School Social Media Platforms: An Emerging Novel Legal Concern That Canadian Principals, Trustees, and Educators Should Be Aware Of!
- The White Hatter
- 8 minutes ago
- 8 min read

Caveat - We want to be clear that we are not lawyers, nor should this article be interpreted as providing legal advice. Our role is to educate, not to offer legal advice.
However, as part of our work in digital literacy, online safety, and emerging technologies, we closely monitor Canadian legislation, privacy developments, and court decisions involving technology, education, and the duty of care owed to youth and teens. We regularly review legal developments because they often influence the practical guidance we provide to schools, parents, caregivers, and educators in our digital literacy presentations.
This article is intended to encourage informed discussion, not to draw legal conclusions. It highlights an emerging issue that we believe school leaders, trustees, and educators should be aware of as artificial intelligence continues to reshape the digital landscape.
If your school or district publicly shares photographs of students or staff on websites or social media platforms, we encourage you to use this article as a starting point for conversations with your district’s legal counsel, privacy officer, and risk management professionals. They are best positioned to provide advice based on your province’s legislation, your board’s policies, and the specific circumstances of your school community.
As with many issues involving artificial intelligence, the law is still evolving. Our goal is not to predict how Canadian courts will rule, but rather to help educational leaders begin asking thoughtful questions today about practices that may carry different legal and privacy implications tomorrow.
As artificial intelligence continues to evolve, schools across Canada are finding themselves navigating legal questions that simply did not exist a few years ago. We believe that one emerging issue and question deserves serious consideration by school leaders, trustees, educators, and policymakers, “If a school publicly posts photographs of students and staff on their school’s social media platform such as Instagram, and those images are later copied by others, manipulated using artificial intelligence into harmful deepfakes, and redistributed online, could the school face legal liability?”
This is no longer a hypothetical scenario. Here in Canada, we are already seeing publicly available images being copied and manipulated using artificial intelligence. As we discussed in an earlier article (1), what was once viewed as a future possibility has now become a present day reality.
In fact, just this week we assisted a Canadian post secondary institution after publicly accessible photographs of students and staff, originally shared on the institution’s Instagram public account, were copied by a malicious actor, manipulated using AI, which were weaponized and then reposted online as a form of harassment and abuse.
While the institution itself was not responsible for the criminal actions of the offender, the incident illustrates how images shared on unrestricted public platforms can be weaponized in ways that were virtually unimaginable only a few years ago. It also reinforces why educational institutions should begin evaluating whether existing policies and practices surrounding the public sharing of student and staff images remain appropriate in an era where AI can rapidly transform a simple photograph into a powerful tool for victimization.
At present, there is no Canadian legal case that we could find that has answered this question directly. No Canadian court has held a school liable because an unrelated third party used publicly available school photographs to create AI generated deepfakes. However, developments in Canadian tort law suggest that this is no longer a hypothetical question that can simply be dismissed. Rather, it is an emerging legal issue that deserves thoughtful discussion.
Understanding the Legal Framework
Much of the current legal discussion surrounding organizational responsibility has focused on vicarious liability, particularly following decisions of the Supreme Court of Canada such as Bazley v. Curry (2) . These decisions emphasize that liability is not always determined solely by identifying who directly committed the wrongful act. As Justice McLachlin wrote in Bazley, courts should consider whether there is,
“a significant connection between the creation or enhancement of a risk and the wrong that accrues therefrom.”
This principle has become one of the cornerstones of Canadian vicarious liability law, and something that the British Columbia Principals and Vice Principals Association spoke to in this discussion paper (3).
However, while this framework is informative, applying it directly to the issue of AI generated deepfakes requires an important distinction.
This Is Probably Not a Vicarious Liability Case
When discussing AI generated image abuse involving publicly posted school photographs, it is tempting to frame the issue as one of vicarious liability. Legally, however, that is probably not the strongest approach.
Traditional vicarious liability applies when an employee commits a wrongful act that is sufficiently connected to their employment, making the employer legally responsible for that employee’s conduct. In the incident we assisted with this week involving AI generated deepfakes, the facts were materially different.
The school’s social media coordinator who posted the photographs of students and staff did not create the deepfakes or engage in any criminal wrongdoing. Rather, an unrelated third party downloaded the publicly available images from the school’s Instagram account, manipulated them using artificial intelligence, and then allegedly committed a separate criminal act by creating and distributing non-consensual intimate images.
This distinction is important. The criminal responsibility rests entirely with the offender who intentionally misused the images, not with the individual who originally posted lawful photographs on behalf of the school. The legal question, however, is not whether the school created the deepfakes, but whether its decision to make identifiable images publicly available on an unrestricted platform could be examined through the lens of negligence and the evolving standard of reasonable care in an era where AI enabled image manipulation has now become a “foreseeable" risk.
That shifts the discussion away from vicarious liability and toward institutional negligence.
The Better Legal Question, “Did the School Meet the Standard of Care?”
Canadian negligence law asks four familiar questions:
Did the school owe a duty of care?
Was the harm reasonably foreseeable?
Did the school meet the required standard of care?
Did any failure materially contribute to the student’s harm?
These questions are far better suited to evaluating AI related image misuse than traditional vicarious liability principles.
Foreseeability Has Changed
Perhaps the most significant legal development is not artificial intelligence itself, but how it has changed what society now considers reasonably foreseeable.
A decade ago, few school administrators could reasonably have anticipated that publicly posted photographs of students might one day be transformed into convincing fake nude images, child sexual abuse material, or sophisticated identity fraud.
