Advisory
Joint Statement on AI-Generated Imagery and the Protection of Privacy (2026-02-23)
IssuedView on JOIC's website Source document
Summary
This is a joint statement, coordinated by the Global Privacy Assembly's International Enforcement Cooperation Working Group and co-signed by dozens of data protection and privacy regulators worldwide, including the Jersey Office of the Information Commissioner. It addresses the misuse of AI systems that generate realistic images and videos of identifiable individuals without consent, such as non-consensual intimate imagery and defamatory deepfakes, and sets out shared expectations rather than new binding legal rules.
- Legal compliance: AI content generation systems must be developed and used in accordance with applicable data protection and privacy laws; creating non-consensual intimate imagery may also be a criminal offence in many jurisdictions.
- Safeguards: Organisations should implement robust safeguards to prevent misuse of personal information and generation of non-consensual intimate imagery or other harmful material, especially involving children.
- Transparency: Organisations should provide meaningful transparency about AI system capabilities, safeguards, acceptable uses, and consequences of misuse.
- Removal mechanisms: Organisations should offer effective, accessible ways for individuals to request removal of harmful content involving their personal information and respond rapidly to such requests.
- Protection of children: Organisations should implement enhanced safeguards for content depicting children and provide clear, age-appropriate information to children, parents, guardians and educators.
The signatories, including JOIC, commit to sharing information on enforcement, policy and education approaches and call on organisations to engage proactively with regulators. The statement does not create new statutory duties but signals coordinated regulatory attention and expectations that existing data protection frameworks will be applied to AI image and video generation.
Key obligations
- Organisations developing or using AI content generation systems should ensure such systems comply with applicable data protection and privacy laws
- Organisations should implement safeguards to prevent generation of non-consensual intimate imagery and other harmful content, particularly involving children
- Organisations should provide transparency about AI system capabilities, safeguards, acceptable uses and consequences of misuse
- Organisations should provide accessible mechanisms for individuals to request removal of harmful AI-generated content and respond rapidly to such requests
- Organisations should implement enhanced safeguards and provide age-appropriate information to protect children from AI-generated harmful content
Applies to
organisations developing AI content generation systems, organisations using AI content generation systems, social media platforms integrating AI image and video generation