How to Protect Your Photos From AI Training

How to Protect Your Photos From AI Training

 

How to Protect Your Photos From AI Training

You finish editing a photograph you really care about.

Maybe it took five minutes to shoot and five hours to plan.

Maybe it came from a wedding you spent twelve hours covering.

Maybe you traveled halfway across the country to get it.

Then comes the part photographers have always had to deal with:

putting the image online.

You need a portfolio.

You need Instagram.

You need clients to see your work.

You want people to share it.

But now there is another question attached to the Upload button:

Could this photograph end up being used to train an AI model?

For a growing number of photographers, that question is no longer theoretical. Recent discussions among working photographers repeatedly come back to scraping, AI training, changing platform terms, watermarks, metadata and the uncomfortable reality that once an image is publicly accessible, controlling every copy becomes extremely difficult.

So can you completely stop AI from training on your photographs?

At the moment, the most useful answer is:

Not with one setting, watermark or piece of metadata.

But you can make better decisions about what you publish, how you publish it and what information travels with the file.

Here is a practical approach.

First: Understand What You Are Actually Protecting Against

Several different problems tend to get grouped together under “AI stealing photos.”

They are related, but they are not exactly the same.

A photographer may be concerned about:

  • someone downloading and reposting a photograph;

  • a scraper collecting an image for a dataset;

  • a company licensing photographs for AI training;

  • a generative model learning from an image;

  • another user removing a watermark;

  • AI imitating a recognizable visual style;

  • losing attribution when an image is copied;

  • a client photograph being used outside its intended context.

Each problem requires a slightly different response.

That is why there is no single “AI protection button.”

A visible watermark helps with attribution.

Content Credentials can communicate provenance and AI-training preferences.

A lower-resolution export reduces what you make publicly available.

A private gallery limits who can access a client shoot.

Keeping your RAW files preserves your original master.

Think in layers rather than searching for one perfect solution.

Can AI Companies Legally Train on Copyrighted Photos?

There is not one universal answer, and the law is still developing.

In the United States, the Copyright Office released Part 3 of its AI report in May 2025 specifically addressing generative AI training. The Office concluded that several stages of AI training can implicate copyright owners' rights, while whether a particular use qualifies as fair use depends on the specific facts — including what works were used, their source, purpose and safeguards.

In other words, simply saying:

“It's online, so anyone can train on it.”

is too simplistic.

But so is:

“I own the copyright, therefore no AI system can technically ingest the file.”

Copyright is a legal right.

It is not a technical firewall.

For photographers, the practical question is therefore:

How do I keep as much control as possible over the version of my work that I publish?

This article is practical information for photographers, not legal advice.

1. Keep Your RAW Files and Master Exports Private

Start with the easiest rule.

Do not upload your most valuable version of the photograph unless there is a real reason to do so.

Your RAW file contains far more information than a normal web image needs.

The same applies to a full-resolution TIFF or maximum-quality JPEG prepared for print.

Your portfolio visitor does not need a 45-megapixel master to decide whether they like your photography.

So separate your workflow into:

Master archive

RAW files, high-resolution edits and print masters.

And:

Public version

A properly resized JPEG made specifically for online viewing.

Photographers discussing AI and image theft increasingly describe this as part of their own workflow — publishing smaller web versions while keeping their full-resolution originals private.

This will not prevent an AI system from processing the public image.

But it means the public internet does not automatically receive your best original file.

2. Upload a Web-Sized Version Instead of Full Resolution

This is probably one of the easiest changes a photographer can make.

Before publishing, create a separate export for:

  • portfolio;

  • blog;

  • social media;

  • online galleries.

The exact resolution depends on your website and display requirements.

The important part is not a magic number like 1800 or 2000 pixels.

It is the principle:

Publish enough resolution for the photograph to look good on screen, but do not automatically publish the largest file you own.

In recent photographer discussions, 2000-pixel-class web exports are one example users mention as a compromise between presentation quality and limiting the public file.

Lower resolution is not an AI-training blocker.

A model can still potentially learn from smaller images.

But it reduces the usefulness of a direct stolen copy for high-quality printing, commercial reproduction and some other forms of reuse.

That makes it worthwhile even outside the AI debate.

3. Keep Copyright and Creator Metadata in Your Exports

Metadata is another useful layer.

Depending on your workflow, you can add IPTC information such as:

  • photographer name;

  • copyright notice;

  • website;

  • contact information;

  • usage information.

Photographers have used metadata for years to help identify who created an image, and discussions around AI have made provenance more important rather than less important.

However, understand the limitation.

Metadata does not physically prevent copying.

A platform may process the image.

