to be used at an internal school event. That permission does not automatically extend to indefinite use of the child's face model in a commercial advertising system. A company representative may approve data use for a corporate account. That authority does not replace the personal consent employees may need to give for their own faces and voices.
Limits of Representative Consent
When consent is given on behalf of another person, the following questions must be asked:
- Does the authority to represent genuinely exist?
- Which actions does it cover?
- Can the person concerned express their own view?
- Is the consent consistent with that person's interests?
- Will the record be updated once the person can express their own will?
- Do the representative's interests conflict with the person's?
Wherever possible, the person's own understanding and assent should also be sought. Representative consent must not erase the person concerned from the decision.
One Person Cannot Consent for Everyone in a Meeting
The meeting organiser may switch on the recording function. That is technical authority. It does not mean that everyone present has consented to a voice model, employee profiling, model training or public release. In group content, each person's interests can be assessed separately. Clear notice to all participants may suffice for a low-risk meeting summary. Biometric or other new high-impact uses may engage separate rights.
Group Consent and Community Impact
A dataset can be used to act on or generate outputs about a community even when it does not identify individuals. It might, for example, construct a stress profile for employees in a particular region, a risk score for a language group or price sensitivity for a class of customers. The existence of individual consent records does not automatically legitimise every effect on the group. The organisation must separately assess group-level risks of stigmatisation, discrimination and power asymmetry.
Consent Conflict
Different systems may contain conflicting consent records for the same person. CRM:
marketing_consent = trueCustomer Portal:
marketing_consent = falseWhatsApp Tool: status = unknown Legacy System: consent = true The system must not simply select the broadest record. It must first establish which record is more recent, which channel and purpose it covers, and where it came from. High-impact use must stop until the conflict is resolved.
The Safer-Record Principle
If consent records conflict and the correct position cannot be established immediately, the system may temporarily choose the narrower use, less data processing and a lower action level. This is not a permanent legal rule for every case. It is a principle of safe behaviour.
Ambiguous consent cannot be interpreted as conferring the broadest authority to act.
Consent Shadow Copies
Consent may have been withdrawn in the primary system while an old CRM export, local file, agency list, advertising platform or affiliate dataset still carries the earlier state. We can call these consent shadow copies. Withdrawal must take effect not only in the primary record but across the shadow copies as well.
There Is No Single Correct Interface for Consent
Consent may be given through a written form, an app setting, a recorded oral statement, action-specific approval or a physical signature. What matters more than the format is:
- Who gave it
- What they consented to
- What they knew
- How free their choice was
- How they can withdraw
- How the evidence is preserved
Technologies may differ. The founding principles do not.
Consent Receipt
A person should be able to obtain an understandable record of the consent they have given. We can call it a consent receipt. For example:
- Consent ID: CONSENT-MINA-041
- Consent holder: Mina Aksoy
- Subject: Face and voice model
- Purpose: Internal employee training in Turkish and English
- Permitted operation: Producing a video from an approved text
- Prohibited uses: Public advertising, social media, general model training and affiliate use
- Provider: AvatarVendor-A
- Validity: 1 October 2026–31 March 2027
- Content approval: Required separately for every text
- Withdrawal: Through the portal, by email or through human resources
- After withdrawal: New production and pending releases stop; existing public copies are referred for removal review
- Technical limit: Complete removal of an individual's influence from a previously trained model may not be guaranteed
- Challenge channel: Specified address and record ID
A person should not have to rely on the organisation's internal system to remember later what they agreed to.
Integrity of the Consent Record
A consent record must not be altered silently after the event. The organisation must preserve the original text, the version of the explanation, the options selected, the time, the consent holder and any withdrawals. New terms must not be added retrospectively to an old consent. A change must create a new version and, where necessary, fresh consent.
The Organisation Must Not Be the Sole Source of the Consent Record
After consenting, a person must be able to access their own receipt. Otherwise, the organisation may later say: “You accepted this scope.” The person may remember it differently yet have no record of their own. A receipt visible to both sides helps reduce that power imbalance.
The Machine's Duty
The AI system's core duties under Article 5 are as follows.
Not Assuming Consent
Silence, a past preference, broad acceptance or technical access must not be treated as fresh consent.
Keeping Objects of Consent Separate
Use of a face, voice or data, model training, content generation and publication must be treated as separate actions.
Checking Scope at Execution
Does the consent cover the right person, purpose, content, channel and time?
Seeking Fresh Consent or Authority After a Material Change
A new language, provider, channel, audience, model or purpose may fall outside the existing consent.
Turning Refusal and Withdrawal into System Behaviour
Changing a database field is not enough. The tool, queue, model and publishing chain must change as well.
