Advisory
Joint Statement on AI-Generated Imagery and the Protection of Privacy (2026-02-23)
IssuedView on PRIVCOM's website Source document
Summary
This is a multilateral joint statement, coordinated by the Global Privacy Assembly's International Enforcement Cooperation Working Group and co-signed by the Bermuda Privacy Commissioner along with dozens of other data protection authorities worldwide. It expresses shared concern about AI systems that generate realistic images or videos of identifiable individuals without their knowledge or consent, including non-consensual intimate imagery and other harmful content, and sets out non-binding privacy expectations for organisations that develop or use such systems.
- Safeguards: Implement robust safeguards to prevent misuse of personal information and the generation of non-consensual intimate imagery or other harmful content, particularly involving children.
- Transparency: Provide meaningful transparency about AI system capabilities, safeguards, acceptable uses, and the consequences of misuse.
- Removal mechanisms: Offer effective, accessible channels for individuals to request removal of harmful content involving their personal information, and respond rapidly to such requests.
- Protection of children: Address specific risks to children through enhanced safeguards and clear, age-appropriate information for children, parents, guardians and educators.
The statement is expressed as a set of shared principles and a commitment among the signatory regulators to cooperate on enforcement, policy and education, rather than as binding legislation. It does not create new statutory obligations under Bermuda law but signals regulatory expectations and potential coordinated scrutiny of AI image generation practices affecting individuals' privacy.
Key obligations
- Organisations developing or using AI content generation systems must comply with applicable data protection and privacy laws when doing so.
- Organisations should implement safeguards to prevent misuse of personal information and generation of non-consensual intimate imagery or other harmful materials, especially where children are depicted.
- Organisations should provide accessible mechanisms for individuals to request removal of harmful AI-generated content involving their personal information and respond rapidly to such requests.
- Organisations should give clear, age-appropriate information to children, parents, guardians and educators about risks and safeguards relating to AI-generated imagery.
Applies to
organisations developing AI content generation systems, organisations using AI content generation systems