Scrolling through social media, you have almost certainly come across friends sharing AI-generated pictures of what they might have looked like in the 1980s, if your entire feed has not already started looking like a magazine from that decade. The trend, taking the internet by a storm, has also made its way to Moroccan users, with thousands proudly and jokingly sharing their «What would I have looked like if I lived in the 1980s?» portraits.
The images are often shared along with the prompts used to create them, encouraging others to try the trend themselves. But to get the result, users first have to upload a photograph of themselves. The nostalgic hairstyles, clothes and aesthetics may be entertaining, but behind them lies a less visible question: what exactly happens when we hand an AI a photograph of our face? And what happens to that photo afterwards?
«A photograph of a face is personal data because it can be used to identify a person. When it is submitted to an AI service, it is no longer stored solely on the user's phone or computer: it is transmitted to a computer system to be analyzed and processed», cybersecurity expert Youssra El Haddad told Yabiladi.
«We should avoid thinking of AI as a simple 'black box' that transforms a photo and then immediately forgets the data», El Haddad warns.
Communications systems engineer Mohamed Abarray points to another, less visible layer of the exchange. A photograph can contain more information than what appears on the screen. Depending on the file, uploading it «may also transmit metadata such as geolocation, the date it was taken or the type of device used».
For Abarray, the nature of facial information makes its protection particularly important. «If a password is exposed, it can be replaced. A face cannot».
From identity theft to deepfakes
The consequences can become more serious if facial images are exposed through a security breach. Abarray warns that compromised photographs could be combined with other information already available online, including names, dates of birth and social media profiles, to facilitate identity theft or impersonation.
The rapid development of generative AI has also introduced another concern: deepfakes. The same technology that can transform a modern selfie into a convincing 1980s portrait can also generate increasingly realistic synthetic images and videos of real people.
«The more photos of their face a person publishes online, the more material they potentially provide for generating synthetic content», El Haddad explains. This can contribute to risks ranging from fake profiles and manipulated images to reputational harm and deepfakes.
Abarray stresses that the quality and quantity of available images also matter. «Clear, high-resolution photographs, particularly several images showing the same face from different angles, can provide much richer source material for tools capable of reproducing a person's appearance», he says. Such technology can potentially be exploited for fraud, defamation or disinformation, including through fake video calls.
But neither expert argues that uploading a single selfie to an AI platform automatically means that it will be stolen or turned into a deepfake.
«The risk depends on the context, the amount of information available about the person, the security of the service used and the way in which these data could be exploited», El Haddad stresses.
There is similar nuance when it comes to what happens to an image after it has been processed. According to El Haddad, practices vary depending on the provider, the service, the type of account and the user's privacy settings. Some services may temporarily retain images, while others offer options allowing users to restrict how their data is used.
A few precautions before clicking upload
For users who still want to join the trend, the experts recommend first understanding the rules of the service they are using rather than uploading their photos automatically.
Abarray advises users to check whether the platform provides an option to prevent their content from being used for model training and, where such an option exists, to activate it. Users should also look for clear information about how long uploaded content is retained and the options available for deleting it.
He also recommends limiting the amount and quality of facial information being provided: avoiding unnecessarily high-resolution photographs or uploading multiple pictures of the same face from different angles. Photos should not be accompanied by sensitive information such as identity documents, addresses or geolocation data.
El Haddad, meanwhile, highlights an issue that can easily be overlooked when participating in viral trends: other people's privacy. «Avoid submitting photos of other people without their consent» and «be particularly cautious with photos of children», she advises. Where possible, users should also delete conversations and uploaded files once they are no longer needed.
For both experts, however, the answer is not to tell people never to use AI image-generation tools. The broader issue is developing what El Haddad describes as better «digital hygiene».
El Haddad offers perhaps the simplest rule to keep in mind before clicking upload: «If you would not be comfortable with the idea of this photo being retained or reused, think carefully before submitting it to an AI service».
(0)Comments