Skip to content
ECONOMYMarkets · Policy · Power

You Can Change a Password, But Not Your Face: How AI Is Putting Facial Data at Risk

Experts say a few selfies can now be enough to create a fake version of you, and countries like Pakistan could respond by regulating biometric data rather than banning facial recognition.

RRohaanPublished 2 min read
You Can Change a Password, But Not Your Face: How AI Is Putting Facial Data at Risk
You Can Change a Password, But Not Your Face: How AI Is Putting Facial Data at Risk · You Can Change a Password, But Not Your Face: How AI Is Putting Facial Data at Risk

AI can create a fake version of you from a few selfies. Learn the risks to facial data, lessons from Australia and China, and how Pakistan could protect biometric privacy.

Facial recognition was introduced as a safer alternative to passwords, but generative AI has made facial data a new target. If a password is breached, you can change it, but you cannot change your face. Just a few selfies can be enough to create a fake digital version of a person, and facial recognition systems in places like shopping markets can record faces automatically, raising privacy and security risks. The suggested response for Pakistan is a dedicated law on biometric data that sets clear rules on when facial recognition may be used, requires consent where appropriate, and limits how facial information is collected, stored and shared.

Why Facial Data Is Different

Biometric security was built on the idea that passwords can be forgotten, while your face is always with you. But once facial data is exposed, it cannot be reset like a password, and it becomes especially intrusive when combined with other personal information.

A Real Example From Australia

The 2024 Outabox case in Australia showed how an ordinary visit to a club could turn into a detailed digital profile. The reported breach exposed facial biometric information along with identity documents, contact details and records of people’s visits.

How China Has Responded

China introduced new facial-recognition measures in June 2025. They generally prevent organisations from making facial recognition the only way to verify identity when an alternative is available, restrict the installation of facial-recognition equipment in public spaces, and require clear warnings wherever facial data is collected.

What Pakistan Could Do

The article argues that countries like Pakistan should regulate the technology rather than simply ban it. Suggested steps include:

  • A dedicated legal framework for biometric data, covering when facial recognition may be used and requiring consent where appropriate

  • Limits on the collection, storage and sharing of citizens’ facial information

  • Independent oversight and strict cybersecurity standards

  • Transparency from organisations that use the technology

  • Penalties for misuse or unauthorised access

With these safeguards, facial recognition could continue to support security and public services while protecting citizens from unnecessary surveillance and permanent privacy violations.

Related stories