A screenshot can create a new file.

A person can export another version.

Metadata can be removed.

So think of it primarily as:

attribution + provenance + evidence

rather than:

access control.

Keep it.

Just do not expect it to do a firewall's job.

4. Should You Still Watermark Your Photos?

Yes — if a watermark fits your business and presentation style.

But not because a watermark makes AI training impossible.

It does not.

Watermarks remain useful because they can show:

  • your name;

  • business name;

  • website;

  • copyright notice.

That means when a photograph leaves your website, the image itself may still tell viewers where it came from.

The trade-off is familiar to every photographer.

Make the watermark tiny, and it is easy to crop.

Make it enormous, and it distracts from the photograph.

Current photography discussions show there is still no consensus: some photographers use strong visible marks, while others believe watermarks hurt the viewing experience enough that they prefer not to use them.

The practical approach is to use watermarks where the risk justifies them.

Good candidates for stronger watermarks

Client proofs.

Previews before payment.

Images being sent for selection.

Photography where unauthorized commercial reuse is common.

Better candidates for subtle branding

Portfolio hero images.

Editorial work.

Social posts where presentation quality matters.

Watermarking is a business decision.

It is not a complete AI defense.

5. Start Using Content Credentials

This is one of the more interesting developments for photographers.

Content Credentials are based on the C2PA provenance ecosystem and are designed to attach verifiable information about the origin and history of digital content. C2PA describes them as a way to bind provenance information securely to a piece of content.

For photographers, Content Credentials can include information such as:

  • creator identity;

  • linked social profiles;

  • how the file was created or edited;

  • generative AI information;

  • AI training and usage preference.

Adobe Content Authenticity currently allows creators to add a preference requesting that supported generative AI models not train on or use the content.

That sounds ideal.

But there is an important limitation.

Content Credentials are a signal, not a universal lock

As of August 2026, Adobe says its generative-AI training and usage preference is supported by Adobe Firefly and Spawning.

That means you should absolutely consider adding the preference.

But you should not interpret it as:

“No AI company in the world can train on this image now.”

The ecosystem works only when the receiving service supports and respects the preference.

Still, standards have to start somewhere.

For a professional photographer, adding a machine-readable expression of your intent is better than leaving your intent invisible.

6. Apply Content Credentials Before You Publish

There is a practical detail worth remembering.

Adobe currently states that Content Credentials need to be applied before publishing; they cannot simply be retroactively attached to the copy that is already sitting on someone else's website.

So make them part of your export workflow.

Instead of:

Edit → Export → Upload

consider:

Edit → Export web version → Add provenance/AI preference → Upload

The less you have to remember manually every time, the more likely you are to do it consistently.

7. Content Credentials Should Complement Copyright Metadata, Not Replace It

There is no reason to choose only one.

You can have:

Traditional IPTC copyright metadata

for normal image identification.

And:

Content Credentials

for stronger provenance and supported AI preferences.

And:

visible branding

when appropriate.

These tools solve slightly different problems.

Layering them makes more sense than expecting one technology to solve everything.

8. Consider Glaze — But Understand What It Was Built For

Another tool frequently mentioned in discussions about protecting creative work from generative AI is Glaze, developed by researchers at the University of Chicago.

Glaze modifies an image in subtle ways intended to make AI models perceive the creator's style differently while leaving the image visually similar to a human viewer. Its core purpose is to disrupt unauthorized style mimicry.

That distinction matters.

Glaze is not simply:

“Encrypt this photograph so AI cannot use it.”

The project itself documents limitations and attacks against protective techniques, and its FAQ makes clear that it was originally designed for style mimicry rather than every possible image-to-image or AI use case.

For photographers there is another consideration:

image quality.

Glaze's own guidance notes that stronger protection settings can introduce more visible artifacts, and its researchers specifically recommend beginning with lower intensity for highly detailed images such as high-resolution photographs.

So test it.

Do not process an entire professional portfolio without first looking carefully at:

  • skin texture;

  • fine detail;

  • gradients;

  • noise;

  • sharpening;

  • color transitions.

For illustrators and artists with a recognizable style, Glaze may fit the threat model particularly well.

For a photographer obsessed with pixel-level image quality, the trade-off deserves evaluation image by image.

9. Client Galleries Should Be Treated Differently From Your Public Portfolio

Your artistic portfolio and a client's wedding gallery are not the same type of content.

One exists primarily to be discovered.

The other exists primarily to be delivered.

That means they do not need the same access rules.

For client work, consider:

  • password-protected galleries;

  • expiring links;

  • private delivery;

  • restricted downloads;

  • separate preview and final-resolution files.

This becomes even more important when photographs include identifiable clients, children, private events or sensitive locations.

If an image does not need to be publicly indexed, there is little reason to make it publicly indexable simply because that is the default setting.

10. Check a Platform's Terms Before Moving Your Portfolio There

Photographers increasingly worry not only about unknown web scrapers but also about the services where they intentionally upload images. Discussions frequently ask whether portfolio hosts, cloud services and social platforms can use uploaded material for AI-related purposes.

Before committing thousands of images to a new service, look for:

Who owns the content?

What license do you grant the service?

Does the service discuss AI training?

Is there an opt-out?

Does it apply to public content, private content or both?

Can terms change?

Can you remove your content and account?

Do not rely on a screenshot of somebody's interpretation of the policy from three years ago.

Read the current terms.

AI policies are changing quickly.

11. Be Careful With Old Claims About Specific Companies

This deserves its own section because AI discussions move much faster than many blog posts do.

A claim about a platform from 2024 may be wrong in 2026.

For example, Adobe currently states that it does not use customer Creative Cloud content to train its generative AI models, while separately providing Content Credentials that let creators express training preferences to supported external systems.

So when evaluating a service, use its current policy.

Do not make a major workflow decision based only on an old Reddit screenshot.

12. Keep Proof of Your Original Work

One of the most valuable assets a photographer has is something nobody browsing Instagram possesses:

the complete chain behind the finished photograph.

That may include:

  • RAW file;

  • sequence of surrounding frames;

  • original metadata;

  • edit history;

  • Lightroom catalog;

  • layered PSD;

  • high-resolution master;

  • backup archive;

  • client agreement.

None of these stop scraping.

But they help establish where the work came from.

For professional photographers, proper archiving was important long before generative AI appeared.

AI makes it even more sensible.

13. Don't Publish Sensitive Location Metadata Unless You Need It

Metadata deserves another distinction.

Copyright metadata is useful.

Precise location data is not always something you want publicly attached to an image.

This is especially true for:

  • wildlife photography;

  • private homes;

  • sensitive landscapes;

  • abandoned locations;

  • client shoots.

So do not treat “preserve all metadata” as a universal rule.

A smarter web export can preserve attribution while removing information you do not want to distribute.

14. “Disable Right Click” Is Not Image Protection

You have probably seen portfolio websites that disable right-click saving.

It may stop the most casual visitor.

It does not stop somebody who can:

  • take a screenshot;

  • inspect page resources;

  • access the image URL;

  • use automated tools.

Public Flickr users discussing scraping point out the same basic technical reality: if public images can be fetched through the web, automated collection remains possible.

Use right-click blocking if it fits your site.

Just don't mistake inconvenience for security.

15. An AI Disclaimer Can Still Be Worth Adding

You may choose to state something such as:

No AI training, machine-learning training or dataset use without written permission.

Will that technically stop a malicious scraper?

No.

But that is not the only reason to write it.

It clearly communicates your intent to:

  • clients;

  • licensing partners;

  • other creators;

  • companies;

  • humans who want to reuse the work.

Photographers discussing the problem increasingly mention adding explicit no-AI language alongside opt-out tools and other protections.

A machine-readable preference such as Content Credentials plus a human-readable licensing statement is stronger communication than either one alone.

16. Don't Destroy Your Portfolio Trying to Protect It

This is the uncomfortable part.

A photographer can protect a photograph very effectively by never showing it to anyone.

That is not particularly useful if photography is your business.

Your portfolio needs to:

  • attract clients;

  • show your style;

  • demonstrate consistency;

  • appear in searches;

  • be shared;

  • create trust.

Photographers themselves describe this exact tension: once work is public it is difficult to guarantee that it will never be collected, yet avoiding online publishing entirely can undermine the reason for creating a professional portfolio in the first place.

So the objective is probably not:

Make copying mathematically impossible.

A more realistic objective is:

Publish deliberately and give away no more control than necessary.

A Practical AI Protection Workflow for Photographers

Here is a workflow that makes sense without turning every upload into a security project.

Keep privately

RAW files.

Original full-resolution files.

Layered masters.

Complete client archives.

Create a separate public export

Resize the image appropriately for the website or social platform.

Do not automatically upload the master file.

Add creator information

Include copyright/IPTC information where your workflow allows it.

Add Content Credentials

When supported, attach:

  • creator identity;

  • attribution;

  • AI training and usage preference.

Remember that the preference currently depends on receiving platforms and models supporting it.

Consider a watermark

Use one when the benefit outweighs its visual impact.

Keep private work private

Use password-protected client galleries when public discovery serves no purpose.

Test stronger protection tools

If style mimicry is a serious concern, evaluate Glaze or similar technologies on copies of your images before making them part of your workflow.

Recheck platform policies

Particularly when a service announces changes involving AI or data licensing.

No single step is perfect.

Together, they create a much better position than uploading the original JPEG everywhere and hoping nobody does anything with it.

What Probably Won't Protect Your Photos by Itself

Watermark alone

Useful for branding and attribution.

Not a technical AI-training blocker.

Copyright metadata alone

Useful provenance.

But metadata can disappear from derivative copies.

“No AI” in your Instagram bio alone

It communicates your preference but does not technically enforce it against every crawler.

Lower resolution alone

Limits what you distribute but does not make the image unusable as machine-learning data.

Content Credentials alone

Promising and increasingly useful, but currently respected only by supporting systems rather than every AI model.

Glaze alone

Designed primarily around style mimicry and has documented limitations.

That is why the layered approach matters.

Frequently Asked Questions

Can I completely stop AI from training on my photos?

There is currently no single technical method that guarantees every publicly accessible photograph will never be collected or used by every AI system. Available protections include limiting public resolution, restricting access, preserving attribution, adding Content Credentials and using AI-training preference signals where supported.

Does a watermark stop AI from using a photo?

A watermark can provide visible attribution and discourage some forms of unauthorized reuse, but it should not be treated as a technical barrier to AI training.

Should photographers upload full-resolution photos?

Usually there is little reason to publish a master-resolution file when a smaller version can provide an excellent web viewing experience. Photographers discussing online protection commonly describe keeping originals while uploading smaller web exports.

What are Content Credentials?

Content Credentials are a C2PA-based provenance system that can attach verifiable information about a piece of digital content, including creator information and editing history. Some implementations also support generative AI training preferences.

Can I tell AI models not to train on my photos?

Adobe Content Authenticity currently lets creators attach a request that supported models not train on or use their content. Adobe lists Firefly and Spawning as current supporters of that preference. It should therefore be viewed as an opt-out signal rather than a universal technical block.

Does Glaze work for photography?

Glaze can process photographic images, but it was created primarily to protect artists against style mimicry. Its own guidance notes that high-detail photographs should begin with lower protection intensities because stronger settings can create more visible changes.

Should I keep RAW files?

Keeping your RAW files and original masters gives you a private source file and a documented creative archive while allowing you to publish smaller derivatives online.

Is AI training on copyrighted photographs legal?

In the United States, the answer depends on the circumstances. The U.S. Copyright Office's current analysis says AI training can involve acts implicating copyright rights, while fair-use analysis depends on the facts of each case. Courts ultimately decide individual disputes.

Final Thoughts

Photographers have always lived with a strange contradiction.

You need people to see your work.

But every time you make that work easier to see, you also make it easier to copy.

Generative AI did not create that problem.

It made the scale of the problem much bigger.

The answer is not necessarily to disappear from the internet.

Keep your masters private.

Publish web versions instead of originals.

Preserve attribution.

Use Content Credentials and AI opt-out preferences where they are supported.

Protect client galleries that have no reason to be public.

Use watermarks where they make sense.

And keep paying attention, because both technology and policy are changing quickly.

Most importantly, stop looking for one perfect anti-AI switch.

Protecting photography online is becoming a workflow, not a checkbox.

 


 

Protect Your Workflow in the Field Too: COIRO Terra Dual Camera Harness

Protecting your photographs does not begin only after the files reach your computer.

For wedding, event, travel and professional photographers, the actual working day often means carrying two camera bodies for hours and switching between them constantly.

The COIRO Terra Dual Harness is a genuine-leather dual camera harness designed specifically for photographers working with two cameras during longer shoots. It distributes the camera setup across the shoulders and back while keeping both cameras accessible, allowing photographers to switch between bodies without repeatedly dealing with separate neck straps.

That is particularly useful when your workflow looks like:

one camera + wide or standard lens

and

second camera + telephoto or portrait lens.

Instead of stopping to change lenses every few minutes, both camera bodies remain ready at your sides.

For photographers shooting:

  • weddings;

  • events;

  • sports;

  • travel;

  • documentary work;

  • long professional sessions;

a dual-camera system is less about carrying more equipment and more about keeping the equipment you already use organized and immediately accessible. COIRO currently offers several Terra Dual configurations for different shooting styles, including the standard Terra Dual Harness and dedicated padded variants.

There is a nice connection between digital and physical workflow here:

keep control of your images after the shoot — and keep control of your cameras while creating them.

Älterer Eintrag Zurück zu Nachrichten