Schools Are Handing Deepfake Criminals a Photo Album

Australia's eSafety regulator is warning schools to stop posting student and teacher photos online after a surge in AI-generated deepfakes built from official school feeds.

ThreatVectr Newsdesk· 4 min read
A large, dimly lit modern office operations centre at night, rows of monitors displaying charts, alert dashboards and data feeds, empty swivel chairs facing the
Share

Key points

  • Between January and March 2025, Australia's eSafety Commission received more than 100 reports of anonymous accounts targeting schools using AI-manipulated images.
  • Nearly all harmful content was built from photos and videos scraped directly from school social media accounts and websites.
  • The eSafety Commissioner confirmed a significant number of cases involved AI-generated child sexual exploitation material traced to school settings.
  • Creating and sharing non-consensual explicit deepfakes is illegal in Australia and carries up to seven years in prison, but not all harmful AI content falls under current law.
  • Experts from UNSW and Curtin University say there is no risk-free way to share images of children online.

Schools post photos to celebrate sports days, highlight drama productions, and attract new enrolments. It is routine. It is also, increasingly, feeding a pipeline for abuse.

Australia's eSafety Commission, the national government body that regulates online safety, released an advisory this week urging schools to rethink that habit. The Sydney Morning Herald first reported the details. Between January and March this year, the regulator received more than 100 reports of anonymous accounts using AI tools to manipulate images of students and teachers. Almost every single case started with photos lifted from an official school social media page or website.

What are these attackers actually doing?

They are taking ordinary school photos and running them through generative AI, meaning software that can fabricate realistic images and video from scratch or alter existing ones. The outputs range from sexualised imagery and fake explicit content to mocking memes and invented stories about named principals.

eSafety Commissioner Julie Inman Grant said a notable share of cases produced AI-generated child sexual exploitation material. "Behind each of these reports are real people, teachers, school staff and students, who are facing humiliation, reputation damage and distress," she said.

Teachers have been targeted with deepfake dance videos that distort their bodies, and fabricated images showing them in sexual situations with colleagues.

Is posting student photos actually illegal?

Posting ordinary school photos is not illegal. Creating and sharing non-consensual explicit deepfakes, however, carries up to seven years in prison under Australian law. The eSafety Commission has also pushed AI-powered "undressing" apps out of the Australian market through industry codes.

The problem is the gap. Inman Grant was direct: not all harmful AI content is covered by the Online Safety Act, particularly material targeting adults. Mocking memes, body-altering videos, fabricated stories about staff members, much of this sits in a legal grey zone.

Manipulation type Who was targeted Covered by current law
AI-generated explicit deepfakes Students and teachers Yes, up to 7 years prison
Sexualised imagery without explicit content Teachers Partially
Mocking memes and fabricated stories Principals and staff Often no
Body-altering dance videos Teachers Often no

What should parents and schools do right now?

Two points from the experts are worth keeping close. First, UNSW Professor Michael Salter put it plainly: "There is no risk-free way to share images and videos of kids online, and particularly kids in school uniform." Second, Curtin University internet studies Professor Tama Leaver said once-a-year consent forms leave families unaware of how broadly their child's photo might travel.

Practically, the eSafety Commission suggests schools verify consent before every post, check who can actually see what they share, and review their privacy settings regularly. Independent Schools NSW advises preferring images taken from behind or at a distance, and avoiding close-up shots of identifiable students.

For parents, it is worth checking your school's current consent arrangement. If your child's photo is publicly visible on a school Facebook or Instagram page, you can contact the school to withdraw consent and ask for those images to be removed.

Common questions

My child's school posts photos all the time. Should I panic?

No, but it is worth reviewing. Ask the school which images of your child are publicly accessible online, and whether you can opt out of public posts specifically without losing newsletter coverage.

Can my child's school be held responsible if images are misused?

Not straightforwardly under current law. The eSafety Commission is pushing schools to act on prevention because the legal remedies after the fact are limited, especially for non-explicit harmful content.

© 2026 Threat Vectr