It's always been pretty straightforward if you don't want people to know where your photographs have been taken. You simply remove the EXIF data or don't release the coordinates showing the location, right?
Right?

Well, maybe not anymore.
Recently, the software security company McAfee, did an experiment with AI that will have a lot of photographers a little bit worried.
The folks at McCaffey research tested 21,236 travel photographs using the AI agent Qwen3 VL 30B and were able to identify the city and country of the photographs in 91% of their test images. Another AI program, Gemma3 27B was able to do it with an accuracy rate of 87%. Both models were programmed to work from visual content rather than embedded location or EXIF data.
Visuals alone.
This broadly lines up with Privacy International's warning, after working with researchers from Southampton, UCL and Queensland University of Technology, who warned that modern vision language models can accurately infer locations from photographs even without GPS or EXIF data. They raise concerns about doxing, surveillance, tracking, and profiling.
This raises obvious issues for photographers who felt that removing EXIF data was enough to protect their privacy – at least to a degree.
These image models are working with elements of photographs that photographers often intentionally include to give an artistic sense of place, such as architecture, vegetation, light, and landscape, which are all fed into AI models and are able to be retrieved.

The McAfee site here actually goes into how this can be used in scams, and it is probably worth a read if you want to protect yourself, although not specifically photography related.
Of concern specifically for photographers would be the issues raised with this information while we are traveling and posting our images; it also has safety implications when photographing people who might be in danger of stalking and whatnot. Basically, in any situation in which you're deliberately trying to conceal sensitive locations, you may need to think twice about uploading these images to the internet.
And this means thinking seriously about what is actually visible in your composition rather than just changing your EXIF data or privacy settings.
We're entering a world where the visuals of the image itself could be the security issue



