Australia’s eSafety commissioner issued an advisory on July 28 urging schools to review how they share images online, citing a rise in the misuse of school photos. Between January and March 2026, the commissioner received over 100 reports concerning anonymous accounts targeting schools and school staff through misuse of images taken from official school websites and social media accounts. Much of the content, shared on platforms including TikTok and Instagram, involved artificial intelligence (AI)-generated materials depicting both children and school staff, including sexualized deepfake images, face swaps, and other manipulated imagery.
In 2024, Human Rights Watch documented that the personal photos of Australian children, including images posted by schools, had been scraped and used to train AI models. In addition to privacy risks, these practices enable the creation of convincing deepfakes, including sexualized imagery of children, which put children at even more risk of exploitation and harm.
Once online, images shared by schools can be rapidly manipulated and distributed. Photos in data sets used to train AI models can also reveal information that could identify children, including names, events, locations, and schedules. This could expose children to lasting harm, as both the original images and malicious deepfakes created from them can remain accessible indefinitely.
Australia has been considering stronger child data protections rules through the government’s proposed Children’s Online Privacy Code. The draft code, published in March, is expected to be finalized later this year. This code is a critical opportunity to strengthen protections for children’s personal information and require companies to act in children’s best interests in accordance with international human rights law.
The cases highlighted by eSafety underscore the growing risks of a regulatory environment that does not explicitly prohibit the scraping and reuse of children’s images and personal data. As the government moves towards finalizing the code, it should ensure that it explicitly prohibits the scraping of children’s photos and personal data for AI training. It should also prohibit the digital replication or manipulation of children’s likenesses.
Children should not have to worry that photographs shared online by their schools will be scraped, manipulated, and turned into harmful content beyond their control. Australia should make it clear as a matter of law that children’s images are not raw material for AI models.
Facts Only
* The eSafety commissioner issued an advisory on July 28 urging schools to review how they share images online.
* Between January and March 2026, the commissioner received over 100 reports concerning anonymous accounts targeting schools and staff via misuse of images from official school websites and social media accounts.
* Much of the shared content involved artificial intelligence (AI)-generated materials depicting children and school staff, including sexualized deepfake images and face swaps.
* Human Rights Watch documented in 2024 that personal photos of Australian children, including school-posted images, were scraped and used to train AI models.
* Data sets used for AI training can reveal identifying information about children, such as names, locations, events, and schedules.
* Australia is considering stronger child data protections through the proposed Children’s Online Privacy Code, published in March.
* The advisory underscores the risk of a regulatory environment that does not explicitly prohibit the scraping and reuse of children’s images for AI training.
Executive Summary
The eSafety commissioner advised schools to review their online image sharing practices due to increased misuse of school photos. Between January and March 2026, over 100 reports were received concerning anonymous accounts targeting schools and staff using images from official channels. Much of this misused content was shared on platforms like TikTok and Instagram and involved AI-generated materials, including sexualized deepfakes and face swaps involving children and staff.
Human Rights Watch documented in 2024 that personal photos of Australian children, including those posted by schools, were used to train AI models. These practices create privacy risks and enable the creation of harmful deepfakes. Furthermore, images used for AI training can contain identifying information such as names, locations, and schedules, potentially exposing children to lasting harm.
Australia is considering stronger child data protections via the proposed Children’s Online Privacy Code, which is expected to be finalized this year. The advisory highlights a regulatory gap where current rules do not explicitly prohibit the scraping of children’s images or personal data for AI training. The recommendation is that the final code should explicitly ban the scraping and digital replication/manipulation of children's likenesses to ensure children's images are protected from uncontrolled use in AI models.
Full Take
The situation reveals a critical divergence between current digital practices and emerging technological capabilities regarding child data. The core tension lies in the ambiguity of existing legal frameworks when applied to image data used for large-scale machine learning, specifically concerning minors. The pattern observed is that privacy protections lag behind technological capacity; images shared in public or semi-public contexts are treated as readily available raw material unless explicitly regulated against their repurposing by sophisticated technologies like deepfakes and AI training.
This points to a systemic vulnerability where data provenance—knowing where an image came from and how it was used—is being eroded by opaque AI pipelines. The argument that children’s images should not be raw material for AI models is not merely a policy preference but a defense of personal agency; if likenesses can be easily replicated and weaponized, the control over one's identity diminishes substantially. The proposed legislative action must move beyond reactive measures to establish a proactive legal posture, treating the unauthorized scraping and malicious manipulation of children's imagery as inherently harmful data misuse requiring explicit prohibition.
The implications suggest that without strict legal barriers against this reuse, the current environment incentivizes the creation of exploitative content by rendering the source material effectively unprotectable. The missing element in the current discourse is framing this not just as a privacy issue for institutions but as a fundamental human rights matter regarding identity and future autonomy. To move forward effectively, the regulatory framework must explicitly define images belonging to children as protected intellectual property against algorithmic appropriation.
Bridge Questions: What established international human rights frameworks are most directly relevant when addressing AI-generated sexualized imagery of minors? How can the proposed data protection code be designed to actively audit and restrict AI training sets rather than merely regulating data collection? What mechanisms exist to hold AI developers accountable for the propagation of harmful synthetic media derived from personal images?
Sentinel — Human
The text appears to be a synthesized report based on real-world events concerning image misuse, AI training data, and child privacy legislation, exhibiting the argumentative structure of journalistic analysis rather than pure machine generation.
