Professional AI-generated photos: GDPR questions every business should ask

Professional AI-generated photos: GDPR questions every business should ask

Professional AI portrait generators are attracting businesses. But entrusting the faces of your employees to an AI is not a software purchase like any other. Questions to ask.

Professional portraiture is changing hands. A studio photo shoot costs between 100 and 500 euros per person, requires a photographer, a slot, retouching – multiply by the size of a team and you understand why marketing departments look elsewhere. AI portrait generators promise the same result in minutes, for a fraction of the price, with perfect visual consistency between all collaborators. The promise is real: the technology behind it, training specialized broadcast models on photos of a person, now produces portraits that are difficult to distinguish from a studio shoot.

But there is a difference in nature between buying accounting software and sending your employees’ selfies to a service provider to train an AI. This difference is called GDPR, and it is too often discovered after signing.

The face is not data like any other

A photograph is not, in itself, biometric data within the meaning of the GDPR. Recital 51 of the regulation is precise: it becomes precise when it is processed by specific technical means allowing the unique identification of a person. But this is exactly what a portrait generator does: it analyzes facial features in a series of photos to build a model capable of faithfully reproducing that person – and often, it verifies the resemblance of the results using facial recognition techniques.

In other words, a company that generates the portraits of its team potentially triggers data processing falling under Article 9 — the most protected category of the regulation. This does not make the practice illegal: it imposes precise requirements on the consent of employees, the legal basis of the processing, and above all on what the service provider actually does with this data. This is where the differences between market players become gaping.

Shared model or private model: the central question

Not all portrait generators work the same way, and the most important distinction is rarely highlighted on sales pages: are your employees’ photos used to train a model of their own, or do they feed a shared model?

In the first case, each person has a private model, trained only on their own photos, which is only used to generate their own portraits. In the second, the faces of your team help improve a system that benefits all of the service provider’s customers — a processing purpose very different from that for which consent was obtained, and a real risk of dilution of control over this data.

The question deserves to be asked in writing before any commitment. A provider who cannot answer it clearly has already answered you.

Five questions to ask before signing

Where is the data physically stored? “Hosting in Europe” is a marketing formula as long as it does not specify what is stored where: the training photos, the trained model and the generated portraits can live on three different infrastructures, with three different subcontractors.

Who are the subcontractors, by name? Training AI models almost always relies on third-party GPU infrastructures. A serious service provider names them in its confidentiality policy, with their location. A vague or absent subcontractor list is a red flag.

Is deletion implemented, or only promised? Many privacy policies promise deletion of data “upon request.” The real question: Is there an effective mechanism — visible, actionable by the user — that removes the training photos, the trained model and the intermediate facial data? Request a demo. The difference between a contractual promise and an implemented functionality can be seen in thirty seconds.

What happens to the trained model at the end of the contract? The model itself is data derived from the faces of your employees. If it survives termination, your control of the data also ends upon termination.

Are the portraits generated identifiable as such? The issue is gaining momentum with the European AI Act, whose transparency obligations on generated content will apply widely by 2026-2027. A company that displays generated portraits on its site has an interest in knowing what its service provider plans in terms of marking and traceability.

A French specificity not to be lost sight of

France has a culture of professional portraiture that is more demanding than average: the photo on the CV remains a standard, the trombinoscope an institution, and the portrait of managers a communication element in its own right. This culture makes the French market a natural area of ​​adoption for these tools — and therefore an area where these questions of compliance will arise more quickly and more forcefully than elsewhere. French HR and legal departments have the opportunity to be ahead of the curve on a subject which, elsewhere, has not even been identified yet.

Transparency as a purchasing criterion

A clarification of honesty: I manage a player in this market. So I have a clear interest in these questions being asked — precisely because they weed out providers who can’t answer them, and they lift the sector up. Generative AI applied to the human face does not need less polling, it needs more. Companies that adopt it have the power to impose this standard: you just need to ask the questions before signing.

Jake Thompson
Jake Thompson
Growing up in Seattle, I've always been intrigued by the ever-evolving digital landscape and its impacts on our world. With a background in computer science and business from MIT, I've spent the last decade working with tech companies and writing about technological advancements. I'm passionate about uncovering how innovation and digitalization are reshaping industries, and I feel privileged to share these insights through MeshedSociety.com.

Leave a Comment