For years, schools have shared photographs of pupils in newsletters, yearbooks and more recently, on their websites too, in order to celebrate sports days, school trips, prize-givings and school performances. Normally, the main question posed to parents was whether or not they were happy to provide permission for their child’s photograph to be published, and that was the most important issue at hand. If the parents said yes, all based were covered.
But, now that artificial intelligence has started dominating just about every sphere of our lives, it’s becoming clear that the questions we’re asking may need to change. A photograph that appears completely innocent when uploaded can now potentially be copied and manipulated using AI, creating risks that traditional image consent policies were never designed to address.
New research from AI image safeguarding company Aidos suggests that schools are becoming more and more aware of the problem, but the secondary issue they’re facing is that they don’t feel prepared to deal with it. They know that there’s a problem, but they don’t know what to do about it.
So, what happens when AI moves faster than the rules and regulations that help schools implement safeguarding to protect the children?
The Growing Risk Of AI Deepfakes
According to Aidos’ “In Plain Sight” report, based on a Censuswide survey of 500 UK headteachers conducted in June 2026, 49% of respondents said that their school had experienced an incident in which pupil images had been misused, manipulated or used as part of an extortion or blackmail attempt. Further to this, 54% of those surveyed said they were personally concerned that images published by their school could be vulnerable to misuse by AI tools, while 45% said their school had received a complaint from a parent or carer about the misuse or potential misuse of a pupil’s image online. Those are incredibly high numbers.
Indeed, it’s becoming clear that general awareness of the threat associated with children’s school images online is also high. In fact, the research found that 93% of headteachers surveyed were aware that criminals were using AI tools to generate deepfake imagery from school websites and social media.
Knowing that there’s a problem that needs to be addressed is an important first step to doing something about it, but awareness is only the first step. Unfortunately, being aware isn’t the same as being prepared, or even knowing how to be prepared.
Only 43% of the educators interviewed said that they would feel very confident knowing exactly what steps to take if their school received a ransom demand involving manipulated pupil images. The problem is, while it doesn’t feel particularly off base that a teacher may not be totally prepared to deal with a ransom situation (because in what world is that something they need to know how to respond to?), unfortunately, this isn’t simply a hypothetical concern anymore.
In May 2026, the UK Safer Internet Centre reported that schools had been given guidance following a harrowing confirmed case in which criminals took photographs from a UK secondary school’s website and social media accounts and used AI to create more than 100 sexual images, which were then used to blackmail the school.
More from Artificial Intelligence
- Can AI Stop Ageing? Inside The Clinical Breakthroughs Delivering Concrete Results
- Experts Are Sounding The Alarm On AI Animal Translation – Breakthrough Tool Or New Form Of Exploitation?
- The Rise of “Agentic Compliance”: Shifting from Policies To Real-Time Guardrails
- Inside Nairobi’s AI Shock: What Happens After AI Wipes Out A 40,000-Worker Economy?
- OpenAI Told Congress It’s Building An Automated Shutdown For AI – How Would It Actually Work?
- The Death of Entry-Level Jobs? AI And The New Corporate Ladder
- Why Is OpenAI Pre-Announcing Astra’s Safety Limits Instead Of Its Capabilities?
- An AI Assistant Just Quoted You A Price. Nobody Checked Whether It Was Real
Have School Safeguarding Policies Kept Up?
One of the most interesting findings from the Aidos research is the gap between consent to publish an image and understanding what could happen to that image once it is online. The Aidos report shows that 85% of schools carry out a risk assessment relating to the online publication of pupil images, but only 43% said their consent process fully addresses the specific risk of AI exploitation or deepfake generation. Worst of all, 16% said their school had no AI or deepfake-specific policy. Essentially, they’re trying their best, but schools just haven’t been able to keep up with evolving AI tech.
So the question is, can parents actually, realistically be giving full informed consent if the risks that are associated with publishing an image aren’t the same as they were when the consent was initially given? Parents may have agreed to their child’s photograph appearing on a school website without considering the possibility that the image could later be scraped and manipulated using AI. Because for many people who aren’t particularly involved in tech and don’t totally understand the nefarious side of AI, this may not even be within the realm of possibilities in their minds.
