Article content
In briefShow moreShow lessA large group of privacy regulators issued a joint statement on AI systems capable of creating realistic and harmful images or videos of real people.
- A large group of privacy regulators issued a joint statement on AI systems capable of creating realistic and harmful images or videos of real people.
- The statement addressed both developers and platforms.
- A joint regulatory statement relevant to Norwegian privacy practice; it does not amend the GDPR or itself create a Norwegian statutory offence.
What happened
A large group of privacy regulators issued a joint statement on AI systems capable of creating realistic and harmful images or videos of real people. Concerns included non-consensual intimate imagery and other abusive or misleading depictions.
The statement addressed both developers and platforms. Risk assessment, built-in safeguards, abuse response, protection of children and effective reporting channels must be part of product design and operation.
Legal status in Norway
A joint regulatory statement relevant to Norwegian privacy practice; it does not amend the GDPR or itself create a Norwegian statutory offence.
What the sources clarify
The statement went beyond responding to content already known to be unlawful. It asked developers to assess foreseeable misuse before launch, build safeguards and monitor whether controls worked. Platforms needed an accessible reporting route, rapid response and particular protection for children. Organisations offering or integrating these functions should test attempts to bypass filters, impersonate real people and misuse uploaded images. Responsibility for removal, preservation of evidence and support to the affected person needs to be agreed before an incident occurs.
A launch gate should therefore require documented misuse scenarios, bypass-test results and named response teams. Reporting must be understandable to children and people without an account. The service should measure time to blocking and removal, recurring attack patterns and whether safeguards merely shift misuse to other features or languages.
Practical implications
Product management should require every high-risk misuse scenario to have a technical control, reporting route and measured response time. Tests should be repeated across relevant languages and uploaded media before new image or voice features launch. Serious bypasses should block release until the mitigation is verified.
Sources
European Data Protection Board: “Joint statement on AI-generated imagery,” 23 February 2026.
Datatilsynet: “Joint statement on AI-generated imagery — Datatilsynet copy,” 23 February 2026.
For discussion
Which scenario should we exercise first?







