NEWS & ANALYSIS | SAFETY & HARM
A school photo may begin as a record of belonging. Once it is public, the school may no longer control who copies it, what is learned from it or what it is made to depict.
By Andrew McDonald · Immortal AI
A child smiles beside a mural. A class poses after an award. Students gather for Book Week, a swimming carnival or a cultural celebration.
Schools publish these images for understandable reasons. They recognise achievement, connect families and preserve a community’s history. Parents may have signed a consent form. Nobody involved intended to supply an artificial intelligence system or give a stranger material from which to make a sexualised fake.
Yet those are now documented possibilities.
Australia’s eSafety Commissioner warned schools in July 2026 that the accessibility of AI tools had significantly increased the risks attached to public photos and videos. Between January and March, the regulator received more than 100 reports about anonymous accounts targeting schools and staff. Almost all involved images taken from school websites or social media accounts.
The reported material included AI-generated dance videos, face swaps, memes and fabricated stories about principals and teachers. eSafety has also seen rising reports involving digitally altered intimate images, including sexualised deepfakes affecting children.
This is not an argument that every school photograph will be misused. It is evidence that the old assumptions behind publishing them no longer hold.
Two different risks
The discussion can become confused because two separate processes are involved.
The first is scraping for AI training. In 2024, Human Rights Watch examined a minute portion of LAION-5B, a dataset containing links to 5.85 billion image-and-caption pairs collected from the public web. It found 190 photographs of Australian children across every state and territory. Some captions or file paths identified names, ages, schools, locations or events.
The images included children at preschool, Book Week and a school swimming carnival. One photograph identified two Perth preschoolers by full name and age and named their preschool.
Human Rights Watch reviewed less than 0.0001 per cent of the dataset, so its finding was not a census of all affected Australian children. It was proof that identifiable childhood images, including photographs published by schools, had entered a dataset used in the development of image-generation systems without the children or families knowingly supplying them for that purpose.
LAION later removed the images identified by the researchers from a newer dataset. It had disputed the suggestion that models trained on LAION-5B could reproduce personal data verbatim. Removing a source image from a dataset, however, does not necessarily remove what an already-trained model learned from the earlier version.
The second risk does not require a child’s photograph to have been used in training at all. A person can take an ordinary image from a school page and upload it to a face-swap, image-generation or so-called “nudify” service. The source photo becomes an input for a new fabrication.
eSafety says a person no longer needs advanced editing skills to place a face into a video, invent a scene or generate sexually explicit material from an ordinary photograph. A uniform, caption, location tag or event notice can add identifying information that makes the person easier to trace or target.
The difference matters. Schools should not tell families that every published image automatically trains an AI model. That is not established. They should tell them that public images can be copied, scraped, analysed, redistributed or manipulated in ways neither the child nor the school can reliably reverse.
Consent for a world that changed
Many school image-consent forms were designed for a simpler question: may the school publish this photograph?
That question is now too narrow.
Meaningful consent should distinguish between an internal school system, a password-protected family portal, a printed yearbook, a public website and a social media platform. Those settings have different audiences, different data practices and different levels of control.
A parent who agrees to a class photograph in a private newsletter has not necessarily agreed to their child’s face, name and school being placed on an open social account. A child may also have a view that differs from the adult signing the form.
Consent is not a complete safeguard. People cannot meaningfully consent to risks that are hidden from them, and even careful families cannot control every camera or every public source. But that does not make consent pointless. It makes the quality of the decision more important.
Schools should explain where an image will appear, who can access it, how long it will remain available and whether the platform may analyse, reuse or expose it to scraping. They should offer choices rather than a single all-purpose permission and make withdrawal practical.
The burden should not fall on children
There is a danger in responding to this problem by telling children and parents to share nothing, celebrate nothing and somehow anticipate every misuse.
The person who publishes an innocent school photograph is not responsible for another person weaponising it. The child depicted is not responsible. Harm is caused by the offender and enabled by systems that make copying, manipulation and distribution easy.
Responsibility also sits with institutions.
Schools decide what they publish and how much identifying information accompanies it. Platforms decide whether public material can be scraped, whether generative tools are built into the service and how quickly abusive output is detected and removed. AI developers decide what data they collect, what safeguards they test and whether people can find and remove personal material. Governments decide whether privacy, child-safety and image-abuse laws keep pace.
Good protection therefore cannot consist only of advice to parents. It needs safer school practice, safer platforms, transparent datasets, effective reporting systems and enforceable duties.
What schools can change now
eSafety’s advice is practical rather than absolute. Schools can begin by asking why a photo must be public and whether the same purpose can be achieved with less exposure.
That may mean using secure family portals for identifiable images, photographing from a distance, avoiding names and location details, checking backgrounds and metadata, and publishing fewer close, high-resolution portraits. It also means reviewing old galleries rather than applying a better policy only to future posts.
Schools need a response plan before an incident. Staff should know how to preserve evidence without redistributing harmful content, support the person targeted, contact police where appropriate and report eligible online abuse to eSafety. A reputational response that treats the school as the victim can leave the child or staff member carrying the real harm alone.
Parents can ask a school where images are published, whether public and private uses are separated on the consent form, how withdrawal works and what the school will do if an image is manipulated. Those questions are not an accusation. They are part of informed care in a changed environment.
What remains unknown
No public authority can say how many Australian school images have been scraped into private AI datasets. Human Rights Watch could examine LAION because it was open. Commercial datasets are often opaque.
Nor do the more than 100 reports to eSafety represent the total number of affected schools or people. They concern reports received during one three-month period, and not every reported item was necessarily a sexualised deepfake or involved a child.
Those limits should restrain the headline, not erase the warning.
We know that Australian children’s school and personal photographs have entered an AI training dataset without informed consent. We know that school images are being harvested for AI-assisted impersonation, ridicule and abuse. We know that public posting can reveal far more than a face.
The remaining question is whether institutions will keep treating publication consent as a routine administrative box, or recognise that a school is making a decision about a child’s identity in a system built to copy.
A photograph can still be a celebration. But before a school shares the memory, it should be able to explain who else may receive it, what they may do with it and who will stand beside the child if control is lost.
Principal sources
- eSafety Commissioner: Sharing school imagery in the age of AI
- eSafety Commissioner: School photo posts vulnerable to emerging AI threat
- Human Rights Watch: Australia’s children’s personal photos misused to power AI tools
- Human Rights Watch: 720 Australian and Brazilian children better protected from AI misuse
Editorial note: This article distinguishes documented misuse from risks that remain unquantified. It does not claim that every public school photograph is used to train AI.
AI disclosure: Immortal AI uses AI-assisted research and drafting. Sources, claims, framing and final editorial decisions remain the responsibility of Immortal AI.

Leave a Reply