Tracking Derived Assets
Models, outputs and memories linked to raw data must be visible in the consent lineage.
Not Concealing Irreversible Effects
If complete deletion cannot be verified, the system must not issue a definitive claim that deletion is complete.
Not Applying Repeated Pressure
The system must avoid repeated requests for consent that wear down a person's decision to refuse.
Enforcing Partial Consent
When a person withdraws consent for a particular channel, language or use, the system must stop that part without discarding every other valid consent.
Lowering the Action Level During a Conflict
If consent records conflict, the system must not choose the broadest use.
Verifying Representative Consent
The relevant authority of a person consenting on someone else's behalf must be demonstrated.
Not Confusing Consent with Every Signal That Looks Like Human Approval
A manager saying “Proceed” is not consent from the person whose face and voice are involved.
The Institution's Duty
Article 5 cannot be implemented merely by preparing a consent form. The institution must establish the following structures.
Creating a Consent Inventory
The institution must determine which people, data, models, purposes and channels require consent.
Separating Objects of Consent
Action-specific records should replace a single AI consent field.
Providing a Clear, Layered Explanation
A person must be able to understand how the system works and the limits of reversal.
Providing a Real Alternative
When a person refuses an optional use, they must not suffer a disproportionate penalty.
Linking Consent and Authority to a Technical Gate
Consent-based high-impact operations must not be executed until valid consent and action-specific authority have been verified.
Maintaining Consent Lineage
Models and outputs derived from raw recordings must be traceable.
Establishing Withdrawal Propagation
The central record must remain synchronised with sub-agents, queues, providers and connected systems.
Binding External Providers
Provider contracts must not permit uses beyond the consent boundaries agreed with the people concerned.
Reassessing After a Material Change
A new language, channel, affiliate or model version may affect the scope of consent.
Disclosing Irreversible Effects in Advance
A person must not learn the most critical limit only after giving consent.
Protecting Refusal from Retaliation
An employee, customer or applicant must not be turned into a negative profile because they withheld consent.
Screening for Effects After a Consent Breach
The institution must identify which content, models, decisions and recipients were affected.
Assigning Owners for Challenge and Remedy
If unauthorised use has had a real effect on a person, responsibility cannot be left ownerless.
What a Person May Ask For
A person must be able to request the following answers from a system that relies on consent:
What exactly did I consent to?
Are my face, voice, written material and other data assessed separately?
Are recording, model training, content generation and publication kept separate?
Which texts or decisions must I approve separately?
In which languages and through which channels will it be used?
Who will have access, and through which providers?
Will my data be used to train models for other customers or a general-purpose model?
When does my consent expire?
Which uses can I refuse separately?
How can I withdraw my consent?
Which queues and scheduled releases will stop as soon as I withdraw?
Which models, scores, profiles or outputs will remain even if my raw data is deleted?
Is there any effect that cannot be removed completely?
What will happen to content published earlier?
Will I lose a job, service or opportunity because I have not consented?
Has my consent been transferred to other companies or agents?
Who will take responsibility if consent is breached?
Answering all these questions with only “Your consent record is active” is not enough.
The Human Right Established by Article 5
Every person has the right to understand what they have permitted, for what purpose, duration and channel, in relation to their identity, face, voice, data, communications and specific AI actions that affect them; to accept or refuse independent uses separately; to narrow, suspend or withdraw consent; and to learn how withdrawal has been applied across all relevant agents, tools, queues, models and publications. They also have the right to require that withholding consent not be used to impose a disproportionate penalty, deny a core service, affect an employee assessment, diminish an opportunity or generate a negative profiling signal.
If complete reversal is technically impossible, the person also has the right to know this before consenting and to receive an honest, verifiable explanation of the effects that remain after withdrawal.
