AI Regulation Tracker / Regulator advisory
Public photo galleries are being harvested for AI deepfakes, Australia's eSafety warns
The advisory published on 28 July 2026 is guidance, not law. What makes it worth an hour of anyone's time is the part that is law: which altered images a regulator can force off a platform, and which ones it cannot touch.
What did eSafety publish, and does it bind anyone?
An advisory. Not a code, not a standard, not an enforcement notice. In eSafety's own words, the threat "has prompted eSafety to publish a new Online Safety Advisory ... to help schools make safer posting decisions and to have action plans in place to respond when images are misused." A school that reads it and does nothing has broken no Australian law by that fact alone.
Two things in the same news cycle do bind, and they bind technology companies rather than schools. eSafety's industry standards, which the release says address AI-generated deepfakes and de-clothing apps, "place clear obligations on technology companies to detect and remove this material quickly," and "companies can face penalties of up to $54.6 million for non-compliance." That ceiling attaches to the standards, not to the advisory, and it is not a penalty anyone incurred this week. The second binding piece is the removal power, and that is the one an institution can actually use.
What do the reported numbers actually say?
The figure being quoted is 100, and the denominator matters more than the number. eSafety's statement is specific: "Between January and March this year, we received more than 100 reports about anonymous accounts targeting schools and school staff, including AI-generated dance videos, face swaps, memes and fabricated stories about principals and teachers. Almost all involved imagery harvested from school social media accounts or websites."
One quarter, one country, counting reports about anonymous accounts targeting schools and school staff. Not a count of deepfake incidents generally, and not a count of victims. The advisory adds that many came through the Adult Cyber Abuse Scheme, because the content was seriously harmful even without intimate imagery. That tells you where the volume is landing: on staff, through the adult pathway, not only on students.
Two other figures are in the primary. eSafety says that last year it saw twice as many reports from under-18s about digitally altered intimate images, including deepfakes. And it says that as a result of its action over the past year, seven of the most widely used nudify services in Australia, previously visited hundreds of thousands of times a month, have either withdrawn access or taken measures to comply with the Online Safety Act. The release names none of them, and neither does this article.
eSafety also states that it knows of "a significant number of recent cases involving AI-generated child sexual exploitation material (deepfake image-based sexual abuse) occurring in school settings." No school and no individual is named in the primary, or here.
Which part of the scheme actually binds, and which part is advice?
This distinction decides what an institution does when an image surfaces, so it is worth stating in the regulator's own terms.
Under the Online Safety Act, image-based abuse means sharing, or threatening to share, an intimate image without consent, and eSafety states that it "includes fake or altered nude and sexual images or videos." For that category eSafety says it "can issue a legally enforceable notice to remove this material" and reports a high success rate "regardless of the age of the person targeted." That power reaches synthetic material.
Outside it, the position changes. eSafety writes that a non-sexual deepfake, such as a face swap, a fake dance video or a harmful meme, "may still cause deep distress" but "may fall outside the legal criteria" for child cyberbullying, image-based abuse or adult cyber abuse, "because the threshold for adults is higher than for children." The Commissioner puts it bluntly in the release: "School communities should be aware that not all harmful material can be addressed under the Online Safety Act, especially material that targets adults." eSafety adds that it cannot remove an account simply because the account is anonymous, or because it is believed to belong to someone under 16.
Behind each of these reports are real people, teachers, school staff and students, who are facing humiliation, reputational damage and distress.eSafety Commissioner Julie Inman-Grant, media release, 28 July 2026
How does the reporting route work in practice?
The advisory sets out an order of operations, and the order is deliberate.
Evidence first. eSafety says to collect it before reporting or blocking an account, where safe to do so: screenshots or screen recordings, the account name and handle, the platform and URL, dates and times, captions, comments and direct messages, and any response from the platform. One limit overrides all of that. "Never save, share or redistribute nude or sexual images or videos of anyone under 18." Keep access to the evidence tightly held, because broad internal circulation re-exposes the affected person.
Report second. eSafety says that in many cases it is best to report the content or account to the service where it appears, using the reporting links in the eSafety Guide. Online harm can also be reported to eSafety at esafety.gov.au/report.
Then plan for the content to come back. A platform may decline removal because the material does not breach its rules, especially where it is not sexual, and a post may be republished through screenshots, reposts or a new account. Keep affected people informed, record the new material, reassess.
