security

The EU AI Act Is Now Enforced. What It Means for Apps Using Your Photos

The EU AI Act's general-purpose AI rules are in full effect. Here's which personal-data app features are now restricted and what users can actually demand.

The EU AI Act is no longer a future regulation. After years of negotiation and a staggered implementation schedule, its most consequential provisions — including the outright ban on certain AI applications and the rules governing general-purpose AI models — have been in full legal force since mid-2025. By August 2026, enforcement agencies in EU member states have opened their first formal investigations, fined their first violators, and established initial precedent for what compliance actually requires.

If you store personal photos, memories, or sensitive files in apps that use AI to organise, search, or analyse your content, you are directly affected — even if you don’t live in the EU. The Act’s extraterritorial reach covers AI systems deployed to EU users, and most consumer apps operate globally.


What the EU AI Act Actually Bans

The Act creates a hierarchy of AI risk categories. At the top are “unacceptable risk” applications, which are flatly prohibited. Several of these touch directly on how AI is used in consumer photo and memory apps.

Emotion recognition in workplaces and educational institutions

The Act prohibits AI systems that infer emotions from facial expressions, voice, or biometric signals in workplace and educational settings. The ban is explicit and unconditional in those contexts.

For consumer photo apps, the practical implication is narrower but still significant: an app that analyses your facial expressions in uploaded photos to infer emotional states — and then uses that inference for anything beyond direct user benefit — is operating in legally contested territory, even in consumer contexts. Several photo memory apps have offered “mood tagging” or “sentiment analysis” features that work exactly this way.

Real-time remote biometric identification in public spaces

The Act bans real-time biometric identification of individuals in public spaces except for specific law enforcement uses. Apps that allow users to identify strangers from photos — by running facial recognition against a database — are prohibited.

This directly affects several social photo apps and “people search” tools that offered facial recognition lookups. These features have been quietly removed from apps available in the EU.

Social scoring and manipulation

AI systems that score individuals based on social behaviour, or that use subliminal techniques to influence behaviour in harmful ways, are prohibited. Apps that create personality or lifestyle profiles from your photo content and use those profiles to target you with recommendations or pricing are in scope.


What Changed for General-Purpose AI Models

The general-purpose AI rules — covering large language models and multimodal AI systems like those that power photo search and auto-captioning — entered force in August 2025.

These rules require providers of GPAI models to:

Publish detailed summaries of training data. Model providers must maintain and make available to competent authorities documentation of what data was used to train their models. For models trained on internet-scale datasets that may have included scraped photos, this is a significant compliance burden.

Allow copyright and data opt-out. Providers must comply with opt-outs from rights holders who do not want their content used to train AI models. This extends to individual users who have exercised their rights under GDPR to object to AI training.

Implement risk mitigation for systemic risks. The highest-tier GPAI models — defined by training compute exceeding a specified threshold — face additional requirements including third-party adversarial testing, incident reporting, and mandatory cybersecurity measures.

The practical effect for users: any app using a major GPAI model to process your photos now has to be able to answer specific questions about how that model was trained and whether your data contributed to it.


What Apps Are Doing (and Not Doing)

Compliance with the EU AI Act has been uneven, and the gap between what apps are legally required to do and what they have actually implemented is significant.

Feature removal. The clearest compliance signal has been the removal of prohibited features from EU-facing app versions. Emotion recognition in photo apps, real-time facial identification in consumer tools, and certain social-scoring features have been disabled or removed for EU users. Some of these removals are global; others are geo-fenced, with the prohibited features still available to users outside the EU.

Documentation updates. Several major cloud photo services have published new sections in their privacy policies describing their AI training data practices and how users can opt out. Google Photos updated its privacy documentation in late 2025 to address AI training opt-out under both the EU AI Act and GDPR. Apple has maintained that its on-device AI processing approach means the Act’s GPAI provisions don’t apply to its photo features — a position that EU data protection authorities haven’t formally endorsed or rejected.

Enforcement gap. As of mid-2026, enforcement has focused primarily on high-risk AI systems in healthcare, hiring, and credit scoring rather than consumer photo apps. This doesn’t mean consumer apps are exempt — it means enforcement capacity is being prioritised. The European AI Office, established to coordinate enforcement across member states, has signalled that consumer-facing GPAI applications are a 2026–2027 enforcement priority.

Nominal compliance. Some providers have added settings labelled “AI training opt-out” that technically exist but are buried in menus, reset to default on update, or ineffective because they govern one model but not others. This pattern is familiar from GDPR cookie consent failures and is likely to attract similar enforcement attention.