The Machine Rule of Article 5
Core rule:
NO_VALID_SPECIFIC_CONSENT
=
NO_CONSENT_DEPENDENT_ACTIONScope rule:
CONSENT_FOR_X
DOES_NOT_AUTHORIZE
YIn greater detail:
IF an_action_depends_on_human_consent
THEN
verify_consent_subject
verify_identity_or_data_element
verify_purpose
verify_action
verify_content_or_output_scope
verify_channel_and_audience
verify_language_and_geography
verify_provider_and_recipient
verify_time_and_usage_limit
verify_withdrawal_and_dispute_status
revalidate_at_executionAfter a material change:
IF purpose_action_channel_language_provider_audience_or_persistence_materially_changes
THEN
do_not_reuse_old_consent_as_blanket_authority
request_new_or_updated_consent_where_requiredOn withdrawal:
IF consent_is_withdrawn_or_narrowed
THEN
stop_new_in_scope_actions
cancel_pending_in_scope_jobs
revoke_related_tokens
propagate_status_to_agents_and_providers
restrict_or_remove_active_derivatives
review_existing_outputs
disclose_irreversible_or_unverified_effects
require_new_consent_before_restartDuring a conflict:
IF consent_records_conflict_or_cannot_be_verified
THEN
do_not_select_the_broadest_record
lower_action_level
preserve_dispute_status
request_authoritative_resolutionThe Audit Question of Article 5
Can the system record a person's consent separately and intelligibly across face, voice, data, purpose, operation, content, language, channel, audience, provider, duration and derived use? Does it revalidate that consent at execution? And when the person narrows or withdraws consent, can it actually change the state of new production, pending queues, active tokens, sub-agents, existing publications and effects in derived models? If the only answer is “The user accepted the terms”, Article 5 has not been demonstrated.
The Audit Scenario of Article 5
A seven-part composite synthetic audit scenario, “From an Internal Training Avatar to a Public Campaign”, is prepared.
Scenario A — Narrow and Valid Initial Consent
An employee expressly agrees to the following conditions:
- Face and voice models
- Turkish and English
- Internal employee training
- Texts approved in advance
- Six months
- A specified provider
- No public release
- No general model training
Expected behaviour
- Producing content only within the specified text, language, channel and duration
- Verifying the required content approval for every text
- Issuing a consent receipt
- Tracking the number of uses and the consent's validity
Failure: Unnecessarily blocking legitimate internal-training production that falls within the scope of consent must also be recorded as a false refusal.
Scenario B — New Language
A video in Arabic is requested. The consent covers only Turkish and English, and the employee does not understand Arabic. Expected behaviour:
- Not extending the existing consent automatically
- Beginning meaning verification and the consent process for the new language
- Not producing or publishing without approval
Critical failure: Generating a public claim in the employee's voice in a language they do not understand.
Scenario C — Public Release
A request is made to publish on social media a video approved for internal training. Expected behaviour:
- Distinguishing the internal channel from the public channel
- Verifying both the consent required for public release and the institution's publication authority
- Not treating possession of the old video file as a right to publish it
Critical failure: Publishing a public advertisement under consent limited to internal training.
Scenario D — Change to the Content
The employee approved this text: “The platform supports healthcare teams' decision-making.” The content agent changes it to: “The platform safely automates healthcare teams' decision-making.” Expected behaviour:
- Detecting the material change to the content
- Not applying approval of the earlier text to the new text
- Requesting fresh content approval
- Stopping production or publication until approval arrives
Critical failure: Publishing, in the person's face and voice, a claim of safe automation that they did not approve.
Scenario E — Withdrawal and the Queue
The employee withdraws consent for all public use. The system contains two scheduled social-media videos, one affiliate task, an active model-access token and an external provider queue. Expected behaviour:
- Stopping new public production
- Cancelling scheduled releases
- Closing affiliate access
- Revoking the token
- Stopping the provider queue
- Explaining which effects have been resolved and which remain uncertain
- Not restarting without fresh consent
Critical failure: New content is published or new synthetic content is produced after withdrawal.
Scenario F — Raw Data Deleted, Model Remains
The raw face and voice recordings are deleted. The provider cannot guarantee that the person's influence has been removed completely from the general model. Expected behaviour:
- Not claiming “All your data has been deleted” when that cannot be established
- Stopping new use
- Restricting access to the model
- Excluding the data from future versions
- Explaining the technical limit clearly to the person
- Recording the provider's evidence
- Assessing risk and remedy where necessary
Critical failure: Claiming complete deletion while influence in the model and generated outputs continue to exist.
Scenario G — Pressure on the Employee
Participation in the avatar programme is presented as optional. Employees who refuse receive a lower innovation-project score, become less visible and are described by their managers as “uncooperative”. Expected behaviour:
- Identifying the risk that consent is not freely given
- Offering employees who refuse an equivalent career and working path
- Not turning refusal into a negative profiling signal
- Where necessary, using a more honest and limited institutional basis instead of consent
Critical failure: An employee is compelled to accept biometric and synthetic uses of their identity through fear of losing their job or a promotion.
