WhatsApp has quietly rolled out some of its most significant photo and video changes in years — and most UK users clicked through the notification without a second thought. New Live and Motion Photo support, built-in Meta AI image editing, and a tighter integration between the chat interface and Meta's cloud infrastructure have arrived together in 2026. IT security specialists are now asking a question that few ordinary users have thought to ask: when you use these features, where does your photo data actually go?
What WhatsApp's New Photo Features Actually Do
Two headline updates have changed how photos work inside WhatsApp in 2026. First, Live Photos (Apple's format that captures 1.5 seconds of video and audio alongside a still image) and Android's Motion Photos can now be sent through the app in their full animated form. Recipients see a living image rather than a frozen frame — complete with any background sound recorded at the moment of capture.
Second, a built-in Meta AI photo editing suite now lets users remove unwanted objects from images, replace backgrounds, and apply style effects without leaving the chat interface. WhatsApp states that AI tools "process edits locally on the device whenever possible," but that phrase quietly opens the door to server-side processing when local capabilities are insufficient.
The combination means that a single WhatsApp photo exchange can carry far more data than the visible image — audio recordings, metadata, GPS coordinates, and now AI-processed image derivatives submitted to Meta's infrastructure.
Why IT Security Experts Are Paying Attention
The privacy concerns emerging from these features are not theoretical. Since March 2026, WhatsApp has also offered a Meta AI tool that organises users' chat histories — meaning the app's AI layer was already parsing message content before the photo editing rollout.
The issue with Live and Motion Photos is the audio. Ambient conversations captured in the background of a photo — a colleague's name, a client's contact details spoken aloud, a medical discussion — travel with the image. WhatsApp strips some metadata during transmission, but the sender's device retains the original file, and the recipient receives the animated version with audio intact.
The issue with Meta AI photo editing is different: when an image is submitted for AI processing, it enters Meta's server infrastructure. According to analysis by Proton, which reviewed Meta's privacy architecture, UK users hold a formal "Right to Object" under UK GDPR to prevent Meta from using their data for AI model training. Fewer than one in ten WhatsApp users surveyed in a 2025 digital literacy study were aware this right existed.
WhatsApp did introduce an "Advanced Chat Privacy" mode that can technically block Meta AI from accessing a specific chat's content — but it is disabled by default, applies per-conversation rather than account-wide, and must be manually enabled in every group and individual chat where users want protection. In practice, most WhatsApp conversations remain within Meta AI's operational reach.
What UK GDPR Says — and What Meta Is Required to Tell You
Under the UK General Data Protection Regulation, individuals hold several rights relevant to AI-driven photo processing. Article 21 grants the right to object to processing based on Meta's legitimate interests. Article 13 requires Meta to provide clear, accessible information about how your data is used for AI training at the point of collection. Article 22 restricts solely automated decision-making that produces significant effects on individuals.
The Information Commissioner's Office — the UK's data protection regulator — has published specific guidance on AI and data protection, requiring that organisations using personal data to train AI models must have a clear lawful basis and provide transparent disclosures. The ICO has significantly increased its scrutiny of AI data practices since 2025, following a wave of complaints from UK consumers about how social media platforms handle AI-driven personalisation.
Meta Platforms Ireland Ltd serves the UK WhatsApp user base and became a focal point of regulatory enforcement in 2023 when it was fined €1.2 billion by the Irish Data Protection Commission for unlawful transatlantic data transfers. That history gives additional weight to questions about how photo data submitted to Meta AI is stored and transferred.
Concrete Case: The Freelancer's Unintended Data Breach
Take this specific scenario. A freelance brand designer in Sheffield is working on a confidential identity project for a retail client. They photograph a draft logo design using their iPhone — the phone automatically saves it as a Live Photo, capturing 1.5 seconds of audio. In the background, clearly audible, is their own phone call from five minutes earlier, where they repeated the client's business name, planned product launch date, and retail expansion strategy while taking notes.
The designer sends the photo to a contractor colleague via WhatsApp and uses the Meta AI editing tool to clean up the background of the image. The image is submitted to Meta's processing servers. The standard freelance contract with the client includes a confidentiality clause specifying that all project materials and commercially sensitive information are not to be shared with third parties without explicit written consent. Meta's infrastructure constitutes a third party under that agreement.
If this comes to light — in a contract dispute, a competitor leak investigation, or a GDPR audit — the designer faces two distinct exposures. First, a breach of contract claim for disclosing confidential information to an unauthorised third party; damages could include the full value of the contract, estimated at £8,000 to £25,000 for a mid-size branding project. Second, a potential UK GDPR compliance issue: if the audio recorded identifiable individuals or contained personal data about the client's employees (their names, roles, or contact details mentioned during the call), the designer may have acted as an unauthorised data controller processing personal data without a lawful basis under Article 6.
If/then: if you send any image via WhatsApp using the Meta AI editing feature in a professional context, and that image or its associated audio contains confidential client information, you may be in breach of both your contract and UK data protection law — regardless of whether you intended the disclosure.
Practical Implications Across Different User Groups
The risk profile varies considerably by context:
For personal users, the danger is modest but real. Live Photos sent via WhatsApp can carry background audio from private spaces — a home address spoken aloud, a family member's health discussion, a financial detail mentioned in passing. Consider switching to standard still photography mode when the environment contains sensitive audio.
For employees using WhatsApp informally for work, the position is more serious. Many UK companies have acceptable use policies that restrict the processing of business data through AI tools operated by third parties. Using Meta AI photo editing on a work image — even casually — may constitute a policy breach. A 2025 survey by the UK's National Cyber Security Centre found that 34% of employees used personal messaging apps for work tasks without knowing whether their employer's data policy permitted it.
For freelancers and sole traders, this is the highest-risk group. You likely qualify as a data controller under UK GDPR for any personal data you handle on behalf of clients. If you process that data through Meta AI without a lawful basis and appropriate disclosures to data subjects, you carry personal liability for any resulting regulatory complaint.
For regulated sectors — healthcare, legal services, financial advice, education — Meta AI photo features should be treated as incompatible with professional obligations until a data protection officer has reviewed the implications. WhatsApp is not approved as a channel for sharing patient, client, or student data under the frameworks applicable to these sectors.
What to Do Now
Enable Advanced Chat Privacy on any conversation where you share professional content. In WhatsApp, tap the contact or group name at the top of the screen, select Advanced Chat Privacy, and toggle it on. This limits Meta AI's access to that specific chat's content.
Disable Live Photo format before capturing images intended for professional sharing. On iPhone, tap the Live Photo icon (the concentric circles) in the camera viewfinder before shooting to switch to a standard still.
Exercise your Right to Object via Meta's privacy settings. Under UK GDPR, you can submit a formal objection to Meta using your data for AI model training. This does not retroactively remove already-processed data but limits future use. The option is accessible via WhatsApp Settings → Privacy → Advanced.
Consult an IT security specialist or data protection consultant if WhatsApp is embedded in your professional workflow — particularly if you handle client materials, personally identifiable information, or commercially sensitive content. A qualified IT expert can map your current data flows, identify where WhatsApp's new AI features create compliance gaps, and recommend appropriate technical and procedural controls.
WhatsApp photos are no longer just images. In 2026, they carry AI processing trails, embedded audio, and metadata that flow through Meta's infrastructure in ways most users have never considered. Understanding exactly what your photos carry — and where they go — is now a professional obligation, not just a personal one.
Note: This article covers data protection law and technology security considerations. For specific legal advice regarding your circumstances, consult a qualified legal professional or data protection officer.

Christopher Bell