Where does this leave a US organisation that publishes photographs?
An American school district, paediatric practice, youth sports body or university communications team has the same exposure and a different set of levers. The mechanics travel: publicly posted, identifiable images of named people are the input, and the removal pathway is narrower than the harm.
The comparison below runs on the axis that matters at eight in the morning when a fake video is circulating. Who can be made to take it down, on whose application, and what falls outside.
| Instrument | Who owes the duty | What it reaches | Who can trigger it |
|---|---|---|---|
| Online Safety Act 2021 (Australia), image-based abuse scheme | The service hosting the material | Sharing or threatening to share an intimate image without consent, including fake or altered nude and sexual images | eSafety, by legally enforceable removal notice, after a report |
| eSafety industry standards (Australia) | Technology companies | The most harmful content, including AI deepfakes and de-clothing apps used to create explicit material depicting children | eSafety, with a penalty ceiling of $54.6 million for non-compliance |
| This advisory (Australia) | Nobody. It is guidance | Publishing practice, consent, governance and incident response in schools | Nothing. No notice, deadline or penalty attaches |
| TAKE IT DOWN Act (United States, federal) | Covered platforms | Nonconsensual intimate images including AI deepfakes, notice-and-removal, per this tracker | The depicted person or a representative, by request to the platform |
The pattern is the same across all four rows. The duty sits on the platform. The organisation that published the source photograph is not the regulated party anywhere on this list, which is why an advisory rather than a rule is the instrument being used on it.
What should a communications team change this week?
What follows is implementation guidance, addressed to the reader. It is drawn from the advisory's own checklist and it is not a legal requirement in the United States or in Australia.
- Audit what is already public. The advisory asks whether archived pages and past posts still need to remain up. Most organisations have never asked. A staff headshot directory and a decade of event galleries are the highest-yield thing you will take down all year.
- Strip the identifiers, not just the faces. eSafety flags names in captions, uniforms, location tags, timetables and event details, and notes that a post revealing a child's name, school, location, interests or routine may help someone target them.
- Fix the consent record. The test is whether consent is active, informed, current, and whether it covers social media. A release signed at enrolment for a printed newsletter is not that.
- Name the owner. Who may post, who approves, who moderates, how consent is recorded, what reviews older material. If the answer is a shared login, you have no process.
- Write the incident plan first. Evidence, platform report, eSafety report, family communication, republication. Decide now who may see the material, because forwarding it around the leadership team is the wrong default.
- Treat staff-targeted abuse as a workplace matter. eSafety frames it as a wellbeing and workplace issue and points to employee assistance programs. It is where the adult-pathway reports are landing.
Frequently asked questions
Is the eSafety advisory legally binding on schools?
No. It is an Online Safety Advisory, which is guidance, published to help schools make safer posting decisions and to have action plans in place when images are misused. The binding obligations here sit under the Online Safety Act 2021 and fall on technology companies, not on the organisation that published the original photograph.
How many reports did eSafety receive, and over what period?
eSafety states that between January and March 2026 it received more than 100 reports about anonymous accounts targeting schools and school staff, including AI-generated dance videos, face swaps, memes and fabricated stories about principals and teachers. Almost all involved imagery harvested from school social media accounts or websites, and many were made through the Adult Cyber Abuse Scheme.
What can eSafety actually compel a platform to remove?
For image-based abuse, which the Online Safety Act defines as sharing or threatening to share an intimate image without consent and which includes fake or altered nude and sexual images, eSafety states it can issue a legally enforceable notice to remove the material and reports a high success rate regardless of the age of the person targeted. A non-sexual deepfake such as a face swap or a harmful meme may fall outside the legal criteria, because the threshold for adults is higher than for children.
Where do reports go?
eSafety directs people to report the content or account to the service where it appears first in most cases, using the reporting links in the eSafety Guide, and to report online harm to eSafety at esafety.gov.au/report. Collect evidence such as screenshots, account handle, platform URL, dates and times before reporting or blocking. Nude or sexual images of anyone under 18 must never be saved, shared or redistributed.
Last verified: July 28, 2026
What this piece declines to say: eSafety names no service, no school and no individual in either document, so neither does this article. No penalty has been reported against any company in connection with this advisory.