Dr. Samir Hayat Khan
24 Aug 2026 9 min read

The missing law of digital identity and post-mortem rights
Death used to be simple, at least in one narrow sense. Once someone's heart stopped, their voice went quiet, their face stopped appearing anywhere new, and their presence in the world gradually receded into memory and record. That certainty is gone. A person can die today and keep talking tomorrow not metaphorically, but literally, through an AI system trained on their old text messages, voicemails, and social posts. Photo albums, voice memos, biometric scans, entire archives of a life lived online: none of it dies when the body does. It just sits there, waiting for someone (or something) to make use of it.
That's the uncomfortable premise behind this piece. The law, as it stands almost everywhere, was not built for this. It assumes a tidy handoff at death: property goes to heirs, rights simply expire, and privacy stops being a relevant concept because there's no one left to have it. Digital remains don't behave that way. They persist, they can be mined, and increasingly they can be reanimated. The internet, in other words, is quietly turning into the largest cemetery humanity has ever built except this one's residents can still be made to talk.
Start with scale, because the numbers are genuinely hard to sit with. Researchers at the Oxford Internet Institute have modeled what happens to a platform like Facebook if current growth patterns hold: by the year 2100, as many as 4.9 billion profiles could belong to people who are no longer alive. Even the most conservative version of that model one where the platform stops gaining new users entirely, starting now — still puts the number above 1.4 billion. Either way, the dead eventually outnumber the living on the platform. That's not a hypothetical far-future concern; it's a trajectory we are already on.
And it isn't just social media, which at least stumbled into this role by accident. Most of what a person owns digitally today never touches a hard drive they physically control. It lives in the cloud, spread across servers run by companies that were never designed to think of themselves as custodians of anyone's legacy. Despite that, almost nothing exists to manage the handover. Wills cover houses and bank accounts; they rarely cover a Google Photos library or a decade of WhatsApp messages.
The gap between what people say they want and what actually happens is stark. A few figures make the point better than any argument could: |
Metric | What the data shows | Why it matters |
Digital Afterlife Industry | Projected to grow from roughly $22B in 2024 to $80B by 2034 | Grief and digital remains are being commercialized faster than any regulation can keep up. |
Digital legacy planning (UK) | 83% of adults have no plan in place | Digital wealth and data are accumulating with no succession or deletion strategy behind them. |
Desire for data erasure | About 1 in 4 UK users want everything deleted after death | There is still no simple, centralized way to honor that wish. |
Legacy contact usage | Only 15.2% of surveyed users have set one up | The tools that do exist are barely used, leaving most accounts in limbo indefinitely. |
Where there's unmanaged data at this scale, there's eventually a business built around it. The Digital Afterlife Industry now covers everything from memorial pages to posthumous data management, but the most unsettling corner of it is AI-based reconstruction: so-called "griefbots" or "deadbots," trained on a dead person's texts, voice recordings, and social media history, built to hold conversations that feel like talking to them again.
These products get marketed as grief therapy, and maybe for some people they genuinely help. But there's no real ethical framework underneath them. When a company takes someone's leftover data and turns it into a product, it is, in a fairly literal sense, deciding what that person gets to say after they can no longer object. Algorithms don't know or care about grief; they just optimize for engagement. That's how a deceased parent's photo can end up in a targeted ad, or how a platform's memory feature can surface a dead friend's face on exactly the wrong day. None of it is malicious, necessarily it's just indifferent, which in some ways is worse.
Nowhere is this fight more visible than in entertainment, where a famous voice or face is worth real money even after the person behind it is gone.
In early 2024, George Carlin's estate sued the makers of a podcast that had used AI to generate an entire "new" comedy special in Carlin's voice and style. The case ended in a settlement: the content came down permanently, and the creators were barred from using Carlin's likeness, voice, or image again without the estate's written say-so.
A strikingly similar story played out in India. After the death of playback singer S.P. Balasubrahmanyam in 2020, the Telugu film Keedaa Cola used AI and deepfake tools to recreate his voice for the soundtrack without asking his family first. His son, S.P. Kalyan Charan, sent a legal notice demanding an apology,damages, and royalties. Buried in that dispute is a bigger warning: if a dead legend's voice can be endlessly synthesized for free, what happens to the living singers competing against an AI copy of someone who can't say no?
It doesn't have to go this way, though. When composer A.R. Rahman used AI to bring back the voices of the late singers Bamba Bakya and Shahul Hameed for a project, his team did something the other cases skipped entirely: they asked the families first and paid them. It's a small example, but it shows the difference between exploitation and consent isn't complicated it just requires someone to bother asking. Robin Williams took a more extreme route, building a trust that legally blocks any commercial use of his name, voice, or likeness until 2039, a full 25 years after his death. That kind of protection works, but it's really only available to people wealthy enough to plan for it. Everyone else is left exposed.
