The National Privacy Commission of the Philippines has issued a strict warning that creating, sharing or circulating AI-generated images of real people without consent can lead to legal repercussions, marking a significant shift in regulating synthetic imagery.
The National Privacy Commission has moved to make one point unmistakable: in the Philippines, creating, posting or circulating AI-generated images of a real person without permission can amount to a privacy violation with legal consequences. In a notice issued on August 11, 2026, the commission said synthetic images that depict identifiable individuals may fall within the scope of the Data Privacy Act of 2012, exposing offenders to criminal, civil and administrative liability.
The warning reflects a broader regulatory shift that has been building for months. In February 2026, the NPC joined 60 other data protection authorities in a joint statement on the privacy risks of AI-generated imagery, urging stronger safeguards, transparency and practical ways for people to have harmful content removed. That international statement made clear that realistic synthetic images and videos can be produced without a person’s knowledge or consent, and that organisations building or using such systems should design against misuse rather than treat it as an afterthought.
In its latest notice, the commission framed a person’s face and likeness as personal information under Philippine law. That matters because the data protection regime does not require a bespoke “deepfake law” for enforcement. Instead, the NPC is treating the unauthorised generation of a person’s image as processing personal data without a lawful basis. The notice also points to false personal data where an AI image shows someone doing, saying or appearing somewhere they never did.
The commission said the usual defences of satire, parody, commentary and journalism may still apply, but only within limits. Any synthetic image must be clearly disclosed as such, and the use of a real person’s likeness must be necessary for the stated purpose. The NPC’s position is that a fabricated image presented as authentic loses that protection. The same logic applies more strongly when minors are involved: the commission said complaints concerning AI-generated imagery of children will be treated with the utmost priority.
The notice also has practical implications for platforms and content creators. The NPC said people who believe an AI image of them is being misused can demand removal in writing, file a complaint with the commission and seek compliance or cease-and-desist orders that may then be relayed to online platforms and other agencies. That enforcement stance follows earlier action by the commission, including an October 2025 cease-and-desist order against Tools for Humanity over biometric processing tied to the World App and Orb system, which shows the NPC is willing to act against data practices it views as unlawful. It has also been building policy capacity around generative AI, including a 2025 agreement with Straits Interactive to support research and guidance work.
For users, the message is direct. The casual creation of AI images of friends, celebrities, public figures or relatives is no longer a harmless novelty in regulatory terms. For journalists, artists and educators, the use of synthetic imagery may still be possible, but disclosure and necessity will be critical. For companies, the notice is a warning that fake endorsements, synthetic testimonials and manipulated celebrity images can create privacy exposure as well as reputational damage. The NPC has not yet laid out every enforcement detail, but its latest intervention removes much of the ambiguity: unauthorised AI-generated likenesses are now being treated as a data privacy issue, not just a social media problem.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





