AI Discoveries

Someone Can Fake an Intimate Image of You. Who Should Stop Them?

IT Club Editorial9 minutes read2 September 2026
WhatsAppEmail
Someone Can Fake an Intimate Image of You. Who Should Stop Them?

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

The barrier to fabricating an intimate image of someone else has fallen, but the resulting harm is not imaginary. This evidence-led guide explains why non-consensual synthetic intimate imagery is a safeguarding issue, what UK law and Ofcom currently say, how app stores and infrastructure providers fit into the chain, and where people affected can seek help.

A few years ago, producing a convincing fabricated intimate image or video required specialist knowledge, time and computing resources. That barrier has fallen. A photograph that was posted for an entirely ordinary reason can now be used as raw material for a sexualised fabrication.

The person depicted does not need to have posed for an intimate photograph, sent one to somebody else or ever been naked in front of a camera. The source may be a public social-media photograph, a school picture, a professional profile or an ordinary selfie. The image may be fake. The humiliation, fear and abuse experienced by the person depicted are real.

Content warning: This article discusses non-consensual sexual imagery, abuse involving young people and harassment. It contains no explicit images and does not link to abusive services.

The short answer

Non-consensual intimate imagery, often shortened to NCII, includes real or synthetic intimate images created, altered, shared or threatened without the depicted person's consent. AI changes the cost and speed of fabrication, but it does not change the underlying issue: someone is using another person's identity and body as material for abuse.

No single company can eliminate the problem. But responsibility is not limited to the person who presses a button. Developers, app stores, payment services, cloud providers, hosts, search engines and social networks each control part of the route by which abuse can be made, sold, found, amplified or removed.

From celebrity targets to classrooms

Early public awareness of sexually explicit deepfakes focused heavily on celebrities and other public figures. That focus was never a reason to treat the abuse as acceptable. It did, however, make the problem look distant: something that happened to people with public profiles rather than to ordinary families, employees or pupils.

The source image does not need to be private. A child may have a school photograph or a public profile picture. A teenager may find that a classmate has circulated a fabricated image as a joke, a bullying tactic or a threat. A person may be pressured to pay, stay silent or send more material. The exact facts vary, and not every reported image is generated by the same technology, but the safeguarding response should not depend on proving the technical method first.

The Internet Watch Foundation's 2026 research describes AI-generated child sexual abuse material as a rapidly developing form of harm and explains that synthetic material can normalise abuse, create new victims and make the work of identifying and protecting children harder. For schools, this is not a pornography story. It is a safeguarding, bullying, consent and child-protection story.

Parents also need a calm conversation rather than a technical lecture. Children may encounter this as a target, a witness, a recipient or a person who has made a dangerous choice without understanding the consequences. The useful messages are simple: an image can be harmful even when it is fabricated; forwarding it can deepen the harm; consent applies to synthetic representations as well as photographs; and an adult should be told early.

IWF: AI child sexual abuse imagery research

NSPCC: talking to children about AI

“But it isn't really them”

That objection confuses the authenticity of the pixels with the reality of the abuse. The person may still experience humiliation, sexualisation without consent, harassment, reputational damage, fear, coercion, loss of control and sustained anxiety about who has seen the material.

Other people may not know whether the image is genuine. A fabricated image can therefore alter how colleagues, classmates, friends or strangers treat the person even when nobody can establish its origin. Asking the target to prove that it is fake places an unreasonable burden on the person who has already been harmed.

Detection is an arms race, not a magic answer

It is wrong to say that deepfakes cannot be detected. Forensic researchers, platforms and investigators can use image analysis, provenance information, known-image matching, account context and other evidence. But detection is not a permanent finish line. Generation improves, detection improves, generation improves again.

  1. 1Generation systems learn to produce more coherent faces, lighting, textures and backgrounds.
  2. 2Detection systems learn from known examples and look for statistical or visual inconsistencies.
  3. 3Editing, resizing, screenshots, compression and new generators change the evidence available to the detector.
  4. 4A detector may return an assessment rather than a definitive answer, so investigators need context and human judgement.

NIST's 2026 GenAI: Deepfakes programme says current detection systems can perform substantially worse when moved from academic evaluation into operational deployment. That is a reason to improve testing, not a reason to abandon detection. It is also why an ordinary person cannot reasonably be expected to perform forensic analysis every time an abusive image appears in a group chat.

