What specific regulatory frameworks might tackle the infrastructure of datafication and the non-consensual training of AI on human images?

Addressing these issues requires moving past simple bans toward structural oversight. One approach involves establishing strict data sovereignty laws. These rules would grant individuals ownership over their biometric patterns and facial geometry, treating a person's likeness as a protected asset rather than public scrap. Under such a system, scraping an image for a machine learning model without a specific, revocable license would constitute a legal violation.

We also need to mandate transparency in training datasets. Regulators could require companies to publish detailed logs of the data used to build their models. If a company cannot prove they obtained permission for the images in their training set, they shouldn't be allowed to deploy the resulting product. This shifts the burden of proof from the victim to the developer.

Finally, we should reconsider how we classify data at the architecture level. Instead of viewing data as a commodity, laws could treat high-level data processing as a regulated utility. This would force companies to build privacy into their code from day one. By implementing technical standards for differential privacy and federated learning, we can make it harder for companies to extract value from individual identities without direct, traceable consent.