Underneath all of this sits a very old legal idea: actio personalis moritur cum persona a person's right to sue dies along with them. For centuries, that made a certain kind of sense. Courts have generally held that a dead person can't be defamed and can't have their privacy violated, because legally speaking, they're no longer a person capable of holding those rights at all.
That logic falls apart the moment AI enters the picture. Nobody can defame a body in a grave. But a digital replica of that same person can be made to say almost anything endorse a product they'd have hated, back a political position they never held, behave in ways that betray everything they actually stood for while they were alive. The law's old assumption that death ends the possibility of harm simply doesn't hold anymore.
American law handles this mostly through the "right of publicity," and that right looks completely different depending on which state you're in. California has been the most active, with its Section 3344.1 post-mortem statute recently strengthened specifically to address AI-made "digital replicas." Tennessee took its own swing at the problem with the ELVIS Act, aimed squarely at unauthorized AI voice cloning. At the federal level, the proposed NO FAKES Act would create one national standard instead of this patchwork but it's still just a proposal, and nothing comprehensive has actually passed yet.
India's situation shows a different kind of gap. The Digital Personal Data Protection Act of 2023 was the country's first real attempt at comprehensive data privacy law, and it does let a "Data Principal" nominate someone to manage their data after death or incapacity. That sounds like progress, but in practice it's little more than an administrative handoff. The Act says nothing meaningful about post-mortem privacy, doesn't touch the "right to be forgotten" for people who have died, and offers no real answer for what happens when a deceased person's un-nominated data gets pulled into training a commercial AI model. With more and more sensitive documents sitting on government platforms like DigiLocker, that gap isn't just theoretical, it leaves real openings for family disputes and corporate overreach. And if someone dies without naming anyone at all, their digital assets just sit there, governed by nothing more than a company's ordinary, non-transferable terms of service.
The internet's architecture guarantees that dying digitally will soon be a messier, more consequential process than dying physically. If nothing changes, the deceased will keep serving as free raw material for an industry now worth close to $80 billion, with no say in the matter and no compensation for their families. Getting ahead of that means legal systems have to abandon the old assumption that dignity and privacy simply evaporate at death.
What's actually needed is something like a recognized "Post-Mortem Right to Digital Dignity" a legal concept that sits between property law (who inherits the data) and human rights (who gets to protect the person's memory). Just as importantly, the tech industry needs to stop treating legacy planning as an optional setting buried three menus deep. Choosing what happens to your digital self after death should be a standard part of setting up an account, carrying the same weight as writing a will.
Until that shift happens, a person's digital face, voice, and legacy remain, for all practical purposes, unclaimed property owned by whichever platform happens to outlive them. Letting the dead actually rest, in any meaningful sense, means giving them the legal right to finally log off.
1 What happens to your social media accounts when you die? – The Gazette, thegazette.co.uk
2 Are the Dead Taking Over Facebook? A Big Data Approach to the Future of Death Online – ResearchGate
3 Geographical distribution of dead profiles under Scenario A – ResearchGate
4 Four things you might not know about your digital afterlife – BBC Science Focus Magazine
5 First Draft – Scribd
6 Does the Right of Publicity Survive Death in California? – Long & Associates / Aexius
7 Son of legendary singer SP Balasubrahmanyam sends legal notice over AI voice recreation – LawStreet Journal
8 SPB's son sends legal notice to Keedaa Cola team over AI/deepfake voice use – The Indian Express
9 Late SPB's son issues legal notice for AI voice recreation – Times of India
10SPB's voice recreated through AI, family serves legal notice – Hindustan Times
11Protecting Your Digital Legacy With an Estate Plan in the Age of AI – Hays Firm
12They Recreated Maradona with AI to Advertise – Global Esur
13From Postmortem Rights to Digital Replicas: Who Owns a Celebrity's Likeness After Death? – Your Law Article
14NPLC CLAT Tathya, January 2026 – NPLC
15Unnominated Nominees and Digital Legacies: Evaluating India's Legal Framework for Postmortem Privacy – IJFMR
Dr. SAMIR HAYAT KHAN

Founder at BioVitalia Organics | Executive Director at Mira IVF | Mint 30 Under 30 | ET 30 Under 30 | IIM Indore Alumni
Sign in to join the discussion.

Indian criminal courts have, since the mid-1990s, protected survivors of sexual violence from a peculiar demand: that trauma be remembered like an invoice, in perfect order, down to the make of a car or the exact hour of an assault. Courts now accept that delay in reporting and gaps in a victim's account do not, by themselves, indicate falsehood.

Consider a criminal case where there are clear video evidence and distinct audio evidence. This kind of evidence is considered to be very credible. However, what if the evidence is a deepfake?