The same caution applies to provenance marks. Content Credentials based on the C2PA standard can provide useful information about how a file was created or edited, but not every file has them and a screenshot or re-export may lose them. A missing credential does not prove that an image is real, and a valid provenance record does not make a misleading caption true.

NIST: GenAI Deepfakes 2026

IT Club: Can you really spot an AI-generated image?

IT Club: Claude watermarking and content provenance

Mr. Deepfakes: when abuse becomes an economy

Laurie Segall's investigation, produced by Mostly Human, is a useful case study because it looks beyond the image itself and asks how a platform and its community operated. Her reporting follows the anonymous operator behind the Mr. Deepfakes platform and examines the people who created material, the people who paid for it and the technology and services around them.

Academic researchers independently characterised the platform in a 2025 study. Their measurements, based on material available in November 2023, recorded tens of thousands of sexual deepfake videos depicting thousands of people, with more than a billion reported views. The study also found that women actors and musicians made up the overwhelming majority of the most common targets. These are measurements of that platform and period, not a count of all deepfake abuse and not evidence that every current service has the same scale.

The important point is structural. This was not simply one person making a few files. It was a platform connected to creators, customers, payment routes, software, hosting and distribution. Once those relationships exist, the activity can begin to look like an economy: people make material, other people buy it, and providers at several layers collect fees or supply the means to continue.

The question to ask

Who enabled the ecosystem, and what did each participant know at the time?

That question should not be used to accuse a named provider without evidence. It should be used to identify the points where credible notice, policy enforcement, product review or a removal request could interrupt the chain.

Mostly Human: Beyond Mr. Deepfakes

Academic study: Characterizing the MrDeepFakes sexual deepfake ecosystem

The most dangerous thing may be the ecosystem

The internet often frames technology abuse around a villain: find the hacker, ban the user, close the website. Those actions can matter, but they do not answer how a harmful service acquires users, processes payments, obtains computing capacity, stays searchable or reaches a new audience after a takedown.

StageWhat it can provideResponsible question
UserAn ordinary photograph, request or paymentWas the person depicted an adult who gave meaningful consent, or is the request abusive?
AI model or applicationImage generation or manipulationDoes the product block non-consensual sexualised use and respond to reports?
App store or distributionA trusted route to devices and usersWhy would a product whose central proposition is sexual manipulation of real people be distributed?
PaymentSubscriptions, creator fees, advertising or infrastructure purchasesWhat happens when credible evidence identifies an abusive service?
Cloud, compute and hostingGPUs, storage, networking and a public endpointAre acceptable-use rules clear, reportable and enforced after confirmation?
Search and social sharingDiscovery, recommendation and amplificationCan the material be delisted, reported, hashed and prevented from spreading again?

Not every provider participates at every stage, and a large infrastructure company may not know what every customer is doing. That distinction matters. The harder question is what should happen after a provider receives a credible report, investigates it and confirms that its service is being used to facilitate abuse.

Apple, Google and the app-store question

In July 2026, San Francisco City Attorney David Chiu sent cease-and-desist letters to Apple and Google demanding that they remove 13 face-swapping applications from their stores. According to the letters and reporting by WIRED, the city alleged that the applications could be used to generate non-consensual intimate images and asked the companies to stop business relationships with the developers. That is an allegation and legal demand, not a final court finding that Apple or Google knowingly enabled abuse.

The companies' responses are important. WIRED reported that Google said it had removed the five Android applications flagged by the city and hundreds of other applications with nudifying features, and that it had restricted related search terms in Google Play. Apple told WIRED that it had removed three of the flagged applications, was terminating their developer accounts and had told four other developers to address policy violations or risk removal. Apple also said that developers are responsible for their apps and that it has rejected and removed similar applications.

Those statements do not settle the wider governance question. Apple's App Review Guidelines prohibit overtly sexual or pornographic material and say user-generated-content services used primarily for pornography can be removed. Google's current developer policy explicitly lists AI-generated non-consensual deepfake sexual material and generative applications primarily intended to be sexually gratifying as examples of prohibited content.

So the fair editorial question is not whether an app store can prevent every abusive file. It is this: if an app is designed around fabricating a sexualised version of a real person without their consent, what legitimate purpose is the store operator expecting it to serve, and why should it pass review at all?

WIRED: San Francisco demands Apple and Google delete AI nudify apps

Apple App Review Guidelines

Google Play: Developer Program Policy

What about cloud companies and payment providers?

