Half of headteachers have dealt with pupil photos being misused

What happened
Nearly half of headteachers in the UK have had to deal with photographs of their pupils being misused. That finding comes from a survey of 500 UK headteachers by the safeguarding platform Aidos, reported by Schools Week on 7 September 2026. The survey found that 49 per cent of heads had dealt with pupil images being misused, manipulated, or used in blackmail attempts. Fifty-four per cent said they were worried about the images their school publishes. The survey also found that many schools are not reviewing what they put online often enough. Only 34 per cent update their pictures every year. Fifty-two per cent update them every two to three years. And just 43 per cent said their consent processes actually address the risk of AI deepfakes. Behind the numbers is a specific and disturbing case. The Internet Watch Foundation reported that photographs of pupils had been taken from a secondary school's own website and turned, using AI, into child sexual abuse material. Ransom demands were then sent to the school. That case prompted the online harms working group to recommend that schools remove identifiable pupil images from their websites. Charlie O'Sullivan, director of safeguarding at The Collegiate Trust, called the findings harrowing, and said that this is a huge risk, with pictures of children absolutely everywhere. Paul Whiteman, general secretary of the NAHT, and Pepe Di'Iasio, general secretary of ASCL, both asked for more government guidance and cybersecurity support for schools.
Why this matters
For most of the last twenty years, putting photographs of children on a school website has been an ordinary, warm and well-intentioned thing to do. It is how a school shows what it is like. The nativity play. Sports day. The trip to the museum. Parents like seeing it. Prospective families look at it. Nobody set out to create a risk. What has changed is not the photographs. It is what can now be done with them. A few years ago, altering an image convincingly needed skill, software and time. Today it needs neither. Tools that can take an ordinary photograph of a face and generate something else entirely are freely available, and they are fast. That turns a class photo from a nice thing into a raw material. The blackmail element makes it worse. A school that receives a ransom demand is in an appalling position. It has a duty to protect the children involved, a duty to be honest with parents, and no good options. And this is not something schools can solve alone. A headteacher is not a cybersecurity specialist. That is precisely why the leaders of the two main headteachers' unions are asking for national help rather than more local effort.
What the evidence actually says
A few things are worth separating out. The 49 per cent figure comes from a survey of 500 headteachers carried out by a company that sells safeguarding services. That does not make it wrong, and 500 heads is a reasonable sample. But it is fair to note that surveys commissioned by companies working in a field tend to find that the field matters. Read it as a strong signal rather than an exact measurement. The Internet Watch Foundation case is different. The IWF is a well-established charity that works to remove child sexual abuse material from the internet, and its reporting is credible and specific. One genuinely encouraging change: guidance for the new academic year now treats AI-generated sexual images of children as a safeguarding matter in the same way as real photographs. That is the right approach. From a child's point of view, an image that appears to be of them causes harm whether or not a camera was ever involved. Treating it as less serious because it was generated would be a failure. What is still missing is practical support. Advising schools to remove identifiable pupil images is sensible, but it does not tell a small primary school with one part-time office administrator how to audit fifteen years of website archives, newsletters and social media posts.
Practical advice
**For parents.** You are allowed to ask. Every school should be able to tell you what photographs of your child are published, where, and what you agreed to. If you signed a consent form when your child started in reception, you can change your mind. Ask for it in writing. **Ask specifically about names.** A photograph on its own is much less useful to someone with bad intentions than a photograph captioned with a full name, a class and a school. Ask whether your school names children in captions. Many have already stopped. **Check your own posting too.** Schools are not the only source. Family photographs on open social media accounts are just as reachable. Consider whether your accounts are private, and think twice about school uniform in publicly visible pictures, because a uniform identifies exactly where a child is every weekday. **Talk to your child, calmly.** Older children should know that images can be faked, that it is not their fault if it happens, and that they should tell an adult straight away rather than trying to handle it alone. That last point matters most. Shame keeps children silent. **Know where to report.** If a child's image has been misused, the school's designated safeguarding lead should be told. The Internet Watch Foundation takes reports of child sexual abuse imagery and works to have it removed. In an emergency, contact the police. **For school staff.** The survey suggests most schools review images every two to three years. If that is you, a review is probably overdue, and starting with the most visible pages is better than waiting until you can do all of it.
What to know
A survey of 500 UK headteachers found 49 per cent had dealt with pupil images being misused, manipulated or used in blackmail attempts, and 54 per cent were concerned about the images their school publishes. Only 43 per cent said their consent processes address AI deepfake risks, and around half of schools review published images only every two to three years. The Internet Watch Foundation has reported a case where images scraped from a school website were turned into AI-generated child sexual abuse material, with a ransom demand sent to the school. New guidance treats AI-generated sexual images of children as seriously as real photographs. School leaders are asking for more government guidance and cybersecurity support. Parents can ask their school what is published, and can withdraw or change consent at any time. Sources: Schools Week, 'Heads ask for more help on how to conquer misuse of pupil images', 7 September 2026, https://schoolsweek.co.uk/heads-ask-for-more-help-on-how-to-conquer-misuse-of-pupil-images/ | Internet Watch Foundation, https://www.iwf.org.uk/ | Department for Education, 'Keeping children safe in education 2026', https://www.gov.uk/government/publications/keeping-children-safe-in-education--2 This article is for general information about online safety in schools. It does not replace advice from your school's designated safeguarding lead, the police, or another qualified professional.
Related articles

Mission Coastal starts in two seaside towns. Where next?
A new government programme aimed at schools in England's coastal towns has begun, and attention has already turned to where it goes next. The programme is call…

New health and relationships lessons are compulsory from this term
From this term, every school in England has to teach an updated version of relationships, sex and health education, known as RSHE. The Department for Education…

Top A-level grades have slipped in 33 council areas. Most are in the North
Analysis published on 7 September 2026 has found that top A-level grades have fallen in 33 local authority areas since 2019, and that most of those areas are in…
