Get consent before you AI-edit or share someone's photo

Get consent before you AI-edit or share someone's photo

Uploading a friend's photo to an AI tool to remove a background, swap a smile, or turn it into an illustration feels like a small, personal edit. For the person in the photo, it can be a much bigger decision they never got to make.

What you should be able to do

The photo being yours to hold does not make every AI edit or new disclosure yours to decide alone when another identifiable person is in the frame. Ask before uploading, materially changing, or sharing their likeness in a new context.

Saved only in this browser.
In this article

Someone has an unflattering group photo from an event and wants to fix it: remove a stranger from the background, swap in a better expression from another shot, turn it into a stylized illustration for a card. Each of these feels like a small, personal editing task. For everyone else in the frame, it is a decision being made about their likeness without them in the room.

What follows is a short, practical consent check for the moment before you upload a photo of someone else to an AI tool - whether the goal is a simple edit, a fun filter, or a full image-generation remix.

Consent, lawful basis, publicity rights, copyright, journalism exceptions, parental responsibility, and a child’s own rights vary by jurisdiction and use. For work, school, care, or commercial contexts, use the organization’s approved process and obtain qualified advice.

Why “it’s just an edit” undersells the decision

Sharing images with AI already covers the data-privacy side of uploading a photo - who might see it, whether it trains a model, whether it belongs in your personal account or a work-approved one. The question here is separate: even when the privacy side is handled correctly, does everyone identifiable in the photo actually want to be edited, generated, or transformed this way at all?

The two questions are genuinely different. A photo can be uploaded to a fully private, non-training-eligible AI tool - privacy handled correctly - and the result can still upset someone who never wanted their face swapped, their expression changed, or their likeness turned into a stylized version of themselves without being asked.

Work through this for anyone identifiable in the photo besides yourself:

  1. Would they be surprised to see this edited version? If you cannot confidently say no, ask first.
  2. Does the edit change something about how they appear - expression, body, setting, who they are next to - beyond a neutral technical fix like cropping or basic color correction?
  3. Where is this going after the edit? A private message to the person themselves is a different request than a public post, a work presentation, or a printed item.
  4. Would they get a say in the final result, or only see it after it is already shared?

If any answer suggests they might object, ask before you upload - not after you have already generated something you now feel invested in keeping.

A person’s consent to be in the original photo is not consent for what AI does to that photo afterward. Someone who was happy to be photographed at a party did not necessarily agree to appear in a stylized illustration, a background-swapped version, or an edited expression that was not their own in the moment.

A short list of edits that need a conversation first

Technical edits such as a background blur, a straightened horizon, or basic cropping may change less about the person than a face or context edit, but uploading the photo to a new service is still a separate data-use decision. The following transformations change the depicted person or context and need a direct conversation first:

  • Changing an expression - swapping in a smile, closed eyes to open, from a different photo or generated entirely.
  • Changing a setting or context - placing someone somewhere they were not, even for a fun or harmless-seeming reason.
  • Stylizing or “AI-ifying” someone’s likeness - a cartoon, an art-style filter, an age-progression or de-aging effect.
  • Combining or removing people from a group photo.
  • Anything going to a public account, work materials, or beyond a small trusted group.

A useful shortcut: if the edit changes something about the person rather than the photo’s framing or quality, ask.

What to do when you cannot ask

Sometimes the person is not reachable - an old photo, someone you have lost touch with, a public figure in a crowd shot. In those cases, treat the absence of consent as a reason for more caution, not less: keep the use private, avoid identifying details in captions, and skip edits that change how the person appears rather than just cleaning up the image. When in doubt, choose the version of the edit that would be least likely to embarrass or misrepresent someone who is not there to object.

Children need an extra layer

If the photo includes a child, involve the person with parental responsibility where the law or setting requires it and seek the child’s age-appropriate assent rather than treating the child as having no voice. Capacity and legal consent rules vary, but safeguarding should become stricter, not weaker, when a child is identifiable. Child privacy in AI products and the family AI agreement cover household norms; school, care, work, and commercial uses need their own approved process.

A worked example

A cousin has a group photo from a family dinner and wants to smooth out lighting and remove a shopping bag before printing it as a gift. The visual change is limited, but uploading the group to a new third-party service is still a new disclosure. The cousin checks the service’s data terms and asks the identifiable people before uploading. Compare that with turning everyone into illustrated caricatures and posting the result publicly: the transformation and audience are broader, so the request must describe both before anyone agrees. The technical steps may look similar from the tool’s side; the consent scope is different.

Authoritative privacy and child-rights anchors

In EU contexts, a photograph of an identifiable person can be personal data; start with the EDPB SME data-protection guide, the GDPR’s lawfulness requirements, and its provisions on children’s consent for information-society services. The UK ICO’s current school-photography guidance is a useful example of the distinctions an organization must make: an identifiable photo is usually personal data, the organization needs a lawful basis, children require particular care, and consent is not automatically the right lawful basis. For children, also use UNICEF’s child online-protection guidance and the UN Convention on the Rights of the Child. These sources do not create one universal consent rule for every photograph; apply the law and safeguarding policy for the actual context.

If you generate something and someone objects afterward

Take the objection at face value rather than defending the edit’s intent. Stop further sharing, delete copies you control, use the platform’s takedown or deletion process for copies you posted, and explain honestly if backups, recipients, screenshots, or platform retention mean complete recall cannot be guaranteed. Do not re-upload a similar edit of the same person without asking directly first. Good intent at the time of making something does not change how it affects the person who did not want it made.

A note on group photos and mixed preferences

Group photos are the hardest case, because different people in the same frame can reasonably want different things - one person is fine with any edit, another would rather not appear in an AI-stylized version at all, and a third has not thought about it. When preferences conflict, default to the most cautious person’s comfort level rather than a majority vote; the cost of asking twice is small, and the person who would have objected has no way to un-see a version of themselves that already circulated.

Where this connects

If the edit involves a realistic transformation of someone’s likeness - not just a filter, but something that could be mistaken for an unedited photo or video - the broader provenance and disclosure questions in synthetic media provenance and consent apply on top of this consent check. If you are exploring image generation tools generally, AI image generation 101 covers the practical tool and prompting side. And if you ever discover someone has generated or edited an image of you without asking, the adult deepfake first-response plan covers what to do next.

Common pitfalls

  • Assuming a private or funny intent makes consent optional. Intent does not change what happens once an image exists and can be reshared.
  • Asking after generating instead of before. People are less likely to say no to something already made and shown to them, which defeats the point of asking at all.
  • Treating “they didn’t complain” as consent. Silence is not agreement, especially from someone who may not want to make it awkward.
  • Skipping the check because the photo is old or the person is out of touch. Unreachable is a reason for more caution, not a loophole.

Try it this week

Before your next AI edit of a photo that includes someone else, run the four-question check above, and ask directly if there is any doubt. Use the photo consent checklist to make the thirty-second habit stick.

Read next

Continue through the same learning path with the next practical articles.