AI services need compute, storage, networks, hosting and payments. That does not mean a cloud provider can inspect every customer request or identify every abusive use in real time. It does mean that acceptable-use rules should cover serious abuse and that a provider needs a credible route for reports, investigation and proportionate enforcement.

The policies are not theoretical. AWS prohibits illegal activity and content that promotes child sexual exploitation or abuse. Google Cloud's Acceptable Use Policy expressly includes non-consensual explicit imagery, as well as child sexual exploitation and abuse, among prohibited uses. Microsoft says its NCII policy covers real and AI-generated imagery and that it has strengthened reporting and detection measures across its services.

Payments are another pressure point. PayPal's UK acceptable-use wording prohibits unlawful activity, items that facilitate illegal activity, privacy-rights violations and certain sexually oriented materials or services. That policy does not prove that a particular provider processed a particular abusive transaction. It does show why payment companies are part of the responsibility discussion: a service that cannot collect subscriptions, pay contributors or buy infrastructure may be harder to operate at scale.

A practical responsibility test

UNKNOWN ABUSE → REPORTED → INVESTIGATED → CONFIRMED → CONTINUED SERVICE?

The dividing line is not perfect knowledge. It is whether a provider has a clear process for credible notice, takes proportionate action when abuse is confirmed and prevents a closed account or removed service from immediately reappearing through the same route.

AWS Acceptable Use Policy

Google Cloud Acceptable Use Policy

Microsoft: strengthening protections against NCII

PayPal Acceptable Use Policy

Search engines and social networks amplify the outcome

A harmful service still needs to be found. Search results, recommendations, public posts, private groups, advertising and messaging can turn a single upload into a much wider crisis. Delisting a page is not the same as deleting the source, and deleting one copy does not guarantee that another copy will not appear.

There are useful countermeasures. Ofcom's May 2026 statement says certain services should use hash matching to detect and reduce the spread of intimate image abuse, with a database equivalent to or better than StopNCII.org. Hash matching is not a universal detector for every new synthetic image, but it can help services recognise known material without requiring people to repeatedly send the image around.

Google provides a removal process for personal sexual content in Search, including non-consensual explicit imagery. Meta's guidance says sharing or threatening to share intimate images, including deepfakes, without consent violates its standards. These routes are valuable, but a removal request is not an admission that the person caused the problem and should not require the victim to become an investigator.

Ofcom: detecting intimate image abuse

Google Search: remove personal sexual content

Meta: report non-consensual intimate images

This area of law is changing, so broad claims are unsafe. The Online Safety Act 2023 already makes sharing or threatening to share an intimate image without consent a criminal offence. In a January 2026 statement to Parliament, the Government said the Data (Use and Access) Act 2025 offence covering the creation or request for creation of non-consensual intimate images would be brought into force that week and treated as a priority offence for relevant online-safety duties.

The Crime and Policing Act 2026 goes further on paper. Its enacted text inserts an offence concerning making or supplying a generator of purported intimate images, with a possible maximum of three years on indictment, and adds provisions about taking down intimate-image content after a report. However, the legislation website labels relevant provisions as prospective. The safe conclusion is that Parliament has created a stronger direction of travel, but readers should check the current commencement position and obtain legal advice for a particular incident.

Ofcom is the regulator for the Online Safety Act. Its work on intimate image abuse emphasises proactive measures, hash matching and the practical difficulty of getting material removed and keeping it from resurfacing. Regulation can require systems and processes, but it cannot remove the need for platforms to make good decisions or for people to receive compassionate support.

GOV.UK: government crackdown on explicit deepfakes

UK Parliament: January 2026 statement on non-consensual sexual deepfakes

Crime and Policing Act 2026: intimate images provisions

What technology companies should do

  • AI developers: test safeguards against non-consensual intimate imagery, block abusive requests, make reporting visible and preserve enough evidence for proportionate investigation.
  • App stores: do not distribute products whose principal function facilitates sexualised manipulation of real people without consent, and make repeat-offender enforcement meaningful.
  • Payment providers: investigate credible evidence of illegal or abusive monetisation, apply acceptable-use rules and avoid making victims carry the whole burden of proof.
  • Cloud and hosting providers: publish clear abuse routes, identify prohibited use in customer terms and enforce those terms after credible confirmation without claiming to know everything in advance.
  • Search and social platforms: reduce discovery and recommendation, respond to removal reports, use known-image matching where appropriate and make re-upload pathways harder.
  • Schools: treat synthetic sexual imagery as a safeguarding and bullying incident, not as harmless because no camera captured the scene.
  • Parents and carers: teach consent, discourage forwarding, listen without blame and help children report early.
  • Users: do not create, request, possess where unlawful or distribute non-consensual intimate imagery.

