This is not a niche creator-rights tool. DDT is the consent verification layer underneath every industry that generates, distributes, or monetizes human likeness. The addressable surface is every platform that touches identity-derived media.
Governments across the US, EU, and UK are moving to regulate AI-generated identity content. Every new law creates a compliance requirement. Every compliance requirement needs infrastructure. DDT is building it before the mandate arrives, which means DDT defines what compliance looks like.
| Date | Jurisdiction | Event |
|---|---|---|
| Already in force | New York | Deceased performer digital replica law (S.8391) |
| Already in force | California | AB 1836 / AB 2602 performer consent laws |
| Already in force | India | IT Rules 2026: deepfake labeling + 3hr takedown |
| May 5 2026 | UK | Digital ID consultation closes |
| June 9 2026 | New York | Synthetic performer disclosure law effective |
| June 2026 | EU | AI Act Code of Practice on labeling finalized |
| June 30 2026 | US | SAG-AFTRA contract expires / negotiations resume |
| Summer 2026 | UK | Digital replicas consultation opens |
| Summer 2026 | UK | Creative Content Exchange pilot launches |
| July 15 2026 | China | Interim Measures effective: AI simulating real persons regulated; lawful training data required |
| August 2 2026 | EU | EU AI Act Article 50 transparency obligations enforceable |
| Autumn 2026 | UK | AI labelling taskforce interim report |
| End 2026 | EU | EUDI Wallet deployment mandate |
| End 2026 (staggered) | EU multi-state | EUDI national wallet rollouts |
| 2027+ | India | Performer consent statutory framework expected |
| Ongoing | US Federal | NO FAKES Act; Senate/House committees |
A convergence arrives in June 2026: SAG-AFTRA AI negotiations resume after a pause through June 30, with synthetic performer attribution and the "tilly tax" structure unresolved. The WGA contract expires May 1 with negotiations underway. The New York Digital Replica Act and deceased performer law take effect June 9. The UK digital replicas consultation closes. The UK Creative Content Exchange begins with writing Personality Rights Rules. The EU AI Code of Practice labeling will be finalized.
These threads arrive simultaneously.
Every platform that has consent verification infrastructure in place before that moment is protected. Every platform that does not is exposed, in multiple jurisdictions, under multiple legal frameworks, at the same time.
Every job AI replaces was defined by a skill. Skills can be replicated. But you: your face, your voice, your story, your presence: cannot be replicated without your consent. That is the only thing AI cannot manufacture from nothing.
DDT is the infrastructure that turns individuality into a licensable, auditable, revenue-generating asset. Not for corporations. For the person it belongs to.
When a platform uses your likeness in an AI-generated advertisement, DDT makes sure you are asked, you are paid, and you have a record. When your voice is synthesized for a product you have never endorsed, DDT makes sure there is a consent check; a platform that ignores it creates its own liability. Your identity becomes income. On your terms.
The companies big enough to build this can't afford to. Their businesses are built on owning content: vaults, catalogs, licenses measured in years. That model only works if a yes, once given, stays given. We built the opposite: permission that lives with the person, live, scoped, and revocable in milliseconds. For an incumbent to offer that, they would have to spend their own money rebuilding their own systems in order to devalue their own inventory. Their engineers could do it. No CFO will fund it. They must stay committed to asset sovereignty because their company's future depends on it. That commitment is our moat, and it is not a gap in their roadmap; it is a property of who they are.
Neutrality is the second wall. A platform checking permission for its own AI pipeline is grading its own homework, and a self-issued record is the first thing challenged in any dispute. The rail has to be run by someone with no stake in the answer. The incumbents are disqualified by definition; we are neutral by design.
Timing is the third. Everyone else answers what happened after the content was already used. Identity doesn't work like money: a second of unauthorized exposure cannot be undone. The only check that preserves value happens before the transaction completes, and that is where we sit. When permission can't be confirmed, the rail returns SUSPENDED and the client decides what to do; we never block anything, we make the answer provable.