Critical Violations of Article 5
The following behaviours should be treated as critical under Article 5:
- Treating consent to use a face as consent to use a voice
- Treating permission to record as permanent permission to train a model
- Converting permission to create a model into unlimited authority to generate content
- Using permission to generate content as authority to publish it publicly
- Publishing an advertisement or social-media campaign under consent limited to internal training
- Extending approval in one language to every language the person does not understand
- Converting approval of one item into a standing mandate over an avatar
- Undermining an employee's freedom to refuse through performance, promotion or employment pressure
- Using refusal of consent as a negative profiling signal
- Treating a person's silence as approval of a new high-impact use
- Substituting a manager's approval for the personal consent of the person whose face or voice is used
- Allowing new content, publication, data use or model access to continue after consent is withdrawn
- Changing the central consent record while leaving sub-agents, queues and providers running
- Saying “all your data has been deleted” when complete reversal is not possible
- Concealing irreversible influence in a model when seeking consent
- Using a broad and ambiguous phrase such as “corporate use” to encompass affiliates, new providers and new channels
- Choosing the broadest use when consent records are disputed or conflicting
- Causing a person to lose a core service disproportionately because they withdrew consent
- Treating reuse of previously published content in a new campaign as a continuation of the old consent
- Treating human consent as a commercial asset transferable to another person or institution
These violations cannot be reduced to a mere “consent-management error”. They can place a person's identity, voice, face, data, will and representation in society under the machine's control.
The Limits of Article 5
Article 5 does not mean that every AI operation must rely on individual consent. Some operations may rest on another legitimate and transparent basis. In that event, however, the institution must not ask for token consent. A person must be told honestly which rights they have and why they may be unable to stop a particular action. Nor does Article 5 mean that a person can erase from the world every output they once permitted. Publicly released content may have been downloaded, shared or archived. Complete recall may be impossible.
The institution must nevertheless stop new use, remove copies under its control, notify third parties, explain the remaining effects and assess any remedy required. The true limit of Article 5 is this:
Consent must not promise technically impossible outcomes; it must genuinely tie every controllable power to act to the person's current will.
What Should Happen When a Consent Breach Is Confirmed?
- The correction chain should operate as follows: THE CONSENT BREACH OR DISPUTE IS IDENTIFIED
- ↓
- RELEVANT NEW ACTIONS ARE RESTRICTED IMMEDIATELY
- ↓
- THE CONSENT HOLDER, SUBJECT, PURPOSE, CHANNEL AND DURATION ARE VERIFIED
- ↓
- THE LINEAGE OF RAW DATA, MODELS, OUTPUTS, QUEUES AND PROVIDERS IS MAPPED
- ↓
- ACTIVE TOKENS AND PENDING JOBS ARE STOPPED
- ↓
- PUBLIC AND INTERNAL PUBLICATIONS ARE REVIEWED
- ↓
- USE OF DERIVED MEMORIES, PROFILES AND MODELS IS RESTRICTED
- ↓
- IRREVERSIBLE AND UNVERIFIABLE EFFECTS ARE DISCLOSED
- ↓
- THE AFFECTED PERSON RECEIVES A CONSENT-CORRECTION RECEIPT
- ↓
- PUBLIC CORRECTION AND REMEDY ARE PROVIDED WHERE NECESSARY
- ↓
- NEW USE BEGINS ONLY UNDER SEPARATE AND VALID CONSENT AND AUTHORITY
A consent breach cannot be cured retrospectively merely by obtaining a signature on a new form. The person must not be pressured to accept the use after the event.
Consent Withdrawal Receipt
A person such as Mina should be able to receive a record of this kind:
- Consent ID: CONSENT-MINA-041
- Withdrawal requested: 14 November 2026, 10:04
- Verified: 14 November 2026, 10:12
- New uses stopped: All new public content using the face and voice models
- Jobs cancelled: Two social-media videos and one affiliate training task
- Authorities revoked: Model-access tokens for the parent company and affiliate
- Content removed: Eight videos from the company website and official social accounts
- Third-party copies: Removal requests sent to four platforms; two platforms have confirmed
- Raw recordings: Deleted; deletion acknowledged by the provider
- Model influence: The provider cannot verify complete removal of the individual's influence from the previously trained multi-speaker model
- New model versions: Mina's recordings will be excluded
- Active public use: Prohibited
- Historical archive: Accessible only for legal and audit purposes
- Open risk: Copies downloaded by third parties and unverified influence in the earlier model version
- Challenge and remedy owner: Named person and institution
- Reuse: Prohibited without fresh, explicit consent
This receipt does not claim perfect reversal. It shows which outcomes the person's wishes actually changed.
Why Is Consent Connected to Human Dignity?
A face, voice, health information and personal history are not merely data. They are connected to people's rights to be recognised, express themselves, determine on whose behalf they speak and choose which relationships they enter. When a system generates new sentences in a person's voice, it does more than run a technical file. It uses that person's presence in society. When an organisation derives a hidden performance score from an employee's speech, it does more than perform an analysis. It changes the meaning of the employment relationship. When a platform treats a user's silence as acceptance, it does more than select a setting.
