AI & Automation

You did not just upload a selfie

Editorial Team 5 min read

Everyone is uploading selfies to AI image generators for that 80s look — feathered hair, shoulder pads, the mottled blue studio backdrop. Good trend, impressive tools, no argument from us.

Now imagine the same selfie taken at your desk. A client name on the screen behind you. A project plan on the whiteboard. A colleague in shot who was not asked. You did not just upload a selfie — you may have uploaded part of your workplace to an external service.

We spend a great deal of time talking about what people paste into AI tools. We talk far less about what they photograph — and the camera has quietly become an input device for AI, treated as harmlessly as it always was. The 80s trend is simply the clearest example of it so far.

What is in the frame?

You framed the picture around your face. That is what you were looking at, and it is not all of what you sent.

Screens are the common one — an email subject line, a client name in a browser tab, a dashboard with figures on it. Then paper on the desk, whiteboards that have been there so long nobody sees them any more, name badges, visitor passes, a delivery label with an address. If you are working from home, the photograph is also a photograph of your home. And if there is a child in the background, that is a decision made on their behalf.

The fix costs nothing: crop tightly, or stand against a plain wall.

Whose faces are in it?

A group photograph contains several people’s information, and one of them made the decision.

Most people would not forward a colleague’s photograph to a company they have never dealt with. Uploading a team picture to an image generator is closer to that than it feels — the informality of a trend disguises what is actually happening.

There is a legal dimension to this in most jurisdictions, including India. But the practical test needs no legislation: would you be comfortable telling them you had done it? A hesitation is your answer.

What happens to the image afterwards?

Two separate questions, and they get conflated constantly.

Retention is whether a copy continues to exist. Some services delete images once they are processed. Some hold them for a defined period. Some keep them until you delete them, because the tool maintains a history you can return to. Free and paid tiers often differ, and the same company may treat images differently across its products.

Training is whether your content contributes to improving the model. It is a separate question from retention and may be governed by a separate setting or policy — the answer to one tells you nothing about the other.

Both are answerable in a couple of minutes in the provider’s own documentation, for the specific product and plan you are using. Worth doing once. Worth also noticing that a tool which appeared last week, with a name you had not heard before, has access to your photograph too.

The version that should concern an IT team

Everything above is a personal decision, and adults can make it. The business version is different, because the person taking the risk is not the person carrying it.

An employee takes a photograph at their desk during a quiet afternoon and uploads it. In the background: a client’s name, a project drawing, an internal dashboard, a partially visible email. The employee has done something harmless and enjoyable. The organisation may have sent client information to an external service that nobody had assessed or approved.

Nothing about it is malicious. That is exactly why a policy is more useful than a warning.

If your organisation handles client information under confidentiality terms, the question worth asking is not whether this could happen. It is would we know if it already had? The uncomfortable answer may be no.

What a workable policy looks like

Specific enough to follow, and short enough to remember.

  • Nothing uploaded to an unapproved tool if it shows work information — client names, project material, screens, documents. Where it was taken is not the issue; what is visible in it is
  • Colleagues’ faces only with their agreement
  • A short list of approved tools, so people are not each choosing their own
  • Somewhere to ask, without it becoming a disciplinary conversation

Blocking tools at the network is a legitimate control, and in some environments it is the right one. It is not a strategy on its own — a block without guidance and approved alternatives tends to move the activity onto personal devices, where there is nothing to see.

The last point on that list does more work than it looks like it should. People follow rules they can ask questions about.

Not an argument for avoiding the tools

We build with them, and telling people not to use image generators would be both dishonest and useless.

It is an argument for thirty seconds that currently is not being spent. Crop tightly. Look at the background properly, including the whiteboard. Consider who else is in the picture. Check the retention and training settings once, for the tool you actually use.

If your workplace has no AI policy at all, that is probably the more useful conversation this week.

Common questions

Is this overcautious? It is only a photograph.

For a cropped selfie against a blank wall, yes — go and enjoy the trend. The caution is about what happens to be in the frame, not about the act of uploading. That distinction is the whole article.

What if it has already been uploaded?

Check whether the service lets you delete it, and do that. If it contained client or colleague information, tell whoever handles this in your organisation rather than hoping. Reported early it is manageable; discovered later it is not.

Does a paid account make it safer?

Terms often differ between consumer and business tiers, sometimes considerably. It is not a safe assumption either way — check for the specific product and plan.

Does this apply to AI tools we use for work?

The same questions apply, with one addition: a business relationship usually means a contract governing how data is handled. That is the difference between a tool your organisation has assessed and one someone found this morning.

More on this: when a language model is the wrong tool and should your business use AI for customer support.

Editorial Team

The Concord Technosoft editorial team writes from the work - building software since 2006, and still running much of it. Everything here comes from systems we operate rather than projects we delivered. Where we cite a rule, a rate or a platform policy, we check it first and date it.

Keep reading

More on AI & Automation

AI & Automation

When a language model is the wrong tool

A great deal of what gets proposed as AI work is better served by a database query, and saying so is the fastest way to tell whether your vendor is worth listening to.

5 min read

Tell us what you are building

We will tell you how we would approach it, and whether we are the right fit.