We filed the architecture before we disclosed it. The patent portfolio is assigned to the company and in active prosecution, US and international, and every verification we sign adds to a record of cleared uses no latecomer can backfill. The moat is giving power to the people whose identities are being mined. We are the Visa of identity. Nobody remembers the first merchant to accept a card. They remember the network.
DDT is not a concept. The Identity Permission State endpoint is answering queries in production today. The three-primitive architecture is operational.
Consent Infrastructure
Every platform shift in history produced one infrastructure layer that became non-negotiable. You didn't choose to use them. The world made them inevitable. That moment is arriving for human identity.
DDT is a real-time permission layer for identity. It enables platforms to verify whether identity-driven content is authorized before it is ingested, generated, or distributed.
What Changed
A New Requirement: Regulation
For the first time, a person's face, voice, and likeness can be synthesized and deployed at scale without their knowledge, without consent, and without any record it happened.
Laws are arriving. State. Federal. International. Every jurisdiction moving on this faces the same problem: the legal requirement exists. The technical infrastructure to fulfill it does not.
DDT builds that infrastructure and answers the only question regulators will ask: was this authorized, and can you prove it?
Compliance is not optional. DDT is how you get there before the lawsuit does.
How it works for platforms
It works the way your browser checks whether a website is safe to visit. A live responder answers: valid or not valid, right now.
For Studios and Rights Holders
Every piece of produced content carries two things that need consent verification: the asset itself, and the people inside it. The asset, meaning the production, the editorial cut, and the digital doubles your teams created, belongs to the studio. The performers' likenesses, voices, and movements inside that asset belong to the performers, and their contracts increasingly require documented consent at the moment of use.
DDT verifies both. The studio's consent record governs the asset: whether it can be distributed, licensed, or ingested by an AI pipeline. The performer's consent record governs their identity within it. Both are queried through the same live system. Both return typed permission states. Both generate signed Verification Receipts. Both can be managed independently, without weakening the other.
DDT does not decide who holds the right to grant permission. That is resolved by contract before content ever moves. DDT answers one question at the moment of use: does permission currently exist, from whoever holds the right to grant it.
We verify the asset and the person inside it. The studio controls one. The performer controls the other. DDT answers for both.
The Unverified World
Every conversation about AI content arrives at the same question: how do you know what is real? The honest answer is that no one reliably does. Detection classifiers decay every time generation models improve, and provenance metadata is stripped in one click. Certainty about arbitrary content is not a product anyone can honestly sell.
DDT answers a different question, the one that holds: is this use verified? A query against our system returns a permission state, and when no consent record exists, that absence is itself the answer. Unverified is a state. It is the state that shifts liability to whoever proceeds anyway.
Payment rails faced this exact problem. The answer was never check detection; it was a network where verified became the standard and unverified became the risk no institution would accept. Browsers never learned to detect malicious sites; they marked unverified ones, and the market did the rest. That is the trajectory of consent verification. As adoption grows, the question stops being whether content can be proven real and becomes whether anyone can prove they had permission.
For the creators enrolled in our system, this is already concrete: their likeness can be recognized in the wild, tagged or not, and checked against their live consent record. For everything else, the system returns the most consequential state there is: unverified.
We do not claim to know what is real. We answer whether it is verified, and we are building the world where that is the question that matters.
Why this helps platforms
The Verification Receipt is a signed, timestamped record that the platform queried, received an answer, and acted on it. That record is the difference between exposure and defense.
When permission is machine-readable and revocable, licensing becomes programmable. Synthetic media, personalized content, and licensed likeness: all viable, all with consent on the record.
NY, EU, UK, and union frameworks all converge on the same requirement: verifiable consent before identity is used. DDT is the infrastructure those requirements converge on.
Ready to get compliant before the mandate arrives?
Early Access