A Marketplace for Faces
In Shenzhen, a platform called ActID has signed up roughly 800 users since launching in March 2026, about 300 of whom have agreed to license their faces to AI-generated "microdrama" studios for 99 to 500 yuan (roughly $15 to $74) per episode, taking a 10% commission. In Chengdu, New Claw — a production house that pivoted into face-licensing after AI disrupted its own business — sets a 500-yuan floor per image specifically to stop producers from racing prices toward zero. Compensation across the sector ranges from $15 to $700 depending on how "distinctive" a face is judged to be. The buyers are producers of China's short-drama industry, which released more than 128,000 microdramas in the first quarter of 2026 alone, over 95% of them using AI in production (Rest of World).
This is, on paper, exactly what China's Personal Information Protection Law (PIPL) and its 2025 facial-recognition rules were built to enable: informed, separate, revocable consent for a category of data the law explicitly treats as sensitive. The question the marketplace is now testing is whether consent captured once, at the point of licensing, can meaningfully govern what happens to a face after it enters an AI production pipeline.
What the Law Actually Requires
PIPL classifies biometric identifiers, including facial data, as "sensitive personal information," which triggers a higher bar than ordinary data processing: a specific and necessary purpose, separate consent apart from a general terms-of-service click-through, and a right to withdraw that must be "as convenient as" giving consent in the first place. That framework was sharpened in the Security Management Measures for the Application of Facial Recognition Technology, jointly issued by the Cyberspace Administration of China and the Ministry of Public Security, which took effect June 1, 2025. The measures require a personal information protection impact assessment before deployment, bar coercing individuals into face verification when an alternative exists, and require processors holding facial data on more than 100,000 people to register with provincial regulators within 30 working days (CAC).
Courts have been willing to enforce the spirit of this regime even where it doesn't map cleanly onto older legal categories. In June 2024, the Beijing Internet Court ruled that an AI face-swapping app had not violated two plaintiffs' portrait rights — the swapped output wasn't recognizably their face — but had violated their personal information rights by collecting and processing their likeness data without separate consent (Global Times). In March 2026, the same court went further, ruling for an actress whose likeness had been AI face-swapped into two episodes of a 44-part drama without her permission. The court rejected the studio's defense that the resemblance was a statistical coincidence, held that infringement occurs "if recognizable by the public" even when the AI output only "slightly differs" from the original, and found the distributing platform liable too, for failing to review content it had both the rights and the technical ability to screen (Beijing Internet Court). The Guangzhou Internet Court alone has handled roughly 700 AI face-theft cases over the past three years (Rest of World).
Where Consent Runs Out
The steelman case for this regulatory architecture is straightforward: facial data is uniquely hard to revoke — you cannot issue yourself a new face the way you can a new password — and a licensing market that pays ordinary people for their likeness, with lawyers on call and infringement monitoring built in, is a more honest and better-compensated arrangement than the alternative, which is studios scraping faces for free and courts sorting out the damage years later. ActID's monitoring function and New Claw's price floor are attempts to build exactly the kind of accountable intermediary regulators want.
But lawyer Yile Deng's assessment of these platforms cuts to the actual gap: "the unclear scope of authorization" means licensing contracts are frequently vague enough that "it's impossible to know who will ultimately use the likeness, or for what purpose," and once uploaded, "users may effectively lose long-term control over how their biometric identity is used" (Rest of World). PIPL's separate-consent requirement was designed for a world of discrete processing events — a company collects your face, for a stated purpose, and you can say no. It was not designed for a supply chain: a face licensed for one microdrama episode can be copied, resold to a second buyer, or folded into a training dataset for a future AI model, and no clause in a 500-yuan licensing agreement can technically prevent that downstream migration once the file exists outside the platform's control.
This is not a reason to abandon consent-based regulation — the Beijing and Guangzhou courts show China's courts are, in fact, willing to punish unauthorized reuse after the fact, which is a real deterrent. But deterrence-after-harm is a weaker instrument than prevention, and a law built around a single consent transaction cannot, by construction, govern a resale chain. The more proportionate fix isn't tighter consent language at the licensing stage — it's binding purpose-limitation and audit obligations on downstream processors, so liability follows the data rather than stopping at whoever collected it first. Until that exists, China's face-licensing marketplaces are a genuinely useful pricing signal for a market regulators haven't finished building rules for.