Indonesian Political, Business & Finance News

Do not upload photos to AI indiscriminately: the privacy risks

| Source: ANTARA_ID Translated from Indonesian | Technology
Do not upload photos to AI indiscriminately: the privacy risks
Image: ANTARA_ID

Jakarta (ANTARA) - The use of Artificial Intelligence (AI) to edit, enhance, or alter photos is becoming increasingly easy. However, users need to be careful before uploading images because a photo can contain personal information that is not always immediately visible.

Facial photos, identity cards, documents, locations, and even the surrounding environment can become part of the information processed when an image is sent to an AI service. The policies of several AI services also explain that images and files uploaded by users can be categorised as content processed by the service.

So, what are the risks that need to be considered before sending photos to AI?

  1. Faces can become sensitive data

Photos displaying faces carry a greater risk than ordinary images. A face can be used as information to recognise or differentiate an individual, especially when the photo is linked to a name, account, or other personal information. Facial recognition technology itself still faces issues regarding accuracy and privacy. Cases of misidentification using facial recognition technology have even occurred as recently as 2026.

Therefore, users should not indiscriminately upload photos of other people’s faces, especially if those individuals have not provided permission.

  1. Photos can contain personal information without being realised

A photo does not only contain the visible main subject. An image can reveal identity numbers, addresses, work documents, vehicle registration plates, home locations, and other information in the background. The risk becomes greater when photos of documents or personal items are sent to third-party services. The privacy policies of AI services may dictate how user-provided content is collected, used, stored, or processed. For example, OpenAI’s updated privacy policy in July 2026 mentions that user content may include images, files, audio, and video uploaded to the service.

  1. Uploaded photos may be processed by the service

Users need to read privacy policies before using AI services, particularly regarding how data is used and how long it is stored. In OpenAI’s consumer services, for instance, content sent to ChatGPT can be used to improve model performance, depending on user settings. Users also have the option to disable the use of content for training through available privacy settings. This means users should not assume that a photo uploaded to an AI service is automatically used only to generate a single image or a single answer.

No digital system is entirely free from security risks. When personal data is stored digitally, there is always the possibility of unauthorised access, misconfiguration, or leaks. In August 2026, for example, a database containing over 9 million facial images was found to be accessible without authentication. This finding shows that visual data can be a serious target in digital security issues. This case does not mean all AI services are unsafe. However, such incidents serve as a reminder that facial photos and biometric data must be treated as valuable and risky information if they fall into the hands of unauthorised parties.

  1. Photos can reveal locations and habits

Photos taken with mobile phones sometimes contain additional information stored in metadata. Furthermore, the content of the photo itself can indicate a person’s location, residence, workplace, school, or frequently visited places. If such photos are processed by digital services and linked with other information, these fragments of information have the potential to provide a more complete picture of an individual. Therefore, photos showing home addresses, private locations, travel documents, or recognisable environments should not be uploaded indiscriminately.

  1. Photos of others should not be uploaded without permission

Users also need to respect the privacy of others. Uploading photos of friends, family members, children, colleagues, or others to AI services without considering consent can raise privacy issues. This is increasingly important if the photo is used to alter faces, create synthetic versions, or generate new images resembling the person in the photo. The risk relates not only to privacy but also to the possibility of identity misuse or the creation of content that could harm the person involved.

  1. Sensitive documents should be avoided

Photos of National Identity Cards (KTP), passports, family cards (KK), driver’s licences, student cards, employee cards, bank statements, medical letters, or other documents containing personal information should not be sent to AI services unless absolutely necessary. These documents can contain full names, identity numbers, dates of birth, addresses, signatures, and other information used to identify an individual. If the user’s only goal is to ask the AI to read or improve the appearance of a document, unnecessary parts should be masked first.

  1. Users need to understand privacy settings

Before uploading photos, check the privacy policy and data settings of the AI service being used. Note whether content can be used to improve models, how long data is stored, who can access it, and whether users have the option to delete or limit data usage.

A safer way to send photos to AI

Users do not have to avoid AI entirely. Privacy risks can be reduced by being more selective about which photos are uploaded. Steps that can be taken include removing sensitive information from photos, masking the faces of others if not required, covering identity numbers and addresses, avoiding photos of important documents, and checking the privacy policy of the service before uploading images. If a photo is only needed to change the background…

View JSON | Print