AI
A McAfee study found AI models can identify where photos were taken—down to city and country—with up to 91% accuracy, using only visual details in the image, even when GPS metadata and geotags are stripped.

A new study reveals that artificial intelligence tools can now determine the geographic location where a photo was taken—solely from its visual content—even when no GPS coordinates, embedded geotags, or filename clues are present. The research, conducted by cybersecurity firm McAfee, demonstrated that AI models correctly identified both the city and country of origin in nearly nine out of ten cases.
The study tested AI performance using more than 21,000 travel photographs. All identifying metadata—including geolocation tags, EXIF data, and filenames—was deliberately removed before analysis. McAfee evaluated two open-weight models: Google’s Gemma 3 27B and Alibaba’s Qwen 3 VL 30B. Neither requires a paid subscription for use. Gemma achieved 87% accuracy in correctly naming both the city and country where each photo was captured; Qwen reached 91%.
AI systems do not rely on GPS signals, geotags, or file names. Instead, they analyze a wide range of visible features within the image itself. These include architectural styles and building designs, street signs and shop signage, skyline landmarks, lighting conditions, road markings, street layouts, and even roadside food stalls. The models compare these visual elements against their internal training knowledge of global locations to infer the most probable place of capture.
Identification proved significantly easier when images contained well-known tourist landmarks or distinctive visual elements. In contrast, models struggled more with generic beach scenes, rural roads, or hotel room interiors. Still, even in those ambiguous cases, AI frequently succeeded in identifying the correct country—even when pinpointing the exact city remained elusive.
The experiment extended beyond publicly posted images. McAfee staff uploaded personal, previously unpublished travel photos to widely available AI tools—including ChatGPT, Claude, and Microsoft Copilot—and asked the models to determine where each photo had been taken. In one instance, an AI correctly identified a riverside scene with trees as Hastings-on-Hudson, a small village in New York State.
The study warns that this capability could empower fraudsters to craft more convincing scams. Rather than relying on broad, random phishing messages, attackers might harvest publicly shared travel photos from Instagram, Facebook, or X (formerly Twitter), feed them into AI models to deduce location—and possibly infer travel timing—and then deploy hyper-contextualized deceptive messages. Examples include fake bank alerts warning of “unusual activity” while the victim is allegedly abroad, or counterfeit login attempt notifications referencing the same city or country. Absolute precision is unnecessary: plausibility alone may be enough to deceive recipients.
The findings highlight a growing concern amid the proliferation of image-understanding AI tools: seemingly innocuous visual details—previously considered irrelevant—can become highly precise geographic indicators when processed by advanced models. Posting a vacation photo thus goes beyond sharing a moment with friends or followers; it may inadvertently disclose the user’s physical location—even if no location name is tagged and geotagging permissions are disabled. That said, the models still face limitations: accuracy drops sharply when images lack distinctive landmarks or contextual cues, meaning precise real-time location or exact street-level identification cannot be reliably derived from a single photo.



