You Can Change a Password, But Not Your Face: How AI Is Putting Facial Data at Risk
Experts say a few selfies can now be enough to create a fake version of you, and countries like Pakistan could respond by regulating biometric data rather than banning facial recognition.

AI can create a fake version of you from a few selfies. Learn the risks to facial data, lessons from Australia and China, and how Pakistan could protect biometric privacy.
Facial recognition was introduced as a safer alternative to passwords, but generative AI has made facial data a new target. If a password is breached, you can change it, but you cannot change your face. Just a few selfies can be enough to create a fake digital version of a person, and facial recognition systems in places like shopping markets can record faces automatically, raising privacy and security risks. The suggested response for Pakistan is a dedicated law on biometric data that sets clear rules on when facial recognition may be used, requires consent where appropriate, and limits how facial information is collected, stored and shared.
Why Facial Data Is Different
Biometric security was built on the idea that passwords can be forgotten, while your face is always with you. But once facial data is exposed, it cannot be reset like a password, and it becomes especially intrusive when combined with other personal information.
A Real Example From Australia
The 2024 Outabox case in Australia showed how an ordinary visit to a club could turn into a detailed digital profile. The reported breach exposed facial biometric information along with identity documents, contact details and records of people’s visits.
How China Has Responded
China introduced new facial-recognition measures in June 2025. They generally prevent organisations from making facial recognition the only way to verify identity when an alternative is available, restrict the installation of facial-recognition equipment in public spaces, and require clear warnings wherever facial data is collected.
What Pakistan Could Do
The article argues that countries like Pakistan should regulate the technology rather than simply ban it. Suggested steps include:
A dedicated legal framework for biometric data, covering when facial recognition may be used and requiring consent where appropriate
Limits on the collection, storage and sharing of citizens’ facial information
Independent oversight and strict cybersecurity standards
Transparency from organisations that use the technology
Penalties for misuse or unauthorised access
With these safeguards, facial recognition could continue to support security and public services while protecting citizens from unnecessary surveillance and permanent privacy violations.
Related stories
Cyber SecurityPTA Warns Public Against Courier Fraud, Urges Citizens Not to Share OTPs
Cyber SecurityOpenAI Alerts Over 100 Groups About Rogue AI Agents
Cyber SecurityUK Firefighter Uses ChatGPT to Win £40,000 Court Case Against Ex-Girlfriend
Cyber SecurityAnthropic Warns AI May Pose "Existential Risks to Humanity" in IPO Filing
· 2 min read
Cyber SecurityNvidia Releases AI Agent Safety Tools It Says Could Have Stopped the Hugging Face Hack
Cyber Security