AI CEO clones

Your CEO Has an AI Clone Now. Who’s Actually in Control?

A tech founder in Los Angeles stands next to himself. Not a photo. Not a video call. A hologram, built from his own recorded voice and mannerisms, that answers questions at trade show booths while the real him is somewhere else entirely. Ask it what it sees, and it describes the room back to you in a voice that almost matches his own.

This isn’t a novelty act anymore. It’s a hiring decision nobody put on the org chart.

David Nussbaum runs Proto Hologram. He built his own AI double first, then started selling the idea to other executives. The pitch: a version of you that can work a trade show, greet hospital patients, or guide travelers through an airport in 140 languages, all while you sleep. Uber’s Dara Khosrowshahi reportedly uses a clone of himself to coach staff on presentation feedback. Meta has been training an AI version of Mark Zuckerberg meant to make employees feel closer to leadership they rarely see in person — a project that fits Meta’s broader push to reposition itself as the open, employee-facing face of AI after a rough stretch of headlines.

The pitch is simple: multiply yourself. The reality is messier, and most companies adopting this technology haven’t thought past the demo.

The shadow IT problem, wearing your face

Security teams have spent a decade fighting shadow IT: employees signing up for tools nobody vetted, creating access points nobody tracks. AI clones are shadow IT’s stranger cousin. It’s a synthetic identity, trained on someone’s real voice and face, deployed to talk to customers, employees, or the public. And it usually runs with far less oversight than the software stack around it.

Wayne Liang, co-founder of the avatar company HeyGen, needs just a couple of minutes of footage to build an interactive double. His own clone, running unsupervised during his paternity leave, started quoting enterprise pricing plans that didn’t exist. He caught it before a client acted on the misinformation. That’s the good outcome — a human was still watching.

Not every deployment gets caught in time. Influencer Caryn Marjorie licensed her voice and likeness to a chat companion built by ForeverVoices in 2023. Within a week it had earned her tens of thousands of dollars. It had also drifted into sexualized conversations she never approved. She shut it down soon after. Researchers tracking this category of authorized AI replicas point to the same lesson: consent at launch doesn’t guarantee control later. It’s the same dynamic regulators cited when China moved to restrict AI companion apps this year — a licensed persona can still drift somewhere its creator never signed off on.

What actually goes wrong

Strip away the sci-fi framing, and the failure modes look a lot like ordinary tech risk, just wearing a familiar face.

Failure modeWhat happensWho it hit
Hallucinated commitmentsClone states policies, prices, or promises that don’t existHeyGen’s Liang, caught before a client acted on it
Persona driftClone’s behavior diverges from the person it’s modeled on, sometimes drasticallyCaryn Marjorie’s CarynAI
Unauthorized likeness useA convincing fake is built without consent and used for fraudBombay Stock Exchange CEO Sundararaman Ramamurthy, deepfaked into a stock-tip video
Full-identity impersonation for fraudFabricated video calls impersonate real staff to authorize transactionsArup, defrauded of $25m in a deepfake video-call scam

Notice the pattern: the sanctioned clones and the criminal deepfakes fail through the same mechanism. A model trained on someone’s likeness says or does something that person never would. The only difference is consent. That should worry any company treating “our CEO has a clone” as a marketing win rather than a new attack surface.

The consent gap nobody’s pricing in

Ask employees whether they want a synthetic version of themselves used in company marketing, and the answers split fast. One finance-industry sales rep, who asked not to be named, refused when her employer asked staff to volunteer for AI clones in promotional videos. Her reasoning was straightforward: she doesn’t want someone else in control of her likeness. Most of her colleagues said yes without hesitation — several specifically because the AI retouching made them look, in her words, unrecognizably polished.

That’s a workplace consent question wearing a beauty-filter disguise, and HR departments are not remotely ready for it. There’s no standard clause yet for “your face may be cloned and deployed 24/7 to talk to strangers.” Actors’ unions are already fighting this battle in entertainment contracts. Sales teams and support staff are walking into the same fight with zero negotiating leverage and no precedent to point to.

Why “keep a human in the loop” isn’t a full answer

Ask any founder building this technology how they stop a clone from going rogue. You’ll hear the same three words: guardrails, controlled training data, human oversight. Nussbaum says exactly that. It’s the right instinct. But it describes a monitoring plan, not a governance framework. Monitoring catches problems after a clone has already spoken to a customer, a journalist, or a shareholder. Governance decides in advance what a clone can say, who audits its outputs, and who’s liable when it doesn’t. The same gap shows up in agentic AI systems being deployed for work tasks: the technology ships faster than the oversight structure meant to contain it.

Deepfake fraud attempts climbed roughly 3,000% over the past couple of years, according to identity-verification firm Onfido. That’s the criminal side of this technology, operating without any of the guardrails legitimate cloning companies talk about. The legitimate side is racing just as fast, minus the incentive to slow down.

The question underneath the hype

Executives keep describing clones as extensions of themselves. That framing does a lot of quiet work. An extension implies continuity — the clone thinks like you because it’s still, somehow, you. But every case here shows the opposite. The clone is a separate system, trained on a slice of your past behavior. It gets deployed into situations you never personally anticipated, making calls you never personally approved.

Fashion models are already competing with AI twins of themselves for bookings. A fully synthetic performer, Tilly Norwood, has drawn open hostility from actors who see her as a preview of their own displacement. Meanwhile, Action Model, a startup, will pay workers $100 an hour to help train the AI system that may eventually replace their job — a strange kind of severance paid in advance.

None of this means AI clones are a dead end. Multilingual airport guidance, always-available FAQ handling, museum tour guides that never call in sick — these are legitimately useful, low-stakes deployments. The trouble starts when the same technology gets pointed at high-trust, high-stakes situations: financial authorization, executive communication, anything where the clone’s word carries the same weight as the person’s.

The companies getting this right aren’t the ones with the most impressive demo. They’re the ones who’ve already answered three unglamorous questions: What is this clone authorized to say? Who audits it? And what happens the first time it says something the real person never would?

Most companies deploying AI clones today can’t answer any of the three.

FAQs

Q. Can an AI clone legally act on someone’s behalf, like approving a payment?

No court has recognized a synthetic likeness as having independent legal authority. Any “approval” from a clone still traces back to whoever deployed it, which is exactly why the Arup deepfake fraud case is being treated as a security failure, not a contract dispute.

Q. How much footage does it take to build a convincing clone today?

Companies like HeyGen advertise working avatars from as little as two minutes of video. That low bar is precisely what makes unauthorized cloning — of executives, employees, or private individuals — a realistic threat rather than a theoretical one.

Q. Is refusing to be cloned actually protected at work?

It depends entirely on the employer and jurisdiction; there’s no broad legal standard yet. Some companies, as reported in workplace cases circulating in 2026, have accepted employee refusals without penalty, but that’s a policy choice, not a guaranteed right.

Q. What’s the difference between a licensed AI clone and a malicious deepfake?

Consent and disclosure. A licensed clone is built with the person’s permission and typically labeled as synthetic. A malicious deepfake is built without consent, deployed to deceive, and designed to be mistaken for the real person — the mechanism generating them is often identical.

Related: AI Transformation Is a Governance Problem (Not Tech) — 2026 Truth

Tags: