There's a big difference in the expectation of privacy between what someone posts on "Facebook, Youtube, et al" and what someone takes a picture of but doesn't share.
Couldn’t they always avoid ever flagging pictures taken on the device itself (camera, rather than download) since if those match, it’s always a false positive?