Identity.org.au editorial · Last updated 3 August 2026
Your likeness is the set of observable characteristics by which other people recognise you: your face, your voice, the way you move and phrase things. For all of human history, likeness was inseparable from presence — to look and sound like you, someone had to be you. Generative models have separated the two. A model trained on photographs and recordings of a person can reproduce their likeness on demand, saying and doing things the person never said or did.
It is worth being precise, because the term is often used loosely. A digital likeness is a reproducible model of how you appear — not a record of anything you did, and not an identity. It is closer to a very good mask than to a passport. The synthetic era's core confusion is that masks have become good enough to pass for passports in systems that only look at faces.
Likeness is not identity
Identity, in the sense that matters to services and to the law, is not how you look. It is the durable link between a person and facts about them: this person is over 18, this person holds this account, this person consented to this action. Likeness is one historical proxy for that link — we recognise faces because for millennia faces could not be forged. When the proxy fails, the link itself does not disappear; it just needs a better anchor.
This distinction is liberating rather than alarming. If identity systems stop treating "looks like you" as proof, then copying your appearance stops being equivalent to stealing your identity. The harm of likeness misuse remains real — reputational, emotional, financial — but the door it opens into your accounts and entitlements can be closed.
A useful mental test: could this check be passed by a very good mask? If yes, it is a likeness check, not an identity check — and in the synthetic era it will eventually be passed by software.
How verification separates the two
Modern verification anchors identity in things a likeness model does not have. First, presence: active liveness challenges require a live body responding in real time, which a rendered face cannot do inside a genuine capture session. Second, hardware: fingerprint and iris capture at higher levels happens inside secure silicon that measures a physical body part, with the device attesting its own integrity. Third, keys and consent: once verified, your identity is represented by cryptographic material bound to your wallet — presenting a proof requires control of the key, not resemblance to a photo.
In the Identity Wallet, your face is used briefly — matched against your document during setup, under liveness challenges — and then the working representation of you becomes a verified credential. Services that rely on the credential are not trusting your appearance; they are trusting mathematics. Someone with a perfect model of your face has none of the things the system actually checks.
Protecting likeness itself
Separating likeness from identity does not make likeness worthless — it remains deeply personal, and systems that process it owe it special care. The commitments that govern this service treat biometric data as the most sensitive category it touches: templates are encrypted on your device before they move, never shared with services, never written unencrypted to the chain, and never sold or traded regardless of consent.
Data minimisation is the other half of protection. Every copy of your face that exists in a database is training material and breach inventory for someone else. A verification system that keeps biometric material out of circulation — deriving results and locking evidence away — shrinks the raw supply from which unauthorised likenesses are built.
What you can do
The deeper story about how these protections became constitutional commitments rather than product features is covered in digital identity and human rights.
- Treat your appearance as public and your keys as private. Assume images of your face exist and can be modelled; protect the credentials and devices that actually authenticate you.
- Prefer services that verify presence, not pictures — a service that accepts an uploaded selfie as proof is accepting your likeness, and everyone else's model of it.
- Use proofs instead of documents where you can. Every document photo you email is likeness plus identity data in one leakable file; a proof reveals neither.
- Know your revocation rights. Consent to biometric processing is revocable at any time, and revocation triggers the deletion schedule.