RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The atlas · 100 retrospective records ↗
School AI Atlas

The atlas / Access & safety

Access & safety / Reference note · Reference note · prepared 16 September 2026

Two regulators tell schools what to do when an image is faked

Australian and UK guidance treat an AI-faked nude as an indecent image and set out what a school, not just a platform, should do next.

Visual for this record: esafety-and-dfe-guidance-on-deepfakes-in-schools
Visual published by assets.publishing.service.gov.uk, shown for identification of the record. Credit: assets.publishing.service.gov.uk · source page ↗ Rights: owner-review-pending.

The classroom note

A school photograph, posted to celebrate a sports day, resurfaces months later altered by an AI tool into a sexualised image of a pupil. No advanced editing skill is required for this any more; consumer apps can now, in the words of Australia's regulator, remove clothing from an image or generate sexually explicit material from an ordinary photograph. Two regulators, not one, have published guidance a school can act on: the eSafety Commissioner's advisory, published 26 July 2026, and England's sharing nudes and semi-nudes guidance, first published in 2020 and updated in March 2024 to cover exactly this kind of image.

What the evidence says

The UK guidance's own definition does the technical work: indecent images include pseudo-images, computer-generated pictures that appear to be a photograph or video, made using photo or video editing software, deepfake apps and generators, or AI text-to-image tools. That places an AI-faked nude in the same legal category as an authentic one. eSafety's advisory sets out what follows in practice: schools should update behaviour and acceptable-use policies to name AI-manipulated content explicitly, and critical-incident plans should cover a fabricated image linked to the school going viral. Both documents are guidance, not statute; eSafety states plainly that not all harmful material can be addressed under the Online Safety Act, especially material targeting adults.

The implementation question

The mechanism a school actually controls is process, not detection. eSafety can issue a legally enforceable removal notice and reports a high success rate regardless of the target's age, but a platform may still decline to act if it judges the content does not breach its own rules, and a removed image can resurface through screenshots or a new account. That gap is why both regulators point schools toward parallel channels: behaviour processes, staff support, and police referral where safety is at risk, rather than waiting on one takedown request to resolve an incident.

What holds and what fails

Posting fewer identifiable images of students, which eSafety recommends schools consider, reduces risk but cannot eliminate it, since images already public elsewhere remain available for misuse. A policy that only mentions sharing images online fails against this specific harm, because the image in a deepfake case may never have been shared by the student at all; the guidance in both countries treats the fabrication itself, not any prior sharing, as the triggering event. Treating a case as solved once a notice is issued or a platform confirms removal is, editorially, premature: support for the person depicted is a separate, ongoing task neither takedown mechanism performs.

  • Do the school's behaviour and acceptable-use policies name AI-manipulated and generated images specifically, not just sharing photos?
  • Does the school's incident plan cover a fabricated image going viral, separately from a genuine one being shared?
  • Who is responsible for supporting the student depicted, once a takedown request has been filed?

Neither regulator promises a fast fix; both are explicit that the platform process is only one part of what a school needs ready before an image is faked, not after.

Sources & reading trail

Sharing school imagery in the age of AI: risks, deepfakes, and how to protect students and staff ↗

eSafety advisory on school-image deepfakes: recommended policy updates, incident-plan coverage, and the limits of takedown notices.

Source published: 26 July 2026 · Retrieved: 16 September 2026

Sharing nudes and semi-nudes: advice for education settings working with children and young people ↗

UK guidance, updated March 2024, defining AI-generated pseudo-images as indecent images requiring the same response as authentic ones.

Source published: Not established · Retrieved: 16 September 2026

Departments, studies and vendor documents establish the record; the implementation reading and the boundary are School AI Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.