Your Rights Under the EU AI Act (and How to Exercise Them)

If you are an EU resident — or if you’re using an app that operates under the Act’s reach — you have specific rights that are enforceable today.

The right to explanation

For high-risk AI systems, the Act requires that users be informed that they are interacting with AI and be able to request a meaningful explanation of how an AI decision was reached. If an app uses AI to flag your photos for content review, make recommendations, or change how your content is surfaced, you can ask for an explanation.

In practice, exercise this right by contacting the service’s support team with a specific data subject rights request referencing the EU AI Act. Responses vary in quality, but sending a written request creates a compliance record.

The right to opt out of AI training

Under the combined operation of GDPR Article 21 (right to object) and the EU AI Act’s data training requirements, you can formally object to your personal data — including photos — being used to train AI models. This right applies even if the app’s terms of service claim a broader licence.

The procedure: send a formal objection in writing to the service’s Data Protection Officer (the address is required to be published in the privacy policy). Reference GDPR Article 21 and, for GPAI model providers, the EU AI Act’s training data opt-out provisions. The provider has one month to respond and must either comply or explain a compelling legitimate ground for continuing processing.

Complaints to data protection authorities

If a provider doesn’t respond to your opt-out request, or responds inadequately, you can file a complaint with your national data protection authority (DPA). EU DPAs now have explicit jurisdiction over AI Act violations for AI applications, in addition to their existing GDPR powers.

The most active DPAs for AI enforcement as of 2026 have been Germany’s Bundesdatenschutzbeauftragter, Ireland’s Data Protection Commission (jurisdiction over many US tech companies’ EU entities), and France’s CNIL. Filing a complaint is free.


The Limits of What Regulation Can Do

The EU AI Act is a significant piece of legislation, and for users in its jurisdiction, it creates real and enforceable rights. But it has several limitations worth understanding.

Geo-fencing is a workaround, not compliance. Some apps disable prohibited features only for EU IP addresses, while leaving them active globally. If you’re outside the EU, you may be subject to AI practices that are illegal in Europe. This isn’t an abstract concern — the same facial recognition tools banned in the EU are still active in some apps’ non-EU versions.

Enforcement lags violations. The Act has been in force for over a year, but enforcement capacity is still developing. Violations that would be caught today are likely to accumulate evidence for years before a formal case concludes. The fines — up to €35 million or 7% of global annual turnover for prohibited practices — are significant, but the timeline from violation to sanction is long.

GPAI model compliance is hard to verify. When an app says it has opted out of using your data for AI training, you have limited ways to verify this independently. Model training is an opaque process, and “our model wasn’t trained on your photos” is a claim that users must take on trust unless auditing mechanisms improve significantly.

The Act doesn’t apply everywhere. The US, India, and most of the rest of the world have not enacted comparable AI regulation. If your app is US-only or you’re using a service that explicitly scopes its commitments to EU users, the EU AI Act doesn’t protect you.


Practical Steps for Non-EU Users

If you’re outside the EU, you’re not covered by the EU AI Act’s consumer protections. But you can still take steps to limit AI processing of your personal photos.

Use services with explicit no-training commitments. Some services — including daftei — commit contractually not to use your personal data to train third-party AI models. This isn’t the same as a statutory right, but it’s a contractual obligation that can be enforced through civil claims.

Exercise opt-outs that exist. Most major cloud photo services now have some form of AI training opt-out in their settings. Whether these opt-outs are comprehensive varies, but enabling them is free and costs nothing to do.

Choose on-device processing where possible. Apps that process your photos locally — running AI models on your device rather than uploading content to servers — sidestep the training data question entirely. Apple’s on-device photo intelligence and Google’s Gemini Nano on Android are examples. On-device AI is less capable than server-side models, but the privacy trade-off is real.

Review what you’ve already shared. Use Google Takeout, Apple’s data download page, or equivalent tools to see what AI features have been applied to your existing library. Understanding what a service already knows about your photo content is the first step to deciding whether to stay.


The Larger Point

The EU AI Act’s enforcement marks the beginning of a period in which AI feature development in consumer apps faces binding legal constraints, not just voluntary norms. The trajectory is toward more regulation, not less — the US AI Safety Institute is developing frameworks, India’s DPDP Act has AI-adjacent provisions, and the UK is expanding its ICO’s AI guidance.

The practical effect for users is that the AI features you interact with in photo apps, memory apps, and cloud storage services are increasingly shaped by regulatory requirements — some of which are clearly in your interest, and some of which create compliance theatre without improving actual privacy.

Understanding the difference between “we comply with the EU AI Act” as a marketing statement and genuine compliance that gives you enforceable rights is the work of reading the actual documentation. The rights exist. Exercising them takes a few minutes and a written request.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts