In January 2026, the Spanish Data Protection Authority (AEPD) published new guidance on the use of third-party images in artificial intelligence (AI) systems, offering a detailed analysis of the visible and invisible risks associated with these practices, which are increasingly widespread in both professional and personal contexts.
In this guidance, the AEPD reiterates that any image or video in which a person is identified or identifiable constitutes personal data, even when the content has been generated or altered using AI tools. Consequently, uploading images of third parties to artificial intelligence platforms or systems—even where the use appears trivial or purely recreational—constitutes the processing of personal data and may give rise to significant legal responsibilities, particularly when carried out without the knowledge or control of the person concerned.
1. Visible impacts
Although many AI tools incorporate filters designed to prevent clearly harmful uses, this does not eliminate all risks. When images of other individuals are used, the potential negative effects may be as serious as—if not more serious than—those associated with real images, particularly where the content is disseminated or taken out of its original context.
In this regard, the AEPD considers that some of the most relevant visible risks relate to the loss of control over the use and dissemination of images. The fact that a photograph appears on social media or has previously been shared does not mean that it may be freely used in AI tools, especially where such use departs from the original context. Moreover, the ease with which this content can be forwarded, copied or removed from context via social networks and messaging services makes it extremely difficult to control who views it and for how long. Even when efforts are made to remove the content, copies, screenshots or reused versions may continue to circulate.
The risk is significantly heightened when generated images attribute to a person actions or behaviours that never occurred but appear credible, when images are manipulated to alter their meaning, or when intimate or sexualised elements are introduced. Such situations may give rise to harassment, blackmail or reputational harm. The use of images of minors, vulnerable individuals or even deceased persons also requires particular caution, as the impact may translate into real harm to the personal, social or professional lives of those affected, as well as serious emotional distress for their close circles.
2. Less visible risks and impacts
Beyond the visible effects of dissemination, the AEPD warns that the mere act of uploading a person’s image to an artificial intelligence system already entails significant risks, even where the use is private, occasional or seemingly harmless. At that point, the image ceases to be under the control of the person concerned and becomes managed by a technology provider, which determines how the content is processed, stored or analysed. In many cases, images may be temporarily retained, generate technical copies or be accessible to different systems and actors, without the affected individual having real visibility over what happens to their image.
In addition, these platforms may use images for additional purposes, such as improving the service or ensuring security, as well as generating metadata and automated analyses that leave a digital footprint. Some tools also allow the repeated recreation of the same individual from a single photograph, increasing the risk of ongoing identification and unforeseen uses. All of this is further compounded by the practical difficulty of exercising rights of erasure or objection, potential security failures or data breaches, and the so-called “multiplier effect”: once an image has been uploaded, it becomes very easy to generate multiple versions, increasing the likelihood of harm arising at later stages.
Which situations are considered particularly relevant by the AEPD?
The AEPD notes that not all uses of images involving artificial intelligence are automatically subject to data protection regulations, particularly when they take place in a strictly personal or domestic context and are not disseminated beyond that environment, nor, as a general rule, when they involve images of deceased persons. However, this does not mean that such uses are free from legal risk, as other rights and legal frameworks beyond data protection—such as the right to honour, privacy or one’s own image—may still be affected.
In this context, the Authority pays particular attention to cases in which the use of images with AI significantly increases the risk to the individual concerned. This includes situations where images are used for professional purposes or publicly disseminated, where the individual loses control over their image, where false but credible content is generated, or where minors or vulnerable persons are involved. Cases involving sexualisation, humiliation or reputational harm, as well as dissemination in high-impact environments, are also considered especially sensitive, as they may seriously affect the reputation, personal life or professional standing of those concerned and, in the most serious cases, give rise to legal consequences beyond the scope of data protection law.
Image: El Referente
↳ Discover more content in the section Insight.
↳ Do you want to stay up today about the sector related news? Follow us on LinkedIn.