Today, that argument has become increasingly difficult to make. AI image generators, face-swapping software, nudification applications, and deepfake technology are now widely available. Canadian law enforcement agencies, privacy commissioners, child protection organizations, educators, and the media have all raised concerns about these technologies. Schools themselves increasingly teach students about deepfakes, misinformation, AI-generated content, and digital manipulation.
As a result, courts evaluating negligence in the future may conclude that AI enabled misuse of publicly available images is no longer a remote or speculative possibility. Instead, it may now be considered a reasonably foreseeable risk.
Most importantly, foreseeability alone does not establish liability, it simply means that the risk becomes one that reasonable decision makers are expected to consider.
Public Social Media Changes the Risk
Not all image sharing creates the same level of legal exposure. There is an important distinction between:
sending photographs directly to parents,
sharing images within password-protected school portals,
publishing photographs in offline yearbooks, and
posting high-resolution, publicly accessible images on unrestricted social media platforms.
Public social media is fundamentally different because it provides unrestricted access to anyone in the world, including individuals with malicious intent. Publicly available images may be copied by:
AI scraping systems,
identity thieves,
online predators,
creators of sexually explicit deepfakes,
fraudsters, or
individuals seeking to harass, intimidate, or extort students and staff.
The school does not create these harms. However, the decision to make identifiable images publicly accessible may become part of the factual analysis if litigation ever arises.
The Question a Court May Eventually Ask
If such a case reaches a Canadian court, the central legal question is unlikely to be, “Did the school create the deepfake?” Instead, it may become, “Knowing what is now widely understood about AI image manipulation, did a reasonable school exercise appropriate care when deciding to publish identifiable photographs of students on unrestricted public social media platforms?”
We believe that is a negligence analysis grounded in today’s realities rather than yesterday’s technology, however, this belief has not been legally tested here in Canada that we could find. However, as a Canadian school, do you want to be the test case?
Causation Would Still Matter
Even if a plaintiff established that the risk was foreseeable, another significant legal hurdle would remain - causation!
The school would almost certainly argue that the independent criminal conduct of the offender broke the chain of causation. In other words, while the school may have posted the original photograph, it was the deliberate criminal actions of a third party that directly caused the harm.
Canadian courts have long recognized that intervening criminal acts can complicate negligence claims. Whether they break the chain of causation depends on the specific facts of each case. It is not an automatic defence, nor does it automatically impose liability on the organization whose actions preceded the criminal conduct. This is precisely why predicting the outcome of any future litigation would be speculative.
What Reasonable Care May Look Like in the AI Era
As AI capabilities continue to evolve, courts may also consider whether schools adopted reasonable safeguards that reflected today’s technological realities.
These could include:
Reviewing whether public social media remains the most appropriate method for sharing student photographs.
Obtaining informed parental consent that specifically acknowledges the risks associated with AI enabled image manipulation,
limiting the use of student’s full names alongside publicly posted images;
favouring secure parent portals or restricted-access platforms where appropriate,
avoiding unnecessary publication of high-resolution, close-up identifiable photographs of students or staff,
implementing image retention and deletion policies, and
conducting privacy impact assessments that specifically consider AI related risks.
None of these measures would eliminate criminal misuse. However, they may become relevant when determining whether a school exercised reasonable care.
A Conversation Worth Having Before the 2026/2027 School Year Begins
Artificial intelligence is changing how courts, organizations, and society think about foreseeable risk.
Practices that were considered entirely reasonable ten years ago may warrant renewed examination today, not because schools have acted improperly, but because the technological landscape has changed dramatically.
This article should not be interpreted as suggesting that schools should stop celebrating student achievements or sharing positive stories with their communities. As well, it should not be interpreted as predicting that Canadian courts will hold schools liable whenever publicly available images are misused by criminals. Instead, it highlights an important legal question that has yet to be answered.
As AI increasingly enables the misuse of publicly available images, school leaders may need to ask a different question than they did in the past. The issue is no longer simply whether they have parental or caregiver permission to post a student’s photograph. It is whether, in light of what is now known about AI enabled image manipulation, their existing practices continue to reflect the standard of reasonable care expected of educational institutions.
Canadian schools owe students a recognized duty of care. What remains far less settled is whether that duty could extend to the way schools publicly share identifiable student images online, particularly where those images are later downloaded and weaponized by a third party using generative AI
The law has always evolved alongside new technologies, and artificial intelligence may represent the next chapter in that evolution. As AI changes what can be done with publicly available images, questions surrounding institutional standards of care, reasonable foreseeability, and potential negligence can no longer be ignored.
Given what is now known about AI enabled image manipulation and the ease with which publicly accessible photographs can be copied, altered, and weaponized, we believe schools should seriously reconsider the practice of publicly posting identifiable photographs of students and staff on unrestricted social media platforms.
This is not about suggesting that schools are responsible for the criminal actions of third parties. It is about recognizing that the risk environment has changed. What may have been considered a reasonable practice several years ago deserves to be reassessed against what schools now know, or reasonably ought to know, about the potential misuse of publicly available images.
The question is no longer simply, “Do we have permission to post this photograph?” It should also be, “Given what we now know about AI and the foreseeable misuse of publicly available images, is a school posting this photograph publicly still the reasonable and prudent thing to do?”
Digital Food For Thought
The White Hatter
Facts Not Fear, Facts Not Emotions, Enlighten Not Frighten, Know Tech Not No Tech
References:














