top of page

AI 1980s Photos: Warning on Personal Data Exposure Risks

3 days ago
5 min read

The AI-generated “1980s photo” trend has raised privacy concerns because users often upload clear facial images to third-party platforms without fully understanding how those images are stored, processed or reused. Potential risks include loss of control over personal data, facial-data misuse, deepfake creation, impersonation and more convincing social engineering or online fraud.

An AI-generated retro portrait may take only seconds to produce, but the data used to create it may remain valuable far longer. The main concern is not the visual effect itself, nor AI technology in general, but whether users know where their images are sent, how long they are retained, what purposes they may be used for and whether they can be reused beyond the original request.

For businesses, the trend also highlights a wider governance issue: employees are increasingly uploading personal information, images and sometimes work-related content to external AI services without formal security review.

personal-data-exposure-ai-1980s-photos
Warning personal data exposure from AI 1980s photos

What is happening with the AI 1980s photo trend?

AI image-generation tools can transform a normal portrait into a retro-style image by analysing visual features and recreating the subject with different hairstyles, clothing, colours and backgrounds. The 1980s trend has become especially accessible because users need little or no image-editing experience.

The privacy concern begins when users upload personal photos to services with unclear ownership, retention policies or data-use terms. Vietnamese authorities have warned that facial images may involve biometric-related information and could be collected, stored or reused in ways users do not fully control.

Not every AI service processes images in the same way, and uploading a photo to an AI platform does not automatically mean the data will be stolen. The level of risk depends on the provider, privacy policy, storage practices, permissions and how uploaded content is used after processing.

Why can a portrait reveal more than just a face?

A portrait can contain features that may be processed for facial recognition or identity-related purposes. Unlike a password, a face is a long-term physical characteristic that cannot simply be replaced if it becomes part of a misuse scenario.

The risk also extends beyond the face itself. A photo may unintentionally reveal:

Data visible in a photo

Potential risk

Face

Impersonation, deepfake generation or identity matching

Vehicle licence plate

Linking the subject to a vehicle or location

Company or school name

Inferring workplace or education

Street signs or home details

Narrowing down a person’s location

Identity documents

Increasing identity-theft risk

Children or family members

Expanding information about family relationships and digital identity

A seemingly harmless photo may therefore disclose more than the user intends. Background details can sometimes be combined with public social-media information to infer where someone lives, works, studies or spends time.

This is why photos should be treated as data assets, not just visual content. In digital environments, risk often comes from combining multiple small pieces of information rather than relying on a single exposed record.

IPSIP Vietnam has previously examined how personal data exposed in digital environments can continue to be exploited, especially when separate data points are combined to build a more complete profile of an individual.

What damage can occur if personal data exposure leaves the user’s control?

The most serious consequences may not appear immediately after the image is generated. Facial and contextual data can retain value for impersonation, social engineering and fraud months or even years later.

1. Fake images and deepfake content

Facial photos can be used as raw material for generating multiple visual variations with different expressions, settings or scenarios. This makes images useful in deepfake and synthetic-media workflows.

In malicious scenarios, manipulated content may be used to impersonate a person, create fake social-media accounts, strengthen a fraudulent story or make scam content appear more credible.

IPSIP Vietnam has also discussed how deepfakes can be combined with online fraud techniques. Its analysis of deepfake and online scam risks highlights why businesses should no longer treat video, images or voice alone as sufficient proof of identity.

2. Identity misuse and targeted social engineering

If facial data is combined with a name, phone number, workplace, social-media account or previously leaked data, an attacker may be able to construct a more convincing and personalised fraud scenario.

Sensitive details visible in the frame, including identity cards, dates of birth, addresses, company information, school names or vehicle registration plates, may provide additional context for scams.

3. Loss of control over the data lifecycle

Deleting an image from a phone or social-media account does not necessarily mean every copy held by a third-party AI provider is also deleted.

Different platforms may have different rules on retention periods, service improvement, data sharing or model-related processing. Users therefore need to review the privacy policy of the specific platform they are using, rather than assuming all AI services handle data in the same way.

4. Long-term risks involving children’s photos

Photos of children require additional caution because adults often make the decision to upload them, while the resulting digital footprint may persist until the child reaches adulthood.

The long retention period creates a different type of risk: children may have little or no control over images and associated data shared on their behalf.

WARNING: Do not upload identity cards, passports, private documents, home addresses, vehicle plates, confidential work information or sensitive images of children to AI image-generation tools solely to participate in an online trend. If the application has an unknown developer or lacks a transparent privacy policy, the safer option is not to provide a real personal photo.

What should users and businesses do before uploading images to AI services?

Risk can be reduced significantly when users treat facial photos as information that requires protection rather than merely content for image generation.

Checklist before uploading a photo to an AI tool:

  • Verify the service provider and application developer.

  • Read the privacy policy and terms governing uploaded images.

  • Check whether uploaded data is retained after image generation.

  • Confirm whether users can request data deletion.

  • Do not upload photos containing identity documents, addresses, vehicle plates or internal company information.

  • Limit the use of children’s photos and highly private images.

  • Crop or blur unnecessary background details before uploading.

  • Review permissions for camera, photo library, contacts and location.

  • Do not upload customer, colleague or third-party data without an appropriate basis.

  • For work accounts, use only AI tools approved by the organisation.

For businesses, the response should go beyond simply banning AI use. A more sustainable approach is to establish data-classification rules, approved-tool lists and clear policies defining which types of information must never be submitted to public AI systems.

What does IPSIP Vietnam’s cybersecurity perspective suggest?

If employees apply the same behaviour to corporate information, organisations may expose internal images, customer data, project material or personal information. The impact can extend to compliance, incident response costs, reputation and customer trust.

The AI 1980s photo trend is a practical example of the trade-off between instant convenience and long-term control over personal information. Users do not need to avoid every AI tool, but they should recognise that facial images, background details and associated metadata may have value well beyond a short-lived entertainment trend.

For Vietnamese businesses, the priority should not be to issue a new ban for every viral AI application. A more resilient approach is to establish consistent rules for AI data handling: classify information before use, approve appropriate providers, restrict sensitive data and train employees to review what they are uploading before they click “submit”.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
bottom of page