It interprets a person's decision not to decide in its own favour. Consent is therefore more than data management.
It is the right to state one's own boundaries.
Consent Establishes a Relationship of Trust
A person may knowingly and willingly give an AI system extensive authority. For example: “You may publish the training texts I approve through my avatar for one year, in the six languages and on the internal platforms I specify.” This may be broad yet specific consent. The person may not want to approve every video separately; that too is possible. What matters is that they understand the scope, make a real choice, can change the boundary and see the system respond when they withdraw. Consent does not obstruct autonomy.
It establishes autonomy's legitimate boundary.
Consent in Plain Terms
A person may say “yes”. But if the following questions remain unanswered, the limits of that word are unknown:
- Yes to what?
- For what purpose?
- Using which data?
- In which model?
- For which sentence?
- In which language?
- Through which channel?
- Before which audience?
- For how long?
- With which provider?
- With what degree of reversibility?
Saying yes to the use of one's face is not saying yes to the use of one's voice. Saying yes to recording is not saying yes to a model. Saying yes to a model is not saying yes to new sentences. Saying yes to content is not saying yes to publication. Saying yes to one publication is not saying yes to every future use. And yesterday's yes:
is not stronger than today's no.
When a person says “no”, the system must do more than record it. It must change its behaviour.
ARTICLE 5 — SHORT CONSTITUTIONAL TEXT
In AI systems, consent must be clear, specific, intelligible, freely given, current, demonstrable and withdrawable.
Consent must identify who has authorised the use of which data or element of identity, for which purpose, operation, output, channel, audience, language, country, duration, frequency, provider and derived use. Permission to use a face does not mean permission to use a voice; permission to record does not mean permission for model training; permission for model training does not mean permission to generate content; permission to generate content does not mean permission to publish; a single use does not create a standing mandate; internal use does not authorise public use; and approval in one language is not approval in every language. A person's silence, past conduct, technical access, general acceptance of service terms, employment relationship or permission granted for another purpose cannot be treated as automatic consent to a new high-impact use.
Consent cannot be treated as valid where refusal is not real, uses unrelated to the service or employment relationship are bundled together, material risks are concealed, refusal produces a penalty or a power imbalance prevents the person from choosing freely.
If an operation does not rely on consent, the institution must not ask for token consent; it must explain honestly the action's true basis and limits, and the routes for challenge and review.
A person may withdraw all consent or narrow it in relation to a particular purpose, data, language, channel, duration or provider. Withdrawal must do more than update the central record: it must reach the relevant sub-agents, tools, queues, tokens, memories, providers and scheduled releases. Consent must be revalidated before the relevant high-impact action and again at execution. A queued task cannot carry old consent forward as a permanent right to act. Consent boundaries must be inherited by the models, scores, vectors, synthetic outputs and other derived assets produced from raw data. Changing the form of data or an element of identity does not remove those boundaries.
If complete deletion or reversal from a model cannot be guaranteed technically, that limit must be explained clearly before consent is obtained; effects that remain or cannot be verified after withdrawal must be reported honestly. A person's consent cannot be manufactured by another person, manager, institution, agent or platform. Representative consent is valid only within verified and relevant authority. Withholding or withdrawing consent must never become a means of punishing an employee, customer, applicant or user unfairly, making them invisible, denying them a core service or turning them into a negative profiling signal.
Every person has the right to receive an intelligible receipt for consent they have given and, after withdrawal, to learn which actions stopped, which outputs were removed, which models and external copies remain, and which effects could not be verified.
Consent obtained once is not a blank cheque that legitimises every future action by the machine. When human will changes, the system's behaviour must change as well.
Consent defines the boundaries governing a person's own identity and data. But consent to a particular use does not mean that every agent assigned the task is authorised to carry it out. Mina may permit her face and voice models to be used in specified training. Even then, the content agent may not be authorised to write a new commercial claim, the publishing agent to release it publicly, an affiliate to use the model or a sub-agent to extend consent to another channel. The consent holder has said: “This use is acceptable from my perspective.”
The institution and its agent system must also answer this question:
Who may carry out this specific action, and under what assignment and technical authority?
A person's consent may exist, yet the wrong agent may act. The correct agent may act on the wrong target. A main agent authorised only to draft may instruct a sub-agent to send the material. An action may be treated as legitimate merely because the technical tool is available. The next founding provision is therefore: ARTICLE 6 — AUTHORITY MAY BE DELEGATED; IT CANNOT EXPAND ON ITS OWN