This is not an argument that Apple, Google, cloud providers or AI companies can stop every act of abuse. Determined offenders may move platforms, self-host, use offshore services, distribute software directly or switch models and payment routes. Difficulty is not the same as futility. We may not be able to eliminate the abuse. We can decide how easy, profitable and scalable we allow it to become.

What parents and schools should understand

A teenager may say, “I only made a fake picture.” The adult response should begin with the impact on the person depicted, not with a debate about whether the file is technically real. The next steps are to stop forwarding, preserve relevant context, tell a trusted adult and use a reporting route. Punishment, safeguarding and legal questions may follow, but panic and public shaming usually make it harder to find out what happened and protect the child.

Schools should record the concern, involve the designated safeguarding lead and follow their child-protection and behaviour procedures. They should not ask a pupil to collect copies from classmates or circulate the image internally. Staff should focus on safety, support, evidence that can be safely preserved and direct reports to the platform or police where appropriate.

IWF: AI child abuse imagery parent safety guide

What if it happens to you?

You do not need to decide whether the image is technically authentic before asking for help. If it is safe to do so, keep the page address, account name, dates, messages and screenshots of surrounding context. Avoid downloading, forwarding or repeatedly re-uploading the intimate image itself. Do not contact the person who made it if that could increase the risk.

  1. 1Tell someone you trust. If you are under 18, tell a parent, carer, teacher or another safe adult; you are not in trouble for being targeted.
  2. 2Report the post, account or message through the platform's NCII or abuse route. Keep the report reference if one is provided.
  3. 3Use Childline's Report Remove service if you are under 18 in the UK. It works with the IWF and is free and confidential.
  4. 4Adults can contact the Revenge Porn Helpline for specialist support with image-based abuse and removal options.
  5. 5Contact the police if there are threats, coercion, stalking, blackmail, a child is involved or you feel unsafe. Call 999 if there is an immediate danger.
  6. 6Ask the school safeguarding lead to act when pupils or school communities are involved. Do not make the pupil prove the harm by showing the image to more people.

Childline: Report Remove for under-18s in the UK

Police.uk: deepfakes, reporting and support

Revenge Porn Helpline: information and advice

The IT Club view

IT Club is pro-technology and pro-AI. Generative systems can create enormous value in education, accessibility, design, research and business. Responsible technology advocacy also requires saying clearly when a product makes serious abuse easier.

Infrastructure providers cannot reasonably know everything every customer does. They can, however, design safer products, apply their published rules, respond to credible notice and avoid making victims navigate an endless loop of forms. Innovation does not remove responsibility. A technically possible product is not automatically a product that an app store must distribute, a payment service must monetise, a search engine must promote or a cloud provider must continue hosting after confirmed abuse.

IT Club: why AI needs practical guardrails

IT Club: AI privacy controls for business data

AI did not invent sexual harassment, bullying or non-consensual image abuse. What it has changed is the barrier to entry. Someone may no longer need an intimate photograph of you; they may only need an ordinary photograph and a service willing to manufacture the rest.

That makes this more than an AI problem. It is a question about consent, responsibility and the kind of technology ecosystem we are prepared to build. The image might be fake. The responsibility isn't.

Attribution and further reading

This article was informed by the 9 July 2026 episode of On with Kara Swisher, “Inside the Fight Against Non-Consensual Deepfake Porn”, featuring Kara Swisher, victims' rights attorney Carrie Goldberg, investigative journalist Laurie Segall and Northwestern computer scientist V.S. Subrahmanian. The episode prompted the questions explored here; the legal, regulatory and policy claims were checked against the sources linked throughout.

On with Kara Swisher: Inside the Fight Against Non-Consensual Deepfake Porn

Plain-English Takeaway

The image may be fabricated, but the abuse is not. Technology companies cannot prevent every misuse, yet they can decide whether harmful products are distributed, monetised, hosted, recommended and left online after credible notice.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor