For years, the standard advice for protecting your location privacy in photos was straightforward: strip the metadata. Every digital photo contains a block of EXIF data — short for Exchangeable Image File Format — that can include GPS coordinates, the timestamp, the device model, and other technical details from the moment the shutter fired. Social platforms strip EXIF when you upload. Privacy-conscious users do it manually before sharing. It’s the established baseline for location privacy in photos.
That baseline is no longer sufficient.
A category of AI tools can now analyze the visual content of a photo — its architecture, vegetation, road markings, light quality, soil type, sky characteristics, and dozens of other environmental signals — and identify where the photo was taken. No GPS coordinates required. No metadata at all. Just the image itself.
How Visual Geolocation Works
The most discussed tool in this category is GeoSpy, developed by Graylark Technologies. Feed it a photo — any photo — and it analyzes visual cues that humans use to recognize places: the style of building construction, regional plant species, the angle and quality of sunlight, the style of road markings, the typography on signs, the color of soil visible in the frame.
These signals are compared against a large training dataset of geolocated images. The result is a location estimate — sometimes a city, sometimes a specific neighborhood, sometimes accurate to within a few meters.
GeoSpy is built on a category of AI called Vision-Language Models (VLMs). These systems are trained to describe and interpret images at a level of detail that goes well beyond what older computer vision could achieve. Where previous systems might recognize “a tree” or “a building,” VLMs can recognize architectural styles associated with specific cities, vegetation species native to particular regions, and infrastructure details that narrow location to small geographic areas.
The privacy implication is that the information you scrubbed from the file — your location — is still present in the image itself. The pixels encode it, and AI can read it.
What It Was Designed For
Graylark marketed GeoSpy to law enforcement and intelligence agencies. The pitch was OSINT — open-source intelligence — specifically for identifying locations of unknown images in investigations. Finding where a photo was taken without a GPS coordinate has legitimate investigative uses: identifying where a hostage photo was taken, verifying claimed locations in documents, geolocating content in legal proceedings.
That intended use is straightforward. The problem emerged from access.
When GeoSpy was made available to general users, the investigative use case was joined by others. Following a 404 Media investigation documenting misuse — specifically reports of individuals using the tool to determine the locations of people they were tracking — Graylark restricted access. The Pro version, which achieves accuracy down to a few meters, is now reserved for verified law enforcement and professional organizations.
However, GeoSpy is not the only tool with this capability. Similar functionality has been incorporated into broader VLM systems that remain publicly accessible. The restriction on one product doesn’t eliminate the underlying capability from the broader AI landscape.
Who Is at Risk
The most direct risk is for people in situations where sharing photos publicly creates personal safety concerns:
People experiencing stalking or harassment. A social media post containing a photo taken near your home, workplace, or regular routes can provide location information even when all metadata is stripped. AI geolocation can potentially infer your address or neighborhood from a photo you considered safe to share.
Survivors of domestic violence. Photos posted on social media or sent to trusted contacts who share them further could be geolocated by someone with harmful intent.
Public figures who want to maintain separation between their public and private lives. A photo taken at home or in a private location, shared publicly or semi-publicly, can reveal home location even if no address or location tag is attached.
Journalists, activists, and humanitarian workers. People in locations where physical security is connected to location secrecy face elevated risk from any capability that can infer location from visual content.
Anyone who has posted photos casually over years. A collection of photos containing consistent background environments — the same trees, the same architecture, the same street — can be cross-referenced to build a picture of where you spend time, even if no individual photo pinpoints a specific address.
What EXIF Stripping Actually Protects Against
This is worth being precise about, because the guidance hasn’t caught up with the technology.
Removing EXIF metadata prevents someone from directly reading the GPS coordinates embedded in a photo file. That is still worth doing. Many people who try to geolocate photos start with EXIF, and removing it prevents the easiest attack.
What EXIF stripping does not do is alter the visual content of the photo. The architectural details in the frame, the vegetation, the infrastructure — these are part of the image data itself, not the metadata. Stripping EXIF leaves them intact.
The analogy is removing a label from a bottle that clearly identifies the product by sight. The label is gone. The contents are unchanged.
What Actually Reduces Visual Geolocation Risk
No technique fully eliminates the risk from sophisticated AI geolocation, but some approaches reduce it meaningfully.
Blur or crop distinctive backgrounds. Architecture, street furniture, and vegetation are the primary signals visual geolocation uses. Photos taken indoors in nondescript settings, or cropped to exclude recognizable background elements, are harder to geolocate than outdoor scenes in identifiable environments.
Be particularly careful with regularly frequented locations. A single photo from a nondescript indoor location provides little signal. A pattern of photos that consistently show the same outdoor environment — the same trees, the same building styles, the same street — can be cross-referenced across images to narrow location over time.
Consider what’s in frame beyond the subject. The most careful subject in a photo can still reveal location through what’s visible in the background: a distinctive building, a street sign partially legible in the distance, a regional vehicle type, a plant species native to a small geographic range.
Privacy regulators in 61 countries — coordinating through the International Conference of Data Protection and Privacy Commissioners — issued a joint statement warning specifically about AI image geolocation as a tool that “enables stalking, harassment, and unauthorized surveillance.” Their guidance to platforms is to restrict access to such capabilities. Their guidance to users is that traditional privacy measures are insufficient.
What This Means for Cloud Photo Storage
Visual geolocation is relevant not only to photos you share publicly but to photos that could potentially be accessed by others: through data breaches, through legal requests, through compromised accounts, or through sharing with parties who might share further.
When you store photos in a cloud service, those photos are accessible to the provider. They may be accessible to law enforcement with proper process. In the event of a breach, they may be accessible to unauthorized parties. In each of those cases, AI geolocation could be applied to photos that were never intended to reveal a location.
Photos taken at home, at a regularly visited location, or in private settings contain visual information that didn’t exist as a privacy concern when those photos were taken. The technology to extract it is newer than the photos themselves.
This context matters for how you think about which cloud services hold your photos. A service that keeps your files encrypted and doesn’t analyze their contents cannot provide the same visual geolocation risk reduction that a service offering unencrypted or analyzed storage creates — but it does reduce the surface area of who can access the raw image files in the first place. Fewer access points means fewer opportunities for any analysis, AI-based or otherwise, to be applied without your knowledge.
The Broader Shift in Visual Privacy
The privacy calculus around photo sharing has changed in a short period. For most of the past decade, the risks associated with sharing a photo were reasonably well understood: your face could be recognized, your GPS coordinates could be read, your timestamp could be noted. Each of these risks had a reasonably understood mitigation: location off, EXIF stripped, face blurred.
AI visual geolocation adds a risk without a clean mitigation. The location information in a photo isn’t a layer that can be removed; it’s embedded in the scene itself. Any photo taken in a recognizable real-world environment potentially encodes location information that sophisticated analysis can extract.
This doesn’t mean avoiding photos or withdrawing from sharing entirely. It means the phrase “this photo doesn’t contain any personal information” no longer means what it used to. Photos of places — even photos that appear to contain no identifying information about the person depicted — can reveal information about where that person lives, works, or spends time.
That’s a different kind of disclosure than most people are aware they’re making. Knowing about it doesn’t make the risk disappear, but it does change the calculation for which photos go where, under what access controls, and in whose hands.