As Charlie O’Sullivan, Director of Safeguarding at The Collegiate Trust, said in the Aidos report, “As a Director of Safeguarding, my job is to anticipate risk, not just respond to it. We haven’t seen our schools targeted, and I hope we never will. But hope is not a safeguarding strategy, and neither is waiting for a case closer to home before we act.”
It seems like the conclusion many people are beginning to reach is that traditional image consent as we used to understand it simply may no longer be enough on its own, and it’s time to put systems in place to prepare for the worst.
Schools Are Also Sitting On Years Of Images
There’s another problem that needs to be considered here, and that’s about how long photographs remain publicly available. Aidos found that just 34% of schools update photographs on their public-facing websites and social media annually, while more than half of them update them every two to three years, and a small percentage every four to five years. Thus, the result of this is that some schools may have years’ worth of photographs publicly accessible online.
The UK Safer Internet Centre’s guidance recommends that schools consider the risks of sharing identifiable images of pupils and suggests alternatives such as photographs taken from a distance or from behind.
For schools, that could mean thinking not only about what they publish from now on, but what they have already published and made available to the public.
What Can and Should Schools Do?
Unfortunately, there isn’t one solution to the problem, and dealing with these concerns and potential dangers will be a complicated endeavour.
Now, one obvious approach is to simply reduce the number of identifiable photographs published online in the first place. Schools can also regularly review existing images and ask whether they still need to be publicly available, whether children can be identified and whether accompanying information could reveal additional details about them.
Updating image policies and consent processes to specifically address AI-generated manipulation could also help schools and parents understand the risks before photographs are published. That would mean parents would generally understand a little more about what they’re agreeing to regarding their children’s photos.
And technology could play a significant role in the solution, too. For example, Aidos has developed a system that replaces children’s real faces in school photographs with artificially generated identities before the images are published. The company says this means the original child’s identity can’t be recovered from the protected image.
It’s one potential approach, but it’s not the only option. Schools could also simply limit identifiable photography, restrict who can access images and regularly audit their online image libraries. The positive thing here is that the issue is being identified; parents and educators are acknowledging that they don’t really know how to solve the issue; and there are a few potential ways that the issue can be addressed.
The Responsibility Doesn’t Just Sit With Schools and Educators
Schools and parents clearly have a huge role to play in limiting how easily children’s photographs can be accessed, but the responsibility can’t sit entirely with them. After all, it’s all based on technology that’s at the core of this potential risk.
In February, the UK’s Information Commissioner’s Office joined international data protection authorities in warning about the privacy risks of AI-generated imagery depicting identifiable people without their knowledge or consent. The statement highlighted particular concerns about potential harms to children and called on organisations developing and using AI systems to put safeguards in place from the outset.
The UK government has also introduced measures targeting AI-generated child sexual abuse material, including a new offence relating to AI models optimised to create such material.
Meanwhile, the Internet Watch Foundation has documented the growing use of AI to generate child sexual abuse material, demonstrating that this is a broader problem extending far beyond schools.
The Risks Have Changed, So Safeguarding Needs To Change Too
The reality is that schools are dealing with a technology that has developed much faster than many of the policies designed to protect children from it. A photograph from a school sports day might once have been considered relatively harmless once parental consent had been obtained, but sadly, today, that same photograph could potentially become raw material for an AI-generated deepfake.
That doesn’t mean schools need to stop photographing children altogether, but it does mean that “we have parental consent” probably can’t be the end of the conversation anymore, as much as that makes everything significantly more complicated. As Simon Bailey CBE, former National Policing Lead for Child Protection and an adviser to Aidos, said in the report, “These findings show that school leaders know this is happening, and that most do not yet feel equipped to respond to it.”
So now, it’s time to make sure that we’re actively trying to ensure that safeguarding practices catch up with the technology. Because when it comes to children’s images, we’re not only dealing with whether or not a school is allowed to publish a photograph, but rather what could potentially happen to that photograph once it’s out there.
